18 Commits
Author SHA1 Message Date
pakrym-oai f5ffa46959 Preserve queued output for observers during code-mode termination (#48207)
## Why

Yield signals and queued runtime events can detach an observer during termination, before the remaining output has been drained.

## What changed

Track the active yield signal separately from the observer so termination can disable yielding while keeping the observer attached. Ignore `Started`, `Pending`, and `YieldRequested` events during termination, allowing queued output to reach the observer in `CellEvent::Terminated`.

## Testing

Extend the termination regression test with an immediate yield timeout, a canceled yield signal, and queued start, yield, output, and completion events. Assert that both the termination caller and the initial observer receive the queued output in the terminated event.

GitOrigin-RevId: 1c08bdec06838123aaa102268da2f50b63ddea3f
2026-09-25 20:34:52 +00:00
pakrym-oai 55543d8772 Add early yielding for code-mode observations (#48123)
## What changed

Add an optional `preempt` signal to `CodeModeSession::execute` and `CodeModeSession::wait` so callers can end an observation early while the cell continues running and remains available for later waits.

Support the signal in the in-process runtime and across both remote transports: `operation/yield` with the negotiated `yield-observation` capability for stdio, and `YieldObservation` for gRPC. Preserve signals received before gRPC observation registration, and retain normal timeout behavior for older hosts that lack support.

## Testing

Add runtime and transport tests covering early execute and wait yields followed by successful cell completion, yields before observation registration, and suppression of yield frames for older stdio hosts.

GitOrigin-RevId: 3f8049d8f0582be6b8f0832cc03f2d974a0b8f18
2026-09-25 15:42:35 +00:00
Vivian Fang 339e981ba7 Make MCP and Code Mode input schema budgets configurable (#47936)
## Why

Fixed schema budgets can strip parameter descriptions from large MCP tools or render their Code Mode input types as `unknown`. Allow larger budgets to preserve that guidance.

## What changed

- Add `mcp_servers.<name>.tool_input_schema_max_bytes` to configure the UTF-8 byte threshold for best-effort input schema compaction, retaining the 5,000-byte default.
- Add `features.code_mode.tool_input_schema_max_bytes` for rendered input types. Use the largest of the 16,000-byte default, the Code Mode setting, and the ordinary MCP server's explicit setting.
- Apply rendering budgets to prompt declarations and the runtime tool catalog, and avoid reusing cached declarations after the Code Mode budget changes.

## Testing

Add coverage for UTF-8 compaction thresholds, budget precedence, configuration round trips, and preservation of parameter guidance in both the Code Mode prompt and `ALL_TOOLS`.

GitOrigin-RevId: 0ef2823a614d4794e636f518b09c0b03a5239b45
2026-09-24 20:39:37 +00:00
Charlie Marsh dd6eff3954 Share stored JSON payloads across code mode cells with Arc (#47036)
## Why

Creating a cell deep-copies every stored JSON value, including values the cell never loads. Storing a value also duplicates its payload between the cell's local state and pending writes.

## What changed

Use `Arc<JsonValue>` throughout the session store, cell runtime, and completion writes to share immutable payloads. Keep a separate map snapshot for each cell so later commits cannot change its view of stored values.

GitOrigin-RevId: 4535f0f2ed0c8f8cbfb8d24cf1cb44cbc74472b5
2026-09-21 13:57:22 +00:00
Kevin Liu aaa2cabfbc Disable V8 optimization paths affected by array sort bugs (#45760)
## Why

The pinned V8 can inline `Array.prototype.sort` with incompatible element kinds when a comparator mutates the array, allowing an object to be stored in an integer-elements array.

## What changed

Disable Maglev, Turbolev, and TurboFan array builtin inlining during code-mode runtime initialization until the V8 artifacts include the upstream fix.

## Testing

Add an integration regression test that requests top-tier and Maglev optimization, checks element kinds after comparator mutation, and verifies ordinary numeric sorting still returns `[1,2,3]`.

GitOrigin-RevId: cea38e920245d6a133a5263118dc664fb3e61838
2026-09-15 18:52:15 +00:00
jif d77ebc7223 Cancel code mode timer tasks when cleared or the cell finishes (#45399)
## Why

Each `setTimeout` spawned a sleeping thread that remained alive until its delay elapsed, even after `clearTimeout` or cell completion.

## What changed

Replace per-timer threads with Tokio sleep tasks held by `AbortOnDropHandle`, so removing a timeout or dropping the isolate cancels its task. Enter the caller's Tokio runtime on the code mode runtime thread to support scheduling these timers.

## Testing

Add a regression test using virtual time to verify that cleared timers release their tasks, an awaited timer completes, and cell completion cancels remaining timers without emitting their output.

GitOrigin-RevId: 59c7e57ed226cb32633e2d4c25b778cfab2af423
2026-09-14 09:29:51 +00:00
Abhinav 3305c4f31d Scope code mode callback delegates to individual executions (#44865)
## Why

A delegate bound at session creation cannot provide different callbacks for cells sharing that session. Each execution needs to retain its own delegate across yields and release it when the cell is cleaned up.

## What changed

- Pass `CodeModeSessionDelegate` to `execute` instead of session creation.
- Route tool calls, notifications, and cell closure callbacks through the execution's delegate in the in-process runtime and the gRPC and stdio transports.
- Retain delegates with pending executions and live cells, releasing them through closure and cancellation cleanup.

## Testing

Add coverage for distinct delegates across yielded cells, gRPC callbacks before cell admission, and delegate release after completion or abandoned execution cleanup. Update transport tests to verify callbacks reach the owning cell's delegate.

GitOrigin-RevId: 7469f52104b993e790a40c65fb800ad02b7fd606
2026-09-11 17:00:07 +00:00
jif 1afffeabb2 Allow discarded code mode tool responses to be garbage collected (#44619)
## Why

Tool response delivery handles kept discarded results alive until the cell ended.

## What changed

Add a local V8 handle scope in `resolve_tool_response` so delivery handles are released when response delivery finishes. Live promises continue to retain their results.

## Testing

Add a regression test that verifies a live promise preserves its response through garbage collection and that dropping the promise makes the response collectible before the cell ends.

GitOrigin-RevId: a74e78acae3ec9a465694d7503150aee123792ec
2026-09-10 18:55:57 +00:00
Alec Barber c1f1467f30 Handle undefined values before JSON serialization in code mode (#43873)
## Why

Passing `undefined` to a tool could fail JSON parsing because V8 stringifies it as the non-JSON text `undefined`.

## What changed

Return no JSON value for JavaScript `undefined`, so explicit `undefined` tool arguments behave like omitted arguments. Attempts to `store` an undefined value report the existing serializability error and preserve the previous stored value.

## Testing

Add regression coverage for storing `undefined` over an existing `null` value, and extend the current-time tool test to cover `{}`, omitted arguments, and explicit `undefined`.

GitOrigin-RevId: 071050ebb2ecc44c8f08453cf8523b4d21728c7e
2026-09-08 17:51:40 +00:00
Adam Perry @ OpenAI 55e5158e18 Improve tracing for nested tool calls and exec processes (#41950)
## Why

Code-mode callbacks can outlive their initial request and run in separate tasks,
so their trace context must be preserved explicitly.

## What changed

- Preserve the execution context for code-mode callbacks and add spans for
  nested tool invocations in the runtime and dispatch broker.
- Propagate each tool invocation span as the parent of its streamed gRPC
  callback, falling back to the outer execution context when needed.
- Add a `codex.exec_server.process` span for each process lifetime, including
  its process ID and completion result, without retaining the request span.

GitOrigin-RevId: a6059e34d895416f5517e51dad6ca0078355adca
2026-09-01 01:00:50 +00:00
Jennifer Zhao 981d6b652b Omit undersized WAV output from Code Mode (#41934)
## Why

Audio models cannot reliably encode tool-generated clips shorter than 25 ms.

## What changed

- Measure the available audio frames in base64-encoded PCM and IEEE float WAV outputs.
- Replace clips under 25 ms with explanatory text while preserving surrounding Code Mode output.
- Leave clips at or above the threshold and unrecognized audio formats unchanged.

## Testing

- Cover the duration boundary across multiple sample rates and all supported `audio()` input forms.
- Verify bounded and truncated WAV chunks, output after `yield_control()`, and end-to-end mixed text and audio output.

GitOrigin-RevId: 342b4bdbc65db4238580f9cdc372763c2576eca5
2026-08-31 23:36:04 +00:00
Adam Perry @ OpenAI 48e22a5fa0 Report code mode host request durations (#41452)
## Why

Code mode wall time should measure the host operation itself, without including
client-side response delays or idle time between requests.

## What changed

- Measure each execute, wait, and terminate request in the code mode host.
- Carry the duration through the stdio and gRPC protocols and use it for
  model-visible wall time.
- Emit a structured `codex.code_mode.host_timing` event correlated with the
  conversation, turn, tool call, and cell.

## Testing

- Cover successful and failed execution timing, delayed response reads,
  repeated waits, termination, and missing cells across stdio and gRPC.
- Verify timing survives protocol serialization and is reflected in app-server
  model output and structured telemetry.

GitOrigin-RevId: d24af30c3fc5820521b4beba1f9970714dad6482
2026-08-29 02:52:58 +00:00
felixxia-oai 16e2722c50 Consolidate code mode output helper tests (#39969)
## What changed

- Cover object serialization through the `text()` helper directly in the code
  mode runtime suite.
- Remove redundant core integration coverage for serialized text and rejected
  image outputs.

GitOrigin-RevId: f465b8361e9d725a7246994d9c41e9d01c969011
2026-08-21 16:50:34 +00:00
felixxia-oai 37a9da9901 Move the global scope check into the code-mode runtime (#39703)
## What changed

Replace the core integration test for allowed `globalThis` properties with an
in-process code-mode runtime test. The test continues to fail when the runtime
exposes a global outside the allowlist without requiring the core network test
harness.

GitOrigin-RevId: f33846ae2bb35e6779b5bec0a3f0ba5729eb707d
2026-08-20 12:02:42 +00:00
jif b0cdcce616 Test text stringify errors in the code mode runtime (#39505)
## What changed

Move circular-value coverage for the `text()` helper from the core integration
suite to the in-process code mode runtime tests. Verify that stringification
returns no content and surfaces the V8 circular-structure error without needing
a mock server or network access.

GitOrigin-RevId: d506591af5ae8ce0a8c7305d633a7b0f2e458335
2026-08-19 15:37:26 +00:00
Sean Huang 9d00bb01c0 Add per-session code-mode execution limits (#37114)
## What changed

- Add `create_session_with_limits` and session-scoped cell execution limits.
- Clamp execute and wait yield times to the session's `max_yield_time_ms`
  without terminating the running cell.
- Negotiate support with remote code-mode hosts and include non-default limits
  in `session/open`, while keeping unlimited sessions compatible with hosts and
  providers that do not support limits.

## Testing

- Cover yield-time clamping, zero-timeout behavior, and isolation between
  sessions.
- Cover wire serialization, capability negotiation, unsupported hosts, and
  shared process-host execution.

GitOrigin-RevId: 9517321cd605bb87f93eeaa6ba331cc2e346e582
2026-08-05 16:09:01 +00:00
Sean Huang 2e32d95894 Enable sandboxed V8 for code mode (#36374)
## Why

Code mode must link against a V8 build with sandbox support, but Windows MSVC
still used upstream non-sandboxed prebuilts and package builds selected the
older release artifact profile.

## What changed

- Enable the `v8_enable_sandbox` feature directly for the code mode runtime.
- Select the `ptrcomp_sandbox_release` archive and bindings in Cargo packaging
  and CI, including Windows MSVC release builds.
- Point Bazel's Windows MSVC targets at the sandbox-enabled Codex artifacts and
  enable the matching crate feature.

## Testing

Add a runtime test that calls `v8__V8__IsSandboxEnabled()` and verifies that
the linked V8 library has sandbox support enabled.

GitOrigin-RevId: c1b49b44a6ccfea5b5006d69ec7866848d1cddd7
2026-07-31 18:32:28 +00:00
Channing Conger 97576b1794 Run code mode exclusively through the standalone host (#36217)
## What changed

- Move the V8 implementation into a dedicated `codex-code-mode-runtime` crate used by `codex-code-mode-host`, removing the embedded runtime fallback from the Codex process.
- Resolve the host executable from the active installation layout and check its availability before selecting tools.
- Fall back to direct tools with a one-time warning when optional code mode is unavailable. Keep `code_mode_only` and `disable_in_process_fallback` configurations fail-closed.

## Testing

- Cover host discovery for standalone and package layouts, including missing hosts and symlinks.
- Verify direct-tool fallback, one-time warnings, and fail-closed code-mode-only behavior.

GitOrigin-RevId: 5aa3c6f1db148b2231fc24089a2ee0e2b00dbddb
2026-07-30 20:24:29 +00:00