5544 Commits
Author SHA1 Message Date
Matthew Zeng 456212ca21 Use explicit histogram buckets for tool and skill context metrics (#48819)
## What changed

- Give tool fragment sizes and namespace counts logarithmic boundaries through 32,768.
- Give enabled and kept skill counts integer boundaries from 0 through 512, removed description characters logarithmic boundaries through 131,072, and skill truncation flags boundaries at 0 and 1.
- Record these metrics with explicit boundaries, separating zero values and retaining overflow buckets above each range.

## Testing

Extend tool and skill metric tests to assert explicit boundaries. Add an export test covering zero, one, the upper boundary, and overflow, including bucket counts, ordering, and sample totals.

GitOrigin-RevId: 9fbf3acbe352d7c74f3ad11f0b690148c083a6ef
2026-09-28 00:05:54 +00:00
vkg-oai 3f4668da20 Add history-aware prewarming for idle threads (#48812)
## What changed

- Add `CodexThread::prewarm_with_history()` to prepare a WebSocket response with existing conversation history and executed-tool metadata using `generate: false`. The next turn can reuse the prepared response when its prompt extends that history and request settings match.
- Keep startup prewarming and `prewarm()` on the existing empty-input path, and skip preparation when the cached WebSocket is ready.
- Label prewarm telemetry by input mode and WebSocket continuation metrics with `after_prewarm`.
- Rename `persistent_mode_enabled` to `persistent_execution_enabled` without changing its behavior.

## Testing

Extend WebSocket coverage to check history preservation during reconnect prewarming, reuse of the prepared response on the next turn, and omission of `previous_response_id` for a non-prefix prompt.

GitOrigin-RevId: c7731541b11b2e6668027a47f37f696213268c66
2026-09-27 23:21:25 +00:00
Won Park d7748e1185 Add opt-in structured errors for Guardian circuit-breaker interruptions (#48796)
## Why

Guardian denial-limit interruptions lack a structured error identifying the cause. Make this opt-in because older clients may not recognize the new error in shared history.

## What changed

- Add `auto_review.circuit_break_action = "strict"` to attach `TooManyDenials` to the interrupted turn. The default leaves the error unset.
- Expose `turn.error.codexErrorInfo = "tooManyDenials"` in app-server notifications and saved history, and update protocol schemas and generated types.
- Preserve the warning, denial limit, and interrupted status without emitting a separate error notification.

## Testing

Add an integration test covering omitted, `default`, and `strict` settings, checking warnings, live turn errors, the absence of separate error notifications, and persisted turn errors after restart.

GitOrigin-RevId: cb5d379e64728d4d7b9daf834c13756e4a70db31
2026-09-27 22:05:19 +00:00
victor-openai ea64727556 Add single-server MCP status discovery with thread connection reuse (#48783)
## Why

Inspecting one MCP server should not require full-inventory discovery or a separate connection when a thread already has one.

## What changed

- Add optional `serverName` to `mcpServerStatus/list` and update generated schemas and bindings.
- With `threadId`, apply any pending runtime refresh and reuse the thread's current connection and tool catalog, waiting only for the selected server during discovery.
- Without `threadId`, create a discovery connection for only the selected server. Unknown names return an empty page; omitting `serverName` preserves full-inventory discovery.

## Testing

Add a regression test covering both status detail modes, checking that tool metadata is preserved and that status reads do not repeat `initialize` or `tools/list` requests.

GitOrigin-RevId: 1b361b67a993ab45cae493e88c146f50cfaf753a
2026-09-27 21:07:54 +00:00
felixxia-oai 21eb35513d Preserve independent Guardian history across parent compaction (#48779)
## Why

Guardian reviews need to retain original evidence across parent compaction when checkpoint reuse is disabled, including after resume and rollback.

## What changed

- Make disabling `guardian_reuse_parent_compaction` select a bounded, independent review transcript while preserving thread-owned authorization.
- Keep synchronous reviews and asynchronous scoring independent of parent checkpoints, and allow reviewer sessions to continue using transcript deltas across parent compaction.
- Persist transcript entries with rollback provenance while remaining compatible with older checkpoint readers and metadata-free checkpoints.
- Exclude compaction output from the transcript and synthetic summaries from rollback turn boundaries. Use acceptance ordering to remove rolled-back evidence even when persistence order differs.

## Testing

Add regression coverage for reviewer continuity, evidence retention across compaction and resume, rollback after local and remote compaction, and checkpoint serialization compatibility.

GitOrigin-RevId: fea0852cc5537372854f4a34bacb6bfda6d13e88
2026-09-27 20:15:23 +00:00
victor-openai 32f5784851 Preserve MCP app resource URIs without defaulting display mode (#48764)
## Why

Defaulting missing or unsupported display preferences to `inline` prevents clients from applying resource display defaults.

## What changed

Populate `mcpAppUi` only when a tool descriptor has a resource URI and an explicit `inline` or `fullscreen` preference. Preserve `mcpAppResourceUri` independently in tool-call events, including when `mcpAppUi` is unset, and document the behavior.

## Testing

Update integration coverage for explicit display modes, missing and unsupported preferences, and legacy resource URIs, checking tool-call events and resumed history.

GitOrigin-RevId: 4876cced068d8e464adeb265abd053d8abe667ce
2026-09-27 18:20:25 +00:00
Ankush Gupta 88235f881d Retain confirmed Code Mode messages for Guardian reviews (#48725)
## Why

Guardian needs the assistant's delivered question to interpret a user's reply. Messages sent through nested Code Mode tools must remain available as review context, and approvals based on earlier context must become stale when a new delivery is confirmed. Assistant messages do not themselves grant authorization.

## What changed

- Capture successful hosted User Messaging sends after input rewriting and before result callbacks or post-tool hooks.
- Retain bounded delivery text in acceptance order, persist it through cancellation and shutdown, and preserve it across compaction and resume with an older-client-compatible rollout encoding.
- Track assistant review context separately from user authorization, invalidating pending and cached approvals for both local and worker reviews when that context changes.
- Associate retained deliveries with the correct instruction or communication boundary during rollback.

## Testing

Add coverage for nested messaging review context, fast replies and communication ordering, shutdown persistence, stale local and worker approvals, rollout compatibility, and rollback retention.

GitOrigin-RevId: 1bc1ec9e8947560b99f4b39a42ddb9f2099f519b
2026-09-27 15:03:38 +00:00
chess 41f9084b30 Remove WebSocket headers and tool payloads from info logs (#48686)
Stop logging response headers on successful WebSocket connections and payload
previews for tool calls. Keep the connection URL, tool name, and thread ID in
their respective log entries.

GitOrigin-RevId: 1d410b6aef8f12153da9bfc60c515b8e797a9de0
2026-09-27 11:30:52 +00:00
Eric Traut 334b6e7321 Remove follow-up prompt suggestions from the TUI (#48621)
## What changed

Remove automatic next-message generation after successful turns, suggestion rendering in the composer, and the associated Tab acceptance and Escape dismissal handling. Remove the `tui.prompt_suggestions` configuration option and its schema entry, along with suggestion-specific tests and snapshots.

GitOrigin-RevId: 63bf6f2ca85da6ece502c86e2a805d000bf34210
2026-09-27 05:29:53 +00:00
alishobeiri-oai 814de47b69 Centralize persistent mode enablement checks (#48611)
## What changed

Add `Features::persistent_mode_enabled` and use it for persistent instructions and current-time reminder defaults. Enablement still requires `ReasoningEffort::Persistent`.

Change `PersistentModeState::new` to accept an explicit enablement boolean, separating instruction rendering from reasoning-effort selection.

## Testing

Update persistent-context tests to use boolean enablement while preserving coverage for instruction replacement, removal, deduplication, and retained history without a snapshot.

GitOrigin-RevId: f412b90d783438d1526956a56c11b9e66385ee0e
2026-09-27 04:00:21 +00:00
Alex Daley 0f9a731ade Preserve deferred tool namespace names before descriptions (#48574)
## Why

Long descriptions could exhaust the 4 KiB tool summary budget and hide later namespace names, limiting their visibility for tool discovery.

## What changed

- Reserve space for all namespace names before sharing the remaining budget across descriptions, including added and removed groups.
- Truncate descriptions at UTF-8 boundaries with `...`, including at the existing 250-character cap. Omit whole namespaces only when names alone exceed the budget, reserving omission notices only in that case.
- Render namespace names and descriptions without XML escaping.

## Testing

Add unit and snapshot coverage for description allocation, Unicode boundaries, namespace omissions, and empty-state notices. Add a scenario verifying that a crowded catalog retains every namespace name, allows discovery of a late namespace with its full description, and keeps the summary unchanged on follow-up.

GitOrigin-RevId: 9743cda5aa14190db22c788c9e91e1785a32682b
2026-09-26 23:46:10 +00:00
open-matt b8d5e3f12e Allow exec-server to proxy permitted private IPs upstream (#48568)
## Why

Private IP destinations always bypassed inherited upstream proxies, preventing their use for private networks reachable through an upstream VPN proxy.

## What changed

- Add `codex exec-server --proxy-private-ips-via-upstream`, also configurable with `CODEX_EXEC_SERVER_PROXY_PRIVATE_IPS_VIA_UPSTREAM=true`. The setting defaults to disabled.
- Allow permitted RFC 1918, carrier-grade NAT, and IPv6 unique-local destinations to use an applicable upstream proxy. Loopback and link-local destinations retain direct routing, and destination access policy still applies.
- Keep connections direct when no valid upstream proxy applies or `allow_upstream_proxy=false`. Errors after selecting an upstream proxy do not trigger a direct retry.
- Rename `ExecServerRuntimePaths` to `ExecServerRuntimeOptions` and carry the routing setting from executor startup into the managed network proxy.

## Testing

Add routing coverage for private address ranges, special-use addresses, and public targets with the option enabled and disabled. Verify that HTTP and CONNECT requests still enforce destination allowlists and denylists, and update the CLI help snapshot.

GitOrigin-RevId: b7c9cc7da0e0f545694a6521b74c9b36b7b92769
2026-09-26 23:17:41 +00:00
pakrym-oai 12de0e395d Preserve WebSocket continuations when steering a turn (#48508)
## Why

Steering an active WebSocket response previously dropped the connection and
resent the full history. Draining the response preserves the connection and
allows the follow-up request to continue with `previous_response_id`.

## What changed

- Drain WebSocket responses when steering. For models using
  `use_responses_lite`, first send `response.interrupt` with
  `mode: "discard_partial_items"` once the response ID is available.
- Treat `response.incomplete` with reason `interrupted` as completion with
  `end_turn: false`, preserving token usage and allowing the turn to continue.
  Other incomplete reasons remain errors.

## Testing

Update the steering integration test to cover completed and discarded reasoning
items, asserting connection reuse, incremental follow-up input, and token usage
from the interrupted response.

GitOrigin-RevId: bc714b713e797cf1a67e3b26ffbf7664cb92eb33
2026-09-26 18:36:55 +00:00
Felipe Coury b334d5b3f2 Default to copying transcript selections in more terminals (#48469)
## What changed

Make `tui.copy_on_select = "auto"` copy on mouse release unless a direct terminal is known to forward its native copy shortcut: Ghostty with a parsed version at least `1.2.0`, Kitty on macOS, Windows Terminal, or VS Code on Windows.

Unknown terminals and Ghostty with older, missing, or unrecognized versions now default to copying. Keep copying enabled under tmux/Zellij and preserve explicit `always` and `never` overrides. Update the configuration documentation and schema to describe these defaults.

## Testing

Expand the existing configuration test matrix to cover more terminals, Ghostty versions (including `1.2.0-dev`), platform-specific defaults, and multiplexer behavior alongside configuration and launch overrides.

GitOrigin-RevId: 410abfa580156454b0f88e0bf4ed977fb8c81b1e
2026-09-26 15:48:27 +00:00
vkg-oai e72da2b538 Stabilize skill catalogs across executor availability changes (#48353)
## Why

Changes in executor availability can alter cloud skill catalog rendering under a shared budget and repeat an unchanged executor catalog when it reconnects.

## What changed

- Cap cloud skills at three quarters of the metadata budget initially, leaving the remaining budget and unused cloud allowance for filesystem skills. Reduce the cloud cap only when doing so allows all skill entries to fit; description truncation alone does not trigger rebalancing.
- Persist the allocation across disconnects, compaction, and thread resume. Recompute it when the cloud inventory or total budget changes.
- Emit a short availability update when an unchanged selected-environment catalog returns and its full text remains in history. Reinject the full catalog when that text is missing.

## Testing

Add coverage for allocation stability, catalog and budget changes, omission handling, and full catalog reinjection after compaction and resume. Extend the selected capability stack test to verify reconnection avoids repeating the catalog.

GitOrigin-RevId: 839fe98024e00c4082a46e6a40675e15fd2c16c6
2026-09-26 04:19:46 +00:00
peilin-openai c9e2520707 Preserve tool metadata for OpenAI provider endpoint overrides (#48344)
## Why

Destination-only filtering stripped raw tool result metadata and MCP attribution when the built-in OpenAI provider used a custom endpoint.

## What changed

Add a runtime-only `include_internal_metadata` grant to `ModelProviderInfo` and enable it for the built-in OpenAI provider. Apply the provider grant or the existing first-party HTTPS destination check to both HTTP and WebSocket Responses requests.

Keep the grant out of serialized configuration and schemas, and default it to false for providers received through remote configuration. Providers without the grant retain the existing destination filtering.

## Testing

Update HTTP and WebSocket tests to expect metadata at overridden OpenAI endpoints. Cover provider grants, destination filtering, MCP attribution on requests, and the grant's exclusion from TOML serialization and configuration.

GitOrigin-RevId: 53aad6fb4d52cdfa9c79c6d92fe87383e1d0d1ef
2026-09-26 03:49:14 +00:00
zm-oai dfdb40cd0b Prevent Windows daemon launches from retaining launcher stdio (#48272)
## Why

Detached Windows daemons can inherit the launcher's output pipes, leaving callers waiting for EOF after the launcher exits.

## What changed

Clear inheritance flags on the launcher's standard handles before spawning managed Windows processes. Leave the flags cleared to protect concurrent launches while preserving the child's configured stdio, and tolerate missing or already-closed handles.

## Testing

- Add a Windows regression test verifying that captured launcher output closes while the detached child remains alive and writes to its configured log.
- Give optional MCP startup grace tests more time to complete on slow runners while keeping the pending server's startup timeout longer than the turn timeout.

GitOrigin-RevId: 053e0417793db3c961e738476a05c7467978f339
2026-09-25 23:28:45 +00:00
jamy-OAI 5f3180c793 Preserve model and access program pairs during compaction (#48224)
## Why

Compaction using the previous model can inherit the current turn's access program, producing a model/program pair that the server rejects.

## What changed

- Persist `cyber_access_program` in previous-turn settings and restore it during rollout reconstruction.
- Use the previous turn's access program when compacting with its model, preserving an absent program instead of inheriting the current selection.
- Pass the selected access program into local compaction prompts.

## Testing

Add regression coverage for local and remote compaction after model switches, including resume, fork, rollback, and compaction checkpoints. Verify fallback and subsequent sampling use the current model/program pair, and API-key sessions do not inherit access-program authorization.

GitOrigin-RevId: eaa7162e8711446dc9eb1bfff194e711abd54d7e
2026-09-25 22:14:19 +00:00
ningyi-oai 63eb71c9da Preserve late result metadata for truncated code-mode calls (#48222)
## Why

When a nested code-mode call's recorded arguments were truncated and attached to an output before its result arrived, the recorder could no longer attach the result metadata to that call.

## What changed

Retain validated call bindings so late result metadata updates the original output across retries and subsequent waits. Keep truncated arguments and incomplete call inventories intact, and apply existing metadata budgets.

Invalidate late metadata bindings when duplicate IDs, reused cells, conflicting outputs, or changed call inventories make attribution ambiguous. Clear stale pending calls when a cell ID is reused, and avoid counting duplicate pending IDs against capacity more than once.

## Testing

Add recorder regression tests for late metadata across retries, compaction, waits, and cell closure, plus ambiguous bindings and budget limits. Add a code-mode integration test that delays a tool result until its truncated call has been recorded and verifies metadata remains attached to the original output across later waits.

GitOrigin-RevId: 7398beaaa1a513147deebdea7aa841513a79d06b
2026-09-25 22:08:14 +00:00
Sean Huang 8f5387d104 Honor execution environment proxy requirements (#48198)
## Why

An execution environment's enabled proxy configuration was reduced to traffic restrictions, leaving restricted commands offline without a controller proxy or an approved network grant.

## What changed

Carry `NetworkProxyConfig.enabled` into `EnvironmentNetworkPolicy.requires_proxy` and honor it when activating managed networking. This lets environment owners require filtered proxy access while direct network access remains restricted. Policies without an explicit proxy requirement retain the existing activation behavior.

## Testing

Extend remote command coverage to check allowed and denied proxy requests without a controller proxy, and verify that direct network access remains blocked.

GitOrigin-RevId: 7cc0063a0d1118de56b1bd30036338cf14360f6a
2026-09-25 20:11:25 +00:00
jackz 1d804e91b7 Protect .aws directories under sandbox writable roots (#48176)
## Why

AWS profiles can select credential helpers that the application executes. Granting write access to a containing directory should therefore keep `.aws` protected by default.

## What changed

Add `.aws` to the protected metadata paths alongside `.git`, `.agents`, and `.codex`, including workspace roots and additional writable roots. Preserve explicit user rules that override the default protection.

## Testing

Extend policy and sandbox tests to cover `.aws` protection. Add macOS coverage for existing and absent `.aws` directories, deletion and replacement attempts, and symlink targets. Verify that Linux sandbox writes to protected configuration files fail while sibling files remain writable.

GitOrigin-RevId: 31ea287bd0dd9b13aff893783fba9ca3aed0c89d
2026-09-25 19:14:31 +00:00
rhan-oai 44a9bfa145 Preserve usage limit windows in turn and compaction analytics (#48174)
## Why

Usage limit errors discarded the server-selected window responsible for the limit, leaving turn and compaction analytics unable to distinguish five-hour limits from weekly limits.

## What changed

Preserve optional `limit_window_minutes` from usage limit error responses in `UsageLimitReachedError` and report it as `usage_limit_window_minutes` in turn and compaction events. Accept unsigned integers that fit in `u16`; treat missing, null, malformed, or out-of-range values as unknown. Events for other error kinds report `null`.

## Testing

Add coverage for HTTP and wrapped WebSocket error mapping, analytics serialization and reduction, and app-server propagation to turn and local/remote compaction events. Cases include five-hour and weekly windows, missing or invalid values, and unrelated errors.

GitOrigin-RevId: a32066a007559d91a3c868a756bfd0f976777176
2026-09-25 19:05:15 +00:00
Steve Coffey f6a4bd81e3 Generate unique exec-server process IDs for every request (#48168)
## Why

Threads sharing an executor and sandbox retries can reuse a public process handle while the executor still retains the previous process.

## What changed

Always append a fresh UUID to the exec-server process ID, including requests without sandbox or shell snapshot settings, to avoid collisions when handles are reused.

## Testing

Update the request-parameter test to check the UUID-suffixed format and verify that repeated calls with the same handle produce distinct process IDs.

GitOrigin-RevId: bd1fc9af3e7d5ea99fdf88382df09afa7dc9f72b
2026-09-25 18:56:32 +00:00
olliem-oai a0b85c7a66 Fix Guardian retained context spacing and empty assistant handling (#48158)
## Why

Complete assistant messages with empty text can produce misleading omitted-context notices in Guardian reviews.

## What changed

- Skip complete, empty assistant messages when recording and rendering retained context, while preserving omission notices for incomplete messages.
- Separate retained instruction fragments with blank lines and keep blank lines free of role prefixes, while labeling every nonempty line with its original role.
- Update source-order guidance detection and empty-section deduplication for the added spacing.

## Testing

Extend retained-context tests to cover empty completed messages across resume, restored empty messages, incomplete-message notices, blank-line spacing, and role labeling. Update Guardian prompt snapshots.

GitOrigin-RevId: e945717b18689fa4538d9b617b89a644858ab1c8
2026-09-25 18:28:46 +00:00
rreichel3-oai c7e80f873f Preserve executor MCP credential boundaries across reconnects (#48143)
## Why

Cached executor MCP declarations must not gain access to host environment credentials when reconnecting to an executor that lacks environment credential resolution.

## What changed

- Retain credential policy through MCP registration, catalog materialization, and runtime setup. Derive selected HTTP plugin policy from the plugin's source environment.
- Reject host bearer-token fallback and transports requiring host environment headers or helpers for executor-owned declarations. Preserve host-configured credential resolution.
- Include credential policy in connection and tool catalog cache identities, and avoid reading host environment values for executor-only identities.

## Testing

Add regression coverage for legacy executors, cached declarations after a capability downgrade, policy preservation through catalog rebuilds, and connection and tool cache isolation.

GitOrigin-RevId: 2d5b85e4e98668c637c538cbe528914c936bd831
2026-09-25 17:15:29 +00:00
pakrym-oai f92655d07f Preempt model responses when new user input arrives (#48141)
## Why

With `instant_interrupt` enabled, new user input should reach the model without waiting for an unfinished response or stream retry backoff.

## What changed

- Interrupt request setup, response streaming, and retry backoff when user input arrives, then continue the turn with the queued input.
- Reset the WebSocket connection and continuation state after preemption so the next request sends full history.
- Drain pending input after a preempted step even when compaction leaves the estimated context above the token limit.

## Testing

Add regression coverage for WebSocket reconnection with full history, interrupted retry backoff, input queued during compaction, and yielding running code-mode calls. Add a streaming scenario that preserves completed commentary while excluding unfinished assistant text from the replacement request.

GitOrigin-RevId: b7e42b6afffbf87da15af05e0850af8579d1353f
2026-09-25 17:05:53 +00:00
pakrym-oai 1bf73324ca Add opt-in code-mode yielding on new user input (#48135)
## Why

User input queued during a long-running code-mode `exec` or `wait` can remain pending until the call returns. Allow these calls to yield early so Codex can receive the new input while the cell continues running.

## What changed

- Add the `instant_interrupt` feature flag, disabled by default.
- Watch queued user input for each sampling request and pass a shared preemption signal to code-mode `exec` and `wait` calls, including calls received later in the same response.
- Yield running cell IDs without stopping the cells, allowing subsequent `wait` calls to collect their results.

## Testing

Add integration coverage for enabled and disabled behavior, repeated steering during `exec` and `wait`, input deferred during compaction, and later calls in the same response. Verify that direct tool results and queued user messages are preserved, and add a scenario snapshot showing continuation after a cell yields.

GitOrigin-RevId: e33466a980d98e113bfb6c6a45c59de0cc7b3c1d
2026-09-25 16:28:36 +00:00
pakrym-oai 55543d8772 Add early yielding for code-mode observations (#48123)
## What changed

Add an optional `preempt` signal to `CodeModeSession::execute` and `CodeModeSession::wait` so callers can end an observation early while the cell continues running and remains available for later waits.

Support the signal in the in-process runtime and across both remote transports: `operation/yield` with the negotiated `yield-observation` capability for stdio, and `YieldObservation` for gRPC. Preserve signals received before gRPC observation registration, and retain normal timeout behavior for older hosts that lack support.

## Testing

Add runtime and transport tests covering early execute and wait yields followed by successful cell completion, yields before observation registration, and suppression of yield frames for older stdio hosts.

GitOrigin-RevId: 3f8049d8f0582be6b8f0832cc03f2d974a0b8f18
2026-09-25 15:42:35 +00:00
felixxia-oai 68e0c9f5d8 Prevent worker completion races in the guardian authorization test (#48119)
## Why

The worker's completion notice can interrupt the root's one-shot question response before the messaging call reaches its cancellation point in `guardian_subagent_review_preserves_late_root_user_authorization`.

## What changed

Gate the worker's initial response with a `oneshot` channel and a streaming SSE server. Release it after the root's question turn completes or its cancellation is observed, then wait for worker completion and shut down the server.

GitOrigin-RevId: d7f287557a7c27f1054c7ae90ba331ff26bba8ef
2026-09-25 15:26:34 +00:00
Felipe Coury b8a1fe4afc Add configurable right-click paste to the fullscreen TUI (#48118)
## What changed

- Add `tui.right_click_paste` with `auto`, `on`, and `off` modes. The default `auto` enables the fallback on Windows and Linux, including WSL when terminal detection is conclusive. `on` also enables macOS. Both modes skip SSH sessions and recognized VS Code terminals.
- Paste clipboard text through the normal composer input path when no selection, search, or blocking view takes precedence. Discard pending results after intervening input, focus loss, or changes to the target thread, draft, or cursor.
- Read text asynchronously through the shared clipboard worker, with a five-second deadline and the message size limit. Read the Windows clipboard through PowerShell on WSL and reject overlapping clipboard operations.

## Testing

Add coverage for platform and terminal policy, normal paste delivery, stale reads, overlapping clipboard operations, read timeouts, oversized text, and large command output.

GitOrigin-RevId: 0a7b6d445c09928da6c5335841ba2a9a66cc7e4b
2026-09-25 15:15:56 +00:00
felixxia-oai bd3d4d1436 Preserve user text parts during local compaction (#48115)
## Why

Local compaction flattened retained user messages into a single text part, losing their original content boundaries and per-part annotations.

## What changed

Preserve the original content parts and annotations for text-only user messages that fit within the token budget. Borrow the original messages until selected history entries are materialized, and rebuild only the text fallback for truncated messages or messages containing media.

## Testing

Extend unit coverage for text boundaries, empty parts, omitted media, and retained metadata. Update the compaction integration test to verify that a multipart user message survives unchanged in the next request and retains its content parts and annotations in persisted replacement history.

GitOrigin-RevId: 39d9df9ae5360506c2a4bdeac76d89198dbbd39c
2026-09-25 15:03:02 +00:00
felixxia-oai d5cbfe1455 Deduplicate retained instructions against Guardian transcripts (#48109)
## Why

Synchronous Guardian reviews can include the same user instruction in both the retained instructions section and the conversation transcript. Avoid this duplication while preserving complete authorization evidence and its original acceptance order.

## What changed

- Carry retained source metadata into transcript rendering. Omit a retained instruction when the transcript delivers its complete matching source revision.
- Label qualifying transcript entries with retained source order and protect them from budget truncation. Keep separate retained instructions when source metadata is missing or incomplete.
- Track delivery of source-order guidance so it remains available even when all retained instructions are delivered through the transcript. Invalidate that delivery proof when messages are shortened.

## Testing

Add coverage for complete-source deduplication, missing or incomplete metadata, budget protection, guidance redelivery, and source metadata preservation across resume. Update Guardian review assertions and snapshots to verify instructions are delivered once.

GitOrigin-RevId: 20ad0304501fa49f1596c4cfaf3ef89d64815753
2026-09-25 14:54:51 +00:00
jif b63a296775 Honor shell environment policy in legacy snapshots (#48099)
## Why

Legacy shell snapshots could retain exports excluded by `shell_environment_policy` and restore captured values over explicit overrides when replayed.

## What changed

- Build snapshots with the resolved environment's policy and omit filtered exports and original values for variables overridden by `set`.
- Skip eager snapshot creation when configuration is unavailable, and reject snapshots whose policy differs from the current turn's policy.

## Testing

Add a regression test covering default and custom exclusions, `include_only`, preservation of multiline values, and `set` overrides that survive snapshot replay. Verify excluded and overridden captured values are absent from the snapshot file.

GitOrigin-RevId: 4b785130f6c5a4d268ab86fd36ab9d77d8c4a3b9
2026-09-25 14:15:05 +00:00
felixxia-oai b35a7afbe8 Preserve recent authorization context for Guardian reviews (#48098)
## Why

User messages could fill the root context limit before assistant questions were considered, while commentary could displace relevant conversational context. Guardian needs that context to interpret user authorization when reviewing subagent actions.

## What changed

- Select recent user and assistant evidence together under a shared message limit, discarding assistants with unknown ordering first.
- Exclude explicit assistant commentary and retain message phases across compaction. For older retained records, check available source messages for commentary phases.
- Mark missing instructions or assistant context when the shared limit removes corresponding evidence, and use remaining space for legacy instructions.

## Testing

Update Guardian authorization tests to cover shared message limits, commentary filtering across compaction and resume, and preservation of ordered replies when legacy assistant context has unknown ordering.

GitOrigin-RevId: c369a2760917cba9d7dfca37fb5e85a7ec49012f
2026-09-25 14:06:57 +00:00
jif 60713126ee Avoid stdin approval for runtime-only permission grants (#48073)
## Why

Runtime filesystem grants, such as those used for plugin metrics, could trigger unnecessary approval for `write_stdin` and prevent input when sandbox approval was disabled.

## What changed

Include retained runtime grants in the baseline permission comparison for stdin review. Continue requiring review for additional agent permissions, sandbox bypasses, and policy changes. Update the approval description to report current permissions when only runtime grants are present.

## Testing

Extend unit coverage to ensure runtime grants do not require review or mask agent filesystem and network grants, and that sandbox bypasses still require review. Add local and remote plugin regression cases that send stdin and verify metric emission with sandbox approval disabled.

GitOrigin-RevId: 989098bdc7fbf839786c01f11cbf02999bae1cc1
2026-09-25 11:43:35 +00:00
jif ca60d6fa72 Skip message-board notification previews when there are no recipients (#48072)
## What changed

Return post metadata from the in-memory message board after updating board state when no notification recipients remain. This avoids constructing an unused notification preview, including when the author is the only requested recipient.

## Testing

Run the existing post-and-search model-context scenario against both disk and in-memory message boards, checking that post metadata and search results reach the model without self-notifications.

GitOrigin-RevId: dcf07a5fd55738fbcd6edd3dce3f6fb8fc910eaf
2026-09-25 11:42:44 +00:00
jif 69fa3881cb Handle early command yields in the Guardian network approval test (#48069)
## Why

The network command can yield before its request reaches Guardian, allowing a parent request to consume the mock response intended for Guardian.

## What changed

Update `guardian_receives_exact_trigger_for_single_network_request` to match parent and Guardian requests separately. Have the parent poll running processes with `write_stdin` until they exit, and bound the wait for turn completion to 30 seconds. Preserve the assertion that Guardian receives exactly the original call ID and command.

GitOrigin-RevId: f39e9461c3628fbab00ba241f828d318b17975b5
2026-09-25 11:30:57 +00:00
felixxia-oai 86be5320b0 Deduplicate retained instructions across Guardian reviews (#48060)
## Why

Reused Guardian sessions already contain previously delivered instructions. Follow-up reviews can avoid repeating that evidence, but must deliver it again if it changes or compaction removes it.

## What changed

- Track retained source identity, revision, and completeness in host-owned history metadata, preserving revisions during replay.
- Omit retained instructions from synchronous review inputs only when the same complete revision remains in reviewer history.
- Restore missing evidence after reviewer compaction, enforcing the request budget before persisting additions. Classify restored evidence as context rather than new user authorization.
- Keep source-order labels stable across eviction and retain full delivery for legacy records without reliable provenance.

## Testing

Add coverage for consecutive-review deduplication, changed revisions, missing or incomplete metadata, and restoring compacted evidence exactly once. Extend compaction and resume coverage to verify retained revisions.

GitOrigin-RevId: e90fca16cde0a0970da36dd873af2ca1dbaaf4d3
2026-09-25 10:49:50 +00:00
open-matt aa380897f6 Add startup-only PID namespace inheritance to exec-server (#47989)
## Why

When a container denies fresh `/proc` mounts, the existing sandbox fallback retains the caller's `/proc` while creating a new PID namespace. Process IDs inside the sandbox can then differ from those exposed by `/proc`, breaking process lookups.

## What changed

- Add `codex exec-server --linux-sandbox-pid-namespace=inherit` to reuse the caller's PID namespace and `/proc` for both process and filesystem helpers. Repository config and command environment variables cannot enable it.
- Keep `isolate` as the default, preserving the existing mount fallback and compatibility with older helpers. Inheritance requires an updated helper and omits `--unshare-pid` and `--as-pid-1`.
- Preserve other sandbox restrictions. With `:minimal`, bind the inherited `/proc` read-only with its container masks and apply explicit filesystem denials afterward.

Inheritance is intended for dedicated environments: it allows sandboxed commands to signal other same-UID processes, including the executor.

## Testing

Add unit and integration coverage for namespace flags, denied proc mounts, consistent process IDs, retained sandbox restrictions, and startup-only selection across process and filesystem helpers.

GitOrigin-RevId: dd13f2b9286d7edcf366b3a42a455f4d78daaf27
2026-09-25 03:12:10 +00:00
Henry Levy 0f0efab8d3 Reuse MCP handlers across equivalent bindings (#47988)
## Why

Refreshing the MCP catalog with unchanged tool metadata recreated handlers and forced the tool search index to rebuild.

## What changed

Cache handlers by canonical tool name and reuse them when tool metadata, agent plugin status, and the input schema size limit are unchanged. Replace handlers when those inputs change and evict tools removed from the catalog, preserving search index reuse across equivalent bindings.

## Testing

Extend the deferred tool world state test to verify that an unchanged catalog refresh captures a new binding without rebuilding the search index, and that removing all deferred tools stops advertising `tool_search`.

GitOrigin-RevId: 150866f635e9ee817d7ca44fb76e724a3f7608a5
2026-09-25 02:54:07 +00:00
Owen Lin 9ef08dcf2b Add multi-agent spawn latency and failure metrics (#47984)
## What changed

- Record successful spawn phase durations in `codex.multi_agent.spawn.phase.duration_ms`, covering residency reservation and fork context when applicable, child creation, durability waits, input admission, and total latency.
- Count spawn failures from the V1 and V2 tool handlers in `codex.multi_agent.spawn.failure`, grouped by bounded error categories.
- Use bounded labels for fork mode, multi-agent version, product SKU, and successful-spawn history mode. Emit phase timings only after a successful spawn.

## Testing

Add in-memory metrics tests for phase durations and labels, plus a tool-handler test verifying that a thread-limit failure emits one counter increment with the expected labels.

GitOrigin-RevId: 04cba9042b9b34acdf57376ace5288c3f741f3b2
2026-09-25 02:40:55 +00:00
Henry Levy 75e0e0aad9 Prepare MCP calls directly from advertised tool identities (#47981)
## What changed

Prepare each MCP call from the selected server's current client and catalog instead of building a full runtime binding. Match the advertised tool by server, tool name, and connector ID, and enforce current tool filters and model visibility.

Preserve the advertised `callable_namespace` and `callable_name` while using current schema, annotations, approval metadata, timeout, and permission authority for execution.

GitOrigin-RevId: 703a90926fc72bd446d83ac974162aee6439f363
2026-09-25 01:52:30 +00:00
Eric Traut b725da3b6d Add Pro Max plan support and update Pro display names (#47971)
## What changed

- Recognize `promax` in authentication, account responses, and backend rate limits; update generated schemas and client types.
- Display `prolite` as “Pro”, `pro` as “Pro (More)”, and `promax` as “Pro (Max)” in account labels, status, and analytics.
- Include Pro Max in experimental context eligibility, paid-plan tooltips, and usage-limit guidance for purchasing credits.

## Testing

Extend coverage for Pro Max plan parsing, account and rate-limit responses, experimental context eligibility, and plan display names. Update the login token test to expect “Pro (More)”.

GitOrigin-RevId: 197e00fa7a99cbce125c8f1d43a451ec1ed5c1fb
2026-09-25 00:20:02 +00:00
sayan-oai 97da50c1aa Expose current environment selections for a running turn (#47970)
## Why

`active_turn_environment_selections()` returns the selections captured at turn start, so it does not reflect later environment settings updates.

## What changed

Add `CodexThread::current_turn_environment_selections(expected_turn_id)` to read the running turn's current selections, including environments that are still starting or have failed. Return `None` when the requested turn is no longer active or has been cancelled.

## Testing

Add a regression test covering selection updates, mismatched turn IDs, and completed turns, while verifying that the initial selection snapshot remains unchanged.

GitOrigin-RevId: bb526a686d549209142150ffde99ad1444add205
2026-09-25 00:07:35 +00:00
Steve Coffey dafb133c5b Surface Flex capacity failures as a distinct terminal error (#47967)
## What changed

- Recognize `flex_unavailable` in HTTP 429 responses and streamed `error` and `response.failed` events. End normal turns without retries and report `Flex capacity unavailable.`
- Expose `flexUnavailable` through the core and app-server protocols and generated schemas and SDK types.
- Keep Flex capacity failures eligible for Guardian review and sampler retries, with a distinct telemetry classification.
- Map unexpected HTTP responses to `HttpConnectionFailed`, preserving their status codes.

## Testing

Add regression coverage for terminal Flex failures over HTTP, SSE, and WebSocket, HTTP 504 status preservation after a stream retry, and protocol serialization. Update Guardian retry and sampler recovery tests to cover Flex failures.

GitOrigin-RevId: f2e03a6d2d36a6d9748c35952e40397f8670d121
2026-09-24 23:33:38 +00:00
ningyi-oai dbb875d23c Bound tool-call observations to the outgoing Responses message budget (#47957)
## Why

Removing tool-result metadata alone can leave requests above the 15 MiB message budget when recorded tool calls and arguments occupy the remaining space. If trimming loses calls or arguments from a Code Mode cell, later waits must not report its call inventory as complete.

## What changed

- Bound all optional tool-call observations against the serialized HTTP or WebSocket message size, preserving ordinary tool outputs and continuation history.
- Shed generic result metadata, sources, and recorded arguments before resource-access evidence, retaining tool names and smaller metadata where possible.
- Invalidate completeness across affected cell outputs and later waits when the outgoing copy loses calls or arguments.
- Preserve size-limit omission markers for direct tool-result metadata when they fit, while continuing to exclude that metadata from custom providers.

## Testing

Add regression coverage for HTTP and WebSocket message budgets, unchanged tool results and history, resource-evidence retention, direct-call omission markers, and Code Mode waits after argument truncation.

GitOrigin-RevId: 538dc9d8c11b0830ec70327422f98a1803122e85
2026-09-24 22:54:29 +00:00
felixxia-oai cf792c3a25 Expand root authorization context to 16 messages (#47947)
## What changed

Increase `MAX_ROOT_MESSAGES` from 8 to 16 so Guardian subagent authorization reviews can include more root conversation context.

## Testing

Update authorization integration tests to exercise the larger message limit, preserve late user authorization and question context, and expect incomplete root instructions when retained user messages exceed the cap.

GitOrigin-RevId: facc55f424a4d7e29626f4161ecfe031021b30c2
2026-09-24 22:04:12 +00:00
jif dda227891d Add an in-memory agent message board for ephemeral sessions (#47946)
## Why

Ephemeral sessions cannot use the SQLite-backed agent message board. An in-memory backend lets agents share discussions without creating durable board storage.

## What changed

- Add the opt-in `message_board_in_memory` setting to the multi-agent v2 configuration, allowing the board to run in ephemeral sessions when both required features are enabled.
- Share board state across agents in the same tree and release it when the last handle is dropped.
- Implement channels, posts, subscriptions, notifications, search, and paginated reads through the existing `AgentMessageBoard` interface, including request deduplication.

## Testing

Add coverage for shared handles, concurrent request deduplication, tree isolation, and state release. Run existing query and tool test cases against both backends, and extend the parent/child scenario to verify ephemeral board sharing without creating a board database.

GitOrigin-RevId: d0b2083f8ea5b1c5a3a70f258ef738b87ea74cef
2026-09-24 21:55:06 +00:00
iceweasel-oai 549455f3ec Remove unused Windows world-writable audit code (#47943)
## What changed

Remove the Windows sandbox audit module and its exported scan-and-deny helper, including the associated tests. Remove the config edit variant and builder method for acknowledging `hide_world_writable_warning`.

GitOrigin-RevId: c9cfc9b276d46c45d5788fe8d29b2bc4e422001c
2026-09-24 21:38:09 +00:00
sayan-oai e8098eb406 Separate selected plugin identities from MCP contributions (#47939)
## Why

Plugin identity and skill ownership need to be available independently of MCP data, including for plugins without servers or connectors. Hosted plugins have no executor root and should not own executor skills.

## What changed

- Add `McpServerContributor::selected_plugins` to declare executor plugin identities with deferred MCP data. Let the host assign server attribution and precedence across contributors.
- Represent hosted connectors with `HostedPluginConnectors` and make `SelectedPluginIdentity::selected_root_id` optional instead of assigning synthetic roots to hosted plugins.
- Resolve executor contributions before reading hosted connectors, and clear stale hosted state on account changes before executor loading can wait.
- Preserve connector declarations from disabled plugins so Apps can hide those connectors.

## Testing

Add coverage for account changes while executor loading is pending. Update tests to verify hosted identities have no executor root and disabled plugins hide their connectors even when plugin IDs differ from root IDs.

GitOrigin-RevId: e7f511264c5874c1b56d5f3e4a46820724046db0
2026-09-24 21:03:50 +00:00