33 Commits
Author SHA1 Message Date
iceweasel-oai 2deb542491 Render remote permission paths using executor context (#47867)
## What changed

- Resolve remote sandbox modes, writable roots, and denied read paths/globs using the executor's filesystem context, displaying paths in its native format. Preserve local filesystem resolution for local environments.
- Resolve remote read denials individually so missing executor facts omit only the unresolved entries.
- Apply a shared 32 KiB budget to displayed permission paths/globs, omitting whole entries and warning that all restrictions still apply, including omitted read denials.

## Testing

Add coverage for remote Windows writable roots and read denials, missing executor path facts, and whole-entry omission with multibyte paths under the shared budget.

GitOrigin-RevId: c61e7ddc8fa569dbc25e9990d90357c42315188f
2026-09-24 15:57:42 +00:00
rhan-oai 29f056c26c Honor catalog schemas for asynchronous user input (#47773)
## What changed

Use the model catalog's `send_user_message_async.parameters` override for the `request_user_input_async` tool schema. Fall back to the bundled schema when the override is absent or invalid, logging a warning for invalid overrides while preserving the catalog description.

## Testing

Extend integration coverage for catalog schemas, empty and invalid overrides, and schema updates during mid-turn model changes. Update the asynchronous question-and-answer scenario to verify that requests carry the catalog schema while work continues and the user's answer arrives.

GitOrigin-RevId: c51a90d3266daaba1e7001aa4026964f84dfb206
2026-09-24 07:21:20 +00:00
rhan-oai b2aa42e6f1 Support model catalog overrides for MCP resource tool specs (#47677)
## Why

MCP resource helpers use fixed descriptions and parameter schemas, preventing the model catalog from supplying model-specific guidance.

## What changed

Add `model_messages.tools.mcp_resources` entries for `list_mcp_resources`, `list_mcp_resource_templates`, and `read_mcp_resource`. Resolve these entries for the current model when constructing tool specs for direct calls and Code Mode.

Descriptions and parameter schemas override independently. Preserve bundled defaults for missing fields and fall back to bundled parameters with a warning when a supplied schema is invalid. MCP resource execution remains unchanged.

## Testing

Add unit coverage for independent overrides, literal descriptions, and invalid-schema fallback. Add integration coverage for resource discovery and reading through direct calls and Code Mode, plus assertions that resource tool specs follow model changes between steps.

GitOrigin-RevId: 40b5beddb38b2b61c19dc9cd6013d6ba5d756dbc
2026-09-23 22:09:18 +00:00
eknight-oai f2654ea6c9 Support model-specific descriptions for agent message board tools (#47670)
## Why

Channel tools use bundled descriptions even when the model catalog supplies tool messages. Let their descriptions follow the active model, including model changes within a turn.

## What changed

- Add channel tool entries to `MultiAgentToolMessages` and pass them to the message board extension for each step.
- Apply catalog descriptions while retaining bundled text for missing or null values and honoring empty strings. Ignore parameter overrides with a warning and keep bundled schemas.
- Clarify bundled descriptions for channel discovery, thread reading, posting, and subscription notifications.

## Testing

Add coverage for full and partial overrides in namespaced and Code Mode tools, preserving Code Mode declarations and parameter schemas. Extend the mid-turn model-change test to verify that the `post` description follows the active model.

GitOrigin-RevId: fca20bed1203d5214713f82cb16a91eeebb38f56
2026-09-23 21:34:11 +00:00
johnl-oai e9b4c6967e Apply Guardian computer-use review to the Browser connector (#47647)
## Why

The Browser connector on `codex_apps` needs the computer-use policies and review handling already applied to `node_repl` and `cua_repl`.

## What changed

- Classify `connector_openai_browser` using registered tool metadata and preserve its computer-use scope through Guardian review.
- Extend confirmation-policy forwarding, review evidence capture, JavaScript execution tracking, and initial-call approval handling to the Browser connector.
- Correlate Browser elicitations with live invocations so nested actions retain their own review identity while assessments are attributed to the originating call. Require verified Browser identity for strict nested review.
- Include the Browser connector in computer-use policy prompts and bundled model messages.

## Testing

Add integration coverage for ordinary and strict Browser nested reviews, including policy injection and action attribution. Verify strict review declines requests with missing or unknown invocation correlation or a non-Browser registration.

GitOrigin-RevId: b04af6fb9db1bac2203dc4265913d210746df90b
2026-09-23 20:05:09 +00:00
rhan-oai 8c66a5a243 Add model-specific prefixes to indirect tool descriptions (#47642)
## What changed

Add `model_messages.tools.indirect_description_prefixes` with selectors for exact namespaces and configured MCP server names. Apply the selected model's guidance to namespace documentation embedded in `CodeModeOnly` prompts, `ALL_TOOLS` descriptions, and namespaces returned by tool search.

Trim prefix values, treat empty values as no prefix, and reject conflicting selectors for the same namespace. Apply prefixes during rendering so model changes take effect without altering direct tool specifications, search ranking, or tool dispatch.

## Testing

Add unit tests for prefix normalization, namespace grouping, MCP server mapping, and conflicts. Add scenarios covering both Code Mode variants, clearing prefixes on model changes, unchanged tool dispatch, and conflict rejection before a model request.

GitOrigin-RevId: 0c7ce6d418c775945c2ccfdab3c605fa4d431b55
2026-09-23 19:54:07 +00:00
Won Park 26cb4d73e2 Add extra policy configuration for Guardian reviews (#47125)
## What changed

- Add `auto_review.extra_policy` and the managed `guardian_extra_policy` requirement to supply policy text alongside the resolved tenant policy. Nonblank managed values take precedence; blank values are ignored.
- Render the additional text through `{{ extra_policy }}` in Guardian reviewer templates and append it to the tenant policy for Guardian v2 classification before truncation.
- Preserve placeholder-like text inside supplied policies literally.

## Testing

Add coverage for configuration precedence, blank values, template substitution, and classifier prompts, plus a scenario verifying that managed tenant and extra policies reach the Guardian reviewer together.

GitOrigin-RevId: 180d8d716c63fe96a92ec5bfbd22db4ddccd4f1f
2026-09-21 23:06:36 +00:00
rhan-oai 5aa4939be4 Support model-catalog overrides for Code Mode tool messages (#47118)
## What changed

- Add `tools.code_mode` catalog messages for `exec`, `wait`, deferred-tool guidance, and shared MCP TypeScript definitions.
- Render `{{ default_exec_yield_time_ms }}` and `{{ image_helper }}` in `exec` descriptions while preserving runtime tool declarations and the freeform grammar.
- Resolve `wait` descriptions and parameter schemas independently, falling back to bundled parameters for invalid or unsupported schemas.
- Use the active model's Code Mode messages, including after mid-turn model changes. Missing overrides retain bundled defaults; empty text overrides suppress the corresponding text.

## Testing

Add coverage for literal template substitution, runtime section preservation, independent `wait` overrides and fallback behavior, mid-turn model changes, and a yielded cell completing through `wait` with catalog messages.

GitOrigin-RevId: e542a0cd47a7138a414871192cee47790ed1214e
2026-09-21 22:49:17 +00:00
felixxia-oai 78d4d983d3 Gate reasoning effort updates on explicit model support (#46530)
## Why

Using Responses Lite does not establish whether a model accepts reasoning-effort `configuration_update` items. Unsupported models need to use the selected request-level effort, including when resuming history containing saved updates.

## What changed

- Add `supports_reasoning_effort_updates` model metadata, defaulting to `false`.
- Require the override feature, an OpenAI provider, and explicit model support for reasoning effort updates, independently of `use_responses_lite`.
- Filter saved configuration updates from unsupported requests without changing persisted history.
- Clear the pinned effort baseline when sampling with an unsupported model so returning to a supported model establishes a fresh baseline. Compaction uses the selected effort without clearing the pin.

## Testing

Add coverage for supported models with either Responses mode, unsupported-model history filtering over HTTP and WebSocket, switching to an unsupported model and back, and compaction versus sampling pin behavior. Verify missing capability metadata defaults to `false`.

GitOrigin-RevId: 8a0fbc141964bd854dbcdd6f31e1c8e97697cf22
2026-09-19 00:18:56 +00:00
rhan-oai cc7591646e Support catalog parameter schemas for Multi-Agent V2 tools (#46505)
## What changed

Add optional JSON-encoded `parameters` to catalog tool messages and apply them to all six Multi-Agent V2 tools, including plain, namespaced, and code-mode exposure. Schema selection follows the active model, including mid-turn model changes.

Require an object schema supported by the existing `JsonSchema` subset and preserve bundled encryption annotations. Fall back to bundled parameters when overrides are missing, invalid, unsupported, or omit encrypted properties. Tool execution and argument handling remain unchanged.

## Testing

Extend integration coverage for schema overrides, fallback behavior, encryption annotations, exposure modes, and mid-turn model changes. Add a snapshot scenario exercising `list_agents` with a catalog parameter schema.

GitOrigin-RevId: 978be6d5f7e6a6865969922be5483bc697b20aca
2026-09-18 23:16:56 +00:00
rhan-oai 3e581ebca8 Support catalog descriptions for all multi-agent V2 tools (#46297)
## Why

Model catalog description overrides only covered `spawn_agent`, leaving the other multi-agent V2 tools with fixed descriptions.

## What changed

Extend `model_messages.tools.multi_agent` description overrides to `send_message`, `followup_task`, `wait_agent`, `interrupt_agent`, and `list_agents`. Resolve each override by tool name across namespaced, plain, and Code Mode exposure.

Missing or null descriptions retain bundled text; empty strings suppress static text without disabling tools. Preserve `spawn_agent` runtime guidance, tool schemas, and execution behavior. Descriptions follow mid-turn model changes.

## Testing

Expand integration coverage to all six tools, including missing, null, empty, and sparse overrides; plain, namespaced, and Code Mode exposure; unchanged V1 behavior; and mid-turn model changes.

GitOrigin-RevId: a2c47eb8efb28c3eeebcc6482e36c188c38a6dd1
2026-09-17 20:05:47 +00:00
rhan-oai c5d079470e Allow model catalogs to override the V2 spawn_agent description (#46123)
## What changed

Read the static V2 `spawn_agent` description from `model_messages.tools.multi_agent.spawn_agent.description`, independently of the runtime tool namespace. Missing or null values retain the bundled description; an empty string suppresses it.

Preserve generated model guidance, local usage hints, and tool parameters when applying an override. Resolve the description from the active model so it follows mid-turn model changes.

## Testing

Add coverage for sparse and empty catalog values, preservation of generated context and outbound tool schemas, and description updates after mid-turn model changes.

GitOrigin-RevId: 96cfa180f8f374dc868e4fabc337e49380e405da
2026-09-17 05:17:31 +00:00
rhan-oai a8c36ca6d2 Centralize model-message resolution and rendering in codex-prompts (#46026)
## What changed

- Add `ResolvedModelMessages` to resolve catalog text and bundled defaults while preserving explicit empty overrides and their source.
- Move base-instruction rendering, Guardian prompt composition, multi-agent role rendering, and `update_plan` guidance filtering into `codex-prompts`; migrate consumers to the shared APIs.
- Separate permission-profile resolution from prompt composition, and annotate Guardian policy and classifier instructions with content kinds.

## Testing

Add and update coverage for missing versus empty templates, literal overrides, multi-agent role composition, Guardian policy substitution and truncation, and preservation of permission path spellings and order.

GitOrigin-RevId: 52335bb7acec0f432d5c57acb2accd5f0276056e
2026-09-16 21:01:13 +00:00
Eric Traut 0cdb1f1c83 Harden goal continuation and remove duplicate prompt helpers (#40628)
## What changed

- Teach goal continuations to distinguish concrete progress, verified waits on live handles, and turns that made no progress.
- Re-poll live work after observation timeouts instead of treating the work as terminal or restarting it, and carry equivalent blockers through the existing blocked audit.
- Remove the duplicate goal prompt renderers and templates from `codex-prompts`; goal steering remains owned by the goal extension.

GitOrigin-RevId: 4ec64721164743e879ae946a2dd024bba5869fbe
2026-08-25 15:50:19 +00:00
pakrym-oai 068847f76d Classify permission instructions under the permissions namespace (#40295)
## What changed

- Change the permission prompt content kind from
  `generic.permissions_instructions` to `permissions.instructions`.
- Update request annotation tests to expect the new content kind.

GitOrigin-RevId: e1e39c74ac24668ac1f3467bb0cc1335a9408712
2026-08-23 23:38:12 +00:00
pakrym-oai 422239eb4b Classify contextual fragments with content kinds (#40180)
## What changed

- Require each `ContextualUserFragment` to provide a stable `<feature>.<name>`
  `ContentItemKind`.
- Add `AnnotatedContent` and `RenderedFragment` so rendered text, its role, and
  its classification can travel together to API boundaries.
- Derive extension-owned world-state classifications from the extension ID and
  keep the skills catalog classification with its fragment implementation.

## Testing

- Verify that an extension-owned world-state section renders with an
  `<extension-id>.instructions` content kind.

GitOrigin-RevId: e46b74a0bb41e0b6112667c9d36bc9e7f2714451
2026-08-23 03:44:21 +00:00
jif 942af8447b Retire the untrusted approval policy (#39630)
## What changed

- Remove `untrusted` from the CLI, configuration schema, and MCP tool interface. Explicit `approval_policy = "untrusted"` settings now fail with an actionable error.
- Remove the known-safe command allowlist. Projects marked untrusted now request approval for every command unless an explicit exec policy rule allows it.
- Keep command parsing conservative by treating in-place `sed` forms as mutating and ignoring unrecognized commands when recording memory usage.

## Testing

- Cover rejection of the retired configuration value and approval requests for commands in untrusted projects.

GitOrigin-RevId: d6bf425edddfffbb325eee6acf383434af5fd33b
2026-08-20 07:03:02 +00:00
iceweasel-oai 2013e04354 Preserve filesystem permission path conventions (#39084)
## Why

Filesystem permission paths can use a convention that differs from the host
running Codex. Converting them immediately to native absolute paths can change
the meaning of ambiguous paths such as `/C:/secret` or Windows UNC paths.

## What changed

- Store literal filesystem permission paths as `PathUri` values through the
  runtime policy and execution protocol.
- Keep legacy string-based serialization at explicit protocol boundaries and
  reject conversions that cannot be represented losslessly.
- Encode native paths as opaque URIs when a normal file URI would imply the
  wrong path convention.

## Testing

Added coverage for cross-platform and ambiguous path round trips, UNC path
variants, permission-profile serialization, and deny-policy enforcement.

GitOrigin-RevId: 5247713796d1f2bb4e02f94eb9fc82d4698060f0
2026-08-17 21:49:30 +00:00
rhan-oai 8d637ae398 Remove unused apply_patch prompt fallback (#38291)
## What changed

- Delete the unused standalone `apply_patch` instruction template and its
  `codex-prompts` export.
- Simplify prompt-caching coverage to assert that requests use the model's base
  instructions.

GitOrigin-RevId: 8c0dc9426d9ac0184d587272622db608a75e8436
2026-08-13 01:52:02 +00:00
rhan-oai 06782eded7 Fix network access rendering in sandbox prompts (#34811)
## What changed

Use the supported `{{ network_access }}` placeholder syntax in the built-in
`danger-full-access`, `read-only`, and `workspace-write` sandbox templates so
permission instructions render the active network access state.

GitOrigin-RevId: 9f8d851016bd7fbedcfc4a9479236b46aca470e8
2026-07-22 19:14:11 +00:00
harinsrikanth-openai 81de4f251c Attribute review findings to repository rules (#34637)
## What changed

- Apply root and scoped project instructions using the established precedence for `AGENTS.override.md`, `AGENTS.md`, and configured fallback files.
- Treat findings as rule-supported only when repository guidance adds material, repository-specific context beyond generic correctness advice.
- Deduplicate findings without losing their supporting rules, and cite the applicable instruction file and smallest relevant line range in each rule-supported finding.
- Continue reporting ordinary findings independently of whether repository rules apply.

GitOrigin-RevId: 64b26555d92c0baa7e8e005130a7fb032b91d170
2026-07-21 23:17:20 +00:00
iceweasel-oai 87f71e35b8 Skip missing paths in filesystem sandbox entries (#34598)
## Why

Default read-only protections for project metadata should apply when paths such
as `.git`, `.agents`, and `.codex` exist, without causing sandbox setup to
materialize missing paths as ACL targets.

## What changed

- Add an optional `missing_path_behavior` to filesystem sandbox entries and
  mark default project-metadata protections with `skip`.
- Preserve the behavior through permission transforms and exec/MCP protocol
  serialization while keeping existing path wire variants stable.
- Ignore skip-missing entries when projecting configuration or Windows sandbox
  overrides, while retaining explicit metadata carveouts.

## Testing

- Cover protocol round trips for path and special-path entries.
- Verify default metadata protections and Windows explicit carveout handling.

GitOrigin-RevId: 6df13dadacdd131c44aab9f15a967c81051355c1
2026-07-21 19:17:18 +00:00
rhan-oai 2be7d3bcd9 Support catalog messages for non-request approval policies (#34434)
## What changed

- Add model-catalog approval message variants for `never` and `unless_trusted`.
- Select the catalog message that matches the active approval policy, while retaining the existing built-in text when that variant is absent.
- Treat an explicitly empty variant as an instruction to suppress the built-in approval text, consistent with `on_request` messages.

## Testing

- Cover variant selection, fallback and empty-message behavior, catalog deserialization, and the initial permissions message sent to the model.

GitOrigin-RevId: a0f8d41a08645f39b80093be53f200eeee18ca25
2026-07-21 00:22:31 +00:00
rhan-oai eb80df0317 Support model catalog permission messages (#33147)
## What changed

- Add per-sandbox-mode permission messages to `ModelMessages` and preserve them when applying model configuration overrides.
- Use the selected catalog message in permission instructions, substituting `{{ network_access }}` with the active network policy. Fall back to the existing sandbox text when no override is provided, and allow an empty override to omit only the sandbox section.
- Apply catalog permission messages when a session starts and when its model changes.

## Testing

- Cover catalog deserialization, mode selection, network substitution, fallback and empty-message behavior, remote model catalogs, and model changes.

GitOrigin-RevId: cd5ed3aee3155dca0e7b2358c0f09bae73236856
2026-07-14 20:14:29 +00:00
Dylan Hurd 358575465c Use model catalog approval messages (#31312)
## Why

Approval guidance is currently assembled entirely by the client. Model
Messages V2 needs model catalogs to provide model-specific `on_request`
guidance for both user-reviewed and auto-reviewed approval flows while
retaining the existing generated prompt as a compatibility fallback.

## What changed

- add nullable `on_request` and `on_request_auto_review` catalog
messages
- select the message matching the active approvals reviewer for
`on_request` policies
- replace the complete legacy approval section when the selected catalog
value exists, including support for an empty string that suppresses the
section
- retain legacy rendering when the object or selected key is absent, and
for non-`on_request` policies
- preserve approval messages when base-instruction or personality
overrides clear instruction templates
- refresh permissions instructions when the active model changes
- pass catalog messages through initial and incremental permissions
construction

## Relationship to reviewer persistence

PR #31309 independently persists the approvals reviewer in turn context
and refreshes permissions when that reviewer changes. This PR is based
directly on `main` and does not duplicate that rollout migration; once
both land, reviewer switches will also select and append the new catalog
variant.

## Testing

- `just test -p codex-protocol`
- `just test -p codex-prompts`
- `just test -p codex-models-manager`
- `just test -p codex-core permissions_messages`
2026-07-07 10:52:38 -07:00
Dylan Hurd ccdfb4f342 Revert "Make auto-review on-request prompt more proactive" (#30508)
Reverts openai/codex#26496
2026-06-28 20:40:55 -07:00
Dylan Hurd 2cf2a6a844 chore(core) rm AskForApproval::OnFailure (#28418)
## Summary
Deletes the OnFailure variant of the `AskForApproval` enum. This option
has been deprecated since #11631.

## Testing
- [x] Tests pass
2026-06-23 12:13:54 -07:00
pakrym-oai bb72e151e5 [codex] Remove child AGENTS.md prompt experiment (#28993)
## Why

`child_agents_md` is a disabled, under-development experiment that adds
a second model-visible explanation of hierarchical `AGENTS.md` behavior.
Keeping it leaves unused prompt, configuration, documentation, and test
surface.

## What changed

- remove the `ChildAgentsMd` feature and `child_agents_md` config schema
entry
- remove the hierarchical prompt asset, export, and instruction
injection
- remove feature-specific tests and documentation
- keep the generic unstable-feature warning coverage using
`apply_patch_streaming_events`

Normal project `AGENTS.md` discovery and composition are unchanged.

## Testing

- `just test -p codex-features`
- `just test -p codex-prompts`
- `just test -p codex-core agents_md`
- `just test -p codex-core unstable_features_warning`
2026-06-18 16:13:07 -07:00
maja-openai d9dace8a59 Make auto-review on-request prompt more proactive (#26496)
## Why

`on-request` approval policy text is currently tuned for user-reviewed
approvals. For auto-reviewed productivity runs, likely sandbox blocks
should be escalated earlier so commands that need remote services,
authentication, or other out-of-sandbox access do not first fail or hang
inside the sandbox.

## What changed

- Adds a separate `on_request_auto_review.md` permissions prompt
selected for `AskForApproval::OnRequest` with
`ApprovalsReviewer::AutoReview`.
- Keeps the normal user-reviewed `on-request` wording unchanged.
- Makes the `When to request escalation` bullets more explicit about
likely sandbox blocks, network access, remote
auth/cluster/cloud/database access, out-of-sandbox environment access,
git operations that may write lock files, and short-timeout reruns after
likely sandbox-blocked attempts.
- Omits approved command prefix and `prefix_rule` guidance for the
auto-review on-request prompt.
- Adds prompt tests covering the auto-review path, normal on-request
wording, and inline permission request behavior.
2026-06-18 13:16:14 -07:00
Adam Perry @ OpenAI 740c4f269d build: run buildifier from just fmt (#28125)
## Intent

Keep Bazel and Starlark files consistently formatted without requiring
contributors to install or version buildifier themselves.

## Implementation

- Add a SHA-256-pinned, cross-platform DotSlash manifest for buildifier
v8.5.1.
- Run buildifier from the shared `just fmt` and `just fmt-check` driver,
with Windows-safe explicit DotSlash invocation.
- Provision DotSlash in formatting CI and contributor devcontainers, and
document the source-build prerequisite.
- Apply the initial mechanical buildifier formatting baseline.
2026-06-13 21:43:39 -07:00
jif 3389fa554e skills: resolve per-turn catalogs from turn input context (#26106)
## Why

The skills extension needs the resolved turn environments to build a
real per-turn `SkillListQuery`. The previous `TurnLifecycleContributor`
hook only had a turn id, so it could only seed a placeholder query and
never carry the executor authorities that executor-scoped skill routing
will need.

Moving catalog resolution onto `TurnInputContributor` puts the skills
extension on the same turn-preparation path that already has the
environment ids and working directories for the submitted turn, while
keeping the actual prompt injection work for follow-up changes.

## What changed

- switch `ext/skills` from `TurnLifecycleContributor` to
`TurnInputContributor`
- build `executor_authorities` from `TurnInputContext.environments` and
pass them through `SkillListQuery`
- keep storing the resolved catalog in `SkillsTurnState`, but drop the
placeholder query helper that no longer matches the real data flow
- update the extension TODOs to reflect that per-turn catalog resolution
now happens in the turn-input contributor, and that prompt/context
injection still needs to move later

## Testing

- Not run locally.
2026-06-03 13:32:55 +02:00
jif ac67905fc4 chore: extract context fragments into dedicated crate (#26122)
## Why

`codex-core` currently owns the generic contextual-fragment trait and
several reusable fragment implementations. That makes it harder for
other crates to share the same host-owned model-input abstraction
without depending on all of `codex-core`.

This change extracts the reusable fragment machinery into a small
`codex-context-fragments` crate so future extension and skills work can
depend on the fragment abstraction directly.

## What Changed

- Added the `codex-context-fragments` crate with:
  - `ContextualUserFragment`
  - `FragmentRegistration` / `FragmentRegistrationProxy`
  - additional-context fragment types
- Moved `SkillInstructions` into `codex-core-skills`, since
skill-specific rendering belongs with skills rather than generic core
context machinery.
- Kept `codex-core` re-exporting the fragment types it still uses
internally, so existing call sites keep the same shape.
- Updated Cargo and Bazel workspace metadata for the new crate.

## Verification

- `cargo metadata --locked --format-version 1 --no-deps`
- `just bazel-lock-update`
- `just bazel-lock-check`
2026-06-03 12:25:21 +02:00
Adam Perry @ OpenAI ba2b67f9cd [codex] Consolidate shared prompts in codex-prompts (#25151)
## Why

`codex_core` is consistently a bottleneck for incremental builds during
iteration. The simplest fix is to make the crate smaller.

## Summary

`codex-core` owns several reusable prompt renderers and static prompt
assets, which makes the crate harder to split apart.

Rename `codex-review-prompts` to `codex-prompts` and move shared review,
goal, permissions, compaction, realtime, hierarchical AGENTS.md, and
`apply_patch` prompts into it. Move prompt-only tests and update
consumers and `CODEOWNERS`.

## Validation

- `just test -p codex-prompts -p codex-apply-patch`
- `just test -p codex-core prompt_caching`
- Bazel builds for the affected crates
2026-06-01 18:45:07 +00:00