## What changed
- Resolve remote sandbox modes, writable roots, and denied read paths/globs using the executor's filesystem context, displaying paths in its native format. Preserve local filesystem resolution for local environments.
- Resolve remote read denials individually so missing executor facts omit only the unresolved entries.
- Apply a shared 32 KiB budget to displayed permission paths/globs, omitting whole entries and warning that all restrictions still apply, including omitted read denials.
## Testing
Add coverage for remote Windows writable roots and read denials, missing executor path facts, and whole-entry omission with multibyte paths under the shared budget.
GitOrigin-RevId: c61e7ddc8fa569dbc25e9990d90357c42315188f
## What changed
Use the model catalog's `send_user_message_async.parameters` override for the `request_user_input_async` tool schema. Fall back to the bundled schema when the override is absent or invalid, logging a warning for invalid overrides while preserving the catalog description.
## Testing
Extend integration coverage for catalog schemas, empty and invalid overrides, and schema updates during mid-turn model changes. Update the asynchronous question-and-answer scenario to verify that requests carry the catalog schema while work continues and the user's answer arrives.
GitOrigin-RevId: c51a90d3266daaba1e7001aa4026964f84dfb206
## Why
MCP resource helpers use fixed descriptions and parameter schemas, preventing the model catalog from supplying model-specific guidance.
## What changed
Add `model_messages.tools.mcp_resources` entries for `list_mcp_resources`, `list_mcp_resource_templates`, and `read_mcp_resource`. Resolve these entries for the current model when constructing tool specs for direct calls and Code Mode.
Descriptions and parameter schemas override independently. Preserve bundled defaults for missing fields and fall back to bundled parameters with a warning when a supplied schema is invalid. MCP resource execution remains unchanged.
## Testing
Add unit coverage for independent overrides, literal descriptions, and invalid-schema fallback. Add integration coverage for resource discovery and reading through direct calls and Code Mode, plus assertions that resource tool specs follow model changes between steps.
GitOrigin-RevId: 40b5beddb38b2b61c19dc9cd6013d6ba5d756dbc
## Why
Channel tools use bundled descriptions even when the model catalog supplies tool messages. Let their descriptions follow the active model, including model changes within a turn.
## What changed
- Add channel tool entries to `MultiAgentToolMessages` and pass them to the message board extension for each step.
- Apply catalog descriptions while retaining bundled text for missing or null values and honoring empty strings. Ignore parameter overrides with a warning and keep bundled schemas.
- Clarify bundled descriptions for channel discovery, thread reading, posting, and subscription notifications.
## Testing
Add coverage for full and partial overrides in namespaced and Code Mode tools, preserving Code Mode declarations and parameter schemas. Extend the mid-turn model-change test to verify that the `post` description follows the active model.
GitOrigin-RevId: fca20bed1203d5214713f82cb16a91eeebb38f56
## Why
The Browser connector on `codex_apps` needs the computer-use policies and review handling already applied to `node_repl` and `cua_repl`.
## What changed
- Classify `connector_openai_browser` using registered tool metadata and preserve its computer-use scope through Guardian review.
- Extend confirmation-policy forwarding, review evidence capture, JavaScript execution tracking, and initial-call approval handling to the Browser connector.
- Correlate Browser elicitations with live invocations so nested actions retain their own review identity while assessments are attributed to the originating call. Require verified Browser identity for strict nested review.
- Include the Browser connector in computer-use policy prompts and bundled model messages.
## Testing
Add integration coverage for ordinary and strict Browser nested reviews, including policy injection and action attribution. Verify strict review declines requests with missing or unknown invocation correlation or a non-Browser registration.
GitOrigin-RevId: b04af6fb9db1bac2203dc4265913d210746df90b
## What changed
Add `model_messages.tools.indirect_description_prefixes` with selectors for exact namespaces and configured MCP server names. Apply the selected model's guidance to namespace documentation embedded in `CodeModeOnly` prompts, `ALL_TOOLS` descriptions, and namespaces returned by tool search.
Trim prefix values, treat empty values as no prefix, and reject conflicting selectors for the same namespace. Apply prefixes during rendering so model changes take effect without altering direct tool specifications, search ranking, or tool dispatch.
## Testing
Add unit tests for prefix normalization, namespace grouping, MCP server mapping, and conflicts. Add scenarios covering both Code Mode variants, clearing prefixes on model changes, unchanged tool dispatch, and conflict rejection before a model request.
GitOrigin-RevId: 0c7ce6d418c775945c2ccfdab3c605fa4d431b55
## What changed
- Add `auto_review.extra_policy` and the managed `guardian_extra_policy` requirement to supply policy text alongside the resolved tenant policy. Nonblank managed values take precedence; blank values are ignored.
- Render the additional text through `{{ extra_policy }}` in Guardian reviewer templates and append it to the tenant policy for Guardian v2 classification before truncation.
- Preserve placeholder-like text inside supplied policies literally.
## Testing
Add coverage for configuration precedence, blank values, template substitution, and classifier prompts, plus a scenario verifying that managed tenant and extra policies reach the Guardian reviewer together.
GitOrigin-RevId: 180d8d716c63fe96a92ec5bfbd22db4ddccd4f1f
## What changed
- Add `tools.code_mode` catalog messages for `exec`, `wait`, deferred-tool guidance, and shared MCP TypeScript definitions.
- Render `{{ default_exec_yield_time_ms }}` and `{{ image_helper }}` in `exec` descriptions while preserving runtime tool declarations and the freeform grammar.
- Resolve `wait` descriptions and parameter schemas independently, falling back to bundled parameters for invalid or unsupported schemas.
- Use the active model's Code Mode messages, including after mid-turn model changes. Missing overrides retain bundled defaults; empty text overrides suppress the corresponding text.
## Testing
Add coverage for literal template substitution, runtime section preservation, independent `wait` overrides and fallback behavior, mid-turn model changes, and a yielded cell completing through `wait` with catalog messages.
GitOrigin-RevId: e542a0cd47a7138a414871192cee47790ed1214e
## Why
Using Responses Lite does not establish whether a model accepts reasoning-effort `configuration_update` items. Unsupported models need to use the selected request-level effort, including when resuming history containing saved updates.
## What changed
- Add `supports_reasoning_effort_updates` model metadata, defaulting to `false`.
- Require the override feature, an OpenAI provider, and explicit model support for reasoning effort updates, independently of `use_responses_lite`.
- Filter saved configuration updates from unsupported requests without changing persisted history.
- Clear the pinned effort baseline when sampling with an unsupported model so returning to a supported model establishes a fresh baseline. Compaction uses the selected effort without clearing the pin.
## Testing
Add coverage for supported models with either Responses mode, unsupported-model history filtering over HTTP and WebSocket, switching to an unsupported model and back, and compaction versus sampling pin behavior. Verify missing capability metadata defaults to `false`.
GitOrigin-RevId: 8a0fbc141964bd854dbcdd6f31e1c8e97697cf22
## What changed
Add optional JSON-encoded `parameters` to catalog tool messages and apply them to all six Multi-Agent V2 tools, including plain, namespaced, and code-mode exposure. Schema selection follows the active model, including mid-turn model changes.
Require an object schema supported by the existing `JsonSchema` subset and preserve bundled encryption annotations. Fall back to bundled parameters when overrides are missing, invalid, unsupported, or omit encrypted properties. Tool execution and argument handling remain unchanged.
## Testing
Extend integration coverage for schema overrides, fallback behavior, encryption annotations, exposure modes, and mid-turn model changes. Add a snapshot scenario exercising `list_agents` with a catalog parameter schema.
GitOrigin-RevId: 978be6d5f7e6a6865969922be5483bc697b20aca
## Why
Model catalog description overrides only covered `spawn_agent`, leaving the other multi-agent V2 tools with fixed descriptions.
## What changed
Extend `model_messages.tools.multi_agent` description overrides to `send_message`, `followup_task`, `wait_agent`, `interrupt_agent`, and `list_agents`. Resolve each override by tool name across namespaced, plain, and Code Mode exposure.
Missing or null descriptions retain bundled text; empty strings suppress static text without disabling tools. Preserve `spawn_agent` runtime guidance, tool schemas, and execution behavior. Descriptions follow mid-turn model changes.
## Testing
Expand integration coverage to all six tools, including missing, null, empty, and sparse overrides; plain, namespaced, and Code Mode exposure; unchanged V1 behavior; and mid-turn model changes.
GitOrigin-RevId: a2c47eb8efb28c3eeebcc6482e36c188c38a6dd1
## What changed
Read the static V2 `spawn_agent` description from `model_messages.tools.multi_agent.spawn_agent.description`, independently of the runtime tool namespace. Missing or null values retain the bundled description; an empty string suppresses it.
Preserve generated model guidance, local usage hints, and tool parameters when applying an override. Resolve the description from the active model so it follows mid-turn model changes.
## Testing
Add coverage for sparse and empty catalog values, preservation of generated context and outbound tool schemas, and description updates after mid-turn model changes.
GitOrigin-RevId: 96cfa180f8f374dc868e4fabc337e49380e405da
## What changed
- Add `ResolvedModelMessages` to resolve catalog text and bundled defaults while preserving explicit empty overrides and their source.
- Move base-instruction rendering, Guardian prompt composition, multi-agent role rendering, and `update_plan` guidance filtering into `codex-prompts`; migrate consumers to the shared APIs.
- Separate permission-profile resolution from prompt composition, and annotate Guardian policy and classifier instructions with content kinds.
## Testing
Add and update coverage for missing versus empty templates, literal overrides, multi-agent role composition, Guardian policy substitution and truncation, and preservation of permission path spellings and order.
GitOrigin-RevId: 52335bb7acec0f432d5c57acb2accd5f0276056e
## What changed
- Teach goal continuations to distinguish concrete progress, verified waits on live handles, and turns that made no progress.
- Re-poll live work after observation timeouts instead of treating the work as terminal or restarting it, and carry equivalent blockers through the existing blocked audit.
- Remove the duplicate goal prompt renderers and templates from `codex-prompts`; goal steering remains owned by the goal extension.
GitOrigin-RevId: 4ec64721164743e879ae946a2dd024bba5869fbe
## What changed
- Change the permission prompt content kind from
`generic.permissions_instructions` to `permissions.instructions`.
- Update request annotation tests to expect the new content kind.
GitOrigin-RevId: e1e39c74ac24668ac1f3467bb0cc1335a9408712
## What changed
- Require each `ContextualUserFragment` to provide a stable `<feature>.<name>`
`ContentItemKind`.
- Add `AnnotatedContent` and `RenderedFragment` so rendered text, its role, and
its classification can travel together to API boundaries.
- Derive extension-owned world-state classifications from the extension ID and
keep the skills catalog classification with its fragment implementation.
## Testing
- Verify that an extension-owned world-state section renders with an
`<extension-id>.instructions` content kind.
GitOrigin-RevId: e46b74a0bb41e0b6112667c9d36bc9e7f2714451
## What changed
- Remove `untrusted` from the CLI, configuration schema, and MCP tool interface. Explicit `approval_policy = "untrusted"` settings now fail with an actionable error.
- Remove the known-safe command allowlist. Projects marked untrusted now request approval for every command unless an explicit exec policy rule allows it.
- Keep command parsing conservative by treating in-place `sed` forms as mutating and ignoring unrecognized commands when recording memory usage.
## Testing
- Cover rejection of the retired configuration value and approval requests for commands in untrusted projects.
GitOrigin-RevId: d6bf425edddfffbb325eee6acf383434af5fd33b
## Why
Filesystem permission paths can use a convention that differs from the host
running Codex. Converting them immediately to native absolute paths can change
the meaning of ambiguous paths such as `/C:/secret` or Windows UNC paths.
## What changed
- Store literal filesystem permission paths as `PathUri` values through the
runtime policy and execution protocol.
- Keep legacy string-based serialization at explicit protocol boundaries and
reject conversions that cannot be represented losslessly.
- Encode native paths as opaque URIs when a normal file URI would imply the
wrong path convention.
## Testing
Added coverage for cross-platform and ambiguous path round trips, UNC path
variants, permission-profile serialization, and deny-policy enforcement.
GitOrigin-RevId: 5247713796d1f2bb4e02f94eb9fc82d4698060f0
## What changed
- Delete the unused standalone `apply_patch` instruction template and its
`codex-prompts` export.
- Simplify prompt-caching coverage to assert that requests use the model's base
instructions.
GitOrigin-RevId: 8c0dc9426d9ac0184d587272622db608a75e8436
## What changed
Use the supported `{{ network_access }}` placeholder syntax in the built-in
`danger-full-access`, `read-only`, and `workspace-write` sandbox templates so
permission instructions render the active network access state.
GitOrigin-RevId: 9f8d851016bd7fbedcfc4a9479236b46aca470e8
## What changed
- Apply root and scoped project instructions using the established precedence for `AGENTS.override.md`, `AGENTS.md`, and configured fallback files.
- Treat findings as rule-supported only when repository guidance adds material, repository-specific context beyond generic correctness advice.
- Deduplicate findings without losing their supporting rules, and cite the applicable instruction file and smallest relevant line range in each rule-supported finding.
- Continue reporting ordinary findings independently of whether repository rules apply.
GitOrigin-RevId: 64b26555d92c0baa7e8e005130a7fb032b91d170
## Why
Default read-only protections for project metadata should apply when paths such
as `.git`, `.agents`, and `.codex` exist, without causing sandbox setup to
materialize missing paths as ACL targets.
## What changed
- Add an optional `missing_path_behavior` to filesystem sandbox entries and
mark default project-metadata protections with `skip`.
- Preserve the behavior through permission transforms and exec/MCP protocol
serialization while keeping existing path wire variants stable.
- Ignore skip-missing entries when projecting configuration or Windows sandbox
overrides, while retaining explicit metadata carveouts.
## Testing
- Cover protocol round trips for path and special-path entries.
- Verify default metadata protections and Windows explicit carveout handling.
GitOrigin-RevId: 6df13dadacdd131c44aab9f15a967c81051355c1
## What changed
- Add model-catalog approval message variants for `never` and `unless_trusted`.
- Select the catalog message that matches the active approval policy, while retaining the existing built-in text when that variant is absent.
- Treat an explicitly empty variant as an instruction to suppress the built-in approval text, consistent with `on_request` messages.
## Testing
- Cover variant selection, fallback and empty-message behavior, catalog deserialization, and the initial permissions message sent to the model.
GitOrigin-RevId: a0f8d41a08645f39b80093be53f200eeee18ca25
## What changed
- Add per-sandbox-mode permission messages to `ModelMessages` and preserve them when applying model configuration overrides.
- Use the selected catalog message in permission instructions, substituting `{{ network_access }}` with the active network policy. Fall back to the existing sandbox text when no override is provided, and allow an empty override to omit only the sandbox section.
- Apply catalog permission messages when a session starts and when its model changes.
## Testing
- Cover catalog deserialization, mode selection, network substitution, fallback and empty-message behavior, remote model catalogs, and model changes.
GitOrigin-RevId: cd5ed3aee3155dca0e7b2358c0f09bae73236856
## Why
Approval guidance is currently assembled entirely by the client. Model
Messages V2 needs model catalogs to provide model-specific `on_request`
guidance for both user-reviewed and auto-reviewed approval flows while
retaining the existing generated prompt as a compatibility fallback.
## What changed
- add nullable `on_request` and `on_request_auto_review` catalog
messages
- select the message matching the active approvals reviewer for
`on_request` policies
- replace the complete legacy approval section when the selected catalog
value exists, including support for an empty string that suppresses the
section
- retain legacy rendering when the object or selected key is absent, and
for non-`on_request` policies
- preserve approval messages when base-instruction or personality
overrides clear instruction templates
- refresh permissions instructions when the active model changes
- pass catalog messages through initial and incremental permissions
construction
## Relationship to reviewer persistence
PR #31309 independently persists the approvals reviewer in turn context
and refreshes permissions when that reviewer changes. This PR is based
directly on `main` and does not duplicate that rollout migration; once
both land, reviewer switches will also select and append the new catalog
variant.
## Testing
- `just test -p codex-protocol`
- `just test -p codex-prompts`
- `just test -p codex-models-manager`
- `just test -p codex-core permissions_messages`
## Why
`child_agents_md` is a disabled, under-development experiment that adds
a second model-visible explanation of hierarchical `AGENTS.md` behavior.
Keeping it leaves unused prompt, configuration, documentation, and test
surface.
## What changed
- remove the `ChildAgentsMd` feature and `child_agents_md` config schema
entry
- remove the hierarchical prompt asset, export, and instruction
injection
- remove feature-specific tests and documentation
- keep the generic unstable-feature warning coverage using
`apply_patch_streaming_events`
Normal project `AGENTS.md` discovery and composition are unchanged.
## Testing
- `just test -p codex-features`
- `just test -p codex-prompts`
- `just test -p codex-core agents_md`
- `just test -p codex-core unstable_features_warning`
## Why
`on-request` approval policy text is currently tuned for user-reviewed
approvals. For auto-reviewed productivity runs, likely sandbox blocks
should be escalated earlier so commands that need remote services,
authentication, or other out-of-sandbox access do not first fail or hang
inside the sandbox.
## What changed
- Adds a separate `on_request_auto_review.md` permissions prompt
selected for `AskForApproval::OnRequest` with
`ApprovalsReviewer::AutoReview`.
- Keeps the normal user-reviewed `on-request` wording unchanged.
- Makes the `When to request escalation` bullets more explicit about
likely sandbox blocks, network access, remote
auth/cluster/cloud/database access, out-of-sandbox environment access,
git operations that may write lock files, and short-timeout reruns after
likely sandbox-blocked attempts.
- Omits approved command prefix and `prefix_rule` guidance for the
auto-review on-request prompt.
- Adds prompt tests covering the auto-review path, normal on-request
wording, and inline permission request behavior.
## Intent
Keep Bazel and Starlark files consistently formatted without requiring
contributors to install or version buildifier themselves.
## Implementation
- Add a SHA-256-pinned, cross-platform DotSlash manifest for buildifier
v8.5.1.
- Run buildifier from the shared `just fmt` and `just fmt-check` driver,
with Windows-safe explicit DotSlash invocation.
- Provision DotSlash in formatting CI and contributor devcontainers, and
document the source-build prerequisite.
- Apply the initial mechanical buildifier formatting baseline.
## Why
The skills extension needs the resolved turn environments to build a
real per-turn `SkillListQuery`. The previous `TurnLifecycleContributor`
hook only had a turn id, so it could only seed a placeholder query and
never carry the executor authorities that executor-scoped skill routing
will need.
Moving catalog resolution onto `TurnInputContributor` puts the skills
extension on the same turn-preparation path that already has the
environment ids and working directories for the submitted turn, while
keeping the actual prompt injection work for follow-up changes.
## What changed
- switch `ext/skills` from `TurnLifecycleContributor` to
`TurnInputContributor`
- build `executor_authorities` from `TurnInputContext.environments` and
pass them through `SkillListQuery`
- keep storing the resolved catalog in `SkillsTurnState`, but drop the
placeholder query helper that no longer matches the real data flow
- update the extension TODOs to reflect that per-turn catalog resolution
now happens in the turn-input contributor, and that prompt/context
injection still needs to move later
## Testing
- Not run locally.
## Why
`codex-core` currently owns the generic contextual-fragment trait and
several reusable fragment implementations. That makes it harder for
other crates to share the same host-owned model-input abstraction
without depending on all of `codex-core`.
This change extracts the reusable fragment machinery into a small
`codex-context-fragments` crate so future extension and skills work can
depend on the fragment abstraction directly.
## What Changed
- Added the `codex-context-fragments` crate with:
- `ContextualUserFragment`
- `FragmentRegistration` / `FragmentRegistrationProxy`
- additional-context fragment types
- Moved `SkillInstructions` into `codex-core-skills`, since
skill-specific rendering belongs with skills rather than generic core
context machinery.
- Kept `codex-core` re-exporting the fragment types it still uses
internally, so existing call sites keep the same shape.
- Updated Cargo and Bazel workspace metadata for the new crate.
## Verification
- `cargo metadata --locked --format-version 1 --no-deps`
- `just bazel-lock-update`
- `just bazel-lock-check`
## Why
`codex_core` is consistently a bottleneck for incremental builds during
iteration. The simplest fix is to make the crate smaller.
## Summary
`codex-core` owns several reusable prompt renderers and static prompt
assets, which makes the crate harder to split apart.
Rename `codex-review-prompts` to `codex-prompts` and move shared review,
goal, permissions, compaction, realtime, hierarchical AGENTS.md, and
`apply_patch` prompts into it. Move prompt-only tests and update
consumers and `CODEOWNERS`.
## Validation
- `just test -p codex-prompts -p codex-apply-patch`
- `just test -p codex-core prompt_caching`
- Bazel builds for the affected crates