102 Commits
Author SHA1 Message Date
Won Park d7748e1185 Add opt-in structured errors for Guardian circuit-breaker interruptions (#48796)
## Why

Guardian denial-limit interruptions lack a structured error identifying the cause. Make this opt-in because older clients may not recognize the new error in shared history.

## What changed

- Add `auto_review.circuit_break_action = "strict"` to attach `TooManyDenials` to the interrupted turn. The default leaves the error unset.
- Expose `turn.error.codexErrorInfo = "tooManyDenials"` in app-server notifications and saved history, and update protocol schemas and generated types.
- Preserve the warning, denial limit, and interrupted status without emitting a separate error notification.

## Testing

Add an integration test covering omitted, `default`, and `strict` settings, checking warnings, live turn errors, the absence of separate error notifications, and persisted turn errors after restart.

GitOrigin-RevId: cb5d379e64728d4d7b9daf834c13756e4a70db31
2026-09-27 22:05:19 +00:00
Eric Traut 334b6e7321 Remove follow-up prompt suggestions from the TUI (#48621)
## What changed

Remove automatic next-message generation after successful turns, suggestion rendering in the composer, and the associated Tab acceptance and Escape dismissal handling. Remove the `tui.prompt_suggestions` configuration option and its schema entry, along with suggestion-specific tests and snapshots.

GitOrigin-RevId: 63bf6f2ca85da6ece502c86e2a805d000bf34210
2026-09-27 05:29:53 +00:00
open-matt b8d5e3f12e Allow exec-server to proxy permitted private IPs upstream (#48568)
## Why

Private IP destinations always bypassed inherited upstream proxies, preventing their use for private networks reachable through an upstream VPN proxy.

## What changed

- Add `codex exec-server --proxy-private-ips-via-upstream`, also configurable with `CODEX_EXEC_SERVER_PROXY_PRIVATE_IPS_VIA_UPSTREAM=true`. The setting defaults to disabled.
- Allow permitted RFC 1918, carrier-grade NAT, and IPv6 unique-local destinations to use an applicable upstream proxy. Loopback and link-local destinations retain direct routing, and destination access policy still applies.
- Keep connections direct when no valid upstream proxy applies or `allow_upstream_proxy=false`. Errors after selecting an upstream proxy do not trigger a direct retry.
- Rename `ExecServerRuntimePaths` to `ExecServerRuntimeOptions` and carry the routing setting from executor startup into the managed network proxy.

## Testing

Add routing coverage for private address ranges, special-use addresses, and public targets with the option enabled and disabled. Verify that HTTP and CONNECT requests still enforce destination allowlists and denylists, and update the CLI help snapshot.

GitOrigin-RevId: b7c9cc7da0e0f545694a6521b74c9b36b7b92769
2026-09-26 23:17:41 +00:00
Felipe Coury b8a1fe4afc Add configurable right-click paste to the fullscreen TUI (#48118)
## What changed

- Add `tui.right_click_paste` with `auto`, `on`, and `off` modes. The default `auto` enables the fallback on Windows and Linux, including WSL when terminal detection is conclusive. `on` also enables macOS. Both modes skip SSH sessions and recognized VS Code terminals.
- Paste clipboard text through the normal composer input path when no selection, search, or blocking view takes precedence. Discard pending results after intervening input, focus loss, or changes to the target thread, draft, or cursor.
- Read text asynchronously through the shared clipboard worker, with a five-second deadline and the message size limit. Read the Windows clipboard through PowerShell on WSL and reject overlapping clipboard operations.

## Testing

Add coverage for platform and terminal policy, normal paste delivery, stale reads, overlapping clipboard operations, read timeouts, oversized text, and large command output.

GitOrigin-RevId: 0a7b6d445c09928da6c5335841ba2a9a66cc7e4b
2026-09-25 15:15:56 +00:00
Celia Chen 8ae55c863d Respect configured authentication in the thread manager sample (#48004)
## Why

The sample hardcoded file-based credential storage and omitted configured auth routing and login restrictions. It should use the configured credentials, including secure storage in `cargo run` builds.

## What changed

- Load authentication settings through the shared bootstrap path and re-export the required helpers and types from `codex-core-api`.
- Honor CLI and MCP credential stores, `features.secret_auth_storage`, auth routing, the ChatGPT base URL, and system proxy settings.
- Preserve managed login-method and ChatGPT workspace restrictions while keeping the sample's built-in execution settings.
- Document the sample's authentication configuration behavior.

GitOrigin-RevId: b49883537acbebf9266b3970d2709e8e7d1bf217
2026-09-25 05:14:07 +00:00
Eric Traut 6743672ad7 Add TUI composer support for prompt suggestions (#47911)
## What changed

Add `tui.prompt_suggestions`, defaulting to `false`, along with suggestion request state, a generation prompt, and strict parsing of single-line suggestions up to 240 characters. Suggestion generation is not connected yet.

Keep suggestions outside the draft and render them dimly in an empty, focused composer. `Tab` accepts a suggestion for editing, a separate `Enter` submits, and `Escape` cancels pending suggestions. Respect active key bindings, popups, attachments, paste bursts, and interactive transcript footers; ignore stale results and cancel suggestions when a task starts.

## Testing

Add parser tests, composer interaction tests, and snapshots covering acceptance, dismissal, stale results, input precedence, wrapping, and transcript search layout.

GitOrigin-RevId: 868001a0fc3e6fd8c11ef1650aabc477fa36e03d
2026-09-24 18:37:33 +00:00
Felipe Coury ab021e9f13 Add configurable copy-on-select for transcript selections (#47639)
## What changed

- Add `tui.copy_on_select` with `auto` (default), `always`, and `never` modes, and apply it to the fullscreen transcript, transcript overlay, and resume/fork previews.
- Enable `auto` in tmux and Zellij, and in direct macOS terminals except Ghostty and Kitty. On other platforms, enable it in direct terminals identified as iTerm2 or Terminal.app.
- Copy nonempty mouse selections on release, including word and line selections, while retaining their highlight. Preserve link activation and ignore empty selections.
- Clear composer selections after confirmed keyboard copies, matching right-click copies, while preserving the draft and cursor. Keep selections when copying fails or delivery is unconfirmed.

## Testing

Add coverage for terminal defaults and configuration overrides, copying on release, retained highlights, repeated clicks, link activation, and empty drags. Extend composer coverage to verify selection clearing for `Cmd-C`, `Ctrl-C`, and right-click across clipboard outcomes.

GitOrigin-RevId: 24e6f9e267ef3ab249c5356db736e094127f68b8
2026-09-23 19:37:42 +00:00
acrognale-oai 22a3f6d5d8 Enforce application network policy across app-server requests (#47407)
## What changed

- Load `application.network` requirements at startup and explicit config/account reloads, applying local policy before authentication and cloud configuration bootstrap.
- Block traffic when policy loading fails, cancel requests that a new policy no longer permits, and reject configuration loads based on superseded policy snapshots. Local requirements edits take effect on the next explicit reload or restart.
- Bind authenticated clients to the current account and revoke them when account ownership changes. Carry policy enforcement through backend requests, realtime connections, workload identity exchanges, and code-mode gRPC streams while preserving gRPC trailers.
- Treat denied credential refreshes as policy errors without retrying them or invalidating stored credentials.

## Testing

Add regression coverage for startup restrictions, reload ordering, cancellation after restrictive or malformed requirements edits, account revocation, gRPC destination denial, workload identity cancellation, and credential preservation after denied OAuth refresh.

GitOrigin-RevId: 0cb4c720a906397e9df06675f01ecf60d741101f
2026-09-23 00:47:07 +00:00
iceweasel-oai 418199f6ad Add an opt-in preference for the local MXC sandbox (#47375)
## What changed

Add the default-off `features.prefer_mxc` flag to select MXC for local Windows execution when native support is available and effective network settings do not explicitly forbid local binding. Otherwise, retain the configured backend and legacy setup behavior.

Resolve the preference during config loading and use the effective local backend for execution, network proxy setup, sandbox diagnostics, and `windowsSandbox/readiness`. Preserve the configured backend for remote executors and `config/read`. Explicit `windows.sandbox = "mxc"` remains strict, and command failures do not trigger backend fallback.

## Testing

Add coverage for preference resolution, startup readiness without rewriting configuration, local and remote backend selection across environment updates and child threads, and workspace-write permission context in an agent turn.

GitOrigin-RevId: b51178f0371d38ebb58e41af54a068fca67fa316
2026-09-22 21:57:52 +00:00
Won Park 26cb4d73e2 Add extra policy configuration for Guardian reviews (#47125)
## What changed

- Add `auto_review.extra_policy` and the managed `guardian_extra_policy` requirement to supply policy text alongside the resolved tenant policy. Nonblank managed values take precedence; blank values are ignored.
- Render the additional text through `{{ extra_policy }}` in Guardian reviewer templates and append it to the tenant policy for Guardian v2 classification before truncation.
- Preserve placeholder-like text inside supplied policies literally.

## Testing

Add coverage for configuration precedence, blank values, template substitution, and classifier prompts, plus a scenario verifying that managed tenant and extra policies reach the Guardian reviewer together.

GitOrigin-RevId: 180d8d716c63fe96a92ec5bfbd22db4ddccd4f1f
2026-09-21 23:06:36 +00:00
Anthony Tafoya f3037cafd3 Refresh host-supplied cloud skills at turn startup (#47074)
## What changed

- Replace the built-in orchestrator skill provider with a host-supplied cloud provider, using `cloud` authority and `c` root aliases in skill tools and prompts.
- Add `cloud.skills.enabled`, defaulting to true but requiring a supplied provider. Keep `orchestrator.skills` accepted as a legacy no-op setting, and remove the app server's automatic orchestrator provider registration.
- Discover cloud skills once per turn during cancellable startup. Serve catalog snapshots to prompts and tools without triggering discovery or retries.
- Scope cached catalogs and resources to authentication state. Preserve them on refresh failures within the same scope, invalidate them when that scope changes, and reject late discovery or read results from replaced cache generations.
- Reuse executor discovery catalogs only when successful discovery inputs and bundled-skill settings match.

## Testing

Add coverage for per-turn refresh, skill removal, same-account failures and reconnects, authentication changes, and stale in-flight results. Update configuration and tool tests for cloud authority, provider gating, and resource reads without an executor.

GitOrigin-RevId: c57e38ec7dcc880c0d4c8a2995adfd3e28301079
2026-09-21 17:28:14 +00:00
Eric Traut a86631502d Add independent TUI rendering toggles for Mermaid, math, and tables (#46938)
## What changed

Add `tui.rendering.mermaid`, `tui.rendering.math`, and `tui.rendering.tables`, all enabled by default and independent of animation settings. Disable individual renderers to display their source instead of diagrams, Unicode math, or formatted tables.

Apply preferences to streaming and completed responses, startup previews, and session changes. When table rendering is disabled, preserve pipe syntax, cell markup, and enclosing Markdown fences. Keep HTML clipboard formatting independent of terminal rendering preferences.

## Testing

Add coverage for individual defaults, source preservation, nested table fences, session settings, and clipboard behavior. Verify incremental rendering and emitted output match completed rendering across all eight toggle combinations.

GitOrigin-RevId: 48d765eac20a82881eed94f186bf5b025ff4f0db
2026-09-21 03:38:46 +00:00
Eric Traut a2de8fedcc Move fullscreen transcript control to TUI configuration (#46849)
## What changed

Use `tui.fullscreen_transcript` to opt into the fullscreen transcript, including scrolling, selection, and search. It defaults to `false`; `--no-alt-screen` and `tui.alternate_screen = "never"` still take precedence.

The new preference controls both the first frame and application startup. Boolean CLI overrides for it are allowed during daemon startup. The old `features.transcript_v2` flag is deprecated and ignored, with a notice directing users to the new setting; it does not migrate into or override the preference.

## Testing

Add coverage for default terminal scrollback, fullscreen persistence through startup, alternate-screen restrictions, daemon override validation, and independence from the deprecated flag. Update existing history and activity tests to use the new preference.

GitOrigin-RevId: 4117bf1ee548fa8d101a594f9506673d87c74c15
2026-09-20 16:59:00 +00:00
Eric Traut bba48e5ce8 Add independent controls for TUI visual effects (#46832)
## What changed

Replace `tui.whimsy` with `[tui.effects]` preferences for `starfield`, `shimmer`, `welcome`, `effort`, `progress`, and `title`. Each defaults to `true` and remains subordinate to the `tui.animations` master switch.

Wire the preferences into composer effects, welcome artwork, status and loading text, progress indicators, and terminal-title animations. For example, disable shimmering text while keeping progress animations:

```toml
[tui.effects]
shimmer = false
```

Keep retired `tui.whimsy` entries loadable but ignore their value. Update the configuration schema to expose the new preferences.

## Testing

Add and extend coverage for independent shimmer and progress effects, master-switch precedence, welcome and starfield controls, terminal-title blinking, and strict configuration loading with the retired setting.

GitOrigin-RevId: 28b37ba52872133b8954543cabe9ff424147f1c5
2026-09-20 16:16:46 +00:00
Henry Levy 49e248d4c3 Add opt-in compaction after final responses (#46541)
## What changed

Add `model_post_turn_compact_threshold_percent` to trigger compaction after a final response when context usage reaches the configured percentage of the usable window or an existing auto-compaction limit. Accept values from `0` to `100`; omitted or zero disables the feature.

Skip post-turn compaction when input is pending, the turn is cancelled, or token-budget mode is enabled. Disable it for approval reviewers to avoid delaying approval completion, and record a distinct `PostTurn` analytics phase.

Buffer local post-turn summaries until compaction succeeds and require a nonempty assistant summary before replacing history. Log compaction failures without failing the completed turn, while still propagating interruptions and turn aborts.

GitOrigin-RevId: b616994175829bd83b5d7974f95dabb042a39a89
2026-09-19 00:52:56 +00:00
Won Park 520e13a4bc Allow configuring the Guardian prompt template (#45516)
## What changed

Add `auto_review.experimental_policy_template` to override the Guardian prompt template in `config.toml`. Trim the configured value and ignore it when empty. Prefer the override over the model catalog template, retaining the bundled template as the final fallback.

The template's `{{ tenant_policy_config }}` placeholder is replaced with the resolved Guardian policy.

## Testing

Extend tests to cover template deserialization, trimming, precedence over the catalog template, and rendered policy text in Guardian inference requests.

GitOrigin-RevId: 85b4a8fc193a42735354894203ccbd1f738a3b58
2026-09-14 21:06:36 +00:00
Nick Steele 374c4b2d82 Resolve enterprise-managed MCP registrations in the catalog (#45459)
## What changed

- Retain the trusted enterprise identity provider in runtime configuration and bind winning MCP registrations during catalog finalization. Require `features.use_xaa` and a configured identity provider for activation, while preserving existing server restrictions.
- Apply plugin `ema_auth` client, issuer, resource, and scope settings to installed and selected plugins. Disable registrations with mismatched endpoints or empty resources without rewriting plugin endpoints.
- Preserve enterprise auth policy across catalog rebuilds and rebind registrations when materialized server settings change. Keep registration rejection separate from persistent server-name vetoes so it does not disable replacement hosted apps.

## Testing

Add coverage for activation gates, configuration ownership, plugin endpoint validation, catalog rebuilds, and skipping interactive OAuth during installation of enterprise-managed plugins. Stabilize the sandbox network proxy test by reading request headers before closing the loopback connection.

GitOrigin-RevId: 3374f507d120835b285767cedbbb511fc7b0fba2
2026-09-14 16:30:00 +00:00
Eric Traut 49a9d78999 Make older app-server notices configurable in the TUI (#43698)
## What changed

Add `tui.show_server_version_notice`, enabled by default. Set it to `false` to suppress informational notices about older stable app servers at startup, on reconnect, and in the agents overview. Compatibility errors and version status remain unaffected.

Refresh the overview notice when local settings change, clearing pending notices when the setting is disabled.

## Testing

Add coverage for disabling and re-enabling overview notices, clearing pending notice state, and preserving remote version status. Extend reconnect and local-settings tests to cover the new setting.

GitOrigin-RevId: d50dcf4472ee221ce31cdd7ab2cd766f901a8039
2026-09-08 04:35:21 +00:00
pmccrary-oai 6af345407d Gate experimental context by model capability at session startup (#43147)
## Why

Experimental context activation previously checked the provider and account eligibility without checking model support. Child sessions also inherited token-budget activation from their parent, even when starting fresh with a different model.

## What changed

- Add `ModelInfo.supports_experimental_context`, defaulting to `false`, and enable it for the bundled `gpt-6-astra` model. Require this capability when activating experimental context.
- Snapshot configured token-budget preferences before startup activation. Restore them for fresh child sessions before applying their starting model's defaults, while history forks retain their parent's activation.
- Pass unresolved token-budget preferences to child sessions so they can use their own model's prompts.

## Testing

Extend coverage for unsupported models, model-switch guidance under explicit and experimental activation, and child configuration from both active and inactive parents. Verify that omitted capability metadata defaults to `false`.

GitOrigin-RevId: 02df9e171682267232fa923d5ea3f7af36527808
2026-09-06 02:28:38 +00:00
Ian MacLeod 6ae8dcf6e1 Add TUI building blocks for inline async question editing (#42889)
## What changed

- Introduce an async-question editor component with per-question drafts, navigation, replay deduplication, and submit or queue handling using the shared composer.
- Add bounded `AnsweredQuestion` framing that truncates question text at a UTF-8 boundary and flattens line breaks before prepending it to an answer.
- Add `prompt_stack_back` and `skip_question` keybinding actions and the `tui.question_esc_back` setting. Normalize `Ctrl+]` and `Ctrl+5` for key matching and conflict detection, and let default question shortcuts yield to explicit bindings.
- Flush buffered typing in both the main composer and the covering view so background input cannot keep the draw loop waiting.

The async-question component is not yet connected to the TUI event flow.

## Testing

Add regression coverage for bounded Unicode question framing, question-shortcut conflicts, and paste-buffer flushing in background and covering editors.

GitOrigin-RevId: 4098043cf588ddafc05c27505645495edd690cb9
2026-09-04 23:56:25 +00:00
Ian MacLeod 147137c1f4 Add Astra sparkle effects to the TUI composer (#42842)
## What changed

- Render sparse, fading stars across the composer when using an Astra model in a true-color terminal.
- Preserve composer content, cursor state, effort effects, and terminal colors, and pause the animation while popups are open.
- Add the default-on `tui.whimsy` setting so decorative effects can be disabled independently. Sparkles also respect `tui.animations`.

## Testing

- Cover model and setting eligibility, terminal color handling, protected composer cells, popup behavior, effort effects, and layout stability.

GitOrigin-RevId: fe0471ebef0bca21c44e1d8f731d46959eba0165
2026-09-04 20:18:13 +00:00
Krish Chainani 03467026f2 Add an injectable attachment store to ThreadManager (#42634)
## What changed

- Add the `codex-attachment-store` crate with storage-neutral attachment metadata, references, errors, and an asynchronous persistence interface.
- Provide an inline implementation that preserves attachment bytes as media-typed base64 data URLs.
- Inject the store into `ThreadManager`, expose it to consumers, and retain inline storage as the default for existing entry points.

## Testing

- Verify inline storage round-trips binary, text, PNG, and JPEG data.
- Verify attachment debug output redacts URLs while retaining file IDs.

GitOrigin-RevId: 7688dcd3c89d7540ed2398f3e7c63881fbfcda97
2026-09-03 23:20:54 +00:00
Eric Traut 5e26f7621c Make the app-server thread unload delay configurable (#42320)
## What changed

- Add the top-level `thread_unload_delay_secs` configuration key for the
  app-server, with a 60-second default instead of the previous 30-minute
  fixed delay.
- Allow zero-delay unloading and reject values that cannot fit in a
  monotonic-clock deadline.
- Reset the unload countdown when a thread gains a subscriber or becomes
  active, and preserve active turns even when the configured delay is zero.
- Document that unloading ephemeral threads discards their in-memory state.

## Testing

- Cover configuration parsing, defaults, overrides, and overflow rejection.
- Cover unsubscribe, resubscribe, delayed and immediate unloading,
  notifications, persisted-thread resume, and WebSocket disconnect behavior.

GitOrigin-RevId: edd46f6b49bbdafbf606bff74378e8f569e95977
2026-09-02 18:18:54 +00:00
Felipe Coury 8ea297ff60 Add a TUI setting to disable automatic recaps (#42101)
## What changed

- Add the `tui.auto_recap` configuration option, enabled by default.
- When disabled, cancel scheduled automatic recap checks, reject automatic
  requests, and discard pending automatic results without retrying.
- Keep manual `/recap` requests available regardless of the setting.

## Testing

- Cover configuration defaults and command-line overrides.
- Cover scheduling cancellation, pending request cleanup, discarded results,
  and manual recaps while automatic recaps are disabled.

GitOrigin-RevId: 7d5323f58a2c84e60683a25a8c77653097efe6e2
2026-09-01 17:09:13 +00:00
rka-oai ec9620c231 Add configurable gating for the sleep tool (#41243)
## What changed

- Add a stable `sleep_tool` feature that can enable or disable registration of the built-in sleep tool independently of the clock tool.
- Support structured `features.sleep_tool` configuration with `model_driven` and `always_on` modes. The default `model_driven` mode preserves the existing model and `current_time_reminder` behavior, while `always_on` registers sleep whenever the feature is enabled.
- Preserve nested sleep-tool configuration across CLI overrides, config merges, and feature toggles, and expose the settings in the generated config schema.

## Testing

- Cover feature-map overrides, both selection modes, legacy clock settings, config merging and editing, and invalid mode rejection.

GitOrigin-RevId: 18eadc582f8a4445958c29d063e5be495276703e
2026-08-28 02:09:07 +00:00
trolle-oai 124e560b93 Make the optional MCP startup grace configurable (#41199)
## What changed

- Add `mcp_optional_startup_grace_ms` with a default of 1,000 ms to control how long tool catalog capture waits for optional MCP servers.
- Treat a value of `0` as disabling the shared grace, so optional servers use their configured `startup_timeout_sec` instead.
- Apply updated grace values during runtime and MCP configuration refreshes, and reset cached startup deadlines when the configured duration changes.

## Testing

- Cover custom, disabled, refreshed, and shared startup grace behavior in MCP connection and core integration tests.

GitOrigin-RevId: 936196215ed6e0a29c9ec72cfee17663978df8ef
2026-08-27 20:31:40 +00:00
jif bce5f2fcfc Standardize shell execution on unified exec (#39772)
## What changed

- Use `exec_command` and `write_stdin` as the shell tool surface.
- Treat legacy `default`, `local`, and `shell_command` model metadata as `unified_exec`.
- Remove obsolete shell-selection configuration and runtime paths while preserving the feature and policy gates for zsh fork execution.

GitOrigin-RevId: d743cbe598630d73052f1fecad680c4cde17977d
2026-08-20 18:29:35 +00:00
Eric Traut ca08a58ab4 Remove the experimental thread config endpoint (#39115)
## What changed

- Remove `experimental_thread_config_endpoint` from the configuration model and schema.
- Stop app-server and the in-process client from constructing a remote thread config loader from local configuration.
- Keep the thread config loader supplied at app-server startup fixed for the lifetime of the config manager.

GitOrigin-RevId: e7907fee2d631e7ecf89ec6bac8f22bc2c221350
2026-08-18 00:45:00 +00:00
jif 632e35ce8d Add a configurable skill catalog token budget (#38978)
## What changed

- Add `[skills].max_context_tokens` to override the token budget used to render the available-skills catalog.
- Require a positive value and cap configured budgets at 10,000 tokens.
- Preserve the existing default of 2% of the model context window when the option is unset.

## Testing

- Cover configuration parsing, override behavior, the 10,000-token cap, and catalog rendering within the configured budget.

GitOrigin-RevId: f29ddcb57fc2d800c0006d03e1c33cbe3ab6272d
2026-08-17 10:01:59 +00:00
cooper-oai 990218bbbd Fail closed when workload identity initialization fails (#38424)
## What changed

- Treat workload identity environment markers as an explicit authentication selection, even when another process credential is present.
- Return initialization errors from `AuthManager` and propagate them through commands and services instead of continuing with an unusable authentication state.
- Make `codex login status` validate workload identity, keep the TUI on an embedded app server for local workload identity, and reject workload identity in `codex mcp-server`, where it is unsupported.

## Testing

- Cover workload identity precedence and partial configuration errors.
- Verify login status reports an unreadable identity assertion and app-server routing enforces the supported workload identity topology.

GitOrigin-RevId: efc6b6b4cd4d61652617de82aaa3d7ffc75d6618
2026-08-13 19:35:22 +00:00
Owen Lin cbb7e82a8b Unify turn input submission and routing (#38275)
## What changed

- Add `TurnInputRequest` and typed submission results for atomically starting a turn, steering the active turn, or declining input with a specific reason.
- Expose `start_or_steer_turn`, `start_turn_if_idle`, and `steer_turn` on `CodexThread`, and migrate Core consumers to these APIs.
- Make app-server `turn/start` steer an active regular turn and return that turn's ID. Reject incompatible output schemas and non-steerable turns without applying settings or enqueueing input.

## Testing

- Cover concurrent start-or-steer submissions, accepted and rejected settings updates, output-schema compatibility, idle-start rejection, and app-server steering.

GitOrigin-RevId: dd9b5528d76ec650c019e97af420bc13190ea86a
2026-08-13 00:00:16 +00:00
stevenlee-oai 285abc0368 Configure PSP routing through the feature system (#38056)
## What changed

- Add the under-development `psp` feature and expose it in the config schema.
- Use the feature to attach the PSP cookie to first-party ChatGPT clients.
- Remove the hidden `--psp` flag and its process-scoped configuration plumbing.
- Preserve configured ChatGPT cookies when creating the PSP client used for GET and POST requests.

## Testing

- Update the config manager service test to verify that enabling `features.psp` retains the setting in the effective config and configures the expected ChatGPT cookie.

GitOrigin-RevId: 53acb5495d2ff71e4ed25f674a0cff787aea474a
2026-08-11 19:16:15 +00:00
jif 279b93242c Remove config lockfile support (#38011)
## What changed

- Remove effective-config lockfile export, replay, and validation from session startup.
- Remove the `debug.config_lockfile` settings and generated schema entries.
- Remove feature-config materialization helpers that were only used to create lockfiles.

GitOrigin-RevId: a8c07c1c06325b3ec3dae9a97c36c2488d37df25
2026-08-11 13:52:48 +00:00
knittel-openai 9e301c8c9a Add configurable Responses API request metadata (#37895)
## What changed

- Add `responses_api_metadata` for product-owned key/value metadata included in
  every Responses API turn metadata payload, including parent and subagent
  requests.
- Limit the map to 16 entries, ASCII identifier keys of at most 64 bytes, and
  values of at most 128 bytes. Reject reserved Codex metadata keys and ignore
  this setting in project-local configuration.
- Give configured product metadata precedence over app-server client metadata
  while keeping it out of metadata sent to external MCP servers.

## Testing

- Cover reserved-key validation, metadata precedence, MCP isolation, and
  propagation to parent and subagent Responses API requests.

GitOrigin-RevId: a7be798294fde25145ab375a468321bb4e4a49f1
2026-08-10 22:58:53 +00:00
Eric Traut a9dee37f9c Add configurable goal token budget limits (#37878)
## What changed

- Add `goals.max_goal_token_budget` as a positive-integer configuration setting.
- Use the configured maximum as the default budget for new goals and when `tokenBudget` is reset to `null`.
- Reject goal creation and updates whose token budget exceeds the configured maximum, including requests through goal tools and `thread/goal/set`.
- Respect managed configuration precedence and per-thread configuration overrides.

## Testing

- Cover configuration parsing and managed overrides.
- Cover defaulting, resetting, and rejecting oversized budgets through the goal service, goal tools, and app-server API.

GitOrigin-RevId: f8d7e6418cdc237d454c8cf47bb32ba0d44a60cf
2026-08-10 21:00:00 +00:00
jif 964a227d8c Preserve base instruction provenance across sessions (#37446)
## Why

Persisted base instructions need to retain whether they were explicitly customized or generated from a model template. Without that distinction, forks and config-lock replays can treat model-generated instructions as custom and keep the wrong template after a model or personality change.

## What changed

- Record custom or model provenance with base instructions in rollouts and config locks.
- Preserve custom instructions across model changes, while allowing model-generated instructions to follow the selected model and personality.
- Keep legacy rollouts without provenance compatible and propagate provenance through forks and spawned agents.

## Testing

- Cover provenance serialization and legacy rollout decoding.
- Cover role personality changes, forked model changes, config-lock replay, and multi-agent configuration.

GitOrigin-RevId: 801c26559835f558027ce5112700c0cd31fcb21b
2026-08-07 14:08:13 +00:00
stevenlee-oai 1d952f027e Add process-scoped PSP routing for ChatGPT requests (#36986)
## What changed

- Add a hidden global `--psp` runtime flag and propagate it through TUI, exec,
  app-server, remote-control, and in-process startup paths.
- Attach the `oai-chat-psp=true` cookie to first-party ChatGPT requests when
  enabled, using a cached cookie-aware client with sensitive request logging
  disabled.
- Keep the routing selection out of persistent configuration layers while
  preserving it across config refreshes and agent role changes.

## Testing

- Cover global flag parsing, app-server propagation, config-layer isolation,
  and preservation across config rebuilds and role changes.

GitOrigin-RevId: 05cdc61ffd7162d8e48fc1e166f4732113e5a816
2026-08-04 22:23:40 +00:00
rka-oai 9952933c1d Add tool registry collision policy configuration (#36954)
## What changed

- Add `features.tool_registry.error_on_tool_collisions`, defaulting to `false`, to the TOML model, generated schema, and resolved runtime configuration.
- Treat `tool_registry` as structured configuration rather than a feature toggle, including in strict config validation and profile configuration.
- Preserve the resolved collision policy in session config lockfiles when it is enabled or explicitly configured.

## Testing

- Cover deserialization, strict validation, default and enabled resolution, feature materialization, and config lockfile serialization.

GitOrigin-RevId: 2c27109dcf2a3d1e51064cc60088703e36a0f85a
2026-08-04 19:28:37 +00:00
tongzhou wang fb4e6ba2f4 Allow disabling the update_plan tool (#35054)
## What changed

- Add a default-on `tools.update_plan.enabled` configuration option.
- Omit `update_plan` from the visible and registered tool sets when the option is disabled.

## Testing

- Cover configuration resolution and tool registration for the disabled setting.

GitOrigin-RevId: c13aa463a6911956fca9f0ef5b74841b543798c4
2026-07-24 00:10:22 +00:00
Celia Chen 265cd2e100 Initialize execution environments with the final HTTP policy (#34995)
## Why

The TUI must inspect the default execution environment before loading its final
configuration. Initializing the environment manager at that point can give
startup services the bootstrap HTTP policy instead of the effective policy after
managed requirements are applied.

## What changed

- Split environment discovery from manager construction so callers can inspect
  the default environment without starting remote connections.
- Build the environment manager after final configuration loading and pass its
  resolved `HttpClientFactory` through all construction paths.
- Add shared test support for managers that use the legacy default HTTP policy.

## Testing

- Cover connection-free environment discovery and explicit HTTP policy
  propagation.
- Verify TUI startup services use the final managed `respect_system_proxy` value.

GitOrigin-RevId: 928fa31e6b4bcfbe1a121cade2f351427fdfa0f4
2026-07-23 19:24:41 +00:00
Adam Perry @ OpenAI c769a05340 Honor the configured SQLite home across state consumers (#34994)
## Why

Codex and SQLite data can use separate home directories, but state consumers
could reconstruct database paths from the Codex home instead of consistently
using the resolved SQLite configuration.

## What changed

- Pass `SqliteConfig` through the core, rollout, state runtime, and thread store
  instead of passing a directory and rebuilding the configuration downstream.
- Use that shared configuration for state, logs, memories, goals, and paginated
  thread-history database access, including integrity checks and cleanup.
- Reject state database handles whose SQLite configuration does not match the
  requesting store.

## Testing

Add coverage with separate Codex and SQLite homes that verifies startup
backfill, thread listing, and paginated history all use the configured SQLite
directory.

GitOrigin-RevId: 1de1cdd1d6ff1d70bbb6c360c8352e6543fb8ebf
2026-07-23 19:19:35 +00:00
sayan-oai 74e9d7efc4 Allow omitting MCP tool prefixes per server (#34991)
## What changed

- Accept a table form of `features.non_prefixed_mcp_tool_names` with an
  optional `server_names` list while preserving the existing boolean form.
- Omit the legacy `mcp__` namespace prefix only for tools from selected MCP
  servers. When no server list is provided, the enabled feature continues to
  omit the prefix for every server.
- Cover configuration resolution, tool normalization, and an MCP stdio
  round trip with selected servers.

GitOrigin-RevId: bdfb7ac54226de5051f06610e2c6b78b23912ef0
2026-07-23 18:54:55 +00:00
pakrym-oai 08ae0fc0ce Consolidate thread startup around StartThreadOptions (#34814)
## What changed

- Add `StartThreadOptions::new` to provide the standard configuration for a new thread.
- Make `ThreadManager::start_thread` the single thread-start entry point and migrate callers from the previous convenience methods.
- Derive default environment selections when `environments` is `None`, while preserving explicit selections, including an empty list.

GitOrigin-RevId: 8977dc11aed54c5e1215a81eaed2b2cf5fc6087a
2026-07-22 19:31:54 +00:00
jif 687f05cb94 Remove CSV-backed agent jobs (#34413)
## What changed

- Remove the `spawn_agents_on_csv` and `report_agent_job_result` tools and their agent-job runtime and state models.
- Drop the legacy `agent_jobs` and `agent_job_items` tables during state database migration.
- Keep `features.enable_fanout` and `agents.job_max_runtime_seconds` accepted as no-op compatibility settings while omitting them from the generated configuration schema.

## Testing

- Verify upgrades remove both legacy agent-job tables.
- Verify the removed feature and configuration keys still parse without taking effect.

GitOrigin-RevId: 8cc3337da78c67162229f02f40a747f503542646
2026-07-20 21:00:17 +00:00
Anais Killian 2895d82b5e Let users remember the working directory for resumed sessions (#33950)
## What changed

- Add `tui.resume_cwd` with `current` and `session` modes for resume and fork flows.
- Let users persist either mode directly from the working-directory prompt, while preserving one-time choices when no preference is configured.
- Apply the preference consistently during startup and in-app resume, honor explicit `--cd` overrides, and reject unsupported or unavailable directory choices with a clear error.

## Testing

- Cover configuration parsing and persistence, prompt behavior, startup and in-app flows, session metadata fallback, and remote workspace constraints.

GitOrigin-RevId: 7bf144c4b8c55bdb868cc8a71caf397c7740451a
2026-07-18 03:58:20 +00:00
jif 9ff47868eb Expose spawn agent types only when roles are configured (#33572)
## Why

The `agent_type` argument is only useful when agent roles are configured. Avoid
advertising an inapplicable override in the model-visible `spawn_agent` schema.

## What changed

- Include `agent_type` in the V1 and V2 spawn tools only when configured roles
  are available.
- Clarify that `agent_type` is an explicit override and document its interaction
  with context forking.
- Remove the unused `agents.support_agent_type` configuration field.

## Testing

- Add coverage for hiding `agent_type` without roles and exposing it when a role
  is configured.

GitOrigin-RevId: 32e0f123b15f317e9cdb71774029375bc073d9ad
2026-07-16 10:28:36 +00:00
jif 03bb3b1236 Unify multi-agent settings under agents (#33550)
## What changed

- Add `agents.enabled` as a user override for multi-agent tools while keeping an enabled `features.multi_agent_v2` authoritative.
- Rename the shared spawned-thread limit to `agents.max_concurrent_threads_per_session`, retain `agents.max_threads` as an alias, and apply the setting to both multi-agent backends.
- Add reserved subagent model, reasoning effort, and agent-type settings to the config surface and persist all resolved agent settings in config locks.
- Show the resolved `[agents]` values in TUI debug-config output.

## Testing

- Cover config loading, legacy alias normalization across merged layers, backend-selection precedence, V2 concurrency, and debug output.

GitOrigin-RevId: 2957c954a2e1aef51592768dbbccd56c4bf8f118
2026-07-16 09:00:51 +00:00
Bryan Ashley 8604689ec5 Allow injecting the Codex Apps tools cache (#33113)
## What changed

- Accept a caller-provided `CodexAppsToolsCache` when constructing a `ThreadManager` and pass it through to the MCP manager.
- Add `ConnectorRuntimeManager::new_without_cache()` for an in-memory runtime that neither loads nor persists connector state on disk.
- Re-export `CodexAppsToolsCache` from `codex-core` and `codex-core-api` for embedders.

## Testing

- Verify that a cache-disabled connector runtime ignores existing disk state and publishes live tools without creating cache files.

GitOrigin-RevId: f52f4f27c425a8d84ad0d0987b30a6fc3c14d702
2026-07-14 17:10:04 +00:00
richardopenai 80c6cd3014 Allow injecting the models manager into ThreadManager (#32911)
## Why

Embedding callers need to control whether model catalogs are persisted to disk.

## What changed

- Accept a shared models manager when constructing `ThreadManager` instead of always creating a cached manager internally.
- Add provider APIs for creating uncached model managers. OpenAI-compatible providers fetch on each `OnlineIfUncached` refresh without reading or writing `models_cache.json`.
- Keep existing app server, MCP server, sample, and test callers on the standard cached manager.

## Testing

- Verify an uncached manager fetches on every refresh.
- Verify an injected uncached manager controls thread refresh behavior and does not create `models_cache.json`.

GitOrigin-RevId: 8bb646054ecec4ccb865b2bf56249384916ea9db
2026-07-14 01:06:11 +00:00
pakrym-oai d2d00b6632 Always send reasoning parameters in Responses requests (#32206)
## What changed

- Build a reasoning payload for every Responses request and always include `reasoning.encrypted_content`.
- Remove `supports_reasoning_summaries` from model metadata and retire the `model_supports_reasoning_summaries` configuration override.
- Use configured or model-default reasoning effort without a capability gate, including for guardian reviews and tracing.

GitOrigin-RevId: 2c9f194a5d2d4d688a2235299e6358f82ab8e1ea
2026-07-10 16:11:58 +00:00