Conversation
## Why Some Windows terminals send legacy mouse reports as key records. Requesting SGR reports lets ConPTY translate them into mouse records. ## What changed Write and flush the SGR encoding request separately from `EnablePointerCapture`, so it also reaches terminals when capture uses the Windows console API. Explicitly reset SGR encoding during Windows mouse cleanup, even if restoring the console mode fails. ## Testing Add regression tests for cleanup after SGR setup fails and an isolated Windows console test that checks mouse input activation, SGR encoding, and restoration of the original console mode and default encoding. GitOrigin-RevId: c1a48d641cda4e770dbbe9fdf805a27e036d35c3
## What changed Render ordered list markers in the TUI with the terminal's `LightBlue` color instead of `accent_color()`. ## Testing Add a snapshot covering ordered list markers alongside links and inline code. Update rendering expectations and nested-list streaming tests to assert `LightBlue`, including the incremental rendering snapshot. GitOrigin-RevId: dea0081737a5bbe8652c761582fb82b20964431a
## Why The “Implement this plan?” prompt blocked transcript scrolling, preventing users from reviewing earlier steps in a long plan while deciding how to proceed. ## What changed Allow mouse-wheel scrolling over the visible transcript while a modal is active. Keep keyboard input with the modal and preserve restrictions on transcript selection, scrolling outside the transcript, and scrolling with completion popups open. ## Testing Add input tests and a snapshot covering plan-prompt scrolling, keyboard navigation, dismissal and submission, pointer boundaries, and completion-popup behavior. GitOrigin-RevId: ac5227c877ce34324a0d3830d5383495241ddbc3
## Why Completion footers hid known durations unless they exceeded 60 seconds, leaving short turns without elapsed-time information. ## What changed Show all known durations for live and restored turns, rendering sub-second durations as `Worked for <1s`. Separate completion metadata with `•` instead of `·`. ## Testing Update live completion, history replay, and separator tests to cover short durations, missing timestamps, and the revised footer format. Refresh affected TUI snapshots. GitOrigin-RevId: 666e765db5426c5f9cc00d73f71cab649ad34947
## What changed - Add `CodexThread::prewarm_with_history()` to prepare a WebSocket response with existing conversation history and executed-tool metadata using `generate: false`. The next turn can reuse the prepared response when its prompt extends that history and request settings match. - Keep startup prewarming and `prewarm()` on the existing empty-input path, and skip preparation when the cached WebSocket is ready. - Label prewarm telemetry by input mode and WebSocket continuation metrics with `after_prewarm`. - Rename `persistent_mode_enabled` to `persistent_execution_enabled` without changing its behavior. ## Testing Extend WebSocket coverage to check history preservation during reconnect prewarming, reuse of the prepared response on the next turn, and omission of `previous_response_id` for a non-prefix prompt. GitOrigin-RevId: c7731541b11b2e6668027a47f37f696213268c66
## Why
Splitting every statement at semicolons and rejecting label punctuation prevents rendering labels such as `A["Go []; &"]`, sequence messages containing `data[0] = {x: 1}`, and class members containing semicolons.
## What changed
- Split statements using diagram-specific rules, preserving semicolons inside flowchart labels, quoted tokens, and class member lines. Sequence quotes remain literal text.
- Respect quoted flowchart label delimiters and allow printable label punctuation, including literal ampersands and comparison operators.
- Reject unsupported entity escapes before statement splitting can truncate them, while retaining rejection of HTML markup and malformed labels.
- Document the supported syntax and require newlines between class members.
## Testing
Add parser assertions and update rendering snapshots for punctuation, quoted delimiters, and semicolons. Extend rejection coverage for entity escapes across diagram families, malformed quotes, and invalid class bodies.
GitOrigin-RevId: da94007a66c7c58444e6f0d6a1b409c8c7251941
…8819) ## What changed - Give tool fragment sizes and namespace counts logarithmic boundaries through 32,768. - Give enabled and kept skill counts integer boundaries from 0 through 512, removed description characters logarithmic boundaries through 131,072, and skill truncation flags boundaries at 0 and 1. - Record these metrics with explicit boundaries, separating zero values and retaining overflow buckets above each range. ## Testing Extend tool and skill metric tests to assert explicit boundaries. Add an export test covering zero, one, the upper boundary, and overflow, including bucket counts, ordering, and sample totals. GitOrigin-RevId: 9fbf3acbe352d7c74f3ad11f0b690148c083a6ef
## Why Capture jitter and mute transitions can shift RTP timestamps off the 20 ms source grid, causing receivers that assemble fixed-duration frames to reject subsequent audio. ## What changed Advance elapsed gaps in whole 20 ms packets and keep the track clock on that grid. Bias empty gap durations by 1 ns to avoid losing an RTP tick to floating-point truncation. ## Testing Update jitter and mute tests to assert exact clock advancement, including a 580 ms gap, and verify that resumed RTP timestamps stay aligned to 960-sample packets. GitOrigin-RevId: 1511c739b77ee5871f72723fd34cb67aa9a48c95
## What changed - Show a hand pointer over actionable transcript links while Codex captures mouse input in Ghostty and Kitty, excluding sessions inside terminal multiplexers. - Share link hit testing between hover and click activation, and refresh hover after rendering so scrolling and live output cannot leave a stale hand pointer. - Suppress link hover during mouse presses and drags, overlays, and popups, and clear remembered mouse coordinates on focus loss, resize, and resume. - Restore the terminal's pointer policy when releasing mouse capture, releasing Kitty's override and using a text pointer in Ghostty. Deduplicate pointer updates and preserve cleanup after write failures. ## Testing Add tests for wrapped links containing wide characters, hover/click target agreement, scrolling, pointer transitions and restoration, write-failure retries, and hover invalidation. GitOrigin-RevId: 1cf52e039a229e12260fa334879784c9bc1c8c87
## Why Fresh threads have no rollout until their first turn, so archiving them previously failed with a missing-rollout error. ## What changed Persist loaded, non-ephemeral threads before looking them up for archival. This lets a newly started thread be archived without creating a user turn. ## Testing Update the archive regression test to cover threads with no turns in both legacy and paginated history modes. Verify the archive notification, empty turn history, `NotLoaded` status, and archived rollout path. GitOrigin-RevId: 507351c6238ad96f5e3ffbd2ed7f432058e3d52c
…48829) ## Why Allow the provisioning service time to start without holding up desktop readiness checks for the full provisioning timeout. ## What changed - Poll service status while startup is pending, waiting up to five seconds within the caller's deadline. Treat absent, deletion-pending, or other non-running service states as unavailable. - Preserve the original provisioning deadline for pipe availability and request processing, and reject requests whose deadline expires during server authentication. - Recheck service status when the pipe disappears while waiting for an available instance. GitOrigin-RevId: ea89175cb41749b9768ac5915083bbfd8ad32713
## What changed Render interrupted turns with secondary text styling and shorter wording, removing the suggestion to tell the model what to do differently. ## Testing Update interruption snapshots and assert that the notice uses secondary text styling. GitOrigin-RevId: 7cb042ed9e6781d107a93d5677fa193f082c764d
## What changed - Default `flowchart` and `graph` to top-down layout when no direction is specified. - Support solid and dashed edges with directed, undirected, or bidirectional endpoints: `-->`, `---`, `<-->`, `-.->`, `-.-`, and `<-.->`. - Accept pipe labels on these edges and spaced directed infix labels such as `A -- send --> B` and `A -. retry .-> B`. - Expand `&` groups into all source-to-target edges, including in chains. For example, `A & B --> C & D` creates four edges. Enforce the 24-edge limit after expansion and cap each group at 24 node references. ## Testing Add coverage for equivalent syntax, edge styles and endpoints, malformed input, and expansion limits. Extend rendering snapshots across all four directions and the TUI native-renderer test with the new syntax. GitOrigin-RevId: 6e51653ebf6b8b7e7e1edec0c2e09a5d9c8dec74
## Why Startup prewarm can reconnect after its empty WebSocket connection closes, consuming the scripted realtime session reply in the environment-key fallback test with ChatGPT authentication. ## What changed Use separate WebSocket servers for startup and realtime traffic, configuring `experimental_realtime_ws_base_url` to point to the realtime server. Assert that it receives exactly one handshake and that the handshake uses the environment key for authorization. GitOrigin-RevId: 0e8ba4bdd66ef8aa3c619e36454dded9dcf55444
) ## Why Message-board notifications delivered as ordinary injected input could cause an agent to sample again after its final answer. ## What changed Route notifications through the current turn's mailbox as `InterAgentCommunication`, checking atomically that the turn is running and still accepts mailbox delivery. Skip notifications when delivery is closed. Accepted notifications may remain in conversation history for a later turn without reopening the finalized answer or starting a new turn. Report pending inter-agent communications as mailbox activity, while preserving priority for steering input. ## Testing Add regression scenarios for notifications arriving before and after finalization, asserting no extra sampling and the expected notification presence in the next turn. Extend input-queue coverage to recognize already-pending mailbox activity. GitOrigin-RevId: 41d786041b4eccc5ccf926f2f190473676a3ac2f
## Why Updates that only change `updated_at` should not rewrite unrelated thread metadata or its indexes. ## What changed Use `touch_thread_updated_at` for timestamp-only patches when the SQLite row exists and the rollout path is unchanged. Preserve the full update path for missing rows, changed rollout paths, and patches containing other metadata, including staged changes. ## Testing Add regression coverage for legacy and paginated histories that verifies missing-row reconstruction, timestamp-only writes using SQLite triggers, preservation of other metadata, and application and removal of staged metadata. GitOrigin-RevId: d5bc70d57e591e3eb8e9521f0c31a7ef75f244d3
## Why Best-effort workspace enrichment can time out independently of the detached request metadata checked by the memory startup test. ## What changed Keep the phase-one service-tier and detached-metadata test fixture outside Git and assert that `workspaces` is absent. Update the header assertion message to refer to turn metadata. GitOrigin-RevId: 9541668fc62a28d1ff3131d7f71b351149b6e152
) ## Why Microsoft Store PowerShell cannot run under MXC. The existing fallback to an unpackaged PowerShell executable only applied to the elevated Windows sandbox. ## What changed Extend local PowerShell fallback discovery to MXC in `unified_exec`, using the executor's Windows sandbox selection. Keep discovery local and automatic `-NoProfile` insertion specific to the elevated sandbox. Skip this preparation for non-Windows target paths. ## Testing Extend command-preparation tests to cover MXC and add a Windows integration test that replaces a Store PowerShell path before launch, writes a file successfully, and verifies `windows_mxc` sandbox metadata. GitOrigin-RevId: 6c581396525a8fec7e1fb538b3e63b0de2ddb926
Older macOS policy compilers do not define the `TIOCSTI` symbol. Generate the sandbox CLI's Seatbelt deny rule with the numeric value from `libc::TIOCSTI` so it remains compatible while blocking terminal input injection. GitOrigin-RevId: de8113fbab92bb399f37b9a22762c5c649f25972
Describe permissions and approvals explicitly in the Codex docs link text, and clarify that the user's ChatGPT plan rate limits and training data preferences apply. Remove the “Before you start” preamble to shorten the success screen. Update the rendering snapshot and hyperlink styling assertions for the revised copy and layout. GitOrigin-RevId: 5166ddade6a433191fa86c960899c4da5092b9f5
…9032) ## Why Setting `auto_vacuum` on every connection can wait for a writer lock even when the mode is unchanged. Logging every span entry and exit can also block SQLx workers on undrained stderr while they hold a write transaction. ## What changed - Set incremental vacuum only for empty databases or databases using full auto-vacuum, before enabling WAL. Preserve existing nonempty databases with auto-vacuum disabled. - Emit span creation and closure events in app-server text and JSON stderr logs, preserving busy/idle timings and explicit events while omitting span entry and exit records. ## Testing Add regression tests for opening and expanding writable pools while another connection holds a writer lock, and for transaction completion with undrained stderr in both log formats. Verify vacuum modes and retained log diagnostics. GitOrigin-RevId: 40d4ef32c7efc49f4240b987277ba45551259335
## Why The transcript supplied to Guardian may omit earlier user instructions, restrictions, or revoked permissions. History retrieval lets the reviewer check relevant authorization before approving actions with side effects. ## What changed - Add the disabled-by-default `guardian_conversation_history_tools` feature. With Apps enabled, expose `user_message.search_messages` and `user_message.read_messages` through the parent's live Apps connection and conversation identity. - Recheck the parent's current app and tool policy on each call, rejecting disabled tools and calls requiring approval. - Add retrieval instructions that distinguish user authorization from assistant context and account for later revocations and incomplete results. Allow overrides through `auto_review.experimental_conversation_history_prompt`. - Limit history responses to an estimated 4,000 tokens by default, configurable through `auto_review.conversation_history_max_output_tokens`, while preserving stricter parent and reviewer limits. - Allow explicit extension registries for isolated sessions and prevent those sessions from inheriting the implicit Apps connection. ## Testing Add scenarios covering history tool exposure, parent connection and identity reuse, custom prompts, output truncation, stricter reviewer budgets, and live permission changes on a reused reviewer. Extend configuration coverage for blank prompt overrides. GitOrigin-RevId: 055a69b113c8548bd58e7d5618ea026ba6d1ffb1
## Why The fullscreen status line showed Plan mode without explaining how to leave it. ## What changed Show `Plan mode (shift+tab to cycle)` when the composer is idle and accepts input, and the hint fits alongside the status text. Fall back to the mode label when space is limited, and hide the shortcut during tasks, popups, interactive footer use, or other non-composer modes. ## Testing Add a rendering snapshot and regression assertions for wide and narrow layouts, running tasks, interactive search, empty status text, disabled input, and parent-owned threads. GitOrigin-RevId: a1cf2762b33f5442ab0611a15205f2e36c84b075
## Why Guardian transcripts omitted encrypted agent messages, leaving reviews without evidence such as encrypted parent replies. ## What changed - Carry encrypted `agent_message` items through synchronous reviews and asynchronous scoring, preserving their order, author, recipient, and ciphertext. - Account for native messages in context budgets and omit them whole with an explicit notice when limits require it. - Support mixed text and native messages during review admission while retaining user-content annotations. ## Testing Add coverage for transcript ordering and budget eviction in both reviewer profiles, plus a mocked scenario verifying that an encrypted parent reply appears exactly once in each of two incremental Guardian reviews. GitOrigin-RevId: abc2f1ce5accd83beb06f799ef9ed9d7fa2cd90a
## Why Copying text selected entirely within inline code added Markdown backticks that were not part of the selected content. ## What changed Return only the selected content as plain text when the selection is contained within one inline code span, including in a single table cell. Preserve Markdown formatting for selections that also include surrounding content, and continue filtering control characters from table copies. ## Testing Add regression coverage for full and partial inline code selections, embedded backticks, Unicode, whitespace, wrapping and resizing, and table selections with mixed content or control characters. GitOrigin-RevId: c63e13cb781f9fca28ae53500cb4f9ae08b72c96
## What changed Update plan labels in the analytics views and status display: - `PlanType::Pro`: `Pro (More)` → `Pro Extra` - `PlanType::ProLite`: `Pro` → `Pro Standard` - `PlanType::ProMax`: `Pro (Max)` → `Pro Max` ## Testing Update the status display-name test expectations for all three Pro tiers. GitOrigin-RevId: 9bd9f1cd8a701019fd40047cd8131e6193f66cb9
## What changed Add the disabled-by-default `guardian_root_handoff_context` feature to select worker-specific root evidence for Guardian reviews. Use recorded `spawn_agent`, `send_message`, and `followup_task` calls targeting a worker or its ancestors to select the three preceding root messages per handoff, plus the three latest root messages so recent cancellations remain visible before another handoff. Preserve verified tool answers and evidence without known ordering, and retain the existing shared message cap. Fall back to the existing root context when no usable handoff window remains or the latest authorization message is a heartbeat. Update the review context revision when the selection changes. ## Testing Add a delegation scenario and Guardian request snapshot covering ancestor handoffs, separate worker branches, cancellation visibility, and fallback after compaction removes handoff calls. Extend heartbeat coverage to exercise the new feature and verify that the latest turn's trusted skills are retained. GitOrigin-RevId: 87dc39158f78b2b7e9f4f2e4afc653257ea12025
#49993) ## Why The rolling retained-context window can change as assistant messages are added or evicted. Placing it before the transcript invalidates the reusable history prefix. ## What changed Move retained user instructions and context after the transcript and action-specific attestations, immediately before the planned action in asynchronous Guardian requests. Keep synchronous section ordering unchanged. ## Testing Extend the cache-prefix regression test to cover retained assistant message growth and eviction alongside changing attestations. Update app-server and async scorer assertions to verify the new request ordering. GitOrigin-RevId: 59953d582d4b174ce3e083606626c7532ce0776d
## Why Fresh TUI threads should use the app server's model settings unless the launch explicitly overrides them. Sending resolved configuration values in `thread/start` turns defaults into explicit overrides. ## What changed - Track explicit launch choices for `model`, `model_provider`, and `model_reasoning_effort`, and omit unselected settings from the initial `thread/start` request. - Preserve accepted model migrations as explicit model and reasoning-effort choices. - Keep explicit profile launches on the existing resolved-configuration path. ## Testing Update startup request tests to cover omitted defaults, CLI model and provider overrides, repeated model overrides, reasoning-effort overrides, accepted migrations, and explicit profiles. GitOrigin-RevId: 4e2661ba42322a80e2b769a55c62f61a576762b0
## Why Concurrent Linux test spawns can inherit writable descriptors for executable fixtures, preventing those fixtures from being executed even after the writing test closes its descriptor. ## What changed Replace direct executable fixture writes and copies across the Rust tests with `codex_utils_cargo_bin::write_executable` and `copy_executable`. These existing helpers complete writes and copies in separate processes on Linux. Remove the empty temporary inode before creating fake bubblewrap executables, and stage tampered bubblewrap bytes in a separate data file before copying them into the executable fixture. Add the required test dependencies. GitOrigin-RevId: c875c83088731a4933ef1574e8d79d8cecc12f54
…50019) ## What changed Add `CODEX_GUARDIAN_DECISIONS_API_KEY` to the non-inheritable environment variables and the HTTP header environment denylist. Case-insensitive filtering removes it from child process environments, including explicit shell policy and command overrides, and rejects its use through `http/request` header `value_env_var`. ## Testing Extend regression coverage for inherited and overridden variables, mixed-case names, and HTTP header rejection before any network request is sent. GitOrigin-RevId: 1adeef814fdccb2d6c77dd68f7a5dfcec0b41cc6
## Why A user restriction such as “Cancel the deployment” can fall outside the recent-message window after unrelated status questions. Guardian reviews need that restriction when assessing delegated actions. ## What changed - Preserve root user messages during handoff relevance filtering, subject to the existing shared message cap. - Apply handoff filtering during heartbeats while retaining saved heartbeat instructions and the active turn's trusted skills. - Mark assistant context as incomplete when handoff filtering omits it, so ordinary user replies are not interpreted without their missing context. ## Testing Add regression coverage for restrictions followed by status questions, bounded user history, omitted assistant questions, and trusted skills across first and repeated heartbeats. Update the delegation request-history snapshot. GitOrigin-RevId: 67f77313572dc54225713cd7cdb90f06b0fbe030
## Why Legacy MCP tool discovery discarded pagination cursors, leaving tools on later pages unavailable. ## What changed Pass `tools/list` pagination cursors to the existing collector in both legacy and modern protocol modes. Legacy discovery now follows subsequent pages and applies the same pagination limits and cursor validation as modern discovery. ## Testing Extend integration coverage to both protocol modes, checking that tools from later pages reach the model and can be called successfully, while catalogs with oversized cursors are rejected. Update the legacy discovery test to expect an error for a repeated cursor. GitOrigin-RevId: a6daa8034d2a403c1f2a5846e385789d8a620af7
## Why Closing Find previously restored the pre-search view, making it difficult to read a match and its surrounding transcript context. ## What changed - Make `Esc` with a nonempty query close query editing while preserving the query, highlighted match, and expanded output. A second `Esc` returns to the latest output; `Ctrl+C` cancels Find and restores the pre-search presentation. - Allow paging through surrounding context and loading older history without losing the query. Keep `Ctrl+N` and `Ctrl+P` available for match navigation, and reopen Find to edit the retained query. - Show context above matches when space permits, preserve match layouts across resizing, and display navigation and history status while reading results. ## Testing Add regression tests and snapshots for retained results, surrounding context, resizing, paging around live output, older-history loading, and footer status. Update interaction tests for the additional `Esc` transition. GitOrigin-RevId: d822956d3c6ffab88fc1665ebdf0c86ccf110899
## Why Starting Find expanded the entire transcript into detailed mode. Searching hidden content should preserve the compact view and manually expanded activities. ## What changed - Search full transcript content, including hidden live output, and temporarily expand only the current matching entry. - Preserve manual disclosure state and retained text revisions while reading or selecting a match. Allow activity controls while reading results. - Use `Enter` or `Ctrl+P` for older matches and `Ctrl+N` for newer matches, with matching footer hints. ## Testing Add regression tests and snapshots for selective expansion, manual disclosures, hidden live matches, retained selections across updates and resizing, and Find in compact transcript overlays. GitOrigin-RevId: 618ee47ba6c3f3a5138c9e3fe0961e7faa3383da
## Why Cygwin records installation timestamps in an unused Java truststore, changing Bazel action cache keys when the same tools are reinstalled. ## What changed Exclude `cygwin/etc/pki/ca-trust/extracted/java/cacerts` from the generated `cygwin` filegroup in `.github/scripts/voice_windows_tools.py`. GitOrigin-RevId: 8fdd910fadba7d977b45718546232652d073cdc8
## Why Environment changes and overlapping catalog refreshes can cause a step to use another step's selected plugins or executor skills. Model context and skill tools need to agree on the capabilities captured for that step. ## What changed - Resolve selected plugins from each step's ready capability roots, honoring disabled plugins, and retain the snapshot with the step's extension data. - Use that snapshot for skill attribution in World State and the first step's active-plugin telemetry. - Return executor skill catalogs directly from refresh so overlapping requests render their own results while retaining thread caches. ## Testing Add regression coverage for overlapping executor catalogs and environment changes during step preparation. Verify that `skills.list` retains the original step's skills, the next step advertises the new skills, and disabled executor and plugin skills remain absent from model context. GitOrigin-RevId: 37d3cbe8c7e062fd06290aa985ada4d3b3462d43
## Why When a turn ends, unsent question answers are recovered into the main composer. Recovering only the answers loses which question each answer belongs to. ## What changed Prepend each recovered answer with its question title as a Markdown blockquote. Separate questions, answers, and existing composer text with blank lines. Sanitize question titles and limit them to 512 bytes at a UTF-8 character boundary, adding an ellipsis when truncated. Keep answer text untruncated. ## Testing Add coverage for bounded titles, multibyte characters, control characters, and multiline question-and-answer submission. Update recovery assertions and snapshots for turn completion, failure, interruption, large pastes, and Vim undo. GitOrigin-RevId: 141dacfb64bcad5fcabc5be217d2340ef7de1eb5
…0054) ## What changed Update `post_sampling_token_estimate_is_disabled_by_always_on_sinks` to register explicit event metadata with the subscriber and assert that its interest is `never`. This replaces the scoped default subscriber and global interest-cache rebuild with a direct check of the configured logging layers. GitOrigin-RevId: 7c4ecd9c4adef148fd222394ad1ad326e8033d95
## What changed - Centralize `windows-sys` at version `0.61.2` in the workspace and migrate dependent crates to it. - Adapt Windows API calls to the updated handle, boolean, and type definitions. Replace custom handle owners with `OwnedHandle` and use `BorrowedHandle` where ownership stays with the caller. - Add explicit wrappers for non-owning Windows handles passed between threads. ## Testing Enable the MCP refresh cleanup test on Windows. Retain process handles to verify that a superseded MCP server stays alive during an in-flight call, exits after cancellation, and leaves the replacement running until shutdown. GitOrigin-RevId: 86f53d9b300d13edff7154f4a7c32e34dacd2919
## Why Bubblewrap consumes and closes the file descriptor for each `--ro-bind-data` mount. Reusing one descriptor across multiple file masks prevents the sandbox from starting. ## What changed Open and preserve a separate `/dev/null` descriptor for each empty-file mask. ## Testing Extend unit tests to verify distinct descriptors for multiple denied files and missing-path masks. Add integration coverage for exact-path and glob deny rules, checking that the sandbox starts, denied files remain unreadable and unwritable, and allowed files remain accessible. GitOrigin-RevId: 85158c83699afd36bb7aca453b2652d777cf65e4
…ion (#50066) ## What changed Add a Decisions sampler under `#[cfg(test)]` for Guardian's optional comparison classifier, without wiring a runtime caller. - Encode text and inline image evidence as a `guardian_risk` choice request using `gpt-6-luna`, accepting only `low` or `high` responses. Reject the complete request when evidence cannot be represented. - Bound concurrency to 16 requests, cancel the oldest unfinished request at capacity, and abort unfinished work when its owning task is dropped. - Enforce a six-second HTTP deadline, an 8 MiB inline image data limit, and a 16 KiB response limit. Keep credentials and wire bodies out of errors. ## Testing Add tests for the HTTP contract, unsupported evidence, inline image preservation and size limits, response validation, oldest-request cancellation, and capacity release when a caller is dropped while awaiting completion. GitOrigin-RevId: e7209ca49a04505acf10ff1aeaca941514589e13
## Why Subagents spawned without forked history do not receive their parent's client-defined dynamic tools, preventing them from using those tools for delegated work. ## What changed Add the disabled-by-default `multi_agent_v2_dynamic_tools` feature flag. When enabled, fresh V2 subagents inherit the parent's dynamic tool definitions and persist them in session metadata. ## Testing Add coverage for V1 and V2 feature gating, tool persistence, and a fresh V2 subagent calling an inherited tool and receiving its result without inheriting parent history. Update TUI assertions and a snapshot to reflect blank-line separation and question text in recovered answers. GitOrigin-RevId: a17a16bf5570f54ce922c1521cffb883022354f2
## What changed Add `StateRuntime::list_thread_attachment_threads` to find threads by exact `attachment_type` and `identity_key`, including threads without previews. Return thread IDs and archive state, with filters for all, archived, or non-archived threads. Order results by thread ID and bind pagination cursors to the attachment identity and archive filter. Add a database index on `(attachment_type, identity_key, thread_id)` to support the lookup. ## Testing Add coverage for exact identity matching, archive filters, pagination, rejection of cursors reused with different lookup parameters, and membership updates after attachment removal or thread deletion. GitOrigin-RevId: 21f32eb0cb1845a82d740d67b374080b6e12eb03
## Why Unread queue-only messages prevented idle agents from unloading, and sending a message to an evicted agent reloaded its session. Pending mail should not require an idle recipient to occupy a loaded thread slot. ## What changed - Retain queue-only mail in an in-memory runtime mailbox when a session unloads. Queue new messages for locally evicted agents without reloading them or starting a turn. - Add `AgentControl::take_mailbox` and `AgentControl::watch_mailbox` so sessions can consume retained mail and react to host mailbox notifications. - Preserve message order across eviction, reload, and subsequent follow-ups. Keep agents with outstanding durable sleep or turn-triggering mail loaded, and discard retained mail when an agent is removed or its tree shuts down. ## Testing Add integration coverage for retaining mail across eviction, sending while unloaded, and ordering messages around a follow-up after reload. Add a host controller test verifying that mailbox notifications wake `wait_agent` and that the message is delivered exactly once. GitOrigin-RevId: 4b55647f9ee9d1aaf3753f0688863bda81617327
…50093) ## Why Reloading an unloaded root from a surviving child can supply the shared instruction wrapper already registered for that root. Replacing its underlying provider with that same wrapper makes instruction loading recurse into itself. ## What changed Reuse the existing wrapper without replacing its provider when both are the same `Arc`. Continue to accept distinct replacement providers. ## Testing Extend regression coverage to reload the root from a surviving child and verify that shared instructions still update. Check wrapper reuse, replacement with a distinct shared provider, and freezing the shared snapshot when switching to a provider that does not share with subagents. GitOrigin-RevId: 7b6b2f9031f206e203f6fa14e1478a36b305ec39
## Why `thread/attachment/list` lists attachments for a known thread. Clients also need to find the threads associated with a given attachment identity. ## What changed Add `thread/attachmentOwner/list` to return owning thread IDs and archive status for an exact `attachmentType` and `identityKey`. Support cursor pagination and an optional `archived` filter, including both archived and non-archived threads by default. Wire the request through the thread store and update documentation, protocol schemas, and generated TypeScript and Python types. The lookup is limited to the configured thread store and reports current membership, not an atomic resource-cleanup check. ## Testing Extend app-server integration tests to cover exact type-and-key matching, multiple owners, archive filtering, and invalid cursor rejection. GitOrigin-RevId: 30f4a20e00243d0023246d465a9b95213b3adeb6
## What changed Add the disabled-by-default `guardianv2_decisions_comparison` feature to run Decisions alongside Guardian V2 snapshot classification using the same policy and evidence. Initialize the comparison sampler with `CODEX_GUARDIAN_DECISIONS_API_KEY`. Publish the baseline score before awaiting comparison results, and keep comparison results and failures from changing approvals. Apply Guardian's input token budget, skip conversation evidence, and cancel comparison work when the baseline classification is superseded. Record success, failure, and skip outcomes with bounded diagnostic reasons, including setup failures. ## Testing Add lifecycle tests covering disabled comparison, disagreeing classifications, backend failures, unchanged published scores, matching policy and evidence, and rejection of over-budget requests before either backend sends them. GitOrigin-RevId: 743d34c8ee440362da94f001058366027b39bd11
## What changed Move footer property construction, mode resolution, hint overrides, quit shortcut hints, and custom footer height calculation from `chat_composer.rs` into `chat_composer/footer_state.rs`. Preserve existing behavior and expose the moved helpers to the parent module where needed. GitOrigin-RevId: 4a23753ac1648352ab19d4bcc3da9f368c48f619
## Why Long drafts need to remain browsable while leaving room for the transcript. Remote image attachments also need to leave an editable prompt row visible. ## What changed - Cap the fullscreen composer, including padding and hints, at two-thirds of the screen, with a minimum of eight rows when the screen allows. - Support mouse-wheel browsing without moving the caret or changing transcript selection, search, or activity focus. Show arrows for hidden prompt rows and hide the cursor when the caret is offscreen. - Resume caret following on editor input, paste, and external edits. - Keep the selected remote image visible while reserving space for prompt text. ## Testing Add regression tests and snapshots for fullscreen scrolling, caret restoration after navigation, paste and external edits, remote image navigation and deletion, resizing at scroll boundaries, and disconnected editing. GitOrigin-RevId: 9a1e4ce14b3b3747e6d136207546327531339258
## What changed Move the voice connection spinner into shared helpers in `codex-rs/tui/src/motion.rs`, keeping its 100 ms animation cadence and static reduced-motion glyph. The helpers handle frame scheduling, and `loading_glyph_with_delay` supports hiding the animated spinner until a specified delay expires. GitOrigin-RevId: c4ebe5e6a33239999aab2f4432c9145432c8f4fd
## What changed Add `codex-cloud-client`, a reusable Rust client for `ThreadService.Resume` and live `ThreadService.Attach` over HTTP/2. Callers supply the native gRPC origin, bearer token, account ID, and `HttpClientFactory`. - Reuse shared proxy, custom CA, and network policy handling for HTTPS. Reject redirects and allow plaintext HTTP only on direct loopback with unrestricted, unmanaged policy. - Preserve notification and server-request protobuf payloads as opaque bytes and expose native gRPC status details while redacting credentials, payloads, and error details from diagnostics. - Bound resume and attach setup to 150 seconds without retrying requests or imposing an idle deadline on live streams. Attach ends on its first error and provides no history or automatic reconnect. - Select Rustls in `HttpClientBuilder::http2_prior_knowledge()` so HTTPS advertises `h2` through ALPN. Include a standalone attach example and documentation of admission semantics and stream behavior. ## Testing Add HTTP/2 fixture tests for protobuf framing, authentication metadata, status trailers, event preservation, malformed responses, stream cancellation, redirect rejection, and diagnostic redaction. Add checks for unsafe origins, network policy restrictions, and TLS `h2` advertisement. GitOrigin-RevId: 55db70438bb5e59272c6995c67a46ced5fa28ff4
## What changed Add `CodexThread::current_turn_model` to return the model slug selected for the named running turn's next step, independently of settings for future turns. Return `None` when the turn ID does not match, the task is cancelled, or the turn is no longer running. ## Testing Extend the step-settings test to verify that the accessor ignores model changes for future turns, reflects active-turn model updates, and returns `None` for a mismatched ID or a completed turn. GitOrigin-RevId: 2cae7c07fa761ed4d64befaa3419a2f9bce4b161
## Why When Codex runs on Unix and launches a stdio MCP server on a Windows executor, explicit remote environment variables activate an allowlist based on Unix defaults. This can filter out Windows runtime and temporary-directory variables. ## What changed Include `SYSTEMROOT`, `TEMP`, and `TMP` in the remote environment allowlist whenever explicit remote variables are requested. ## Testing Extend the environment-filtering test to verify that `SystemRoot`, `TEMP`, and `TMP` survive alongside requested variables while unrequested secrets remain excluded. GitOrigin-RevId: 059c9e23833be66aaf5b65ba5f95013f94f0f792
## What changed Add `codex tcp-tunnel --diagnostics-json` to emit versioned, newline-delimited JSON diagnostics on stderr. Records classify startup, CONNECT, transport, and control failures without exposing credentials, addresses, headers, or raw error messages. Rejected CONNECT records may include a validated `http_status`. Distinguish terminal failures from recoverable stream and transport events, flush terminal records before returning a generic error, and preserve stdout readiness and credential acknowledgments. Keep human-readable diagnostics as the default and document the version 1 schema and consumer fallback rules. ## Testing Add tests for bounded output, error-chain suppression, terminal flushing, control error classification, CONNECT status validation, legacy behavior, and flag parsing. Extend the reconnect test to exercise a rejected CONNECT followed by a successful connection in JSON mode. GitOrigin-RevId: 350f67fe8e3f313e8a6d3bb0fd891952b77647fd
## Why Permission shortcuts checked local configuration while the picker used the connected server's catalog and requirements. Shortcuts should respect the same server restrictions, including model-specific auto-review requirements. ## What changed - Share a cached server catalog between the permission picker and shortcuts. Show the loading picker when no catalog is available and reuse an outstanding fetch. - Clear the cache on session, account, working-directory, or connection changes. - Give discovery RPCs distinct request IDs for each fetch and profile page so repeated requests after timeouts do not collide. ## Testing Add coverage for loading and catalog reuse, managed permission restrictions, and refetching after disconnect. Update timeout coverage to verify that repeated discovery attempts use distinct IDs and each reports a timeout. GitOrigin-RevId: 7d79874294136bfe3a654bb306eb7caf36d4df1e
## What changed Expose `create_worktree`, `get_worktree_creation_status`, and `list_worktrees` through MCP when the worktrees feature is enabled for a trusted local project and attachment storage is available. Support both embedded and local daemon sessions. Create worktrees asynchronously and attach them to the requesting task, with ownership and attachments retained across restarts. Default to the repository's remote default branch unless `ref` is supplied. Keep the task's working directory and execution environment unchanged, and leave uncommitted source changes in place. Reject creation in ephemeral side conversations and explicitly untrusted source projects, reuse pending operations, and reject configured MCP servers that conflict with the TUI tools namespace. ## Testing Add integration and model-request snapshot coverage for creation, polling, listing, attachment persistence across restart, task isolation, trust checks, namespace conflicts, and worker failure reporting. GitOrigin-RevId: b6a57e92cf5f6fc51fd6d4028543d6fabaf5ac49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )