Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
812 commits
Select commit Hold shift + click to select a range
df1ee09
mcp: keep elicitation requests below app wire types (#29724)
anp-oai Jun 24, 2026
24423f5
[plugins] Track plugin install requests by ID (#29684)
adaley-openai Jun 24, 2026
39aab9f
Pipeline bounded AGENTS.md and Git root probes (#29870)
jif-oai Jun 24, 2026
bb05c1f
[codex] dedupe remote control account header (#29893)
shuo-openai Jun 24, 2026
4e0f863
Add a connector declaration snapshot (#29851)
jif-oai Jun 24, 2026
81f3404
path-uri: normalize parent segments in absolute joins (#29903)
anp-oai Jun 24, 2026
9ff8068
Read connector declarations from executor plugins (#29852)
jif-oai Jun 24, 2026
134646e
Isolate curated plugin sync Git environment (#29785)
etraut-openai Jun 24, 2026
8005292
[codex] namespace sleep under clock (#29907)
rka-oai Jun 25, 2026
35f5d02
[codex] nest sleep config under current time reminder (#29910)
rka-oai Jun 25, 2026
f4e6aa7
feat(remote-control): add daemon pairing command (#29913)
apanasenko-oai Jun 25, 2026
f15df62
core: add configurable <context_window_guidance> message (#29936)
bolinfest Jun 25, 2026
a0d5fd7
TUI Plugin Sharing 5 - polish remote plugin catalog rows (#26705)
canvrno-oai Jun 25, 2026
4c0706e
Allow ChatGPT-hosted MCP servers to use session auth (#29733)
aibrahim-oai Jun 25, 2026
3e51b46
[1/3] core: make world state snapshots serializable (#29833)
sayan-oai Jun 25, 2026
6801941
TUI support for buffer experience (#29919)
etraut-openai Jun 25, 2026
f8937b7
Represent MCP authentication with an enum (#29924)
aibrahim-oai Jun 25, 2026
b3e1c33
code-mode: define process host wire protocol (#29804)
cconger Jun 25, 2026
6db9372
[codex] Populate remote plugin local versions (#29956)
abhinav-oai Jun 25, 2026
fa036d3
[2/3] core: persist world state in rollouts (#29835)
sayan-oai Jun 25, 2026
df1199f
[codex] Add Ultra reasoning effort (#29899)
shijie-oai Jun 25, 2026
a747713
[3/3] core: replay persisted world state (#29837)
sayan-oai Jun 25, 2026
cef5444
Report MCP error codes with server attribution (#29969)
aibrahim-oai Jun 25, 2026
22f1256
core: raise token budget message limits (#29970)
bolinfest Jun 25, 2026
f66d793
[codex] route sleep through time providers (#29973)
rka-oai Jun 25, 2026
51864b0
feat: use run agent task auth for inference (#19051)
adrian-openai Jun 25, 2026
f2f80ef
core: make AGENTS.md react to environment changes (#29810)
sayan-oai Jun 25, 2026
ab80d4d
core: reconcile legacy WorldState sections (#29997)
sayan-oai Jun 25, 2026
5579792
Parallelize environment skill loading (#29990)
anp-oai Jun 25, 2026
6368937
Support HTTP MCP servers from selected executor plugins (#28522)
jif-oai Jun 25, 2026
b215961
Support OAuth for HTTP MCP servers from selected executor plugins (#2…
jif-oai Jun 25, 2026
c38b2e9
Test executor-routed MCP OAuth token exchange (#29656)
jif-oai Jun 25, 2026
2683280
chore(app-server): mark thread/rollback as deprecated (#29928)
owenlin0 Jun 25, 2026
8f02973
Persist selected capability roots and resolve availability per model …
jif-oai Jun 25, 2026
2dec46e
[codex] Record exec-server lifecycle metrics (#27467)
richardopenai Jun 25, 2026
6d9dbac
feat: add provider-aware model fallback to thread start (#29942)
celia-oai Jun 25, 2026
31b99f6
cli: rename sandbox permission profile flag (#30095)
bolinfest Jun 25, 2026
cc78903
[codex] current time reminder interval to be set to 0 (#30029)
rka-oai Jun 25, 2026
c65cfea
core: expose permission profile to shell tools (#29941)
bolinfest Jun 25, 2026
e8d4a1a
[codex] add current time reminder delivery mode config (#30031)
rka-oai Jun 25, 2026
964b138
[codex] Retry temporarily offline exec-server recovery (#30098)
richardopenai Jun 25, 2026
adccb46
[codex] impl delivery_mode: current time reminders on response bounda…
rka-oai Jun 25, 2026
3b78f58
[codex] extend code-mode host IPC transport (#30108)
cconger Jun 25, 2026
3b22498
[codex] Observe remote exec-server lifecycle (#27470)
richardopenai Jun 25, 2026
62c7f50
[codex] poll external clock during sleep (#30113)
rka-oai Jun 25, 2026
703793c
feat(core, mcp): cache codex_apps tools in memory (#29003)
owenlin0 Jun 25, 2026
891f1f4
release: publish standalone zsh artifacts (#30114)
bolinfest Jun 25, 2026
e23e7cb
release: consume standalone zsh artifacts (#30116)
bolinfest Jun 25, 2026
db541f4
[codex] Add managed MCP server matchers (#29648)
felixxia-oai Jun 25, 2026
c9e6d97
Let extensions contribute World State sections (#30100)
jif-oai Jun 25, 2026
b80fbb7
fix(app-server): suppress TUI rollback warning (#30124)
fcoury-oai Jun 25, 2026
a6d20ed
[codex] Surface MCP reauthentication-required startup failures (#29877)
felixxia-oai Jun 25, 2026
e2746fd
Recognize Work web and mobile thread originators (#29988)
chiam-oai Jun 25, 2026
6c21297
[codex] add code-mode host failure supervision hooks (#30110)
cconger Jun 25, 2026
5eebeb8
Project executor skills through World State (#30088)
jif-oai Jun 25, 2026
8ce931a
[codex] Propagate traces through exec-server HTTP (#30117)
wiltzius-openai Jun 25, 2026
ee9e0f6
Pin MCP runtimes to model steps (#30101)
jif-oai Jun 25, 2026
5044062
ci: narrow Windows test skips (#30134)
anp-oai Jun 26, 2026
3095ea9
Project selected plugin runtime by environment availability (#30093)
jif-oai Jun 26, 2026
8ebf71e
Reuse walk inventory for environment skill metadata (#30145)
jif-oai Jun 26, 2026
da78d5f
[codex] implement standalone code-mode process host (#30111)
cconger Jun 26, 2026
841f305
[codex] Attribute app-server analytics by thread originator (#29935)
alexsong-oai Jun 26, 2026
723b23e
Reinject missing World State fragments on resume (#30152)
jif-oai Jun 26, 2026
fb8598d
Keep MCP elicitation routable across runtime refreshes (#30127)
jif-oai Jun 26, 2026
ec300bc
Expose MCP app identity in app context (#29934)
martinauyeung-oai Jun 26, 2026
0d4351c
[codex] allow CCA image generation and web search extensions (#29909)
won-openai Jun 26, 2026
25f50de
Test selected capabilities across availability and resume (#30157)
jif-oai Jun 26, 2026
f5f8123
[codex] fix terminal rollout event durability (#30144)
wiltzius-openai Jun 26, 2026
92d2e1d
Retry failed Codex Apps MCP startup (#29920)
kbazzi Jun 26, 2026
b5866ee
Persist Cloudflare affinity cookies for MCP HTTP (#29516)
stevenlee-oai Jun 26, 2026
ab16046
[codex] add process-owned code-mode session client (#30112)
cconger Jun 26, 2026
7d8906b
[codex] wire process-owned code mode host into core (#30142)
cconger Jun 26, 2026
451c0a4
[codex] fix CreateThreadParams test initializer (#30198)
anp-oai Jun 26, 2026
6d2168f
Reuse MCP runtimes when selected availability changes nothing (#30148)
jif-oai Jun 26, 2026
3c03bb4
Test selected capabilities across unavailable resume (#30215)
jif-oai Jun 26, 2026
914c8ee
[codex] narrow unused skills intro export (#29991)
aibrahim-oai Jun 26, 2026
2c5bc5e
Relax hooks.json top-level metadata validation (#30229)
charlesgong-openai Jun 26, 2026
5267e80
feat(app-server): add history_mode to thread (#29927)
owenlin0 Jun 26, 2026
f913343
fix main (#30276)
owenlin0 Jun 26, 2026
d9cf931
[codex] Add managed new-thread model settings (#29683)
hefuc-oai Jun 26, 2026
a938d5f
Overlap executor skill reads with namespace discovery (#30225)
jif-oai Jun 26, 2026
79a8ffd
[codex] allow AGENTS.md and skills to authorize delegation (#30274)
charlesdu-openai Jun 26, 2026
cf36c68
[codex] Use managed defaults for TUI threads (#30147)
hefuc-oai Jun 26, 2026
812cd2b
ensure thread.history_mode is immutable (#30261)
owenlin0 Jun 26, 2026
f72976a
feat(app-server): add optional turn_id to thread/fork (#30277)
owenlin0 Jun 26, 2026
ac85409
Let Codex consult user-level code-review-* skills. (#30143)
anp-oai Jun 26, 2026
69596f0
feat: add GPT-5.6 variants to Bedrock catalog (#30285)
celia-oai Jun 26, 2026
c55ce3b
Close thread persistence when submission channel closes (#30173)
alfozan Jun 26, 2026
526f495
[codex] Classify nested MCP authentication startup errors (#30257)
felixxia-oai Jun 26, 2026
6509f31
[codex] Support npm marketplace plugin sources (#29375)
charlesgong-openai Jun 26, 2026
1168254
[codex] group blocking and postmerge CI workflows (#30146)
anp-oai Jun 26, 2026
a107b84
feat(protocol): define missing rollout turn items (#30282)
owenlin0 Jun 26, 2026
d047c33
fix(remote-control): avoid server token refresh retry storms (#30201)
apanasenko-oai Jun 27, 2026
d4ec08b
[codex] consume pushed exec-server process events (#30273)
richardopenai Jun 27, 2026
3ae0543
core: overlap diff root discovery with world state (#30286)
anp-oai Jun 27, 2026
4f1b5a4
app-server: structure and test JSON shutdown logs (#30314)
bolinfest Jun 27, 2026
c464468
Update security check wording (#30317)
etraut-openai Jun 27, 2026
328e951
Preserve namespaces on custom tool calls (#30302)
nhamidi-oai Jun 27, 2026
d2885dc
core: stabilize synthesized call output IDs (#30327)
bolinfest Jun 27, 2026
e2398d0
[app-server] expose environment info RPC (#30291)
maxj-oai Jun 27, 2026
9dbdb4e
[plugins] Enforce marketplace source policy at runtime (#29691)
xl-openai Jun 27, 2026
bdd282f
[app-server] increase currentTime/read timeout (#30384)
rka-oai Jun 27, 2026
e428a12
[codex] Enable remote plugins by default (#30297)
xl-openai Jun 28, 2026
850da19
fix(tui): clear completed safety buffering prompt (#30490)
fcoury-oai Jun 28, 2026
6b5f574
[codex] Use model metadata for skills usage instructions (#29740)
ani-oai Jun 29, 2026
8dac605
[codex] Restore v1 delegation guidance (#30511)
aibrahim-oai Jun 29, 2026
ccdfb4f
Revert "Make auto-review on-request prompt more proactive" (#30508)
dylan-hurd-oai Jun 29, 2026
80f54d1
[codex] Treat max as a first-class reasoning effort (#30467)
shijie-oai Jun 29, 2026
9d13291
Update safety check links (#30491)
etraut-openai Jun 29, 2026
4808c16
[codex] auto-label AWS Bedrock issues (#30607)
etraut-openai Jun 29, 2026
cfead68
[codex] disable Nagle on Rendezvous WebSockets (#30269)
richardopenai Jun 30, 2026
0208281
[codex] Update safety notice wording (#30645)
etraut-openai Jun 30, 2026
db887d0
fix(core) Remove full text websocket trace (#30757)
dylan-hurd-oai Jun 30, 2026
d059658
docs: add tag to fenced code block (#30851)
bolinfest Jul 1, 2026
042e617
[codex] bound Rendezvous WebSocket liveness (#30643)
richardopenai Jul 1, 2026
a98a217
Consolidate multi-agent v2 communication sends (#30867)
bolinfest Jul 2, 2026
129ea2a
Log multi-agent communication lifecycle (#30872)
bolinfest Jul 2, 2026
6ff670b
[codex] emit per-request TTFT completion telemetry (#30883)
xli-oai Jul 2, 2026
cbdd7f0
Fix inherited availability metadata for Bedrock models (#30897)
shijie-oai Jul 2, 2026
0ccb676
fix: address quick-xml security advisories (#30941)
bolinfest Jul 2, 2026
b35d4b6
fix(websockets) ignore metadata for incremental requests (#30770)
dylan-hurd-oai Jul 2, 2026
beca198
telemetry: log structured direct tool-call timing (#30334)
bolinfest Jul 2, 2026
da4c8ca
[codex] Add configurable multi-agent mode hint text (#30493)
shijie-oai Jul 3, 2026
1f17e75
Fix MIME types for path-backed feedback attachments (#30796)
btraut-openai Jul 3, 2026
319d030
fix(install): reuse GitHub release metadata (#31056)
bolinfest Jul 3, 2026
d206a5d
[codex] expose remote plugin versions (#30981)
ericning-o Jul 3, 2026
98d28aa
chore: remove unused git-cliff configuration (#31066)
bolinfest Jul 4, 2026
be33f80
[codex] Read buffering metadata from response events (#31064)
fc-oai Jul 5, 2026
9c5be7e
Make plugin guidance react to environment readiness (#30223)
sayan-oai Jul 6, 2026
bce481f
Fix cancelled review leaving MCP startup busy (#31189)
charliemarsh-oai Jul 6, 2026
8917244
[core] Support interleaved response items (#30876)
alexi-openai Jul 6, 2026
7094fa4
[codex] Read retry model from buffering events (#31262)
fc-oai Jul 6, 2026
7b4e70d
Revert "[core] Support interleaved response items" (#31261)
alexi-openai Jul 6, 2026
dbf67f3
Emit exec-policy warnings for freshly loaded thread config (#31253)
etraut-openai Jul 6, 2026
8f5bb61
Remove TUI exec-policy core exports (#31179)
etraut-openai Jul 6, 2026
8268cbf
Conditional codex_home dotenv (#29959)
canvrno-oai Jul 6, 2026
84fe70c
elicitations: Move to shared ElicitationService (#30627)
cconger Jul 6, 2026
a86d525
core: trace executor skill discovery (#30318)
anp-oai Jul 6, 2026
2e20d2e
Revert "Conditional codex_home dotenv" (#31276)
canvrno-oai Jul 6, 2026
7affe3e
refactor(protocol): isolate legacy item fanout (#30956)
owenlin0 Jul 6, 2026
58ec528
[app-server] Include reset-credit details in rate limits (#30395)
jayp-oai Jul 6, 2026
aa94ea1
chore(approvals) consolidate guardian calls for shell tools (#31267)
dylan-hurd-oai Jul 6, 2026
02868b9
[tui] Truncate hook context in conversation history (#31252)
abhinav-oai Jul 6, 2026
c976741
[codex] Flush trailing realtime transcript tail (#29918)
guinness-oai Jul 6, 2026
3c2bfe7
Make Apps guidance react to MCP availability (#30226)
sayan-oai Jul 6, 2026
d847857
Use popup token ranges for autocomplete insertion (#31190)
charliemarsh-oai Jul 6, 2026
1013295
fix: attribut network requests to the exact exec on linux (#29697)
jif-oai Jul 6, 2026
d61ad78
feat(code-mode): allow disabling V8 JIT (#31303)
cconger Jul 6, 2026
9e24996
chore: use .worktreeinclude for user Bazel config (#31271)
anp-oai Jul 6, 2026
9732b40
fix: update crossbeam-epoch for RUSTSEC-2026-0204 (#31308)
cconger Jul 6, 2026
3f61570
[codex] bundle code mode host in release packages (#30202)
cconger Jul 6, 2026
c71895f
[codex] app-server: expose plugin install policy source (#31293)
ericning-o Jul 7, 2026
7226904
ci: share common workflow setup (#31318)
anp-oai Jul 7, 2026
8a18312
app-server: cover selected environments in integration tests (#29992)
anp-oai Jul 7, 2026
45be435
Warn when configured service tiers are unsupported (#31284)
etraut-openai Jul 7, 2026
9acfe89
Extract shared HTTP transport into codex-http-client (#31323)
bolinfest Jul 7, 2026
641aa1b
Migrate direct HTTP consumers to codex-http-client (#31331)
bolinfest Jul 7, 2026
8f34310
fix: restore Codex environment setup table (#31337)
anp-oai Jul 7, 2026
831c14f
Preserve managed exec policy after rules parse errors (#31188)
etraut-openai Jul 7, 2026
775ef7d
[codex] Support sequential cutoff reasoning summaries (#31306)
ashwinnathan-openai Jul 7, 2026
9365b08
exec-server: use virtual time in Noise relay test (#31344)
bolinfest Jul 7, 2026
b9b934e
refactor(protocol): map canonical tool items to legacy events (#31296)
owenlin0 Jul 7, 2026
6afcf26
core: route Responses API through system proxy (#31335)
bolinfest Jul 7, 2026
6cf42cf
Serialize shared MCP OAuth credential stores (#30292)
stevenlee-oai Jul 7, 2026
d7ab20c
[codex-cli] Show reset details in redemption picker (#30488)
jayp-oai Jul 7, 2026
cca16a1
feat(core): emit canonical command execution items (#31297)
owenlin0 Jul 7, 2026
f659eb1
feat(core): emit canonical dynamic tool call items (#31298)
owenlin0 Jul 7, 2026
42156ba
test(skills): cover plugin namespace loading (#31369)
anp-oai Jul 7, 2026
f363ed7
fix(release): add missing Intel V8 signing entitlement (#30953)
malsamiri-oai Jul 7, 2026
a3f8b0b
refactor: make ExternalAuth return CodexAuth (#31355)
lt-oai Jul 7, 2026
8841f50
ci: increase Windows Bazel local test jobs (#31352)
anp-oai Jul 7, 2026
f6e251c
[codex-rs] Add writes app approval mode (#30482)
zamoshchin-openai Jul 7, 2026
78df123
Handle bio policy errors in Codex (#31439)
fc-oai Jul 7, 2026
1345c16
[codex] add connector runtime latency metrics (#31319)
mzeng-openai Jul 7, 2026
3585754
Use model catalog approval messages (#31312)
dylan-hurd-oai Jul 7, 2026
f158b31
test: generalize exec-server fixture (#31422)
anp-oai Jul 7, 2026
ff06ab7
[codex] Enable auth elicitation by default (#28772)
mzeng-openai Jul 7, 2026
1fd0858
[login] support hosted success redirects (#28745)
rafael-jac Jul 7, 2026
1f710c9
chore: extract remote compaction request attempts (#31316)
celia-oai Jul 7, 2026
1bd9d84
feat(core): emit canonical sub-agent activity items (#31299)
owenlin0 Jul 7, 2026
777f5da
[1/5] [codex] sync managed-layer bundle schema (#31285)
hefuc-oai Jul 7, 2026
058d97c
feat(core): emit canonical collab tool call items (#31300)
owenlin0 Jul 7, 2026
6b48825
feat(core): emit canonical collab wait items (#31301)
owenlin0 Jul 7, 2026
172ab26
fix: retry rejected previous-model compaction with selected model (#3…
celia-oai Jul 7, 2026
9deb4f9
Handle mixed-case URLs in Windows command safety (#30879)
charliemarsh-oai Jul 7, 2026
2589f7a
Handle completion separators and popup dismissal (#31191)
charliemarsh-oai Jul 7, 2026
9222493
test: add TestAppServer builder (#31425)
anp-oai Jul 7, 2026
8139255
http-client: expose WebSocket proxy prerequisites (#31342)
bolinfest Jul 7, 2026
58b66d3
perf(skills): resolve plugin namespaces per root (#31348)
anp-oai Jul 7, 2026
07d6318
Use canonical indexed web access field (#31289)
winston-openai Jul 7, 2026
49f5cb0
Speed up review branch picker via `for-each-ref` (#31464)
charliemarsh-oai Jul 8, 2026
77b766c
ci: parameterize Cargo target paths (#31332)
anp-oai Jul 8, 2026
e60af81
refactor: unify external auth resolution (#31421)
pakrym-oai Jul 8, 2026
dbd2df2
test: migrate TestAppServer callers to builder (#31451)
anp-oai Jul 8, 2026
c4d748f
## New Features
owenlin0 Jul 8, 2026
8784de4
[codex] Add externally provided Codex auth (#31274)
lt-oai Jul 8, 2026
f8d07b5
trace hook command execution (#31501)
wiltzius-openai Jul 8, 2026
aaa30f7
ci: run V8 source builds on Windows 2025 (#31356)
anp-oai Jul 8, 2026
f1affba
core: support extension-owned turn items (#31283)
owenlin0 Jul 8, 2026
a52b35f
fs: support pruning hidden directories during walks (#31570)
jif-oai Jul 8, 2026
6849549
Align empty branch list message with search (#31465)
charliemarsh-oai Jul 8, 2026
8dfd397
Stabilize encrypted MAv2 spawn request test (#31586)
jif-oai Jul 8, 2026
f17a57b
Stabilize remote compaction parity against dynamic skill catalogs (#3…
jif-oai Jul 8, 2026
1ee0e9a
Log plugin install failure subtypes (#31518)
charlesgong-openai Jul 8, 2026
0bbea86
Stabilize shared rollout budget test (#31587)
jif-oai Jul 8, 2026
e212cc9
Detect Codex installs managed by pnpm (#31503)
charliemarsh-oai Jul 8, 2026
a219b6f
core: migrate standalone web search to extension-owned turn items (#3…
owenlin0 Jul 8, 2026
23aac92
feat(core): emit canonical review mode items (#31473)
owenlin0 Jul 8, 2026
f73a072
test: remove TestAppServer constructors (#31452)
anp-oai Jul 8, 2026
48cf582
Round MCP timeout durations in error messages (#31612)
jif-oai Jul 8, 2026
166534f
fix(windows-sandbox): allow deletion in writable roots (#31138)
fcoury-oai Jul 8, 2026
9c67159
code-mode: move to hosted mode by default (#31500)
cconger Jul 8, 2026
9077300
tui: sanitize terminal controls in user messages (#31494)
etraut-openai Jul 8, 2026
154433c
chore(protocol): use UUIDv7 for generated item IDs (#31524)
owenlin0 Jul 8, 2026
8d83687
Fall back to HTTP when Apple Git is unavailable (#31496)
fc-oai Jul 8, 2026
a14b4c2
Bound exec-server pending RPCs (#31578)
jif-oai Jul 8, 2026
1d14221
[codex] Sanitize imported session fallback titles (#29875)
stefanstokic-oai Jul 8, 2026
927004c
tui: warn on Ultra with high multi-agent concurrency (#31621)
shijie-oai Jul 8, 2026
2780bd5
websocket-client: add proxy-aware connector (#31622)
bolinfest Jul 8, 2026
c6b124b
[codex] Grant Windows sandbox access to primary runtime (#31574)
abhinav-oai Jul 8, 2026
bdaad68
Reuse MCP tool snapshot within a sampling request (#31292)
sayan-oai Jul 8, 2026
ba5dd1f
feat(core): emit canonical hook prompt items (#31630)
owenlin0 Jul 8, 2026
bff9c49
feat: change amazon Bedrock GPT-5.6 display names (#31636)
celia-oai Jul 8, 2026
602dbb4
core: stop emitting legacy command events directly (#31629)
owenlin0 Jul 8, 2026
e621d7d
core: preserve Responses WebSockets with system proxy (#31441)
bolinfest Jul 8, 2026
bd5c860
ci: route build IO through Dev Drives (#31357)
anp-oai Jul 8, 2026
4b64bf0
chore: remove inert cargo audit workflow (#31461)
anp-oai Jul 8, 2026
5c7624a
test: migrate app-server v2 starts to auto env (#31614)
anp-oai Jul 8, 2026
b6f9aee
[codex] increase tool schema compaction threshold (#31497)
fbauer33 Jul 8, 2026
c55cb4b
code-mode: make all approvals trigger elicitation pause (#31650)
cconger Jul 8, 2026
f3bfaca
Clarify device-code phishing warning (#31648)
etraut-openai Jul 8, 2026
4e270dd
test(app-server): use native rollout fixture paths (#31663)
fcoury-oai Jul 8, 2026
a09a7c4
[codex-apps] Omit internal fields from file payloads (#31330)
jacobzhou-oai Jul 8, 2026
3eb5653
Update auto review prompting (#31480)
olliem-oai Jul 8, 2026
b780738
Update models.json (#21818)
github-actions[bot] Jul 8, 2026
3fa9066
test: add delayed exec-server transport (#31427)
anp-oai Jul 9, 2026
0746e8a
[codex] Preserve reviewer when resuming threads (#30278)
viyatb-oai Jul 9, 2026
20e5edf
Expand agent core ownership (#31675)
pakrym-oai Jul 9, 2026
555aa79
[connectors] Refresh codex_apps /ps/mcp auth (#31486)
stevenlee-oai Jul 9, 2026
5892c7b
model-provider: route model discovery through HTTP client factory (#3…
bolinfest Jul 9, 2026
2342b2c
feat(rollout): persist TurnItems for paginated thread rollouts (#30188)
owenlin0 Jul 9, 2026
a7c72ae
Use the image generation extension by default (#31596)
won-openai Jul 9, 2026
3380969
Update models.json (#31684)
github-actions[bot] Jul 9, 2026
7678224
## New Features
aibrahim-oai Jul 9, 2026
63f6a39
Record upstream rust-v0.143.0 ancestry
dkropachev Jul 28, 2026
0e8d163
Merge tag 'rust-v0.144.0' into sync/upstream-rust-v0.144.0-main-20260728
dkropachev Jul 28, 2026
dd2cfcd
Fix rust-v0.144.0 sync conflicts
dkropachev Jul 28, 2026
86f8f59
Fix CI validation for rust-v0.144.0 sync
dkropachev Jul 28, 2026
99c048c
Fix Bazel validation for rust-v0.144.0 sync
dkropachev Jul 28, 2026
69242f5
codex: reject workflow commands during active turns
dkropachev Jul 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .bazelrc
Original file line number Diff line number Diff line change
Expand Up @@ -190,7 +190,7 @@ common:ci-windows-cross --strategy=TestRunner=local
# V8 embeds IsolateData offsets in snapshot builtins; Windows snapshots must be
# generated by a Windows mksnapshot binary rather than the Linux RBE host tool.
common:ci-windows-cross --strategy=V8Mksnapshot=local
common:ci-windows-cross --local_test_jobs=4
common:ci-windows-cross --local_test_jobs=8
common:ci-windows-cross --test_env=RUST_TEST_THREADS=1
# Native Windows CI still covers the PowerShell parser-process tests. The
# cross-built gnullvm binaries currently hang in those tests when run on the
Expand Down
3 changes: 3 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
# Core crate ownership.
/codex-rs/arg0/ @openai/codex-core-agent-team
/codex-rs/codex-mcp/ @openai/codex-core-agent-team
/codex-rs/core/ @openai/codex-core-agent-team
/codex-rs/exec-server/ @openai/codex-core-agent-team
/codex-rs/exec-server-protocol/ @openai/codex-core-agent-team
/codex-rs/ext/extension-api/ @openai/codex-core-agent-team
/codex-rs/prompts/ @openai/codex-core-agent-team
Expand Down
26 changes: 6 additions & 20 deletions .github/actions/setup-bazel-ci/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,38 +12,24 @@ outputs:
runs:
using: composite
steps:
- uses: ./.github/actions/setup-ci
- id: setup_ci
uses: ./.github/actions/setup-ci

- name: Set up Bazel
uses: bazel-contrib/setup-bazel@c5acdfb288317d0b5c0bbd7a396a3dc868bb0f86 # 0.19.0
# Without an explicit Bazelisk version, setup-bazel leaves PATH unchanged
# and Windows can use the runner's standalone Bazel, ignoring .bazelversion.
with:
bazelisk-version: 1.28.1
# setup-bazel writes an explicit output_base, which otherwise overrides
# BAZEL_OUTPUT_USER_ROOT and leaves Bazel's I/O-heavy trees on C:.
output-base: ${{ steps.setup_ci.outputs.bazel-output-base }}

- name: Configure Bazel repository cache
id: configure_bazel_repository_cache
shell: pwsh
run: |
# Keep the repository cache under HOME on all runners. Windows `D:\a`
# cache paths match `.bazelrc`, but `actions/cache/restore` currently
# returns HTTP 400 for that path in the Windows clippy job.
$repositoryCachePath = Join-Path $HOME '.cache/bazel-repo-cache'
"repository-cache-path=$repositoryCachePath" | Out-File -FilePath $env:GITHUB_OUTPUT -Encoding utf8 -Append
"BAZEL_REPOSITORY_CACHE=$repositoryCachePath" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append

- name: Configure Bazel output root (Windows)
if: runner.os == 'Windows'
shell: pwsh
run: |
# Use the shortest available drive to reduce argv/path length issues,
# but avoid the drive root because some Windows test launchers mis-handle
# MANIFEST paths there.
$hasDDrive = Test-Path 'D:\'
$bazelOutputUserRoot = if ($hasDDrive) { 'D:\b' } else { 'C:\b' }
$repoContentsCache = Join-Path $env:RUNNER_TEMP "bazel-repo-contents-cache-$env:GITHUB_RUN_ID-$env:GITHUB_JOB"
"BAZEL_OUTPUT_USER_ROOT=$bazelOutputUserRoot" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
"BAZEL_REPO_CONTENTS_CACHE=$repoContentsCache" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
"repository-cache-path=$env:BAZEL_REPOSITORY_CACHE" | Out-File -FilePath $env:GITHUB_OUTPUT -Encoding utf8 -Append

- name: Expose MSVC SDK environment (Windows)
if: runner.os == 'Windows'
Expand Down
58 changes: 58 additions & 0 deletions .github/actions/setup-ci/action.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,67 @@
name: setup-ci
description: Prepare common tools and environment shared by CI jobs.
outputs:
bazel-output-base:
description: Filesystem path used for Bazel's output base.
value: ${{ steps.configure_ci_build_paths.outputs.bazel-output-base }}
cargo-target-dir:
description: Filesystem path used for Cargo's target directory.
value: ${{ steps.configure_ci_build_paths.outputs.cargo-target-dir }}

runs:
using: composite
steps:
# setup-ci expects either this step or the Unix fallback below to define
# CI_BUILD_ROOT. Windows puts it on a Dev Drive because Cargo and Bazel
# spend significant time reading and writing build/cache trees.
- name: Configure Dev Drive (Windows)
if: runner.os == 'Windows'
shell: pwsh
run: ./.github/scripts/setup-dev-drive.ps1

- name: Configure CI build root (Unix)
if: runner.os != 'Windows'
shell: bash
run: echo "CI_BUILD_ROOT=$HOME/.cache/codex-ci" >> "$GITHUB_ENV"

- name: Configure CI build paths
id: configure_ci_build_paths
shell: bash
run: |
set -euo pipefail
# setup-bazel passes output_base explicitly, so keep both it and the
# user root under the shared build root. Keep these directory names tiny
# on every platform so Windows Bazel paths do not overflow argv or
# confuse test MANIFEST handling.
bazel_output_base="$CI_BUILD_ROOT/o"
bazel_output_user_root="$CI_BUILD_ROOT/b"
bazel_repository_cache="$CI_BUILD_ROOT/bazel-repository-cache"
bazel_repo_contents_cache="$CI_BUILD_ROOT/bazel-repo-contents-cache-$GITHUB_RUN_ID-$GITHUB_JOB"
cargo_target_dir="$CI_BUILD_ROOT/cargo-target"
tmp="$CI_BUILD_ROOT/tmp"

build_dirs=(
"$bazel_output_base"
"$bazel_output_user_root"
"$bazel_repository_cache"
"$bazel_repo_contents_cache"
"$cargo_target_dir"
"$tmp"
)
mkdir -p "${build_dirs[@]}"
echo "bazel-output-base=$bazel_output_base" >> "$GITHUB_OUTPUT"
echo "cargo-target-dir=$cargo_target_dir" >> "$GITHUB_OUTPUT"

{
echo "BAZEL_OUTPUT_BASE=$bazel_output_base"
echo "BAZEL_OUTPUT_USER_ROOT=$bazel_output_user_root"
echo "BAZEL_REPOSITORY_CACHE=$bazel_repository_cache"
echo "BAZEL_REPO_CONTENTS_CACHE=$bazel_repo_contents_cache"
echo "CARGO_TARGET_DIR=$cargo_target_dir"
echo "TEMP=$tmp"
echo "TMP=$tmp"
} >> "$GITHUB_ENV"

- name: Prefer the Git CLI for Cargo git dependencies
shell: bash
run: echo "CARGO_NET_GIT_FETCH_WITH_CLI=true" >> "$GITHUB_ENV"
Expand Down
2 changes: 1 addition & 1 deletion .github/actions/windows-code-sign/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ runs:
{
echo "files<<EOF"
for binary in ${BINARIES}; do
echo "${GITHUB_WORKSPACE}/codex-rs/target/${TARGET}/release/${binary}.exe"
echo "${CARGO_TARGET_DIR}/${TARGET}/release/${binary}.exe"
done
echo "EOF"
} >> "$GITHUB_OUTPUT"
Expand Down
10 changes: 10 additions & 0 deletions .github/scripts/macos-signing/codex-app-server.entitlements.plist
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>com.apple.security.cs.allow-jit</key>
<true/>
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
<true/>
</dict>
</plist>
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>com.apple.security.cs.allow-jit</key>
<true/>
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
<true/>
</dict>
</plist>
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>com.apple.security.cs.allow-jit</key>
<true/>
</dict>
</plist>
2 changes: 2 additions & 0 deletions .github/scripts/macos-signing/codex.entitlements.plist
Original file line number Diff line number Diff line change
Expand Up @@ -4,5 +4,7 @@
<dict>
<key>com.apple.security.cs.allow-jit</key>
<true/>
<key>com.apple.security.cs.allow-unsigned-executable-memory</key>
<true/>
</dict>
</plist>
59 changes: 44 additions & 15 deletions .github/scripts/run_bazel_with_buildbuddy.py
Original file line number Diff line number Diff line change
Expand Up @@ -131,25 +131,54 @@ def bazel_args_without_remote_execution(args: Sequence[str]) -> list[str]:
def bazel_args_with_remote_config(
args: Sequence[str], env: Mapping[str, str]
) -> list[str]:
command_idx = next(
(idx for idx, arg in enumerate(args) if not arg.startswith("-")),
None,
)
if command_idx is None:
raise ValueError("expected a Bazel command")

config = remote_config(args, env)
if config is None:
return bazel_args_without_remote_execution(args)
configured_args = bazel_args_without_remote_execution(args)
else:
# `remote_config()` returns a configuration only when this key is present.
api_key = env["BUILDBUDDY_API_KEY"]
remote_args = [
f"--config={config}",
f"--remote_header=x-buildbuddy-api-key={api_key}",
]

# Insert immediately after the Bazel command. This keeps wrapper-added
# options out of positional payloads and lets later CI configs override
# shared RBE defaults such as the Windows cross-compilation exec platforms.
configured_args = [
*args[: command_idx + 1],
*remote_args,
*args[command_idx + 1 :],
]

# `remote_config()` returns a configuration only when this key is present.
api_key = env["BUILDBUDDY_API_KEY"]
remote_args = [
f"--config={config}",
f"--remote_header=x-buildbuddy-api-key={api_key}",
]
try:
separator_idx = configured_args.index("--")
except ValueError:
separator_idx = len(configured_args)

# Insert immediately after the Bazel command. This keeps wrapper-added
# options out of positional payloads and lets later CI configs override
# shared RBE defaults such as the Windows cross-compilation exec platforms.
insertion_idx = next(
(idx + 1 for idx, arg in enumerate(args) if not arg.startswith("-")),
len(args),
)
return [*args[:insertion_idx], *remote_args, *args[insertion_idx:]]
cache_args = [
f"{option_prefix}{env[env_name]}"
for env_name, option_prefix in (
("BAZEL_REPO_CONTENTS_CACHE", "--repo_contents_cache="),
("BAZEL_REPOSITORY_CACHE", "--repository_cache="),
)
if env.get(env_name)
and not any(
arg.startswith(option_prefix) for arg in configured_args[:separator_idx]
)
]
return [
*configured_args[:separator_idx],
*cache_args,
*configured_args[separator_idx:],
]


def bazel_command(*args: str, env: Mapping[str, str] | None = None) -> list[str]:
Expand Down
18 changes: 12 additions & 6 deletions .github/scripts/rusty_v8_bazel.py
Original file line number Diff line number Diff line change
Expand Up @@ -258,21 +258,27 @@ def stage_artifacts(
print(staged_checksums)


def upstream_release_pair_paths(source_root: Path, target: str) -> tuple[Path, Path]:
def upstream_release_pair_paths(
target: str,
target_dir: Path,
) -> tuple[Path, Path]:
lib_name = (
"rusty_v8.lib" if target.endswith("-pc-windows-msvc") else "librusty_v8.a"
)
gn_out = source_root / "target" / target / "release" / "gn_out"
gn_out = target_dir / target / "release" / "gn_out"
return gn_out / "obj" / lib_name, gn_out / "src_binding.rs"


def stage_upstream_release_pair(
source_root: Path,
target: str,
output_dir: Path,
target_dir: Path,
sandbox: bool = False,
) -> None:
lib_path, binding_path = upstream_release_pair_paths(source_root, target)
lib_path, binding_path = upstream_release_pair_paths(
target,
target_dir,
)
stage_artifacts(target, lib_path, binding_path, output_dir, sandbox)


Expand Down Expand Up @@ -330,7 +336,7 @@ def parse_args() -> argparse.Namespace:
"stage-upstream-release-pair"
)
stage_upstream_release_pair_parser.add_argument(
"--source-root", type=Path, required=True
"--target-dir", type=Path, required=True
)
stage_upstream_release_pair_parser.add_argument("--target", required=True)
stage_upstream_release_pair_parser.add_argument("--output-dir", required=True)
Expand Down Expand Up @@ -373,9 +379,9 @@ def main() -> int:
return 0
if args.command == "stage-upstream-release-pair":
stage_upstream_release_pair(
source_root=args.source_root,
target=args.target,
output_dir=Path(args.output_dir),
target_dir=args.target_dir,
sandbox=args.sandbox,
)
return 0
Expand Down
37 changes: 19 additions & 18 deletions .github/scripts/setup-dev-drive.ps1
Original file line number Diff line number Diff line change
@@ -1,14 +1,15 @@
# Configure a fast drive for Windows CI jobs.
#
# GitHub-hosted Windows runners do not always expose a secondary D: volume. When
# they do not, try to create a Dev Drive VHD and fall back to C: if the runner
# image does not allow that provisioning path.
# they do not, create a Dev Drive VHD. CI depends on this path for its
# build directories where CI spends significant time doing I/O, so fail the
# job if no real Dev Drive is available.

function Use-FallbackDrive {
param([string]$Reason)
function Test-DevDrive {
param([string]$Drive)

Write-Warning "$Reason Falling back to C:"
return "C:"
& fsutil devdrv query $Drive *> $null
return $LASTEXITCODE -eq 0
}

function Invoke-BestEffort {
Expand All @@ -21,10 +22,14 @@ function Invoke-BestEffort {
}
}

if (Test-Path "D:\") {
Write-Output "Using existing drive at D:"
if ((Test-Path "D:\") -and (Test-DevDrive "D:")) {
Write-Output "Using existing Dev Drive at D:"
$Drive = "D:"
} else {
if (Test-Path "D:\") {
Write-Output "Existing D: volume is not a Dev Drive; provisioning a new Dev Drive VHD."
}

try {
$VhdPath = Join-Path $env:RUNNER_TEMP "codex-dev-drive.vhdx"
$SizeBytes = 64GB
Expand All @@ -42,21 +47,17 @@ if (Test-Path "D:\") {

$Drive = "$($Volume.DriveLetter):"

if (-not (Test-DevDrive $Drive)) {
throw "Provisioned volume at $Drive did not pass Dev Drive verification."
}

Invoke-BestEffort { fsutil devdrv trust $Drive } "Trusting Dev Drive $Drive"
Invoke-BestEffort { fsutil devdrv enable /disallowAv } "Disabling AV filter attachment for Dev Drives"
Invoke-BestEffort { fsutil devdrv query $Drive } "Querying Dev Drive $Drive"

Write-Output "Using Dev Drive at $Drive"
} catch {
$Drive = Use-FallbackDrive "Failed to create Dev Drive: $($_.Exception.Message)"
throw "Failed to create Dev Drive: $($_.Exception.Message)"
}
}

$Tmp = "$Drive\codex-tmp"
New-Item -Path $Tmp -ItemType Directory -Force | Out-Null

@(
"DEV_DRIVE=$Drive"
"TMP=$Tmp"
"TEMP=$Tmp"
) | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
"CI_BUILD_ROOT=$Drive" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
Loading
Loading