Skip to content

Releases: Dirard/codex

Codex fork 0.162.0

Choose a tag to compare

@Dirard Dirard released this 09 Oct 01:26

Codex fork 0.162.0

This main-based fork release follows fork 0.160.0. It is not a byte-for-byte rebuild of OpenAI's official 0.162.0 release. It includes the preserved fork runtime, matching Go SDK, and five verified platform packages.

Comparison and source

  • Previous fork runtime and SDK source: 54fc12f7aa, published as 0.160.0.
  • Previous pinned base: 2cf9b0875a. New pinned local merge base: 5a2a6eacc62e897edcf7aa2d4d544100aefffc3f, combining observed origin/main@2af3fe862d with OpenAI main@515c291d87. The local merge retains this fork's release-workflow customization; it does not change OpenAI main.
  • Official OpenAI 0.162.0 was published 2026-10-08 at 18:55:59 UTC. Its tag object is 1f3f93473394b620b35580859b7e6864f7a9f948, peeling to c1382380de. This fork follows the pinned main-based history, not that official release branch.
  • Reviewed semantic source: cc065ef0a4. Independent product and engineering review found no blocking or non-blocking findings. Version-stamped 0.162.0 source: 045ae853a9, pushed with an exact lease. The single pinned five-target build was dispatched on 2026-10-08 at 22:49:29 UTC and all five jobs succeeded by 2026-10-09 at 01:14:27 UTC. Matching annotated rust-v0.162.0 and sdk/go/v0.162.0 tags both point to this exact release source.

The upstream section below covers all 220 non-merge commits between the pinned bases in git log order, not every change on OpenAI's official 0.162.0 release branch. Exact commit links follow at the end.

Upstream changes since fork 0.160.0

Agents, context, and history

  • Agent state and capabilities survive more idle-unload, navigation, and fork scenarios; shutdown failures have bounded diagnostics. Upstream removes partial-history subagent forks. fork_turns now advertises all or none; numeric strings are legacy aliases for full history, not a last-N-turns mode.
  • Turn lineage is exposed and persisted across app-server turns, queued mail, recovery, compaction, and host-owned Apps calls. Subagent activity records resolved model and reasoning effort; partial assistant answers gain a message phase and consistent handling in agent workflows, realtime routing, and thread search.
  • Compaction replacement history installs full captured context. Context parts gain source attribution, Guardian sender context can be recovered from persistence, and tool-call metadata preserves completeness even when large recorded arguments are truncated. Fork-specific raw replay, originating truncation, compaction headroom, and cache behavior were reconciled with this full-context format.

Code Mode, MCP, app-server, and security

  • JavaScript Code Mode gains ranked discovery, description-first ordering, promise settlement streaming helpers, default interruption, and gRPC session recovery. Incremental tool updates distinguish namespace removals and preserve base-instruction history.
  • Guardian gains opt-in trust for orchestrator connector identities, concurrent conversation classification with ordered actions, checkpoint recovery, retained sender context, stricter assessment parsing, and issuing-step context for MCP elicitation reviews. MCP and environment handling adds required-skill checks, selected-environment context, verified sandbox-launcher exposure, and clearer verification failures.
  • App-server protocol additions include thread/list.excludedThreadIds, turn parentTurnId/rootTurnId lineage, subagent model/effort, independent Fast/Ultra Fast requirements, browser-extension request headers, environment WebSocket request IDs and required skills, and an opaque misalignment review target. Experimental prediction forks can inherit parent context; that is opt-in protocol behavior, not a default fork mode.
  • Application network policy is enforced for daemon updates and standalone MCP commands; proxy DNS checks authorize hostnames first. Sandbox integrity checks, MXC policy/SDK updates, and Windows sandbox fixes also landed. These upstream security controls must not be weakened during fork reconciliation.

Terminal UI, daemon, platform, and build

  • TUI updates include clickable wrapped links, side-conversation persistence, task pinning and model/effort details, safer config reloads, Daybreak API-key gating, and iTerm2 lifecycle/foreground status. Windows Terminal Shift+Enter, installer, sandbox, and daemon publication paths received fixes.
  • Upstream removes the patched zsh execution backend and stops bundling patched zsh. This fork does not restore or package that removed backend. Bazel release-building support and source-package stripping were added upstream; this fork's planned downloadable layout remains the five bin-only system archives below.

Fork reconciliation and Go SDK

All 150 fork commits were replayed: 93 patch-identical, 57 adapted, 0 dropped or unmatched. The frozen semantic candidate passed independent review. Preserved fork behavior includes independent direct-MCP/Code-Mode line and originating output limits; raw rollout replay; custom providers/context overrides; plaintext provider messages; inherited dynamic tools for fresh V1/V2 children; cumulative spawn budgets, follow-ups, quiet waits and parent completion; Guardian isolation; bounded compaction history and capacity retry floors. The loaded-agent budget repair prevents repeated resume/load paths from resetting the current turn's cumulative spawn budget; cold-load seeding and new-turn budgets remain. Existing shared ThreadManager inheritance covers both fresh and forked children without an additional production-side tool-copy path. Bash snapshot replay now explicitly suppresses repeated .bashrc loading without changing capture, login fallback, or sandbox policy. Partial-history fork_turns is intentionally excluded because upstream removed it.

Rust stable/experimental schemas, precomputed exports, serde manifest, and generated Go protocol were regenerated and checked. Six runtime initialize digest constants were refreshed after the protocol regression test detected the stale snapshot. Both the fresh semantic-candidate and final downloaded-release strict handshakes passed. Go SDK changes are:

  • Generated raw fields for thread exclusions, turn parent/root IDs, subagent model/effort, config speed/browser requirements, environment skills/WebSocket request ID, and misalignment review target. The existing high-level TurnOptions maps ParentTurnID and RootTurnID; the experimental fork prediction field remains raw-only.
  • Go source compatibility change: protocol.SkillMetadata.Path and protocol.SkillSummary.Path change from AbsolutePathBuf to LegacyAppPathString (the latter remains optional in SkillSummary). Both still use a JSON string on the wire; Go callers assigning the old named type may need an explicit conversion.
  • Existing typed ThreadItemsListCursor, opt-in BackendReasoningStatus, unknown CodexErrorInfo passthrough, MCP OAuth loginId correlation with legacy fallback, explicit goal provenance, strict initialize digest/mode validation, and module path github.com/openai/codex/sdk/go are retained. The protocol and Go checks below passed.

RequestHeader.Value can contain sensitive data. Do not print real values in logs, tests, or issue reports.

Use the runtime and Go SDK from this same 0.162.0 source. Strict protocol digest validation is not implicitly bypassed. Replace the entire binary package, including codex-code-mode-host; do not mix a new CLI with an old app-server or daemon.

Downloadable packages

The release has exactly five bin-only system archives. All five pinned builds, exact runner checkouts, package-layout assertions, codex-cli 0.162.0 runner smokes, and downloaded archive checks passed:

  • codex-package-aarch64-apple-darwin.tar.gz and codex-package-x86_64-apple-darwin.tar.gz: bin/codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • codex-package-aarch64-unknown-linux-gnu.tar.gz and codex-package-x86_64-unknown-linux-gnu.tar.gz: the same four binaries plus bin/bwrap; GNU/glibc, not musl.
  • codex-package-x86_64-pc-windows-msvc.zip: .exe versions of the four binaries plus codex-command-runner.exe and codex-windows-sandbox-setup.exe.

Optional voice/audio resources, patched zsh, musl builds, individual archives, and provisioned Windows sandbox-service packaging are not part of this bin-only layout. Verified release archive sizes and SHA256 digests (these are the downloadable packages, not the outer Actions artifact ZIPs):

  • codex-package-aarch64-apple-darwin.tar.gz: 200774406 bytes; SHA256 3dff7c3079d48a087e69972079589031805ec60ced622d2ec4df5e3e7b71dd5a.
  • codex-package-aarch64-unknown-linux-gnu.tar.gz: 207930934 bytes; SHA256 79c524a1a391f3cd31d8e63692ed81459c2af1ece84a475cf2d3bc8b0c1b6096.
  • codex-package-x86_64-apple-darwin.tar.gz: 214091102 bytes; SHA256 353df0f7733a5bfbec4e061a5ddbdf24ca7786ece77ef45f0f7f9f65a1b2896a.
  • codex-package-x86_64-pc-windows-msvc.zip: 232609682 bytes; SHA256 634df8cf14962c7b07d8943a5bca9523aeaca39017d9c3b99fb23800737862cb.
  • codex-package-x86_64-unknown-linux-gnu.tar.gz: 221186599 bytes; SHA256 af26b4f37fc3c0860e9b783f70967219490006493ce572a520be518f7808161c.

Upgrade note: replacing binaries on disk does...

Read more

Codex fork 0.160.0

Choose a tag to compare

@Dirard Dirard released this 04 Oct 05:12

Codex fork 0.160.0

This is a main-based fork release following fork 0.159.0, not a byte-for-byte rebuild of OpenAI's official 0.160.0 release. The fork remains based on pinned OpenAI main; the official release follows a different branch history.

Comparison and source

  • Previous fork runtime and SDK source: dfbd20689f, published as 0.159.0.
  • Previous pinned base: 85714c61d1. New pinned base: 2cf9b0875a, merging OpenAI main@b172810921.
  • Official OpenAI 0.160.0 was published 2026-10-01 at 20:19:13 UTC and points to a956835d02. This fork does not claim to be identical to or rebuilt from that release branch.
  • Final reviewed semantic source: 0688bd1c60. The independent review of f65d445480 found two issues; the same reviewer closed both after targeted repair, with no remaining blocking findings.
  • Version-stamped 0.160.0 release source: 54fc12f7aa, shared by the annotated rust-v0.160.0 and sdk/go/v0.160.0 tags. This changes only the workspace and 161 local package versions; all 1,312 external Cargo records and other fields are unchanged. Exact-lease push and the single pinned five-target build succeeded.

The upstream section below covers all 229 non-merge commits between the pinned bases, not every change on OpenAI's official 0.160.0 release branch. Exact commit links follow at the end.

Upstream changes since fork 0.159.0

Agents, context, and history

  • Abort callbacks now complete before terminal turn events. Remote message-board notifications can reach active turns, queued agent mail survives session eviction, and upstream fresh V2 subagents gain opt-in dynamic-tool inheritance; this fork retains its unconditional fresh-child inheritance. The subagent picker and delegated-task previews track thread/archive and task-input state more accurately.
  • Resume/replay gained authoritative history, reusable unchanged-history snapshots, ordered world-state response items, persisted world-state snapshots, and persisted additional tool definitions. Explicit user goal edits can be recorded with explicit provenance; live tool-call metadata survives request windows.
  • Guardian V2 adds retained conversation support in async classification, bounded Decisions comparison transport, sender-review context, omission deduplication, and decisions agreement/latency telemetry. Host skill discovery is skipped for reviews and user restrictions survive handoff context.

MCP, app-server, protocol, and security

  • Stable thread/attachmentOwner/list finds owning threads by exact attachmentType and identityKey, with archived filtering and cursor pagination. Experimental thread-prediction request/notification types were added, but this upstream snapshot does not implement prediction runtime behavior.
  • MCP follows legacy tool pagination, validates enterprise authorization servers before ID-JAG exchange, uses rmcp for managed token exchange, preserves Windows environment variables, keeps resource helpers and shared types available in Code Mode, and emits attributed OAuth credential-storage telemetry.
  • The app-server protocol now accepts unknown CodexErrorInfo strings or objects, adds an advisory experimental Bedrock GovCloud requirements check, and carries optional explicit goal-mutation provenance. ModelProviderCapabilitiesReadResponse.namespaceTools is removed and tool namespaces are no longer provider-gated. Separately, custom providers gain capability overrides.
  • Bedrock adds GovCloud support, Ultrafast service tiers for Astra models, Sol catalog defaults, multi-agent V2/Ultra reasoning, and API-key Daybreak/cyber program paths. Model visibility remains server-, provider-, catalog-, and account-controlled; this release does not globally guarantee Sol visibility or access.
  • Exec/server paths gained writable streaming, bounded opens and request cleanup, cancellable reads, session recovery, permission catalogs, retry/jitter behavior, diagnostics, and stronger path/sandbox handling. Responses retries honor failed-event Retry-After advice while preserving the fork's capacity-retry floor.

Terminal UI, daemon, platform, and build

  • Transcript selection/copying, Find, pager and configured keybindings, Markdown links/tables/blockquotes, literal HTML copy, owned-transcript keyboard selection, and modal-period selection behavior improved. Command Center task renaming, retained backdrops, selection adjacency, and fork shortcuts were refined.
  • Daybreak gained persistent TUI selection, status/title state, continuation handling, API-key access, and codex exec support. Voice adds audio-device/microphone selection, local-device settings, and realtime transcript-tail persistence; managed in-app voice remains feature-gated.
  • Daemon update/startup diagnostics, release identity, cwd recovery, Windows-mounted WSL handling, updater stderr, remote-control socket setup, and diagnostic pruning improved. Windows sandbox/process/path and macOS/Linux sandbox handling received targeted fixes.
  • Rollout attachments are bundled more compactly, paginated command output is bounded, reverse JSONL scans use memrchr, blocking history/index work is moved off async workers, and SQLite corruption/recovery handling is typed. CI/build updates include toolchain, Windows bindings, age, signing-page, and test-infrastructure changes; they are not claims about bundled optional resources.

Fork reconciliation and Go SDK

All 146 fork commits were replayed: 105 patch-identical, 41 adapted, 0 dropped or unmatched. The new base remains an ancestor. Cumulative fork capabilities are retained, including independent direct-MCP/Code-Mode mcp_max_lines and originating output caps through replay; custom providers and context/compaction overrides; plaintext provider messages and inherited dynamic tools; cumulative spawn budgets, active/idle follow-ups, quiet waits, parent completion, bounded compaction history and capacity retry floors.

Final review of f65d445480 found two blockers. R1 was a duplicate abort_all_tasks lifecycle callback after upstream moved callback completion ahead of the terminal event; the duplicate outer emit was removed and the existing red regression now passes four targeted cases. R2 lost unconditional inherited dynamic tools for fresh V1/default V2 children; fresh-child inheritance was restored and the three targeted cases now pass. Guardian tool isolation and fresh-history behavior remain unchanged. The combined Guardian/abort/inheritance selection passed 14 tests. A fresh debug CLI/helper rebuild and isolated required-real-runtime strict SDK handshake passed, followed by scoped fix/format checks and the same reviewer's targeted closure of both findings.

The Rust stable/experimental schemas, serde manifest, precomputed exports, and generated Go protocol are synchronized from one frozen protocol snapshot. The Go generator now renders the open CodexErrorInfo anyOf as its existing typed union: known strings and known object variants keep typed fields, while unknown strings or objects round-trip through RawJSON instead of degrading the whole type to json.RawMessage.

Raw Go protocol changes include:

  • Breaking raw-field removal: ModelProviderCapabilitiesReadResponse.NamespaceTools is gone because the upstream wire response no longer contains namespaceTools.
  • Stable raw ThreadAttachmentOwnerList binding and types.
  • Experimental raw ThreadPredictionRequest, ThreadPredictionUpdatedNotification, and result types. These are protocol bindings only; no prediction runtime workflow is implemented by this snapshot.
  • Experimental raw BedrockCheckGovCloudRequirements binding and response types.
  • ThreadGoalSetParams and ThreadGoalClearParams gain optional nullable origin: "user" | "automatic". Generic wrappers do not infer or substitute user; callers must set it explicitly when they genuinely represent user provenance.

No new high-level SDK wrappers are claimed for these methods; generated raw-client coverage is the intentional scope. Existing MCP OAuth loginId correlation and legacy name/thread fallback, typed ThreadItemsListCursor, opt-in BackendReasoningStatus, strict digest handshake, resource clients, Gateway OAuth lifecycle, realtime behavior, and module path github.com/openai/codex/sdk/go remain in place.

Use the runtime and Go SDK from the same matching 0.160.0 release. Strict digest validation is not implicitly bypassed. Update the entire binary package, including codex-code-mode-host; do not mix a new CLI with an old daemon/app-server.

Downloadable packages

The pinned five-target release build succeeded on all targets. All five runner checkouts and codex-cli 0.160.0 version assertions passed. The release contains exactly five bin-only system archives:

  • codex-package-aarch64-apple-darwin.tar.gz and codex-package-x86_64-apple-darwin.tar.gz: bin/codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • codex-package-aarch64-unknown-linux-gnu.tar.gz and codex-package-x86_64-unknown-linux-gnu.tar.gz: the same four bi...
Read more

Codex fork 0.159.0

Choose a tag to compare

@Dirard Dirard released this 30 Sep 00:00

Codex fork 0.159.0

This is a main-based fork release following fork 0.158.0, not a byte-for-byte rebuild of OpenAI's official 0.159.0 tag. The pinned main snapshot and official release tag have different branch histories. All five exact-source runtime packages have been built and verified.

Comparison and source

The upstream section below covers all 78 non-merge commits between the pinned bases, not every change on OpenAI's official release branch. Exact commit links follow at the end.

Upstream changes since fork 0.158.0

Agents, Guardian, and context

  • Remote agent message boards now work in multi-agent sessions without reopening a final answer; pending environments survive subagent spawning, and parents are notified when Guardian stops a subagent. The agent command center gained history pagination.
  • Guardian reviews gained opt-in conversation-history retrieval, encrypted and handoff-aware root context, cached approval handling with incomplete context, and context-mode telemetry. Turn phases and accepted input can be correlated in tracing; lifecycle contributors receive original error details.
  • Content-filter retries provide recovery guidance in the shared Responses handler. Compaction usage limits reach lifecycle extensions, and cloud/executor skill listings are deduplicated before budgeting.

MCP, app-server, and configuration

  • Enterprise MCP sign-in and account-scoped grant cleanup were added, with fail-closed authorization/config-refresh behavior. Explicit MCP OAuth login responses and completion notifications now carry an optional loginId for attempt correlation; older servers may omit it. The TUI gained /mcp login <name>.
  • App-server running-turn tracking is incremental. Config reloads preserve thread overrides and cloud policy validity; explicit provider model catalogs remain authoritative. Provider auth storage documentation was corrected.
  • SQLite metadata writes/reads and background page reclamation were improved; remote plugin requests reuse HTTP connections and parsed plugin manifests are cached.
  • The bundled catalog adds GPT-6.1 Sol as the default catalog model. Model availability and picker visibility can still be controlled by the server/provider catalog and account rollout; installing this release alone does not grant access or force a hidden model to appear in /model.

TUI, platform, and build

  • The TUI gained projectless workspace defaults, X11 primary-selection/middle-click paste, reconnect draft recovery, improved selection copying and follow-up labels, centralized subscription labels, and more faithful server-provided reasoning settings and provider defaults.
  • Windows sandbox/process launch and PowerShell fallback behavior, macOS sandbox policy, and Linux bwrap fixture reliability received targeted fixes. Windows sandbox policy events no longer include configuration values.
  • Cargo package versions propagate to Bazel Rust targets; h2 and CI setup were updated. Test fixtures for realtime, Guardian, memory, and remote compaction were isolated or repaired. These are source changes, not claims about bundled optional resources.

Fork reconciliation and Go SDK

All 141 fork commits were replayed: 128 patch-identical, 13 adapted, 0 dropped or unmatched. The fork retains independent direct-MCP/Code-Mode mcp_max_lines and originating output caps through replay; custom providers and context/compaction overrides; plaintext provider messages and inherited dynamic tools; cumulative spawn budgets, active/idle follow-ups, quiet waits, parent completion, bounded compaction history and retry floors. These are cumulative fork capabilities, not all new in 0.159.0. Focused checks and independent review with targeted finding closure are complete.

The new runtime reconciliation preserves upstream pending-environment inheritance and captured capability roots. A targeted repair lets an isolated Guardian session advertise its explicitly installed conversation-history extension while still excluding inherited generic MCP/dynamic/hosted tools and enforcing the existing tool allowlist and live app authorization. The three upstream history regressions now pass, including parent connection identity, output budgets, and permission changes on a reused reviewer. A second Guardian repair preserves the child's Interrupted status after a strict circuit breaker while notifying its parent of the safety stop; normal interruptions remain silent and real terminal errors remain Errored. Local-compaction snapshots were aligned with the existing fork prompt-cache behavior; an encrypted-reasoning fixture was scaled to leave room for the fixed prompt without weakening the runtime headroom guard.

The Rust stable/experimental schema, reviewed serde manifest and generated Go protocol now include MCP OAuth loginId. A high-level MCP OAuth handle correlates a completion by its returned nonempty ID when available, while retaining name/thread matching for an older server that omits the ID. The existing raw thread/items/list cursor type Optional[ThreadItemsListCursor] and RealtimeStartOptions.BackendReasoningStatus opt-in/skip-false behavior remain intact. The module path stays github.com/openai/codex/sdk/go; existing Gateway OAuth lifecycle, realtime and resource clients remain in place. Use matching runtime and SDK versions, and update the entire binary package including codex-code-mode-host; strict digest validation is not bypassed implicitly. Independent review, local debug-runtime handshake and downloaded Linux release-runtime strict handshake passed.

Downloadable packages

The release contains exactly five verified bin-only system archives:

  • codex-package-aarch64-apple-darwin.tar.gz and codex-package-x86_64-apple-darwin.tar.gz: bin/codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • codex-package-aarch64-unknown-linux-gnu.tar.gz and codex-package-x86_64-unknown-linux-gnu.tar.gz: the same four binaries plus bin/bwrap (GNU/glibc, not musl).
  • codex-package-x86_64-pc-windows-msvc.zip: .exe versions of those four binaries, plus codex-command-runner.exe and codex-windows-sandbox-setup.exe.

Optional native voice/audio resources and provisioned Windows sandbox-service packaging are outside this bin-only layout. Exact-source workflow run 36623353284 succeeded on all five targets on its first attempt; checkout SHA and the codex-cli 0.159.0 version assertion were verified for every runner. All downloaded artifact sizes/SHA256 and outer ZIP CRCs matched; inner archive integrity, exact file layout, ELF/Mach-O/PE architecture and Unix 0755 permissions passed.

Release archive sizes and SHA256 (these identify the downloadable packages, not their Actions ZIP wrappers):

  • codex-package-aarch64-apple-darwin.tar.gz — 197589187 bytes; e0a88d7321e869e1f0ee5c735c65380bcb9e010fb5a5b6dd2e21fc401cfeb496
  • codex-package-aarch64-unknown-linux-gnu.tar.gz — 204444691 bytes; d81f541765ed6ef5642523cd578f38518850e5b8ca8170bc3beba7e4e9589c80
  • codex-package-x86_64-apple-darwin.tar.gz — 210468041 bytes; 65c91cf029c37ee119b33ea32517d2906fbb1f1b3ef646a683dfe9e32501527a
  • codex-package-x86_64-pc-windows-msvc.zip — 228314616 bytes; 20a2ce3513a09043e3cdb92fd75bcbd5f32aea9aa98e84f1d8b35d028a4e5b77
  • codex-package-x86_64-unknown-linux-gnu.tar.gz — 217350013 bytes; 9e5b6e59454b5ecd4d7f3e327481715ee1338039f36b61cfd75bc79f6c57b2f1

Upgrade note: replacing binaries on disk does not update or restart an already-running app-server/daemon. An older process can still cause configuration or strict protocol-handshake errors. Run matching components; restart the daemon yourself if appropriate, or use --no-daemon to bypass it. This release does not automatically alter the installed CLI or running processes.

Validation and limitations

  • Rebase accounting, ancestry, diff checks, and preservation of user-owned files passed: 141/141 fork commits retained (128 patch-identical, 13 adapted). Independent review found one Guardian-status regression; the targeted repair and recheck closed it, leaving no known unresolved blocking findings. All five targeted Guardian/completion cases passed after reproducing the original failure.
  • ...
Read more

Codex fork 0.158.0

Choose a tag to compare

@Dirard Dirard released this 28 Sep 22:08

Codex fork 0.158.0

This is a main-based fork release following fork 0.156.0, not a byte-for-byte rebuild of OpenAI's official 0.158.0 tag. The pinned OpenAI main snapshot and the official release tag follow different branch histories; commit-SHA differences alone do not imply missing features.

Comparison baseline and provenance

  • Previous fork runtime and SDK: 0.156.0, source e8bab0d47f.
  • Previous pinned fork base: cdd1d9e1bb.
  • New pinned fork base: 1a840f77ea, merging OpenAI main@44fe510ce3.
  • Final reviewed semantic source: 25aac31a3a. Version-stamped release source: 5066ec32ee; only the workspace/local package versions change beyond the reviewed semantic source.
  • Matching tags: rust-v0.158.0 and sdk/go/v0.158.0. Earlier tags are not moved. The mistakenly dispatched 0.157.0 build was cancelled and is not a source of these packages. The corrected manual five-target run 36428114388, attempt 1, checked out exact source 5066ec32eea7bd37952337e2f35359db7445a629 on every runner and completed successfully on 2026-09-28 at 16:34:43 UTC.

The upstream section below covers all 303 non-merge commits between the pinned bases, not every change in OpenAI's official 0.158.0 release branch. The full exact commit list follows at the end.

Upstream changes since the previous pinned base

Agents, Guardian, and context

  • Agent operations and V2 child lookup/loading now route through AgentControl, including host-provided controllers. Pending inter-agent messages and ephemeral message boards survive their relevant lifecycle transitions; agent status and spawn observability improved.
  • Guardian now retains ordered assistant and authorization context, deduplicates retained instructions, keeps its own history across parent compaction, binds reviews to the target environment, and applies computer-use review to the Browser connector. Circuit-breaker interruptions gained opt-in structured errors.
  • Compaction preserves model/access-program pairs and user text, resumes context from the latest boundary, and applies the unchanged-model shortcut to more session sources. New user input can preempt a response; Code Mode can yield early for observations or opt in to user-input yielding.
  • Code Mode and tool metadata retention are more selective under outgoing budgets, including late truncated results and provider endpoint overrides. MCP/Code Mode input schema budgets are configurable.

App-server, networking, and security

  • thread/items/list accepts an item anchor as well as its existing opaque string cursor; mcpServerStatus/list can discover one server and reuse a thread's MCP connection. Realtime V3 adds opt-in backend reasoning status, and the executor connection API accepts an optional bearer token.
  • Application network policy now reaches HTTP/WebSocket, app-server, remote control, AWS auth/telemetry, and embedded startup paths. Executor authentication, reconnect credential boundaries, request bounds, and socket/process handling received targeted hardening.
  • Server Retry-After deadlines are preserved. Flex capacity failures have a distinct terminal error; plugin extension metadata was deliberately removed from discovery and summaries. Pro Max plan support and updated plan labels were added.
  • Windows sandbox startup/provisioning and child-process launches, macOS Seatbelt trust, Linux descriptor cleanup, and daemon socket masking received platform fixes. Diagnostic uploads and logs include more useful context while sensitive WebSocket headers and tool payloads are kept out of info logs.

Terminal UI and developer experience

  • Transcript selection/copying, links, scrolling, warnings, status, session switching, reconnect notices, startup drafts, and the fullscreen composer received focused fixes. Mermaid flowcharts support more native syntax, labels, shapes, and relationships; Markdown tables and math rendering/copying are more faithful.
  • Voice sessions remain active across thread navigation, and RTP timing is aligned. Prompt suggestions, working/completion tips, turn durations, and the welcome screen were refined.
  • Build/test infrastructure adds prebuilt V8 use, Rust debug-profile alignment, more reliable executable fixtures, and several race/fixture fixes. These are upstream source changes, not claims that optional voice resources or external service integrations are bundled in the archives below.

Fork reconciliation and Go SDK

All 134 fork commits were replayed: 90 patch-identical, 44 adapted, 0 dropped or unmatched. The adaptations preserve fork behavior on upstream AgentControl, host-owned child controllers, current Code Mode/context/history owners, independent Guardian history, and absolute Retry-After deadlines. The canonical collaboration tool remains wait_agent.

Two independent final-review findings were corrected and closed on the reviewed semantic source. R1 restores raw rollout output persistence and applies originating byte/token/line policy during replay, including old serialized rollouts, rather than bypassing caps after a processed-output reconstruction. R2 makes V2 wait inspect the selected AgentControl, so a host-owned running child is visible even without local runtime registration. No new rollout wire marker or migration was added. Fork-specific overloaded-server retry floors remain separate from upstream terminal Flex failures.

The generated Go SDK and runtime protocol are synchronized. Existing opaque string pagination cursors remain JSON strings; a new item anchor is an object. In source, ThreadItemsListParams.Cursor changes from Optional[string] to Optional[ThreadItemsListCursor], with typed string/anchor constructors. This is an intentional raw-Go source API change even though the old string wire shape remains compatible; callers assigning protocol.Some("cursor") must wrap the string with protocol.NewThreadItemsListCursorString("cursor").

RealtimeStartOptions.BackendReasoningStatus opts in with true; omitted/default false is not sent. Generated types also include MCP serverName, environment authBearerToken, FlexUnavailable/TooManyDenials, and Pro Max. Upstream-removed plugin extension bindings and their obsolete test were removed instead of restoring the server feature; surviving PluginSummary defaults remain. The Go module path stays github.com/openai/codex/sdk/go. Strict runtime/SDK digest matching and explicit compatibility overrides remain in force; use matching runtime and SDK versions together. Existing Gateway OAuth admission, cancellation, opt-in, and connection ownership behavior is retained.

Existing fork capabilities retained

These are cumulative fork differences, not all new in 0.158.0:

  • Independent mcp_max_lines for direct MCP and whole emitted Code Mode results, including exec/wait/notify, while ordinary tools keep the general cap; raw/encrypted/media outputs retain originating byte/token policies through model switches, persistence, and replay.
  • Custom providers, typed/fallback context-window and auto-compaction overrides, configurable plaintext messages across providers, and inherited dynamic tools.
  • Cumulative per-turn spawn budgets, active/idle follow-up semantics, quiet waits, parent completion notifications, bounded compaction history, headroom/no-progress handling, and at least three capacity retries.
  • Typed Go SDK resource clients, strict digest handshake, Gateway OAuth lifecycle, realtime closure, filtered completion backlog, image paths, and JSON Schema forwarding.

Downloadable packages

The release contains exactly five bin-only system archives — codex-package-aarch64-apple-darwin.tar.gz, codex-package-aarch64-unknown-linux-gnu.tar.gz, codex-package-x86_64-apple-darwin.tar.gz, codex-package-x86_64-unknown-linux-gnu.tar.gz, and codex-package-x86_64-pc-windows-msvc.zip — each with bin/ and unsuffixed executable names:

  • Linux GNU/glibc x86_64 and ARM64: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy, bwrap.
  • macOS x86_64 and ARM64: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • Windows x86_64: codex.exe, codex-app-server.exe, codex-code-mode-host.exe, codex-responses-api-proxy.exe, codex-command-runner.exe, codex-windows-sandbox-setup.exe.

Linux uses GNU/glibc, not musl. Optional native voice/audio resources and provisioned Windows sandbox-service packaging are outside this bin-only layout. All five artifact sizes and SHA256 digests matched GitHub metadata. Outer ZIP CRCs, package integrity, exact contents, ELF/Mach-O/PE architectures, and Unix 0755 permissions were verified.

SHA256 of the five release archives:

29ac8c2e3b164b69baf471275e2f4bd4f086f2d26dcdf59a2791c325d6797dd3  codex-package-aarch64-apple-darwin.tar.gz
79c56dcee6ad36836b19956943152f61e5c9d95e7908d852904cb0b02ac97966  codex-package-aarch64-unknown-linux-gnu.tar.gz
477fc854e49fd03cf3667fb5b273ae2c3c4f13e7b3ce962e8e9486038b11a458  codex-package-x86_64-apple-darwin.tar.gz
3377e33b80026af109a0dbdd33208b38a51c7c8d01bd91e6db4db522c259b321  codex-package-x86_64-pc-windows-msvc.zip
5ef31921b896deec30b6504c408e598012a80385185c2b310ab4939c1e813f00  codex-package-x86_64-unknown-linux-gnu.tar.gz

Upgrade note: replacing binaries on disk does not update or restart an already-running app-...

Read more

Codex fork 0.156.0

Choose a tag to compare

@Dirard Dirard released this 23 Sep 12:11

Codex fork 0.156.0

This is a main-based fork release following the corrected 0.155.1 runtime, not a byte-for-byte rebuild of OpenAI's 0.156.0 tag.

Comparison baseline

  • Previous fork runtime: 0.155.1, corrected source 1a82148f5d2cb846dadd976c2297260a8edc76cf.
  • Previous upstream-tracking base: 4981b6d01effb84d0a79faa5e41f5e06c4fc5ce7.
  • New upstream-tracking base: cdd1d9e1bbc0cccc80eaa03e6ad0de176e11e5a6, corresponding to OpenAI main@7db578fca663b3e0026996e9c50104784d420744.
  • Reviewed runtime and SDK release source: e8bab0d47f7c74642f4f98032f8f306bee1404ff.
  • New release tags: rust-v0.156.0 and sdk/go/v0.156.0. Earlier version tags remain unchanged.

The upstream section below covers all 194 non-merge commits between these pinned bases. OpenAI's official 0.156.0 changelog uses a different baseline and includes features already present in the previous fork release; those are not claimed as new here.

Upstream changes since the fork's 0.155.1 base

Terminal UI and transcript

  • Fullscreen transcript mode is enabled by default in this pinned main snapshot; /tui selects the terminal UI mode for the next launch.
  • Added transcript search, compact browsing and prompt navigation, per-activity detail controls, selection/copying, plain-click links, and right-click copying for transcript/composer selections.
  • Added mouse selection and editing to the fullscreen composer, preserving drafts until sessions are ready and retaining streamed answers when subagents finish.
  • Improved transcript ordering, persisted activity details, viewport anchoring, wrapping, list spacing, selection/autoscroll behavior, and full URL destinations at different terminal widths.
  • Added status filters, simpler navigation, and improved task metadata/layout in the agent command center; read-only agent sessions handle Escape navigation correctly.
  • Added independent controls for visual effects and Mermaid/math/table rendering. Mermaid supports stadium nodes; terminal math supports aligned equations and optimization notation.
  • Refined warning visibility, quota notices, picker consistency, clock preferences, keyboard hints, reduced-motion voice UI, usage-dashboard navigation, and layout.
  • The welcome animation is limited to onboarding; completion hints and recap spacing are kept close to the transcript tail.

Agent lifecycle and collaboration

  • Added persistent local agent message boards: channel posts/subscriptions, pagination, latest-post indexes, collaboration tools, and thread-deletion cleanup.
  • Added attributed message previews, automatic subscription to newly posted channels, preservation of explicit unsubscribes, and suppression of notifications back to the post author.
  • Consolidated lifecycle operations in AgentControl/LocalAgentControl, with captured spawn/send requests and local runtime state separated from controller handles.
  • Agent inspection can read unloaded-agent metadata without restoring runtimes; status subscriptions stream agent snapshots, and close operations return snapshots.
  • Addressed queued-message/eviction races, overlapped spawn persistence, cleaned up cancelled children, and skipped unnecessary stored-title reads for ephemeral forks.
  • Conditional turn interruption preserves pending input. Subagents can request MCP elicitation input; delivered messages survive post-tool hook failures.
  • Guardian uses thread context by default, supports extra policy configuration, retains ordered assistant context, and tolerates compatible compaction-hash differences for synchronous reviews.

Context, Code Mode, and runtime state

  • Compaction checkpoints persist resume metadata; retained remote-compaction history excludes descendant channel posts.
  • Code Mode shares stored JSON values across cells with Arc, preserves empty-cell metadata under recorder pressure, and recovers executed-tool metadata under capacity pressure.
  • Yielded skill calls retain originating turn metadata; model catalogs can override Code Mode tool messages.
  • MCP request attribution accumulates across requests and history; transport workers retain request trace context.
  • Extension tool history is materialized lazily. Cloud skill catalogs refresh at turn startup and can be reused until invalidated.
  • Thread creator identity and item lifecycle timestamps are persisted; plugin recommendations move into developer context.
  • Added GPT-6 Sol/Luna model catalog entries, including Amazon Bedrock catalogs. Catalog metadata and service-tier availability were refreshed.
  • invalid_prompt is preserved as its own error classification; image-generation failures retain request IDs.

API, plugins, authentication, and networking

  • Added explicit gateway OAuth read/login/cancel operations, authentication status notifications, and the initialize capability for explicit gateway sign-in.
  • Hardened gateway credential persistence and error redaction; MCP OAuth authorization endpoints are restricted to HTTP(S).
  • MCP resource reads can target specific apps/accounts; MCP server status exposes HTTP origins.
  • Plugin summaries expose hosted extensions such as entrypoints, icons, quick actions, search providers, and settings.
  • Standalone web-search redirects and realtime WebSocket connections honor configured proxy routes; the network proxy accepts caller-provided MITM CAs.
  • File blob upload timeout increased from one minute to five minutes; attachment uploads carry thread IDs.
  • Temporary structured threads use read-only permissions; Unix local MCP processes are restricted to stdio descriptors.
  • Environment updates are serialized; removed pending attachments are cancelled. Foreign working directories and required Windows environment variables are preserved.
  • Daemon socket paths are masked through ancestor bind mounts. macOS filesystem helpers avoid fork; local child-process spawning moves into the shared PTY utilities.

Background server, diagnostics, and builds

  • Automatic daemon startup is enabled by default; the TUI offers explicit recovery for incompatible background servers and supports /import with remote/local daemon sessions.
  • Improved codex doctor diagnostics for SQLite databases and path/URL check status without exposing configuration values.
  • Added rollout compression diagnostics and bounded report reason tags.
  • Reduced unused dependency features and avoided building the host SQLite driver for SQLx macros.
  • Removed upstream's rust-release-prepare workflow; clarified Bazel lock verification failures.
  • Added or updated focused regression tests across message boards, lifecycle ordering, snapshots, queues, and credential handling.

Fork reconciliation and Go SDK

All 129 fork commits were replayed without dropping a commit. Runtime adaptations follow the new AgentControl, SpawnAgentOptions, captured send requests, and core-owned submission types instead of restoring retired controller wrappers. Per-turn spawn accounting, legacy parent-completion watching, upstream cancelled-spawn cleanup, and the new Guardian/MCP persistence metadata are preserved together.

The fork-only agent status tool rename is rolled back: both collaboration APIs again advertise and dispatch the upstream wait_agent name. This avoids rejection of check_agent_status inside the reserved collaboration namespace. Wait behavior, timeout controls, namespace configuration, and historical trace recognition remain unchanged.

The Go SDK now exposes the actual stable and experimental app-server additions:

  • Explicit gateway OAuth read/login/cancel calls and status notifications. ClientConfig.ExplicitGatewayOAuth is opt-in; its exact Rust wire field is explicitGatewayOauth, including default-false and omission behavior. Managed login captures the authorization URL before waiting for the blocking RPC and handles RPC completion/error without a notification. Cancellation stops an unsent login locally or follows the already-sent login with a connection-scoped cancel request. Only one managed login is active per client; failed cancellation retains ownership, and an old handle cannot cancel a subsequent one.
  • MCP HTTP origins and explicit resource targets, including required-nullable linkId for selected-account versus no-auth reads.
  • Plugin extension entrypoints, quick actions, search/settings metadata, tagged unions, flattened fields, and raw JSON. Variant-specific defaults no longer leak into other union variants.
  • Nullable item start/completion timestamps with legacy omitted-field support.

Existing SDK methods and definitions remain present. Stable and experimental protocol/schema/manifest digests were regenerated; use the matching runtime and SDK together. The module path and explicit compatibility-override policy remain unchanged. No earlier SDK tag is moved.

Gateway login is registered on the app-server before background dispatch, so an early cancellation cannot acknowledge success and then leave an already-accepted login starting afterward. Dropped queued requests release their admission slot; connection ownership and notification opt-out checks remain enforced.

Existing fork capabilities retained

These are cumulative fork differences, not all-new 0.156.0 features. The targeted preservation checks are described below.

  • Independent mcp_max_lines override for direct MCP results and the whole emitted Code Mode result, including exec/wait/notify; ordinary direct tools retain the general line limit.
  • Original byte/token policies retained through saved metadata, model switches, and replay; raw nested JavaScript values and typed/encrypted MCP results preserved.
  • Custom providers and typed/fallback context-window/auto-compaction overrides; configurable cross-provider plaintext messages and inherited dynamic tools.
  • Cumulative per-turn spawn budgets, race-safe publicat...
Read more

Codex fork 0.155.1

Choose a tag to compare

@Dirard Dirard released this 20 Sep 03:21

Codex fork 0.155.1

This release updates the fork from 0.155.0 to 0.155.1: a rebase onto the next pinned upstream main snapshot, adaptation of the fork's agent/runtime changes, synchronized Go SDK bindings, and five complete bin-only runtime packages.

Same-version reissue: the runtime packages have been rebuilt with the MCP/Code Mode line-limit correction described below. If you downloaded the original 0.155.1 packages, download them again; --version remains codex-cli 0.155.1.

Comparison baseline

  • Previous fork release: 0.155.0, source 3c37c16dc636604b7cc7324eed09d2a45db516fb.
  • Previous upstream-tracking base: 08ff997106556c1bae45144b717ecbbffde14744.
  • New upstream-tracking base: 4981b6d01effb84d0a79faa5e41f5e06c4fc5ce7, corresponding to OpenAI main@78245b47af2a7aafcabe025828ceecca69db4df1.
  • Runtime release source: 1a82148f5d2cb846dadd976c2297260a8edc76cf.
  • Original 0.155.1 runtime source: 5838f5d29977bf2c969fad74a849190c3e0b5def.
  • CLI tag: rust-v0.155.1. Compatible Go SDK tag: sdk/go/v0.155.1, retained at 5838f5d29977bf2c969fad74a849190c3e0b5def; its module contents are unchanged by this reissue.

This is a main-based fork release, not a byte-for-byte rebuild of OpenAI's 0.155.1 tag. The upstream section covers all 80 non-merge commits between the pinned bases; the complete commit list is included below. Older fork commits rewritten by rebase are not presented as new features.

Upgrade and compatibility notes

  • When upgrading from 0.155.0, update the CLI/app-server and Go SDK together: the protocol/schema/manifest digests changed in the original 0.155.1 release. This MCP correction does not change those digests or the SDK API.
  • The Go module path remains github.com/openai/codex/sdk/go; the minimum Go version remains 1.25. Select the matching fork revision/tag through your existing fork integration.
  • The Go SDK adds PluginDetail.OnboardingSkill and removes ConfigRequirements.WindowsSandboxPrivateDesktop, matching the current upstream API.
  • New local TUI threads no longer request reasoning summaries by default. Explicit reasoning-summary settings remain respected.
  • Replace each system's bin/ files together; executable names have no operating-system or architecture suffixes.
  • This explicitly requested same-version correction replaces only the rust-v0.155.1 runtime tag and its five archives. Older version tags and sdk/go/v0.155.1 are unchanged; the Go tag is retained to avoid breaking module proxy/checksum immutability. User/provider configuration is not automatically modified.
  • These bin-only packages do not include optional native voice/audio resources or the provisioned Windows sandbox-service package.

MCP / Code Mode correction in this reissue

  • The MCP line setting is now an independent override. With max_lines = 150 and mcp_max_lines = 5000, a 225-line MCP response reaches the model without being cut back to the general 150-line limit. When the MCP setting is absent, the general limit remains the fallback; zero and stricter MCP limits retain their meaning.
  • Code Mode applies this override to each complete emitted result, including exec, wait, and notifications. It applies to the whole result, even when JavaScript combines MCP data, command output, and generated text; it does not infer per-source limits after arbitrary JavaScript transformations.
  • History keeps the selected policy. Existing metadata carries the effective line limit through recording and replay. Delayed notifications retain the originating policy after a model switch. The intermediate MCP formatter no longer reapplies the line limit, avoiding a second cut of an existing omission marker.
  • Other boundaries remain intact. Ordinary direct command, custom, and dynamic outputs retain the general line limit. Byte/token budgets and explicit max_output_tokens still apply; this is not unlimited output. Raw nested JavaScript values, typed media ordering, and the encrypted-MCP fix below are preserved. Raw events and traces retain their byte/token bound.

Upstream changes since 0.155.0

TUI, reasoning, and task navigation

  • Restored disabled reasoning summaries as the default for new local TUI sessions, preventing provider request rejection where summaries are unsupported. This is the principal upstream 0.155.1 release fix.
  • Preserved reasoning order within TUI activity groups and kept exploration grouped across reasoning and nonzero command exits.
  • Added user notifications for asynchronous questions and made their replies compatible with the desktop client.
  • Added six bundled themes and theme-aware accents, and used catalog model display names throughout the TUI.
  • Unified tool-output previews around a three-row limit.
  • Limited the agent command center's initial load to ten recent sessions.
  • Allowed recovery commands when the current thread is unavailable and allowed /review during MCP startup.

Agent control, instructions, and Guardian

  • Introduced a backend-independent AgentControl contract while retaining local execution in LocalAgentControl.
  • Agent listing now returns LiveAgent records; completion routing and rollout-budget accounting are owned by the controller.
  • Thread instruction providers can share updates with subagents.
  • Guardian reviews use captured live checkpoints and the applied instruction snapshot; completed reviews are flushed before decisions are delivered.
  • Enabled Guardian reuse of parent compaction by default.
  • Preserved request-level reasoning effort for memory/title workers and gated effort changes on explicit model support.
  • Added explicit turn triggers for exec/TUI requests.
  • Added catalog-provided parameter schemas for Multi-Agent V2 tools.

Context, retries, and runtime efficiency

  • Added opt-in compaction after final responses.
  • Centralized retry eligibility and delays in CodexErr.
  • Avoided cloning excluded or active turn items for metadata-only/history-limited resume operations.
  • Skipped unnecessary skill discovery when injecting items into initialized threads.
  • Kept captured step settings, approval environments, permissions, and daemon recovery environment state consistent.
  • Refreshed model catalogs before new turns after authentication changes.
  • Corrected active-turn environment lookups and executor registration refresh/recovery.
  • No fixed token-savings percentage is claimed; these are correctness and resource-use changes, not an end-to-end benchmark.

Plugins, providers, networking, and authentication

  • Exposed declared onboarding skills in plugin details.
  • Separated catalog discovery/listing from plugin package resolution, added shared catalog APIs and turn-start cloud plugin discovery, and renamed internal MCP/app extension interfaces.
  • Bound remote plugin measurements to trusted plugin releases and added authenticated measurement references.
  • Added explicit provider model-catalog URLs and authentication-mode labels for catalog-fetch timing.
  • Added system-proxy fallback for login/startup requests.
  • Composed gateway OAuth with primary-provider authentication and handled unknown error classifications.
  • Shared ChatGPT cookies between HTTP and WebSocket transports.
  • Added a standalone network-proxy binary with JSON configuration and corrected its policy initialization. That optional standalone executable is not an additional asset in this fork's bin-only package layout.
  • Advertised the control socket's WebSocket message-size limit and added a command-start lifecycle callback.

Permissions, sandboxing, daemons, and platforms

  • Linux sandbox checks now accept unrelated namespace mounts without treating namespace identifiers as ordinary filesystem paths, while preserving socket isolation.
  • macOS Seatbelt policies deny XPC service lookups, restrict mutating fcntl operations, remove an unnecessary runningboard default, and preserve exclusions in scratch directories.
  • Shared process-group termination uses a macOS member fallback; provisioned macOS CLI packages retain their signing identity.
  • Legacy Windows sandboxes always use private desktops, removing the old optional requirement field. Sandboxed descendants retain Windows package identity.
  • Managed networking defaults local binding to true where applicable; approved escalation remains available with environment-owned network policies.
  • Remote workspace roots stay under server control.
  • Shared-daemon startup accepts compatible feature overrides, and worktree sessions can reuse an existing local daemon.

Builds, diagnostics, and tests

  • Added a composite action for building and smoke-testing Codex packages and pinned WinGet publication dependencies.
  • Added bounded filesystem-path diagnostics to codex doctor and configuration/feature diagnostics to report metadata.
  • Added environment inheritance support to workspace-root tests.
  • Stabilized delayed-startup, busy-executable, Guardian, multi-agent resume, model-catalog timeout, sampler, and TUI interruption tests; local Windows sandbox tests run exclusively.
  • Split analytics test suites and refreshed environment-sensitive test fixtures.
  • The complete changelog below also records internal maintenance that is not a separate user-facing feature.

New fork reconciliation changes

These changes preserve the existing fork's behavior on the new upstream architecture. Rebase-candidate defects are not claims of regressions in the previously published 0.155.0.

  • Encrypted MCP results survive stricter line limits. Fixed an existing fork bug where text content marked codex/encryptedContent could be flattened into ordinary text when mcp_max_lines was stricter than the general line limit and structuredContent was absent. The encrypted payload could then be displayed as ciphertext or truncated away. The fix preserves the already decoded EncryptedContent and uses the exist...
Read more

Codex fork 0.155.0

Choose a tag to compare

@Dirard Dirard released this 18 Sep 21:42

Codex fork 0.155.0

This release updates the fork from 0.153.4 to 0.155.0: a rebase onto the pinned upstream main snapshot, reconciliation of the fork's runtime changes, an expanded Go SDK, and five complete runtime packages.

Comparison baseline

  • Previous fork release: 0.153.4, commit 20a8b8519f4d8bd58b9bfb94f87516fa2eab1a0e.
  • Previous upstream-tracking base: 59acd25a948759cf0d0f8454bc9ded6e48e72f52.
  • New fork upstream-tracking base: 08ff997106556c1bae45144b717ecbbffde14744, corresponding to upstream main@7498521d288b9b3b96ffba4eedf089d8d6e06a84 on September 18.
  • Released fork source: 3c37c16dc636604b7cc7324eed09d2a45db516fb.
  • CLI tag: rust-v0.155.0; matching Go SDK tag: sdk/go/v0.155.0.

This is a main-based fork release, not a byte-for-byte rebuild of OpenAI's 0.155.0 tag. It incorporates changes from the 0.154.0/0.155.0 development cycle and later main-branch work. The previous fork already contained some changes subsequently advertised in upstream 0.154.0, so those are not presented again as new fork features.

The sections below describe behavior and compatibility changes. The expandable changelog at the end lists all 641 upstream non-merge commits between the pinned bases, including smaller fixes, tests, refactors, and build changes.

Upgrade and compatibility notes

  • Update the CLI/app-server and Go SDK together: the strict protocol, schema, and manifest digests changed.
  • The Go module path remains github.com/openai/codex/sdk/go; the minimum Go version remains 1.25. Select the fork revision/tag through your existing fork integration.
  • thread/rollback and ThreadsClient.Rollback are removed. Migrate to thread/revert and ThreadsClient.Revert, using the new request/response types.
  • The deprecated codex mcp-server command is removed upstream.
  • Each downloadable archive contains one system's runtime under bin/, with no target suffixes on executable names. Replace the binaries together.
  • Native voice requires additional helper/audio resources that are not included in these bin-only fork packages.
  • Existing published release tags were not moved. This update does not automatically change your user configuration.

Upstream changes since the previous fork release

Threads, worktrees, and task management

  • Expanded managed worktree support for new and forked sessions: creation from session commands and the agents overview, browsing/resuming linked worktrees, ownership details, and confirmed deletion of clean managed worktrees. Worktrees are enabled by default in the pinned main snapshot.
  • Added task hiding, archiving, deletion, direct session creation, model grouping, task token/usage estimates, and richer Markdown task details to the agents overview/command center.
  • Conversations with another active writer can be opened as read-only history, preserving the user's draft instead of attempting to take over the writer.
  • Resume and fork paths better preserve saved permissions, runtime workspace roots, collaboration mode, multi-agent runtime selection, and model/profile settings. Fresh sessions and implicit forks respect server defaults unless explicitly overridden.
  • Fixed stale history after switching threads, draft/focus loss around task transitions, ambiguous session labels, and composer responsiveness while creating a session.
  • Editing an earlier prompt uses the current thread's revert operation. The retired rollback API was removed.
  • Current attachments are copied into non-ephemeral forks, and pending automatic title generation is cancelled after a manual rename.

Background server, updates, and recovery

  • Added configurable daemon update schedules, codex app-server daemon update, explicit package replacement, and a local /daemon menu.
  • Added --no-daemon to bypass the shared background server, plus opt-in automatic background-server startup.
  • Managed shutdown persists loaded threads and recovery candidates. Saved threads, active goals, and interrupted work can be recovered after a managed daemon restart.
  • Improved cancellation-safe thread startup, release of persistent writers, shutdown admission, bounded stdio shutdown, and Unix SIGTERM handling.
  • Separated daemon packages from standalone CLI installation and improved managed-package discovery and bootstrap behavior.
  • These server-side recovery changes do not establish that a separately observed desktop-client pending goal/set indicator/callback issue is fixed.

Context, compaction, goals, and resource usage

  • Model context, extension context, tool planning/execution, history recording, and subagent spawning use the settings captured for the originating step rather than unrelated later or initial turn settings.
  • Preserved originating tool-output budgets across resume/fork and delayed Code Mode notifications.
  • History token estimates are based on content rather than serialized message envelopes.
  • Accepted user prompts are persisted even if compaction fails before a turn starts.
  • Supported providers use streamed remote compaction; the unused legacy remote-compaction implementation was removed. Compaction checkpoint validation is centralized, and fallback can use the current model.
  • Reasoning-effort overrides are preserved through recovery/compaction where required, with duplicate or disabled overrides filtered appropriately.
  • Ephemeral forks preserve parent cache affinity; file-ID images participate in context budgeting and are normalized for the receiving model.
  • Added user-requested goal pause support and blocking after three empty automatic goal-continuation turns.
  • Reduced unnecessary copying, repeated catalog lookups, and allocation around active turns, MCP schemas, and Code Mode results.
  • No fixed token-savings percentage is claimed: these are correctness and resource-use changes, not an end-to-end usage benchmark.

Code Mode and multi-agent behavior

  • Scoped Code Mode callback delegates to individual executions and preserved the originating context of yielded calls.
  • Hardened nested tool-call completeness tracking, including completed empty inventories, and bounded output previews across result blocks.
  • Discarded tool responses can be garbage-collected; cleared timers and timers belonging to finished cells are cancelled. Undefined values are handled before JSON serialization.
  • Added optional Code Mode overhead timing and more precise dispatch/result tracing. Tool metadata is included in compaction prompts.
  • Added startup tool allowlists for threads and model-catalog descriptions for multi-agent V2 tools, including spawn_agent.
  • Improved delegated-work trigger/identity propagation and visibility of unloaded child threads in environment context.
  • MCP user interaction and plugin-install requests are routed through the root thread.
  • App-server delegated operations, managed thread lifetimes, and cancellation/shutdown boundaries were tightened.

MCP, plugins, authentication, and model providers

  • Existing sessions pick up refreshed plugin tools, skills, and hooks after installation or external updates. Refreshed catalogs remain paired with their clients.
  • Plugin/orchestrator caches survive metadata-only and MCP runtime refreshes; dormant MCP bindings can be reused.
  • Improved OAuth refresh, expired-credential status, reconnect guidance, auth-change notifications, and manual callback entry. Elicitation cancellation/reset on reconnect was corrected.
  • Added native user-verification contracts, cancellation, and tool-continuation support; supported macOS clients can use Touch ID/Secure Enclave verification.
  • MCP requests support read-only policy and use the correct turn environment for policy evaluation. Status exposes advertised server capabilities, and tool-call history preserves MCP App UI metadata.
  • Thread-level plugin exclusions are persisted and applied consistently to runtime capabilities and shared connectors.
  • Model catalogs, cached WebSocket state, and remote-control sessions are tied to the provider/authentication owner and invalidated appropriately when the account changes.
  • Added command-based AWS credential acquisition for Amazon Bedrock, opt-in model discovery for OpenAI API keys, and OAuth credential management for model-provider gateways.
  • Improved managed-provider requirements, residency checks, workspace request routing, and preservation of configured Flex service tiers.
  • Corrected retry classification for throttling, rate limits, quota errors, and non-retryable policy failures.

Attachments, rollouts, memory, and SDK surfaces

  • Added stored thread attachments with transactional add/list/remove operations, pagination, coordinated deletion, and update notifications.
  • Added attachment upload/resolution paths and file-ID image handling. Local images can be transferred as portable attachments to remote app servers.
  • Coordinated rollout compression with active writers, added an experimental compression endpoint, and continued searches when an individual compressed rollout cannot be processed.
  • Added configurable memory versions with isolated storage, memory v2 extraction/consolidation/read prompts, summary-only extraction, priority for user-authored information, dual writing, and readiness/status reporting.
  • These additions do not mean memory v2 or other optional features were enabled in the user's configuration.
  • Expanded experimental user-verification APIs, Daybreak settings, and disabled-plugin overrides.
  • Upstream Python SDK generation, per-turn/history options, subscriptions, and publication were synchronized more closely with the matching runtime. This release does not claim a separate fork PyPI publication.

Guardian, permissions, and sandbox security

  • Preserved user instructions, verified answers, sender context, and authorization evidence through forks, checkpoints, and compaction.
  • Invalidated stale approvals after h...
Read more

Codex fork 0.153.4

Choose a tag to compare

@Dirard Dirard released this 05 Sep 20:44

Codex fork 0.153.4

Built from fork commit f6073442d1. This release was rebased onto fork origin/main at 59acd25a94, based on upstream main at ddf04ad267, and includes the 0.153.3 and 0.153.4 fixes plus subsequent main-branch changes. The full review also covered the fork-only repository configuration carried on origin/main.

Upstream changes since 0.153.2

  • Updated GPT-6-Astra model availability and guidance for asynchronous questions.
  • Added interactive asynchronous questions in the TUI, including selectable and custom answers, with preserved state during history and queue navigation.
  • Improved Guardian authorization context, retained instructions, post-compaction reviews, and request-scoped approval decisions.
  • Added explicit root-turn identity for independent tasks and memory requests, and improved ordering of retained thread context.
  • Added managed WebMCP policy to the app-server API and extended persisted thread metadata.
  • Improved remote execution, Windows sandbox integration, Markdown copying, and model-picker presentation.

Go SDK

  • Regenerated stable and experimental schemas, bindings, and compatibility digests against the rebased app-server sources.
  • Added persisted daybreakEnabled thread metadata and its update parameter. Corrected the experimental-field inventory so stable-mode clients reject this experimental parameter before writing to the transport.
  • Added the managed allowWebmcp requirement.
  • Updated Guardian action paths to LegacyAppPathString, preserving foreign-platform and UNC path representation.
  • Existing typed resource clients expose these fields without additional wrapper methods. This upstream update changes payloads, not the set of RPC methods or notifications.
  • Corrected union-field generation across actual variants: compatible shapes are merged, required nullable values remain nullable while their keys stay required, and incompatible shapes retain their JSON representation instead of taking the first variant's type.
  • Generated wrappers backed by json.RawMessage or Optional[...] are now Go aliases, preserving the underlying JSON marshal and unmarshal methods. Calls with unset nullable named parameters omit the parameter payload.
  • Stable-mode clients now accept supported non-granular approval policies. Granular approval policy values and Daybreak fields remain experimental and continue to be rejected before transport in stable mode.

Go SDK compatibility note

Some previously incorrect generated field types necessarily changed to represent the existing protocol correctly. The app-server wire protocol itself is unchanged.

  • Nullable fields: ParsedCommand.Path, CommandAction.Path, PluginSource.Path, ResponseItem.Name, and ResponseItem.Status.
  • Fields now using json.RawMessage: McpServerElicitationRequestParams.RequestedSchema, ResponseItem.Action, ResponseItem.Arguments, ResponseItem.Content, SandboxPolicy.NetworkAccess, ThreadItem.Content, ThreadItem.DurationMs, ThreadItem.Result, and ThreadTimelineEntry.Item.

Applications accessing the raw fields directly should decode the appropriate variant with encoding/json. The generated aliases have the runtime type identity of their underlying Go targets, so reflection-based code should not expect a distinct generated named type.

Reliability fixes found during the full fork review

  • Local compaction now honors the minimum of three model-capacity retries even when the provider's configured stream retry count is zero, using the shared retry handler.
  • Starting a new compaction window clears the previous server-observed prefill baseline, so BodyAfterPrefix accounting follows the new compacted context. A stale prepared-window update still leaves the current baseline intact.
  • Repeated compaction without progress now returns ContextWindowExceeded through the normal task-error path, producing an error event and terminal failed status instead of a successful completion.
  • Direct-only MCP tools now have non-dispatching Code Mode stubs that return direct_tool_required, instead of an undefined JavaScript function. MCP tools explicitly omitted from Code Mode remain absent from both its callable tools and metadata.
  • Deferred non-V2 follow-ups capture their status cursor before starting, coordinate the previous completion watcher, and reliably report completion when Running/Completed updates coalesce or a follow-up starts after interruption. Interrupting a turn preserves pending trigger messages without silently restarting them.
  • Realtime streams install their final close callback before router publication and synchronize closed-state registration, preventing close races and stale session registrations.
  • Filtered subscriptions claim only matching pending notifications, preserving unmatched backlog order, deduplication, and byte accounting when concurrent thread-scoped flows share a routing key. Live notifications rejected by existing subscriptions also remain queued for the matching operation's later Wait.
  • JSONSchema now passes the schema object directly to turn/start; its name argument remains for source compatibility, and ObjectSchema defaults additionalProperties to false for strict output schemas.
  • LocalImage resolves relative paths once and uses the resulting absolute path for both validation and submission, preventing client and app-server working directories from selecting different files.
  • Stabilized the existing grandchild-context regression fixture so legitimate extra parent continuations do not receive a test-server 404. The context and ancestry assertions remain unchanged.

Fork maintenance

  • Restored the upstream assemble-codex-package development command.
  • Removed unused Bazel helper parameters left behind by the retired SDK runtime-layout implementation.
  • Removed the redundant single-binary Windows workflow; the existing fork release workflow supports targeted Windows builds with the complete runtime set.
  • Removed a forwarding-only tool-event helper without changing event handling.
  • Removed lifecycle bookkeeping used only to test its own declarations; generated lifecycle metadata checks and runtime behavior remain intact.
  • Made schema generation use the existing platform-aware Python interpreter.
  • Made release packaging verify the exact CLI version instead of accepting a matching substring.
  • Corrected an inherited MCP hook-output regression test to enforce the stricter global/per-tool output budget in both limit orderings.

Retained fork capabilities

  • Configurable byte and line truncation for function, custom, dynamic, MCP, and command output, including overlapping output budgets.
  • Custom providers and context/auto-compaction limits for typed and fallback agents; configurable plaintext messages for cross-provider delegation.
  • Inherited dynamic tools, cumulative per-turn spawn limits, quiet check_agent_status waits, and parent completion notifications.
  • Compaction headroom and progress checks, prompt-cache preservation, and tolerant parsing of malformed completed-response usage metadata.
  • The Go SDK's typed clients, protocol-mode selection, generated bindings, and strict compatibility handshake.

Packages

Each asset contains the complete runtime binary set for one target under bin/. Binary names do not have target suffixes.

  • Linux GNU/glibc: codex-package-x86_64-unknown-linux-gnu.tar.gz and codex-package-aarch64-unknown-linux-gnu.tar.gz, each containing codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy, and bwrap.
  • macOS: codex-package-x86_64-apple-darwin.tar.gz and codex-package-aarch64-apple-darwin.tar.gz, each containing codex, codex-app-server, codex-code-mode-host, and codex-responses-api-proxy.
  • Windows: codex-package-x86_64-pc-windows-msvc.zip, containing codex.exe, codex-app-server.exe, codex-code-mode-host.exe, codex-responses-api-proxy.exe, codex-command-runner.exe, and codex-windows-sandbox-setup.exe.

Upstream release notes: 0.153.3, 0.153.4.

0.153.2

Choose a tag to compare

@Dirard Dirard released this 04 Sep 12:28

Codex fork 0.153.2

Rebased onto upstream Codex 0.153.2 while preserving and adapting the fork-specific behavior. This build uses upstream main at 148f3c1538, including the fixes merged immediately after the 0.153.2 tag.

Upstream changes since 0.151.0

  • Added Vim undo/redo, remote plugin marketplace management, optional TUI auto-recaps, richer command history, and more resilient TUI reconnect/session handling.
  • Added GPT-6-Astra catalog support and corrected the Fast tier description to “2x speed, increased usage.”
  • Improved Guardian history, compaction, permission handling, rollout compression, MCP approvals, OAuth refresh, and remote execution safety.
  • Added model/reasoning metadata, structured asynchronous questions, active protocol mode, MCP tool-discovery errors, managed codex exec worktrees, local file citations, and voice-host WebRTC negotiation.

Fork-specific changes

  • Fixed Go SDK rate-limit requests so optional flags reach the wire while the legacy zero-argument API remains source-compatible.
  • Restored the strictest effective truncation budget when global and per-tool MCP limits overlap.
  • Extended plaintext cross-provider agent messaging to spawn_agent, send_message, and followup_task calls issued from Code Mode.
  • Preserved configurable byte and line truncation for function, MCP, custom, and dynamic tool output.
  • Preserved at least three retries for model-capacity errors.
  • Preserved custom context-window and auto-compaction limits for root, typed, fallback, and cross-provider agents.
  • Preserved compaction headroom, inherited dynamic tools, bounded per-turn spawning, check_agent_status, and Code Mode direct-tool routing protection.

Go SDK

  • Regenerated stable and experimental bindings against the current app-server protocol.
  • Added plugin reconciliation, parameterized rate-limit reads, app links and approval settings, asynchronous questions, expanded thread/model/environment metadata, activeProtocolMode, and MCP toolsError reporting.
  • Preserved existing high-level and raw API compatibility for account rate-limit reads.
  • Manifest, schema, generator drift checks, and go test ./... pass.

Packages

Each asset is a complete runtime package for one target. Binaries keep their normal runtime names and do not have target suffixes.

  • Linux: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy, bwrap.
  • macOS: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • Windows: codex.exe, codex-app-server.exe, codex-code-mode-host.exe, codex-responses-api-proxy.exe, codex-command-runner.exe, codex-windows-sandbox-setup.exe.

Upstream changelog: openai/codex@rust-v0.151.0...rust-v0.153.2

Fork changelog: rust-v0.151.0...rust-v0.153.2

0.151.0

Choose a tag to compare

@Dirard Dirard released this 30 Aug 02:42

Codex fork 0.151.0

Rebased onto upstream Codex 0.151.0 while preserving and adapting the fork-specific behavior.

Upstream 0.151.0

  • Added a configurable grace period for discovering tools from optional MCP servers.
  • Extensions can inspect or replace MCP tool results before they reach the model.
  • Plugin catalogs now combine repository-specific configuration and report invalid project marketplaces without hiding valid plugins.
  • Preserved restored permission profiles across TUI turns and prevented /cd from weakening sandbox restrictions.
  • Kept tool availability and reasoning effort correct when switching or falling back between models.
  • Improved remote sandbox enforcement and preserved structured MCP errors.
  • Counted nested subagent token usage toward root goal budgets.
  • Prevented stale Guardian classifications from authorizing actions after permission changes.

Fork-specific changes

  • Preserved configurable byte and line truncation for function, MCP, custom, and dynamic tool output while retaining upstream per-tool MCP limits.
  • Added regression coverage ensuring dynamic tool output follows the configured line limit.
  • Preserved at least three retries for model-capacity errors.
  • Preserved compaction headroom, cache-aware message budgeting, and failed-tool progress handling.
  • Preserved custom context-window and auto-compaction overrides for root, typed, fallback, and cross-provider agents.
  • Preserved plaintext cross-provider subagent messages, inherited dynamic tools, bounded per-turn spawning, and the check_agent_status tool.
  • Preserved Code Mode direct-tool routing protection and camelCase Go SDK timeline fields.

Go SDK

  • Regenerated stable and experimental bindings against the 0.151.0 app-server protocol.
  • Added auth-recovery notifications, project sorting/metadata updates, shell command timeouts, and elicitation updates.
  • Auth-recovery notifications now expose reviewed thread/turn routing metadata.
  • Generator drift checks and go test ./... pass.

Packages

Each asset is a complete runtime package for one target. Binaries keep their normal runtime names and do not have target suffixes.

  • Linux: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy, bwrap.
  • macOS: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • Windows: codex.exe, codex-app-server.exe, codex-code-mode-host.exe, codex-responses-api-proxy.exe, codex-command-runner.exe, codex-windows-sandbox-setup.exe.

Upstream changelog: openai/codex@rust-v0.150.0...rust-v0.151.0