Skip to content

Codex fork 0.155.0

Choose a tag to compare

@Dirard Dirard released this 18 Sep 21:42

Codex fork 0.155.0

This release updates the fork from 0.153.4 to 0.155.0: a rebase onto the pinned upstream main snapshot, reconciliation of the fork's runtime changes, an expanded Go SDK, and five complete runtime packages.

Comparison baseline

  • Previous fork release: 0.153.4, commit 20a8b8519f4d8bd58b9bfb94f87516fa2eab1a0e.
  • Previous upstream-tracking base: 59acd25a948759cf0d0f8454bc9ded6e48e72f52.
  • New fork upstream-tracking base: 08ff997106556c1bae45144b717ecbbffde14744, corresponding to upstream main@7498521d288b9b3b96ffba4eedf089d8d6e06a84 on September 18.
  • Released fork source: 3c37c16dc636604b7cc7324eed09d2a45db516fb.
  • CLI tag: rust-v0.155.0; matching Go SDK tag: sdk/go/v0.155.0.

This is a main-based fork release, not a byte-for-byte rebuild of OpenAI's 0.155.0 tag. It incorporates changes from the 0.154.0/0.155.0 development cycle and later main-branch work. The previous fork already contained some changes subsequently advertised in upstream 0.154.0, so those are not presented again as new fork features.

The sections below describe behavior and compatibility changes. The expandable changelog at the end lists all 641 upstream non-merge commits between the pinned bases, including smaller fixes, tests, refactors, and build changes.

Upgrade and compatibility notes

  • Update the CLI/app-server and Go SDK together: the strict protocol, schema, and manifest digests changed.
  • The Go module path remains github.com/openai/codex/sdk/go; the minimum Go version remains 1.25. Select the fork revision/tag through your existing fork integration.
  • thread/rollback and ThreadsClient.Rollback are removed. Migrate to thread/revert and ThreadsClient.Revert, using the new request/response types.
  • The deprecated codex mcp-server command is removed upstream.
  • Each downloadable archive contains one system's runtime under bin/, with no target suffixes on executable names. Replace the binaries together.
  • Native voice requires additional helper/audio resources that are not included in these bin-only fork packages.
  • Existing published release tags were not moved. This update does not automatically change your user configuration.

Upstream changes since the previous fork release

Threads, worktrees, and task management

  • Expanded managed worktree support for new and forked sessions: creation from session commands and the agents overview, browsing/resuming linked worktrees, ownership details, and confirmed deletion of clean managed worktrees. Worktrees are enabled by default in the pinned main snapshot.
  • Added task hiding, archiving, deletion, direct session creation, model grouping, task token/usage estimates, and richer Markdown task details to the agents overview/command center.
  • Conversations with another active writer can be opened as read-only history, preserving the user's draft instead of attempting to take over the writer.
  • Resume and fork paths better preserve saved permissions, runtime workspace roots, collaboration mode, multi-agent runtime selection, and model/profile settings. Fresh sessions and implicit forks respect server defaults unless explicitly overridden.
  • Fixed stale history after switching threads, draft/focus loss around task transitions, ambiguous session labels, and composer responsiveness while creating a session.
  • Editing an earlier prompt uses the current thread's revert operation. The retired rollback API was removed.
  • Current attachments are copied into non-ephemeral forks, and pending automatic title generation is cancelled after a manual rename.

Background server, updates, and recovery

  • Added configurable daemon update schedules, codex app-server daemon update, explicit package replacement, and a local /daemon menu.
  • Added --no-daemon to bypass the shared background server, plus opt-in automatic background-server startup.
  • Managed shutdown persists loaded threads and recovery candidates. Saved threads, active goals, and interrupted work can be recovered after a managed daemon restart.
  • Improved cancellation-safe thread startup, release of persistent writers, shutdown admission, bounded stdio shutdown, and Unix SIGTERM handling.
  • Separated daemon packages from standalone CLI installation and improved managed-package discovery and bootstrap behavior.
  • These server-side recovery changes do not establish that a separately observed desktop-client pending goal/set indicator/callback issue is fixed.

Context, compaction, goals, and resource usage

  • Model context, extension context, tool planning/execution, history recording, and subagent spawning use the settings captured for the originating step rather than unrelated later or initial turn settings.
  • Preserved originating tool-output budgets across resume/fork and delayed Code Mode notifications.
  • History token estimates are based on content rather than serialized message envelopes.
  • Accepted user prompts are persisted even if compaction fails before a turn starts.
  • Supported providers use streamed remote compaction; the unused legacy remote-compaction implementation was removed. Compaction checkpoint validation is centralized, and fallback can use the current model.
  • Reasoning-effort overrides are preserved through recovery/compaction where required, with duplicate or disabled overrides filtered appropriately.
  • Ephemeral forks preserve parent cache affinity; file-ID images participate in context budgeting and are normalized for the receiving model.
  • Added user-requested goal pause support and blocking after three empty automatic goal-continuation turns.
  • Reduced unnecessary copying, repeated catalog lookups, and allocation around active turns, MCP schemas, and Code Mode results.
  • No fixed token-savings percentage is claimed: these are correctness and resource-use changes, not an end-to-end usage benchmark.

Code Mode and multi-agent behavior

  • Scoped Code Mode callback delegates to individual executions and preserved the originating context of yielded calls.
  • Hardened nested tool-call completeness tracking, including completed empty inventories, and bounded output previews across result blocks.
  • Discarded tool responses can be garbage-collected; cleared timers and timers belonging to finished cells are cancelled. Undefined values are handled before JSON serialization.
  • Added optional Code Mode overhead timing and more precise dispatch/result tracing. Tool metadata is included in compaction prompts.
  • Added startup tool allowlists for threads and model-catalog descriptions for multi-agent V2 tools, including spawn_agent.
  • Improved delegated-work trigger/identity propagation and visibility of unloaded child threads in environment context.
  • MCP user interaction and plugin-install requests are routed through the root thread.
  • App-server delegated operations, managed thread lifetimes, and cancellation/shutdown boundaries were tightened.

MCP, plugins, authentication, and model providers

  • Existing sessions pick up refreshed plugin tools, skills, and hooks after installation or external updates. Refreshed catalogs remain paired with their clients.
  • Plugin/orchestrator caches survive metadata-only and MCP runtime refreshes; dormant MCP bindings can be reused.
  • Improved OAuth refresh, expired-credential status, reconnect guidance, auth-change notifications, and manual callback entry. Elicitation cancellation/reset on reconnect was corrected.
  • Added native user-verification contracts, cancellation, and tool-continuation support; supported macOS clients can use Touch ID/Secure Enclave verification.
  • MCP requests support read-only policy and use the correct turn environment for policy evaluation. Status exposes advertised server capabilities, and tool-call history preserves MCP App UI metadata.
  • Thread-level plugin exclusions are persisted and applied consistently to runtime capabilities and shared connectors.
  • Model catalogs, cached WebSocket state, and remote-control sessions are tied to the provider/authentication owner and invalidated appropriately when the account changes.
  • Added command-based AWS credential acquisition for Amazon Bedrock, opt-in model discovery for OpenAI API keys, and OAuth credential management for model-provider gateways.
  • Improved managed-provider requirements, residency checks, workspace request routing, and preservation of configured Flex service tiers.
  • Corrected retry classification for throttling, rate limits, quota errors, and non-retryable policy failures.

Attachments, rollouts, memory, and SDK surfaces

  • Added stored thread attachments with transactional add/list/remove operations, pagination, coordinated deletion, and update notifications.
  • Added attachment upload/resolution paths and file-ID image handling. Local images can be transferred as portable attachments to remote app servers.
  • Coordinated rollout compression with active writers, added an experimental compression endpoint, and continued searches when an individual compressed rollout cannot be processed.
  • Added configurable memory versions with isolated storage, memory v2 extraction/consolidation/read prompts, summary-only extraction, priority for user-authored information, dual writing, and readiness/status reporting.
  • These additions do not mean memory v2 or other optional features were enabled in the user's configuration.
  • Expanded experimental user-verification APIs, Daybreak settings, and disabled-plugin overrides.
  • Upstream Python SDK generation, per-turn/history options, subscriptions, and publication were synchronized more closely with the matching runtime. This release does not claim a separate fork PyPI publication.

Guardian, permissions, and sandbox security

  • Preserved user instructions, verified answers, sender context, and authorization evidence through forks, checkpoints, and compaction.
  • Invalidated stale approvals after history changes or permission widening; complete actions and complete request budgets are handled more consistently.
  • Separated review failures from unsafe-action findings and improved transient-failure handling and reuse of stable review-history prefixes.
  • Hardened credential handling in shell snapshots, replay, credential brokerage, and network tunnels.
  • Filesystem paths, socket grants, network policies, and permission profiles use the executor's operating-system/path context, including mixed-OS client/server setups.
  • Strengthened daemon socket isolation and Linux/WSL sandbox boundaries, including WSL interop and duplicate-root escape paths.
  • Expanded Windows sandbox/MXC execution, networking, provisioning, identity/runtime permissions, account repair, registration refresh, and uninstall cleanup.
  • No authentication, authorization, sandbox, or secret-handling checks were intentionally relaxed by the fork reconciliation.

TUI and native voice

  • Added streaming reasoning summaries in the status row and completion timestamps after successful turns.
  • Improved transcript restoration, half-page scrolling, tmux resize recovery, terminal scrollback, SSH/tmux clipboard routing, and streaming prose before a newline.
  • Added Mermaid diagram rendering, inline/display math rendering, and additional Unicode math symbols.
  • Added session-only model/reasoning selection, consistent task colors, clearer activity summaries and recaps, and reduced-motion/screen-reader behavior.
  • /copy can include status fields and completed commentary. Pending inline questions are cleared when a new prompt is accepted.
  • Removed personality selection from the TUI.
  • Upstream added native voice conversations, live transcripts, microphone/mute controls, voice selection, and configurable shortcuts, with many audio/transcript reliability fixes.
  • Voice is not available from this release's bin-only fork packages: the separately prepared native audio runtime and voice helper are not included.

Build, packaging, and internal maintenance

  • Updated Rust/workspace dependencies, platform toolchains, native voice preparation, Windows build/provisioning infrastructure, and release packaging throughout the upstream range.
  • Improved release-upload serialization/retries, runtime/SDK publication coordination, pinned V8 artifact handling, and deterministic schema generation.
  • Split large runtime/Guardian/TUI implementation areas into focused modules and expanded regression coverage.
  • Removed the old app-server README/contributor update requirement and retired repository devcontainer configuration.
  • The complete commit list below includes the individual maintenance, testing, and platform changes that are not separate user-facing features.

New fork fixes and rebase reconciliation

These changes adapt the existing fork to the new upstream architecture. Some defects were caught in the rebased candidate before release; this is not a claim that every one existed in the previously published 0.153.4.

  • Truncation follows the producing step. Extended output limits use the captured step settings, not stale initial turn settings after a model change.
  • Resume/fork/replay retain extended limits. The fork now works with upstream's raw rollout storage. Originating byte/token policy plus general and MCP line limits are persisted and reapplied when reconstructing model context. Raw output on disk is not permission to inject it unbounded into the model. The legacy token-budget metadata alias remains compatible.
  • Delayed Code Mode results retain byte limits. Fixed loss of configured max_bytes in notification preparation and prevented legacy token-only metadata from overriding the complete originating policy. The byte-limit regression failed before the fix.
  • New idle-agent tasks receive the correct spawn budget. V1 send_input and V2 follow-ups carry the requester's captured budget through ordered internal submissions and the mailbox. A new idle task no longer inherits an exhausted budget from its predecessor. Active tasks and QueueOnly messages keep their existing budget; no public protocol fields or turn-ID lookup registry were added.
  • Full-buffer process cleanup is restored. Upstream cancellation/deadline and pipe-drain behavior again handles descendants that keep pipes open after the leader exits, without reporting incomplete capture as a successful full result. The fork's bounded partial-output drain for ordinary shell tools remains. Nine existing cleanup regressions were reproduced before repair.
  • Sensitive startup output is not logged before redaction. Restored the SensitiveFullBuffer guard for filesystem-denial diagnostics.
  • Linux namespace mounts no longer break sandbox setup. Mount roots such as net:[inode] are not incorrectly treated as ordinary filesystem paths. Socket-directory alias, nested-mount, and covering-mount protections remain enforced.
  • Cross-provider plaintext delivery uses the current upstream path. The fork's option is integrated into centralized agent delivery, including delivery initiated from Code Mode, rather than restoring retired helpers.
  • Tool instructions are consistent. Shared guidance uses check_agent_status and EXEC_TOOLS. Direct-only routing recovery, explicit tool omissions, and warnings about unobserved nested results remain.
  • Obsolete/conflicted integration code was removed. Tests and call sites were adapted to step/session settings, image references, per-execution Code Mode delegates, and host timing fields.
  • Release/SDK workflows were reconciled. Restored required packaging environment setup, corrected outdated arguments and Windows command structure, and aligned cache/runtime validation conditions.
  • Versioning is consistent. All 154 local workspace package records are stamped 0.155.0. The version-stamp commit does not introduce additional external dependency changes, and Bazel lock regeneration produced no drift.
  • Previously reverted unified-wait/background-disable experiments and cascading subagent interruption were not reintroduced as fork features.

Go SDK changes

New methods and options

  • Added ThreadsClient.AddAttachment, ListAttachments, and RemoveAttachment, plus routing for thread/attachment/updated.
  • Added ThreadsClient.Revert; removed the retired ThreadsClient.Rollback and its old protocol contract.
  • Added Memory.Status, ThreadStartOptions.DaybreakEnabled, and TurnOptions.DisabledPluginIDs.
  • Preserved the distinction between an omitted disabled-plugin override and an explicitly empty list.
  • Added ImageFileID(...) alongside URL and local-file image inputs.
  • Generated typed Raw() methods cover newly exposed experimental APIs, including user verification and rollout compression.

Protocol and decoder correctness

  • Regenerated stable/experimental schemas, Go bindings, routing metadata, manifest information, and strict compatibility digests against the released app-server.
  • The resulting inventory is 104 stable / 167 experimental-mode client methods and 62 stable / 84 experimental-mode server notifications. Experimental-mode totals include stable methods/notifications; they are not additional counts.
  • Corrected nested image anyOf decoding to match Rust's URL/file-ID alternatives without inventing an exactly-one restriction.
  • Alternatives decode into temporary values and are assigned only on success. Reused receivers clear stale alternative fields, including an old URL that is absent from the new payload.
  • Invalid-only inputs are rejected, valid selected alternatives survive JSON round trips, and malformed non-selected alternatives do not invalidate an otherwise accepted variant.
  • Global Optional semantics and strict audio validation were not weakened.
  • Updated serde defaults and experimental-field gating and restored the user-verification RPC error export.
  • Retained previous timeline camelCase, nullable/union JSON, OAuth/realtime, additional-context, JSON Schema, local-image path, and filtered-notification/completion fixes.

Integration

Use the matching sdk/go/v0.155.0 revision with this CLI/app-server. The module path and Go 1.25 minimum are unchanged. Strict compatibility checks intentionally detect mismatched protocol/schema/manifest versions.

Existing fork capabilities retained

These are cumulative differences retained from earlier fork releases, not newly introduced features of 0.155.0:

  • Configurable model-visible byte and line truncation for function, custom, dynamic, MCP, and command output, including overlapping budgets and the strictest applicable MCP limit.
  • Custom providers and context-window/auto-compaction overrides for typed and fallback agents.
  • Configurable plaintext cross-provider agent messages and inherited dynamic tools in child/delegate threads.
  • Cumulative per-turn spawn limits, race-safe publication accounting, quiet check_agent_status waits, and parent completion notifications for follow-ups.
  • Compaction headroom, bounded retained history, no-progress detection that does not count failed tools as useful progress, and correct failed-turn reporting when compaction cannot progress.
  • Prompt-cache preservation during local compaction and prefill reset when the context window advances.
  • At least three retries for model-capacity errors, including local compaction.
  • Tolerant parsing of malformed completed-response usage metadata.
  • User input support up to 2 MiB.
  • The fork's typed Go SDK resource clients, event/request routing, and strict runtime compatibility handshake, including the earlier wire-format and subscription fixes.

Downloadable packages

All five packages are built from 3c37c16dc636604b7cc7324eed09d2a45db516fb. Executable names inside bin/ have no operating-system/architecture suffixes.

  • Linux GNU/glibc x86_64 and ARM64: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy, and bwrap.
  • macOS x86_64 and ARM64: codex, codex-app-server, codex-code-mode-host, and codex-responses-api-proxy.
  • Windows x86_64: codex.exe, codex-app-server.exe, codex-code-mode-host.exe, codex-responses-api-proxy.exe, codex-command-runner.exe, and codex-windows-sandbox-setup.exe.

The Linux packages use GNU/glibc, not musl. Native voice resources and optional provisioned Windows sandbox-service packaging are outside this bin-only layout; the ordinary Windows helper binaries are included.

Validation and known limitations

Completed checks

  • Full Go test suite with -race; stable/experimental generation and manifest checks; strict SDK handshake against the built runtime.
  • Targeted context, truncation, replay, model-switching, cross-provider, compaction, and agent regression suites.
  • 87 execution tests, including the reproduced cleanup regressions and sensitive-logging checks.
  • 100 related agent/queue/delegate/budget tests and a separate 80 Guardian/turn-input/step-activation tests.
  • Code Mode, protocol, transport, configuration/model, history/output-truncation, and Linux sandbox checks.
  • Core/app-server all-target checks, scoped Clippy, formatting, and generated-schema consistency.
  • Independent Astra review found five blocking defects in the candidate; all five were repaired and closed in the targeted recheck. No blocking findings remained on the released source.
  • All five GitHub build jobs passed. Each runner checked the package listing and codex-cli 0.155.0 before uploading.
  • Downloaded archives were checked for exact layout, integrity, executable permissions, and CLI architecture. Linux x86_64 also passed a local version smoke check.
  • SHA-256 digests of all five published assets matched the checked local archives; all five public download URLs were verified.

Limits of the validation

The full app-server suite was not completely green: 1738 passed, 7 failed, 2 skipped on the local validation host.

  • Six failures were caused by additional stderr from the host's Ubuntu im-config/systemd-cat initialization.
  • One process-disconnect cleanup failure was reproduced with system bubblewrap 0.11.1: an inner sandbox process survived termination of the outer wrapper. The same isolated check passed with bundled 0.11.2, while the relevant app-server lifecycle code was unchanged from upstream.
  • Upstream prefers an installed system bwrap over the bundled fallback. Installing this archive alone does not resolve that host case if the older system binary still takes precedence.
  • Native voice is not supported by these packages because the optional audio runtime/helper is not bundled.
  • Provider/agent regression tests used mocks; no claim is made that every external model/provider was exercised through live paid requests.

Source and complete changelog

Because the fork was rebased, comparing release histories by commit count alone can include rewritten older fork commits. The pinned upstream-base comparison, the four new fork commits, and the cumulative fork comparison above separate those cases.

Complete upstream commit log since the previous fork base — 641 non-merge commits

Newest first. Original commit subjects are retained; PR links point to openai/codex. This index also includes intermediate changes that were subsequently refined or reverted; the sections above describe the released behavior.

  • 7498521d28 Keep MCP policy evaluation consistent with turn environments (#46335)
  • 3724dc8361 Share platform identity across path, network, and sandbox configuration (#46334)
  • fd875b188b Handle disabled Windows sandbox accounts during cleanup (#46333)
  • 3cd255a4ee Dim conversation recaps in the TUI (#46332)
  • ad70cbdd96 Defer environment network policy validation until after composition (#46331)
  • ff73d63e64 Move retry backoff into codex-async-utils (#46330)
  • 608e4cc9a1 Avoid persisting project trust for projectless directories (#46328)
  • 5492c2b06e Broaden compaction fallback to the current model (#46324)
  • a1efb59c4a Record active plugin inventory in turn analytics (#46323)
  • 1f631def3f Set the Windows sandbox type in the pending environment test (#46322)
  • f8c6026c38 Preserve web search actions and results in exec JSON output (#46319)
  • a129392ebb Add OAuth credential management for model provider gateways (#46318)
  • c775dd3c33 Defer environment selection changes until the next turn (#46310)
  • 0c9be8a836 Preserve plugin caches across display metadata refreshes (#46309)
  • fa8cf44985 Preserve bio policy errors as a distinct non-retryable error (#46306)
  • 55db7e8c88 Avoid cloning turn items for app-server active turn lookups (#46305)
  • 7a3c5a83e4 Serialize release asset uploads to avoid secondary rate limits (#46303)
  • ea218f5cd8 Validate network socket policies using the executor OS (#46302)
  • 8f73cdee45 Centralize OAuth login and refresh handling with safer diagnostics (#46300)
  • 3e581ebca8 Support catalog descriptions for all multi-agent V2 tools (#46297)
  • 17baabd01b Separate thread startup metadata from replay history (#46294)
  • 47fc8d661e Route skill discovery and loading through EnvironmentAccess (#46293)
  • 93321c88d8 Preserve selected reasoning effort for synchronous Guardian reviews (#46292)
  • 47915cee7a Filter saved reasoning overrides from requests when disabled (#46291)
  • 0fd1cd8d99 Add opt-in overhead timing to code-mode responses (#46288)
  • 0a5b999169 Connect app-server workspace discovery to model request routing (#46281)
  • d7f8e48d7d Preserve Guardian's reusable history prefix across approval requests (#46279)
  • 3ed49879c8 Reduce R2 release upload concurrency and enable standard retries (#46278)
  • 8b78600dc8 Enable MXC selection through Windows sandbox configuration (#46271)
  • 3d3ae4965a Add filesystem accessors bound to environment permissions (#46268)
  • 608825d511 Expand Unicode math rendering with accents, symbols, and delimiters (#46266)
  • 16f49ccd7f Relax delegation guidance in the v2 spawn_agent description (#46264)
  • 96aca987f7 Preserve uploaded image file IDs in user message display history (#46258)
  • fcf05456bb Publish Guardian cached scores and coverage atomically (#46245)
  • 2833985d88 Repair Windows sandbox access to existing runtime children (#46241)
  • 32b54cffdd Prefer the provisioning service for automatic Windows sandbox setup (#46239)
  • c11fdc944f Improve Windows sandbox error details and registry cleanup (#46237)
  • 7abf2a3b5c Preserve configured Flex tiers without catalog or fast-mode support (#46230)
  • e269f2164c Include sender user messages in Guardian delegation reviews (#46179)
  • b0659c5386 Record daemon startup and update telemetry with consent handling (#46126)
  • 1bd1bfa7ca Fix daemon socket isolation checks for private tmp mounts (#46125)
  • c5d079470e Allow model catalogs to override the V2 spawn_agent description (#46123)
  • a4ee536f01 Route filesystem reads and writes by their own sandbox permissions (#46122)
  • 70e8fe1be3 Add opt-in automatic background server startup (#46117)
  • 4b0f19d6f9 Make TUI web and image activity summaries compact and descriptive (#46116)
  • 841b5490b2 Preserve filesystem sandbox policy context when the cwd disappears (#46112)
  • 108e6a6dbe Replace Sites migration state with a runtime compatibility guard (#46108)
  • 77c1feb00e Box app-server request handler futures to reduce stack usage (#46107)
  • 16f59db96e Pause TUI events in the agents overview regression test (#46104)
  • f3da3861c5 Add a one-time composer starfield for new Astra tasks (#46096)
  • 787823cf95 Add --no-daemon to bypass the shared background server (#46088)
  • 8452164c76 Mark finished empty Code Mode tool inventories as complete (#46081)
  • 1e9564fb85 Keep the composer responsive during Command Center session creation (#46077)
  • 800d183e2d Use captured step settings when spawning subagents (#46075)
  • 6749535c8f Bound code-mode output previews across result blocks (#46073)
  • b974893c90 Account for file images in context budgets and Guardian reviews (#46072)
  • ce03f22af6 Add a configurable F8 shortcut for voice conversations (#46071)
  • 36b84c81ec Suppress warnings when skill descriptions are shortened (#46070)
  • 172f8a2901 Use syntax theme colors for inline code and file paths (#46069)
  • e22e6523eb Remove the done prefix from TUI completion timestamps (#46067)
  • 40584fad87 Keep MCP user interaction on the root thread (#46066)
  • 5e636ea760 Route prepared images through the attachment store (#46065)
  • 08663cc91b Consolidate Guardian tests at shared policy and context boundaries (#46064)
  • e412b93d08 Trim Guardian tests and tighten request layout assertions (#46063)
  • 8ace915ace Attribute analytics events to realtime voice sessions (#46058)
  • f915e0de07 Render Mermaid code blocks as diagrams in the TUI (#46054)
  • c56dda711c Track WebSocket continuation modes and full-input send reasons (#46051)
  • 821ad43f9d Tag rollout compression metrics by trigger (#46047)
  • 20f4d12f76 Include Code Mode tool metadata in compaction prompts (#46044)
  • 51c30ad800 Repair expired Windows sandbox account passwords during setup (#46043)
  • b97abdbe30 Add read-only policy support to MCP tool requests (#46042)
  • 78e7825a47 Tighten request handling in Guardian approval tests (#46041)
  • 515530d9b2 Default TUI animations off when a screen reader is detected (#46040)
  • 4cf84b7603 Test Windows sandbox bin DACL modification permissions (#46038)
  • 4fa7e82274 Preserve config error causes when saving the approvals reviewer (#46036)
  • a6d4741d39 Add per-app tool exposure configuration (#46035)
  • 29e6bc814e Preserve orchestrator skill caches across MCP runtime updates (#46033)
  • 73bf181272 Require forced macOS preferences for managed configuration (#46032)
  • 105fe8761c Keep Noise relay streams alive after repeated handshake failures (#46031)
  • 2b2b0fa870 Allow browser app cleanup hooks on interrupt (#46029)
  • 47c27cbffa Document and test ? wildcards in network proxy domain patterns (#46027)
  • a8c36ca6d2 Centralize model-message resolution and rendering in codex-prompts (#46026)
  • 0d083092b4 Add an experimental rollout compression endpoint (#46020)
  • 6d75b525ea Allow hosted Apps MCP contributions to override the protocol mode (#46019)
  • fc2ea82e7e Allow callers to disable executor skills per environment (#46015)
  • a2f62e88cf Route permission shortcuts through the shared selection flow (#46013)
  • bee042d119 Enforce managed residency when constructing API providers (#46011)
  • 3a589370a4 Enable app tool result metadata with analytics controls (#46010)
  • 7f0ab95827 Centralize compaction checkpoint selection and validation (#46009)
  • 2b59d92dbd Route built-in permission selections through the app server (#46008)
  • 39a99a6c36 Report clock failures again after recovery (#46006)
  • 43354d0f61 Preserve attachment Unix socket grants when controller policy is omitted (#46004)
  • 3c6f32ca82 Extract route-aware HTTP request execution into a separate module (#46002)
  • fd346b8dba Centralize Guardian action preparation for review (#45987)
  • 66dfadbe66 Replace guardian review result tuples with named structs (#45985)
  • 49305d74b4 Isolate app-server Unix sockets from filesystem-restricted commands (#45984)
  • 0666c12e78 Show a loading message when opening tasks from the agents overview (#45983)
  • 53401a2808 Use native DNS resolution for the network proxy on macOS (#45982)
  • 7b6dd0c7b8 Preserve session config when switching thread permission profiles (#45981)
  • d7104e268b Fall back to summary history for read-only conversations (#45980)
  • 5761102868 Keep selection adjacent when hiding tasks in the agents overview (#45978)
  • da18000cae Measure rollout read and materialization durations (#45966)
  • 2d90e054d6 Expose partial completion in rollout compression metrics (#45964)
  • 9b43825f23 Tag memory usage telemetry with the memory version (#45960)
  • 7275afc5c7 Centralize Guardian policy resolution in config and protocol (#45957)
  • 6500c1f844 Record memory storage size after successful consolidation (#45956)
  • 4701aa4b42 Avoid redundant model catalog lookups in reused Guardian reviewers (#45933)
  • 977193486d Bound model catalog decode errors and classify request timeouts (#45928)
  • 8f38d5a877 Make Code Mode wrappers transparent to Guardian model policies (#45915)
  • 2aff7208fe Add a hidden HTTP/3 TCP tunnel command (#45900)
  • 50d77959bf Reject paths in project documentation fallback filenames (#45865)
  • 83dc7d11e8 Preserve executor path URIs in permission profile workspace roots (#45863)
  • 04581f9604 Add /daemon menu for local background server updates (#45854)
  • 7322c5e790 Preserve executor path conventions in permission summaries (#45852)
  • 90f7b37d23 Preserve the app-server shutdown signal future across loop iterations (#45849)
  • ffae979216 Revert the current thread when editing an earlier TUI prompt (#45845)
  • 8ece31a7bf Hide WSLg's duplicate root in restricted Linux sandboxes (#45837)
  • 0dfb28edb9 Allow session-only model and reasoning selection in the TUI (#45831)
  • ca99b271d4 Use app-server configuration for Windows sandbox state in the TUI (#45830)
  • 5bf132cd52 Add opt-in nonfatal handling for clock read failures (#45825)
  • fac58c1153 Run R2 publishing when release dependencies succeed (#45823)
  • ced02c5c38 Add opt-in response body limits to the HTTP transport (#45822)
  • 73db60e71f Use app-server state for TUI Windows sandbox decisions (#45821)
  • f2b5b81f39 Continue interrupted work after managed daemon restarts (#45820)
  • 7c709f0ffd Add a bounded Mermaid text renderer (#45817)
  • 7f501cd334 Track Windows sandbox policy and per-thread executor hosts in the TUI (#45813)
  • 58e2e8cf3c Add workspace routing support for Responses requests (#45812)
  • 8f9d0e4652 Bound WSL terminal detection and handle inconclusive probes safely (#45811)
  • 883af106b9 Retire the personality feature flag and document deprecated settings (#45809)
  • 4d2807023a Record interrupted turns in managed daemon recovery snapshots (#45807)
  • 7f83d4922d Restrict plugin install requests to the root thread (#45806)
  • b71af39fe6 Preserve MCP App UI metadata in tool-call events and history (#45805)
  • 872fc22f9c Complete Windows sandbox uninstall cleanup (#45799)
  • 63c09ed212 Preserve ImageUserInput in the Python SDK (#45796)
  • 7b8b17b97a Support image references by file ID in inputs and tool outputs (#45794)
  • c51cb968e4 Preserve Guardian evidence during checkpoint migration (#45789)
  • 0c3a14bbc2 Preserve Guardian authorization evidence across checkpoint migration (#45782)
  • 1427825c40 Normalize bullet glyphs in the image preparation disconnect snapshot (#45781)
  • 321dcf5a6f Allow daemon updates to restore pinned packages to latest stable (#45780)
  • c0316291ca Use native process identities for PID-managed daemons (#45779)
  • b1f3c2f77e Expose experimental analytics plan history and improve navigation (#45772)
  • de40696ec4 Improve analytics chart readability and navigation (#45770)
  • 9bd49c9dcc Add an account Summary tab to Analytics (#45769)
  • 8f0d2459ac Add consumer Top chats usage analytics (#45768)
  • 0d0979f457 Add gated plan usage history to TUI analytics (#45766)
  • 0e7ab7c1b5 Add Top chats to usage analytics (#45765)
  • ca53e19c75 Add an account analytics dashboard to /usage (#45764)
  • af3bc6f796 Add stacked chart primitives for account analytics (#45763)
  • 1fc46a532b Load analytics reports with server plans and account identity checks (#45762)
  • aaa2cabfbc Disable V8 optimization paths affected by array sort bugs (#45760)
  • a5c15ab5c0 Wire Windows sandbox selection into managed proxy routing (#45757)
  • af1fc2dbff Honor canonical plugin disables for shared connectors (#45755)
  • 9899091441 Extract reusable Bash and Zsh startup scripts (#45749)
  • 8a30bc31ef Explicitly gate DotSlash publishing on release success (#45746)
  • db078158c3 Add account-bound authentication for analytics requests (#45742)
  • 7224096b85 Add token history and credit formatting helpers for analytics (#45741)
  • 1fd5399004 Add account analytics data normalization to the TUI (#45740)
  • ab3b40c28b Add typed account analytics reports to the backend client (#45739)
  • fbad00774b Separate Windows sandbox implementations from legacy setup modes (#45737)
  • eeded5ba1a Route Guardian requests through /responses with identifying headers (#45736)
  • d4e11a9b97 Separate executor sandbox selection from Windows sandbox levels (#45730)
  • a9d2564bcb Move Guardian reviewer configuration into the extension (#45729)
  • 7784318b5f Classify MCP auth and approval outcomes in analytics (#45716)
  • 2fdcdeaf0e Add startup tool allowlists for threads (#45711)
  • 7f01a84eff Move Guardian approval routing into the reviewer extension (#45693)
  • 508a006d7a Pass ReviewModel through guardian review sessions (#45684)
  • 709efcb7a9 Consolidate guardian transcript tests in guardian-context (#45683)
  • 954fa9057b Restrict guardian assessment parsing and circuit breaker visibility (#45680)
  • 1fd392f6b2 Retire the unused Guardian extension prototype API (#45679)
  • 0265dd7b45 Move Guardian review reporting and denial accounting into the extension (#45677)
  • 40f01fbe08 Move spawned-agent interruption rules into AgentControl (#45676)
  • a113f3e063 Consolidate Guardian reviewer lifecycle ownership (#45672)
  • 4415f985dc Move V2 agent message delivery into AgentControl (#45670)
  • b13164d86f Centralize child agent configuration in the agent module (#45669)
  • b0af519c39 Add elicitation classification support to app and MCP analytics (#45649)
  • a8964cb1ba Render standalone display math in the TUI (#45612)
  • 31ffe2bc9a Fix retry classification for throttling and quota errors (#45602)
  • fc269b66ad Add explicit daemon package replacement from the CLI (#45580)
  • 19286b8819 Copy current thread attachments into non-ephemeral forks (#45579)
  • 4e6450bbfd Resume Windows sandbox registration refresh after service restarts (#45559)
  • 653e5fbb9d Seed missing daemon installs from complete local CLI packages (#45558)
  • 446b771049 Add attachment upload and resolution APIs and pass stores into sessions (#45556)
  • 364b511dcd Use shared Bazel cache preparation in SDK CI (#45554)
  • 4199fda578 Add opt-in registered package execution to the Windows sandbox (#45550)
  • 529bcb2fdf Preserve streamed answers and plans when turns terminate (#45549)
  • c18db9ba69 Honor prepared Unix socket permissions in Seatbelt (#45548)
  • 923c6028b6 Move daemon packages out of the standalone CLI installation (#45546)
  • 2f1583b411 Discourage logging full image generation results (#45544)
  • 5a66d460d3 Refactor image content to use a shared ImageReference type (#45543)
  • 6ae5e71458 Add service-managed package registration for Windows sandbox accounts (#45542)
  • 18d7ace221 Move Guardian reviewer lifecycle into the extension (#45537)
  • 12b0164a48 Classify tool analytics events by call origin (#45535)
  • 99914f4950 Honor explicit Unix socket grants in the Linux managed sandbox (#45534)
  • d39cfa8a2d Harden and share Windows sandbox identity helpers (#45533)
  • a4354e2d27 Expose selected workspace routing in app-server account reads (#45529)
  • b44af92ca0 Compress larger Windows release artifacts first (#45528)
  • b0d95427c2 Stage Python runtime wheels directly from package directories (#45526)
  • 60e35765c3 Enable MXC TTY launches and managed networking in the exec server (#45524)
  • e84a594636 Move Guardian reviewer startup into the pool (#45521)
  • 78dfc1349e Add dependencies to the Windows sandbox service (#45520)
  • 91d54f1667 Restore collaboration mode when resuming threads (#45519)
  • 7c73903be2 Route Guardian reviewers through ThreadManager for inline parents (#45518)
  • 280c7e1e56 Use a dedicated mock server in the provider enforcement test (#45517)
  • 520e13a4bc Allow configuring the Guardian prompt template (#45516)
  • fd5bf3b059 Filter plugin-install test analytics by event type (#45515)
  • ef8b356c22 Allow setting daybreakEnabled when starting a thread (#45513)
  • ea3c4848d8 Share MCP tool specs until search results are selected (#45509)
  • b9bfc0aff8 Allow background persistence for steered user input (#45506)
  • 4d5d37c5f8 Add lifecycle tracing for unified exec (#45505)
  • 6ce16aadce Allow ConPTY output to close after the last console client exits (#45504)
  • 973ec2942c Add revocable network policy primitives to the HTTP client (#45503)
  • 08d3748cf0 Add managed thread lifetimes with cancellation-safe startup (#45502)
  • ad8a5e3a1b Render inline TeX math as Unicode in the TUI (#45501)
  • d38b5260a1 Send local TUI images as portable attachments to remote app servers (#45499)
  • afaad7cdc0 Trace global user instruction loading (#45496)
  • a20092a7a2 Expose effective login methods in config requirements (#45495)
  • d3812ddbb3 Make the Guardian deadline cancellation helper crate-private (#45493)
  • 43da136850 Split Guardian V2 async scoring into focused modules (#45492)
  • f2d9bccbde Remove Guardian subagent-spawner plumbing (#45491)
  • e5a2094817 Update rustls and AWS-LC dependencies in Cargo and Bazel lockfiles (#45489)
  • 21b1ef18c6 Retain thread persistence acquisition through session cancellation (#45487)
  • 5fb3b7e401 Fix fuzzy match scoring within Unicode lowercase expansions (#45475)
  • 99b3ab2131 Allow dedicated listeners for managed network proxies (#45463)
  • 3fa9039bd7 Label rollout compression failures by stage and I/O error kind (#45461)
  • 374c4b2d82 Resolve enterprise-managed MCP registrations in the catalog (#45459)
  • b876f88981 Fix clipboard routing for tmux and SSH sessions (#45457)
  • 1a02867bd1 Refactor Windows sandbox setup and service helpers (#45455)
  • 7a48b95c6c Preserve tabs in non-bracketed paste bursts (#45454)
  • 4d8eca1ff3 Attribute command and plugin analytics to the invoking model (#45445)
  • b6a5d5bb14 Preserve Guardian parent response IDs across sampling requests (#45441)
  • f8bed26f7b Share Apps tool catalogs without retaining unused snapshots (#45440)
  • f3803587c9 Share tool output schemas and defer MCP envelope construction (#45439)
  • e9633d7a02 Avoid cloning MCP server status snapshot data (#45428)
  • 2f8603f075 Extract Guardian sampler execution into a dedicated module (#45420)
  • 9d036249da Extract Guardian conversation bookkeeping into the reviewer crate (#45418)
  • b3e0c49dfb Extract guardian transcript selection into guardian-context (#45417)
  • 99cda7a9a5 Invalidate Guardian review sessions after parent history resets (#45413)
  • d761097734 Add session and originating window IDs to MCP request metadata (#45409)
  • d77ebc7223 Cancel code mode timer tasks when cleared or the cell finishes (#45399)
  • 5b1d656018 Publish opt-in provisioned macOS packages with Rust releases (#45345)
  • 3abbf9fe2c Extract Windows sandbox configuration preparation into a helper (#45312)
  • 6f39a47bb3 Add worktree session creation to the agents overview (#45276)
  • 44b9011611 Preserve terminal scrollback when growing the TUI viewport (#45271)
  • a505c71490 Route pastes into the active history search query (#45262)
  • 516f2780fd Open new sessions directly from the command center (#45255)
  • 16537b20a5 Use captured step settings for request metadata and tool hooks (#45248)
  • 36f0dbe796 Register Windows desktop uninstall ownership before sandbox setup (#45224)
  • 1715e55076 Bind direct tool-call metadata to invocation outputs (#45185)
  • e61f381900 Validate Windows sandbox token groups before copying SIDs (#45182)
  • cfde11a24c Extract shared network configuration and environment policy helpers (#45180)
  • a4c61afff2 Split Windows sandbox cleanup into preparation and completion phases (#45178)
  • c379459bba Wire the Windows MXC sandbox into command execution (#45176)
  • dfaf451426 Extract Windows sandbox setup and installation storage into the library (#45169)
  • a592c38c16 Use OpenSSL 3.6.4 for musl builds (#45149)
  • 7efa9d96fb Remove Astra sparkle animation from the TUI composer (#45137)
  • b966240bea Preview streaming prose before a newline arrives in the TUI (#45135)
  • b979d4f1f0 Add a feature flag for asynchronous user messages (#45124)
  • 70eb36203d Prevent multiline report notes from submitting early (#45116)
  • a7475e74aa Use blueberry in the realtime background-agent test fixture (#45112)
  • b4c864dd64 Cancel pending thread title generation after manual renames (#45108)
  • b04a2c2645 Estimate history tokens from content instead of serialized envelopes (#45094)
  • 8d3c6cc13d Preserve conversation context and separate next actions in recaps (#45090)
  • f16c2237a5 Delay automatic recaps and compact their TUI layout (#45089)
  • ee6814bfa4 Consolidate Rust release artifact downloads (#45051)
  • 53c542d944 Use gzip compression level 6 for Codex package archives (#45039)
  • 727e48697d Run DotSlash publishing directly on Ubuntu runners (#45035)
  • c4017a87aa Make context snapshot text rendering consistent (#44976)
  • aee8a55ab6 Show task tokens and usage estimates in the agent command center (#44970)
  • 7efb0262d6 Open tasks managed elsewhere as read-only history in the command center (#44969)
  • 53ff712a48 Add model grouping to the agent command center (#44957)
  • 944d6fd1ba Keep voice captions visible across speaker updates and history handoff (#44952)
  • 89c8bcf37d Add context snapshots for async questions and plugin refresh (#44948)
  • 132c739171 Retire Friendly and Pragmatic personality selection (#44946)
  • cebdb732ea Route TUI Windows sandbox setup through the app server (#44945)
  • 39d193d72d Enforce managed provider requirements on existing app-server threads (#44944)
  • d43f1e7eb2 Clarify the Windows Visual C++ runtime notice for voice packages (#44942)
  • c210f4c222 Respect execution hosts in Windows sandbox setup (#44939)
  • 2e572378f4 Add connector auth failure detection without an install URL (#44938)
  • 12e82f44f8 Remove personality selection from the TUI (#44935)
  • e8271aa8b4 Add scenario snapshots for remote compaction and Code Mode tools (#44934)
  • f3c4d082d9 Remove Windows world-writable scans and warnings from the TUI (#44933)
  • 202d61c629 Unify context snapshots and group requests into windows (#44932)
  • 4d205c7a4d Stop setting YARN_NO_PROXY in the managed proxy environment (#44931)
  • c18277043e Embed friendly instructions in bundled GPT-5.4 and GPT-5.5 (#44930)
  • 16491f7f70 Preserve voice meter history through quiet samples (#44928)
  • 1b5e27c7f0 Accept voice response audio before captions on quiet turns (#44925)
  • 7ef70f95d5 Refresh the speaker format when restarting voice output (#44924)
  • ce7fbb373b Bundle native voice runtimes in Windows releases (#44922)
  • 3f59eb965a Enable TUI voice conversations by default (#44921)
  • 3052bbcf8c Remove the deprecated thread/rollback API (#44915)
  • c62d191c4c Expose disabled plugin settings in the app-server API (#44905)
  • 42cd1ec497 Wire up the native Windows MXC helper entry point (#44903)
  • e3a52b87b2 Expose available access programs in model discovery (#44893)
  • 4dcce4f0c4 Reject token-budget history notes for unsupported starting models (#44883)
  • 33bdf976cc Fade Astra composer stars and stabilize cursor redraws (#44879)
  • 7b491281c8 Return public key metadata from user verification enrollment (#44877)
  • 2c9e1a5775 Add managed network policy support to the Windows MXC sandbox (#44872)
  • 68bc5369ba Enable worktrees by default and clarify local daemon errors (#44870)
  • 122d55cba8 Preserve originating budgets for code mode notifications (#44867)
  • 2fc4bda3ca Preserve originating context for yielded code-mode tool calls (#44866)
  • 3305c4f31d Scope code mode callback delegates to individual executions (#44865)
  • bc5957eac9 Preserve parent cache affinity for ephemeral forks (#44862)
  • 0818b6550b Add consistent theme-based thread colors across the TUI (#44857)
  • 654b0a77d0 Add trusted enterprise MCP auth configuration (#44832)
  • 7a6f469dcf Expose advertised MCP server capabilities in status responses (#44826)
  • 624ccf7947 Test approved command execution with managed unified exec disabled (#44814)
  • 02a8f038b8 Check folder consent before creating or resuming TUI tasks (#44755)
  • b9934480bf Render Markdown in agent overview task details (#44752)
  • ab95cd4dd9 Preserve voice caption order when replaying TUI history (#44749)
  • eab107fed0 Update quinn-proto and allow the pinned H3 Git source (#44747)
  • 84e7d4a1fe Check folder trust after resolving the startup destination (#44746)
  • eaa8b6d917 Make archive confirmation number shortcuts act immediately (#44744)
  • eabb7c91d1 Preserve editor yanks across new sessions and thread switches (#44742)
  • 40b0409aa1 Clarify folder trust prompts and add restricted widget support (#44732)
  • da20788df9 Bundle Linux voice runtimes and improve audio reliability (#44714)
  • 08e49689b8 Return to the command center after session cancellation or deletion (#44711)
  • fc948f8c47 Add a provider for thread-scoped instructions (#44701)
  • dc55274818 Include the Windows sandbox service in release artifacts (#44694)
  • aff3e0db94 Preserve selected profile settings over managed new-thread defaults (#44693)
  • e53c444964 Warn about ignored configuration settings (#44691)
  • 9e22e74e8d Resolve permission profiles with explicit execution-host path context (#44676)
  • 935ac7710d Refresh global instructions at model-request boundaries (#44675)
  • 28f43b0417 Keep voice sessions alive through mute and audio backlog (#44671)
  • 1b83e5cdf9 Restrict login setup redirects to known platform origins (#44670)
  • cc05ecfe17 Resolve filesystem denials with explicit path context (#44669)
  • 78600239a1 Honor system reduced-motion preferences in the TUI (#44666)
  • 84ed5744d9 Trace tool call receipt, result readiness, and code-mode dispatch (#44661)
  • e004dc6a4b Preserve turn triggers across delegated agent work (#44659)
  • 4caa5d615d Keep Windows sandbox private desktops alive across helper exits (#44658)
  • c8a8295e79 Attribute turn metrics to the models used during the turn (#44656)
  • 8570091e14 Honor thread-level plugin exclusions across runtime capabilities (#44655)
  • 5c94936b56 Preserve missing environment variable diagnostics in Codex Doctor (#44654)
  • db2e09106c Keep command center errors visible and preserve drafts (#44651)
  • 1aaa453ce2 Enforce managed model provider selection and definitions (#44650)
  • 60825b4988 Honor thread analytics opt-outs when using shared clients (#44646)
  • e25bedc166 Block non-loopback inbound traffic for the Windows offline sandbox (#44639)
  • 8e2afc0912 Recover OAuth metadata discovery from 503 responses via OIDC (#44636)
  • b9852fe6f7 Focus the task list when reopening the agent command center (#44631)
  • f8ab57359d Add manual callback input to MCP OAuth login (#44629)
  • 9b033b4642 Expose session analytics state in Responses turn metadata (#44628)
  • 4150a2c205 Add bounded environment transport for MXC launch requests (#44626)
  • 9c9451131f Add /voice settings to choose a voice for future conversations (#44622)
  • 5c013177d8 Support temporary and minimal filesystem grants in MXC (#44620)
  • 1afffeabb2 Allow discarded code mode tool responses to be garbage collected (#44619)
  • 663eb5fbdd Invalidate cached Guardian approvals for unscored permission widening (#44617)
  • 86661eb626 Simplify enterprise OAuth login helpers and expand callback tests (#44616)
  • 3422443ec4 Treat non-interactive dumb terminals as warnings in codex doctor (#44615)
  • 3715bf4100 Enable user verification for local Codex Desktop sessions (#44613)
  • 196964ef10 Preserve root turn attribution in turn-start events (#44611)
  • 242c5ce01c Preserve whole diagnostic attachments and report incomplete uploads (#44606)
  • 818f1cca8c Remove repo_url from skill invocation analytics events (#44586)
  • d1696652a2 Support symbolic :root filesystem policies in MXC (#44580)
  • bfca0335fa Tie network approval reviews to their originating execution (#44575)
  • 6bb5be869f Use captured action settings for Guardian reviews (#44574)
  • 6baa076eb6 Allow extensions to select MCP protocol mode per HTTP server (#44571)
  • 287e4f7dbf Preserve Guardian authorization evidence until request budgeting (#44570)
  • 9c4879f3a5 Preserve complete actions in Guardian approval reviews (#44569)
  • 3319d9b296 Add app-server APIs for stored thread attachments (#44564)
  • 94697375cb Add MIME-filtered resource listing for Codex Apps (#44548)
  • 4e6d5c0a96 Move Guardian reporting and denial accounting into the extension (#44544)
  • eca63f0803 Move Guardian reviewer settings and execution into the reviewer crate (#44536)
  • 713caa89f3 Bound app-server stdio shutdown and handle Unix SIGTERM gracefully (#44523)
  • ed6dde9fda Decouple session isolation from subagent attribution (#44521)
  • 9688359977 Bound MCP descriptions separately from Guardian action JSON (#44493)
  • 102fc57e4a Distinguish HTTP quota errors from rate limits (#44492)
  • 537278c65f Reset cached WebSocket state when auth ownership changes (#44489)
  • ee93abb690 Preserve incoming prompts when pre-turn compaction fails (#44487)
  • 5d3fe48b08 Improve Guardian retries and review failure reporting (#44482)
  • 03f014564d Harden Code Mode tool-call completeness tracking (#44472)
  • b348fc2667 Add archive and delete actions to the agents overview (#44433)
  • bf5ebd98c5 Add a hide shortcut to the agents overview (#44424)
  • ddea03ad04 Start Python SDK turn subscriptions at their attachment point (#44400)
  • ea53c8d4f7 Add opt-in model discovery for OpenAI API keys (#44392)
  • 5a9eb145c4 Update the forked-thread hook test to use StartThreadOptions (#44377)
  • a62e98d18c Return focus to the agents overview composer on Escape (#44360)
  • d996b4f02a Report OAuth authentication failures in MCP status snapshots (#44359)
  • e2a9ee05f4 Extract shared footer hint wrapping in the TUI (#44354)
  • 0447e4a1fd Remove path-bearing fields from Guardian review analytics (#44352)
  • 2df0b747ba Add thread attachment operations with coordinated deletion (#44350)
  • e444aa99d7 Distinguish forked sessions in session-start hooks (#44349)
  • c6a59ef923 Support native verification in MCP tool continuations (#44346)
  • 3ef3cecd20 Open tasks with Right from the agents overview (#44344)
  • 1bff94edb6 Bind remote-control sessions to their authentication owner (#44341)
  • d390f0a09c Return to the agent command center after archiving on shared servers (#44337)
  • 0df6366a87 Add bounded tool-result metadata support to executed tool calls (#44336)
  • b5544d5732 Persist disabled plugin IDs in thread settings (#44332)
  • e722303e38 Expose voice conversations in experimental features (#44331)
  • 130d6e4fba Add paginated thread attachment listing to the state runtime (#44330)
  • 2808a9c348 Clear pending TUI questions when accepting a new prompt (#44328)
  • f11d0dd012 Prevent filesystem-root read denies in the Windows sandbox (#44327)
  • 0adfc1f2f2 Return the prompt hash in upload responses (#44325)
  • 0735c51978 Block goals after three empty automatic continuation turns (#44320)
  • eb680c0558 Give hosted Codex Apps an independent MCP protocol opt-in (#44318)
  • e1b23086ac Restore saved threads when the managed daemon restarts (#44314)
  • 434efa95e6 Honor shared Retry-After deadlines for remote control (#44311)
  • 45eec73b11 Add opt-in provisioned macOS CLI release candidates (#44307)
  • 7c88f037d9 Record thread recovery candidates on managed daemon shutdown (#44299)
  • 742472c525 Set turn triggers for guardian and memory requests (#44298)
  • 87cf20ee49 Isolate the hook pipe I/O timeout test from shell startup files (#44297)
  • 72348693ec Enforce the async Guardian classifier's complete input budget (#44293)
  • fa7af3883d Allow user-requested goal pauses through update_goal (#44290)
  • d117c2eb02 Expand MXC volume grants and resolve deny globs (#44289)
  • 885113aa1d Prevent command hooks from hanging on blocked stdin (#44288)
  • f71543813f Block WSL interop escapes from restricted filesystem sandboxes (#44286)
  • 5d3f8752fc Preserve prewarmed reasoning effort across replay and early rollback (#44285)
  • bb71d758cd Add telemetry for the Windows system config namespace (#44284)
  • c1840dc55e Persist loaded threads before managed daemon shutdown (#44283)
  • fcd90d8f07 Enforce complete request budgets for Guardian reviews (#44281)
  • 9caddc5cf5 Surface environment startup failure reasons to the model (#44277)
  • f5c5d9b2b0 Avoid duplicate reasoning effort updates during turn recovery (#44276)
  • 1ac689cc7d Remove the unused legacy remote compaction implementation (#44273)
  • a3ba42b010 Remove the Windows /sandbox-add-read-dir slash command (#44259)
  • 3dc1e2a584 Always use streamed remote compaction for supported providers (#44255)
  • 2617ed2e1c Move synchronous Guardian orchestration into the reviewer extension (#44252)
  • eb7bd64ef9 Remove retired model entries while preserving migration prompts (#44250)
  • 6eecd04fc1 Normalize image detail for the receiving model (#44249)
  • aa88a0333c Preserve tool output truncation budgets across resume and fork (#44248)
  • b64de2f3ad Use the originating model when recording conversation history (#44243)
  • 205f3671e1 Use captured step settings for tool planning and execution (#44242)
  • ed4ca07ba6 Handle credential provider source remapping across config layers (#44241)
  • 3436cad5ab Fix MCP elicitation cancellation and reset state on reconnect (#44238)
  • e8e7103cb9 Extract Guardian review policy into a dedicated crate (#44227)
  • a2e83a783e Continue rollout searches when a compressed rollout cannot be searched (#44226)
  • 4f2449b4b2 Measure total exec-server request duration including queueing (#44207)
  • 8ff4aa8ee4 Use captured step model settings for extension context (#44202)
  • b4507997e0 Use captured step settings when building model context (#44200)
  • ccf470c060 Preserve voice indicator styles during composer sparkle effects (#44198)
  • ce2c2759eb Release persistent writers when session startup is cancelled (#44183)
  • 2bba3a29a0 Use explicit histogram buckets for Guardian context metrics (#44181)
  • c77c34ed33 Reduce TUI stack usage during session transitions (#44176)
  • 0df1daf526 Attach compressed rollouts to diagnostic reports as JSONL (#44175)
  • 17e64839eb Add aggregate budget enforcement for Guardian context (#44166)
  • d3ffbbed5a Add Guardian context cost and request token telemetry (#44164)
  • 73a1148c9c Coordinate rollout compression with active thread writers (#44138)
  • 20f109eadb Reuse MCP bindings while cached servers remain dormant (#44121)
  • 9e868bd9dc Handle empty voice arguments in macOS release packaging (#44101)
  • 634ebc1865 Support credential brokering in plaintext HTTP tunnels (#44089)
  • 1a4096e273 Add untrusted external messages to the Python SDK (#44086)
  • 8afccec87a Expose Python SDK history selection and per-turn options (#44084)
  • 7b9e7d99bd Make staged macOS voice runtimes writable before packaging (#44080)
  • 56d3e8192f Refactor credential-broker tunnel protocol detection (#44077)
  • 38cbebaf3f Support configured credential providers across shell snapshots (#44072)
  • 129fd21687 Reject empty audio payloads in data URLs (#44070)
  • f45115a137 Preserve credential broker destinations across environment filtering (#44068)
  • b4d42052cd Publish Python packages after stable CLI releases (#44067)
  • 5a9aec40a5 Extend configured credential brokerage to embedded aliases (#44066)
  • 85c2d4d921 Fix voice runtime release builds and packaging (#44062)
  • 26ce6649a2 Build Python SDK artifacts before publishing the runtime (#44061)
  • 3d3df0a0ca Raise Guardian's action review limit to 200,000 bytes (#44060)
  • 1bfd383890 Add configurable credential providers to the network proxy (#44056)
  • 96c2b4377f Gate Python SDK publishing on runtime availability and verify PyPI files (#44055)
  • c55db1b8d9 Test Python SDK against the built CLI and installed runtime (#44053)
  • 9ba1d9eb5b Extract credential broker environment and registry helpers (#44049)
  • 283f34387b Use StartThreadOptions across thread fork APIs (#44043)
  • ec512d2347 Harden credential handling in shell snapshots and replay (#44040)
  • a548463b78 Handle copied credentials in the broker and shell snapshots (#44038)
  • 45134c0463 Generate Python SDK types from repository app-server schemas (#44032)
  • fe52d795c9 Add AWS credential export commands for Amazon Bedrock (#44028)
  • 2ce38ae6d8 Support image attachments in agents overview background tasks (#44027)
  • 7aba218851 Refresh workspace lockfile before building macOS voice releases (#44025)
  • 0d46c252b3 Encapsulate executed tool call metadata recording (#44002)
  • b831057106 Clear stale transcript history when switching threads (#43994)
  • 721f46a07a Bundle signed voice resources in macOS releases (#43983)
  • dafb6781ee Heap-allocate the resume future in the legacy history test (#43966)
  • 8c72f2ff56 Use curly apostrophes in protocol error messages (#43961)
  • c3eeaae9a3 Gate new app-server work during graceful shutdown (#43959)
  • 4e09b0c1f1 Increase the TUI thread capability test stack to 12 MiB (#43956)
  • 808b3411fd Cache protected shell snapshots and harden capture cleanup (#43954)
  • 929389f596 Preserve per-image generation IDs in image generation analytics (#43953)
  • 102e1763b9 Keep app-server thread RPCs active until delegated work completes (#43950)
  • 589874be81 Add transactional thread attachment mutations to the state runtime (#43949)
  • 5b682c9875 Show configured app-server updater settings in doctor (#43948)
  • 5ac0b8768d Surface MCP reconnect signals when expired OAuth tokens cannot refresh (#43947)
  • 7c098d8741 Gate new turn submissions on host shutdown admission (#43943)
  • 973dcd80fc Show worktree owner details and add confirmed deletion (#43942)
  • c53f342fec Add executor-context filesystem permission helpers (#43939)
  • 1032738aa0 Tag TUI startup metrics with terminal and multiplexer categories (#43937)
  • 6ab3ae5323 Stabilize subagent and unified exec test fixtures (#43936)
  • fba22e9a2a Track voice session lifecycle metrics in the TUI (#43934)
  • 5e3f0ee94b Avoid Windows sandbox setup for irrelevant proxy port changes (#43930)
  • 9d88e9ae08 Rename thread artifacts to attachments in the state database (#43927)
  • 82d4a98912 Add cancellation for native user-verification RPCs (#43925)
  • 9ec33e1926 Show streaming reasoning summaries in the TUI status row (#43921)
  • 78932f4493 Expose the queued event count on CodexThread (#43918)
  • f419c3214a Remove the repository devcontainer configurations (#43915)
  • 900b1e4cec Add tracing for project instructions and filesystem sandbox operations (#43913)
  • dd112a9fd5 Keep Guardian reviewers on summary-based compaction (#43912)
  • 2e220af1f6 Protect shell snapshots when credential brokerage is enabled (#43909)
  • 1530f828cb Preserve complete shell snapshot exports through filtering and replay (#43907)
  • f046cf35df Scope model catalog caches to the current provider and auth identity (#43906)
  • 4fd2c460dd Extract Windows deny-read glob scan planning into protocol (#43903)
  • 6d377e96eb Propagate Apps tool refreshes to existing threads (#43900)
  • f31bd3adff Persist provider and auth identity with model catalog caches (#43897)
  • 94e4b3d0bd Preserve __oailb routing cookies in ChatGPT HTTP clients (#43895)
  • 9d83c48e5c Preserve thread identity in code-mode tool dispatch traces (#43894)
  • 095da4b7e8 Fix transcript viewer restoration and half-page scrolling (#43889)
  • 5a65fd87d8 Close active network proxy connections on teardown (#43884)
  • cfd5d77d63 Detach Unix hook commands from the controlling terminal (#43876)
  • c1f1467f30 Handle undefined values before JSON serialization in code mode (#43873)
  • 44ab72674e Close MCP stderr readers on client teardown (#43870)
  • ce254df05a Add canonical permission translation for MXC execution requests (#43853)
  • 6515a72db7 Preserve runtime workspace roots across thread resume (#43848)
  • dd9512c000 Include completed commentary in the /copy picker (#43846)
  • b090e901f8 Add staged enterprise OIDC login and coordinated logout (#43844)
  • cbfa321ecd Wait for parent idle before rollback in guardian fork tests (#43842)
  • 2cbbf0c9b5 Add memory dual writing and v2 readiness reporting (#43827)
  • 553df1c691 Add dedicated memory v2 consolidation and read prompts (#43813)
  • e7f5de0a6a Move v2 extraction chunking into the memory writer (#43808)
  • 0337192dfd Centralize Guardian transcript policy in context profiles (#43806)
  • 0034ef93a7 Centralize Guardian context composition (#43805)
  • 74d3a5bf10 Add summary-only extraction for memory v2 (#43800)
  • 6924ce636b Prioritize human evidence in memory v2 extraction (#43799)
  • 5371951292 Batch non-user history eviction to preserve Guardian transcript deltas (#43798)
  • 3f76e88a48 Add configurable memory versions with isolated storage (#43797)
  • 35d9e4bc4d Preserve reasoning effort through compaction and reset it on success (#43796)
  • 31ccaf40c2 Pin request reasoning effort while configuration overrides are active (#43795)
  • df522cae16 Limit app-server storage metrics to session directories (#43790)
  • d6489472f3 Enable user verification for the bundled TUI on supported devices (#43715)
  • c7f81afc19 Enable MCP user verification in the TUI (#43712)
  • 95327467c3 Add TUI request bookkeeping for user verification (#43708)
  • ef6c058202 Disable clock synchronization in the voice audio sink (#43704)
  • 54e04f25db Add a TUI user verification prompt component (#43702)
  • 6b6fdc3572 Preserve split-flap animation state when voice transcripts scroll (#43699)
  • 49a9d78999 Make older app-server notices configurable in the TUI (#43698)
  • 9a3af22d01 Stabilize realtime voice meter sampling across redraws (#43695)
  • 45305dd229 Make the voice mute shortcut configurable in the TUI (#43690)
  • 98c7c0415b Move voice controls into a dedicated composer strip (#43683)
  • 3caf9f9586 Style spoken prompts and link workspace files in voice transcripts (#43676)
  • 4e93cf9b4e Animate live voice transcripts with split-flap tiles (#43656)
  • 4b0d9669cc Add voice mute shortcut and recording activity indicators (#43651)
  • 6fee98cc85 Expand TUI regression coverage for realtime voice conversations (#43645)
  • e7637306bc Add macOS user verification with Secure Enclave signing (#43624)
  • 530383e36d Warn when the connected Codex service is older than the CLI (#43622)
  • 4b0f44d304 Add worktree classification to thread telemetry (#43621)
  • c977cc0c19 Add a stable TUI/app-server version comparison helper (#43619)
  • 8e694e955a Exclude base instructions from the bundled model catalog (#43604)
  • 7d2c58e6e0 Recover missed tmux resize notifications in the TUI (#43603)
  • d75ed505d7 Move Guardian REPL evidence rendering into the shared context registry (#43602)
  • b4373e53ab Move Guardian image selection into shared context sections (#43601)
  • f5331dc237 Move trusted skill evidence into the Guardian context registry (#43599)
  • 2554239561 Move trusted tool metadata into shared Guardian context (#43597)
  • 0b9b5ecff3 Centralize bounded Guardian review evidence in guardian-context (#43595)
  • a444546564 Remove a stale transcript field assignment from the TUI (#43584)
  • b01c3986fd Add live WebRTC voice conversations to the TUI (#43581)
  • 4110342321 Group adjacent computer actions in the TUI (#43576)
  • a51608398d Make the managed app-server shutdown grace period configurable (#43572)
  • 98a5cb46b1 Manage synchronous Guardian reviewers through the thread manager (#43570)
  • ca6fb194b6 Wire app-server user verification RPCs to the native provider (#43568)
  • daca1fab84 Add an explicit app-server daemon update command (#43562)
  • 333c41eef6 Show completion timestamps after successful TUI turns (#43558)
  • 769a6a5bcd Record the launched app-server executable identity in PID files (#43552)
  • b7ad941b1f Add user-verification provider abstractions and RPC adapters (#43547)
  • 4f1a2bb5ff Preserve fork runtime versions without loading full model context (#43545)
  • 7d8e2dd6c5 Make app-server daemon automatic updates configurable (#43542)
  • cc737efd65 Preserve the multi-agent version when forking at a turn cutoff (#43540)
  • 81f23bc186 Move Guardian permission context into the shared section registry (#43538)
  • 93ac341410 Preserve Guardian context sections and share planned-action rendering (#43534)
  • 53ba408a2f Fix jemalloc tools and compiler flags for Bazel musl builds (#43533)
  • c9c7b73c4f Ensure the standalone updater runs on managed daemon starts (#43529)
  • 1e66885a16 Discount an approval's own code-mode wrapper from Guardian score lag (#43527)
  • f326857cf4 Restrict MCP user verification and add workspace-scoped identity (#43524)
  • adee0b04fa Preserve standalone release pins during daemon updates (#43521)
  • b1205c12d5 Set recursion_limit to 256 for app-server, exec, and TUI (#43519)
  • dbe2f6d528 Expose a stable executor build identity in environment metadata (#43513)
  • 6750f5bd13 Treat zombie processes as inactive in the Unix PID backend (#43504)
  • 9f70e348e0 Allow internal sessions to fork from selected history (#43495)
  • d0a8dcd157 Limit archive rollout reads to requested threads (#43494)
  • d665e3bbc8 Include unloaded children in multi-agent v2 environment context (#43491)
  • d70044072c Expose shared Guardian reviewer helpers through guardian_review (#43490)
  • 16ff14c266 Retain inherited Guardian instructions in standalone forks (#43478)
  • aa12ab45df Recover missing Guardian root instructions in acceptance order (#43472)
  • db0568dbbb Remove legacy Guardian approval review paths (#43462)
  • 8260619cb6 Centralize Guardian context mode and checkpoint policy (#43458)
  • f3f53ee949 Wait for thread idle before rollback in model-switching tests (#43456)
  • c84003c7e1 Add diagnostic labels to shell snapshot capture metrics (#43454)
  • ce5c4133bd Route MCP elicitations through the shared approval decision path (#43447)
  • c0b6285711 Pin V8 release manifests and prevent published release replacement (#43444)
  • 5b85aea979 Keep Guardian review evidence consistent and reject stale approvals (#43442)
  • e1eb98461c Route approvals through the extension decision API (#43432)
  • 0df39752cb Notify opted-in stdio MCP servers of auth changes (#43428)
  • 0b263a3331 Handle Luna HTTP requests in guardian history tests (#43426)
  • 4875084025 Remove the app-server docs update requirement from AGENTS.md (#43423)
  • d3ee328ee6 Remove the app-server README and its contributor guidance references (#43421)
  • b04ed4c50c Initialize cwd in TUI resume and fork test fixtures (#43419)
  • 7769bccbb2 Avoid WebSocket connection waits in Guardian v2 classification (#43408)
  • 5ecb3afd1b Defer resume picker and directory changes to a fresh TUI stack (#43376)
  • 694b6319d3 Use app-server metadata for TUI session restoration (#43360)
  • 21bd5d3cdc Show the server's model provider ID in TUI status (#43359)
  • 0e9589ffae Let the app server resolve implicit model settings for CLI forks (#43355)
  • 555b82afa9 Add opt-in MCP user-verification transport (#43352)
  • 121f91fd5d Enable remote named permission profile selection in the TUI (#43340)
  • 1fb5158b34 Preserve saved permissions when resuming or forking remote tasks (#43330)
  • 112be0bd74 Sort JSON schema object keys for consistent Cargo and Bazel output (#43325)
  • 02d4529f55 Resolve session labels uniquely before acting on them (#43315)
  • 455318c202 Replace Windows app-server shutdown files with socket requests (#43308)
  • a51da75131 Isolate Bazel build commit metadata from Rust compilation inputs (#43304)
  • 52e12e0cb5 Defer managed worktree transitions to fresh TUI loop iterations (#43298)
  • 3cd6004dc4 Add capability-gated MCP user-verification handling (#43289)
  • b053ef9e5a Add a managed worktree browser to the TUI (#43286)
  • 8d7cc24a87 Make Bazel binary stamping opt-in (#43282)
  • 8283bc56b1 Move npm package staging into a separate release workflow job (#43281)
  • d30f9cc72a Include linked worktrees in TUI session discovery (#43279)
  • ad931a45b2 Add experimental user verification API contracts (#43265)
  • 7bab4526f9 Use server defaults when starting TUI background tasks (#43261)
  • 4aec23384e Show read-only conversations when resume encounters an active writer (#43253)
  • a9896da3fe Connect voice-host RTP audio to speaker playback (#43248)
  • 9daf7d22ca Add bounded GStreamer playback components to the voice host (#43244)
  • ac192cd793 Allow guarded legacy resume with background migration enabled (#43178)
  • 9587c9ef36 Use server model defaults for fresh TUI startup (#43177)
  • 6af345407d Gate experimental context by model capability at session startup (#43147)
  • 1c40ffe427 Add Windows MSVC Bazel targets for native voice libraries (#43144)
  • 008bbd5884 Expose native Windows build tools through Bazel targets (#43126)
  • aa4a870e06 Add explicit Windows tool selection for native voice builds (#43125)
  • e01f38c388 Require a prepared runtime when assembling voice helper packages (#43121)
  • f6976ab036 Add managed worktree creation to TUI session commands (#43120)
  • f5a71ff40a Link Unix Bazel bindings against the prepared voice runtime (#43117)
  • a947db131b Add Bazel preparation for native voice runtimes (#43114)
  • fc748ab8d5 Save subagent and memory opt-ins through the app server (#43113)
  • a31c18ab7a Add a Bazel target for native voice dependencies (#43111)
  • 56a8470aa0 Record reasoning effort changes in conversation history behind a flag (#43110)
  • e67a8ae6c9 Add explicit toolchain inputs for native voice builds (#43109)
  • e4ce83419b Move Guardian thread context into guardianv2 configuration (#43104)
  • 47ca4619be Include GIO in voice SDKs and native runtimes (#43102)
  • 64b482500d Add bounded incoming Opus RTP handling to the voice host (#43100)
  • 5d35805715 Add receipt-verified native voice SDK export (#43099)
  • 64e9a68987 Add a helper-backed realtime WebRTC session API (#43097)
  • 7dc7c7a756 Send processed microphone audio over RTP in voice-host (#43090)
  • 0683368584 Supply Bazel-managed CMake and Ninja for the bundled Opus build (#43083)
  • 19b62211d9 Add opt-in local audio devices to the voice helper (#43079)
  • 51c97f3a67 Show a retryable error when the apps popup fails to load (#43074)
  • dfea985976 Clarify comments in CI setup and the Rust workflow (#43070)
  • 3525845978 Support managed worktrees for interactive sessions and forks (#43069)
  • 52e73e3a54 Allow /copy to copy status output and individual fields (#43055)
  • 89208f09f8 Avoid filesystem scans when seeding the agents overview (#43043)
  • 2cfee7de25 Refresh live thread tools through app/installed (#43039)
  • 32351a7b1a Keep refreshed MCP tool catalogs with their clients (#43031)
  • 588b781ab4 Add Guardian V2 failure reasons and connection timing metrics (#43005)
  • dee21ec1bc Replace Guardian tickets with parent response IDs (#43002)
  • a7a4321593 Preserve the resolved multi-agent version when reverting threads (#43000)
  • 531f3836a1 Remove the deprecated codex mcp-server command (#42993)
  • 2bd71f96d4 Refresh session hooks after external plugin updates (#42990)