Repository navigation
Codex fork 0.155.0
Codex fork 0.155.0
This release updates the fork from 0.153.4 to 0.155.0: a rebase onto the pinned upstream main snapshot, reconciliation of the fork's runtime changes, an expanded Go SDK, and five complete runtime packages.
Comparison baseline
- Previous fork release: 0.153.4, commit
20a8b8519f4d8bd58b9bfb94f87516fa2eab1a0e. - Previous upstream-tracking base:
59acd25a948759cf0d0f8454bc9ded6e48e72f52. - New fork upstream-tracking base:
08ff997106556c1bae45144b717ecbbffde14744, corresponding to upstreammain@7498521d288b9b3b96ffba4eedf089d8d6e06a84on September 18. - Released fork source:
3c37c16dc636604b7cc7324eed09d2a45db516fb. - CLI tag:
rust-v0.155.0; matching Go SDK tag:sdk/go/v0.155.0.
This is a main-based fork release, not a byte-for-byte rebuild of OpenAI's 0.155.0 tag. It incorporates changes from the 0.154.0/0.155.0 development cycle and later main-branch work. The previous fork already contained some changes subsequently advertised in upstream 0.154.0, so those are not presented again as new fork features.
The sections below describe behavior and compatibility changes. The expandable changelog at the end lists all 641 upstream non-merge commits between the pinned bases, including smaller fixes, tests, refactors, and build changes.
Upgrade and compatibility notes
- Update the CLI/app-server and Go SDK together: the strict protocol, schema, and manifest digests changed.
- The Go module path remains
github.com/openai/codex/sdk/go; the minimum Go version remains 1.25. Select the fork revision/tag through your existing fork integration. thread/rollbackandThreadsClient.Rollbackare removed. Migrate tothread/revertandThreadsClient.Revert, using the new request/response types.- The deprecated
codex mcp-servercommand is removed upstream. - Each downloadable archive contains one system's runtime under
bin/, with no target suffixes on executable names. Replace the binaries together. - Native voice requires additional helper/audio resources that are not included in these bin-only fork packages.
- Existing published release tags were not moved. This update does not automatically change your user configuration.
Upstream changes since the previous fork release
Threads, worktrees, and task management
- Expanded managed worktree support for new and forked sessions: creation from session commands and the agents overview, browsing/resuming linked worktrees, ownership details, and confirmed deletion of clean managed worktrees. Worktrees are enabled by default in the pinned main snapshot.
- Added task hiding, archiving, deletion, direct session creation, model grouping, task token/usage estimates, and richer Markdown task details to the agents overview/command center.
- Conversations with another active writer can be opened as read-only history, preserving the user's draft instead of attempting to take over the writer.
- Resume and fork paths better preserve saved permissions, runtime workspace roots, collaboration mode, multi-agent runtime selection, and model/profile settings. Fresh sessions and implicit forks respect server defaults unless explicitly overridden.
- Fixed stale history after switching threads, draft/focus loss around task transitions, ambiguous session labels, and composer responsiveness while creating a session.
- Editing an earlier prompt uses the current thread's revert operation. The retired rollback API was removed.
- Current attachments are copied into non-ephemeral forks, and pending automatic title generation is cancelled after a manual rename.
Background server, updates, and recovery
- Added configurable daemon update schedules,
codex app-server daemon update, explicit package replacement, and a local/daemonmenu. - Added
--no-daemonto bypass the shared background server, plus opt-in automatic background-server startup. - Managed shutdown persists loaded threads and recovery candidates. Saved threads, active goals, and interrupted work can be recovered after a managed daemon restart.
- Improved cancellation-safe thread startup, release of persistent writers, shutdown admission, bounded stdio shutdown, and Unix SIGTERM handling.
- Separated daemon packages from standalone CLI installation and improved managed-package discovery and bootstrap behavior.
- These server-side recovery changes do not establish that a separately observed desktop-client pending
goal/setindicator/callback issue is fixed.
Context, compaction, goals, and resource usage
- Model context, extension context, tool planning/execution, history recording, and subagent spawning use the settings captured for the originating step rather than unrelated later or initial turn settings.
- Preserved originating tool-output budgets across resume/fork and delayed Code Mode notifications.
- History token estimates are based on content rather than serialized message envelopes.
- Accepted user prompts are persisted even if compaction fails before a turn starts.
- Supported providers use streamed remote compaction; the unused legacy remote-compaction implementation was removed. Compaction checkpoint validation is centralized, and fallback can use the current model.
- Reasoning-effort overrides are preserved through recovery/compaction where required, with duplicate or disabled overrides filtered appropriately.
- Ephemeral forks preserve parent cache affinity; file-ID images participate in context budgeting and are normalized for the receiving model.
- Added user-requested goal pause support and blocking after three empty automatic goal-continuation turns.
- Reduced unnecessary copying, repeated catalog lookups, and allocation around active turns, MCP schemas, and Code Mode results.
- No fixed token-savings percentage is claimed: these are correctness and resource-use changes, not an end-to-end usage benchmark.
Code Mode and multi-agent behavior
- Scoped Code Mode callback delegates to individual executions and preserved the originating context of yielded calls.
- Hardened nested tool-call completeness tracking, including completed empty inventories, and bounded output previews across result blocks.
- Discarded tool responses can be garbage-collected; cleared timers and timers belonging to finished cells are cancelled. Undefined values are handled before JSON serialization.
- Added optional Code Mode overhead timing and more precise dispatch/result tracing. Tool metadata is included in compaction prompts.
- Added startup tool allowlists for threads and model-catalog descriptions for multi-agent V2 tools, including
spawn_agent. - Improved delegated-work trigger/identity propagation and visibility of unloaded child threads in environment context.
- MCP user interaction and plugin-install requests are routed through the root thread.
- App-server delegated operations, managed thread lifetimes, and cancellation/shutdown boundaries were tightened.
MCP, plugins, authentication, and model providers
- Existing sessions pick up refreshed plugin tools, skills, and hooks after installation or external updates. Refreshed catalogs remain paired with their clients.
- Plugin/orchestrator caches survive metadata-only and MCP runtime refreshes; dormant MCP bindings can be reused.
- Improved OAuth refresh, expired-credential status, reconnect guidance, auth-change notifications, and manual callback entry. Elicitation cancellation/reset on reconnect was corrected.
- Added native user-verification contracts, cancellation, and tool-continuation support; supported macOS clients can use Touch ID/Secure Enclave verification.
- MCP requests support read-only policy and use the correct turn environment for policy evaluation. Status exposes advertised server capabilities, and tool-call history preserves MCP App UI metadata.
- Thread-level plugin exclusions are persisted and applied consistently to runtime capabilities and shared connectors.
- Model catalogs, cached WebSocket state, and remote-control sessions are tied to the provider/authentication owner and invalidated appropriately when the account changes.
- Added command-based AWS credential acquisition for Amazon Bedrock, opt-in model discovery for OpenAI API keys, and OAuth credential management for model-provider gateways.
- Improved managed-provider requirements, residency checks, workspace request routing, and preservation of configured Flex service tiers.
- Corrected retry classification for throttling, rate limits, quota errors, and non-retryable policy failures.
Attachments, rollouts, memory, and SDK surfaces
- Added stored thread attachments with transactional add/list/remove operations, pagination, coordinated deletion, and update notifications.
- Added attachment upload/resolution paths and file-ID image handling. Local images can be transferred as portable attachments to remote app servers.
- Coordinated rollout compression with active writers, added an experimental compression endpoint, and continued searches when an individual compressed rollout cannot be processed.
- Added configurable memory versions with isolated storage, memory v2 extraction/consolidation/read prompts, summary-only extraction, priority for user-authored information, dual writing, and readiness/status reporting.
- These additions do not mean memory v2 or other optional features were enabled in the user's configuration.
- Expanded experimental user-verification APIs, Daybreak settings, and disabled-plugin overrides.
- Upstream Python SDK generation, per-turn/history options, subscriptions, and publication were synchronized more closely with the matching runtime. This release does not claim a separate fork PyPI publication.
Guardian, permissions, and sandbox security
- Preserved user instructions, verified answers, sender context, and authorization evidence through forks, checkpoints, and compaction.
- Invalidated stale approvals after history changes or permission widening; complete actions and complete request budgets are handled more consistently.
- Separated review failures from unsafe-action findings and improved transient-failure handling and reuse of stable review-history prefixes.
- Hardened credential handling in shell snapshots, replay, credential brokerage, and network tunnels.
- Filesystem paths, socket grants, network policies, and permission profiles use the executor's operating-system/path context, including mixed-OS client/server setups.
- Strengthened daemon socket isolation and Linux/WSL sandbox boundaries, including WSL interop and duplicate-root escape paths.
- Expanded Windows sandbox/MXC execution, networking, provisioning, identity/runtime permissions, account repair, registration refresh, and uninstall cleanup.
- No authentication, authorization, sandbox, or secret-handling checks were intentionally relaxed by the fork reconciliation.
TUI and native voice
- Added streaming reasoning summaries in the status row and completion timestamps after successful turns.
- Improved transcript restoration, half-page scrolling, tmux resize recovery, terminal scrollback, SSH/tmux clipboard routing, and streaming prose before a newline.
- Added Mermaid diagram rendering, inline/display math rendering, and additional Unicode math symbols.
- Added session-only model/reasoning selection, consistent task colors, clearer activity summaries and recaps, and reduced-motion/screen-reader behavior.
/copycan include status fields and completed commentary. Pending inline questions are cleared when a new prompt is accepted.- Removed personality selection from the TUI.
- Upstream added native voice conversations, live transcripts, microphone/mute controls, voice selection, and configurable shortcuts, with many audio/transcript reliability fixes.
- Voice is not available from this release's bin-only fork packages: the separately prepared native audio runtime and voice helper are not included.
Build, packaging, and internal maintenance
- Updated Rust/workspace dependencies, platform toolchains, native voice preparation, Windows build/provisioning infrastructure, and release packaging throughout the upstream range.
- Improved release-upload serialization/retries, runtime/SDK publication coordination, pinned V8 artifact handling, and deterministic schema generation.
- Split large runtime/Guardian/TUI implementation areas into focused modules and expanded regression coverage.
- Removed the old app-server README/contributor update requirement and retired repository devcontainer configuration.
- The complete commit list below includes the individual maintenance, testing, and platform changes that are not separate user-facing features.
New fork fixes and rebase reconciliation
These changes adapt the existing fork to the new upstream architecture. Some defects were caught in the rebased candidate before release; this is not a claim that every one existed in the previously published 0.153.4.
- Truncation follows the producing step. Extended output limits use the captured step settings, not stale initial turn settings after a model change.
- Resume/fork/replay retain extended limits. The fork now works with upstream's raw rollout storage. Originating byte/token policy plus general and MCP line limits are persisted and reapplied when reconstructing model context. Raw output on disk is not permission to inject it unbounded into the model. The legacy token-budget metadata alias remains compatible.
- Delayed Code Mode results retain byte limits. Fixed loss of configured
max_bytesin notification preparation and prevented legacy token-only metadata from overriding the complete originating policy. The byte-limit regression failed before the fix. - New idle-agent tasks receive the correct spawn budget. V1
send_inputand V2 follow-ups carry the requester's captured budget through ordered internal submissions and the mailbox. A new idle task no longer inherits an exhausted budget from its predecessor. Active tasks andQueueOnlymessages keep their existing budget; no public protocol fields or turn-ID lookup registry were added. - Full-buffer process cleanup is restored. Upstream cancellation/deadline and pipe-drain behavior again handles descendants that keep pipes open after the leader exits, without reporting incomplete capture as a successful full result. The fork's bounded partial-output drain for ordinary shell tools remains. Nine existing cleanup regressions were reproduced before repair.
- Sensitive startup output is not logged before redaction. Restored the
SensitiveFullBufferguard for filesystem-denial diagnostics. - Linux namespace mounts no longer break sandbox setup. Mount roots such as
net:[inode]are not incorrectly treated as ordinary filesystem paths. Socket-directory alias, nested-mount, and covering-mount protections remain enforced. - Cross-provider plaintext delivery uses the current upstream path. The fork's option is integrated into centralized agent delivery, including delivery initiated from Code Mode, rather than restoring retired helpers.
- Tool instructions are consistent. Shared guidance uses
check_agent_statusandEXEC_TOOLS. Direct-only routing recovery, explicit tool omissions, and warnings about unobserved nested results remain. - Obsolete/conflicted integration code was removed. Tests and call sites were adapted to step/session settings, image references, per-execution Code Mode delegates, and host timing fields.
- Release/SDK workflows were reconciled. Restored required packaging environment setup, corrected outdated arguments and Windows command structure, and aligned cache/runtime validation conditions.
- Versioning is consistent. All 154 local workspace package records are stamped 0.155.0. The version-stamp commit does not introduce additional external dependency changes, and Bazel lock regeneration produced no drift.
- Previously reverted unified-wait/background-disable experiments and cascading subagent interruption were not reintroduced as fork features.
Go SDK changes
New methods and options
- Added
ThreadsClient.AddAttachment,ListAttachments, andRemoveAttachment, plus routing forthread/attachment/updated. - Added
ThreadsClient.Revert; removed the retiredThreadsClient.Rollbackand its old protocol contract. - Added
Memory.Status,ThreadStartOptions.DaybreakEnabled, andTurnOptions.DisabledPluginIDs. - Preserved the distinction between an omitted disabled-plugin override and an explicitly empty list.
- Added
ImageFileID(...)alongside URL and local-file image inputs. - Generated typed
Raw()methods cover newly exposed experimental APIs, including user verification and rollout compression.
Protocol and decoder correctness
- Regenerated stable/experimental schemas, Go bindings, routing metadata, manifest information, and strict compatibility digests against the released app-server.
- The resulting inventory is 104 stable / 167 experimental-mode client methods and 62 stable / 84 experimental-mode server notifications. Experimental-mode totals include stable methods/notifications; they are not additional counts.
- Corrected nested image
anyOfdecoding to match Rust's URL/file-ID alternatives without inventing an exactly-one restriction. - Alternatives decode into temporary values and are assigned only on success. Reused receivers clear stale alternative fields, including an old URL that is absent from the new payload.
- Invalid-only inputs are rejected, valid selected alternatives survive JSON round trips, and malformed non-selected alternatives do not invalidate an otherwise accepted variant.
- Global
Optionalsemantics and strict audio validation were not weakened. - Updated serde defaults and experimental-field gating and restored the user-verification RPC error export.
- Retained previous timeline camelCase, nullable/union JSON, OAuth/realtime, additional-context, JSON Schema, local-image path, and filtered-notification/completion fixes.
Integration
Use the matching sdk/go/v0.155.0 revision with this CLI/app-server. The module path and Go 1.25 minimum are unchanged. Strict compatibility checks intentionally detect mismatched protocol/schema/manifest versions.
Existing fork capabilities retained
These are cumulative differences retained from earlier fork releases, not newly introduced features of 0.155.0:
- Configurable model-visible byte and line truncation for function, custom, dynamic, MCP, and command output, including overlapping budgets and the strictest applicable MCP limit.
- Custom providers and context-window/auto-compaction overrides for typed and fallback agents.
- Configurable plaintext cross-provider agent messages and inherited dynamic tools in child/delegate threads.
- Cumulative per-turn spawn limits, race-safe publication accounting, quiet
check_agent_statuswaits, and parent completion notifications for follow-ups. - Compaction headroom, bounded retained history, no-progress detection that does not count failed tools as useful progress, and correct failed-turn reporting when compaction cannot progress.
- Prompt-cache preservation during local compaction and prefill reset when the context window advances.
- At least three retries for model-capacity errors, including local compaction.
- Tolerant parsing of malformed completed-response usage metadata.
- User input support up to 2 MiB.
- The fork's typed Go SDK resource clients, event/request routing, and strict runtime compatibility handshake, including the earlier wire-format and subscription fixes.
Downloadable packages
All five packages are built from 3c37c16dc636604b7cc7324eed09d2a45db516fb. Executable names inside bin/ have no operating-system/architecture suffixes.
- Linux GNU/glibc x86_64 and ARM64:
codex,codex-app-server,codex-code-mode-host,codex-responses-api-proxy, andbwrap. - macOS x86_64 and ARM64:
codex,codex-app-server,codex-code-mode-host, andcodex-responses-api-proxy. - Windows x86_64:
codex.exe,codex-app-server.exe,codex-code-mode-host.exe,codex-responses-api-proxy.exe,codex-command-runner.exe, andcodex-windows-sandbox-setup.exe.
The Linux packages use GNU/glibc, not musl. Native voice resources and optional provisioned Windows sandbox-service packaging are outside this bin-only layout; the ordinary Windows helper binaries are included.
Validation and known limitations
Completed checks
- Full Go test suite with
-race; stable/experimental generation and manifest checks; strict SDK handshake against the built runtime. - Targeted context, truncation, replay, model-switching, cross-provider, compaction, and agent regression suites.
- 87 execution tests, including the reproduced cleanup regressions and sensitive-logging checks.
- 100 related agent/queue/delegate/budget tests and a separate 80 Guardian/turn-input/step-activation tests.
- Code Mode, protocol, transport, configuration/model, history/output-truncation, and Linux sandbox checks.
- Core/app-server all-target checks, scoped Clippy, formatting, and generated-schema consistency.
- Independent Astra review found five blocking defects in the candidate; all five were repaired and closed in the targeted recheck. No blocking findings remained on the released source.
- All five GitHub build jobs passed. Each runner checked the package listing and
codex-cli 0.155.0before uploading. - Downloaded archives were checked for exact layout, integrity, executable permissions, and CLI architecture. Linux x86_64 also passed a local version smoke check.
- SHA-256 digests of all five published assets matched the checked local archives; all five public download URLs were verified.
Limits of the validation
The full app-server suite was not completely green: 1738 passed, 7 failed, 2 skipped on the local validation host.
- Six failures were caused by additional stderr from the host's Ubuntu
im-config/systemd-catinitialization. - One process-disconnect cleanup failure was reproduced with system bubblewrap 0.11.1: an inner sandbox process survived termination of the outer wrapper. The same isolated check passed with bundled 0.11.2, while the relevant app-server lifecycle code was unchanged from upstream.
- Upstream prefers an installed system
bwrapover the bundled fallback. Installing this archive alone does not resolve that host case if the older system binary still takes precedence. - Native voice is not supported by these packages because the optional audio runtime/helper is not bundled.
- Provider/agent regression tests used mocks; no claim is made that every external model/provider was exercised through live paid requests.
Source and complete changelog
- Previous fork release 0.153.4.
- Upstream-tracking base comparison.
- Cumulative fork implementation relative to the new base.
- New runtime reconciliation commit.
- New Go SDK synchronization/decoder commit.
- Release and SDK workflow reconciliation.
- 0.155.0 workspace version stamp.
- Official upstream release notes: 0.154.0 and 0.155.0.
Because the fork was rebased, comparing release histories by commit count alone can include rewritten older fork commits. The pinned upstream-base comparison, the four new fork commits, and the cumulative fork comparison above separate those cases.
Complete upstream commit log since the previous fork base — 641 non-merge commits
Newest first. Original commit subjects are retained; PR links point to openai/codex. This index also includes intermediate changes that were subsequently refined or reverted; the sections above describe the released behavior.
7498521d28Keep MCP policy evaluation consistent with turn environments (#46335)3724dc8361Share platform identity across path, network, and sandbox configuration (#46334)fd875b188bHandle disabled Windows sandbox accounts during cleanup (#46333)3cd255a4eeDim conversation recaps in the TUI (#46332)ad70cbdd96Defer environment network policy validation until after composition (#46331)ff73d63e64Move retry backoff intocodex-async-utils(#46330)608e4cc9a1Avoid persisting project trust for projectless directories (#46328)5492c2b06eBroaden compaction fallback to the current model (#46324)a1efb59c4aRecord active plugin inventory in turn analytics (#46323)1f631def3fSet the Windows sandbox type in the pending environment test (#46322)f8c6026c38Preserve web search actions and results in exec JSON output (#46319)a129392ebbAdd OAuth credential management for model provider gateways (#46318)c775dd3c33Defer environment selection changes until the next turn (#46310)0c9be8a836Preserve plugin caches across display metadata refreshes (#46309)fa8cf44985Preserve bio policy errors as a distinct non-retryable error (#46306)55db7e8c88Avoid cloning turn items for app-server active turn lookups (#46305)7a3c5a83e4Serialize release asset uploads to avoid secondary rate limits (#46303)ea218f5cd8Validate network socket policies using the executor OS (#46302)8f73cdee45Centralize OAuth login and refresh handling with safer diagnostics (#46300)3e581ebca8Support catalog descriptions for all multi-agent V2 tools (#46297)17baabd01bSeparate thread startup metadata from replay history (#46294)47fc8d661eRoute skill discovery and loading throughEnvironmentAccess(#46293)93321c88d8Preserve selected reasoning effort for synchronous Guardian reviews (#46292)47915cee7aFilter saved reasoning overrides from requests when disabled (#46291)0fd1cd8d99Add opt-in overhead timing to code-mode responses (#46288)0a5b999169Connect app-server workspace discovery to model request routing (#46281)d7f8e48d7dPreserve Guardian's reusable history prefix across approval requests (#46279)3ed49879c8Reduce R2 release upload concurrency and enable standard retries (#46278)8b78600dc8Enable MXC selection through Windows sandbox configuration (#46271)3d3ae4965aAdd filesystem accessors bound to environment permissions (#46268)608825d511Expand Unicode math rendering with accents, symbols, and delimiters (#46266)16f49ccd7fRelax delegation guidance in the v2spawn_agentdescription (#46264)96aca987f7Preserve uploaded image file IDs in user message display history (#46258)fcf05456bbPublish Guardian cached scores and coverage atomically (#46245)2833985d88Repair Windows sandbox access to existing runtime children (#46241)32b54cffddPrefer the provisioning service for automatic Windows sandbox setup (#46239)c11fdc944fImprove Windows sandbox error details and registry cleanup (#46237)7abf2a3b5cPreserve configured Flex tiers without catalog or fast-mode support (#46230)e269f2164cInclude sender user messages in Guardian delegation reviews (#46179)b0659c5386Record daemon startup and update telemetry with consent handling (#46126)1bd1bfa7caFix daemon socket isolation checks for private tmp mounts (#46125)c5d079470eAllow model catalogs to override the V2spawn_agentdescription (#46123)a4ee536f01Route filesystem reads and writes by their own sandbox permissions (#46122)70e8fe1be3Add opt-in automatic background server startup (#46117)4b0f19d6f9Make TUI web and image activity summaries compact and descriptive (#46116)841b5490b2Preserve filesystem sandbox policy context when the cwd disappears (#46112)108e6a6dbeReplace Sites migration state with a runtime compatibility guard (#46108)77c1feb00eBox app-server request handler futures to reduce stack usage (#46107)16f59db96ePause TUI events in the agents overview regression test (#46104)f3da3861c5Add a one-time composer starfield for new Astra tasks (#46096)787823cf95Add--no-daemonto bypass the shared background server (#46088)8452164c76Mark finished empty Code Mode tool inventories as complete (#46081)1e9564fb85Keep the composer responsive during Command Center session creation (#46077)800d183e2dUse captured step settings when spawning subagents (#46075)6749535c8fBound code-mode output previews across result blocks (#46073)b974893c90Account for file images in context budgets and Guardian reviews (#46072)ce03f22af6Add a configurable F8 shortcut for voice conversations (#46071)36b84c81ecSuppress warnings when skill descriptions are shortened (#46070)172f8a2901Use syntax theme colors for inline code and file paths (#46069)e22e6523ebRemove thedoneprefix from TUI completion timestamps (#46067)40584fad87Keep MCP user interaction on the root thread (#46066)5e636ea760Route prepared images through the attachment store (#46065)08663cc91bConsolidate Guardian tests at shared policy and context boundaries (#46064)e412b93d08Trim Guardian tests and tighten request layout assertions (#46063)8ace915aceAttribute analytics events to realtime voice sessions (#46058)f915e0de07Render Mermaid code blocks as diagrams in the TUI (#46054)c56dda711cTrack WebSocket continuation modes and full-input send reasons (#46051)821ad43f9dTag rollout compression metrics by trigger (#46047)20f4d12f76Include Code Mode tool metadata in compaction prompts (#46044)51c30ad800Repair expired Windows sandbox account passwords during setup (#46043)b97abdbe30Add read-only policy support to MCP tool requests (#46042)78e7825a47Tighten request handling in Guardian approval tests (#46041)515530d9b2Default TUI animations off when a screen reader is detected (#46040)4cf84b7603Test Windows sandbox bin DACL modification permissions (#46038)4fa7e82274Preserve config error causes when saving the approvals reviewer (#46036)a6d4741d39Add per-app tool exposure configuration (#46035)29e6bc814ePreserve orchestrator skill caches across MCP runtime updates (#46033)73bf181272Require forced macOS preferences for managed configuration (#46032)105fe8761cKeep Noise relay streams alive after repeated handshake failures (#46031)2b2b0fa870Allow browser app cleanup hooks on interrupt (#46029)47c27cbffaDocument and test?wildcards in network proxy domain patterns (#46027)a8c36ca6d2Centralize model-message resolution and rendering incodex-prompts(#46026)0d083092b4Add an experimental rollout compression endpoint (#46020)6d75b525eaAllow hosted Apps MCP contributions to override the protocol mode (#46019)fc2ea82e7eAllow callers to disable executor skills per environment (#46015)a2f62e88cfRoute permission shortcuts through the shared selection flow (#46013)bee042d119Enforce managed residency when constructing API providers (#46011)3a589370a4Enable app tool result metadata with analytics controls (#46010)7f0ab95827Centralize compaction checkpoint selection and validation (#46009)2b59d92dbdRoute built-in permission selections through the app server (#46008)39a99a6c36Report clock failures again after recovery (#46006)43354d0f61Preserve attachment Unix socket grants when controller policy is omitted (#46004)3c6f32ca82Extract route-aware HTTP request execution into a separate module (#46002)fd346b8dbaCentralize Guardian action preparation for review (#45987)66dfadbe66Replace guardian review result tuples with named structs (#45985)49305d74b4Isolate app-server Unix sockets from filesystem-restricted commands (#45984)0666c12e78Show a loading message when opening tasks from the agents overview (#45983)53401a2808Use native DNS resolution for the network proxy on macOS (#45982)7b6dd0c7b8Preserve session config when switching thread permission profiles (#45981)d7104e268bFall back to summary history for read-only conversations (#45980)5761102868Keep selection adjacent when hiding tasks in the agents overview (#45978)da18000caeMeasure rollout read and materialization durations (#45966)2d90e054d6Expose partial completion in rollout compression metrics (#45964)9b43825f23Tag memory usage telemetry with the memory version (#45960)7275afc5c7Centralize Guardian policy resolution in config and protocol (#45957)6500c1f844Record memory storage size after successful consolidation (#45956)4701aa4b42Avoid redundant model catalog lookups in reused Guardian reviewers (#45933)977193486dBound model catalog decode errors and classify request timeouts (#45928)8f38d5a877Make Code Mode wrappers transparent to Guardian model policies (#45915)2aff7208feAdd a hidden HTTP/3 TCP tunnel command (#45900)50d77959bfReject paths in project documentation fallback filenames (#45865)83dc7d11e8Preserve executor path URIs in permission profile workspace roots (#45863)04581f9604Add/daemonmenu for local background server updates (#45854)7322c5e790Preserve executor path conventions in permission summaries (#45852)90f7b37d23Preserve the app-server shutdown signal future across loop iterations (#45849)ffae979216Revert the current thread when editing an earlier TUI prompt (#45845)8ece31a7bfHide WSLg's duplicate root in restricted Linux sandboxes (#45837)0dfb28edb9Allow session-only model and reasoning selection in the TUI (#45831)ca99b271d4Use app-server configuration for Windows sandbox state in the TUI (#45830)5bf132cd52Add opt-in nonfatal handling for clock read failures (#45825)fac58c1153Run R2 publishing when release dependencies succeed (#45823)ced02c5c38Add opt-in response body limits to the HTTP transport (#45822)73db60e71fUse app-server state for TUI Windows sandbox decisions (#45821)f2b5b81f39Continue interrupted work after managed daemon restarts (#45820)7c709f0ffdAdd a bounded Mermaid text renderer (#45817)7f501cd334Track Windows sandbox policy and per-thread executor hosts in the TUI (#45813)58e2e8cf3cAdd workspace routing support for Responses requests (#45812)8f9d0e4652Bound WSL terminal detection and handle inconclusive probes safely (#45811)883af106b9Retire the personality feature flag and document deprecated settings (#45809)4d2807023aRecord interrupted turns in managed daemon recovery snapshots (#45807)7f83d4922dRestrict plugin install requests to the root thread (#45806)b71af39fe6Preserve MCP App UI metadata in tool-call events and history (#45805)872fc22f9cComplete Windows sandbox uninstall cleanup (#45799)63c09ed212PreserveImageUserInputin the Python SDK (#45796)7b8b17b97aSupport image references by file ID in inputs and tool outputs (#45794)c51cb968e4Preserve Guardian evidence during checkpoint migration (#45789)0c3a14bbc2Preserve Guardian authorization evidence across checkpoint migration (#45782)1427825c40Normalize bullet glyphs in the image preparation disconnect snapshot (#45781)321dcf5a6fAllow daemon updates to restore pinned packages to latest stable (#45780)c0316291caUse native process identities for PID-managed daemons (#45779)b1f3c2f77eExpose experimental analytics plan history and improve navigation (#45772)de40696ec4Improve analytics chart readability and navigation (#45770)9bd49c9dccAdd an account Summary tab to Analytics (#45769)8f0d2459acAdd consumer Top chats usage analytics (#45768)0d0979f457Add gated plan usage history to TUI analytics (#45766)0e7ab7c1b5Add Top chats to usage analytics (#45765)ca53e19c75Add an account analytics dashboard to/usage(#45764)af3bc6f796Add stacked chart primitives for account analytics (#45763)1fc46a532bLoad analytics reports with server plans and account identity checks (#45762)aaa2cabfbcDisable V8 optimization paths affected by array sort bugs (#45760)a5c15ab5c0Wire Windows sandbox selection into managed proxy routing (#45757)af1fc2dbffHonor canonical plugin disables for shared connectors (#45755)9899091441Extract reusable Bash and Zsh startup scripts (#45749)8a30bc31efExplicitly gate DotSlash publishing on release success (#45746)db078158c3Add account-bound authentication for analytics requests (#45742)7224096b85Add token history and credit formatting helpers for analytics (#45741)1fd5399004Add account analytics data normalization to the TUI (#45740)ab3b40c28bAdd typed account analytics reports to the backend client (#45739)fbad00774bSeparate Windows sandbox implementations from legacy setup modes (#45737)eeded5ba1aRoute Guardian requests through/responseswith identifying headers (#45736)d4e11a9b97Separate executor sandbox selection from Windows sandbox levels (#45730)a9d2564bcbMove Guardian reviewer configuration into the extension (#45729)7784318b5fClassify MCP auth and approval outcomes in analytics (#45716)2fdcdeaf0eAdd startup tool allowlists for threads (#45711)7f01a84effMove Guardian approval routing into the reviewer extension (#45693)508a006d7aPassReviewModelthrough guardian review sessions (#45684)709efcb7a9Consolidate guardian transcript tests inguardian-context(#45683)954fa9057bRestrict guardian assessment parsing and circuit breaker visibility (#45680)1fd392f6b2Retire the unused Guardian extension prototype API (#45679)0265dd7b45Move Guardian review reporting and denial accounting into the extension (#45677)40f01fbe08Move spawned-agent interruption rules intoAgentControl(#45676)a113f3e063Consolidate Guardian reviewer lifecycle ownership (#45672)4415f985dcMove V2 agent message delivery intoAgentControl(#45670)b13164d86fCentralize child agent configuration in the agent module (#45669)b0af519c39Add elicitation classification support to app and MCP analytics (#45649)a8964cb1baRender standalone display math in the TUI (#45612)31ffe2bc9aFix retry classification for throttling and quota errors (#45602)fc269b66adAdd explicit daemon package replacement from the CLI (#45580)19286b8819Copy current thread attachments into non-ephemeral forks (#45579)4e6450bbfdResume Windows sandbox registration refresh after service restarts (#45559)653e5fbb9dSeed missing daemon installs from complete local CLI packages (#45558)446b771049Add attachment upload and resolution APIs and pass stores into sessions (#45556)364b511dcdUse shared Bazel cache preparation in SDK CI (#45554)4199fda578Add opt-in registered package execution to the Windows sandbox (#45550)529bcb2fdfPreserve streamed answers and plans when turns terminate (#45549)c18db9ba69Honor prepared Unix socket permissions in Seatbelt (#45548)923c6028b6Move daemon packages out of the standalone CLI installation (#45546)2f1583b411Discourage logging full image generation results (#45544)5a66d460d3Refactor image content to use a sharedImageReferencetype (#45543)6ae5e71458Add service-managed package registration for Windows sandbox accounts (#45542)18d7ace221Move Guardian reviewer lifecycle into the extension (#45537)12b0164a48Classify tool analytics events by call origin (#45535)99914f4950Honor explicit Unix socket grants in the Linux managed sandbox (#45534)d39cfa8a2dHarden and share Windows sandbox identity helpers (#45533)a4354e2d27Expose selected workspace routing in app-server account reads (#45529)b44af92ca0Compress larger Windows release artifacts first (#45528)b0d95427c2Stage Python runtime wheels directly from package directories (#45526)60e35765c3Enable MXC TTY launches and managed networking in the exec server (#45524)e84a594636Move Guardian reviewer startup into the pool (#45521)78dfc1349eAdd dependencies to the Windows sandbox service (#45520)91d54f1667Restore collaboration mode when resuming threads (#45519)7c73903be2Route Guardian reviewers through ThreadManager for inline parents (#45518)280c7e1e56Use a dedicated mock server in the provider enforcement test (#45517)520e13a4bcAllow configuring the Guardian prompt template (#45516)fd5bf3b059Filter plugin-install test analytics by event type (#45515)ef8b356c22Allow settingdaybreakEnabledwhen starting a thread (#45513)ea3c4848d8Share MCP tool specs until search results are selected (#45509)b9bfc0aff8Allow background persistence for steered user input (#45506)4d5d37c5f8Add lifecycle tracing for unified exec (#45505)6ce16aadceAllow ConPTY output to close after the last console client exits (#45504)973ec2942cAdd revocable network policy primitives to the HTTP client (#45503)08d3748cf0Add managed thread lifetimes with cancellation-safe startup (#45502)ad8a5e3a1bRender inline TeX math as Unicode in the TUI (#45501)d38b5260a1Send local TUI images as portable attachments to remote app servers (#45499)afaad7cdc0Trace global user instruction loading (#45496)a20092a7a2Expose effective login methods in config requirements (#45495)d3812ddbb3Make the Guardian deadline cancellation helper crate-private (#45493)43da136850Split Guardian V2 async scoring into focused modules (#45492)f2d9bccbdeRemove Guardian subagent-spawner plumbing (#45491)e5a2094817Updaterustlsand AWS-LC dependencies in Cargo and Bazel lockfiles (#45489)21b1ef18c6Retain thread persistence acquisition through session cancellation (#45487)5fb3b7e401Fix fuzzy match scoring within Unicode lowercase expansions (#45475)99b3ab2131Allow dedicated listeners for managed network proxies (#45463)3fa9039bd7Label rollout compression failures by stage and I/O error kind (#45461)374c4b2d82Resolve enterprise-managed MCP registrations in the catalog (#45459)b876f88981Fix clipboard routing for tmux and SSH sessions (#45457)1a02867bd1Refactor Windows sandbox setup and service helpers (#45455)7a48b95c6cPreserve tabs in non-bracketed paste bursts (#45454)4d8eca1ff3Attribute command and plugin analytics to the invoking model (#45445)b6a5d5bb14Preserve Guardian parent response IDs across sampling requests (#45441)f8bed26f7bShare Apps tool catalogs without retaining unused snapshots (#45440)f3803587c9Share tool output schemas and defer MCP envelope construction (#45439)e9633d7a02Avoid cloning MCP server status snapshot data (#45428)2f8603f075Extract Guardian sampler execution into a dedicated module (#45420)9d036249daExtract Guardian conversation bookkeeping into the reviewer crate (#45418)b3e0c49dfbExtract guardian transcript selection intoguardian-context(#45417)99cda7a9a5Invalidate Guardian review sessions after parent history resets (#45413)d761097734Add session and originating window IDs to MCP request metadata (#45409)d77ebc7223Cancel code mode timer tasks when cleared or the cell finishes (#45399)5b1d656018Publish opt-in provisioned macOS packages with Rust releases (#45345)3abbf9fe2cExtract Windows sandbox configuration preparation into a helper (#45312)6f39a47bb3Add worktree session creation to the agents overview (#45276)44b9011611Preserve terminal scrollback when growing the TUI viewport (#45271)a505c71490Route pastes into the active history search query (#45262)516f2780fdOpen new sessions directly from the command center (#45255)16537b20a5Use captured step settings for request metadata and tool hooks (#45248)36f0dbe796Register Windows desktop uninstall ownership before sandbox setup (#45224)1715e55076Bind direct tool-call metadata to invocation outputs (#45185)e61f381900Validate Windows sandbox token groups before copying SIDs (#45182)cfde11a24cExtract shared network configuration and environment policy helpers (#45180)a4c61afff2Split Windows sandbox cleanup into preparation and completion phases (#45178)c379459bbaWire the Windows MXC sandbox into command execution (#45176)dfaf451426Extract Windows sandbox setup and installation storage into the library (#45169)a592c38c16Use OpenSSL 3.6.4 for musl builds (#45149)7efa9d96fbRemove Astra sparkle animation from the TUI composer (#45137)b966240beaPreview streaming prose before a newline arrives in the TUI (#45135)b979d4f1f0Add a feature flag for asynchronous user messages (#45124)70eb36203dPrevent multiline report notes from submitting early (#45116)a7475e74aaUse blueberry in the realtime background-agent test fixture (#45112)b4c864dd64Cancel pending thread title generation after manual renames (#45108)b04a2c2645Estimate history tokens from content instead of serialized envelopes (#45094)8d3c6cc13dPreserve conversation context and separate next actions in recaps (#45090)f16c2237a5Delay automatic recaps and compact their TUI layout (#45089)ee6814bfa4Consolidate Rust release artifact downloads (#45051)53c542d944Use gzip compression level 6 for Codex package archives (#45039)727e48697dRun DotSlash publishing directly on Ubuntu runners (#45035)c4017a87aaMake context snapshot text rendering consistent (#44976)aee8a55ab6Show task tokens and usage estimates in the agent command center (#44970)7efb0262d6Open tasks managed elsewhere as read-only history in the command center (#44969)53ff712a48Add model grouping to the agent command center (#44957)944d6fd1baKeep voice captions visible across speaker updates and history handoff (#44952)89c8bcf37dAdd context snapshots for async questions and plugin refresh (#44948)132c739171Retire Friendly and Pragmatic personality selection (#44946)cebdb732eaRoute TUI Windows sandbox setup through the app server (#44945)39d193d72dEnforce managed provider requirements on existing app-server threads (#44944)d43f1e7eb2Clarify the Windows Visual C++ runtime notice for voice packages (#44942)c210f4c222Respect execution hosts in Windows sandbox setup (#44939)2e572378f4Add connector auth failure detection without an install URL (#44938)12e82f44f8Remove personality selection from the TUI (#44935)e8271aa8b4Add scenario snapshots for remote compaction and Code Mode tools (#44934)f3c4d082d9Remove Windows world-writable scans and warnings from the TUI (#44933)202d61c629Unify context snapshots and group requests into windows (#44932)4d205c7a4dStop settingYARN_NO_PROXYin the managed proxy environment (#44931)c18277043eEmbed friendly instructions in bundled GPT-5.4 and GPT-5.5 (#44930)16491f7f70Preserve voice meter history through quiet samples (#44928)1b5e27c7f0Accept voice response audio before captions on quiet turns (#44925)7ef70f95d5Refresh the speaker format when restarting voice output (#44924)ce7fbb373bBundle native voice runtimes in Windows releases (#44922)3f59eb965aEnable TUI voice conversations by default (#44921)3052bbcf8cRemove the deprecatedthread/rollbackAPI (#44915)c62d191c4cExpose disabled plugin settings in the app-server API (#44905)42cd1ec497Wire up the native Windows MXC helper entry point (#44903)e3a52b87b2Expose available access programs in model discovery (#44893)4dcce4f0c4Reject token-budget history notes for unsupported starting models (#44883)33bdf976ccFade Astra composer stars and stabilize cursor redraws (#44879)7b491281c8Return public key metadata from user verification enrollment (#44877)2c9e1a5775Add managed network policy support to the Windows MXC sandbox (#44872)68bc5369baEnable worktrees by default and clarify local daemon errors (#44870)122d55cba8Preserve originating budgets for code mode notifications (#44867)2fc4bda3caPreserve originating context for yielded code-mode tool calls (#44866)3305c4f31dScope code mode callback delegates to individual executions (#44865)bc5957eac9Preserve parent cache affinity for ephemeral forks (#44862)0818b6550bAdd consistent theme-based thread colors across the TUI (#44857)654b0a77d0Add trusted enterprise MCP auth configuration (#44832)7a6f469dcfExpose advertised MCP server capabilities in status responses (#44826)624ccf7947Test approved command execution with managed unified exec disabled (#44814)02a8f038b8Check folder consent before creating or resuming TUI tasks (#44755)b9934480bfRender Markdown in agent overview task details (#44752)ab95cd4dd9Preserve voice caption order when replaying TUI history (#44749)eab107fed0Updatequinn-protoand allow the pinned H3 Git source (#44747)84e7d4a1feCheck folder trust after resolving the startup destination (#44746)eaa8b6d917Make archive confirmation number shortcuts act immediately (#44744)eabb7c91d1Preserve editor yanks across new sessions and thread switches (#44742)40b0409aa1Clarify folder trust prompts and add restricted widget support (#44732)da20788df9Bundle Linux voice runtimes and improve audio reliability (#44714)08e49689b8Return to the command center after session cancellation or deletion (#44711)fc948f8c47Add a provider for thread-scoped instructions (#44701)dc55274818Include the Windows sandbox service in release artifacts (#44694)aff3e0db94Preserve selected profile settings over managed new-thread defaults (#44693)e53c444964Warn about ignored configuration settings (#44691)9e22e74e8dResolve permission profiles with explicit execution-host path context (#44676)935ac7710dRefresh global instructions at model-request boundaries (#44675)28f43b0417Keep voice sessions alive through mute and audio backlog (#44671)1b83e5cdf9Restrict login setup redirects to known platform origins (#44670)cc05ecfe17Resolve filesystem denials with explicit path context (#44669)78600239a1Honor system reduced-motion preferences in the TUI (#44666)84ed5744d9Trace tool call receipt, result readiness, and code-mode dispatch (#44661)e004dc6a4bPreserve turn triggers across delegated agent work (#44659)4caa5d615dKeep Windows sandbox private desktops alive across helper exits (#44658)c8a8295e79Attribute turn metrics to the models used during the turn (#44656)8570091e14Honor thread-level plugin exclusions across runtime capabilities (#44655)5c94936b56Preserve missing environment variable diagnostics in Codex Doctor (#44654)db2e09106cKeep command center errors visible and preserve drafts (#44651)1aaa453ce2Enforce managed model provider selection and definitions (#44650)60825b4988Honor thread analytics opt-outs when using shared clients (#44646)e25bedc166Block non-loopback inbound traffic for the Windows offline sandbox (#44639)8e2afc0912Recover OAuth metadata discovery from 503 responses via OIDC (#44636)b9852fe6f7Focus the task list when reopening the agent command center (#44631)f8ab57359dAdd manual callback input to MCP OAuth login (#44629)9b033b4642Expose session analytics state in Responses turn metadata (#44628)4150a2c205Add bounded environment transport for MXC launch requests (#44626)9c9451131fAdd/voice settingsto choose a voice for future conversations (#44622)5c013177d8Support temporary and minimal filesystem grants in MXC (#44620)1afffeabb2Allow discarded code mode tool responses to be garbage collected (#44619)663eb5fbddInvalidate cached Guardian approvals for unscored permission widening (#44617)86661eb626Simplify enterprise OAuth login helpers and expand callback tests (#44616)3422443ec4Treat non-interactive dumb terminals as warnings incodex doctor(#44615)3715bf4100Enable user verification for local Codex Desktop sessions (#44613)196964ef10Preserve root turn attribution in turn-start events (#44611)242c5ce01cPreserve whole diagnostic attachments and report incomplete uploads (#44606)818f1cca8cRemoverepo_urlfrom skill invocation analytics events (#44586)d1696652a2Support symbolic:rootfilesystem policies in MXC (#44580)bfca0335faTie network approval reviews to their originating execution (#44575)6bb5be869fUse captured action settings for Guardian reviews (#44574)6baa076eb6Allow extensions to select MCP protocol mode per HTTP server (#44571)287e4f7dbfPreserve Guardian authorization evidence until request budgeting (#44570)9c4879f3a5Preserve complete actions in Guardian approval reviews (#44569)3319d9b296Add app-server APIs for stored thread attachments (#44564)94697375cbAdd MIME-filtered resource listing for Codex Apps (#44548)4e6d5c0a96Move Guardian reporting and denial accounting into the extension (#44544)eca63f0803Move Guardian reviewer settings and execution into the reviewer crate (#44536)713caa89f3Bound app-server stdio shutdown and handle Unix SIGTERM gracefully (#44523)ed6dde9fdaDecouple session isolation from subagent attribution (#44521)9688359977Bound MCP descriptions separately from Guardian action JSON (#44493)102fc57e4aDistinguish HTTP quota errors from rate limits (#44492)537278c65fReset cached WebSocket state when auth ownership changes (#44489)ee93abb690Preserve incoming prompts when pre-turn compaction fails (#44487)5d3fe48b08Improve Guardian retries and review failure reporting (#44482)03f014564dHarden Code Mode tool-call completeness tracking (#44472)b348fc2667Add archive and delete actions to the agents overview (#44433)bf5ebd98c5Add a hide shortcut to the agents overview (#44424)ddea03ad04Start Python SDK turn subscriptions at their attachment point (#44400)ea53c8d4f7Add opt-in model discovery for OpenAI API keys (#44392)5a9eb145c4Update the forked-thread hook test to useStartThreadOptions(#44377)a62e98d18cReturn focus to the agents overview composer on Escape (#44360)d996b4f02aReport OAuth authentication failures in MCP status snapshots (#44359)e2a9ee05f4Extract shared footer hint wrapping in the TUI (#44354)0447e4a1fdRemove path-bearing fields from Guardian review analytics (#44352)2df0b747baAdd thread attachment operations with coordinated deletion (#44350)e444aa99d7Distinguish forked sessions in session-start hooks (#44349)c6a59ef923Support native verification in MCP tool continuations (#44346)3ef3cecd20Open tasks with Right from the agents overview (#44344)1bff94edb6Bind remote-control sessions to their authentication owner (#44341)d390f0a09cReturn to the agent command center after archiving on shared servers (#44337)0df6366a87Add bounded tool-result metadata support to executed tool calls (#44336)b5544d5732Persist disabled plugin IDs in thread settings (#44332)e722303e38Expose voice conversations in experimental features (#44331)130d6e4fbaAdd paginated thread attachment listing to the state runtime (#44330)2808a9c348Clear pending TUI questions when accepting a new prompt (#44328)f11d0dd012Prevent filesystem-root read denies in the Windows sandbox (#44327)0adfc1f2f2Return the prompt hash in upload responses (#44325)0735c51978Block goals after three empty automatic continuation turns (#44320)eb680c0558Give hosted Codex Apps an independent MCP protocol opt-in (#44318)e1b23086acRestore saved threads when the managed daemon restarts (#44314)434efa95e6Honor shared Retry-After deadlines for remote control (#44311)45eec73b11Add opt-in provisioned macOS CLI release candidates (#44307)7c88f037d9Record thread recovery candidates on managed daemon shutdown (#44299)742472c525Set turn triggers for guardian and memory requests (#44298)87cf20ee49Isolate the hook pipe I/O timeout test from shell startup files (#44297)72348693ecEnforce the async Guardian classifier's complete input budget (#44293)fa7af3883dAllow user-requested goal pauses throughupdate_goal(#44290)d117c2eb02Expand MXC volume grants and resolve deny globs (#44289)885113aa1dPrevent command hooks from hanging on blocked stdin (#44288)f71543813fBlock WSL interop escapes from restricted filesystem sandboxes (#44286)5d3f8752fcPreserve prewarmed reasoning effort across replay and early rollback (#44285)bb71d758cdAdd telemetry for the Windows system config namespace (#44284)c1840dc55ePersist loaded threads before managed daemon shutdown (#44283)fcd90d8f07Enforce complete request budgets for Guardian reviews (#44281)9caddc5cf5Surface environment startup failure reasons to the model (#44277)f5c5d9b2b0Avoid duplicate reasoning effort updates during turn recovery (#44276)1ac689cc7dRemove the unused legacy remote compaction implementation (#44273)a3ba42b010Remove the Windows/sandbox-add-read-dirslash command (#44259)3dc1e2a584Always use streamed remote compaction for supported providers (#44255)2617ed2e1cMove synchronous Guardian orchestration into the reviewer extension (#44252)eb7bd64ef9Remove retired model entries while preserving migration prompts (#44250)6eecd04fc1Normalize image detail for the receiving model (#44249)aa88a0333cPreserve tool output truncation budgets across resume and fork (#44248)b64de2f3adUse the originating model when recording conversation history (#44243)205f3671e1Use captured step settings for tool planning and execution (#44242)ed4ca07ba6Handle credential provider source remapping across config layers (#44241)3436cad5abFix MCP elicitation cancellation and reset state on reconnect (#44238)e8e7103cb9Extract Guardian review policy into a dedicated crate (#44227)a2e83a783eContinue rollout searches when a compressed rollout cannot be searched (#44226)4f2449b4b2Measure total exec-server request duration including queueing (#44207)8ff4aa8ee4Use captured step model settings for extension context (#44202)b4507997e0Use captured step settings when building model context (#44200)ccf470c060Preserve voice indicator styles during composer sparkle effects (#44198)ce2c2759ebRelease persistent writers when session startup is cancelled (#44183)2bba3a29a0Use explicit histogram buckets for Guardian context metrics (#44181)c77c34ed33Reduce TUI stack usage during session transitions (#44176)0df1daf526Attach compressed rollouts to diagnostic reports as JSONL (#44175)17e64839ebAdd aggregate budget enforcement for Guardian context (#44166)d3ffbbed5aAdd Guardian context cost and request token telemetry (#44164)73a1148c9cCoordinate rollout compression with active thread writers (#44138)20f109eadbReuse MCP bindings while cached servers remain dormant (#44121)9e868bd9dcHandle empty voice arguments in macOS release packaging (#44101)634ebc1865Support credential brokering in plaintext HTTP tunnels (#44089)1a4096e273Add untrusted external messages to the Python SDK (#44086)8afccec87aExpose Python SDK history selection and per-turn options (#44084)7b9e7d99bdMake staged macOS voice runtimes writable before packaging (#44080)56d3e8192fRefactor credential-broker tunnel protocol detection (#44077)38cbebaf3fSupport configured credential providers across shell snapshots (#44072)129fd21687Reject empty audio payloads in data URLs (#44070)f45115a137Preserve credential broker destinations across environment filtering (#44068)b4d42052cdPublish Python packages after stable CLI releases (#44067)5a9aec40a5Extend configured credential brokerage to embedded aliases (#44066)85c2d4d921Fix voice runtime release builds and packaging (#44062)26ce6649a2Build Python SDK artifacts before publishing the runtime (#44061)3d3df0a0caRaise Guardian's action review limit to 200,000 bytes (#44060)1bfd383890Add configurable credential providers to the network proxy (#44056)96c2b4377fGate Python SDK publishing on runtime availability and verify PyPI files (#44055)c55db1b8d9Test Python SDK against the built CLI and installed runtime (#44053)9ba1d9eb5bExtract credential broker environment and registry helpers (#44049)283f34387bUseStartThreadOptionsacross thread fork APIs (#44043)ec512d2347Harden credential handling in shell snapshots and replay (#44040)a548463b78Handle copied credentials in the broker and shell snapshots (#44038)45134c0463Generate Python SDK types from repository app-server schemas (#44032)fe52d795c9Add AWS credential export commands for Amazon Bedrock (#44028)2ce38ae6d8Support image attachments in agents overview background tasks (#44027)7aba218851Refresh workspace lockfile before building macOS voice releases (#44025)0d46c252b3Encapsulate executed tool call metadata recording (#44002)b831057106Clear stale transcript history when switching threads (#43994)721f46a07aBundle signed voice resources in macOS releases (#43983)dafb6781eeHeap-allocate the resume future in the legacy history test (#43966)8c72f2ff56Use curly apostrophes in protocol error messages (#43961)c3eeaae9a3Gate new app-server work during graceful shutdown (#43959)4e09b0c1f1Increase the TUI thread capability test stack to 12 MiB (#43956)808b3411fdCache protected shell snapshots and harden capture cleanup (#43954)929389f596Preserve per-image generation IDs in image generation analytics (#43953)102e1763b9Keep app-server thread RPCs active until delegated work completes (#43950)589874be81Add transactional thread attachment mutations to the state runtime (#43949)5b682c9875Show configured app-server updater settings in doctor (#43948)5ac0b8768dSurface MCP reconnect signals when expired OAuth tokens cannot refresh (#43947)7c098d8741Gate new turn submissions on host shutdown admission (#43943)973dcd80fcShow worktree owner details and add confirmed deletion (#43942)c53f342fecAdd executor-context filesystem permission helpers (#43939)1032738aa0Tag TUI startup metrics with terminal and multiplexer categories (#43937)6ab3ae5323Stabilize subagent and unified exec test fixtures (#43936)fba22e9a2aTrack voice session lifecycle metrics in the TUI (#43934)5e3f0ee94bAvoid Windows sandbox setup for irrelevant proxy port changes (#43930)9d88e9ae08Rename thread artifacts to attachments in the state database (#43927)82d4a98912Add cancellation for native user-verification RPCs (#43925)9ec33e1926Show streaming reasoning summaries in the TUI status row (#43921)78932f4493Expose the queued event count onCodexThread(#43918)f419c3214aRemove the repository devcontainer configurations (#43915)900b1e4cecAdd tracing for project instructions and filesystem sandbox operations (#43913)dd112a9fd5Keep Guardian reviewers on summary-based compaction (#43912)2e220af1f6Protect shell snapshots when credential brokerage is enabled (#43909)1530f828cbPreserve complete shell snapshot exports through filtering and replay (#43907)f046cf35dfScope model catalog caches to the current provider and auth identity (#43906)4fd2c460ddExtract Windows deny-read glob scan planning into protocol (#43903)6d377e96ebPropagate Apps tool refreshes to existing threads (#43900)f31bd3adffPersist provider and auth identity with model catalog caches (#43897)94e4b3d0bdPreserve__oailbrouting cookies in ChatGPT HTTP clients (#43895)9d83c48e5cPreserve thread identity in code-mode tool dispatch traces (#43894)095da4b7e8Fix transcript viewer restoration and half-page scrolling (#43889)5a65fd87d8Close active network proxy connections on teardown (#43884)cfd5d77d63Detach Unix hook commands from the controlling terminal (#43876)c1f1467f30Handle undefined values before JSON serialization in code mode (#43873)44ab72674eClose MCP stderr readers on client teardown (#43870)ce254df05aAdd canonical permission translation for MXC execution requests (#43853)6515a72db7Preserve runtime workspace roots across thread resume (#43848)dd9512c000Include completed commentary in the/copypicker (#43846)b090e901f8Add staged enterprise OIDC login and coordinated logout (#43844)cbfa321ecdWait for parent idle before rollback in guardian fork tests (#43842)2cbbf0c9b5Add memory dual writing and v2 readiness reporting (#43827)553df1c691Add dedicated memory v2 consolidation and read prompts (#43813)e7f5de0a6aMove v2 extraction chunking into the memory writer (#43808)0337192dfdCentralize Guardian transcript policy in context profiles (#43806)0034ef93a7Centralize Guardian context composition (#43805)74d3a5bf10Add summary-only extraction for memory v2 (#43800)6924ce636bPrioritize human evidence in memory v2 extraction (#43799)5371951292Batch non-user history eviction to preserve Guardian transcript deltas (#43798)3f76e88a48Add configurable memory versions with isolated storage (#43797)35d9e4bc4dPreserve reasoning effort through compaction and reset it on success (#43796)31ccaf40c2Pin request reasoning effort while configuration overrides are active (#43795)df522cae16Limit app-server storage metrics to session directories (#43790)d6489472f3Enable user verification for the bundled TUI on supported devices (#43715)c7f81afc19Enable MCP user verification in the TUI (#43712)95327467c3Add TUI request bookkeeping for user verification (#43708)ef6c058202Disable clock synchronization in the voice audio sink (#43704)54e04f25dbAdd a TUI user verification prompt component (#43702)6b6fdc3572Preserve split-flap animation state when voice transcripts scroll (#43699)49a9d78999Make older app-server notices configurable in the TUI (#43698)9a3af22d01Stabilize realtime voice meter sampling across redraws (#43695)45305dd229Make the voice mute shortcut configurable in the TUI (#43690)98c7c0415bMove voice controls into a dedicated composer strip (#43683)3caf9f9586Style spoken prompts and link workspace files in voice transcripts (#43676)4e93cf9b4eAnimate live voice transcripts with split-flap tiles (#43656)4b0d9669ccAdd voice mute shortcut and recording activity indicators (#43651)6fee98cc85Expand TUI regression coverage for realtime voice conversations (#43645)e7637306bcAdd macOS user verification with Secure Enclave signing (#43624)530383e36dWarn when the connected Codex service is older than the CLI (#43622)4b0f44d304Add worktree classification to thread telemetry (#43621)c977cc0c19Add a stable TUI/app-server version comparison helper (#43619)8e694e955aExclude base instructions from the bundled model catalog (#43604)7d2c58e6e0Recover missed tmux resize notifications in the TUI (#43603)d75ed505d7Move Guardian REPL evidence rendering into the shared context registry (#43602)b4373e53abMove Guardian image selection into shared context sections (#43601)f5331dc237Move trusted skill evidence into the Guardian context registry (#43599)2554239561Move trusted tool metadata into shared Guardian context (#43597)0b9b5ecff3Centralize bounded Guardian review evidence in guardian-context (#43595)a444546564Remove a stale transcript field assignment from the TUI (#43584)b01c3986fdAdd live WebRTC voice conversations to the TUI (#43581)4110342321Group adjacent computer actions in the TUI (#43576)a51608398dMake the managed app-server shutdown grace period configurable (#43572)98a5cb46b1Manage synchronous Guardian reviewers through the thread manager (#43570)ca6fb194b6Wire app-server user verification RPCs to the native provider (#43568)daca1fab84Add an explicit app-server daemon update command (#43562)333c41eef6Show completion timestamps after successful TUI turns (#43558)769a6a5bcdRecord the launched app-server executable identity in PID files (#43552)b7ad941b1fAdd user-verification provider abstractions and RPC adapters (#43547)4f1a2bb5ffPreserve fork runtime versions without loading full model context (#43545)7d8e2dd6c5Make app-server daemon automatic updates configurable (#43542)cc737efd65Preserve the multi-agent version when forking at a turn cutoff (#43540)81f23bc186Move Guardian permission context into the shared section registry (#43538)93ac341410Preserve Guardian context sections and share planned-action rendering (#43534)53ba408a2fFix jemalloc tools and compiler flags for Bazel musl builds (#43533)c9c7b73c4fEnsure the standalone updater runs on managed daemon starts (#43529)1e66885a16Discount an approval's own code-mode wrapper from Guardian score lag (#43527)f326857cf4Restrict MCP user verification and add workspace-scoped identity (#43524)adee0b04faPreserve standalone release pins during daemon updates (#43521)b1205c12d5Setrecursion_limitto 256 for app-server, exec, and TUI (#43519)dbe2f6d528Expose a stable executor build identity in environment metadata (#43513)6750f5bd13Treat zombie processes as inactive in the Unix PID backend (#43504)9f70e348e0Allow internal sessions to fork from selected history (#43495)d0a8dcd157Limit archive rollout reads to requested threads (#43494)d665e3bbc8Include unloaded children in multi-agent v2 environment context (#43491)d70044072cExpose shared Guardian reviewer helpers throughguardian_review(#43490)16ff14c266Retain inherited Guardian instructions in standalone forks (#43478)aa12ab45dfRecover missing Guardian root instructions in acceptance order (#43472)db0568dbbbRemove legacy Guardian approval review paths (#43462)8260619cb6Centralize Guardian context mode and checkpoint policy (#43458)f3f53ee949Wait for thread idle before rollback in model-switching tests (#43456)c84003c7e1Add diagnostic labels to shell snapshot capture metrics (#43454)ce5c4133bdRoute MCP elicitations through the shared approval decision path (#43447)c0b6285711Pin V8 release manifests and prevent published release replacement (#43444)5b85aea979Keep Guardian review evidence consistent and reject stale approvals (#43442)e1eb98461cRoute approvals through the extension decision API (#43432)0df39752cbNotify opted-in stdio MCP servers of auth changes (#43428)0b263a3331Handle Luna HTTP requests in guardian history tests (#43426)4875084025Remove the app-server docs update requirement fromAGENTS.md(#43423)d3ee328ee6Remove the app-server README and its contributor guidance references (#43421)b04ed4c50cInitializecwdin TUI resume and fork test fixtures (#43419)7769bccbb2Avoid WebSocket connection waits in Guardian v2 classification (#43408)5ecb3afd1bDefer resume picker and directory changes to a fresh TUI stack (#43376)694b6319d3Use app-server metadata for TUI session restoration (#43360)21bd5d3cdcShow the server's model provider ID in TUI status (#43359)0e9589ffaeLet the app server resolve implicit model settings for CLI forks (#43355)555b82afa9Add opt-in MCP user-verification transport (#43352)121f91fd5dEnable remote named permission profile selection in the TUI (#43340)1fb5158b34Preserve saved permissions when resuming or forking remote tasks (#43330)112be0bd74Sort JSON schema object keys for consistent Cargo and Bazel output (#43325)02d4529f55Resolve session labels uniquely before acting on them (#43315)455318c202Replace Windows app-server shutdown files with socket requests (#43308)a51da75131Isolate Bazel build commit metadata from Rust compilation inputs (#43304)52e12e0cb5Defer managed worktree transitions to fresh TUI loop iterations (#43298)3cd6004dc4Add capability-gated MCP user-verification handling (#43289)b053ef9e5aAdd a managed worktree browser to the TUI (#43286)8d7cc24a87Make Bazel binary stamping opt-in (#43282)8283bc56b1Move npm package staging into a separate release workflow job (#43281)d30f9cc72aInclude linked worktrees in TUI session discovery (#43279)ad931a45b2Add experimental user verification API contracts (#43265)7bab4526f9Use server defaults when starting TUI background tasks (#43261)4aec23384eShow read-only conversations when resume encounters an active writer (#43253)a9896da3feConnect voice-host RTP audio to speaker playback (#43248)9daf7d22caAdd bounded GStreamer playback components to the voice host (#43244)ac192cd793Allow guarded legacy resume with background migration enabled (#43178)9587c9ef36Use server model defaults for fresh TUI startup (#43177)6af345407dGate experimental context by model capability at session startup (#43147)1c40ffe427Add Windows MSVC Bazel targets for native voice libraries (#43144)008bbd5884Expose native Windows build tools through Bazel targets (#43126)aa4a870e06Add explicit Windows tool selection for native voice builds (#43125)e01f38c388Require a prepared runtime when assembling voice helper packages (#43121)f6976ab036Add managed worktree creation to TUI session commands (#43120)f5a71ff40aLink Unix Bazel bindings against the prepared voice runtime (#43117)a947db131bAdd Bazel preparation for native voice runtimes (#43114)fc748ab8d5Save subagent and memory opt-ins through the app server (#43113)a31c18ab7aAdd a Bazel target for native voice dependencies (#43111)56a8470aa0Record reasoning effort changes in conversation history behind a flag (#43110)e67a8ae6c9Add explicit toolchain inputs for native voice builds (#43109)e4ce83419bMove Guardian thread context intoguardianv2configuration (#43104)47ca4619beInclude GIO in voice SDKs and native runtimes (#43102)64b482500dAdd bounded incoming Opus RTP handling to the voice host (#43100)5d35805715Add receipt-verified native voice SDK export (#43099)64e9a68987Add a helper-backed realtime WebRTC session API (#43097)7dc7c7a756Send processed microphone audio over RTP in voice-host (#43090)0683368584Supply Bazel-managed CMake and Ninja for the bundled Opus build (#43083)19b62211d9Add opt-in local audio devices to the voice helper (#43079)51c97f3a67Show a retryable error when the apps popup fails to load (#43074)dfea985976Clarify comments in CI setup and the Rust workflow (#43070)3525845978Support managed worktrees for interactive sessions and forks (#43069)52e73e3a54Allow/copyto copy status output and individual fields (#43055)89208f09f8Avoid filesystem scans when seeding the agents overview (#43043)2cfee7de25Refresh live thread tools throughapp/installed(#43039)32351a7b1aKeep refreshed MCP tool catalogs with their clients (#43031)588b781ab4Add Guardian V2 failure reasons and connection timing metrics (#43005)dee21ec1bcReplace Guardian tickets with parent response IDs (#43002)a7a4321593Preserve the resolved multi-agent version when reverting threads (#43000)531f3836a1Remove the deprecatedcodex mcp-servercommand (#42993)2bd71f96d4Refresh session hooks after external plugin updates (#42990)