Repository navigation
Codex fork 0.155.1
Codex fork 0.155.1
This release updates the fork from 0.155.0 to 0.155.1: a rebase onto the next pinned upstream main snapshot, adaptation of the fork's agent/runtime changes, synchronized Go SDK bindings, and five complete bin-only runtime packages.
Same-version reissue: the runtime packages have been rebuilt with the MCP/Code Mode line-limit correction described below. If you downloaded the original 0.155.1 packages, download them again; --version remains codex-cli 0.155.1.
Comparison baseline
- Previous fork release: 0.155.0, source
3c37c16dc636604b7cc7324eed09d2a45db516fb. - Previous upstream-tracking base:
08ff997106556c1bae45144b717ecbbffde14744. - New upstream-tracking base:
4981b6d01effb84d0a79faa5e41f5e06c4fc5ce7, corresponding to OpenAImain@78245b47af2a7aafcabe025828ceecca69db4df1. - Runtime release source:
1a82148f5d2cb846dadd976c2297260a8edc76cf. - Original 0.155.1 runtime source:
5838f5d29977bf2c969fad74a849190c3e0b5def. - CLI tag:
rust-v0.155.1. Compatible Go SDK tag:sdk/go/v0.155.1, retained at5838f5d29977bf2c969fad74a849190c3e0b5def; its module contents are unchanged by this reissue.
This is a main-based fork release, not a byte-for-byte rebuild of OpenAI's 0.155.1 tag. The upstream section covers all 80 non-merge commits between the pinned bases; the complete commit list is included below. Older fork commits rewritten by rebase are not presented as new features.
Upgrade and compatibility notes
- When upgrading from 0.155.0, update the CLI/app-server and Go SDK together: the protocol/schema/manifest digests changed in the original 0.155.1 release. This MCP correction does not change those digests or the SDK API.
- The Go module path remains
github.com/openai/codex/sdk/go; the minimum Go version remains 1.25. Select the matching fork revision/tag through your existing fork integration. - The Go SDK adds
PluginDetail.OnboardingSkilland removesConfigRequirements.WindowsSandboxPrivateDesktop, matching the current upstream API. - New local TUI threads no longer request reasoning summaries by default. Explicit reasoning-summary settings remain respected.
- Replace each system's
bin/files together; executable names have no operating-system or architecture suffixes. - This explicitly requested same-version correction replaces only the
rust-v0.155.1runtime tag and its five archives. Older version tags andsdk/go/v0.155.1are unchanged; the Go tag is retained to avoid breaking module proxy/checksum immutability. User/provider configuration is not automatically modified. - These bin-only packages do not include optional native voice/audio resources or the provisioned Windows sandbox-service package.
MCP / Code Mode correction in this reissue
- The MCP line setting is now an independent override. With
max_lines = 150andmcp_max_lines = 5000, a 225-line MCP response reaches the model without being cut back to the general 150-line limit. When the MCP setting is absent, the general limit remains the fallback; zero and stricter MCP limits retain their meaning. - Code Mode applies this override to each complete emitted result, including
exec,wait, and notifications. It applies to the whole result, even when JavaScript combines MCP data, command output, and generated text; it does not infer per-source limits after arbitrary JavaScript transformations. - History keeps the selected policy. Existing metadata carries the effective line limit through recording and replay. Delayed notifications retain the originating policy after a model switch. The intermediate MCP formatter no longer reapplies the line limit, avoiding a second cut of an existing omission marker.
- Other boundaries remain intact. Ordinary direct command, custom, and dynamic outputs retain the general line limit. Byte/token budgets and explicit
max_output_tokensstill apply; this is not unlimited output. Raw nested JavaScript values, typed media ordering, and the encrypted-MCP fix below are preserved. Raw events and traces retain their byte/token bound.
Upstream changes since 0.155.0
TUI, reasoning, and task navigation
- Restored disabled reasoning summaries as the default for new local TUI sessions, preventing provider request rejection where summaries are unsupported. This is the principal upstream 0.155.1 release fix.
- Preserved reasoning order within TUI activity groups and kept exploration grouped across reasoning and nonzero command exits.
- Added user notifications for asynchronous questions and made their replies compatible with the desktop client.
- Added six bundled themes and theme-aware accents, and used catalog model display names throughout the TUI.
- Unified tool-output previews around a three-row limit.
- Limited the agent command center's initial load to ten recent sessions.
- Allowed recovery commands when the current thread is unavailable and allowed
/reviewduring MCP startup.
Agent control, instructions, and Guardian
- Introduced a backend-independent
AgentControlcontract while retaining local execution inLocalAgentControl. - Agent listing now returns
LiveAgentrecords; completion routing and rollout-budget accounting are owned by the controller. - Thread instruction providers can share updates with subagents.
- Guardian reviews use captured live checkpoints and the applied instruction snapshot; completed reviews are flushed before decisions are delivered.
- Enabled Guardian reuse of parent compaction by default.
- Preserved request-level reasoning effort for memory/title workers and gated effort changes on explicit model support.
- Added explicit turn triggers for exec/TUI requests.
- Added catalog-provided parameter schemas for Multi-Agent V2 tools.
Context, retries, and runtime efficiency
- Added opt-in compaction after final responses.
- Centralized retry eligibility and delays in
CodexErr. - Avoided cloning excluded or active turn items for metadata-only/history-limited resume operations.
- Skipped unnecessary skill discovery when injecting items into initialized threads.
- Kept captured step settings, approval environments, permissions, and daemon recovery environment state consistent.
- Refreshed model catalogs before new turns after authentication changes.
- Corrected active-turn environment lookups and executor registration refresh/recovery.
- No fixed token-savings percentage is claimed; these are correctness and resource-use changes, not an end-to-end benchmark.
Plugins, providers, networking, and authentication
- Exposed declared onboarding skills in plugin details.
- Separated catalog discovery/listing from plugin package resolution, added shared catalog APIs and turn-start cloud plugin discovery, and renamed internal MCP/app extension interfaces.
- Bound remote plugin measurements to trusted plugin releases and added authenticated measurement references.
- Added explicit provider model-catalog URLs and authentication-mode labels for catalog-fetch timing.
- Added system-proxy fallback for login/startup requests.
- Composed gateway OAuth with primary-provider authentication and handled unknown error classifications.
- Shared ChatGPT cookies between HTTP and WebSocket transports.
- Added a standalone network-proxy binary with JSON configuration and corrected its policy initialization. That optional standalone executable is not an additional asset in this fork's bin-only package layout.
- Advertised the control socket's WebSocket message-size limit and added a command-start lifecycle callback.
Permissions, sandboxing, daemons, and platforms
- Linux sandbox checks now accept unrelated namespace mounts without treating namespace identifiers as ordinary filesystem paths, while preserving socket isolation.
- macOS Seatbelt policies deny XPC service lookups, restrict mutating
fcntloperations, remove an unnecessary runningboard default, and preserve exclusions in scratch directories. - Shared process-group termination uses a macOS member fallback; provisioned macOS CLI packages retain their signing identity.
- Legacy Windows sandboxes always use private desktops, removing the old optional requirement field. Sandboxed descendants retain Windows package identity.
- Managed networking defaults local binding to true where applicable; approved escalation remains available with environment-owned network policies.
- Remote workspace roots stay under server control.
- Shared-daemon startup accepts compatible feature overrides, and worktree sessions can reuse an existing local daemon.
Builds, diagnostics, and tests
- Added a composite action for building and smoke-testing Codex packages and pinned WinGet publication dependencies.
- Added bounded filesystem-path diagnostics to
codex doctorand configuration/feature diagnostics to report metadata. - Added environment inheritance support to workspace-root tests.
- Stabilized delayed-startup, busy-executable, Guardian, multi-agent resume, model-catalog timeout, sampler, and TUI interruption tests; local Windows sandbox tests run exclusively.
- Split analytics test suites and refreshed environment-sensitive test fixtures.
- The complete changelog below also records internal maintenance that is not a separate user-facing feature.
New fork reconciliation changes
These changes preserve the existing fork's behavior on the new upstream architecture. Rebase-candidate defects are not claims of regressions in the previously published 0.155.0.
- Encrypted MCP results survive stricter line limits. Fixed an existing fork bug where text content marked
codex/encryptedContentcould be flattened into ordinary text whenmcp_max_lineswas stricter than the general line limit andstructuredContentwas absent. The encrypted payload could then be displayed as ciphertext or truncated away. The fix preserves the already decodedEncryptedContentand uses the existing typed truncation path, including a zero-line budget. A new regression failed before the fix; all 18 context/output tests passed afterward. - Spawn budgets survive the controller migration. The cumulative
TurnSpawnBudgetnow lives with shared agent types and is carried bySpawnAgentOptions. V1/V2 follow-ups preserve the captured requesting turn's budget: a newly triggered idle task gets the new budget, while active work andQueueOnlymessages retain their existing budget. - Quiet waits use the new agent-listing contract.
check_agent_statusreadsLiveAgentidentity/status records, excluding the current agent correctly. - Completion delivery remains quiet and ordered. The upstream terminal-turn controller path is retained, but parent completions are enqueued without triggering premature resampling. Status-aware delivery and Guardian completion flushing remain intact.
- Upstream tool schemas and fork plaintext delivery coexist. Catalog parameter overrides and their validation are retained. The catalog lookup key remains
wait_agent, while the model-facing tool name remainscheck_agent_status; no new alias or unified-wait layer is added. - Capacity retry guarantees use upstream's new retry logic. The separate overload counter and minimum three retries are retained before the centralized retry-delay decision, including local compaction. Server delay advice, saturating counters, transport fallback, and exhausted-retry metadata are preserved.
- Local compaction uses the new error-reporting owner. Retry handling is connected to upstream's renamed helper without duplicating error recording in the inner loop; post-turn compaction remains best-effort.
- The Linux namespace fix is now upstream-owned. The fork's duplicate nsfs patch/test was removed because upstream openai#46535 covers the behavior and additional isolation cases. The daemon-mount implementation/tests now match the pinned upstream base.
- Historical no-op commits were removed. The already-reverted cascade-interruption patch and its revert were omitted as a net-zero pair. Cascading interruptions and the reverted unified-wait/background-disable experiments were not restored.
- Runtime tests and imports follow upstream's new type/environment owners. No replacement controller architecture or extra fallback layer was introduced.
Go SDK changes
- Added typed
PluginDetail.OnboardingSkillasOptional[SkillSummary]. - Missing
onboardingSkillnow decodes to explicit null, matching Rust's serde default; explicit null and skill objects preserve their semantics and camelCase round trips. - Removed only
ConfigRequirements.WindowsSandboxPrivateDesktop, because upstream always uses private desktops for the corresponding sandbox path. - Regenerated stable/experimental schema bundles, serde manifest metadata, Go protocol types, compatibility digests, and the initialize digest snapshot.
- RPC and notification inventories did not change, so no speculative high-level wrappers were added.
- Existing nullable/union behavior, image decoding, timeline casing, local-image paths, JSON Schema forwarding, bounded additional context, filtered completion backlog, and realtime notification behavior are retained.
- The matching Go SDK successfully completed its strict handshake against the newly built runtime, without a compatibility override.
Existing fork capabilities retained
These are cumulative differences from upstream, not new features introduced by 0.155.1:
- Configurable model-visible byte/line truncation for function, custom, dynamic, MCP, and command output, including intersecting byte/token budgets. The MCP and Code Mode line-override semantics are corrected as described above.
- Originating-step policies retained through delayed Code Mode results, raw rollout storage, resume, fork, and replay.
- Custom providers and context-window/auto-compaction overrides for typed and fallback agents.
- Configurable plaintext cross-provider messages and inherited dynamic tools in child/delegate threads.
- Cumulative per-turn spawn limits, race-safe publication accounting, quiet
check_agent_statuswaits, and parent completion notifications for follow-ups. - Compaction headroom, bounded retained history, no-progress detection that excludes failed tools, and failed-turn reporting when compaction cannot progress.
- Prompt-cache preservation during local compaction and prefill reset when the context window advances.
- At least three retries for model-capacity errors, including local compaction.
- Tolerant parsing of malformed completed-response usage metadata.
- The expanded user-input limit of 2,097,152 text characters.
- The typed Go SDK's resource clients, request/event routing, and strict runtime compatibility checks.
- Direct-only routing recovery, explicit tool omissions, consistent tool instructions, and warnings about unobserved nested Code Mode results.
Downloadable packages
Exactly five system archives, all built from the release source above. Each contains bin/ with unsuffixed executable names:
- Linux GNU/glibc x86_64 and ARM64:
codex,codex-app-server,codex-code-mode-host,codex-responses-api-proxy,bwrap. - macOS x86_64 and ARM64:
codex,codex-app-server,codex-code-mode-host,codex-responses-api-proxy. - Windows x86_64:
codex.exe,codex-app-server.exe,codex-code-mode-host.exe,codex-responses-api-proxy.exe,codex-command-runner.exe,codex-windows-sandbox-setup.exe.
Linux archives use GNU/glibc, not musl. Optional native voice/audio resources and provisioned Windows sandbox-service packaging are outside this bin-only layout.
Validation and limitations
MCP correction and rebuilt packages
- The direct 225-line MCP regression failed on the original runtime and passed after the fix. Targeted core unit/context/history checks: 119 passed. Core integration checks: 158 passed, including the Code Mode module, truncation, direct MCP,
exec/wait, delayed notifications, model switches, and replay. Adjacent packages (codex-tools, output truncation, history, config): 488 passed. - Fresh independent Astra review of the complete correction diff: PASS, no blocking or non-blocking findings. This was a review of the correction, not another broad rebase review.
- The configuration schema changed only its
mcp_max_linesdescription. SDK/API shapes, Cargo dependencies, and the Bazel lock did not change. Scoped Clippy, formatting, and whitespace checks passed. - A freshly built debug CLI passed the isolated
0.155.1version smoke and strict Go SDK handshake (-count=1, required real runtime, 0.908s), without a compatibility override or live paid provider calls. - All five targets passed in run 35471390450 for source
1a82148f5d2cb846dadd976c2297260a8edc76cf, including runner checkout, package layout, andcodex-cli 0.155.1assertions. macOS ARM64 was retried once after a GitHub artifact-upload DNS failure; the four successful targets were retained. - All five downloaded artifact ZIPs matched GitHub's SHA-256 digests and sizes. The five runtime archives passed integrity and exact-layout checks; all 24 executable payloads have the expected ELF/Mach-O/PE architecture and Unix executable permissions. Both Linux packages use GNU/glibc loaders; Linux x86_64 also passed a local version smoke with isolated homes.
- All five uploaded replacement assets matched the verified local archive sizes and GitHub SHA-256 digests before publication. The existing release was updated through a draft after backing up and checksum-verifying the original packages.
Original rebase / initial 0.155.1 validation
The following checks were completed for the original source 5838f5d29977bf2c969fad74a849190c3e0b5def; they are retained here as the rebase record, not claimed as rerun for the MCP correction.
- Go
-race: 573 tests across 14 packages; stable/experimental/both generation and manifest checks passed. - App-server protocol: 346 passed, one skipped.
- Strict SDK initialization passed against the newly built debug CLI, using temporary homes and local mocks.
- Core/app-server/Code Mode runtime all-target checks passed.
- Targeted tests passed for turn spawn budgets, quiet waits, dynamic tools, plaintext delivery, model/context overrides, truncation/replay, compaction/retries, full-buffer cleanup, and sensitive diagnostics.
- Additional passing suites: Code Mode runtime 87; history 28; output truncation 21; Linux daemon mounts 22; targeted app-server initialization/additional-context/agent-instruction tests 32; GitHub/build scripts 52.
- Configuration schema and Bazel lock regeneration had no drift. Scoped Clippy, formatting, and the complete fork whitespace/conflict check passed.
- Independent Astra review of the complete effective fork delta identified one blocker, F-01. After the minimal encrypted-MCP fix and red-to-green regression, an independent targeted recheck closed F-01 and confirmed that neighboring plaintext/mixed limits remain enforced. No blocking findings remain; the broad review was not repeated.
- All five GitHub target jobs passed in run 35444376471, with matching source SHA, exact package-list checks, and
codex-cli 0.155.1version checks on each runner. - All five downloaded archives passed integrity and exact-layout checks. All 24 executable payloads have the expected ELF/Mach-O/PE architecture; Unix executable permissions are present. Linux x86_64 additionally passed a local
--versionsmoke test in an isolated temporary home and uses the GNU/glibc loader. - GitHub's SHA-256 digests and sizes for all five uploaded release assets match the checked local archives.
Validation scope: the full core, workspace, and app-server suites were not run for this cycle. This is not an “all tests green” claim. The host-specific caveats recorded in 0.155.0 are not established as fixed by these targeted checks. Provider regressions were tested with mocks, not every live paid external provider.
Source and complete changelog
- Previous fork release 0.155.0.
- Pinned upstream-base comparison.
- Cumulative fork implementation.
- Official upstream 0.155.1 release notes.
Because the fork was rebased, release-history commit counts also contain rewritten older fork commits. The pinned base comparison separates new upstream work from that rewritten history.
Complete upstream changelog: all 80 non-merge commits since the previous pinned base
78245b47afDeny XPC service lookups in macOS Seatbelt profiles (openai#46583)ed12cc75d3Keep Guardian reviews on the applied instruction snapshot (openai#46580)6b78e825aeLimit the agent command center to 10 recent sessions on startup (openai#46579)29a57861e3Fix standalone network proxy policy initialization (openai#46578)e24ac448b3Allow thread instruction providers to share updates with subagents (openai#46577)fd59b42a09Preserve Windows package identity for sandboxed descendants (openai#46575)d5afb62bb3Notify users when asynchronous questions arrive in the TUI (openai#46574)94e3c20906Add a standalone network proxy binary with JSON configuration (openai#46573)394dadb93dAdd turn-start cloud plugin discovery to the MCP extension (openai#46572)d84ebff592Preserve macOS Seatbelt exclusions in scratch directories (openai#46571)c223ff3170Tag remote model fetch duration by authentication mode (openai#46570)f81a6331b4Set explicit turn triggers for exec and TUI requests (openai#46569)5685183570Use captured environment state for permissions and daemon recovery (openai#46568)a7e069dc3aSeparate plugin catalog listing from package resolution (openai#46567)ef9f3d022aAllow recovery commands when the current thread is unavailable (openai#46566)de33f2d22aPreserve reasoning order in TUI activity groups (openai#46565)b948cfa88dRename plugin MCP and app extension APIs (openai#46564)3bb0a530d1Add system proxy fallback for login and startup requests (openai#46562)888be42a20Support explicit provider model catalog URLs (openai#46561)c2a924fc4aFix stale environment config in the network approval test (openai#46560)e416eadf7fEncapsulate rollout budget accounting inLocalAgentControl(openai#46559)46d87f3b1cAdd shared plugin catalog discovery APIs (openai#46558)cd2f9ca692Fix active-turn environment selection lookup (openai#46557)c7828dd010Keep step settings and approval environments consistent (openai#46556)328feb0c29Track executor registrations across connection refresh and recovery (openai#46555)a633ebc124Always use private desktops for legacy Windows sandboxes (openai#46554)c6f5d9e9b5ReturnLiveAgentrecords from agent listing (openai#46553)7a15548c6aMove child completion routing into the agent controller (openai#46552)bfb8daa3c9Add a composite action to build and smoke-test Codex packages (openai#46551)98a8d4ea9cAdvertise the control socket's WebSocket message size limit (openai#46548)c026e7a622Expose a backend-independent agent control contract (openai#46547)7e0463b568Skip skill discovery when injecting items into initialized threads (openai#46546)05de935205Expose declared onboarding skills in plugin details (openai#46544)b33199b1fbAdd bounded filesystem path diagnostics tocodex doctor(openai#46543)184ea84526Add authenticated remote plugin measurement references (openai#46542)49e248d4c3Add opt-in compaction after final responses (openai#46541)d5b29951acCentralize retry decisions and delays inCodexErr(openai#46540)b244e9bafeAdd a command-start callback for tool lifecycle extensions (openai#46539)22dea11020Allow unrelated namespace mounts in Linux sandbox socket checks (openai#46535)ab59b78287Supportenv_inheritinworkspace_root_test(openai#46534)61b08f1011Disable reasoning summaries by default for new TUI threads (openai#46533)01f92c5780Removecom.apple.runningboardfrom Seatbelt platform defaults (openai#46532)f5b7ca7249Preserve request-level reasoning effort for memory and title workers (openai#46531)78d4d983d3Gate reasoning effort updates on explicit model support (openai#46530)1537497e52Allow compatible feature overrides when starting the shared daemon (openai#46529)6cf2ff11b3Bind executor plugin measurements to the trusted plugin version (openai#46528)6adaf3cac4Pin WinGet publishing dependencies in the release workflow (openai#46527)5701a576ccRetry busy executable launches in packaged daemon tests (openai#46524)74af2496c9Default local binding to true for MXC managed networking (openai#46523)3fd9e7e30eEnable Guardian parent-compaction reuse by default (openai#46522)d6fb836f31Use macOS member fallback in shared process-group termination helpers (openai#46521)4b9e7f6473Use paused time in sampler and model catalog timeout tests (openai#46519)cdfda82386Handle delayed process startup in the Guardian network approval test (openai#46518)e811c2832aStabilize the TUI exit interruption test (openai#46517)d374a93b41Handle completion timing in the multi-agent resume test (openai#46516)8933a816ebReplay guardian checkpoints into a fresh session in tests (openai#46514)7fb599de8cRenameAgentControltoLocalAgentControl(openai#46513)0f7c8608bdCapture Guardian review checkpoints from live context (openai#46512)05a93a8a1dAvoid cloning excluded turn items during thread resume (openai#46511)dfb265764dAvoid cloning active turn items for metadata-only thread resumes (openai#46510)36430b3688Flush completed Guardian reviews before delivering decisions (openai#46509)2b84296288Refresh the model catalog before turns after auth changes (openai#46508)8003609cc7Run Windows sandbox tests exclusively when local (openai#46507)12acac2a66Share ChatGPT cookies between HTTP and WebSocket transports (openai#46506)cc7591646eSupport catalog parameter schemas for Multi-Agent V2 tools (openai#46505)907b751eabAdd six bundled TUI themes and theme-aware accents (openai#46504)547c9a1aadUse catalog model display names throughout the TUI (openai#46503)f5b941c910Add configuration and feature diagnostics to report metadata (openai#46501)04e4d2b40fBlock mutating fcntls in restricted macOS Seatbelt policies (openai#46500)e0f05de6e0Allow approved escalation with environment-owned network policies (openai#46499)e497393552Allow worktree sessions to use an existing local daemon (openai#46498)c0e1b78253Preserve the provisioned macOS CLI's code-signing identity (openai#46495)6d29cc6bacKeep remote workspace roots under server control (openai#46494)35b746a3e3Allow/reviewduring MCP startup (openai#46493)4f3867123fUnify TUI tool output previews with a three-row limit (openai#46492)4d23af0975Compose gateway OAuth with primary provider authentication (openai#46490)2f522c5dc0Split analytics tests into focused suites (openai#46488)71406edbd5Keep TUI exploration grouped across reasoning and nonzero exits (openai#46487)dbf478850fMake TUI async question replies compatible with desktop (openai#46486)3d5b66c655Handle unknown error classifications and configure gateway OAuth (openai#46482)