Skip to content

Codex fork 0.155.1

Choose a tag to compare

@Dirard Dirard released this 20 Sep 03:21

Codex fork 0.155.1

This release updates the fork from 0.155.0 to 0.155.1: a rebase onto the next pinned upstream main snapshot, adaptation of the fork's agent/runtime changes, synchronized Go SDK bindings, and five complete bin-only runtime packages.

Same-version reissue: the runtime packages have been rebuilt with the MCP/Code Mode line-limit correction described below. If you downloaded the original 0.155.1 packages, download them again; --version remains codex-cli 0.155.1.

Comparison baseline

  • Previous fork release: 0.155.0, source 3c37c16dc636604b7cc7324eed09d2a45db516fb.
  • Previous upstream-tracking base: 08ff997106556c1bae45144b717ecbbffde14744.
  • New upstream-tracking base: 4981b6d01effb84d0a79faa5e41f5e06c4fc5ce7, corresponding to OpenAI main@78245b47af2a7aafcabe025828ceecca69db4df1.
  • Runtime release source: 1a82148f5d2cb846dadd976c2297260a8edc76cf.
  • Original 0.155.1 runtime source: 5838f5d29977bf2c969fad74a849190c3e0b5def.
  • CLI tag: rust-v0.155.1. Compatible Go SDK tag: sdk/go/v0.155.1, retained at 5838f5d29977bf2c969fad74a849190c3e0b5def; its module contents are unchanged by this reissue.

This is a main-based fork release, not a byte-for-byte rebuild of OpenAI's 0.155.1 tag. The upstream section covers all 80 non-merge commits between the pinned bases; the complete commit list is included below. Older fork commits rewritten by rebase are not presented as new features.

Upgrade and compatibility notes

  • When upgrading from 0.155.0, update the CLI/app-server and Go SDK together: the protocol/schema/manifest digests changed in the original 0.155.1 release. This MCP correction does not change those digests or the SDK API.
  • The Go module path remains github.com/openai/codex/sdk/go; the minimum Go version remains 1.25. Select the matching fork revision/tag through your existing fork integration.
  • The Go SDK adds PluginDetail.OnboardingSkill and removes ConfigRequirements.WindowsSandboxPrivateDesktop, matching the current upstream API.
  • New local TUI threads no longer request reasoning summaries by default. Explicit reasoning-summary settings remain respected.
  • Replace each system's bin/ files together; executable names have no operating-system or architecture suffixes.
  • This explicitly requested same-version correction replaces only the rust-v0.155.1 runtime tag and its five archives. Older version tags and sdk/go/v0.155.1 are unchanged; the Go tag is retained to avoid breaking module proxy/checksum immutability. User/provider configuration is not automatically modified.
  • These bin-only packages do not include optional native voice/audio resources or the provisioned Windows sandbox-service package.

MCP / Code Mode correction in this reissue

  • The MCP line setting is now an independent override. With max_lines = 150 and mcp_max_lines = 5000, a 225-line MCP response reaches the model without being cut back to the general 150-line limit. When the MCP setting is absent, the general limit remains the fallback; zero and stricter MCP limits retain their meaning.
  • Code Mode applies this override to each complete emitted result, including exec, wait, and notifications. It applies to the whole result, even when JavaScript combines MCP data, command output, and generated text; it does not infer per-source limits after arbitrary JavaScript transformations.
  • History keeps the selected policy. Existing metadata carries the effective line limit through recording and replay. Delayed notifications retain the originating policy after a model switch. The intermediate MCP formatter no longer reapplies the line limit, avoiding a second cut of an existing omission marker.
  • Other boundaries remain intact. Ordinary direct command, custom, and dynamic outputs retain the general line limit. Byte/token budgets and explicit max_output_tokens still apply; this is not unlimited output. Raw nested JavaScript values, typed media ordering, and the encrypted-MCP fix below are preserved. Raw events and traces retain their byte/token bound.

Upstream changes since 0.155.0

TUI, reasoning, and task navigation

  • Restored disabled reasoning summaries as the default for new local TUI sessions, preventing provider request rejection where summaries are unsupported. This is the principal upstream 0.155.1 release fix.
  • Preserved reasoning order within TUI activity groups and kept exploration grouped across reasoning and nonzero command exits.
  • Added user notifications for asynchronous questions and made their replies compatible with the desktop client.
  • Added six bundled themes and theme-aware accents, and used catalog model display names throughout the TUI.
  • Unified tool-output previews around a three-row limit.
  • Limited the agent command center's initial load to ten recent sessions.
  • Allowed recovery commands when the current thread is unavailable and allowed /review during MCP startup.

Agent control, instructions, and Guardian

  • Introduced a backend-independent AgentControl contract while retaining local execution in LocalAgentControl.
  • Agent listing now returns LiveAgent records; completion routing and rollout-budget accounting are owned by the controller.
  • Thread instruction providers can share updates with subagents.
  • Guardian reviews use captured live checkpoints and the applied instruction snapshot; completed reviews are flushed before decisions are delivered.
  • Enabled Guardian reuse of parent compaction by default.
  • Preserved request-level reasoning effort for memory/title workers and gated effort changes on explicit model support.
  • Added explicit turn triggers for exec/TUI requests.
  • Added catalog-provided parameter schemas for Multi-Agent V2 tools.

Context, retries, and runtime efficiency

  • Added opt-in compaction after final responses.
  • Centralized retry eligibility and delays in CodexErr.
  • Avoided cloning excluded or active turn items for metadata-only/history-limited resume operations.
  • Skipped unnecessary skill discovery when injecting items into initialized threads.
  • Kept captured step settings, approval environments, permissions, and daemon recovery environment state consistent.
  • Refreshed model catalogs before new turns after authentication changes.
  • Corrected active-turn environment lookups and executor registration refresh/recovery.
  • No fixed token-savings percentage is claimed; these are correctness and resource-use changes, not an end-to-end benchmark.

Plugins, providers, networking, and authentication

  • Exposed declared onboarding skills in plugin details.
  • Separated catalog discovery/listing from plugin package resolution, added shared catalog APIs and turn-start cloud plugin discovery, and renamed internal MCP/app extension interfaces.
  • Bound remote plugin measurements to trusted plugin releases and added authenticated measurement references.
  • Added explicit provider model-catalog URLs and authentication-mode labels for catalog-fetch timing.
  • Added system-proxy fallback for login/startup requests.
  • Composed gateway OAuth with primary-provider authentication and handled unknown error classifications.
  • Shared ChatGPT cookies between HTTP and WebSocket transports.
  • Added a standalone network-proxy binary with JSON configuration and corrected its policy initialization. That optional standalone executable is not an additional asset in this fork's bin-only package layout.
  • Advertised the control socket's WebSocket message-size limit and added a command-start lifecycle callback.

Permissions, sandboxing, daemons, and platforms

  • Linux sandbox checks now accept unrelated namespace mounts without treating namespace identifiers as ordinary filesystem paths, while preserving socket isolation.
  • macOS Seatbelt policies deny XPC service lookups, restrict mutating fcntl operations, remove an unnecessary runningboard default, and preserve exclusions in scratch directories.
  • Shared process-group termination uses a macOS member fallback; provisioned macOS CLI packages retain their signing identity.
  • Legacy Windows sandboxes always use private desktops, removing the old optional requirement field. Sandboxed descendants retain Windows package identity.
  • Managed networking defaults local binding to true where applicable; approved escalation remains available with environment-owned network policies.
  • Remote workspace roots stay under server control.
  • Shared-daemon startup accepts compatible feature overrides, and worktree sessions can reuse an existing local daemon.

Builds, diagnostics, and tests

  • Added a composite action for building and smoke-testing Codex packages and pinned WinGet publication dependencies.
  • Added bounded filesystem-path diagnostics to codex doctor and configuration/feature diagnostics to report metadata.
  • Added environment inheritance support to workspace-root tests.
  • Stabilized delayed-startup, busy-executable, Guardian, multi-agent resume, model-catalog timeout, sampler, and TUI interruption tests; local Windows sandbox tests run exclusively.
  • Split analytics test suites and refreshed environment-sensitive test fixtures.
  • The complete changelog below also records internal maintenance that is not a separate user-facing feature.

New fork reconciliation changes

These changes preserve the existing fork's behavior on the new upstream architecture. Rebase-candidate defects are not claims of regressions in the previously published 0.155.0.

  • Encrypted MCP results survive stricter line limits. Fixed an existing fork bug where text content marked codex/encryptedContent could be flattened into ordinary text when mcp_max_lines was stricter than the general line limit and structuredContent was absent. The encrypted payload could then be displayed as ciphertext or truncated away. The fix preserves the already decoded EncryptedContent and uses the existing typed truncation path, including a zero-line budget. A new regression failed before the fix; all 18 context/output tests passed afterward.
  • Spawn budgets survive the controller migration. The cumulative TurnSpawnBudget now lives with shared agent types and is carried by SpawnAgentOptions. V1/V2 follow-ups preserve the captured requesting turn's budget: a newly triggered idle task gets the new budget, while active work and QueueOnly messages retain their existing budget.
  • Quiet waits use the new agent-listing contract. check_agent_status reads LiveAgent identity/status records, excluding the current agent correctly.
  • Completion delivery remains quiet and ordered. The upstream terminal-turn controller path is retained, but parent completions are enqueued without triggering premature resampling. Status-aware delivery and Guardian completion flushing remain intact.
  • Upstream tool schemas and fork plaintext delivery coexist. Catalog parameter overrides and their validation are retained. The catalog lookup key remains wait_agent, while the model-facing tool name remains check_agent_status; no new alias or unified-wait layer is added.
  • Capacity retry guarantees use upstream's new retry logic. The separate overload counter and minimum three retries are retained before the centralized retry-delay decision, including local compaction. Server delay advice, saturating counters, transport fallback, and exhausted-retry metadata are preserved.
  • Local compaction uses the new error-reporting owner. Retry handling is connected to upstream's renamed helper without duplicating error recording in the inner loop; post-turn compaction remains best-effort.
  • The Linux namespace fix is now upstream-owned. The fork's duplicate nsfs patch/test was removed because upstream openai#46535 covers the behavior and additional isolation cases. The daemon-mount implementation/tests now match the pinned upstream base.
  • Historical no-op commits were removed. The already-reverted cascade-interruption patch and its revert were omitted as a net-zero pair. Cascading interruptions and the reverted unified-wait/background-disable experiments were not restored.
  • Runtime tests and imports follow upstream's new type/environment owners. No replacement controller architecture or extra fallback layer was introduced.

Go SDK changes

  • Added typed PluginDetail.OnboardingSkill as Optional[SkillSummary].
  • Missing onboardingSkill now decodes to explicit null, matching Rust's serde default; explicit null and skill objects preserve their semantics and camelCase round trips.
  • Removed only ConfigRequirements.WindowsSandboxPrivateDesktop, because upstream always uses private desktops for the corresponding sandbox path.
  • Regenerated stable/experimental schema bundles, serde manifest metadata, Go protocol types, compatibility digests, and the initialize digest snapshot.
  • RPC and notification inventories did not change, so no speculative high-level wrappers were added.
  • Existing nullable/union behavior, image decoding, timeline casing, local-image paths, JSON Schema forwarding, bounded additional context, filtered completion backlog, and realtime notification behavior are retained.
  • The matching Go SDK successfully completed its strict handshake against the newly built runtime, without a compatibility override.

Existing fork capabilities retained

These are cumulative differences from upstream, not new features introduced by 0.155.1:

  • Configurable model-visible byte/line truncation for function, custom, dynamic, MCP, and command output, including intersecting byte/token budgets. The MCP and Code Mode line-override semantics are corrected as described above.
  • Originating-step policies retained through delayed Code Mode results, raw rollout storage, resume, fork, and replay.
  • Custom providers and context-window/auto-compaction overrides for typed and fallback agents.
  • Configurable plaintext cross-provider messages and inherited dynamic tools in child/delegate threads.
  • Cumulative per-turn spawn limits, race-safe publication accounting, quiet check_agent_status waits, and parent completion notifications for follow-ups.
  • Compaction headroom, bounded retained history, no-progress detection that excludes failed tools, and failed-turn reporting when compaction cannot progress.
  • Prompt-cache preservation during local compaction and prefill reset when the context window advances.
  • At least three retries for model-capacity errors, including local compaction.
  • Tolerant parsing of malformed completed-response usage metadata.
  • The expanded user-input limit of 2,097,152 text characters.
  • The typed Go SDK's resource clients, request/event routing, and strict runtime compatibility checks.
  • Direct-only routing recovery, explicit tool omissions, consistent tool instructions, and warnings about unobserved nested Code Mode results.

Downloadable packages

Exactly five system archives, all built from the release source above. Each contains bin/ with unsuffixed executable names:

  • Linux GNU/glibc x86_64 and ARM64: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy, bwrap.
  • macOS x86_64 and ARM64: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • Windows x86_64: codex.exe, codex-app-server.exe, codex-code-mode-host.exe, codex-responses-api-proxy.exe, codex-command-runner.exe, codex-windows-sandbox-setup.exe.

Linux archives use GNU/glibc, not musl. Optional native voice/audio resources and provisioned Windows sandbox-service packaging are outside this bin-only layout.

Validation and limitations

MCP correction and rebuilt packages

  • The direct 225-line MCP regression failed on the original runtime and passed after the fix. Targeted core unit/context/history checks: 119 passed. Core integration checks: 158 passed, including the Code Mode module, truncation, direct MCP, exec/wait, delayed notifications, model switches, and replay. Adjacent packages (codex-tools, output truncation, history, config): 488 passed.
  • Fresh independent Astra review of the complete correction diff: PASS, no blocking or non-blocking findings. This was a review of the correction, not another broad rebase review.
  • The configuration schema changed only its mcp_max_lines description. SDK/API shapes, Cargo dependencies, and the Bazel lock did not change. Scoped Clippy, formatting, and whitespace checks passed.
  • A freshly built debug CLI passed the isolated 0.155.1 version smoke and strict Go SDK handshake (-count=1, required real runtime, 0.908s), without a compatibility override or live paid provider calls.
  • All five targets passed in run 35471390450 for source 1a82148f5d2cb846dadd976c2297260a8edc76cf, including runner checkout, package layout, and codex-cli 0.155.1 assertions. macOS ARM64 was retried once after a GitHub artifact-upload DNS failure; the four successful targets were retained.
  • All five downloaded artifact ZIPs matched GitHub's SHA-256 digests and sizes. The five runtime archives passed integrity and exact-layout checks; all 24 executable payloads have the expected ELF/Mach-O/PE architecture and Unix executable permissions. Both Linux packages use GNU/glibc loaders; Linux x86_64 also passed a local version smoke with isolated homes.
  • All five uploaded replacement assets matched the verified local archive sizes and GitHub SHA-256 digests before publication. The existing release was updated through a draft after backing up and checksum-verifying the original packages.

Original rebase / initial 0.155.1 validation

The following checks were completed for the original source 5838f5d29977bf2c969fad74a849190c3e0b5def; they are retained here as the rebase record, not claimed as rerun for the MCP correction.

  • Go -race: 573 tests across 14 packages; stable/experimental/both generation and manifest checks passed.
  • App-server protocol: 346 passed, one skipped.
  • Strict SDK initialization passed against the newly built debug CLI, using temporary homes and local mocks.
  • Core/app-server/Code Mode runtime all-target checks passed.
  • Targeted tests passed for turn spawn budgets, quiet waits, dynamic tools, plaintext delivery, model/context overrides, truncation/replay, compaction/retries, full-buffer cleanup, and sensitive diagnostics.
  • Additional passing suites: Code Mode runtime 87; history 28; output truncation 21; Linux daemon mounts 22; targeted app-server initialization/additional-context/agent-instruction tests 32; GitHub/build scripts 52.
  • Configuration schema and Bazel lock regeneration had no drift. Scoped Clippy, formatting, and the complete fork whitespace/conflict check passed.
  • Independent Astra review of the complete effective fork delta identified one blocker, F-01. After the minimal encrypted-MCP fix and red-to-green regression, an independent targeted recheck closed F-01 and confirmed that neighboring plaintext/mixed limits remain enforced. No blocking findings remain; the broad review was not repeated.
  • All five GitHub target jobs passed in run 35444376471, with matching source SHA, exact package-list checks, and codex-cli 0.155.1 version checks on each runner.
  • All five downloaded archives passed integrity and exact-layout checks. All 24 executable payloads have the expected ELF/Mach-O/PE architecture; Unix executable permissions are present. Linux x86_64 additionally passed a local --version smoke test in an isolated temporary home and uses the GNU/glibc loader.
  • GitHub's SHA-256 digests and sizes for all five uploaded release assets match the checked local archives.

Validation scope: the full core, workspace, and app-server suites were not run for this cycle. This is not an “all tests green” claim. The host-specific caveats recorded in 0.155.0 are not established as fixed by these targeted checks. Provider regressions were tested with mocks, not every live paid external provider.

Source and complete changelog

Because the fork was rebased, release-history commit counts also contain rewritten older fork commits. The pinned base comparison separates new upstream work from that rewritten history.

Complete upstream changelog: all 80 non-merge commits since the previous pinned base