Skip to content

Codex fork 0.158.0

Choose a tag to compare

@Dirard Dirard released this 28 Sep 22:08

Codex fork 0.158.0

This is a main-based fork release following fork 0.156.0, not a byte-for-byte rebuild of OpenAI's official 0.158.0 tag. The pinned OpenAI main snapshot and the official release tag follow different branch histories; commit-SHA differences alone do not imply missing features.

Comparison baseline and provenance

  • Previous fork runtime and SDK: 0.156.0, source e8bab0d47f.
  • Previous pinned fork base: cdd1d9e1bb.
  • New pinned fork base: 1a840f77ea, merging OpenAI main@44fe510ce3.
  • Final reviewed semantic source: 25aac31a3a. Version-stamped release source: 5066ec32ee; only the workspace/local package versions change beyond the reviewed semantic source.
  • Matching tags: rust-v0.158.0 and sdk/go/v0.158.0. Earlier tags are not moved. The mistakenly dispatched 0.157.0 build was cancelled and is not a source of these packages. The corrected manual five-target run 36428114388, attempt 1, checked out exact source 5066ec32eea7bd37952337e2f35359db7445a629 on every runner and completed successfully on 2026-09-28 at 16:34:43 UTC.

The upstream section below covers all 303 non-merge commits between the pinned bases, not every change in OpenAI's official 0.158.0 release branch. The full exact commit list follows at the end.

Upstream changes since the previous pinned base

Agents, Guardian, and context

  • Agent operations and V2 child lookup/loading now route through AgentControl, including host-provided controllers. Pending inter-agent messages and ephemeral message boards survive their relevant lifecycle transitions; agent status and spawn observability improved.
  • Guardian now retains ordered assistant and authorization context, deduplicates retained instructions, keeps its own history across parent compaction, binds reviews to the target environment, and applies computer-use review to the Browser connector. Circuit-breaker interruptions gained opt-in structured errors.
  • Compaction preserves model/access-program pairs and user text, resumes context from the latest boundary, and applies the unchanged-model shortcut to more session sources. New user input can preempt a response; Code Mode can yield early for observations or opt in to user-input yielding.
  • Code Mode and tool metadata retention are more selective under outgoing budgets, including late truncated results and provider endpoint overrides. MCP/Code Mode input schema budgets are configurable.

App-server, networking, and security

  • thread/items/list accepts an item anchor as well as its existing opaque string cursor; mcpServerStatus/list can discover one server and reuse a thread's MCP connection. Realtime V3 adds opt-in backend reasoning status, and the executor connection API accepts an optional bearer token.
  • Application network policy now reaches HTTP/WebSocket, app-server, remote control, AWS auth/telemetry, and embedded startup paths. Executor authentication, reconnect credential boundaries, request bounds, and socket/process handling received targeted hardening.
  • Server Retry-After deadlines are preserved. Flex capacity failures have a distinct terminal error; plugin extension metadata was deliberately removed from discovery and summaries. Pro Max plan support and updated plan labels were added.
  • Windows sandbox startup/provisioning and child-process launches, macOS Seatbelt trust, Linux descriptor cleanup, and daemon socket masking received platform fixes. Diagnostic uploads and logs include more useful context while sensitive WebSocket headers and tool payloads are kept out of info logs.

Terminal UI and developer experience

  • Transcript selection/copying, links, scrolling, warnings, status, session switching, reconnect notices, startup drafts, and the fullscreen composer received focused fixes. Mermaid flowcharts support more native syntax, labels, shapes, and relationships; Markdown tables and math rendering/copying are more faithful.
  • Voice sessions remain active across thread navigation, and RTP timing is aligned. Prompt suggestions, working/completion tips, turn durations, and the welcome screen were refined.
  • Build/test infrastructure adds prebuilt V8 use, Rust debug-profile alignment, more reliable executable fixtures, and several race/fixture fixes. These are upstream source changes, not claims that optional voice resources or external service integrations are bundled in the archives below.

Fork reconciliation and Go SDK

All 134 fork commits were replayed: 90 patch-identical, 44 adapted, 0 dropped or unmatched. The adaptations preserve fork behavior on upstream AgentControl, host-owned child controllers, current Code Mode/context/history owners, independent Guardian history, and absolute Retry-After deadlines. The canonical collaboration tool remains wait_agent.

Two independent final-review findings were corrected and closed on the reviewed semantic source. R1 restores raw rollout output persistence and applies originating byte/token/line policy during replay, including old serialized rollouts, rather than bypassing caps after a processed-output reconstruction. R2 makes V2 wait inspect the selected AgentControl, so a host-owned running child is visible even without local runtime registration. No new rollout wire marker or migration was added. Fork-specific overloaded-server retry floors remain separate from upstream terminal Flex failures.

The generated Go SDK and runtime protocol are synchronized. Existing opaque string pagination cursors remain JSON strings; a new item anchor is an object. In source, ThreadItemsListParams.Cursor changes from Optional[string] to Optional[ThreadItemsListCursor], with typed string/anchor constructors. This is an intentional raw-Go source API change even though the old string wire shape remains compatible; callers assigning protocol.Some("cursor") must wrap the string with protocol.NewThreadItemsListCursorString("cursor").

RealtimeStartOptions.BackendReasoningStatus opts in with true; omitted/default false is not sent. Generated types also include MCP serverName, environment authBearerToken, FlexUnavailable/TooManyDenials, and Pro Max. Upstream-removed plugin extension bindings and their obsolete test were removed instead of restoring the server feature; surviving PluginSummary defaults remain. The Go module path stays github.com/openai/codex/sdk/go. Strict runtime/SDK digest matching and explicit compatibility overrides remain in force; use matching runtime and SDK versions together. Existing Gateway OAuth admission, cancellation, opt-in, and connection ownership behavior is retained.

Existing fork capabilities retained

These are cumulative fork differences, not all new in 0.158.0:

  • Independent mcp_max_lines for direct MCP and whole emitted Code Mode results, including exec/wait/notify, while ordinary tools keep the general cap; raw/encrypted/media outputs retain originating byte/token policies through model switches, persistence, and replay.
  • Custom providers, typed/fallback context-window and auto-compaction overrides, configurable plaintext messages across providers, and inherited dynamic tools.
  • Cumulative per-turn spawn budgets, active/idle follow-up semantics, quiet waits, parent completion notifications, bounded compaction history, headroom/no-progress handling, and at least three capacity retries.
  • Typed Go SDK resource clients, strict digest handshake, Gateway OAuth lifecycle, realtime closure, filtered completion backlog, image paths, and JSON Schema forwarding.

Downloadable packages

The release contains exactly five bin-only system archives — codex-package-aarch64-apple-darwin.tar.gz, codex-package-aarch64-unknown-linux-gnu.tar.gz, codex-package-x86_64-apple-darwin.tar.gz, codex-package-x86_64-unknown-linux-gnu.tar.gz, and codex-package-x86_64-pc-windows-msvc.zip — each with bin/ and unsuffixed executable names:

  • Linux GNU/glibc x86_64 and ARM64: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy, bwrap.
  • macOS x86_64 and ARM64: codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • Windows x86_64: codex.exe, codex-app-server.exe, codex-code-mode-host.exe, codex-responses-api-proxy.exe, codex-command-runner.exe, codex-windows-sandbox-setup.exe.

Linux uses GNU/glibc, not musl. Optional native voice/audio resources and provisioned Windows sandbox-service packaging are outside this bin-only layout. All five artifact sizes and SHA256 digests matched GitHub metadata. Outer ZIP CRCs, package integrity, exact contents, ELF/Mach-O/PE architectures, and Unix 0755 permissions were verified.

SHA256 of the five release archives:

29ac8c2e3b164b69baf471275e2f4bd4f086f2d26dcdf59a2791c325d6797dd3  codex-package-aarch64-apple-darwin.tar.gz
79c56dcee6ad36836b19956943152f61e5c9d95e7908d852904cb0b02ac97966  codex-package-aarch64-unknown-linux-gnu.tar.gz
477fc854e49fd03cf3667fb5b273ae2c3c4f13e7b3ce962e8e9486038b11a458  codex-package-x86_64-apple-darwin.tar.gz
3377e33b80026af109a0dbdd33208b38a51c7c8d01bd91e6db4db522c259b321  codex-package-x86_64-pc-windows-msvc.zip
5ef31921b896deec30b6504c408e598012a80385185c2b310ab4939c1e813f00  codex-package-x86_64-unknown-linux-gnu.tar.gz

Upgrade note: replacing binaries on disk does not update or restart an already-running app-server/daemon. An older process may still cause configuration or strict protocol-handshake errors. Run matching components, restart the daemon yourself if appropriate, or use --no-daemon to bypass it. This release does not automatically alter the installed CLI or running processes.

Validation and limitations

  • Rebase accounting: 134/134 fork commits replayed (90 identical, 44 adapted), pinned new base is an ancestor, and independent final review plus targeted R1/R2 closure found no remaining blockers.
  • Rust checks were focused, not full suites: app-server-protocol 350 passed/1 skipped; adjacent selections 927 passed; code-mode-runtime 88 passed; R1 old-wire/history checks 150 passed plus four metadata/encrypted cases; R2 host-owned wait plus existing cases 20 passed. These selections overlap and are not summed as unique coverage.
  • Stable and experimental schema/manifest/generator checks passed. The full Go race-enabled suite passed: 598 tests in 14 packages. A freshly rebuilt debug CLI passed an isolated strict real-runtime SDK handshake in 0.410s without compatibility override or paid model call.
  • All five runners passed the packaged codex-cli 0.158.0 version assertion. The downloaded Linux x86_64 release CLI passed an isolated version smoke and a fresh required-real-runtime strict SDK handshake (-count=1, 0.283s), without compatibility override. No installed binary or running daemon was changed.
  • Full Rust core, workspace, and app-server suites were not run. Focused checks are not full-suite coverage. The cancelled 0.157.0 run is excluded; only artifacts from corrected run 36428114388 are included.

Source and full upstream changelog

All 303 upstream non-merge commits since the previous pinned base