Skip to content

Codex fork 0.160.0

Choose a tag to compare

@Dirard Dirard released this 04 Oct 05:12

Codex fork 0.160.0

This is a main-based fork release following fork 0.159.0, not a byte-for-byte rebuild of OpenAI's official 0.160.0 release. The fork remains based on pinned OpenAI main; the official release follows a different branch history.

Comparison and source

  • Previous fork runtime and SDK source: dfbd20689f, published as 0.159.0.
  • Previous pinned base: 85714c61d1. New pinned base: 2cf9b0875a, merging OpenAI main@b172810921.
  • Official OpenAI 0.160.0 was published 2026-10-01 at 20:19:13 UTC and points to a956835d02. This fork does not claim to be identical to or rebuilt from that release branch.
  • Final reviewed semantic source: 0688bd1c60. The independent review of f65d445480 found two issues; the same reviewer closed both after targeted repair, with no remaining blocking findings.
  • Version-stamped 0.160.0 release source: 54fc12f7aa, shared by the annotated rust-v0.160.0 and sdk/go/v0.160.0 tags. This changes only the workspace and 161 local package versions; all 1,312 external Cargo records and other fields are unchanged. Exact-lease push and the single pinned five-target build succeeded.

The upstream section below covers all 229 non-merge commits between the pinned bases, not every change on OpenAI's official 0.160.0 release branch. Exact commit links follow at the end.

Upstream changes since fork 0.159.0

Agents, context, and history

  • Abort callbacks now complete before terminal turn events. Remote message-board notifications can reach active turns, queued agent mail survives session eviction, and upstream fresh V2 subagents gain opt-in dynamic-tool inheritance; this fork retains its unconditional fresh-child inheritance. The subagent picker and delegated-task previews track thread/archive and task-input state more accurately.
  • Resume/replay gained authoritative history, reusable unchanged-history snapshots, ordered world-state response items, persisted world-state snapshots, and persisted additional tool definitions. Explicit user goal edits can be recorded with explicit provenance; live tool-call metadata survives request windows.
  • Guardian V2 adds retained conversation support in async classification, bounded Decisions comparison transport, sender-review context, omission deduplication, and decisions agreement/latency telemetry. Host skill discovery is skipped for reviews and user restrictions survive handoff context.

MCP, app-server, protocol, and security

  • Stable thread/attachmentOwner/list finds owning threads by exact attachmentType and identityKey, with archived filtering and cursor pagination. Experimental thread-prediction request/notification types were added, but this upstream snapshot does not implement prediction runtime behavior.
  • MCP follows legacy tool pagination, validates enterprise authorization servers before ID-JAG exchange, uses rmcp for managed token exchange, preserves Windows environment variables, keeps resource helpers and shared types available in Code Mode, and emits attributed OAuth credential-storage telemetry.
  • The app-server protocol now accepts unknown CodexErrorInfo strings or objects, adds an advisory experimental Bedrock GovCloud requirements check, and carries optional explicit goal-mutation provenance. ModelProviderCapabilitiesReadResponse.namespaceTools is removed and tool namespaces are no longer provider-gated. Separately, custom providers gain capability overrides.
  • Bedrock adds GovCloud support, Ultrafast service tiers for Astra models, Sol catalog defaults, multi-agent V2/Ultra reasoning, and API-key Daybreak/cyber program paths. Model visibility remains server-, provider-, catalog-, and account-controlled; this release does not globally guarantee Sol visibility or access.
  • Exec/server paths gained writable streaming, bounded opens and request cleanup, cancellable reads, session recovery, permission catalogs, retry/jitter behavior, diagnostics, and stronger path/sandbox handling. Responses retries honor failed-event Retry-After advice while preserving the fork's capacity-retry floor.

Terminal UI, daemon, platform, and build

  • Transcript selection/copying, Find, pager and configured keybindings, Markdown links/tables/blockquotes, literal HTML copy, owned-transcript keyboard selection, and modal-period selection behavior improved. Command Center task renaming, retained backdrops, selection adjacency, and fork shortcuts were refined.
  • Daybreak gained persistent TUI selection, status/title state, continuation handling, API-key access, and codex exec support. Voice adds audio-device/microphone selection, local-device settings, and realtime transcript-tail persistence; managed in-app voice remains feature-gated.
  • Daemon update/startup diagnostics, release identity, cwd recovery, Windows-mounted WSL handling, updater stderr, remote-control socket setup, and diagnostic pruning improved. Windows sandbox/process/path and macOS/Linux sandbox handling received targeted fixes.
  • Rollout attachments are bundled more compactly, paginated command output is bounded, reverse JSONL scans use memrchr, blocking history/index work is moved off async workers, and SQLite corruption/recovery handling is typed. CI/build updates include toolchain, Windows bindings, age, signing-page, and test-infrastructure changes; they are not claims about bundled optional resources.

Fork reconciliation and Go SDK

All 146 fork commits were replayed: 105 patch-identical, 41 adapted, 0 dropped or unmatched. The new base remains an ancestor. Cumulative fork capabilities are retained, including independent direct-MCP/Code-Mode mcp_max_lines and originating output caps through replay; custom providers and context/compaction overrides; plaintext provider messages and inherited dynamic tools; cumulative spawn budgets, active/idle follow-ups, quiet waits, parent completion, bounded compaction history and capacity retry floors.

Final review of f65d445480 found two blockers. R1 was a duplicate abort_all_tasks lifecycle callback after upstream moved callback completion ahead of the terminal event; the duplicate outer emit was removed and the existing red regression now passes four targeted cases. R2 lost unconditional inherited dynamic tools for fresh V1/default V2 children; fresh-child inheritance was restored and the three targeted cases now pass. Guardian tool isolation and fresh-history behavior remain unchanged. The combined Guardian/abort/inheritance selection passed 14 tests. A fresh debug CLI/helper rebuild and isolated required-real-runtime strict SDK handshake passed, followed by scoped fix/format checks and the same reviewer's targeted closure of both findings.

The Rust stable/experimental schemas, serde manifest, precomputed exports, and generated Go protocol are synchronized from one frozen protocol snapshot. The Go generator now renders the open CodexErrorInfo anyOf as its existing typed union: known strings and known object variants keep typed fields, while unknown strings or objects round-trip through RawJSON instead of degrading the whole type to json.RawMessage.

Raw Go protocol changes include:

  • Breaking raw-field removal: ModelProviderCapabilitiesReadResponse.NamespaceTools is gone because the upstream wire response no longer contains namespaceTools.
  • Stable raw ThreadAttachmentOwnerList binding and types.
  • Experimental raw ThreadPredictionRequest, ThreadPredictionUpdatedNotification, and result types. These are protocol bindings only; no prediction runtime workflow is implemented by this snapshot.
  • Experimental raw BedrockCheckGovCloudRequirements binding and response types.
  • ThreadGoalSetParams and ThreadGoalClearParams gain optional nullable origin: "user" | "automatic". Generic wrappers do not infer or substitute user; callers must set it explicitly when they genuinely represent user provenance.

No new high-level SDK wrappers are claimed for these methods; generated raw-client coverage is the intentional scope. Existing MCP OAuth loginId correlation and legacy name/thread fallback, typed ThreadItemsListCursor, opt-in BackendReasoningStatus, strict digest handshake, resource clients, Gateway OAuth lifecycle, realtime behavior, and module path github.com/openai/codex/sdk/go remain in place.

Use the runtime and Go SDK from the same matching 0.160.0 release. Strict digest validation is not implicitly bypassed. Update the entire binary package, including codex-code-mode-host; do not mix a new CLI with an old daemon/app-server.

Downloadable packages

The pinned five-target release build succeeded on all targets. All five runner checkouts and codex-cli 0.160.0 version assertions passed. The release contains exactly five bin-only system archives:

  • codex-package-aarch64-apple-darwin.tar.gz and codex-package-x86_64-apple-darwin.tar.gz: bin/codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • codex-package-aarch64-unknown-linux-gnu.tar.gz and codex-package-x86_64-unknown-linux-gnu.tar.gz: the same four binaries plus bin/bwrap; Linux is GNU/glibc, not musl.
  • codex-package-x86_64-pc-windows-msvc.zip: .exe versions of the four binaries plus codex-command-runner.exe and codex-windows-sandbox-setup.exe.

Downloaded workflow artifacts matched their GitHub sizes and SHA256 digests, and their outer ZIP CRC checks passed. Inner archive integrity, exact binary layout, ELF/Mach-O/PE architecture, and Unix 0755 permissions passed. The downloaded Linux x86_64 CLI reported codex-cli 0.160.0; TestRealAppServerInitializeStrictDigest -count=1 passed in 0.231 s with the real downloaded runtime required, isolated/mock homes, and no compatibility override. No real OAuth login or paid provider call was used. Optional native voice/audio resources and provisioned Windows sandbox-service packaging remain outside this bin-only layout.

Archive sizes and SHA256 (these describe the downloadable packages, not the enclosing workflow artifact ZIPs):

  • codex-package-aarch64-apple-darwin.tar.gz: 199,280,891 bytes; 817cc9d837e4df6c3f0252f04114f1d52589a6bef21b217e43632521033d9df8.
  • codex-package-aarch64-unknown-linux-gnu.tar.gz: 206,294,385 bytes; 5076f696b6a737f54d41d1ce13ea073100929cc4a5b515607e8547afce7db5b6.
  • codex-package-x86_64-apple-darwin.tar.gz: 212,538,780 bytes; 00310d3de032dc15a58f568dbfe898d38f56c5d68bfba1888b954e06f6a1b606.
  • codex-package-x86_64-pc-windows-msvc.zip: 230,645,735 bytes; e83b22ff04132898d9e53c50f9a945fbffbde043620abe6a539ea34fe6899ce3.
  • codex-package-x86_64-unknown-linux-gnu.tar.gz: 219,507,103 bytes; 6c23fb5abd32609f8a82d574674d85f5d6da75ae089937eae3ce5c7c10da540f.

Upgrade note: replacing binaries on disk does not update or restart an already-running app-server/daemon. An older process can still cause configuration or strict protocol-handshake errors. Restart the daemon yourself if appropriate, or use --no-daemon; this release never changes a running process or installed CLI on its own.

Validation and limitations

  • Rebase accounting and preservation checks passed: 146/146 fork commits retained, 105 patch-identical, 41 adapted, 0 dropped, with the pinned base as ancestor and protected user files unchanged.
  • Adjacent selected Rust tests: 2,515 total, initially 2,510 passed, 5 failed, and 9 skipped. Both capacity failures were repaired and their existing checks passed; all three rmcp remote failures were closed after a fresh CLI/exec-server helper and passed. One intrinsic flaky retry was not treated as a source failure. The complete adjacent suite was not rerun as one final pass.
  • just test -p codex-app-server-protocol: 356 passed, 1 skipped. Stable/experimental schema and precomputed generation, Rust Go-manifest check, and Go generator checks in stable, experimental, and combined modes passed.
  • Go SDK: go test -race ./... passed with 602 tests across 14 packages, without inherited runtime-path/required-real-runtime environment variables.
  • Core/Code Mode targeted behavior selection: all 226 selected behaviors are green after eight targeted repairs. Targeted app-server checks passed 20 cases. R1/R2 closure added the 14-test combined check and a fresh isolated strict SDK handshake (0.276 s, required runtime, no compatibility override). Scoped fix/clippy/format checks passed; these selections overlap and are not summed as unique coverage.
  • Version-only stamp, exact-lease push, all five release build jobs, downloaded artifact/archive checks, and the fresh packaged-runtime strict digest handshake passed. Runtime and SDK tags point to the same exact source; no existing release tag was moved.
  • Full Rust core, workspace, app-server, platform-wide, Docker/Wine, and official-release test suites were not run. Focused checks are not full-suite or all-platform coverage. No result from the previous 0.159.0 release is counted as verification of this candidate.

Source and full upstream changelog

All 229 upstream non-merge commits since the previous pinned base