Skip to content

Codex fork 0.162.0

Latest

Choose a tag to compare

@Dirard Dirard released this 09 Oct 01:26

Codex fork 0.162.0

This main-based fork release follows fork 0.160.0. It is not a byte-for-byte rebuild of OpenAI's official 0.162.0 release. It includes the preserved fork runtime, matching Go SDK, and five verified platform packages.

Comparison and source

  • Previous fork runtime and SDK source: 54fc12f7aa, published as 0.160.0.
  • Previous pinned base: 2cf9b0875a. New pinned local merge base: 5a2a6eacc62e897edcf7aa2d4d544100aefffc3f, combining observed origin/main@2af3fe862d with OpenAI main@515c291d87. The local merge retains this fork's release-workflow customization; it does not change OpenAI main.
  • Official OpenAI 0.162.0 was published 2026-10-08 at 18:55:59 UTC. Its tag object is 1f3f93473394b620b35580859b7e6864f7a9f948, peeling to c1382380de. This fork follows the pinned main-based history, not that official release branch.
  • Reviewed semantic source: cc065ef0a4. Independent product and engineering review found no blocking or non-blocking findings. Version-stamped 0.162.0 source: 045ae853a9, pushed with an exact lease. The single pinned five-target build was dispatched on 2026-10-08 at 22:49:29 UTC and all five jobs succeeded by 2026-10-09 at 01:14:27 UTC. Matching annotated rust-v0.162.0 and sdk/go/v0.162.0 tags both point to this exact release source.

The upstream section below covers all 220 non-merge commits between the pinned bases in git log order, not every change on OpenAI's official 0.162.0 release branch. Exact commit links follow at the end.

Upstream changes since fork 0.160.0

Agents, context, and history

  • Agent state and capabilities survive more idle-unload, navigation, and fork scenarios; shutdown failures have bounded diagnostics. Upstream removes partial-history subagent forks. fork_turns now advertises all or none; numeric strings are legacy aliases for full history, not a last-N-turns mode.
  • Turn lineage is exposed and persisted across app-server turns, queued mail, recovery, compaction, and host-owned Apps calls. Subagent activity records resolved model and reasoning effort; partial assistant answers gain a message phase and consistent handling in agent workflows, realtime routing, and thread search.
  • Compaction replacement history installs full captured context. Context parts gain source attribution, Guardian sender context can be recovered from persistence, and tool-call metadata preserves completeness even when large recorded arguments are truncated. Fork-specific raw replay, originating truncation, compaction headroom, and cache behavior were reconciled with this full-context format.

Code Mode, MCP, app-server, and security

  • JavaScript Code Mode gains ranked discovery, description-first ordering, promise settlement streaming helpers, default interruption, and gRPC session recovery. Incremental tool updates distinguish namespace removals and preserve base-instruction history.
  • Guardian gains opt-in trust for orchestrator connector identities, concurrent conversation classification with ordered actions, checkpoint recovery, retained sender context, stricter assessment parsing, and issuing-step context for MCP elicitation reviews. MCP and environment handling adds required-skill checks, selected-environment context, verified sandbox-launcher exposure, and clearer verification failures.
  • App-server protocol additions include thread/list.excludedThreadIds, turn parentTurnId/rootTurnId lineage, subagent model/effort, independent Fast/Ultra Fast requirements, browser-extension request headers, environment WebSocket request IDs and required skills, and an opaque misalignment review target. Experimental prediction forks can inherit parent context; that is opt-in protocol behavior, not a default fork mode.
  • Application network policy is enforced for daemon updates and standalone MCP commands; proxy DNS checks authorize hostnames first. Sandbox integrity checks, MXC policy/SDK updates, and Windows sandbox fixes also landed. These upstream security controls must not be weakened during fork reconciliation.

Terminal UI, daemon, platform, and build

  • TUI updates include clickable wrapped links, side-conversation persistence, task pinning and model/effort details, safer config reloads, Daybreak API-key gating, and iTerm2 lifecycle/foreground status. Windows Terminal Shift+Enter, installer, sandbox, and daemon publication paths received fixes.
  • Upstream removes the patched zsh execution backend and stops bundling patched zsh. This fork does not restore or package that removed backend. Bazel release-building support and source-package stripping were added upstream; this fork's planned downloadable layout remains the five bin-only system archives below.

Fork reconciliation and Go SDK

All 150 fork commits were replayed: 93 patch-identical, 57 adapted, 0 dropped or unmatched. The frozen semantic candidate passed independent review. Preserved fork behavior includes independent direct-MCP/Code-Mode line and originating output limits; raw rollout replay; custom providers/context overrides; plaintext provider messages; inherited dynamic tools for fresh V1/V2 children; cumulative spawn budgets, follow-ups, quiet waits and parent completion; Guardian isolation; bounded compaction history and capacity retry floors. The loaded-agent budget repair prevents repeated resume/load paths from resetting the current turn's cumulative spawn budget; cold-load seeding and new-turn budgets remain. Existing shared ThreadManager inheritance covers both fresh and forked children without an additional production-side tool-copy path. Bash snapshot replay now explicitly suppresses repeated .bashrc loading without changing capture, login fallback, or sandbox policy. Partial-history fork_turns is intentionally excluded because upstream removed it.

Rust stable/experimental schemas, precomputed exports, serde manifest, and generated Go protocol were regenerated and checked. Six runtime initialize digest constants were refreshed after the protocol regression test detected the stale snapshot. Both the fresh semantic-candidate and final downloaded-release strict handshakes passed. Go SDK changes are:

  • Generated raw fields for thread exclusions, turn parent/root IDs, subagent model/effort, config speed/browser requirements, environment skills/WebSocket request ID, and misalignment review target. The existing high-level TurnOptions maps ParentTurnID and RootTurnID; the experimental fork prediction field remains raw-only.
  • Go source compatibility change: protocol.SkillMetadata.Path and protocol.SkillSummary.Path change from AbsolutePathBuf to LegacyAppPathString (the latter remains optional in SkillSummary). Both still use a JSON string on the wire; Go callers assigning the old named type may need an explicit conversion.
  • Existing typed ThreadItemsListCursor, opt-in BackendReasoningStatus, unknown CodexErrorInfo passthrough, MCP OAuth loginId correlation with legacy fallback, explicit goal provenance, strict initialize digest/mode validation, and module path github.com/openai/codex/sdk/go are retained. The protocol and Go checks below passed.

RequestHeader.Value can contain sensitive data. Do not print real values in logs, tests, or issue reports.

Use the runtime and Go SDK from this same 0.162.0 source. Strict protocol digest validation is not implicitly bypassed. Replace the entire binary package, including codex-code-mode-host; do not mix a new CLI with an old app-server or daemon.

Downloadable packages

The release has exactly five bin-only system archives. All five pinned builds, exact runner checkouts, package-layout assertions, codex-cli 0.162.0 runner smokes, and downloaded archive checks passed:

  • codex-package-aarch64-apple-darwin.tar.gz and codex-package-x86_64-apple-darwin.tar.gz: bin/codex, codex-app-server, codex-code-mode-host, codex-responses-api-proxy.
  • codex-package-aarch64-unknown-linux-gnu.tar.gz and codex-package-x86_64-unknown-linux-gnu.tar.gz: the same four binaries plus bin/bwrap; GNU/glibc, not musl.
  • codex-package-x86_64-pc-windows-msvc.zip: .exe versions of the four binaries plus codex-command-runner.exe and codex-windows-sandbox-setup.exe.

Optional voice/audio resources, patched zsh, musl builds, individual archives, and provisioned Windows sandbox-service packaging are not part of this bin-only layout. Verified release archive sizes and SHA256 digests (these are the downloadable packages, not the outer Actions artifact ZIPs):

  • codex-package-aarch64-apple-darwin.tar.gz: 200774406 bytes; SHA256 3dff7c3079d48a087e69972079589031805ec60ced622d2ec4df5e3e7b71dd5a.
  • codex-package-aarch64-unknown-linux-gnu.tar.gz: 207930934 bytes; SHA256 79c524a1a391f3cd31d8e63692ed81459c2af1ece84a475cf2d3bc8b0c1b6096.
  • codex-package-x86_64-apple-darwin.tar.gz: 214091102 bytes; SHA256 353df0f7733a5bfbec4e061a5ddbdf24ca7786ece77ef45f0f7f9f65a1b2896a.
  • codex-package-x86_64-pc-windows-msvc.zip: 232609682 bytes; SHA256 634df8cf14962c7b07d8943a5bca9523aeaca39017d9c3b99fb23800737862cb.
  • codex-package-x86_64-unknown-linux-gnu.tar.gz: 221186599 bytes; SHA256 af26b4f37fc3c0860e9b783f70967219490006493ce572a520be518f7808161c.

Upgrade note: replacing binaries on disk does not update or restart an already-running app-server/daemon. An older process can still cause configuration or strict protocol-handshake errors. Restart the daemon yourself if appropriate, or use --no-daemon; this release does not modify a running process or installed CLI on its own.

Validation and limitations

  • Rebase accounting and preservation checks passed: all 150 fork commits retained, 93 patch-identical and 57 adapted; 297 protected user files unchanged. All 1,307 external Cargo package records match the pinned base. The version stamp changes only the workspace version and 160 local lockfile package versions to 0.162.0; all other parsed Cargo fields remain unchanged. The independent reviewer did not author or repair the candidate.
  • Nine adjacent Rust crates passed 1,493 tests, with 9 skipped. Three remote RMCP cases subsequently passed with a fresh helper in the second selected batch. GitHub scripts passed 80 tests. Bazel lock synchronization passed without lockfile drift; config-schema generation had no semantic change.
  • Rust app-server-protocol passed 357 tests, with 1 skipped, after the stale initialize digest snapshot was corrected. Stable/experimental schema and precomputed generation, manifest drift check, Go generator checks in stable/experimental/combined modes, and full Go -race passed. Conditional real-runtime Go tests were not enabled in that broad SDK run; the strict real-runtime check is separate below.
  • The targeted core/Code Mode run selected 347 cases: 336 initially passed; all 11 failures were closed by targeted reruns after budget, mock-host, and nine reviewed snapshot updates. Five fresh/fork inheritance cases also passed. Full Code Mode crates were included; the full core suite was not run. Scoped lint fixes/checks passed for five changed crates, followed by repository formatting, diff checks, and protected-file checksums.
  • The second selected batch ran 1,056 tests: 1,044 passed initially, including targeted app-server consumers and remote RMCP. Seven daemon failures were stale initialize-response fixtures and passed after the shared mock was updated. One Bash snapshot replay failure was fixed by suppressing repeated RC startup only on replay; the original case and a deterministic SSH startup regression passed with existing sandbox and output assertions retained. The adjacent snapshot run reported 20 passes; successful-test output was not retained, so execution beyond the skip guards of two protected-transport cases was not independently confirmed.
  • Four upstream exec-server cases remain host-limited, not passing: three remote fallback cases return the correct output/status but fail empty-stderr assertions because this host's im-config login hook invokes systemd-cat under restricted networking; an isolated clean-profile rerun could not exercise them because nested user namespaces were unavailable. A fourth test's deny of symlinked /dev/fd fails closed during bubblewrap mount setup. Sandbox policy, test assertions, and host startup files were not weakened or changed to hide these limitations.
  • Fresh semantic-candidate CLI/helper build and isolated codex-cli 0.160.0 smoke passed before the release-only version stamp. After the Bash repair, the refreshed build passed in 30.25s and required-real-runtime TestRealAppServerInitializeStrictDigest -count=1 passed in 0.277s. The downloaded Linux x86_64 release reports codex-cli 0.162.0 and passed that same required strict test in 0.216s, using isolated/mock homes and no compatibility override.
  • All five builds and exact source checkouts passed. Downloaded outer artifact ZIP sizes/SHA256/CRC, inner gzip/ZIP integrity, exact bin-only layout, ELF64/Mach-O 64/PE32+ architecture for all 24 binaries, and Unix 0755 permissions passed. Archive checks do not claim full cross-platform functional test coverage.
  • Full Rust core, workspace, app-server, platform-wide, Docker/Wine, and official-release suites were not run. Results from 0.160.0 are not evidence for this candidate. No real OAuth login or paid provider call was made.

Source and full upstream changelog

All 220 upstream non-merge commits since the previous pinned base