Conversation
…s object
Codex auto-discovers a plugin's hooks/hooks.json whenever the Codex
manifest has no `hooks` field: load_plugin_hooks falls back to a
hardcoded DEFAULT_HOOKS_CONFIG_FILE = "hooks/hooks.json" and registers
it. hooks/hooks.json is the Claude Code SessionStart hook, it is tracked
in this repo, and the Codex marketplace installs the whole repo root
(source url "./"), so the fallback re-registered the SessionStart hook
and its install-time trust prompt on Codex.
Removing the Codex hook file and the manifest `hooks` pointer (commit
"Remove Codex hooks") did not disable the hook on Codex — it removed the
explicit declaration that was overriding the fallback, so the fallback
took over and found the Claude hooks/hooks.json.
Declare an empty inline hooks object ({}) in .codex-plugin/plugin.json.
It parses as an empty inline hook set and stops Codex reaching the
auto-discovery fallback. An absent field, an empty array ([]), and an
empty inline list all collapse back to the fallback, so the value must
be exactly {}.
Update the test to assert the manifest declares hooks: {} (and that
hooks/hooks.json exists, which is what makes the declaration necessary),
replacing the prior assertion that the field was absent — which passed
while the hook was still being auto-discovered.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… docs hooks/session-start-codex has had no caller since "Remove Codex hooks" (#1845) deleted hooks-codex.json and its manifest registration; the Codex manifest now declares an empty hooks object so Codex registers no session-start hook at all. The script is Codex-specific dead code — nothing executes it on Codex or any other harness. - Delete hooks/session-start-codex. - tests/hooks/test-session-start.sh: drop the two Codex cases that are redundant with the generic session-start tests (nested-format and the legacy-warning omission are already covered by the Claude Code cases). Re-point the "wrapper dispatches" case to the live `session-start` script so run-hook.cmd dispatch coverage — used by Claude Code and Cursor in production — is preserved rather than lost. - docs/porting-to-a-new-harness.md: Codex is no longer a Shape A (shell-hook) harness, so re-anchor that worked example to Cursor (a live shell-hook harness that demonstrates the same per-harness field, schema, and matcher variance) and mark Codex as native skill discovery with no session-start hook. Clears the references to the deleted hooks-codex.json. - docs/windows/polyglot-hooks.md: the "check hooks-codex.json" pointer referenced a file deleted in #1845; re-point to hooks-cursor.json. RELEASE-NOTES.md keeps its historical mention of hooks-codex.json (it accurately records what that release did). The tests/codex-plugin-sync fixtures build their own synthetic session-start-codex and test the sync mechanism generically, so they are intentionally left as-is. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…x portal packaging
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Who is submitting this PR? (required)
claude-opus-4-8)What problem are you trying to solve?
This is the v6.1.1 release of the accumulated Codex work since v6.1.0. The headline problem it fixes is a real, user-visible regression that shipped in v6.1.0:
v6.1.0's release notes said "Codex no longer ships a SessionStart hook." That was wrong in practice. Removing the Codex hook config and the manifest
hookspointer meant the Codex manifest had nohooksfield — and Codex's plugin loader treats an absenthooksfield as "auto-discover," falling back to a hardcodedhooks/hooks.json. That file is the Claude Code SessionStart hook, tracked in the repo, and the Codex marketplace installs the whole repo root. So v6.1.0 actually caused Codex to re-register the Claude SessionStart hook and its install-time trust prompt — the opposite of what the notes claimed.This was found while building Codex "portal" packaging (a distributable zip/tar.gz of the Codex plugin); the packaging surfaced the same manifest-hooks question and led to the root-cause diagnosis above.
What does this PR change?
Declares an explicit empty
hooks: {}object in.codex-plugin/plugin.jsonso Codex parses it as "no hooks" instead of hitting the auto-discovery fallback; removes the now-orphanedhooks/session-start-codexdead code and re-anchors the affected docs; and addsscripts/package-codex-plugin.sh(a deterministic Codex portal packaging script) plus its test suite. Version bumped to 6.1.1 across all seven manifests.Is this change appropriate for the core library?
Yes. It fixes correctness of the Codex integration that ships in core (the SessionStart-hook regression affects every Codex user) and adds maintainer tooling for the core repo's own Codex distribution. It integrates no third-party service and is not project- or domain-specific.
What alternatives did you consider?
[]or empty inline list instead of{}— rejected: all of[], an empty inline list, and an absent field collapse back to Codex's auto-discovery fallback. Only an inline empty object{}suppresses it. This is asserted in the test.hooks/hooks.json— rejected: that file is the live Claude Code / Cursor SessionStart hook. The fix has to suppress Codex's fallback without touching the hook other harnesses depend on.hooksfrom the packaged portal manifest — tried, then reverted: the packaged manifest must keep thehooks: {}object, or a portal-installed Codex plugin hits the exact same auto-discovery bug.Does this PR contain multiple unrelated changes?
No. Every change is Codex hook-correctness or Codex packaging — one coherent theme. As a release-integration PR it bundles the nine commits that landed on
devsince v6.1.0, but they are all part of the same Codex packaging/hook-correctness effort.Existing PRs
devwork, not a new external contribution.Environment tested
Test method: the repo's shell test suites, run on macOS (darwin 25.2.0).
Evaluation
This is a release PR, not a skill/behavior change, so the verification is the test suites rather than agent evals. On the
release-v6.1.1branch, all release-relevant suites pass:tests/codex/test-package-codex-plugin.sh— PASS (24 assertions: archive determinism, executable modes, OpenAI metadata, icons, dirty-worktree guard, metadata-source reproducibility,hooks: {}preserved)tests/codex/test-marketplace-manifest.sh— PASStests/hooks/test-session-start.sh— PASStests/codex-plugin-sync/test-sync-to-codex-plugin.sh— PASStests/shell-lint/test-lint-shell.sh— PASS;package-codex-plugin.shand all touched shell files are shellcheck-cleanRigor
writing-skills/ adversarial-eval requirement applies.package-codex-plugin.shbehavior is tested beyond the happy path (rejects dirty worktrees, rejects incomplete metadata sources, verifies archive reproducibility).Human review