What feature would you like to see?
Please expose a lower-level hardened execution surface in @openai/codex-sdk, or first-class thread options that provide these equivalent controls before codex exec starts:
- ignore ambient user configuration and exec-policy rules, equivalent to
--ignore-user-config and --ignore-rules;
- bound each stdout JSONL record and retained stderr output, while reporting when bytes or records were discarded; and
- expose the spawned child/process-group lifecycle so an aborting automation host can terminate and await the complete descendant process tree.
The separate ephemeral-session gap is already tracked in #34760.
Config overrides and a controlled environment are useful but do not replace the first requirement: they cannot stop ambient files from being loaded before overrides apply. Likewise, an AbortSignal that kills only the direct child does not guarantee cleanup when tool commands have spawned descendants.
A possible API could be one of:
- explicit
ThreadOptions for the isolation flags plus bounded diagnostic callbacks and a process-tree-aware abort contract; or
- a documented low-level execution hook that receives the fully constructed invocation and child handle while the SDK continues to own protocol compatibility.
Why is this useful?
Long-running CI and agent-harness services need stronger guarantees than an interactive client:
- host config or approval rules must not silently change a supposedly pinned run;
- a hostile or accidental multi-megabyte JSONL/stderr record must not grow memory without limit;
- telemetry consumers must be able to mark results incomplete when stream data was dropped instead of guessing; and
- timeout, cancellation, and shutdown must not leave tool subprocesses running after the SDK call ends.
Without these hooks, automation either accepts weaker isolation/resource guarantees or maintains a parallel CLI/protocol/process wrapper. The SDK already covers typed events, output schemas, controlled environments, config overrides, and custom executable selection; these lifecycle controls are the remaining gap for adopting it as the sole invocation boundary.
Additional context
Re-evaluated against @openai/codex-sdk 0.145.0 on 2026-07-22. A migration contract can be validated with tests that assert ambient config/rules are bypassed, oversized diagnostic records are bounded and observable, and aborting the SDK invocation kills a spawned grandchild process.
What feature would you like to see?
Please expose a lower-level hardened execution surface in
@openai/codex-sdk, or first-class thread options that provide these equivalent controls beforecodex execstarts:--ignore-user-configand--ignore-rules;The separate ephemeral-session gap is already tracked in #34760.
Config overrides and a controlled environment are useful but do not replace the first requirement: they cannot stop ambient files from being loaded before overrides apply. Likewise, an
AbortSignalthat kills only the direct child does not guarantee cleanup when tool commands have spawned descendants.A possible API could be one of:
ThreadOptionsfor the isolation flags plus bounded diagnostic callbacks and a process-tree-aware abort contract; orWhy is this useful?
Long-running CI and agent-harness services need stronger guarantees than an interactive client:
Without these hooks, automation either accepts weaker isolation/resource guarantees or maintains a parallel CLI/protocol/process wrapper. The SDK already covers typed events, output schemas, controlled environments, config overrides, and custom executable selection; these lifecycle controls are the remaining gap for adopting it as the sole invocation boundary.
Additional context
Re-evaluated against
@openai/codex-sdk0.145.0 on 2026-07-22. A migration contract can be validated with tests that assert ambient config/rules are bypassed, oversized diagnostic records are bounded and observable, and aborting the SDK invocation kills a spawned grandchild process.