test: harden release compatibility contracts - #4297
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5026567c1b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 38dab9dcbd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ab031791bf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
ab03179 to
4bc5628
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4bc56281df
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1d03a15897
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f8f4f62633
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
f8f4f62 to
a6557fb
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a6557fbfba
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
a6557fb to
6e8c024
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6e8c024c31
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
6e8c024 to
6006cf4
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6006cf4631
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 04b775e0d0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3472d0f50a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
3472d0f to
0c1bcfd
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0c1bcfdaea
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
0c1bcfd to
861cdca
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 861cdca6fb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
861cdca to
d5126e3
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d5126e33b9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
d5126e3 to
be58ead
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: be58ead641
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
be58ead to
93b82d2
Compare
There was a problem hiding this comment.
💡 Codex Review
openai-agents-python/src/agents/sandbox/entries/mounts/patterns.py
Lines 125 to 131 in 93b82d2
When one mount credential is a prefix of another, this replacement order can expose the longer value's suffix in a provider error. For example, redacting "abcdef" with the normal environment order ['abc', 'abcdef'] produces "REDACTEDdef"; MountpointMountPattern.apply() supplies access key, secret key, and session token in that order before applying this helper to stderr. Deduplicate and redact values longest-first so overlapping credentials cannot be partially retained in diagnostics.
AGENTS.md reference: AGENTS.md:L103-L103
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
93b82d2 to
8b43db7
Compare
This pull request adds a layered release-hardening system for v0.20.0. It expands the fast unit suite, verifies the actual wheel and source distribution, exercises historical
RunStatecompatibility, compares streaming and non-streaming semantics, and adds adversarial checks around sandbox credentials and persisted state.The goal is to catch compatibility, packaging, lifecycle, and credential-containment regressions at the boundary where they matter, while keeping the normal
tests/suite deterministic and fast.Public API compatibility contracts
This gives future releases an explicit compatibility baseline. Newly released APIs can be added during local release preparation, while previously released behavior remains protected.
Historical
RunStatecompatibility corpusmax_turns=None.Runner, covering both approval and rejection without duplicate tool execution or session history.This protects resume behavior against actual historical payloads and detects silent data loss that a current-writer-only round trip would miss.
Streaming and non-streaming symmetry
RunResultandRunResultStreaming.This prevents streaming and non-streaming execution paths from drifting in billing, persistence, approval, error, or tracing behavior.
Packaged, release, nightly, and security profiles
site-packages, not the repository checkout.This separates fast pull-request feedback from slower artifact, provider, and sandbox verification while ensuring strict release gates cannot become false-green through skips or malformed reports.
Sandbox credential and error hardening
RunState.CancelledError,KeyboardInterrupt, andSystemExitinstances.This verifies credential containment at public runtime, persistence, packaging, and sandbox boundaries instead of relying only on sanitized error messages.
Compatibility considerations
No new runtime public symbols are introduced.
The
RunStaterestoration path now validates exact built-in serialized structures without invoking caller-defined mapping behavior. An exact baseRunContextWrapperreturned bycontext_overrideorcontext_deserializerremains supported and preserves its identity and restored state.RunContextWrappersubclasses are rejected before their custom descriptors or private hooks can run; callers can return the custom context value directly or use the exact base wrapper.Credential-bearing historical sandbox state remains readable, but authority is removed during migration and must be rebound by trusted application code before the sandbox can resume.
Release workflow
The released API manifest remains a local release-preparation operation:
The update command first verifies the existing released contract, then adds compatible APIs from the final candidate. After rebasing the release branch, rerun the check command to ensure the committed manifest still matches the candidate.
The primary verification entry points are:
The exact release candidate can then be verified with: