Defaults that survive a fresh install, and results that mean what they say. Most of this came from spending a day measuring real delegations against the installed CLI: three places were asking Codex a question in the wrong directory, and two numbers in every result meant something other than what they looked like.
Upgrade notes
This is a minor release with breaking changes:
- The sandbox ceiling now defaults to
workspace-write. An unconfigured server used to let a call requestdanger-full-access, which removes the sandbox entirely, network included. SetCODEX_SUBAGENT_MAX_SANDBOX=danger-full-accessif you need it. - The token line in a result changed shape, separating
tokens this turnfromtokens thread so far. A follow-up used to report the thread's running total as that call's cost. working_dir: ""is refused instead of falling back to the server's own directory.
Highlights
- A result now tells you what Codex actually applied, not only what was requested: the metadata line ends with
applied=confirmed,differsorunconfirmed, and a sandbox recorded as wider than the one requested fails the delegation. - New
CODEX_SUBAGENT_DEFAULT_SANDBOX, so someone who delegates edits all day sets it once instead of repeatingsandbox: "workspace-write"on every call.read-onlystays the built-in default. - The recursion guard, the preflight, the model catalog and
codex_recommendall run in the delegation's working directory. Codex resolves configuration against the directory it runs in, so each of them was answering about somewhere else — and for the recursion guard, that was the one place a repository could have registered this server. - A thread survives a restart. A follow-up on a thread this server has no record of recovers the model, effort and directory from Codex's own session file, validated through the usual policy.
- A read-only run is told what it cannot verify, after a measured run reported 80 failing tests that were sandbox artefacts, and that its shell has no network while the web-search tool works.
- Results report the true command count, the effective working directory and uncached input.
- Writing a delegation: what a delegation costs and how to shape one, measured rather than guessed — including an explicit list of what
target_files,working_dirandread-onlydo not mean. - Releases are built and staged by GitHub Actions with npm provenance through trusted publishing, and reach users only when a maintainer approves the staged release with two-factor authentication.
codex_review was planned for this release and dropped after measurement: wrapping codex exec review cost more than a plain delegation on the same commit, found less, hides its usage in a subagent thread, and has no sandbox flag. The issue stays open with the numbers attached.
Verified against
- Codex CLI 0.154.0 on macOS.
- Release smoke test (real CLI,
gpt-5.6-luna): 23 of 23 checks passed — preflight, catalog, recommendation, five refusals including the new ceiling and empty-directory ones, a read-only delegation with applied-settings confirmation, effort clamping, a follow-up that restated its model and separated this turn's tokens from the thread total, prompt-injection inertness, and a background job. - Build, tests and startup on Linux (Node 22, 24, 26), Windows (Node 22, 24) and macOS (Node 24). A real delegation has still never been run on Windows or Linux.
Full details in the changelog.