Skip to content

v0.3.0

Latest

Choose a tag to compare

@parisbs parisbs released this 18 Sep 01:32
· 4 commits to main since this release
fce7a63

Defaults that survive a fresh install, and results that mean what they say. Most of this came from spending a day measuring real delegations against the installed CLI: three places were asking Codex a question in the wrong directory, and two numbers in every result meant something other than what they looked like.

Upgrade notes

This is a minor release with breaking changes:

  • The sandbox ceiling now defaults to workspace-write. An unconfigured server used to let a call request danger-full-access, which removes the sandbox entirely, network included. Set CODEX_SUBAGENT_MAX_SANDBOX=danger-full-access if you need it.
  • The token line in a result changed shape, separating tokens this turn from tokens thread so far. A follow-up used to report the thread's running total as that call's cost.
  • working_dir: "" is refused instead of falling back to the server's own directory.

Highlights

  • A result now tells you what Codex actually applied, not only what was requested: the metadata line ends with applied=confirmed, differs or unconfirmed, and a sandbox recorded as wider than the one requested fails the delegation.
  • New CODEX_SUBAGENT_DEFAULT_SANDBOX, so someone who delegates edits all day sets it once instead of repeating sandbox: "workspace-write" on every call. read-only stays the built-in default.
  • The recursion guard, the preflight, the model catalog and codex_recommend all run in the delegation's working directory. Codex resolves configuration against the directory it runs in, so each of them was answering about somewhere else — and for the recursion guard, that was the one place a repository could have registered this server.
  • A thread survives a restart. A follow-up on a thread this server has no record of recovers the model, effort and directory from Codex's own session file, validated through the usual policy.
  • A read-only run is told what it cannot verify, after a measured run reported 80 failing tests that were sandbox artefacts, and that its shell has no network while the web-search tool works.
  • Results report the true command count, the effective working directory and uncached input.
  • Writing a delegation: what a delegation costs and how to shape one, measured rather than guessed — including an explicit list of what target_files, working_dir and read-only do not mean.
  • Releases are built and staged by GitHub Actions with npm provenance through trusted publishing, and reach users only when a maintainer approves the staged release with two-factor authentication.

codex_review was planned for this release and dropped after measurement: wrapping codex exec review cost more than a plain delegation on the same commit, found less, hides its usage in a subagent thread, and has no sandbox flag. The issue stays open with the numbers attached.

Verified against

  • Codex CLI 0.154.0 on macOS.
  • Release smoke test (real CLI, gpt-5.6-luna): 23 of 23 checks passed — preflight, catalog, recommendation, five refusals including the new ceiling and empty-directory ones, a read-only delegation with applied-settings confirmation, effort clamping, a follow-up that restated its model and separated this turn's tokens from the thread total, prompt-injection inertness, and a background job.
  • Build, tests and startup on Linux (Node 22, 24, 26), Windows (Node 22, 24) and macOS (Node 24). A real delegation has still never been run on Windows or Linux.

Full details in the changelog.