[pull] main from openai:main - #48
Merged
Merged
Conversation
## Why Copying executable fixtures in the test process can expose writable file descriptors to sibling spawns. The shared `copy_executable` helper completes copies in a separate process on Linux before launching the fixtures. ## What changed Use `copy_executable` for both `codex-linux-sandbox` and `bwrap` in `bazel_build_rejects_tampered_bundled_bwrap`, and add `codex-utils-cargo-bin` as a Linux test dependency. GitOrigin-RevId: 05fb1381eeefb64568b525925c9e81863acc2b54
## Why Missing retained root instructions could indefinitely block a worker's matching low-risk cached score from approving an action. ## What changed Require complete retained local context for cached approvals, while allowing incomplete root context when the cached score matches the current authorization. Root omissions remain visible to the classifier. ## Testing Extend the cached-delivery regression test to verify that a worker with complete local context and an `IncompleteRootInstructions` marker can approve using a matching low-risk cached score. GitOrigin-RevId: 06feda47fe47feb933c67239d32bf154b2032615
## Why Configuration reloads must honor current managed restrictions without granting new enterprise MCP authority to existing sessions or overwriting newer configuration with stale snapshots. ## What changed - Allow enterprise managed authentication only for configured MCP servers. Remove plugin `ema_auth` overlays from the schema and disable servers that still use them. - Refresh ordinary MCP settings while preserving session settings and initially admitted enterprise registrations. Disable enterprise MCP when its registration changes, policy revokes access, or configuration loading or resolution fails; require a new session to restore enterprise authority. - Publish refreshes only when their captured configuration is still current, with bounded retries in app-server reloads. Preserve updated managed restrictions even when a refresh is rejected. - Finish processing other thread refreshes before `config/mcpServer/reload` reports a rejection, and document that an error can accompany partially applied changes. ## Testing Add regression coverage for stale refreshes, bounded retries, managed-policy revocation, persistent enterprise disablement, ordinary MCP transport changes, and rejection of plugin enterprise authentication. Verify that denied enterprise servers receive no requests. GitOrigin-RevId: 34429cd339c1ec152a2ee8697cb29f0cff5d9e5f
## Why Restoring the error mode with `SetErrorMode` can overwrite the failure code from `CreateProcessWithLogonW`, causing `RunnerLogonError` to report the wrong error. ## What changed Capture `GetLastError()` immediately after a failed runner launch, before restoring the previous error mode, and use the saved code for `RunnerLogonError`. GitOrigin-RevId: c0f4267232306be4d06e7e8accd60f7b77b8d6f3
## Why Steering and recovery requests can have different traces from the turn they join. Sampling can also finish while tools remain in flight. Tracing needs to preserve that correlation and distinguish sampling time from time spent waiting for tools. ## What changed - Add `codex.turn_input` spans with `conversation.id` and the accepted `turn.id` for started, steered, and recovered turns. - Add sampling, tool-blocking, and automatic and manual compaction spans with `codex.turn.phase` and conversation and turn IDs. End the sampling span before draining outstanding tools. - Emit a `codex.mailbox_preemption` event when pending mailbox input preempts sampling. ## Testing Add integration coverage for cross-trace steering and recovery, sampling and tool-blocking boundaries through a blocked dynamic tool, and completion or interruption. Extend mailbox preemption tests to check event emission with preemption enabled or deferred. GitOrigin-RevId: 59893c2d463c02cbd05f5c332e5afc2351cc8b62
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )