Skip to content

[pull] main from openai:main - #48

Merged
pull[bot] merged 5 commits into
bfloat16:mainfrom
openai:main
Sep 29, 2026
Merged

pull[bot] merged 5 commits into
bfloat16:mainfrom
openai:main

Conversation

@pull

@pull pull Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

felixxia-oai and others added 5 commits September 29, 2026 11:51
## Why

Copying executable fixtures in the test process can expose writable file descriptors to sibling spawns. The shared `copy_executable` helper completes copies in a separate process on Linux before launching the fixtures.

## What changed

Use `copy_executable` for both `codex-linux-sandbox` and `bwrap` in `bazel_build_rejects_tampered_bundled_bwrap`, and add `codex-utils-cargo-bin` as a Linux test dependency.

GitOrigin-RevId: 05fb1381eeefb64568b525925c9e81863acc2b54
## Why

Missing retained root instructions could indefinitely block a worker's matching low-risk cached score from approving an action.

## What changed

Require complete retained local context for cached approvals, while allowing incomplete root context when the cached score matches the current authorization. Root omissions remain visible to the classifier.

## Testing

Extend the cached-delivery regression test to verify that a worker with complete local context and an `IncompleteRootInstructions` marker can approve using a matching low-risk cached score.

GitOrigin-RevId: 06feda47fe47feb933c67239d32bf154b2032615
## Why

Configuration reloads must honor current managed restrictions without granting new enterprise MCP authority to existing sessions or overwriting newer configuration with stale snapshots.

## What changed

- Allow enterprise managed authentication only for configured MCP servers. Remove plugin `ema_auth` overlays from the schema and disable servers that still use them.
- Refresh ordinary MCP settings while preserving session settings and initially admitted enterprise registrations. Disable enterprise MCP when its registration changes, policy revokes access, or configuration loading or resolution fails; require a new session to restore enterprise authority.
- Publish refreshes only when their captured configuration is still current, with bounded retries in app-server reloads. Preserve updated managed restrictions even when a refresh is rejected.
- Finish processing other thread refreshes before `config/mcpServer/reload` reports a rejection, and document that an error can accompany partially applied changes.

## Testing

Add regression coverage for stale refreshes, bounded retries, managed-policy revocation, persistent enterprise disablement, ordinary MCP transport changes, and rejection of plugin enterprise authentication. Verify that denied enterprise servers receive no requests.

GitOrigin-RevId: 34429cd339c1ec152a2ee8697cb29f0cff5d9e5f
## Why

Restoring the error mode with `SetErrorMode` can overwrite the failure code from `CreateProcessWithLogonW`, causing `RunnerLogonError` to report the wrong error.

## What changed

Capture `GetLastError()` immediately after a failed runner launch, before restoring the previous error mode, and use the saved code for `RunnerLogonError`.

GitOrigin-RevId: c0f4267232306be4d06e7e8accd60f7b77b8d6f3
## Why

Steering and recovery requests can have different traces from the turn they join. Sampling can also finish while tools remain in flight. Tracing needs to preserve that correlation and distinguish sampling time from time spent waiting for tools.

## What changed

- Add `codex.turn_input` spans with `conversation.id` and the accepted `turn.id` for started, steered, and recovered turns.
- Add sampling, tool-blocking, and automatic and manual compaction spans with `codex.turn.phase` and conversation and turn IDs. End the sampling span before draining outstanding tools.
- Emit a `codex.mailbox_preemption` event when pending mailbox input preempts sampling.

## Testing

Add integration coverage for cross-trace steering and recovery, sampling and tool-blocking boundaries through a blocked dynamic tool, and completion or interruption. Extend mailbox preemption tests to check event emission with preemption enabled or deferred.

GitOrigin-RevId: 59893c2d463c02cbd05f5c332e5afc2351cc8b62
@pull pull Bot locked and limited conversation to collaborators Sep 29, 2026
@pull pull Bot added the ⤵️ pull label Sep 29, 2026
@pull
pull Bot merged commit a7660cd into bfloat16:main Sep 29, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants