Skip to content

[pull] main from openai:main - #50

Merged
pull[bot] merged 24 commits into
bfloat16:mainfrom
openai:main
Sep 30, 2026
Merged

pull[bot] merged 24 commits into
bfloat16:mainfrom
openai:main

Conversation

@pull

@pull pull Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

viyatb-oai and others added 24 commits September 29, 2026 19:50
…49353)

## Why

Denied-read policies previously kept explicitly approved commands within their original filesystem restrictions, preventing operations that need broader write access, such as updating Git metadata.

## What changed

- Apply broader filesystem permissions after approval of explicit escalation while retaining the sandbox, denied reads, and network policy. Command allow rules alone do not widen filesystem access.
- Reject escalation when the required local sandbox is unavailable or a remote exec server lacks support for preserving the restrictions.
- Track escalated terminal access so subsequent `write_stdin` calls still require review when stdin approval is enabled.

## Testing

Add coverage for approved and denied escalation, allow rules, remote server compatibility, and stdin approval before input delivery. Add a Windows integration test verifying that an approved `git pull` updates Git metadata while exact-path and glob-based read denials remain enforced. Serialize Windows sandbox integration tests across processes to protect shared test account credentials.

GitOrigin-RevId: 5dce6d41487ee4d39bd795c8d086398ab9794d5b
## Why

Pasting multiple lines into a blockquote previously left subsequent lines unquoted.

## What changed

- Continue the current line's `> ` prefix across pasted lines, including blank and trailing lines, in the TUI composer and embedded answer fields.
- Append two unquoted newlines so typing resumes in the next Markdown block. Preserve quoting when large paste placeholders expand on submission.
- Use a shared edit target for paste context and insertion so selection replacement uses the prefix at the replacement start.
- Keep shell input and provisional startup pastes literal.

## Testing

Add unit tests and rendering snapshots for blockquote pastes, embedded answers, cursor placement, selection replacement, and large-paste expansion. Add textarea tests for forward and backward selections, adjacent elements, and Vim Replace backspace recovery.

GitOrigin-RevId: 525a7951aa16a25d49cc3be98822d0dd0709de97
…49360)

## What changed

- Carry the selected shell and login mode through unified exec using `ShellInvocation`. Use this metadata for shell snapshots and credential brokerage instead of inferring it from command arguments.
- Add `prependPathDirs` to exec-server environment metadata, populated from the executor's package PATH directory. Default to an empty list for older servers and omit empty lists from serialized output.

## Testing

Extend environment metadata round-trip coverage for `prependPathDirs` and the remote exec-server integration test to verify the packaged `codex-path` directory is reported.

GitOrigin-RevId: c571c068effcb305d196a701ad9a335ec7a3f5a2
…49361)

## Why

Credentials can use a keyring backend, so describing all login and logout operations as reads or writes to `auth.json` is misleading.

## What changed

- Remove the API-key onboarding claim that keys are stored in `auth.json`.
- Describe authentication storage and credential-removal errors in terms of stored credentials and the selected backend.
- Label the doctor output's auth-file path as the file backend or fallback, and document why startup checks also consider `config.toml` when credentials may be in a keyring.

## Testing

Add API-key entry snapshots for terminal widths of 80 and 40 columns.

GitOrigin-RevId: 87189f422448b88721ea2d7448930ece63102803
Update the runtime catalog test expectations for `global.openai.gpt-6-sol`
and `us.openai.gpt-6-sol` from `MultiAgentVersion::V1` to
`MultiAgentVersion::V2`.

GitOrigin-RevId: 1b038ab988cae221a641ee54002bffc25109f45c
## Why

Hook dispatch recompiles regex matchers for each input even though discovery already validates them.

## What changed

Store compiled `HookMatcher` values on configured handlers and reuse them during dispatch. Preserve match-all, exact-name, pipe-alternative, and regex matching semantics, along with the original pattern spelling for configuration equality. Invalid regexes continue to be rejected during discovery.

GitOrigin-RevId: 117a8a19c7bc0e55ccbedcd5940b806a17ebba10
## Why

Successful file fallback can hide a secure-store failure. Storage diagnostics need to distinguish that fallback from explicit file storage while keeping credential values out of error output.

## What changed

- Record credential load, save, delete, and fallback-file cleanup outcomes, including secure-store failures and fallback reasons.
- Preserve the initiating client's attribution across app-server requests, login tasks, sessions, turns, and blocking token persistence.
- Preserve storage error context and typed causes while redacting credential JSON data errors and payload-bearing keyring errors.
- Include sanitized fallback completion warnings in the default `codex login` file logs.

## Testing

Add coverage for storage policy and metric attribution, credential redaction, login diagnostics, concurrent app-server clients, device-code login, and token refresh during a turn.

GitOrigin-RevId: 6d5651c1718d184016fa77befa02aa528750b2ae
## Why

Opaque Windows paths encoded as UTF-16LE could be mistaken for POSIX paths when they began with `/`, or fail Windows convention inference when their leading separators mixed `/` and `\`. This prevented them from retaining the Windows path convention across URI serialization.

## What changed

Distinguish a UTF-16LE slash from a POSIX root and recognize either Windows separator in both positions of an opaque UNC prefix.

## Testing

Add round-trip coverage for Windows drive, UNC, device, and namespace paths, including forward and mixed separators. Cover JSON serialization, absolute-path joins, relative-path separator handling, and Windows-only host-native conversions.

GitOrigin-RevId: d4e8a40a314cfc030c30fa8c124bfdd1e565076d
## Why

Elevated sandbox tests share machine-local Windows accounts. Concurrent setup can rotate account passwords between another test's setup and logon.

## What changed

- Add a shared file-lock guard for elevated sandbox tests in `codex-core`, `codex-exec-server`, and `codex-windows-sandbox`, held through sandbox commands and cleanup.
- Queue these tests in a single-threaded Nextest group before their timeouts start, while retaining the file lock to coordinate other test processes.
- Limit account locking to tests that use elevated accounts and remove the sandbox crate's blanket Bazel `exclusive-if-local` tag.

GitOrigin-RevId: 26d4606cb1fdcac65926d29835bed4eac04c19c0
## What changed

- Instrument MCP OAuth loads, saves, deletes, fallback cleanup, and refresh persistence with credential-free storage metrics, distinguishing configured policy from operations on a pinned store.
- Retain the originating client across background tasks, blocking storage operations, and session recovery, including recovery after startup found no credentials.
- Preserve typed keyring and lock error categories for metrics and remove raw error details from storage warnings.

## Testing

Add tests for policy and pinned-store outcomes, best-effort cleanup failures, wrapped lock errors, and successful or failed refresh persistence without duplicate observations. Add recovery tests that verify client attribution after anonymous startup and across threads with different originators.

GitOrigin-RevId: 5ea4528bcdcf500c8ffdf1d9c7008ea52112c726
## What changed

Remove startup greeting phrases and the shared greeting state from startup drafts, session headers, and the empty-state animation. Raw session headers now consistently include `model:` and `directory:` fields.

## Testing

Update startup and fresh-thread snapshots to omit greetings, and adjust raw-header assertions to check model and directory fields.

GitOrigin-RevId: 531b5ba42d7a88f86b1c7f69030f3560abc25198
## Why

Persistence and aggregate metadata budgets can omit tool-call observations that are still relevant to the current request, including tool result metadata needed during compaction.

## What changed

- Retain live direct-call observations separately from bounded persisted outputs, keyed by response item ID so reused call IDs cannot mix results.
- Restore those observations for sampling and compaction, pruning them only when sampling confirms they have left the history window. Preserve observations across shortened compaction retries.
- Remove aggregate prompt metadata caps while retaining per-call argument limits and the outgoing message size limit. Invalidate cell completeness when argument normalization truncates a recorded call.

## Testing

Add regression coverage for exhausted persistence budgets, reused call IDs and reversed completion order, shortened compaction retries, and completeness after argument truncation. Extend integration coverage for large Code Mode metadata, provider metadata support, and fork/resume behavior.

GitOrigin-RevId: 004082b69bff9cc8b05f36d1052057f163c67f07
## What changed

Register `login_shell_package_path` as a disabled-by-default experimental feature and add it to the configuration schema. Expose it in `/experimental` as “Bundled tools in login shells,” with a description explaining its intended use when login shell startup resets `PATH`.

## Testing

Extend the experimental feature metadata snapshot test to cover the new feature's label, description, and unchecked default state.

GitOrigin-RevId: dc110486ccd8d2d76ac788ba5a413a1374699ff8
## What changed

Forward explicit `cyberAccessProgram` selections for the built-in OpenAI provider when both `api_key_cyber_access_programs` and `api_key_model_discovery` are enabled. The new feature defaults to disabled and can be toggled through the app server's experimental feature enablement API.

Reject explicit selections in OpenAI API-key sessions when either feature is disabled, instead of silently omitting the program. Leave entitlement and model restrictions to the server, and preserve the requested program when a server rejection triggers transport retries.

## Testing

Add app-server coverage for both feature gates, forwarding all three program values, and server rejection without fallback. Update core coverage for API-key resumes with disabled features and custom-provider omission.

GitOrigin-RevId: aa639afb841aa651b28f6f3f61198299372baa2d
## Why

A stuck transport can fill the outbound queue, leaving an `environment/info` request blocked while sending. The timeout must cover sending as well as waiting for a response.

## What changed

Wrap the live metadata RPC in a 30-second timeout. On timeout, close the probed connection and request session recovery, returning the timeout error without retrying the failed request. Document the experimental `environment/info` endpoint and its timeout behavior.

## Testing

Extend the WebSocket session recovery test to cover an unanswered `environment/info` request, checking that it times out, closes the connection, and resumes the same session while retaining the client instance.

GitOrigin-RevId: 9035d2edab3626e780d8bd40ebcdf0ca327bfddb
## What changed

Update the replay assertion in the recorder refresh test to compare `executed_tool_call_metadata()` instead of entire response items. This keeps the assertion focused on preserving recorded tool call metadata across a configuration refresh.

GitOrigin-RevId: 763173a918f4e0bc79c3c04466453cafb9629775
GitOrigin-RevId: c0725029a8e58d384d17ff50d99030cc7d1c9e96
…49414)

## What changed

Set the default SQLite log filter to `DEBUG` for `tokio_graceful::guard` and `tokio_graceful::trigger`, dropping their `TRACE` events while retaining debug and higher-level diagnostics.

## Testing

Extend the SQLite sink filter test to verify that guard and trigger traces are dropped, their debug events are retained, and `tokio_graceful::shutdown` trace events remain available.

GitOrigin-RevId: c98495c834db35f3d8799ab4f0a1f7a82a53c8ef
## What changed

Use `derive_more::Debug` for `ContentItem` and `UserInput` to limit debug formatting of `ContentItem::InputText` and `UserInput::Text` to a prefix of at most 512 bytes, ending at a UTF-8 character boundary. Append the full text length in bytes to each preview.

GitOrigin-RevId: ca711dde8f0e3ba7047103415dbc1836f6401e61
## Why

`ansi_escape_line` logged the rendered contents of every line when given multiline input, allowing large payloads to inflate warning logs.

## What changed

Replace line contents in the warning with structured `input_bytes` and `line_count` fields. Preserve the existing behavior of returning the styled first line.

## Testing

Enable unit tests for `codex-ansi-escape` and add coverage with small and 128 KiB tails, asserting the exact warning fields and preservation of first-line styling.

GitOrigin-RevId: 4be985b4442eaa12f7fdee8a583d6e9714c618d8
## Why

`LegacyAppPathString` treated `//server/share/project` as POSIX, losing its UNC interpretation when inferring a `PathUri`.

## What changed

Infer Windows syntax whenever an API path starts with two separators, including forward and mixed slashes, independently of the host. For example, `//server/share/project` now converts to `file://server/share/project`. Double-slash POSIX paths require an explicit `PathConvention::Posix`; inferred paths still undergo validation.

## Testing

Add regression tests for UNC and namespace paths, mixed separators, URI serialization round trips, explicit POSIX conversion, convention mismatches, and malformed UNC paths.

GitOrigin-RevId: 720893de517addb7a938e6784d1ed0f05df3ec0d
## Why

Startup-only cleanup leaves expired logs in long-running sessions, and age-based retention alone does not limit database usage.

## What changed

Run cleanup in the background immediately after initialization and every 30 minutes. Start with the existing 10-day retention window, then halve it until occupied SQLite pages fit within a 64 MiB budget or the window reaches one second. Preserve logs within that final second even when they exceed the budget.

Exclude free pages from the budget so SQLite can reuse them, and retain the passive checkpoint after the first sweep. Stop the task when the runtime is dropped or the log pool is closed.

## Testing

Add tests for the 10-day boundary, repeated retention-window halving, free-page accounting, the one-second retention floor, immediate startup cleanup, and periodic cleanup without new writes or a restart. Update existing log tests to use current timestamps so background retention does not remove their fixtures.

GitOrigin-RevId: c6eeb5ec13006d4a03354e08322827429be53ce8
## Why

Daemon-launched app servers should use the same analytics default as first-party clients while honoring explicit user opt-outs.

## What changed

Pass `--analytics-default-enabled` when the PID backend launches an app server, with or without remote control. Users can still disable analytics with `analytics.enabled = false` in `config.toml`.

## Testing

Update argument assertions for both remote-control modes and the daemon start/restart test to expect the analytics flag alongside launch feature overrides.

GitOrigin-RevId: 8a222a00fc56737f5fe2b0385abf59466d1a6671
## Why

Embedded app-server configuration discovery must remain available after login and workspace changes, while content access granted to the previous account must be revoked.

## What changed

Give `AuthRouteConfig` a separate application network policy and bind embedded bootstrap authentication to the effective application policy. Use that policy for account-owned content clients and invalidate it when the authenticated owner changes, preserving the local, endpoint-restricted bootstrap policy.

## Testing

Add a regression test covering bootstrap discovery across login, workspace changes, and sign-out; revocation of previous account clients and permits; and continued enforcement of bootstrap endpoint restrictions and local requirements.

GitOrigin-RevId: 083933e69508224f8232349ba3750c02329af06a
@pull pull Bot locked and limited conversation to collaborators Sep 30, 2026
@pull pull Bot added the ⤵️ pull label Sep 30, 2026
@pull
pull Bot merged commit d8f69ea into bfloat16:main Sep 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.