Skip to content

[pull] main from openai:main - #51

Merged
pull[bot] merged 11 commits into
bfloat16:mainfrom
openai:main
Sep 30, 2026
Merged

pull[bot] merged 11 commits into
bfloat16:mainfrom
openai:main

Conversation

@pull

@pull pull Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

bc-openai and others added 11 commits September 30, 2026 01:58
## Why

Voice conversations previously opened the system-default microphone and speaker. Users need to choose which local devices to use, including when connected to a remote app server.

## What changed

- Add input and output device pickers alongside voice selection, with back navigation and a System default option.
- Persist selections as `audio.microphone` and `audio.speaker` on the TUI's machine, excluding project configuration layers. Apply them to the next voice conversation.
- Enumerate devices without opening audio streams and pass the selected names to the voice helper at startup.
- Disable ambiguous device names in the picker and use the same eligibility filtering for discovery and named-device startup.

## Testing

Add tests for device preference persistence across project and remote transitions, picker navigation and duplicate names, discovery without capture, and forwarding selected devices to the helper.

GitOrigin-RevId: d48fb3a09fa9b982a408f5a7c96bdd81776af21d
## Why

Responses overload and exhausted-request errors could terminate despite server retry advice, and WebSocket-to-HTTP fallback could issue a request before the advised deadline.

## What changed

- Allow `ServerOverloaded` and `RetryLimit` errors to retry when server advice is present, within the configured retry budgets.
- Preserve `Retry-After` headers from rejected WebSocket upgrades and wait for the server deadline before falling back to HTTP.
- Keep quota, usage-limit, and policy failures terminal even when they include retry advice.

## Testing

Add coverage for HTTP overload and rate-limit recovery, WebSocket upgrade rejection and fallback timing, retry deadline preservation through error mapping, and retry limits for sampling and manual and automatic compaction.

GitOrigin-RevId: 72d30a9f078652664754dfa971fd7dc7a78f20e8
Replace the byte-by-byte reverse newline search with `memchr::memrchr` and add `memchr` as a dependency of `codex-rollout`.

GitOrigin-RevId: b07e42e15efb0d63d7b00ee9a2ee29c446f4cf59
## Why

Login shell startup can reset `PATH`, preventing commands and their children from finding bundled tools such as `rg` in executor-reported directories.

## What changed

When `login_shell_package_path` is enabled, prepend missing executor-reported directories to `PATH` inside the POSIX login shell before running the requested command. Preserve existing entries and the order of newly added directories, and export `PATH` for child commands.

Respect explicit `PATH` overrides and preserve the requested login mode when directories are unusable or `PATH` is read-only. Keep shell diagnostics and `$LINENO` aligned with the original script, including when directory names contain newlines. The feature remains disabled by default.

## Testing

Add shell tests for nested tool lookup, existing entries, quoting, line numbers, and read-only `PATH`. Extend remote execution tests to cover feature gating, explicit overrides, unusable directories, and preservation of the original command in execution events.

GitOrigin-RevId: 301aa34e72cc6292293693250e190c19903f390a
## Why

Client permission definitions and constraints can differ from those on the connected app server. Accepted permission changes also need to survive task transitions before their settings notifications arrive.

## What changed

- Discover permission profiles and availability from the connected server and apply selections through `thread/settings/update`, including custom profiles.
- Adopt the server's effective permission settings instead of reapplying local definitions or constraints.
- Retain accepted selections and effective approval settings across new tasks, forks, side conversations, directory changes, reconnects, and safety retries without blocking navigation on a settings notification.
- Recognize the current built-in permission preset when the server supplies an unnamed profile.

## Testing

Add regression coverage for conflicting client/server profile definitions, rejected and unchanged selections, consecutive requests with omitted approval settings, and permission carryover before confirmation. Extend discovery and menu tests to verify server-provided availability and unnamed-profile highlighting.

GitOrigin-RevId: bcd767b58dc92dc4f945189078e51e6e5fce6d24
## What changed

Upgrade `rmcp` to a pinned Git revision of version `3.3.0` and enable `auth-enterprise-managed`. Delegate the two-stage ID-JAG exchange and token validation to the SDK, replacing the local implementation while retaining Codex HTTP routing and credential lifecycle policy.

Map SDK errors by exchange stage so `invalid_grant` distinguishes enterprise identity failures from resource authorization failures, and preserve handling of `insufficient_user_authentication`.

## Testing

Update exchange tests to verify rejection of unsupported `authorization_details` and malformed signed scopes. Exercise errors from both token endpoints to check credential policy, prevent credential reflection in diagnostics, and ensure rejected grants are not retried.

GitOrigin-RevId: a56034aa3fd70002754ea552fd2da70bdcd85b31
## Why

`TurnAborted` could be emitted before extension abort callbacks finished, allowing consumers to observe a terminal event while lifecycle cleanup was still pending.

## What changed

Await `on_turn_abort` within task abort handling before emitting `TurnAborted`, retaining callback delivery for already-cancelled tasks. Document that `on_turn_stop` and `on_turn_abort` complete before their corresponding terminal events, if emitted.

## Testing

Add regression coverage for interrupt, conditional interrupt, and shutdown. Hold the abort callback open to verify that `TurnAborted` waits for completion, then verify that the callback runs exactly once with the expected turn ID and abort reason.

GitOrigin-RevId: f34d7e94d04c02544178dc445b85abc65a6ce499
#49478)

## What changed

Add `exchange_ema_auth_token` to discover and validate the MCP resource's authorization server before resolving enterprise identity credentials and performing the ID-JAG token exchange. Keep the lower-level exchange primitive private.

- Probe `server/discover` with the enterprise-managed authorization extension, support recognized legacy discovery rejections, and follow protected-resource metadata challenges or well-known fallbacks.
- Match configured resource and issuer constraints, require advertised public-client JWT bearer support, and validate token endpoint metadata without requiring an authorization endpoint.
- Bound discovery with a shared timeout, redirect and authorization-server limits, reject cross-origin metadata redirects, and restrict private authorization-server destinations while allowing local loopback discovery.

## Testing

Add tests covering resource and issuer mismatches before identity access, metadata capability validation, query preservation, modern challenges, JSON and SSE legacy fallback behavior, cross-origin redirect rejection, and private or malformed issuer destinations.

GitOrigin-RevId: 9a55233a20ff42c293f9bd8175e01141ac2d8576
## What changed

Define `thread/prediction/request` with `threadId` and `sourceTurnId`, and `thread/prediction/updated` with a `completed` result containing optional text or a `failed` result.

Update generated JSON schemas, TypeScript types, and Python notification models. Route prediction notifications to their thread in the TUI and ignore them in the chat widget.

The request remains unimplemented and returns a method-not-found error.

GitOrigin-RevId: 09922f583d5c56f808d018121c651dcd92734515
#49489)

## What changed

Add a debug-only analytics test that switches accounts after the first isolated event request. Assert that only the first request reaches the server and carries the original account's credentials, so subsequent batches do not send stale credentials after the switch.

Remove an unused `ToolCallSource` import.

GitOrigin-RevId: e66904c7a7176f1eaa37662b836132586328884a
## What changed

- Fork the selected conversation and open the new session with `f`, configurable through `agents.fork` in the TUI keymap.
- Move the default search shortcuts to `F3` and `/`, preserving unshadowed defaults when custom bindings conflict.
- Keep queued input on the source conversation while attaching and forking, and require closing an open side conversation before forking another task.
- Expose the fork action in command-center help and the keymap picker.

## Testing

Add regression coverage for queued-input preservation, side-conversation protection, configurable fork shortcuts, metadata editing, disconnected actions, and search fallback bindings. Update help and keymap snapshots.

GitOrigin-RevId: b11ae21ef6a2053609b31ce97c646104f18806a3
@pull pull Bot locked and limited conversation to collaborators Sep 30, 2026
@pull pull Bot added the ⤵️ pull label Sep 30, 2026
@pull
pull Bot merged commit d420560 into bfloat16:main Sep 30, 2026
4 of 23 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants