Found by review C of #58 (Codex 0.157.1 acceptance), and seen first-hand: a 2026-09-26 recording in an untrusted directory painted exactly this dialog.
"Do you trust the contents of this directory?" / "No, quit" exist in 0.150.1 to 0.155.1 and are gone from 0.156.0 onward (binary-verified bisect). 0.157.1 instead shows:
- "Folder access … Trust this folder? Codex can read, edit, and run files here, subject to your permission settings … Your trust decision will be saved.";
- the options "1. Trust and continue" / "2. Quit" (and "Open restricted" in some layouts).
src/parsers/TrustDialogParser.ts:65–71, src/parsers/ScreenParser.ts:175–182 and Codex01491ComposerSurface.ts:157 all anchor on the old opener.
The primary mechanism, pre-trust through [projects."<path>"] trust_level = "trusted", still works. On the fallback path (pre-trust cannot be written), the dialog is never detected: no auto-accept, and prompts are typed into the modal. The fix needs a recorded 0.157.1 frame; the W1 scratch recording of 2026-09-26 shows the full text.
Found by review C of #58 (Codex 0.157.1 acceptance), and seen first-hand: a 2026-09-26 recording in an untrusted directory painted exactly this dialog.
"Do you trust the contents of this directory?"/"No, quit"exist in 0.150.1 to 0.155.1 and are gone from 0.156.0 onward (binary-verified bisect). 0.157.1 instead shows:src/parsers/TrustDialogParser.ts:65–71,src/parsers/ScreenParser.ts:175–182andCodex01491ComposerSurface.ts:157all anchor on the old opener.The primary mechanism, pre-trust through
[projects."<path>"] trust_level = "trusted", still works. On the fallback path (pre-trust cannot be written), the dialog is never detected: no auto-accept, and prompts are typed into the modal. The fix needs a recorded 0.157.1 frame; the W1 scratch recording of 2026-09-26 shows the full text.