Repository navigation
fix(trust): detect the Codex 0.156+ Folder access dialog and send its keystrokes - #67
Merged
Juliusolsson05 merged 6 commits intoSep 27, 2026
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…strokes Codex 0.157.1 rewrote the trust dialog: no '> You are in', no 'Do you trust the contents', options 'Trust and continue' / 'Quit' or 'Back to Agent Command Center' (or 'Open restricted' / 'Open existing task'). detectCodexTrustDialog returned not-visible for the live, blocking dialog. It now recognises both layouts structurally (whole-line anchor, adjacent option pair, key hint that must agree with option 2) and reads labels, folder and Git trust target from the screen. Upstream also changed the keys (trust_directory.rs at rust-v0.157.1): 1 only moves the highlight, Enter confirms. The state now carries per-layout keystrokes (legacy '1'; 0.156+ '1\r'), the condition labels its actions from the screen, and CodexHeadless's legacy trust_dialog event stops sending '2\r'. ScreenParser and the 0.149.1 composer surface share the detector / add the new hint anchor. Fail-first: a recorded 0.157.1 PTY replay (no key sent) and upstream's insta snapshots, red on main. Fixes #65 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ept a wrapped hint Review of #67 (a, b): a transcript quoting the dialog verbatim was read as a live, answerable trust dialog. The dialog is Codex's onboarding screen, so its key hint is the last painted row; a quoted copy always has the live composer below it. Detection now reads bottom-up: hint last (one wrap allowed, for the Windows sandbox hint below 46 columns), nearest adjacent option pair above, nearest Folder access above that. Adds tests for the copied frame, the wrapped hint, an unknown option-1 label, option adjacency, both option-2 condition labels, legacy streaming suppression, and the CodexHeadless trust_dialog callbacks driven through the public class with the 0.157.1 recording. Refs #65 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…0.156+ hint row as a modal Review c of #67: - F1: the legacy layout accepted a verbatim quoted dialog above the live composer, the same phantom fixed for 0.156+. Its 'Press enter to continue' hint is the last painted row as well (rust-v0.149.1 and the recorded 0.149.1 frame), so it is read bottom-up the same way. - F2: pinning the composer-surface anchor exposed that the unwrapped 0.156+ hint has the idle-footer shape, so the dialog read as a composer drafting '1. Trust and continue'. It is now a bottom-row structural check (identical to #63's branch); the window-based anchor is removed. - F3: API.md rewritten for both layouts; new constants and the layout type exported. Refs #65 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Owner
Author
|
Disposition (W1). Three reviews at
Verification a (after |
Juliusolsson05
changed the base branch from
main
to
integration/batch-2026-09-27-cxh-v
September 27, 2026 23:40
Juliusolsson05
merged commit Sep 27, 2026
ccb6080
into
integration/batch-2026-09-27-cxh-v
6 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #65. Refs agent-code#234 (Codex 0.157.1 acceptance).
The bug
Codex 0.156+ repainted the trust dialog.
detectCodexTrustDialogreturns{visible:false}for the live, blocking dialog, so:codex.trust-dialogcondition is raised;Recorded from codex-cli 0.157.1, with no key sent:
Upstream also changed the keys. In
trust_directory.rsatrust-v0.157.1:1/ynow only moves the highlight ("trust always requires an explicit Enter confirmation");2,n,q, Esc, Ctrl+C and Ctrl+D still act at once.So the old accept bytes (
'1') would leave the dialog up.Change
Both layouts are read bottom-up. The dialog is Codex's onboarding screen, so its key hint is the last painted row. A copied frame inside a transcript always has the live composer below it and never matches (review a/b P1). This applies to the legacy layout too: its
Press enter to continuehint is last in rust-v0.149.1 (review c F1). The new layout needs:enter continue · esc quit|backas the last row (one wrap allowed, for the Windows hint below 46 columns), withquit/backagreeing with option 2;1./2.pair above it, with labels upstream can paint;Folder accessabove that.Prose that quotes the rows still cannot match.
Fields read from the screen:
trustTarget).Keystrokes per layout, carried on the state. Legacy accept is
'1'. 0.156+ accept is'1\r':1pins the highlight, so the Enter can only confirm option 1. Decline is'2'in both.The condition's actions use the state's keys and on-screen labels. Ids are unchanged. The legacy
trust_dialogevent no longer sends'2\r'.Shared detector.
ScreenParser's streaming-text suppression uses it. Before, it matched on substrings, so quoted prose blanked the stream.Composer surface. In
Codex01491ComposerSurface, a bottom-rowTRUST_HINT_FOOTERcheck marks the dialog a modal. Its hint row has the idle-footer shape, so without this check the dialog read as a composer drafting1. Trust and continue(found by review c F2's test). The hunk is byte-identical to feat(prompt-input): issue the input profile for recorded Codex 0.157.1 #69's.Docs and exports.
API.mdis rewritten for both layouts. The new constants andCodexTrustDialogLayoutare exported.Evidence and tests (fail-first: 5 of the new tests are red on main)
testing/fixtures/trust-dialog-0157/folder-access-back.json: a raw PTY recording of codex-cli 0.157.1 at 80×24.HeadlessTerminaland checked with the parser, the condition actions and the streaming-text extractor.upstream-snapshots-0157.1.json: upstream's 9TrustDirectoryWidgetinsta snapshots, verbatim (Apache-2.0, attributed). They cover:esc backcase where only the whitelist rejects;CodexHeadless.trustDialog.test.tsdrives the public class with the recording and asserts thetrust_dialogcallbacks write'1\r'and'2'.Codex01491ComposerSurface.test.tspins that the dialog is a modal, unwrapped and wrapped.CODEX_HOMEon codex-cli 0.157.1. After1alone the dialog was still up, and the following Enter reached the composer.tsc --noEmitclean. CI green atd9a1305.RolloutOwnership.recordedmodern-0149-large-bootstrap-first, on its 5 s timeout under load (bug(testing): RolloutOwnership.recorded 'modern-0149-large-bootstrap-first' exceeds 5 s under load #60, untouched here).Not verified / residuals
CodexTrustDialogModalin agent-code) still shows fixed "Trust Folder"/Cancel copy and ignores the action labels. When option 2 is "Back to Agent Command Center", its cancel really goes back rather than quitting. That is an agent-code follow-up for the 0.157 bump.Plan:
docs/plans/2026-09-27-trust-dialog-0157.md.🤖 Generated with Claude Code