Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1615 commits
Select commit Hold shift + click to select a range
482e649
Merge trusted plugin attribution from openai/main
cbusillo Jul 23, 2026
90839c4
ci: preserve available macOS V8 runners
shiny-code-bot Jul 23, 2026
84fa68b
Attribute command executions to trusted plugin scripts (#35020)
kmbroai Jul 23, 2026
fe0d472
Adapt keyboard event reporting to the terminal (#35021)
fcoury-oai Jul 23, 2026
1ee8f49
Route exec-server HTTP through configured proxy policy (#35023)
celia-oai Jul 23, 2026
3c2e090
Fix integration candidate CI checks
shiny-code-bot Jul 23, 2026
091e4a5
Preserve refreshed Apps tools across MCP runtime updates (#35028)
jif-oai Jul 23, 2026
9fc4e5a
Preserve plugin attribution across command approvals (#35029)
kmbroai Jul 23, 2026
9633165
Enforce writer ownership for thread archive and deletion (#35031)
owenlin0 Jul 23, 2026
4177555
Expose Browser Use requirements through the app server (#35033)
rafael-oai Jul 23, 2026
d45055a
Route environment registry requests through the shared HTTP client (#…
celia-oai Jul 23, 2026
b115de9
Preserve Windows sandbox proxy settings in guardian sessions (#35036)
iceweasel-oai Jul 23, 2026
4123bf6
Track app/read request duration (#35048)
stevenlee-oai Jul 23, 2026
bb24b67
Register the Guardian V2 feature flag (#35049)
won-openai Jul 23, 2026
fb4e6ba
Allow disabling the update_plan tool (#35054)
tz-openai Jul 24, 2026
94ebae7
Route exec-server WebSockets through configured proxies (#35056)
celia-oai Jul 24, 2026
09241ae
Decouple exec-server HTTP from reqwest types (#35059)
celia-oai Jul 24, 2026
1d4b58f
Track deferred tool namespaces in world state (#35063)
aibrahim-oai Jul 24, 2026
3947f0d
Avoid duplicating deferred sources in tool search (#35065)
aibrahim-oai Jul 24, 2026
f47f28c
Fix Bazel test configuration for platform-specific data (#35067)
anp-oai Jul 24, 2026
0dfa778
Add WebSocket transport to the code-mode host (#35078)
cconger Jul 24, 2026
c6c0df6
Merge remote-tracking branch 'origin/main' into code/upstream-snapsho…
shiny-code-bot Jul 24, 2026
fee69f9
Adapt blocking CI runners for Codex Lab
shiny-code-bot Jul 24, 2026
e7078c4
Fix hosted Bazel CI fallbacks
shiny-code-bot Jul 24, 2026
f61b51d
Support remote code-mode hosts in app-server (#35098)
cconger Jul 24, 2026
b9d5fd0
Fix keyless Windows Bazel toolchains
shiny-code-bot Jul 24, 2026
a73ce49
Keep Windows Bazel out of blocking CI
shiny-code-bot Jul 24, 2026
a28374e
Support Agent Plugins manifests (#35105)
jacobzhou-oai Jul 24, 2026
81da9de
Allow hosts to customize `wait_for_environment` descriptions (#35106)
TAFOYA-OAI Jul 24, 2026
29c945b
Budget hosted blocking CI cold builds
shiny-code-bot Jul 24, 2026
7c11d80
Route heavy CI to trusted postmerge runners
shiny-code-bot Jul 24, 2026
f61974b
Support trusted runners without passwordless sudo
shiny-code-bot Jul 24, 2026
832d347
Harden Bazel setup for trusted Linux runner
shiny-code-bot Jul 24, 2026
a3bb1d1
Expose bundled models to Bazel config builds
shiny-code-bot Jul 24, 2026
ef2d3ed
Prewarm MCP runtime updates in the background (#35144)
jif-oai Jul 24, 2026
6c729ef
Refresh MCP runtimes when session auth changes (#35146)
jif-oai Jul 24, 2026
f201c30
Reconnect MCP servers on explicit refresh (#35151)
jif-oai Jul 24, 2026
c42e1b2
Make Code Bridge witness helpers clippy-clean
shiny-code-bot Jul 24, 2026
f090bd9
Fix restored integration clippy findings
shiny-code-bot Jul 24, 2026
c8957bb
Encapsulate MCP refresh coordination (#35164)
jif-oai Jul 24, 2026
5dd992a
Route extension warnings to app-server threads (#35168)
felixxia-oai Jul 24, 2026
5a1c54f
Compact host skill paths under metadata pressure (#35172)
felixxia-oai Jul 24, 2026
1a817bb
Wait for reloaded worker completion in the resume test (#35175)
jif-oai Jul 24, 2026
7c71783
Expose executor skills through skill tools (#35184)
jif-oai Jul 24, 2026
06e9e59
Route trusted workflows to repository runners
shiny-code-bot Jul 24, 2026
634a998
Preserve output from hooks that exit before reading stdin (#35194)
jif-oai Jul 24, 2026
5f6a2c3
Make the Apps recovery exposure test deterministic (#35196)
jif-oai Jul 24, 2026
fe8500c
Enable resource reads for explicit executor skills (#35198)
jif-oai Jul 24, 2026
3645a43
Refresh MCP runtimes across thread startup (#35204)
jif-oai Jul 24, 2026
319c217
Merge remote-tracking branch 'origin/main' into code/upstream-snapsho…
shiny-code-bot Jul 24, 2026
000d254
Use current MCP authority for elicitation reviews (#35205)
jif-oai Jul 24, 2026
a177013
Refresh managed MCP requirements for active threads (#35213)
jif-oai Jul 24, 2026
58b4277
Refresh MCP config independently across threads (#35216)
jif-oai Jul 24, 2026
05f0002
Support paginated thread forks (#35220)
owenlin0 Jul 24, 2026
99744cf
Avoid persisting non-local threads for hook transcripts (#35221)
rasmusrygaard Jul 24, 2026
050f352
Fix remote control reconnect races
shiny-code-bot Jul 24, 2026
b726506
Merge remote-tracking branch 'origin/main' into code/upstream-snapsho…
shiny-code-bot Jul 24, 2026
544007d
Support the ent26 enterprise plan (#35238)
bwanner-oai Jul 24, 2026
89a3b89
Route MCP auth discovery through runtime HTTP clients (#35239)
celia-oai Jul 24, 2026
1811b67
Support ephemeral forks of paginated threads (#35251)
owenlin0 Jul 24, 2026
32329b2
Expose workspace plugin publish capability (#35254)
tsarlandie-oai Jul 24, 2026
0a8fb6b
Merge origin/main while deferring package lane
cbusillo Jul 24, 2026
07fd04a
Propagate remote plugin IDs to skill metadata (#35261)
jameswt-oai Jul 24, 2026
0d2a0aa
Track remote plugin IDs in skill invocation analytics (#35262)
jameswt-oai Jul 24, 2026
a453588
Sign bundled macOS helper binaries (#35264)
cconger Jul 24, 2026
cba0e27
Allow disabling the in-process code-mode host fallback (#35266)
cconger Jul 24, 2026
63fe5a6
Harden network approval cancellation and concurrency (#35267)
viyatb-oai Jul 25, 2026
25b6fc9
Include code-mode tool names in Responses Lite metadata (#35271)
rka-oai Jul 25, 2026
c3e926e
Trace remote exec-server connection setup (#35275)
rphilizaire-openai Jul 25, 2026
4c43465
Skip plugin MCP filtering when no allowlists are configured (#35280)
xli-oai Jul 25, 2026
3a08af4
Handle exec-server network policy requests in the client (#35359)
viyatb-oai Jul 25, 2026
af7f6f4
Include item start times in completion events (#35363)
owenlin0 Jul 25, 2026
5c36e86
Bound Code Mode metadata compatibility headers (#35364)
tz-openai Jul 25, 2026
322d5b9
Keep unified mention results fresh (#35365)
charliemarsh-oai Jul 25, 2026
324201d
Merge openai/main through 4c43465133 into Codex Lab candidate
cbusillo Jul 25, 2026
5950ce2
Merge openai/main through af7f6f4d34
cbusillo Jul 25, 2026
643e05a
test(app-server): include optional item start timestamp
cbusillo Jul 25, 2026
49a0f31
Merge openai/main through 322d5b96cf
cbusillo Jul 25, 2026
b0e2979
chore(core): allow MCP projection argument count
cbusillo Jul 25, 2026
0eaff10
chore: format upstream integration changes
cbusillo Jul 25, 2026
20dafe2
Make the keymap action menu responsive (#35375)
fcoury-oai Jul 25, 2026
dea4008
fix(release): define Codex Lab app build profile
cbusillo Jul 25, 2026
8ca503f
fix(mcp-server): raise optimized build recursion limit
cbusillo Jul 25, 2026
2d78221
Merge remote-tracking branch 'origin/main' into code/upstream-snapsho…
cbusillo Jul 25, 2026
83df7b8
Merge remote-tracking branch 'openai/main' into code/upstream-snapsho…
cbusillo Jul 25, 2026
b57a27e
state: preserve shipped migration versions 36-38
cbusillo Jul 25, 2026
89255b4
guard(convergence): fail refreshes that silently drop owned paths
cbusillo Jul 25, 2026
89a6cf2
ci: fork-guard R2 publishing and strip the Codex Lab engine
cbusillo Jul 25, 2026
9fafdcb
fix(core): bound world-state context
shiny-code-bot Jul 25, 2026
509b7e3
fix(core): restore retained world-state fragments
shiny-code-bot Jul 25, 2026
5778e58
fix(runtime): preserve auth and updater isolation
cbusillo Jul 25, 2026
7e3790d
Merge state migration compatibility for #465
cbusillo Jul 25, 2026
8e93938
Merge release hardening for #465
cbusillo Jul 25, 2026
ced83ba
Merge convergence safety guard for #428
cbusillo Jul 25, 2026
2a1060c
wip: restore project validation onto upstream snapshot
cbusillo Jul 25, 2026
87cbe72
Merge branch 'code/upstream-snapshot-428' into code/restore-auto-revi…
cbusillo Jul 25, 2026
f27b248
fix(provenance): restore verified dogfood launcher
shiny-code-bot Jul 25, 2026
0b02c84
feat(tui): expose build provenance in diagnostics
shiny-code-bot Jul 25, 2026
11c469a
test(tui): refresh default command snapshot
shiny-code-bot Jul 25, 2026
a7f78ec
fix(provenance): harden launcher and convergence evidence
cbusillo Jul 25, 2026
62fd410
Ignore generated system skills in the skills watcher (#35408)
victor-openai Jul 25, 2026
6b410ab
fix(provenance): bound retained dogfood candidates
cbusillo Jul 25, 2026
07053d7
fix(provenance): reap orphaned staging artifacts
cbusillo Jul 26, 2026
baab552
Merge remote-tracking branch 'openai/main' into code/openai-refresh-2…
cbusillo Jul 26, 2026
61a4488
Raise the MCP server recursion limit (#35414)
rka-oai Jul 26, 2026
cd0c1dd
docs(convergence): record 62fd upstream refresh
cbusillo Jul 26, 2026
83f80ce
Merge remote-tracking branch 'openai/main' into code/openai-refresh-2…
cbusillo Jul 26, 2026
6c1db49
docs(convergence): record 61a448 upstream refresh
cbusillo Jul 26, 2026
8ecc5fc
feat(validation): restore automatic project validation
cbusillo Jul 26, 2026
4fff615
Merge Project Validation restoration for #428
cbusillo Jul 26, 2026
e39b453
Merge July 26 upstream refresh for #428
cbusillo Jul 26, 2026
25a64a0
Forward-port SessionProvenance contract onto upstream snapshot
Jul 26, 2026
26ab1d4
Merge SessionProvenance restoration for #428
cbusillo Jul 26, 2026
46b663f
feat: restore external integration contracts
cbusillo Jul 26, 2026
c0e3374
fix(tui): keep provenance separate from session source
cbusillo Jul 26, 2026
4284cbf
Merge external integration restoration for #428
cbusillo Jul 26, 2026
145033f
test(core): cover project validation workspace sandbox
cbusillo Jul 26, 2026
00df387
Merge Project Validation sandbox coverage for #428
cbusillo Jul 26, 2026
6289419
Restore background auto review contract
cbusillo Jul 26, 2026
78450ef
Merge Background Review restoration for #428
cbusillo Jul 26, 2026
524107e
fix(state): stop shipped databases from breaking on migration rewrites
cbusillo Jul 26, 2026
f6e91da
Bound model-visible context in bridge, external agents, and auto review
cbusillo Jul 26, 2026
e368b0b
core: restore external-agent preflight and routing coverage
cbusillo Jul 26, 2026
a912f9f
Restore API/CLI/config compatibility surfaces for the upstream snapshot
cbusillo Jul 26, 2026
9ff0c28
Cover Background Review trigger, budgets, RPC, and disposition
cbusillo Jul 26, 2026
f656722
Merge migration safety fixes for #428
cbusillo Jul 26, 2026
5f7eb0b
Merge compatibility restoration for #428
cbusillo Jul 26, 2026
c77739d
Merge model-context hardening for #428
cbusillo Jul 26, 2026
efdbb48
Merge external-agent integration coverage for #428
cbusillo Jul 26, 2026
084dde0
Merge Background Review integration coverage for #428
cbusillo Jul 26, 2026
300e3db
ci: make fork release and CI publishing fail-safe
cbusillo Jul 26, 2026
1255c7b
Merge release and CI safety hardening for #428
cbusillo Jul 26, 2026
624e9b1
test(convergence): restore Code Bridge proofs and generalize the owne…
cbusillo Jul 26, 2026
fdbc22b
Merge restored integration proofs and convergence coverage for #428
cbusillo Jul 26, 2026
9daa317
fix(core): bound model-visible context sinks and recover from invalid…
cbusillo Jul 26, 2026
e56dded
Merge model-context safety fixes for #428
cbusillo Jul 26, 2026
cdc6321
test: cover validation, background review control, and CLI config sur…
Jul 26, 2026
fd58c87
Merge high-value behavioral coverage for #428
cbusillo Jul 26, 2026
25a49be
fix: restore shipped app-server, hooks, and rollout compatibility
cbusillo Jul 26, 2026
32d1d78
Merge external compatibility restorations for #428
cbusillo Jul 26, 2026
03882cb
test(convergence): prove the environment writer and close the guard gaps
cbusillo Jul 26, 2026
de24f03
chore(convergence): regenerate guard and inventory artifacts
cbusillo Jul 26, 2026
0962349
Merge final proof and guard coverage for #428
cbusillo Jul 26, 2026
b14fe2f
Bound the remaining unbounded model-visible context items
cbusillo Jul 26, 2026
f71e701
Merge final model-context bounds for #428
cbusillo Jul 26, 2026
31b2e76
Restore remaining external compatibility surfaces
cbusillo Jul 26, 2026
ac9c95b
Merge remaining compatibility fixes for #428
cbusillo Jul 26, 2026
d96308e
chore(convergence): refresh guard after final restorations
cbusillo Jul 26, 2026
e48f82b
fix: close the final draft-publication gates for #428
cbusillo Jul 26, 2026
2fd8cf5
Merge final draft-publication gate fixes for #428
cbusillo Jul 26, 2026
2b393e5
fix(ci): restore lint and Bazel compatibility
cbusillo Jul 26, 2026
f720041
fix(rust): annotate opaque literal arguments
cbusillo Jul 26, 2026
f59b994
fix(ci): align sample config and docs formatting
cbusillo Jul 26, 2026
4bb0ef9
fix(ci): source V8 artifacts explicitly in full CI
cbusillo Jul 26, 2026
201bb1a
fix(auto-review): compile PID liveness checks on Windows
cbusillo Jul 26, 2026
0133594
fix(ci): unblock Windows and ARM full CI
cbusillo Jul 26, 2026
7b0a7c4
test(core): skip POSIX agent commands on Windows
cbusillo Jul 26, 2026
3bfe89b
fix(ci): allow full argument lint to finish
cbusillo Jul 26, 2026
e5945d2
fix(ci): make cross-platform test failures deterministic
cbusillo Jul 26, 2026
c3566f2
fix(ci): repair Windows portability across full CI
cbusillo Jul 26, 2026
be75f60
fix(auto-review): make save_run persistence O(1) in index size
cbusillo Jul 26, 2026
a39db9f
fix: harden persistence and auth CI paths
cbusillo Jul 26, 2026
86a844d
fix(ci): close remaining cross-platform gaps
cbusillo Jul 26, 2026
4ac9473
Stabilize hosted full CI lanes
cbusillo Jul 26, 2026
8a2b89e
Remove stale model convergence waivers
cbusillo Jul 26, 2026
5450eff
Restore compact convergence waiver formatting
cbusillo Jul 26, 2026
ce2f852
Merge pull request #477 from cbusillo/code/upstream-convergence-syste…
shiny-code-bot Jul 26, 2026
5dd9b8e
Merge pull request #478 from cbusillo/code/convergence-bootstrap-ci-428
shiny-code-bot Jul 26, 2026
47047f8
Wire convergence validation into repo checks
cbusillo Jul 26, 2026
e9d4aaa
Harden convergence evidence validation
cbusillo Jul 26, 2026
4c93e91
Pin guard regeneration policy
cbusillo Jul 26, 2026
8740275
Expose convergence bootstrap evidence
cbusillo Jul 26, 2026
165bf81
Test convergence summary rendering
cbusillo Jul 26, 2026
8ea6175
Merge PR #479: port canonical convergence controls
shiny-code-bot Jul 26, 2026
add7ec6
tui: assert exact kitty file-reference payload
cbusillo Jul 26, 2026
3808241
Stabilize seatbelt metadata carveouts
cbusillo Jul 26, 2026
bf6bcc7
tui: compact home-relative AGENTS summary paths
cbusillo Jul 26, 2026
a51777d
windows-sandbox: add process startup env floor
cbusillo Jul 26, 2026
e2cb02a
Stabilize Windows process-heavy tests
cbusillo Jul 26, 2026
6ae6e1d
Bound one-shot MCP startup recovery
cbusillo Jul 26, 2026
f48579d
stabilize full CI across supported platforms
cbusillo Jul 27, 2026
84daf79
Merge pull request #480 from cbusillo/code/pr465-windows-ci-stability
cbusillo Jul 27, 2026
4fea023
ci: bound Bazel repo contents cache lifecycle
cbusillo Jul 27, 2026
eb94fd5
Merge remote-tracking branch 'origin/code/upstream-snapshot-428' into…
cbusillo Jul 27, 2026
f9adf63
windows-sandbox: restore PowerShell-compatible token
cbusillo Jul 27, 2026
0c9ca9a
Merge pull request #481 from cbusillo/fix/bazel-run-cache-lifecycle
shiny-code-bot Jul 27, 2026
a5f9dfa
Merge pull request #482 from cbusillo/code/pr465-windows-token-compat
cbusillo Jul 27, 2026
731cc41
Stabilize remaining full CI shards
cbusillo Jul 27, 2026
fcb0481
Merge pull request #483 from cbusillo/code/pr465-final-ci-stability
cbusillo Jul 27, 2026
5d467de
Harden Windows legacy CI fixtures
cbusillo Jul 27, 2026
dd7e9ba
ci: secure and scale self-hosted runners
cbusillo Jul 27, 2026
edae67d
Merge pull request #485 from cbusillo/code/trusted-runner-lanes
cbusillo Jul 27, 2026
99d7e8a
test(windows): fix whoami option spelling
cbusillo Jul 27, 2026
1960061
ci: preserve stacked app validation
cbusillo Jul 27, 2026
6d09ba6
test(windows): parse whoami SID directly
cbusillo Jul 27, 2026
2157cf0
Merge pull request #486 from cbusillo/code/trusted-runner-pr-trigger-fix
cbusillo Jul 27, 2026
03c5eb2
Merge pull request #484 from cbusillo/code/pr465-windows-acl-followup
cbusillo Jul 27, 2026
2c19dc0
ci: isolate self-hosted caches by runner
cbusillo Jul 27, 2026
2da3fa4
Merge pull request #487 from cbusillo/code/per-runner-cache-isolation
cbusillo Jul 27, 2026
2e6bc10
windows-sandbox: preserve capability containment
cbusillo Jul 28, 2026
1eaf9c3
ci: schedule and fail fast full verification
cbusillo Jul 28, 2026
3cf5924
ci: gate releases on full verification
cbusillo Jul 28, 2026
78bb3e6
Merge pull request #489 from cbusillo/code/full-ci-policy
cbusillo Jul 28, 2026
5f11b1e
Merge remote-tracking branch 'origin/code/upstream-snapshot-428' into…
cbusillo Jul 28, 2026
fa08a8e
windows-sandbox: clarify unelevated limits
cbusillo Jul 28, 2026
cc460d6
test: make archived full CI hermetic
cbusillo Jul 28, 2026
a2a02db
test: harden archived full CI fixtures
cbusillo Jul 28, 2026
a537179
test: remap archived Cargo resources
cbusillo Jul 28, 2026
84ce418
test: keep Unix sockets below path limit
cbusillo Jul 28, 2026
67391ba
test: keep legacy shell policy fixtures local
cbusillo Jul 28, 2026
7086262
ci: bound storage and collect full diagnostics
cbusillo Jul 28, 2026
8b92687
ci: harden diagnostic fallbacks
cbusillo Jul 28, 2026
f3a4890
Merge pull request #488 from cbusillo/code/full-ci-failure-followup
cbusillo Jul 28, 2026
17fe631
Merge remote-tracking branch 'origin/code/upstream-snapshot-428' into…
cbusillo Jul 28, 2026
d13ef7e
Merge remote-tracking branch 'origin/code/world-state-context-bounds-…
cbusillo Jul 28, 2026
de674df
Merge remote-tracking branch 'origin/code/upstream-snapshot-428' into…
cbusillo Jul 28, 2026
3cd4dad
chore(convergence): refresh World State guard
cbusillo Jul 28, 2026
c01ea3f
chore(convergence): refresh provenance guard
cbusillo Jul 28, 2026
62603e4
fix(convergence): preserve historical policy snapshots
cbusillo Jul 28, 2026
5461675
Merge pull request #474 from cbusillo/code/world-state-retained-match…
shiny-code-bot Jul 28, 2026
243a9a2
Merge pull request #473 from cbusillo/code/world-state-context-bounds…
shiny-code-bot Jul 28, 2026
56cfc6c
Merge remote-tracking branch 'origin/code/upstream-snapshot-428' into…
cbusillo Jul 28, 2026
4439489
chore(convergence): combine provenance and World State guards
cbusillo Jul 28, 2026
74ed407
Merge pull request #475 from cbusillo/code/provenance-diagnostics-311
shiny-code-bot Jul 28, 2026
2a03ba9
test(login): isolate revoke endpoint users
cbusillo Jul 28, 2026
1811e31
Merge pull request #491 from cbusillo/code/contract-test-isolation-30…
shiny-code-bot Jul 28, 2026
e47ab57
fix(auth): rebind threads after account removal
cbusillo Jul 28, 2026
17385eb
Merge pull request #492 from cbusillo/code/remove-account-lease-inval…
cbusillo Jul 28, 2026
ae68067
test(app-server): restore hermetic integration keyring
cbusillo Jul 29, 2026
7b966ec
chore(convergence): remove restored keyring waiver
cbusillo Jul 29, 2026
9cff6ee
test(convergence): cover restored app-server registry
cbusillo Jul 29, 2026
a04892b
Merge pull request #493 from cbusillo/code/restore-hermetic-keyring-306
cbusillo Jul 29, 2026
1a290ec
fix: restore bounded validation contracts
cbusillo Jul 29, 2026
39cd538
chore: resolve execution convergence waivers
cbusillo Jul 29, 2026
18857d2
fix: harden structural validation diagnostics
cbusillo Jul 29, 2026
317d01d
Merge pull request #494 from cbusillo/code/exec-contract-307
shiny-code-bot Jul 29, 2026
6e14cb4
fix(exec): wait safely for background reviews
shiny-code-bot Jul 29, 2026
13f3922
guard(convergence): preserve headless background review wait
shiny-code-bot Jul 29, 2026
dd231f3
chore(convergence): resolve review suite waivers
shiny-code-bot Jul 29, 2026
5ae93ae
Merge pull request #495 from cbusillo/code/tui-guardian-308
shiny-code-bot Jul 29, 2026
c1e2902
Restore binding skill-routing contracts
shiny-code-bot Jul 29, 2026
842f295
Guard binding skill-routing ownership
shiny-code-bot Jul 29, 2026
8194c1d
Version binding skill-routing ownership
shiny-code-bot Jul 29, 2026
67d008c
Regenerate versioned convergence guard
shiny-code-bot Jul 29, 2026
b599ca2
Merge pull request #496 from cbusillo/code/skills-audit-83
shiny-code-bot Jul 29, 2026
e26514d
Restore final convergence proof artifacts
cbusillo Jul 29, 2026
bbaf982
Refresh convergence guard manifest
cbusillo Jul 29, 2026
d967e45
Preserve artifact lifecycle classification contracts
cbusillo Jul 29, 2026
7dc35cd
Refresh artifact lifecycle guard entries
cbusillo Jul 29, 2026
86cad52
Merge pull request #497 from cbusillo/code/finalize-upstream-snapshot…
cbusillo Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
19 changes: 8 additions & 11 deletions .bazelrc
Original file line number Diff line number Diff line change
Expand Up @@ -89,8 +89,8 @@ common:remote --jobs=800

# GitHub Actions CI configs.
common:ci --remote_download_minimal
common:ci --keep_going
common:ci --verbose_failures
common:ci --keep_going
common:ci --build_metadata=REPO_URL=https://github.com/openai/codex.git
common:ci --build_metadata=ROLE=CI
common:ci --build_metadata=VISIBILITY=PUBLIC
Expand All @@ -105,10 +105,6 @@ common:ci --disk_cache=
# Shared config for the main Bazel CI workflow.
common:ci-bazel --config=ci
common:ci-bazel --build_metadata=TAG_workflow=bazel
# Keep code-mode integration cases out of ordinary Bazel legs. The
# Windows-cross config below re-enables them after generating its Windows V8
# snapshot on the Windows runner.
common:ci-bazel --test_env=CODEX_BAZEL_TEST_SKIP_FILTERS=suite::code_mode::

# Shared config for Bazel-backed Rust linting.
build:clippy --aspects=@rules_rust//rust:defs.bzl%rust_clippy_aspect
Expand Down Expand Up @@ -164,6 +160,8 @@ build:argument-comment-lint --@rules_rust//rust/toolchain/channel=nightly
common:ci-windows --config=ci-bazel
common:ci-windows --build_metadata=TAG_os=windows
common:ci-windows --repo_contents_cache=D:/a/.cache/bazel-repo-contents-cache
# The hidden dynamic-tool callback currently times out on Windows.
common:ci-windows --test_env=CODEX_BAZEL_TEST_SKIP_FILTERS=suite::code_mode::code_mode_can_call_hidden_dynamic_tools

# We prefer to run the build actions entirely remotely so we can dial up the concurrency.
# We have platform-specific tests, so we want to execute the tests on all platforms using the strongest sandboxing available on each platform.
Expand All @@ -189,13 +187,12 @@ common:ci-windows-cross --strategy=TestRunner=local
# V8 embeds IsolateData offsets in snapshot builtins; Windows snapshots must be
# generated by a Windows mksnapshot binary rather than the Linux RBE host tool.
common:ci-windows-cross --strategy=V8Mksnapshot=local
common:ci-windows-cross --local_test_jobs=4
common:ci-windows-cross --local_test_jobs=8
common:ci-windows-cross --test_env=RUST_TEST_THREADS=1
# Native Windows CI still covers the PowerShell tests. The cross-built gnullvm
# binaries currently hang in PowerShell AST parser tests when those binaries are
# run on the Windows runner. Keep V8-backed code-mode tests enabled except for
# the hidden dynamic-tool callback test, which currently times out on Windows.
common:ci-windows-cross --test_env=CODEX_BAZEL_TEST_SKIP_FILTERS=powershell,suite::code_mode::code_mode_can_call_hidden_dynamic_tools
# Native Windows CI still covers the PowerShell parser-process tests. The
# cross-built gnullvm binaries currently hang in those tests when run on the
# Windows runner. This replaces the Windows skip list, so retain its exclusions.
common:ci-windows-cross --test_env=CODEX_BAZEL_TEST_SKIP_FILTERS=command_safety::powershell_parser::tests::,suite::code_mode::code_mode_can_call_hidden_dynamic_tools
common:ci-windows-cross --platforms=//:windows_x86_64_gnullvm
common:ci-windows-cross --extra_execution_platforms=//:rbe,//:windows_x86_64_msvc
common:ci-windows-cross --extra_toolchains=//:windows_gnullvm_tests_on_msvc_host_toolchain
Expand Down
1 change: 1 addition & 0 deletions .codespellignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
iTerm
iTerm2
numer
psuedo
SOM
te
Expand Down
23 changes: 0 additions & 23 deletions .codex/.gitignore

This file was deleted.

3 changes: 2 additions & 1 deletion .codex/environments/environment.toml
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,9 @@
version = 1
name = "codex"

# TODO(anp) make it optional to specify this field
[setup]
script = "python ./.codex/environments/setup.py"
script = ""

[[actions]]
name = "Run"
Expand Down
65 changes: 0 additions & 65 deletions .codex/environments/setup.py

This file was deleted.

63 changes: 0 additions & 63 deletions .codex/skills/PROVENANCE.md

This file was deleted.

41 changes: 35 additions & 6 deletions .codex/skills/babysit-pr/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,8 @@ Accept any of the following:
3. Inspect the `actions` list in the JSON response.
4. If `diagnose_ci_failure` is present, inspect failed run logs and classify the failure.
5. If the failure is likely caused by the current branch, patch code locally, commit, and push. Do not patch random flaky tests, CI infrastructure, dependency outages, runner issues, or other failures that are unrelated to the branch.
6. If `process_review_comment` is present, inspect surfaced review items and decide whether to address them.
7. If a review item is actionable and correct, patch code locally, commit, push, and then mark the associated review thread/comment as resolved once the fix is on GitHub.
6. If `process_review_comment` is present, inspect surfaced published review items and decide whether to address them.
7. If a review item is actionable and correct, patch code locally, commit, push, and then resolve the associated review thread only when allowed by the GitHub state mutation policy below.
8. Do not post replies to human-authored review comments/threads unless the user explicitly confirms the exact response. If a human review item is non-actionable, already addressed, or not valid, surface the item and recommended response to the user instead of replying on GitHub.
9. If the failure is likely flaky/unrelated and `retry_failed_checks` is present, rerun failed jobs with `--retry-failed-now`.
10. If both actionable review feedback and `retry_failed_checks` are present, prioritize review feedback first; a new commit will retrigger CI, so avoid rerunning flaky checks on the old SHA unless you intentionally defer the review change.
Expand Down Expand Up @@ -92,23 +92,52 @@ The watcher surfaces review items from:
- Inline review comments
- Review submissions (COMMENT / APPROVED / CHANGES_REQUESTED)

Only act on published feedback. Ignore review submissions in GitHub's `PENDING` state and inline
comments attached to those pending reviews. Do not mark pending review feedback as seen; it should
be eligible to surface after the reviewer submits the review.

It intentionally surfaces Codex reviewer bot feedback (for example comments/reviews from `chatgpt-codex-connector[bot]`) in addition to human reviewer feedback. Most unrelated bot noise should still be ignored.
For safety, the watcher only auto-surfaces trusted human review authors (for example repo OWNER/MEMBER/COLLABORATOR, plus the authenticated operator) and approved review bots such as Codex.
On a fresh watcher state file, existing pending review feedback may be surfaced immediately (not only comments that arrive after monitoring starts). This is intentional so already-open review comments are not missed.
On a fresh watcher state file, existing unaddressed published review feedback may be surfaced immediately (not only comments that arrive after monitoring starts). This is intentional so already-open review comments are not missed.

When you agree with a comment and it is actionable:

1. Patch code locally.
2. Commit with `codex: address PR review feedback (#<n>)`.
3. Push to the PR head branch.
4. After the push succeeds, mark the associated GitHub review thread/comment as resolved.
4. After the push succeeds, resolve the associated GitHub review thread only when allowed by the GitHub state mutation policy below.
5. Resume watching on the new SHA immediately (do not stop after reporting the push).
6. If monitoring was running in `--watch` mode, restart `--watch` immediately after the push in the same turn; do not wait for the user to ask again.

Do not post replies to human-authored GitHub review comments/threads automatically. If you disagree with a human comment, believe it is non-actionable/already addressed, or need to answer a question, report the item to the user with a suggested response and wait for explicit confirmation before posting anything on GitHub. If the user approves a response, prefix it with `[codex]` so it is clear the response is automated and not from the human user.
If the watcher later surfaces your own approved reply because the authenticated operator is treated as a trusted review author, treat that self-authored item as already handled and do not reply again.
If a code review comment/thread is already marked as resolved in GitHub, treat it as non-actionable and safely ignore it unless new unresolved follow-up feedback appears.

## GitHub State Mutation Policy

You can read any PR state you need for monitoring. Writes must comply with this policy.

You can push PRs to update the code under review or to force CI re-runs as described above.

You can resolve review comment threads from the human who requested babysitting or from the Codex
review bot. When resolving, leave a comment prefixed with `[from Codex]: ` and explain what changes
you made and which commit includes them. Don't touch review threads if other humans other than the
user who requested babysitting have participated.

Before making any changes, fetch the PR state yourself instead of relying on the PR watcher script's
output.

Unless explicitly asked, do not:

* comment on other humans' review threads, communicate with the user in chat instead
* resolve review threads from humans other than the user
* interact with humans other than the user
* mark PRs as drafts or ready for review
* close or reopen PRs

In general, never act on GitHub in ways that would make it hard to tell whether you or the user did
something visible to other humans. When in doubt, ask the user for clarification in chat.

## Git Safety Rules

- Work only on the PR head branch.
Expand All @@ -133,10 +162,10 @@ Use this loop in a live Codex session:
3. First check whether the PR is now merged or otherwise closed; if so, report that terminal state and stop polling immediately.
4. Check CI summary, new review items, and mergeability/conflict status.
5. Diagnose CI failures and classify branch-related vs flaky/unrelated. If the overall run is still pending but `failed_jobs` already includes a failed job, fetch that job's logs and diagnose immediately instead of waiting for the whole workflow run to finish. Patch only when the failure is branch-related.
6. For each surfaced review item from another author, patch/commit/push and then resolve it if it is actionable. If it is non-actionable, already addressed, or requires a written answer, surface it to the user with a suggested response instead of posting automatically. If a later snapshot surfaces your own approved reply, treat it as informational and continue without responding again.
6. For each surfaced review item from another author, patch/commit/push if it is actionable, then resolve it only when allowed by the GitHub state mutation policy above. If it is non-actionable, already addressed, or requires a written answer, surface it to the user with a suggested response instead of posting automatically. If a later snapshot surfaces your own approved reply, treat it as informational and continue without responding again.
7. Process actionable review comments before flaky reruns when both are present; if a review fix requires a commit, push it and skip rerunning failed checks on the old SHA.
8. Retry failed checks only when `retry_failed_checks` is present and you are not about to replace the current SHA with a review/CI fix commit. Do not make code changes for unrelated flakes or infrastructure failures just to get CI green.
9. If you pushed a commit, resolved a review thread, or triggered a rerun, report the action briefly and continue polling (do not stop). If a human review comment needs a written GitHub response, stop and ask for confirmation before posting.
9. If you pushed a commit, resolved an eligible review thread, or triggered a rerun, report the action briefly and continue polling (do not stop). If a human review comment needs a written GitHub response, stop and ask for confirmation before posting.
10. After a review-fix push, proactively restart continuous monitoring (`--watch`) in the same turn unless a strict stop condition has already been reached.
11. If everything is passing, mergeable, not blocked on required review approval, and there are no unaddressed review items, report that the PR is currently ready to merge but keep the watcher running so new review comments are surfaced quickly while the PR remains open.
12. If blocked on a user-help-required issue (infra outage, exhausted flaky retries, unclear reviewer request, permissions), report the blocker and stop.
Expand Down
2 changes: 1 addition & 1 deletion .codex/skills/babysit-pr/agents/openai.yaml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
interface:
display_name: "PR Babysitter"
short_description: "Watch PR review comments, CI, and merge conflicts"
default_prompt: "Babysit the current PR: monitor reviewer comments, CI, and merge-conflict status (prefer the watcher’s --watch mode for live monitoring); surface new review feedback before acting on CI or mergeability work, fix valid issues, push updates, and rerun flaky failures up to 3 times. Do not post replies to human-authored review comments unless the user explicitly confirms the exact response. Do not patch unrelated flaky tests, CI infrastructure, dependency outages, runner issues, or other failures that are not caused by the branch. Keep exactly one watcher session active for the PR (do not leave duplicate --watch terminals running). If you pause monitoring to patch review/CI feedback, restart --watch yourself immediately after the push in the same turn. If a watcher is still running and no strict stop condition has been reached, the task is still in progress: keep consuming watcher output and sending progress updates instead of ending the turn. Do not treat a green + mergeable PR as a terminal stop while it is still open; continue polling autonomously after any push/rerun so newly posted review comments are surfaced until a strict terminal stop condition is reached or the user interrupts."
default_prompt: "Babysit the current PR: monitor published reviewer comments, CI, and merge-conflict status (prefer the watcher’s --watch mode for live monitoring); ignore unpublished comments in pending GitHub reviews; surface new published review feedback before acting on CI or mergeability work, fix valid issues, push updates, and rerun flaky failures up to 3 times. Do not post replies to human-authored review comments unless the user explicitly confirms the exact response. Do not patch unrelated flaky tests, CI infrastructure, dependency outages, runner issues, or other failures that are not caused by the branch. Keep exactly one watcher session active for the PR (do not leave duplicate --watch terminals running). If you pause monitoring to patch review/CI feedback, restart --watch yourself immediately after the push in the same turn. If a watcher is still running and no strict stop condition has been reached, the task is still in progress: keep consuming watcher output and sending progress updates instead of ending the turn. Do not treat a green + mergeable PR as a terminal stop while it is still open; continue polling autonomously after any push/rerun so newly posted review comments are surfaced until a strict terminal stop condition is reached or the user interrupts."
3 changes: 3 additions & 0 deletions .codex/skills/babysit-pr/references/github-api-notes.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,9 @@ Reruns only failed jobs (and dependencies) for a workflow run.
- Review submissions:
- `gh api repos/{owner}/{repo}/pulls/<pr_number>/reviews?per_page=100`

Use each inline comment's `pull_request_review_id` to find its parent review. Ignore parent reviews
whose `state` is `PENDING`, along with their inline comments, until the review is submitted.

## JSON fields consumed by the watcher

### `gh pr view`
Expand Down
Loading
Loading