Skip to content
CAI
Software that uses CAICheck a score

openai/codex

68.7

Adequate · 28 September 2026

1031.8k

lines of production code

Rust

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Rust-based CLI agent platform that manages AI-driven code execution, sandboxing, and multi-agent collaboration. It provides a secure execution environment with platform-specific sandboxes, policy engines, and network controls to safely run commands and apply code patches. The architecture supports extensible plugins, local and remote model providers, and persistent session management with detailed telemetry and analytics.

How it got here

2025 — Rust CLI migration and build system overhaul

79 changes.

The project initiated a major migration of the Codex CLI from TypeScript to Rust, introducing the codex-rs codebase with comprehensive Bazel build support and hermetic infrastructure. This period involved stripping out the legacy TypeScript implementation and build tooling while simultaneously establishing new crates for core functionality, sandboxing, and protocol definitions. The work focused on laying the architectural groundwork for a secure, cross-platform Rust-native client alongside updated CI/CD and SDK integrations.

2026 — Modularization and security hardening

136 changes.

The project underwent extensive architectural refactoring, extracting core functionalities like state management, analytics, and tool handling into dedicated crates to improve modularity and maintainability. Concurrently, significant effort was directed toward security and reliability, introducing robust sandboxing, network policy enforcement, and comprehensive test coverage across Windows, Linux, and macOS environments.

Features

Add Bazel build targets for V8 and native voice runtime dependencies

This change introduces Bazel build infrastructure for the V8 JavaScript engine (rusty\_v8 v150.4.0) and the native voice runtime dependencies. For V8, it adds targets to select between prebuilt archives (with sandboxing and pointer compression enabled on Darwin and GNU Linux) and source-built archives (for musl Linux and Windows GNU), while also bundling a custom libc++ runtime to ensure ABI compatibility. For the voice runtime, it adds targets to fetch, verify, and prepare sources for GStreamer, GLib, Opus, and other native libraries, along with build tools like CMake and Ninja, enabling the subsequent compilation and packaging of the voice host.

_third\party · high confidence

Add LM Studio OSS provider support

Introduces a new local model provider for LM Studio, allowing users to run open-source models locally. The implementation includes a Bazel build target and a Rust client that verifies the LM Studio server is reachable, fetches available models, downloads missing models via the \lms\ CLI tool, and loads the selected model. This enables the \--oss\ flag to utilize a local LM Studio instance as the inference backend.

codex-rs/lmstudio · high confidence

Add ThreadManager sample crate for single-turn execution

A new \codex-thread-manager-sample\ binary is introduced to demonstrate how to initialize a Codex thread using \ThreadManager\ from \codex-core-api\, submit a single user turn, and print the final assistant message. The sample respects configured authentication (including \CODEX\_HOME\ credential stores) and allows overriding the model via the \--model\ flag or piping a prompt through stdin.

codex-rs/thread-manager-sample · high confidence

Add V8 proof-of-concept crate with sandbox verification

A new Rust crate, codex\_v8\poc, has been added to the codex-rs/v8-poc location to serve as a proof-of-consumer for the built V8 library. This crate exposes functions to retrieve the embedded V8 version and the Bazel target label, and specifically verifies whether the linked V8 library was built with the in-process sandbox enabled by checking the v8\\V8\\_IsSandboxEnabled symbol. The build configuration (BUILD.bazel) conditionally enables the 'sandbox' crate feature on non-MSVC platforms, and the included tests confirm that the Rust-side feature flag matches the actual linked V8 sandbox status, alongside basic JavaScript evaluation and CRDTP message parsing tests.

codex-rs/v8-poc · high confidence

Add codex-stdio-to-uds adapter for UNIX domain socket transport

Introduces a new \codex-stdio-to-uds\ utility that bridges standard input/output to a UNIX domain socket, enabling MCP servers to communicate via UDS for better process attachment and file-permission-based access control. The tool accepts a socket path argument and relays data bidirectionally, using a cross-platform async UDS implementation to support Windows. This change also adds Bazel build support for the crate and includes integration tests to verify the relay functionality.

codex-rs/stdio-to-uds · high confidence

Added script to regenerate app-server schema fixtures and Python SDK types

A new Python script, write\_schema\_fixtures.py, has been added to the app-server-protocol scripts directory. This tool allows users to regenerate vendored app-server schema fixtures by invoking a specific Rust test, and optionally updates the Python SDK types by running the SDK's artifact update script. It supports configuration via environment variables and command-line arguments for the schema root, Prettier executable, and experimental export regeneration.

codex-rs/app-server-protocol/scripts · high confidence

App Server v2 TypeScript protocol schema introduced

The app-server-protocol TypeScript definitions for version 2 have been added to the \codex-rs/app-server-protocol/schema/typescript/v2\ directory. This change introduces the foundational type system for the v2 API, including core account and authentication types (e.g., \Account\, \AccountUpdatedNotification\), app and connector metadata structures (e.g., \AppInfo\, \AppBranding\), and configuration schemas for permissions, approvals, and network requirements. These types serve as the contract for the v2 app-server interface.

codex-rs/app-server-protocol/schema/typescript/v2 · high confidence

App-server protocol TypeScript schema generated

The TypeScript schema types for the app-server protocol have been generated and committed to the \codex-rs/app-server-protocol/schema/typescript\ directory. This update introduces a comprehensive set of TypeScript definitions—including request, response, and notification types—that reflect the current state of the app-server API surface. For users, this ensures that TypeScript clients have accurate, up-to-date type information for interacting with the app-server, covering features such as thread management, plugin operations, file system access, and authentication modes.

codex-rs/app-server-protocol/schema/typescript · high confidence

Bounded, shared Git-root discovery for metadata enrichment

A new \git-discovery\ utility has been added to manage optional Git metadata enrichment. It implements a bounded, shared discovery mechanism that limits concurrent filesystem probes (defaulting to 8) and deduplicates requests for the same working directory. The implementation ensures that blocked probes do not delay application shutdown by running in detached threads and allowing cancellation of waiters without blocking the runtime, while avoiding caching of completed results to handle repository changes dynamically.

codex-rs/utils/git-discovery · high confidence

Centralized feature flag system with structured configuration support

The feature flag system has been refactored into a dedicated crate with a unified registry, introducing structured TOML configuration for complex features like Guardian v2, Code Mode, and Multi-Agent v2. Users can now configure detailed settings (e.g., token limits, review thresholds, tool namespaces) alongside simple boolean toggles. The system also supports legacy key aliases for backward compatibility and enforces strict validation for new configuration shapes.

codex-rs/features/src · high confidence

Enhanced feedback diagnostics and attachment handling

The feedback module now collects and attaches connectivity diagnostics (specifically proxy environment variables) to help troubleshoot network issues, and it automatically includes evidence of failed Guardian safety reviews in diagnostic reports. Additionally, the system supports attaching compressed rollout data (zstd-compressed JSONL) to feedback submissions, ensuring that large diagnostic payloads are handled efficiently without materializing temporary files unnecessarily.

codex-rs/feedback · high confidence

Expanded backend model support for rate limits, usage analytics, and cloud tasks

The \codex-backend-openapi-models\ crate now exposes a comprehensive set of generated Rust types that enable richer interaction with the backend API. Users can now access detailed rate-limiting information, including specific \RateLimitReachedType\ distinctions (such as credit depletion versus usage limits) and per-plan \PlanType\ enums covering new tiers like ProMax, EduPlus, and Enterprise variants. The models also introduce structured analytics for tracking workspace and credit usage, support for retrieving configuration bundles and files, and full type definitions for cloud-based code tasks and their associated Git pull requests.

codex-rs/codex-backend-openapi-models · high confidence

Extracted context-fragments crate for structured conversation context

The \codex-rs/context-fragments\ crate has been introduced to centralize the handling of contextual conversation data. This new module provides a unified framework for managing various context types—including additional user/developer context, answered questions, and recap prompts—by classifying them with specific content kinds and applying consistent token-budget truncation. It also introduces \AnnotatedContent\ to pair model-visible content with harness-owned classifications, ensuring that metadata and content kinds are preserved when messages are processed or truncated.

codex-rs/context-fragments · high confidence

Extracted readiness utility into a dedicated crate with Bazel build support

The readiness flag logic, which provides token-based authorization and async waiting for service readiness, has been extracted into a new dedicated crate at codex-rs/utils/readiness. This change includes the implementation of the ReadinessFlag struct and its associated traits, along with a new BUILD.bazel file to enable building this component using the Bazel build system.

codex-rs/utils/readiness · high confidence

Git attribution extension adds Codex authorship to commits and PRs

A new git-attribution extension has been introduced to automatically append Codex attribution to agent-generated git commits and pull requests. The extension integrates as a context contributor that resolves an attribution policy from the backend (checking the \commit\_attribution\_enabled\ setting) and injects instructions into the developer world state. When enabled, it instructs the model to add the \Co-authored-by: Codex \<[e-mail redacted]\>\ trailer to commit messages and the \Generated with \Codex\.\ marker to pull request bodies, handling deduplication and respecting workspace-level enable/disable states. The implementation includes retry logic for policy resolution and handles authentication recovery.

codex-rs/ext/git-attribution · high confidence

Global user instructions are now loaded from Codex home directory

The Codex home module now provides a \CodexHomeUserInstructionsProvider\ that loads global user instructions from \AGENTS.md\ (or \AGENTS.override.md\) in the Codex home directory. The provider implements a caching strategy that retains the last successfully loaded instructions if a refresh fails, and it prioritizes the override file over the default. This change introduces the mechanism for loading and caching these instructions, which will be used to configure the model's behavior.

codex-rs/codex-home · high confidence

Guardian v2 async scoring extension introduced

The Guardian v2 extension now includes an asynchronous scoring module that classifies tool calls in the background and caches risk scores to speed up approval decisions. This module handles action rendering with token-budget enforcement, manages cached evidence validity against authorization and context changes, and integrates with the approval reviewer to allow fast-path approvals when scores are still valid. It also supports configurable review thresholds, model-specific policy overrides, and transcript retention settings.

codex-rs/ext/guardian-v2 · high confidence

Initial import of the Rust CLI implementation (codex-rs)

This change introduces the initial codebase for the Rust-based Codex CLI, including the core source files, Bazel build configuration, Nix build definitions, and a Windows setup script. It establishes the project structure with configuration files for Rust tooling (clippy, rustfmt, cargo-deny) and documentation, laying the groundwork for the CLI's development and distribution.

codex-rs · high confidence

Introduce AbsolutePathBuf for safe, normalized path handling

The \codex-rs/utils/absolute-path\ crate now provides the \AbsolutePathBuf\ type, which guarantees that paths are absolute and normalized without requiring filesystem access for basic operations. This utility supports home-directory expansion (tilde), resolves relative paths against a specified base or the current working directory, and handles platform-specific nuances such as Windows drive prefixes and UNC namespace normalization. It also includes logic to resolve top-level system aliases (like macOS \/var\ to \/private/var\) while preserving logical paths for mutable symlinks and missing descendants, ensuring consistent path behavior across different operating systems.

codex-rs/utils/absolute-path · high confidence

Introduce Bazel build support for the Linux sandbox

The Linux sandbox crate now includes a \BUILD.bazel\ file and a \bazel\_bwrap.rs\ module to enable building with Bazel. This adds a Bazel-specific mechanism to locate the bundled \bubblewrap\ binary via runfiles during debug builds, ensuring the sandbox helper can find its dependencies when built in a Bazel environment.

codex-rs/linux-sandbox · high confidence

Introduce Bazel build system for the Codex CLI

The Codex CLI now supports building with Bazel, adding a \BUILD.bazel\ file that defines the \codex\ binary and its dependencies, including the \bwrap\ sandbox helper. A \build.rs\ script ensures macOS builds link Objective-C libraries correctly, and an end-to-end benchmark harness is added to measure CLI startup performance via \codex --help\.

codex-rs/cli · high confidence

Introduce Bazel build system for the repository

The repository now supports building with Bazel, introducing a comprehensive build configuration including \MODULE.bazel\ with pinned dependencies (such as \rules\_rs\ 0.0.96, \llvm\ 0.8.11, and \bazel\_skylib\ 1.9.0), a \BUILD.bazel\ file defining local platforms and toolchains, and a \.bazelrc\ file configuring remote execution via BuildBuddy, CI-specific settings, and Clippy linting rules. This change adds the necessary infrastructure for hermetic builds, remote caching, and cross-platform compilation (including Windows MSVC and gnullvm support) alongside the existing Cargo-based workflow.

(repo-wide) · high confidence

Introduce Code Mode host protocol with gRPC and JSON-IPC transports

This change establishes the \codex-rs/code-mode-protocol\ crate, defining the wire protocol for the standalone Code Mode host. It introduces a gRPC service (\CodeModeHost\) for stateful JavaScript execution and tool call delegation, alongside a JSON-based IPC transport using length-prefixed framing for host-client communication. The protocol supports session management, tool execution with configurable yield times and output token budgets, and early observation yielding, enabling the Code Mode host to run exclusively and handle nested tool calls efficiently.

codex-rs/code-mode-protocol · high confidence

Introduce GPT-6-Astra model with enhanced reasoning and multi-agent capabilities

The models manager now includes a new 'GPT-6-Astra' model entry in its bundled catalog. This model supports a maximum context window of 872,000 tokens, parallel tool calls, and multi-agent collaboration (v2) with 'xhigh' reasoning effort. It also introduces granular reasoning level controls (from 'low' to 'ultra') and specific instructions for persistent mode, auto-review policies, and computer/browser use confirmation.

codex-rs/models-manager · high confidence

Introduce Ollama integration for local OSS models

Added a new \codex-rs/ollama\ crate that enables the use of local Ollama instances as an open-source model provider. This includes an \OllamaClient\ that routes requests through the shared HTTP client, supports both native Ollama and OpenAI-compatible endpoints, and verifies server reachability. The integration automatically pulls the default \gpt-oss:20b\ model if missing and enforces a minimum Ollama version (0.13.4) to ensure support for the Responses API. Progress reporting for model pulls is provided via CLI and TUI reporters, and the build system now includes a Bazel \BUILD.bazel\ file for the crate.

codex-rs/ollama · high confidence

Introduce PathUri for cross-platform path handling

The \codex-rs/utils/path-uri\ crate introduces a new \PathUri\ type that represents file paths as immutable, cross-platform \file:\ URIs. This change enables the system to handle paths from different operating systems (POSIX and Windows) within a single, consistent format, preserving special filesystem subpaths and normalizing Windows drive letters. It also adds \LegacyAppPathString\ to safely bridge legacy API path strings with the new URI-native system, ensuring that path conventions are respected during serialization and resolution.

codex-rs/utils/path-uri · high confidence

Introduce Python automation for macOS notarization, release publishing, and package verification

This change adds a suite of Python scripts to the CI/CD pipeline to streamline the release process. It introduces \notarize\_with\_akv.py\ to handle macOS code-signing notarization using Azure Key Vault, \publish\_r2\_release.py\ to mirror GitHub release assets to Cloudflare R2 with integrity verification, and \provisioned\_macos\_cli\_package.py\ to prepare and verify the macOS CLI bundle. Additionally, it adds \rusty\_v8\_module\_bazel.py\ to validate V8 checksums, \check\_blob\_size.py\ to enforce repository size policies, and \codex\_package\ utilities (including \cargo.py\, \dotslash.py\, and \smoke\_tests/fixtures.py\) to build, fetch, and test the Codex package artifacts.

python · high confidence

Introduce ThreadStore as the central persistence boundary for Codex threads

The \codex-rs/thread-store\ crate is introduced to serve as the storage boundary for Codex threads, defining the \ThreadStore\ trait along with local and in-memory implementations. This change centralizes thread persistence by providing a canonical history append API (\append\_items\) and a single metadata write entry point (\update\_thread\_metadata\), ensuring that application code treats \ThreadId\ as the only durable handle regardless of the backing store. The local implementation (\LocalThreadStore\) persists history through \codex-rollout\ JSONL files and queryable metadata via a SQLite state database, while \LiveThread\ manages the active session persistence lifecycle. This establishes a storage-neutral interface that decouples session logic from storage details, supporting features like paginated history, thread archiving, and metadata synchronization.

codex-rs/thread-store · high confidence

Introduce TypeScript SDK for the Codex agent

The TypeScript SDK now provides a programmatic interface to the Codex agent, allowing developers to start and resume conversation threads, send text and local image inputs, and receive structured event streams or completed turn results. The SDK exposes configuration options for model selection, sandbox modes, reasoning effort levels, web search, and approval policies, while also supporting structured output schemas and cancellation via AbortSignal.

sdk/typescript · high confidence

Introduce Unix shell-escalation protocol and execve wrapper

This change introduces a new \codex-shell-escalation\ crate that implements a Unix-specific protocol for intercepting and controlling shell command execution. It includes a patched version of \zsh\ (via \patches/zsh-exec-wrapper.patch\) that supports an \EXEC\_WRAPPER\ environment variable, allowing the shell to delegate \execve\ calls to a Rust-based \codex-execve-wrapper\ binary. This wrapper communicates with an escalation server over a socket to decide whether to run a command directly (\Run\), escalate it to the server for execution (\Escalate\), or deny it (\Deny\). The crate exposes the \EscalateServer\, \EscalationSession\, and \ShellCommandExecutor\ traits, enabling the platform to enforce security policies and manage sandbox configurations for shell commands.

codex-rs/shell-escalation · high confidence

Introduce Windows sandbox provisioning service

Adds a new Windows-specific service that manages sandbox provisioning via authenticated local IPC. The service validates client identity, enforces managed machine policies (such as network access and proxy port restrictions), and handles the secure setup and lifecycle of sandbox environments, including directory pinning and cleanup.

codex-rs/windows-sandbox-service · high confidence

Introduce \`codex exec\` subcommand with human-readable and JSONL output modes

The \codex exec\ subcommand is now available for running non-interactive agent sessions. It supports two output modes: a default human-readable mode that prints agent responses and command status to stderr (writing only the final message to stdout), and a \--json\ mode that emits structured JSONL events to stdout for programmatic consumption. The command includes subcommands for resuming previous sessions (\resume\), forking existing sessions (\fork\), and running code reviews (\review\), along with flags for configuration isolation (\--ignore-user-config\, \--ignore-rules\), ephemeral execution (\--ephemeral\), and output control (\--output-last-message\, \--output-schema\).

codex-rs/exec · high confidence

Introduce agent graph store for thread-spawn topology

A new \agent-graph-store\ crate provides a storage-neutral interface for persisting the parent/child topology of spawned threads. It defines the \AgentGraphStore\ trait and a SQLite-backed \LocalAgentGraphStore\ implementation that manages thread-spawn edges (upserting, updating status, and listing children/descendants with optional status filters) using the existing state runtime.

codex-rs/agent-graph-store · high confidence

Introduce agent message-board extension with in-memory and SQLite backends

Adds a new agent message-board extension that enables agents to create channels, post messages, subscribe to discussions, and search content. The extension provides a shared \AgentMessageBoard\ trait with two concrete implementations: an in-memory board for ephemeral training sessions and a persistent SQLite-backed board for long-running multi-agent runtimes. It installs model tools for board operations, handles board lifecycle (creation, deletion, and recovery from corruption), and manages notification delivery to other agents while respecting subscription states and author exclusions.

codex-rs/ext/agent-message-board · high confidence

Introduce arg0 crate for unified process dispatch and PATH management

The \codex-rs/arg0\ crate is introduced to centralize the handling of special process invocations (such as \apply\_patch\, sandbox helpers, and exec-server utilities) and to manage the \PATH\ environment variable with persistent aliases. This change consolidates logic previously scattered across other components, ensuring that helper executables are correctly located and that the process can dispatch to the appropriate internal handler based on its own executable name (\argv\[0\]\).

codex-rs/arg0 · high confidence

Introduce argument-comment lint to enforce parameter naming in Rust calls

A new Rust lint tool has been added to the \tools/argument-comment-lint\ directory to improve code readability by requiring explicit parameter names in function and method calls. The tool introduces two checks: \ARGUMENT\_COMMENT\_MISMATCH\, which warns when a \/\param\/\ comment does not match the actual parameter name, and \UNCOMMENTED\_ANONYMOUS\_LITERAL\_ARGUMENT\, which encourages adding comments to bare literal arguments like \None\ or booleans. The implementation includes a standalone binary runner that bundles the necessary Dylint infrastructure and a comment parser to extract parameter names from inline comments.

tools/argument-comment-lint · high confidence

Introduce argument-comment-lint tool with Bazel aspect integration

The repository now includes a new Rust linting tool, \argument-comment-lint\, located in \tools/argument-comment-lint\. This tool enforces the use of \/\param\/\ comments on anonymous literal arguments (like \None\, \true\, \false\) and validates that such comments match the actual parameter names. It is integrated into the build system via a native Bazel aspect (\lint\_aspect.bzl\) that runs the lint during compilation, and is also available via Python wrappers (\run.py\, \run-prebuilt-linter.py\) for local development. The tool supports pre-built binaries for macOS, Linux, and Windows via DotSlash, and includes a set of UI tests to verify its behavior.

tools · high confidence

Introduce bounded, terminal-native Mermaid diagram renderer

A new standalone Rust crate, codex-mermaid, renders a bounded subset of Mermaid diagrams as plain Unicode text in the terminal. It supports flowcharts (including stadium nodes, quoted labels, and ampersands), sequence diagrams, state diagrams, class diagrams, and ER diagrams, with explicit limits on source size (16 KiB), node/edge counts, and canvas width. The renderer is theme-independent, returning semantic spans so callers can apply their own styling, and it performs no I/O or external runtime dependencies.

codex-rs/mermaid · high confidence

Introduce cloud plugin discovery and executor plugin MCP integration

The MCP extension now supports discovering and projecting cloud-based plugins at the start of each turn, gated by the Plugins feature flag, and integrates with executor plugins to load their declared MCP server configurations from the selected environment. This change adds a new \HostedPluginRuntimeExtension\ that registers the Codex Apps MCP server when the Apps feature is enabled, and introduces a \PluginContributor\ that coordinates cloud catalog refreshes and executor plugin metadata loading, ensuring that plugin contributions are properly scoped to the thread and respect authentication state changes.

codex-rs/ext/mcp · high confidence

Introduce cloud tasks TUI and CLI with environment discovery and mock client

The \codex-rs/cloud-tasks\ crate now provides a terminal UI and CLI for managing Codex Cloud tasks, including commands to list, view status, apply diffs, and execute new tasks. Environment discovery is routed through the shared HTTP client pool, automatically selecting environments based on local Git repository origins or user preference. A dedicated mock client (\codex-cloud-tasks-mock-client\) is included to support local development and testing without hitting the real backend. The TUI features a scrollable diff viewer that correctly handles halfwidth Japanese sound marks, and the CLI supports branch overrides and best-of-N attempt selection.

codex-rs/cloud-tasks · high confidence

Introduce cloud-config crate for managed bundle lifecycle and caching

The new \codex-rs/cloud-config\ crate centralizes the retrieval, caching, and validation of cloud-delivered configuration bundles for eligible accounts (Business, Education, and Enterprise). It fetches bundles from the backend, stores them in an HMAC-signed on-disk cache scoped to the authenticated user and account, and enforces a 60-minute TTL. The service layer manages startup loading with a 20-second timeout, retries transient failures up to five times, and runs background cache refreshes every 15 minutes. Bundles are validated against managed requirements and model-provider definitions before being exposed to the rest of the application.

codex-rs/cloud-config · high confidence

Introduce cloud-tasks-client library for backend task operations

This change adds the \codex-rs/cloud-tasks-client\ crate, providing a new HTTP-based client for interacting with the cloud tasks backend. It defines the \CloudBackend\ trait and \HttpClient\ implementation to support listing tasks, retrieving summaries and diffs, managing turn attempts, and applying code changes (including dry-run preflight checks). The client handles authentication via \SharedAuthProvider\ and exposes structured types for task status, apply outcomes, and diff summaries.

codex-rs/cloud-tasks-client · high confidence

Introduce codex-ansi-escape crate for safe ANSI-to-TUI conversion

A new Rust crate, codex-ansi-escape, has been added to provide helper functions for converting ANSI escape sequences into ratatui text structures. The crate exposes \ansi\_escape\ and \ansi\_escape\_line\ functions that wrap the \ansi\_to\_tui\ library, automatically expanding tab characters into spaces to prevent visual artifacts in transcript views and handling parsing errors by logging and panicking rather than returning errors to the caller. A Bazel build file (\BUILD.bazel\) is also included to integrate the crate into the build system.

codex-rs/ansi-escape · high confidence

Introduce codex-api crate as the dedicated wire-level layer for Codex/OpenAI APIs

The \codex-api\ crate is introduced to centralize the HTTP and WebSocket transport logic for the Codex platform. It hosts the request/response models and builders for the Responses API, Memory Summarize, Images, Realtime (WebRTC and WebSocket), and Search endpoints. This layer encapsulates provider configuration, authentication header injection, retry tuning, and SSE stream parsing into typed \ResponseEvent\ streams, serving as the foundational wire-level interface consumed by \codex-core\ for all API interactions.

codex-rs/codex-api · high confidence

Introduce codex-client as a shared HTTP transport layer with retry and SSE utilities

The codex-client crate is introduced as a higher-level request policy layer built on top of codex-http-client, providing reusable utilities for retry logic (including configurable policies, backoff, and jitter), Server-Sent Events (SSE) stream handling with idle timeouts, and request telemetry callbacks. This change extracts shared HTTP transport behavior into a dedicated module, allowing consumers to incrementally migrate to codex-http-client while standardizing how API clients handle retries, streaming, and observability.

codex-rs/codex-client · high confidence

Introduce codex-core-api as the public facade for thread management

A new \codex-rs/core-api\ crate has been added to serve as the public facade for thread management APIs built on \codex-core\. This crate re-exports key types, configuration structures, and services from underlying modules—including \codex\_core\, \codex\_config\, \codex\_exec\_server\, \codex\_extension\_api\, \codex\_login\, and \codex\_protocol\—providing a unified entry point for host applications to access thread management, authentication, environment configuration, and extension capabilities.

codex-rs/core-api · high confidence

Introduce codex-mcp crate for MCP server management

This change extracts the MCP server management logic into a new \codex-mcp\ crate. The new module provides configuration parsing for Agent Plugins MCP servers, manages MCP server registrations and catalogs with source-based precedence, handles authentication elicitation and auth-change notifications, and maintains immutable bindings for tool execution and resource access.

codex-rs/codex-mcp · high confidence

Introduce codex-network-proxy for local network policy enforcement

A new local network policy enforcement proxy is introduced, providing HTTP (default 127.0.0.1:3128) and SOCKS5 (default 127.0.0.1:8081) listeners. It enforces allow/deny domain policies, supports a 'limited' mode for read-only access, and handles HTTPS MITM with managed CA trust. The proxy includes credential brokerage for tunnel protocols, structured policy decision signaling, and OTEL audit logging, configurable via \config.toml\ or a standalone JSON file.

codex-rs/network-proxy · high confidence

Introduce codex-protocol crate for shared type definitions

The \codex-rs/protocol\ crate has been added to centralize the type definitions used by the Codex CLI. This new crate defines the internal types for communication between \codex-core\ and \codex-tui\, as well as the external types used with the \codex app-server\. It includes foundational types such as \PlanType\ for account plans, \AgentPath\ for multi-agent pathing, and \GuardianAssessmentAction\ for approval workflows, ensuring a minimal-dependency, shared contract for the system's protocol.

codex-rs/protocol · high confidence

Introduce codex-responses-api-proxy with npm distribution and Bazel build support

The responses-api-proxy is now available as a standalone Rust binary with an npm package (@openai/codex-responses-api-proxy) for easy installation on macOS, Linux, and Windows. The proxy acts as a strict HTTP forwarder for POST requests to /v1/responses, injecting the Authorization header from stdin and rejecting all other requests with 403. It supports dumping request/response pairs to JSON files for debugging, writing server info (port and PID) to a file, and an optional HTTP shutdown endpoint. The build system now includes Bazel support via a new BUILD.bazel file.

codex-rs/responses-api-proxy · high confidence

Introduce codex-rs/chatgpt crate for ChatGPT backend integration and patch application

This change introduces the new \codex-rs/chatgpt\ crate, which provides the core infrastructure for interacting with the ChatGPT backend API and applying agent-generated patches. It adds a \chatgpt\_client\ module that manages a cached HTTP client, enforces Codex backend authentication, and attaches the \OAI-Product-Sku: codex\ header to requests. The crate exposes a \connectors\ module to list and merge directory and plugin connectors, and an \apply\_command\ module that retrieves task diffs from the backend and applies them to the local repository via Git. An end-to-end test suite validates the patch application logic, including success cases and merge conflict handling.

codex-rs/chatgpt · high confidence

Introduce codex-utils-cargo-bin for cross-build test helpers

Adds a new utility crate that provides \cargo\_bin\ and \find\_resource!\ helpers to resolve test binaries and fixtures consistently across Cargo and Bazel builds. The \cargo\_bin\ function transparently handles environment variables and Bazel runfiles manifests to locate built binaries, while the \find\_resource!\ macro resolves test data paths using the runfiles manifest when available or falling back to Cargo manifest directories otherwise. Additionally, it includes platform-specific executable fixture creation logic to avoid Linux ETXTBSY races during test setup.

codex-rs/utils/cargo-bin · high confidence

Introduce dedicated Agent Identity crate for secure agent registration and authentication

A new \codex-rs/agent-identity\ crate has been added to handle the lifecycle of agent identities, including registration, JWT verification, and task signing. This component enables agents to securely register with the backend using Ed25519 keys, verify their identity via JWTs signed by the server, and sign task assertions for execution. It supports both production and staging environments, integrating with the shared HTTP client for network operations and defining specific constants for timeouts and API endpoints.

codex-rs/agent-identity · high confidence

Introduce dedicated memory write crate with v2 extraction and rate-limit guards

The \codex-rs/memories/write\ crate is introduced to own the memory write path, including the startup pipeline, Phase 1 and Phase 2 prompt rendering, extension pruning, and workspace diffing. It adds a rate-limit guard that skips memory startup when Codex rate limits are below a configured threshold, and implements memory v2 extraction that produces summary-only outputs instead of raw memories. The crate also seeds ad-hoc extension instructions, prunes old extension resources, and enforces workspace diffing and consolidation artifacts for memory v2.

codex-rs/memories/write · high confidence

Introduce dedicated plugin crate with capability summaries and bundled hook allowlisting

The \codex-rs/plugin\ crate is extracted to centralize plugin package models, identifiers, and telemetry summaries. It introduces \PluginCapabilitySummary\ to aggregate a plugin's skills, MCP servers, and app connectors, and adds \PluginLoadOutcome\ to manage active plugins and their derived capabilities. A new bundled hook allowlist (\bundled\_hooks.rs\) authorizes specific cleanup hooks for bundled plugins (e.g., browser, chrome, computer-use) to run on stop/interrupt events, ensuring proper cleanup for these internal tools.

codex-rs/plugin · high confidence

Introduce durable user-message queue extension

A new queue extension (\codex\_queue\_extension\) is added to persist and dispatch user messages across process restarts or external writes. The extension registers a lifecycle contributor that monitors for idle threads and new thread creations, then automatically submits queued items when the thread becomes available. It includes a background watcher that polls for external message changes every 10 seconds to ensure cross-process consistency, and enforces input size limits and validation before submission.

codex-rs/ext/queue · high confidence

Introduce exec-server protocol crate with capability discovery, network policy, and bounded JSON-RPC

The exec-server-protocol crate now defines the JSON-RPC wire contracts for the executor, introducing V2 capability discovery (capabilities/discoverV2) to inventory plugins and skills, an environment config read endpoint (environmentConfig/read) to fetch executor-local TOML layers, and network policy request/decision methods (network/policyRequest, network/policyDecision) to audit and enforce network access. The protocol also exposes environment info and status, process lifecycle methods (start/read/write/signal/terminate/output/exited/closed), filesystem operations (including a bounded walk), and HTTP request streaming, while adding a ProcessId type and environment capabilities flags (e.g., capability\_discovery\_v2, environment\_config\_read, sandboxed\_file\_streaming, shell\_snapshot\_v2, windows\_mxc). To protect against resource exhaustion, JSON-RPC decoding is bounded to 256,000 value nodes and streamed HTTP response bodies are limited to 1 MB per delta, with tests verifying stable JSON shapes and rejection of compact-array heap amplification.

codex-rs/exec-server-protocol · high confidence

Introduce experimental API gating and precomputed protocol schema exports

The app-server-protocol crate now supports marking protocol types and fields as experimental via a new \ExperimentalApi\ trait and \\#\[experimental\]\ derive macro, allowing the system to track and gate unstable features. To improve build performance and consistency, the crate now ships with precomputed, zstd-compressed TypeScript and JSON schema exports that are decompressed and written to disk at runtime, replacing on-the-fly generation for standard builds. Additionally, a new \export\_user\_verification\ module filters the \openai/userVerification\ mode from stable elicitation exports, ensuring that opt-in verification features remain excluded from stable client contracts while remaining available in experimental builds.

codex-rs/app-server-protocol · high confidence

Introduce gRPC transport for the code-mode host

The code-mode host now supports a gRPC transport layer, enabling remote code-mode sessions to be managed and executed over gRPC. This change adds the \GrpcCodeModeHost\ service implementation, along with modules for session state management, event streaming, tool call routing, and protocol conversions. It includes validation for identifiers and tool filters, enforces frame size limits, and preserves execution timing and trace context across the transport boundary.

codex-rs/code-mode-host · high confidence

Introduce gRPC-backed code-mode sessions

Code-mode sessions can now run over a gRPC transport in addition to the existing WebSocket path. This adds a new gRPC session provider and client implementation in the code-mode crate, including callback handling, tool-call completion, request deadline enforcement, and generation-aware cell ID mapping to support host restarts and reconnections. Users benefit from more robust session management and better error preservation for large tool outputs when using the gRPC backend.

codex-rs/code-mode · high confidence

Introduce history and notes tools for token-budget sessions

A new extension provides private, model-only history and notes tools (list, read, search, write) that allow the model to recover context and maintain notes across context-window resets. The extension is enabled via the \use\_history\_notes\_extension\ config flag and is scoped to token-budget sessions using the OpenAI provider. It injects a thread hint into the context window to surface recent notes, forwards truncation policies to the backend, and encrypts sensitive arguments for specific endpoints. Image attachments from history are preserved and forwarded to the model using a shared \ImageReference\ type, while backend errors are sanitized and thread-hint outcomes are tracked for analytics.

codex-rs/ext/history-notes · high confidence

Introduce macOS user verification with Secure Enclave signing

The codex-rs/user-verification crate now provides a platform-specific user-verification provider for macOS that creates and manages P-256 keys in the Secure Enclave, enforces biometric access via LocalAuthentication, and signs server challenges. It exposes a stable Rust API (UserVerificationProvider) with credential lifecycle operations (status, ensure\_key, delete, verify), cancellation guards, and a file-based lifecycle lock to serialize operations across processes. On non-macOS platforms, the same API is available but returns provider-unavailable errors, ensuring consistent behavior across builds.

codex-rs/user-verification · high confidence

Introduce managed app-server daemon for background lifecycle and remote control

A new \codex-app-server-daemon\ package has been added to manage the app-server as a background service on Linux, macOS, and Windows. This daemon provides lifecycle commands (start, stop, restart, update) and persists remote-control settings, allowing remote clients like desktop and mobile apps to manage the server. It handles platform-specific process management, including PID tracking, graceful shutdowns with configurable grace periods, and automatic updates. On Windows, it ensures non-elevated launches and handles detached process constraints.

codex-rs/app-server-daemon · high confidence

Introduce managed worktree isolation and lifecycle management

The \codex-rs/worktree\ library now provides a \WorktreeManager\ that creates isolated Git worktrees for agents, ensuring they run without inheriting repository hooks, filters, or fsmonitor helpers. It manages the worktree lifecycle (creation, listing, and removal) and supports thread ownership binding via \codex-thread.json\ metadata. Configuration is shared with the Desktop client, allowing users to customize the worktree root, retention count, and auto-cleanup behavior.

codex-rs/worktree · high confidence

Introduce native Windows MXC sandbox backend

Added a new \mxc-sandbox\ crate that provides a native Windows sandbox backend using Microsoft's MXC \BaseContainerRunner\. This backend routes commands through the Codex executable into MXC, enforcing filesystem permissions via canonical permission profiles and supporting managed network access with loopback proxy listeners. It includes a bounded environment transport to handle large launch payloads, validates Unicode path requirements, and respects explicit filesystem denials and volume grants. The feature is opt-in via the \features.prefer\_mxc\ configuration flag for local Windows execution, while remote executors remain unaffected.

codex-rs/mxc-sandbox · high confidence

Introduce private voice-host process with WebRTC and GStreamer audio pipeline

The voice-host component establishes a separate, inherited-pipe lifecycle process that manages local audio devices and WebRTC negotiation. It initializes a bundled GStreamer runtime to handle bounded Opus RTP capture and playback, connecting microphone input to speaker output via a bounded queue system that preserves audio across pauses and packet bursts. The process exposes a JSON-over-pipe API for lifecycle management (hello, ready, initializeRuntime, close) and transport negotiation (startTransport, applyAnswer), allowing the parent application to control audio controls and device states while keeping the native audio dependencies isolated from the main binary.

codex-rs/voice-host · high confidence

Introduce process-hardening crate with Bazel build support

Added a new \codex-process-hardening\ crate that provides a \pre\_main\_hardening()\ function to be called before \main()\. This function hardens the process by disabling core dumps, preventing ptrace attachment (on Linux, macOS, FreeBSD, and OpenBSD), and removing dangerous environment variables like \LD\PRELOAD\ and \DYLD\\*\. The crate includes platform-specific implementations for Linux, macOS, BSDs, and a stub for Windows, along with tests ensuring correct handling of non-UTF-8 environment variables. A Bazel build file (\BUILD.bazel\) was added to support building this crate within the Bazel build system.

codex-rs/exec-server, codex-rs/process-hardening · high confidence

Introduce real-time voice session support via WebRTC and a native voice host

This change adds a new \realtime-webrtc\ crate that enables real-time voice conversations. It introduces a \RealtimeWebrtcSession\ API for starting sessions, negotiating WebRTC transport, and managing audio controls (microphone mute, speaker suppression) with ordered command queuing. The implementation relies on a separate native \codex-voice-host\ process for media handling, communicating via a bounded framed IPC protocol. It includes lifecycle management for the helper, runtime initialization for GStreamer, and specific support for Linux ALSA plugin discovery. The session handles offer/answer negotiation, device opening, and audio state inspection, while ensuring sensitive data like SDP credentials are redacted in diagnostics.

codex-rs/realtime-webrtc · high confidence

Introduce remote agent message board client with secure SSE handling

Added a new \RemoteAgentMessageBoard\ client that implements the existing board contract over an HTTP API, allowing the backend to be deployed independently of Codex. The client validates HTTP(S) endpoints and credentials at construction, uses bearer authentication for all requests, and includes strict bounds on Server-Sent Events (SSE) frames to prevent resource exhaustion and malformed UTF-8 issues during live notification streams.

codex-rs/agent-message-board-client · high confidence

Introduce rmcp-client crate with modern MCP protocol support and enterprise OAuth

The new rmcp-client crate provides a Rust-based Model Context Protocol (MCP) client implementation, including a Bazel build configuration and a suite of test servers (stdio, streamable HTTP, and MCP 2026 discovery) for integration testing. It adds support for the MCP 2026-07-28 protocol version, modern elicitation handling (including OpenAI form extensions), and robust enterprise OAuth policies with strict credential destination validation and identity assertion (ID-JAG) verification. The client also features bounded stdio transport to prevent resource exhaustion and dedicated services for managing user verification and authentication status.

codex-rs/rmcp-client · high confidence

Introduce sandboxed V8 runtime for code mode execution

Code mode now executes user-provided code in a dedicated, sandboxed V8 runtime environment rather than the previous execution model. This change introduces a new \code-mode-runtime\ crate that manages isolated V8 isolates, installs a restricted set of global helpers (such as \text\, \image\, \audio\, \store\, \load\, \notify\, \yield\_control\, and \exit\), and exposes a \tools\ object for invoking enabled tools. The runtime handles asynchronous tool calls via promises, manages timeouts, and ensures that panics or unexpected thread exits in the V8 execution are reported back to the session owner. It also includes logic to parse and validate audio outputs (specifically omitting undersized WAV files) and to normalize content items like images and text before delivery.

codex-rs/code-mode-runtime · high confidence

Introduce shared Guardian context library for centralized review evidence and budgeting

The \codex-rs/guardian-context\ crate is introduced to centralize the composition, budgeting, and delivery of evidence used by Guardian reviewers. This library provides a unified framework for assembling context sections—including planned actions, root conversation history, trusted user answers, and conversation transcripts—into structured messages for both synchronous and asynchronous approval flows. It implements a strict token budgeting system that enforces input limits by selectively truncating optional or historical evidence while preserving required action details and user instructions. Additionally, it standardizes how MCP tool call metadata is projected for review and how multimodal content (images) is accounted for in token estimates, ensuring that reviewer inputs remain bounded and consistent across different execution modes.

codex-rs/guardian-context · high confidence

Introduce shared build-info crate for runtime identity

The new \codex-rs/build-info\ crate provides a centralized way to resolve and expose the runtime's build identity. It determines the version from the package manifest when available, falling back to a stamped Git commit for source builds, and embeds the compilation target (architecture/ABI) via a build script. Additionally, it exposes a stable, SHA-256-based build ID derived from the commit and target, enabling consistent identification of builds across different environments.

codex-rs/build-info · high confidence

Introduce shared in-process and remote app-server client facade

A new \codex-app-server-client\ crate is added to centralize the startup, lifecycle, and transport logic for the app-server runtime. This provides a unified API for CLI surfaces like the TUI and \codex-exec\ to interact with the app-server, supporting both in-process communication (via typed channels) and remote connections (over WebSocket or Unix Domain Sockets). The client handles the initialize handshake, request/response routing, and event streaming, allowing callers to switch between local and remote transports without changing their higher-level session logic.

codex-rs/app-server-client · high confidence

Introduce standalone file-search CLI and library

Adds a new standalone \codex-file-search\ tool and library (\codex\_file\_search\) that provides fast fuzzy file search capabilities. The library uses the \ignore\ crate for directory traversal (honoring \.gitignore\ rules) and \nucleo-matcher\ for fuzzy matching, exposing a cancellable session-based API with options for limiting results, excluding patterns, and computing match indices. The accompanying CLI allows users to run searches from the command line, supporting JSON output, custom thread counts, and ANSI-highlighted match indices for terminal use.

codex-rs/file-search · high confidence

Introduce standalone image generation and editing extension

Adds a new \image-generation\ extension that exposes the \image\_gen.imagegen\ tool, enabling users to generate images from text descriptions and edit existing images via instructions. The extension handles background transparency settings, supports referencing images by local file paths or by including the most recent conversation images, and persists generated outputs to a session-specific artifacts directory. It integrates with the existing model provider for API access and tracks request IDs for analytics.

codex-rs/ext/image-generation · high confidence

Introduce standalone web search extension

Adds a new standalone web search extension that provides a \web.run\ tool, enabling the model to perform internet searches, open pages, and interact with search results directly. The extension supports multiple search modes (Disabled, Cached, Indexed, Live), respects user location and domain filters, and includes logic to manage conversation history context for search queries. It also exposes structured search results and handles telemetry for result payload sizes.

codex-rs/ext/web-search · high confidence

Introduce strict string templating library for prompt assets

Added a new Rust utility library (\codex\_utils\_template\) that provides strict string templating for prompt and text assets. The library supports \{{ name }}\ placeholder interpolation and \{{{{\ / \}}}}\ for literal braces. It enforces strictness by failing on malformed placeholders, missing values, duplicate values, and extra unused values, ensuring that template rendering is predictable and safe for user-facing content.

codex-rs/utils/template · high confidence

Introduce the Goal extension for persistent thread goals

This change adds the \codex-rs/ext/goal\ crate, a new extension that provides persistent goal management within threads. It introduces three tools—\get\_goal\, \create\_goal\, and \update\_goal\—allowing users and the system to define objectives, set token budgets, and control goal status (active, paused, complete, or blocked). The extension includes built-in accounting to track token and time usage, automatic steering prompts to guide the agent based on goal progress, and analytics/metrics to monitor goal lifecycle events.

codex-rs/ext/goal · high confidence

Introduce the OpenAI Codex Python SDK with runtime pinning and first-class login

The \sdk/python\ directory now contains the official OpenAI Codex Python SDK (\openai-codex\), providing both synchronous (\Codex\) and asynchronous (\AsyncCodex\) clients for managing threads, running turns, and streaming events. The SDK automatically installs and pins a platform-specific runtime package (\openai-codex-cli-bin\) to ensure compatibility with the CLI version. It supports multiple authentication methods, including API keys, ChatGPT browser login, and device-code flows, and includes comprehensive documentation, API references, and runnable examples for common workflows like image input, thread lifecycle management, and error handling.

sdk · high confidence

Introduce the openai-codex Python SDK for workflow automation

The Python SDK is now available as the \openai-codex\ package, providing \Codex\ and \AsyncCodex\ clients to run automated workflows. Users can start threads with configurable sandbox presets (\read\_only\, \workspace\_write\, \full\_access\) and manage execution via an \ApprovalMode\ enum that supports \deny\_all\ or \auto\_review\ for permission escalations. The SDK includes first-class login support (via \ChatgptLoginHandle\ and \DeviceCodeLoginHandle\), robust error handling with retry logic for server overloads, and comprehensive type definitions generated from the app-server schemas.

sdk/python · high confidence

Introduce the skills extension with advanced skill selection and catalog rendering

The \codex-rs/ext/skills\ directory now contains the new skills extension, which centralizes skill catalog management, rendering, and selection logic. This extension introduces a configurable token budget for skill catalogs to control context usage, and implements multiple cheap, shadow-mode skill selection algorithms (including character n-grams, fielded BM25, and routing cards) to improve skill discovery without altering the model-visible prompt. It also adds support for cloud skill caching, host skill aliasing to shorten paths, and distinct prompt instructions for different skill source types (host, executor, cloud).

codex-rs/ext/skills · high confidence

Introduce typed extension API with contributor hooks and host capabilities

The extension system now exposes a structured API that allows extensions to integrate with the host through typed contributor traits and capability interfaces. Extensions can register context contributors to inject prompt fragments, tool lifecycle contributors to observe and react to tool execution, thread and turn lifecycle hooks to manage state across the session, and MCP server contributors to register or override server configurations. The API also provides host capabilities such as a conversation history snapshot for reading past turns, an event sink for emitting warnings and protocol events, metrics recording, and a response item injector for steering active model turns. An example demonstrates how to install these contributors and share state across threads using the new ExtensionData store.

codex-rs/ext/extension-api · high confidence

Introduces a portable keyring-backed credential store with platform-specific error handling

The codex-rs/keyring-store module now provides a unified abstraction for storing and retrieving credentials using the system's native keyring (macOS Keychain, Linux Secret Service, or Windows Credential Manager). It introduces a \KeyringStore\ trait with \load\, \save\, and \delete\ operations, implemented by \DefaultKeyringStore\ for production use and \MockKeyringStore\ for testing. A key behavioral change is the addition of \error\_kind.rs\, which maps native keyring failures to standard \std::io::ErrorKind\ values (e.g., mapping macOS \errSecAuthFailed\ to \PermissionDenied\ or Linux \secret\_service::Error::Locked\ to \WouldBlock\), ensuring consistent error handling across platforms. The module also includes a Bazel build file (\BUILD.bazel\) to integrate this crate into the build system.

codex-rs/keyring-store · high confidence

Introduces core-plugin-common and core-plugins crates for plugin identity and discovery

This change adds the \codex-rs/core-plugin-common\ and \codex-rs/core-plugins\ crates, establishing the foundational logic for plugin identity, cataloging, and manifest handling. \core-plugin-common\ provides stable plugin ID parsing (e.g., \name@marketplace\), validation, and installed-version selection. \core-plugins\ introduces the \PluginCatalog\ and \PluginIdentity\ types to unify local and remote plugin discovery, along with logic to parse Agent Plugin manifests, apply MCP environment overlays, and route app declarations based on authentication mode. It also includes utilities for migrating legacy source commands into Codex skills and recognizing trusted artifact operations.

codex-rs/core-plugins · high confidence

Introduces install-context crate to detect and manage Codex installation layouts

Adds a new Rust crate (\codex\_install\_context\) that detects how Codex is installed (Standalone, npm, pnpm, Vite+, Bun, Homebrew, or Other) and exposes the associated package layout, including paths for binaries, resources, and environment variables. This enables the CLI to correctly locate bundled dependencies like \rg\ and the code-mode host executable regardless of the installation method, and includes tests to verify layout detection for standalone macOS bundles and Windows winget-style packages.

codex-rs/install-context · high confidence

Introduces proxy-aware WebSocket client with shared ChatGPT cookies

A new WebSocket client library has been added to the Codex workspace, enabling WebSocket connections to respect the same outbound proxy policies and network restrictions as HTTP requests. The client automatically shares ChatGPT authentication cookies between HTTP and WebSocket transports, ensuring consistent session handling. It also supports explicit proxy routing, loopback bypass, and configurable TLS modes, with comprehensive tests verifying cookie sharing, proxy adherence, and network policy enforcement.

codex-rs/websocket-client · high confidence

Introduces shared output truncation utility for tool and execution results

A new \codex\_utils\_output\_truncation\ library has been added to provide shared logic for truncating tool and execution output based on byte or token budgets. This utility handles text, images, audio, and encrypted content within function call outputs, ensuring that long responses are safely truncated while preserving media items and reporting omitted content counts to the user.

codex-rs/utils/output-truncation · high confidence

Introduces thread-safe LRU cache with non-blocking initialization

The cache utility now provides a \BlockingLruCache\ that wraps an LRU cache with a Tokio mutex, allowing safe concurrent access. A key behavioral improvement is the \get\_or\_init\ method, which initializes values outside the global cache lock using \Arc\<OnceLock\>\, preventing thread contention during expensive initializations while ensuring deterministic results. The module also includes a \sha1\_digest\ helper for generating content-based cache keys and is now buildable via Bazel.

codex-rs/utils/cache · high confidence

Materialized SQLite schema for paginated thread history

The application now persists thread history in a dedicated SQLite database to support efficient, paginated retrieval of conversation turns and items. This change introduces a new storage layer comprising tables for thread turns, thread items, and realtime session events, along with projection state tracking to manage incremental updates and rollout boundaries. Users benefit from improved performance when browsing long conversation histories, as the system can now query pre-materialized data rather than reconstructing it from raw event streams.

_codex-rs/state/thread\_history\migrations · high confidence

Message history is persisted to a local JSONL file with bounded batch lookups

The message history is now stored as an append-only JSONL file at \\~/.codex/history.jsonl\, allowing users to retain conversation records across sessions. The system enforces size limits by trimming the oldest entries when the file exceeds a configured \max\_bytes\ threshold, and it uses advisory file locking to prevent data corruption from concurrent writes. For performance, history retrieval uses bounded batch lookups (up to 128 rows or 64 KiB per request) with cursors that enable efficient backward scanning, ensuring that large history files do not cause significant latency when browsing past messages.

codex-rs/message-history · high confidence

Multi-agent tools now emit structured collaboration events

The multi-agent tool handlers (spawn, wait, close, resume, and send\_input) now emit structured \CollabAgentToolCall\ turn items that expose detailed context such as sender and receiver thread IDs, agent nicknames and roles, effective model and reasoning effort, and agent states. This provides richer, machine-readable feedback for multi-agent interactions, improving observability and enabling clients to track the lifecycle and status of sub-agents more precisely.

_codex-rs/core/src/tools/handlers/multi\agents · high confidence

Multi-agent v2 tools now report private collaboration analytics

The multi-agent v2 tool handlers (spawn, send\_message, followup\_task, interrupt\_agent, list\_agents, and wait\_agent) now automatically record private collaboration analytics for every tool invocation. A new analytics module tracks the lifecycle of each tool call—recording start time, status (completed, failed, or interrupted), target agent/thread, and relevant model or reasoning-effort metadata—and sends these events to the analytics backend without emitting a public tool item to the user. This provides backend visibility into multi-agent activity while keeping the user-facing conversation clean.

_codex-rs/core/src/tools/handlers/multi\_agents\v2 · high confidence

New AWS authentication and signing library for Amazon Bedrock

A new \codex-aws-auth\ library has been introduced to handle AWS credential loading, profile discovery, and SigV4 request signing. This library integrates with the application's HTTP client factory and network policy system, ensuring that AWS SDK credential resolution and request signing respect configured network restrictions. The \model-provider\ module now uses this library to support multiple Amazon Bedrock authentication modes, including managed API keys, managed access keys, AWS SDK profiles, and credential exports, while also implementing a mechanism to refresh expired AWS credentials via a configurable command.

codex-rs/model-provider · high confidence

New Guardian reviewer extension for synchronous action approval

A new \guardian-reviewer\ extension has been introduced to own the synchronous review lifecycle, including assessment parsing, circuit-breaker logic, conversation bookkeeping, and review completion. This change centralizes Guardian review reporting and denial accounting within the extension, allowing the host to supply review attempts while the extension enforces the resulting decisions on bound actions. Users benefit from more robust handling of review outcomes, including better error classification, retry logic, and structured feedback for failed reviews.

codex-rs/ext/guardian-reviewer · high confidence

New OSS provider utility crate for shared setup logic

A new \codex\_utils\_oss\ crate has been added to centralize utilities for Open Source Software (OSS) model providers. This library provides functions to retrieve default models and ensure provider readiness (checking for model downloads and service reachability) for LM Studio and Ollama, allowing the TUI and execution components to share this setup logic without duplication.

codex-rs/utils/oss · high confidence

New OpenTelemetry integration crate for Codex telemetry

The \codex-otel\ crate introduces a centralized OpenTelemetry integration for Codex, providing session-scoped business event emission via \SessionTelemetry\, configurable trace metadata, and bounded credential-storage telemetry helpers. It adds opt-in logging for final agent responses and Guardian assessments, exports turn cost and latency metrics, and includes a buffered metrics system to handle startup timing. The crate also enforces network policies for AWS auth and telemetry, and provides a Bazel build target for the integration.

codex-rs/otel · high confidence

New PR babysitting script for monitoring CI and review activity

Added a new Python script, \gh\_pr\_watch.py\, to the \.codex/skills/babysit-pr/scripts\ directory that monitors GitHub Pull Request CI status and review comments for Codex PR babysitting workflows. The script provides command-line options to poll PR state, detect failed or flaky CI runs, and recommend actions such as retrying failed jobs or processing review comments. It also includes a corresponding test suite (\test\_gh\_pr\_watch.py\) to verify the logic for fetching review items, prioritizing actions, and handling pending review states.

.codex/skills/babysit-pr/scripts · high confidence

New RedactedString utility to prevent credential leakage in logs

A new \RedactedString\ type has been added to the \codex-rs/utils/redacted-string\ crate. This wrapper type implements \Debug\ to output \\<redacted\>\ instead of the actual value, ensuring that sensitive credentials are not accidentally exposed in application logs or debug output, while still allowing normal string operations via \Deref\ and \DerefMut\.

codex-rs/utils/redacted-string · high confidence

New SQLite-backed state crate for persistent agent memory, goals, and logs

The \codex-rs/state\ crate introduces a dedicated SQLite database to persist agent state, replacing previous in-memory or file-based approaches. This change adds structured storage for thread goals (including status tracking and token budgets), a memory system with extraction jobs and consolidation progress, paginated thread history, and a dedicated log database for diagnostic tracing. It also introduces a \LogDbLayer\ that buffers tracing events to SQLite with configurable filtering to prevent noisy logs from overwhelming the store, and provides migration tooling to handle schema evolution and legacy data repair.

codex-rs/state · high confidence

New agent extension for running resolved agent prompts in forked threads

This change introduces a new agent extension (\codex\_agent\_extension\) that allows resolved agent invocations to be started in isolated, forked threads. The \AgentRunner\ component takes a parent thread ID and an \AgentInvocation\ (containing config and prompt), validates that the prompt is not empty, and uses the \ThreadManager\ to spawn a legacy sub-agent thread. It then submits the user input to this new thread and returns the resulting \AgentRun\ details (thread ID, turn ID, and thread handle). This enables the system to execute specific agent tasks in their own context while maintaining a link to the parent thread for traceability.

codex-rs/ext/agent · high confidence

New app-server-transport crate for managing server connections and remote control

The app-server-transport module has been extracted into a dedicated crate to centralize transport logic. It now manages connection lifecycles by binding them to the authentication owner, invalidating queued work if credentials change. The module supports multiple transport modes (stdio, Unix sockets, WebSocket) and introduces a robust remote control system with client tracking, enrollment, and pairing. It also handles managed daemon recovery by persisting interrupted turns and ensures graceful shutdown across platforms, including Windows-specific socket-based termination signals.

codex-rs/app-server-transport · high confidence

New approval presets for configuring sandbox permissions

A new \approval-presets\ utility crate has been introduced to provide a standardized set of configurations that pair approval policies with permission profiles. This crate exposes three built-in presets—Read Only, Default (Auto), and Full Access—allowing users to quickly select a security level that defines whether the agent can read/write files or access the internet, and whether it requires approval for actions. These presets are designed to be UI-agnostic and reusable across both the TUI and MCP server, simplifying the setup of sandbox states by abstracting the underlying permission profile logic into simple, selectable options.

codex-rs/utils/approval-presets · high confidence

New audio preparation utility crate

A new utility crate at codex-rs/utils/audio has been introduced to handle audio input preparation and token estimation. This component canonicalizes audio data URLs, rejects unsupported formats or remote URLs, and replaces invalid audio content with descriptive text placeholders (e.g., indicating unsupported formats like wav, mp3, m4a, webm, or ogg, or size limits). It also provides a function to estimate audio token counts based on decoded duration, caching results to avoid redundant processing.

codex-rs/utils/audio · high confidence

New backend-client module for analytics, usage, and rate-limit operations

The codex-rs/backend-client library has been introduced to centralize authenticated HTTP interactions with the backend. It provides structured clients for fetching account analytics (usage, credits, plugins, skills), querying ChatGPT per-turn cost estimates, retrieving seven-day plan-limit history, reading account profile statistics, and managing rate-limit reset credits (listing and consuming). The client supports both Codex and ChatGPT API path styles, handles authentication recovery for 401 errors, and includes comprehensive tests for these new capabilities.

codex-rs/backend-client · high confidence

New bundled image generation skill with built-in and CLI fallback modes

A new bundled skill named 'imagegen' is now available to generate or edit raster images (photos, illustrations, mockups, etc.). It defaults to using the built-in \image\_gen\ tool, which does not require an API key, but includes a fallback CLI mode (\scripts/image\_gen.py\) for users who explicitly request it or need specific model controls (such as \gpt-image-2\ or \gpt-image-1.5\). The skill provides comprehensive guidance for prompt structuring, use-case classification, and handling transparent backgrounds, along with reference documentation for network approvals and API parameters.

codex-rs/skills · high confidence

New codex-config crate with packaged defaults and cloud-managed config support

The \codex-rs/config\ crate has been extracted from \codex-core\ to centralize configuration handling. It introduces a \defaults.toml\ file that sets fixed defaults for packaged clients (such as enabling permissions instructions, setting the file opener to VS Code, and configuring history persistence). The crate also adds a \CloudConfigBundle\ loader that fetches and applies enterprise-managed configuration fragments from the cloud, ensuring they are correctly layered into the configuration stack with strict validation and proper path resolution.

codex-rs/config · high confidence

New codex-file-system crate with environment-bound access and bounded walks

The \codex-rs/file-system\ crate introduces a new \EnvironmentAccess\ trait and \FileSystemEnvironmentAccessor\ that bind filesystem operations to a specific environment's sandbox permissions, ensuring callers cannot bypass the sandbox or swap the underlying filesystem. It adds bounded recursive directory walks with configurable limits on depth, directory count, and entry count, plus options to follow symlinks and prune hidden directories. File paths are now represented using \PathUri\ instead of legacy native paths, and the crate exposes a \find\_nearest\_ancestor\_with\_markers\ utility for efficient, pipelined ancestor discovery. Serialization of executor permission profiles is updated to use \PathUri\-based URIs, and file metadata now includes file size.

codex-rs/file-system · high confidence

New codex-sandboxing library for cross-platform sandbox management

The \codex-sandboxing\ crate has been introduced to centralize sandbox logic across Linux, macOS, and Windows. On Linux, it manages \bubblewrap\ detection and user-namespace probing, explicitly rejects WSL1 environments, and handles Landlock helper invocation with support for managed network proxy contexts. On macOS, it bundles Seatbelt platform policies (base, network, read-only defaults, and preferences) and exposes violation recording. On Windows, it provides integration points for the MXC sandbox and restricted token overrides. The library also standardizes permission profile normalization, merging, and intersection, and introduces a \denial\ module to semantically detect sandbox-enforced command failures across platforms.

codex-rs/sandboxing · high confidence

New codex-utils-pty library for unified process spawning

A new Rust library, codex-utils-pty, has been introduced to provide a unified interface for spawning interactive and non-interactive processes. It supports both PTY (pseudo-terminal) and pipe-based execution, allowing callers to switch backends based on TTY requirements. The library includes platform-specific optimizations for Linux and macOS, such as native POSIX spawning and descriptor cleanup, and ensures Windows processes do not allocate console windows. It also features a runtime-independent child reaper to prevent orphan processes and improve cleanup reliability during runtime shutdowns.

codex-rs/utils/pty · high confidence

New connector extension for loading plugin app declarations

A new \codex\_connectors\_extension\ crate has been added to handle loading application declarations from executor plugins. This component reads plugin configuration files from the environment, parses them, and exposes a \PluginAppProvider\ interface that returns \AppDeclaration\ objects, enabling the system to discover and utilize app-level features defined by external plugins.

codex-rs/ext/connectors · high confidence

New connectors crate centralizes app metadata, policy evaluation, and runtime caching

The \codex-rs/connectors\ crate now owns the core logic for connector-backed app tools, introducing dedicated modules for metadata, policy, and state management. \app\_info.rs\ defines the \AppInfo\ schema (including branding, metadata, and accessibility flags) used for directory discovery and caching. \app\_tool\_policy.rs\ provides the \AppToolPolicyEvaluator\ to resolve enablement and approval modes (Auto, Prompt, Approve) by merging local user configuration with managed requirements. \connector\_runtime\ manages process-local, account-scoped snapshots of available tools with disk persistence, while \directory\_cache.rs\ handles persistent caching of the connector directory list. \accessible.rs\ and \filter.rs\ implement logic to aggregate accessible connectors and filter discoverable apps for tool suggestions.

codex-rs/connectors · high confidence

New dedicated memories tools for ad-hoc notes, listing, reading, and searching

The memories extension now registers a set of dedicated tools—add\_ad\_hoc\_note, list, read, and search—that allow the model to manage and retrieve memory files stored locally in the Codex home directory. These tools are gated by configuration flags (enabled and dedicated\_tools) and are installed via the extension registry, contributing both the tool definitions and the necessary prompt context (memory summary instructions) to the conversation. The implementation includes a local filesystem backend with path scoping, symlink rejection, and pagination support, along with metrics recording for tool call performance.

codex-rs/ext/memories · high confidence

New execpolicy engine with Starlark-based prefix rules and CLI validation

The \codex-rs/execpolicy\ crate introduces a new execution policy engine that evaluates commands against Starlark-defined prefix rules. Users can now define policies using \prefix\_rule()\ with \allow\, \prompt\, or \forbidden\ decisions, along with optional justifications and example-based validation (\match\/\not\_match\). The engine supports host executable resolution, allowing basename fallbacks for absolute paths when explicitly configured. A new \codex execpolicy check\ CLI command allows users to validate commands against policy files, outputting structured JSON results. The crate also includes a migration path to clean up legacy allow rules and persists network approvals.

codex-rs/execpolicy · high confidence

New external agent migration crate for detecting and importing Claude and Cursor data

A new \codex-rs/external-agent-migration\ crate has been added to handle the detection and migration of configuration, sessions, plugins, and memory from external agents (Claude Code and Cursor). This includes logic to detect recent session files, identify used connectors via MCP tool calls and manifest metadata, merge missing TOML configuration values and MCP server definitions, and import plugin settings, ensuring that existing Codex configurations are preserved while adding new compatible settings from the source agents.

codex-rs/external-agent-migration · high confidence

New fuzzy-match utility with Unicode-aware scoring

A new \codex\_utils\_fuzzy\_match\ crate has been added to provide case-insensitive subsequence matching that correctly handles Unicode characters which expand during lowercasing (such as the Turkish dotted I). The \fuzzy\_match\ function returns the indices of matched characters in the original string and a score that rewards contiguous matches and prefix hits, ensuring accurate highlighting even when lowercasing changes character counts.

codex-rs/utils/fuzzy-match · high confidence

New git-utils crate for Git operations

A new dedicated \codex-rs/git-utils\ crate has been introduced to centralize Git-related functionality. This library provides utilities for applying unified diffs via \git apply\ (with preflight/dry-run support), managing internal Git baselines for resettable diff mechanisms, retrieving repository metadata (commit hashes, branches, remote URLs), and handling Git process execution with timeouts and environment scrubbing. It also includes helpers for branch merge-base calculations, filesystem monitor detection, and worktree identity resolution.

codex-rs/git-utils · high confidence

New home-dir utility with strict CODEX\_HOME validation

A new \home-dir\ crate has been added to provide a standardized way to locate the Codex configuration directory. It introduces the \find\_codex\_home\ function, which respects the \CODEX\_HOME\ environment variable but strictly validates that the specified path exists and is a directory, returning an error if it does not. If the environment variable is not set, it defaults to \\~/.codex\. The utility returns an \AbsolutePathBuf\ to ensure path safety and consistency across the application.

codex-rs/utils/home-dir · high confidence

New hooks engine crate for lifecycle and tool event automation

The \codex-rs/hooks\ crate introduces a dedicated hooks engine that allows users to define and execute custom automation logic in response to specific session and tool events. This engine discovers hook configurations from \hooks.json\ and \config.toml\ layers, supporting both command-line scripts and MCP tool invocations as handlers. It enforces trust metadata and allows users to persistently enable, disable, or trust specific hooks via configuration. The engine handles execution modes (synchronous and asynchronous), manages concurrency limits for async hooks, and ensures security by isolating hook processes from sensitive environment variables like auth tokens. It also supports executor-scoped hooks for plugin integration and provides detailed telemetry and status reporting for each hook run.

codex-rs/hooks · high confidence

New image utility library with resizing, caching, and metadata preservation

A new \codex\_utils\_image\ library has been introduced to handle image processing for prompts. It includes logic to resize images to fit within 2048-pixel bounds while preserving RGB ICC profiles and EXIF metadata, supports multiple modes (ResizeToFit, Original, ResizeWithLimits), and implements a content-digest-based LRU cache to avoid redundant processing. The module also provides benchmarking infrastructure and specific error handling for image decoding and encoding failures.

codex-rs/utils/image · high confidence

New internal app-server test client for smoke testing and protocol validation

An internal test client tool is now available to bootstrap, connect to, and exercise the Codex app-server. It provides commands to start the server, send messages via V1 and V2 APIs, resume threads, and watch raw WebSocket traffic. It includes dedicated smoke tests for plugin analytics (capturing install, enable/disable, and usage events to a local JSONL file) and a mutation test that installs and uninstalls a remote plugin to verify backend state restoration. The client also supports testing Amazon Bedrock login/logout flows, handling interactive user input requests, and running with OpenTelemetry tracing enabled.

codex-rs/app-server-test-client · high confidence

New login crate with redesigned authentication flows and UI

The \codex-rs/login\ crate has been introduced to centralize authentication logic, featuring a new Rust-based login server and redesigned OAuth success and error pages. It adds support for multiple authentication modes including Agent Identity JWTs, Amazon Bedrock API keys, and Bedrock access keys, alongside improved handling of personal access tokens and external auth headers. The implementation includes robust state tracking for credential changes, secure storage of secrets, and comprehensive test coverage for auth flows, workspace restrictions, and token management.

codex-rs/login · high confidence

New model provider configuration module with gateway OAuth and residency enforcement

A new \model-provider-info\ module has been introduced to centralize model provider definitions and configuration validation. This module adds support for secondary gateway OAuth credentials, allowing providers to deliver authentication tokens via configurable HTTP headers or cookies while enforcing strict security rules (e.g., preventing conflicts with reserved headers or unsafe URL schemes). It also introduces process-wide managed residency requirements, ensuring that API requests comply with data residency policies (e.g., US-only) by injecting the appropriate residency header. The module defines the structure for provider info, including support for AWS authentication, custom HTTP headers, and various timeout/retry configurations, serving as the foundational registry for Codex's model provider ecosystem.

codex-rs/model-provider-info · high confidence

New path-utils crate for safe system command discovery and path normalization

A new Rust utility crate (codex\_utils\_path) has been introduced to centralize path handling and system helper discovery. It provides safe, explicit resolution of installed system executables (like Git or package managers) by scanning trusted installation directories (e.g., /nix/store, Homebrew, Program Files) without relying on the ambient PATH, preventing execution of untrusted tools before workspace trust is established. Additionally, it introduces robust path normalization for cross-platform consistency, including WSL-specific lowercase handling for /mnt drives, Windows verbatim path simplification, and safe symlink resolution with cycle detection.

codex-rs/utils/path-utils · high confidence

New plugin utilities crate for shared plugin resolution and syntax helpers

A new \codex-rs/utils/plugins\ crate has been introduced to centralize plugin-related logic previously scattered across the codebase. This module provides shared utilities for resolving plugin namespaces by discovering manifest files (such as \plugin.json\) in standard and alternate locations (e.g., \.claude-plugin\, \.cursor-plugin\), handling plugin identity including remote IDs, and defining plaintext mention sigils (\$\ for tools, \@\ for plugins). It also includes helpers for sanitizing plugin names for MCP connectors and managing migrated command skills, establishing a common foundation for plugin discovery and metadata handling across Codex components.

codex-rs/utils/plugins/src · high confidence

New rollout-trace diagnostic crate for local session replay

A new \codex-rs/rollout-trace\ crate has been added to provide an opt-in, local diagnostic tracing system for Codex sessions. When the \CODEX\_ROLLOUT\_TRACE\_ROOT\ environment variable is set, the system records raw runtime evidence—including inference requests/responses, tool calls, code-mode cell lifecycles, terminal operations, and multi-agent v2 interactions—into local JSON bundles. These bundles are then reduced into a semantic graph (\state.json\) that separates model-visible conversation from runtime debug objects, allowing developers to inspect exactly how the model saw the conversation and how runtime work (like nested tool calls or compaction) influenced the session. The crate includes the trace schema, a no-op capable writer for hot-path instrumentation, and a reducer for offline replay.

codex-rs/rollout-trace · high confidence

New sandbox-summary utility for human-readable permission descriptions

A new \sandbox-summary\ crate has been added to provide user-friendly, text-based summaries of sandbox policies and permission profiles. It exposes two functions, \summarize\_sandbox\_policy\ and \summarize\_permission\_profile\, which convert internal configuration structures (such as \SandboxPolicy\ variants like \ReadOnly\, \ExternalSandbox\, and \WorkspaceWrite\, and \PermissionProfile\ states) into concise strings. These summaries explicitly indicate network access status (e.g., appending "(network access enabled)") and detail writable paths for workspace-write modes, helping users quickly understand the security posture and capabilities of the current sandbox configuration.

codex-rs/utils/sandbox-summary · high confidence

New scripts for ASCII validation and Codex package assembly

Added \scripts/asciicheck.py\ to enforce ASCII-only content in files (with an optional \--fix\ mode to replace non-ASCII characters like non-breaking spaces with ASCII equivalents) and introduced a new \scripts/codex\_package\ module with \build\_codex\_package.py\ to assemble canonical Codex package directories and archives (supporting \.tar.gz\, \.tar.zst\, and \.zip\ formats) for various targets and variants.

scripts · high confidence

New secrets management crate with isolated OAuth namespaces and caching

The \codex-secrets\ crate introduces a centralized secrets backend that stores encrypted credentials in separate local files based on namespace: general managed secrets, Codex authentication, MCP OAuth, and Gateway OAuth. Gateway OAuth credentials are now cached in memory to speed up reads, while other namespaces remain uncached. The crate also includes a sanitizer utility that redacts known secret patterns (such as Bearer tokens, OpenAI keys, and AWS access keys) from log output.

codex-rs/secrets · high confidence

New shared CLI utility crate for configuration and option handling

A new \codex-rs/utils/cli\ crate has been introduced to centralize shared command-line argument definitions and configuration override logic for Codex CLI tools. This change introduces the \SharedCliOptions\ struct, which consolidates common flags such as \--sandbox\, \--approve-for-me\, \--dangerously-bypass-approvals-and-sandbox\, and \--profile\ into a reusable component. It also adds \CliConfigOverrides\ to support the \-c key=value\ syntax for overriding configuration values at runtime, and provides helper modules for parsing approval and sandbox modes (\ApprovalModeCliArg\, \SandboxModeCliArg\) and formatting resume command hints. This refactoring standardizes how CLI options are defined, inherited, and applied across different Codex entry points.

codex-rs/utils/cli · high confidence

New shared HTTP transport crate with route-aware proxy and custom CA support

A new \codex-http-client\ crate has been introduced to centralize outbound HTTP transport for the application. This change introduces a policy-aware HTTP client factory that enforces explicit outbound proxy policies (including system proxy, PAC/WPAD, and environment variables) and manages route-aware connection pooling to ensure requests are sent over the correct proxy route. It also adds support for custom CA certificate handling via \CODEX\_CA\_CERTIFICATE\ and \SSL\_CERT\_FILE\ environment variables, allowing the application to work correctly behind enterprise proxies or gateways that intercept TLS. Additionally, the crate includes a shared cookie store for ChatGPT infrastructure cookies and a network policy system to restrict or revoke outbound destinations.

codex-rs/http-client · high confidence

New shell-command crate for command parsing and safety classification

A new \codex-rs/shell-command\ crate has been introduced to centralize shell command parsing and safety checks. It provides robust parsing for Bash and PowerShell scripts using tree-sitter and a long-lived PowerShell AST subprocess, enabling the system to safely classify commands, detect dangerous operations (such as forced deletions or URL-based launches), and handle complex shell syntax for security policy enforcement.

codex-rs/shell-command · high confidence

New stream-parser utility for incremental text processing

A new Rust crate, codex-utils-stream-parser, has been added to handle incremental parsing of streamed text. It provides a \StreamTextParser\ trait and implementations for stripping and extracting \\<oai-mem-citation\>\ tags, parsing \\<proposed\_plan\>\ blocks in plan mode, and handling raw byte streams with correct UTF-8 boundary handling. This allows the application to safely render visible text immediately while extracting hidden payloads like citations and plan segments, even when tags are split across chunk boundaries.

codex-rs/utils/stream-parser · high confidence

New string utility library with JSON and truncation helpers

The codex-rs/utils/string crate now provides a set of string manipulation utilities. It includes JSON serialization helpers that can escape non-ASCII characters for ASCII-safe transport and limit output size. It also offers functions to truncate strings by character count or approximate token count while preserving prefixes and suffixes. Additional features include UUID extraction from text, metric tag sanitization, and conversion of markdown-style location suffixes to terminal-friendly formats.

codex-rs/utils/string · high confidence

New terminal-detection crate for identifying terminal environments

A new \terminal-detection\ crate has been introduced to centralize terminal identification logic. This module detects the active terminal emulator (such as iTerm2, Ghostty, Apple Terminal, VS Code, and others) and multiplexers (tmux, zellij) by reading environment variables like \TERM\_PROGRAM\ and \TERM\. The detected information is structured into \TerminalInfo\ and is used to generate sanitized User-Agent tokens for OpenTelemetry logging and to inform terminal-specific configuration choices in the TUI. The implementation includes safeguards to avoid executing PATH helpers before workspace trust is established.

codex-rs/terminal-detection · high confidence

Prevent idle sleep during active turns on macOS, Linux, and Windows

The sleep-inhibitor utility now prevents the computer from entering idle sleep while a turn is running on macOS, Linux, and Windows. On macOS, it uses native IOKit power assertions instead of spawning external processes. On Linux, it spawns \systemd-inhibit\ or \gnome-session-inhibit\ to block idle sleep. On Windows, it uses the \PowerCreateRequest\ API with the \PowerRequestSystemRequired\ type. This ensures that long-running operations are not interrupted by the OS entering a low-power state.

codex-rs/utils/sleep-inhibitor · high confidence

Support for workload identity token exchange

The \codex\_workload\_identity\ crate now enables authentication via workload identity federation. It reads a file-backed assertion, exchanges it for a short-lived access token using the JWT Bearer grant type, and caches the result to minimize network calls. The implementation supports forwarding an optional workload identity context, enforces network policies for outbound requests, and handles concurrent token resolution and refresh with single-flight semantics to prevent thundering herds.

codex-rs/workload-identity · high confidence

Versioned memory usage classification and citation parsing

The new \codex\_memories\_read\ crate introduces best-effort classification of shell read and search commands to distinguish between memory versions (V1 and V2) and specific artifact types (MEMORY.md, memory summaries, raw memories, rollout summaries, and skills). This enables telemetry to be tagged with the correct memory version and usage kind. Additionally, the crate adds logic to parse memory citations, extracting both structured citation entries and legacy thread IDs or rollout IDs from memory content.

codex-rs/memories/read · high confidence

Windows sandbox now builds with Bazel

The Windows sandbox component can now be built using the Bazel build system. A new BUILD.bazel file defines the crate, handling the embedding of the Windows setup manifest for both MSVC and cross-compilation (gnullvm) targets, and disables the legacy Cargo build script to avoid linker directive warnings. A build.rs script and manifest file are included to support this, and smoke tests are provided to validate the sandbox behavior via the CLI.

codex-rs/windows-sandbox-rs · high confidence

Removals

Removal of Codex CLI example projects

The self-contained example projects for the Codex CLI have been removed from the repository. This includes the \camerascii\ (webcam ASCII art), \build-codex-demo\ (reimplementation of the original Codex demo), \impossible-pong\ (enhanced Pong game), and \prompt-analyzer\ (prompt clustering utility) directories. Consequently, the \README.md\ documentation describing how to run these examples and the helper \run.sh\ scripts, \task.yaml\ specifications, and template files associated with each project are no longer available.

codex-cli/examples · high confidence

Removal of React hooks from the CLI source code

The \use-confirmation\ and \use-terminal-size\ React hooks have been removed from the \codex-cli/src/hooks\ directory. This change eliminates the code responsible for managing confirmation queues and terminal size detection within the CLI's React-based components.

codex-cli/src/hooks · high confidence

Removal of TypeScript build tooling and configuration

The codex-cli directory has had its TypeScript build infrastructure removed, including the deletion of tsconfig.json, build.mjs, .eslintrc.cjs, and related build helpers like require-shim.js and the react-devtools ignore plugin. This change eliminates the TypeScript compilation, bundling, and linting setup that previously existed in this location, effectively stripping the CLI of its TypeScript build pipeline.

codex-cli · high confidence

Removal of legacy CLI overlay components

The approval mode, help, history, model, and typeahead overlay components, along with the singlepass CLI application component, have been removed from the codebase. This eliminates the previous interactive UI for switching approval modes, viewing session history, selecting models, and accessing help, as well as the singlepass-specific application logic.

codex-cli/src/components · high confidence

Removal of legacy TypeScript CLI implementation

The legacy TypeScript source files for the CLI (\app.tsx\, \cli.tsx\, \cli\_singlepass.tsx\, \typings.d.ts\) and the rollout storage utility (\save-rollout.ts\) have been removed from the repository. This deletion eliminates the previous React/Ink-based terminal interface, command-line argument parsing, and session-saving logic, indicating a migration away from the TypeScript codebase in this directory.

codex-cli/src · high confidence

Removal of legacy TypeScript agent-loop implementation

The legacy TypeScript agent-loop implementation, including the core \AgentLoop\ class, command execution logic (\exec.ts\, \handle-exec-command.ts\), patch parsing (\apply-patch.ts\, \parse-apply-patch.ts\), and session logging (\log.ts\), has been removed from the repository. This change eliminates the previous TypeScript-based agent execution path, which previously handled model interactions, command approvals, and sandboxing.

codex-cli/src/utils/agent · high confidence

Removal of legacy command approval and patch parsing logic

The command approval system, including the \canAutoApprove\ safety assessment logic and the \parseApplyPatch\ patch parser, has been removed from the CLI library. This change eliminates the previous mechanism for auto-approving safe commands (like \ls\ or \cat\) and parsing custom patch formats, along with the associated test suites and command formatting utilities.

codex-cli/src/lib · high confidence

Removal of legacy utility modules

The CLI has removed several internal utility modules from the source tree, including approximate-tokens-used, auto-approval-mode, check-in-git, config, input-utils, model-utils, parsers, session, short-path, and terminal. This cleanup eliminates code that is no longer required for the current CLI operation, simplifying the codebase and reducing maintenance overhead.

codex-cli/src/utils · high confidence

Removal of singlepass TypeScript utilities

The TypeScript implementation files in the \codex-cli/src/utils/singlepass\ directory have been deleted. This removes the code responsible for generating and colorizing unified diffs, managing file operation summaries, handling task context rendering, caching file contents, and enforcing context size limits. Users will no longer have access to these specific single-pass file processing and diff-generation utilities within the CLI.

codex-cli/src/utils/singlepass · high confidence

Removal of vendored CLI UI components

The vendored implementations for the CLI's interactive user interface components have been removed from the repository. This change deletes the source code for the spinner (\ink-spinner\), text input (\ink-text-input\), and select menu (\ink-select\) components, along with their associated helper files and themes. Users relying on these internal components for custom integrations or extensions will no longer have access to these specific UI primitives.

codex-cli/src/components/vendor · high confidence

Removed TypeScript sandbox implementation files

Deleted the TypeScript source files for the sandbox execution logic, including the interface definitions, the macOS Seatbelt policy implementation, and the raw execution handler. This removes the TypeScript-based code responsible for spawning child processes and managing sandbox policies within the CLI.

codex-cli/src/utils/agent/sandbox · high confidence

Removed legacy chat UI components

Deleted the legacy chat UI components (message-history, multiline-editor, terminal-chat-command-review, terminal-chat-input-thinking, terminal-chat-input, terminal-chat-new-input, terminal-chat-past-rollout, terminal-chat-response-item, terminal-chat-tool-call-item, terminal-chat-utils, terminal-chat, and terminal-header) from the codex-cli chat interface.

codex-cli/src/components/chat · high confidence

Security

App server now rejects WebSocket requests with Origin headers

The app server enforces stricter security on WebSocket connections by rejecting requests that include Origin headers. This change prevents unauthorized cross-origin WebSocket upgrades, ensuring that only direct, intended connections are established with the server.

codex-rs/app-server · high confidence

Architecture

Extract rollout persistence into a dedicated crate with compression and metadata support

The rollout persistence and discovery logic has been extracted into its own \codex-rs/rollout\ crate. This new module introduces background compression of cold local rollout files to \.zst\ format, transparent handling of both plain and compressed JSONL files via a unified line reader, and robust metadata extraction from session files. It also includes paginated thread listing capabilities, model context scanning for bounded history reconstruction, and maintenance locking to coordinate compression and migration operations safely.

codex-rs/rollout · high confidence

Extract shared tool support crate (codex-tools)

A new \codex-tools\ crate has been introduced to host shared, host-facing tool machinery that is decoupled from \codex-core\. This location contributes the core type definitions (such as \ToolSpec\, \ToolExecutor\, and \ToolOutput\), schema parsing and sanitization logic (including large-schema compaction and JSON Schema normalization), and adaptation helpers for code-mode, dynamic tools, and image detail. By centralizing these reusable components, the codebase prepares for a broader migration where tool planning and adaptation logic can be shared across multiple consumers without depending on core orchestration.

codex-rs/tools · high confidence

Extracted analytics engine into a dedicated crate

The analytics logic has been extracted from the main application into a standalone \codex-rs/analytics\ crate. This new module provides the \AnalyticsEventsClient\ and \AnalyticsReducer\ to ingest internal facts and emit structured telemetry events (such as skill invocations, tool calls, and Guardian reviews) via HTTP or, in debug builds, to a local capture file. It also includes specific handling for accepted-line fingerprints and Guardian V2 classifier events.

codex-rs/analytics · high confidence

Behavioural changes

184 commits (0 fixes) modifying codex-rs/app-server-protocol/schema/precomputed

A change to existing behaviour in codex-rs/app-server-protocol/schema/precomputed — 184 commits, 2 files.

codex-rs/app-server-protocol/schema/precomputed · medium confidence · unverified

Centralized prompt management with model-catalog overrides

The \codex-rs/prompts\ crate now centralizes all prompt templates and instruction rendering, introducing a system where model-catalog values can override bundled defaults for model instructions, permissions, approval policies, multi-agent role hints, and collaboration modes. This change ensures that prompt text is consistently resolved from the model catalog when available, while retaining bundled defaults and preserving the source of the text (catalog vs. bundled) for accurate attribution and debugging.

codex-rs/prompts · high confidence

Config schema generator moved to dedicated crate

The tool for generating the canonical JSON schema for config.toml has been extracted into its own crate (codex\_config\_schema). This change reorganizes the build structure by creating a new dedicated crate for the schema generation logic, which writes the schema to config.schema.json.

codex-rs/config-schema · medium confidence

Containerized execution now uses dynamic domain allowlisting and sandboxed permissions

The \run\_in\_container.sh\ script has been updated to support multiple allowed domains via the \OPENAI\_ALLOWED\_DOMAINS\ environment variable, writing them to a file inside the container for the firewall to consume, rather than hardcoding \api.openai.com\. Additionally, the script now creates unique container names per working directory to prevent conflicts, ensures the container is cleaned up on exit, and changes the execution mode from \--dangerously-auto-approve-everything\ to \--sandbox workspace-write --ask-for-approval on-request\ for improved security. The \init\_firewall.sh\ script was also modified to read its domain list from this new file with a fallback to the default, and the \build\_container.sh\ script was removed.

codex-cli/scripts · high confidence

Hermetic Wine and PowerShell test support

The build system now includes a hermetic test harness for Wine and PowerShell, allowing tests to run without requiring system-level Wine installations or 32-bit host libraries. This is achieved by pinning specific versions of Wine (11.0-amd64-wow64) and PowerShell (7.2.24) via Bazel modules, ensuring consistent test execution across different environments.

bazel/modules · high confidence

Introduce Bazel patch layer for Windows, Rust, and V8 builds

This change adds a new \patches/\ directory containing a collection of Bazel patches that modify the build behavior of \rules\_cc\, \rules\_foreign\_cc\, \rules\_rs\, \rusty\_v8\, and \v8\. These patches enable and stabilize native Windows builds (including MSVC and MinGW/ARM64), align Rust toolchain behavior with Cargo defaults, and adapt V8's Bazel rules to the workspace's hermetic toolchains.

patches · high confidence

Introduce Rust-based apply\_patch implementation with line-ending preservation and sandboxed execution

The \codex-rs/apply-patch\ crate provides a new Rust implementation of the \apply\_patch\ tool, replacing the previous external \patch(1)\ dependency with a native parser and file-updater. This change introduces a \PreserveLineEndings\ mode that maintains existing file line endings (CRLF, CR, LF) and uses the file's preferred style for new lines, addressing cross-platform consistency issues. The implementation routes all file operations through the \ExecutorFileSystem\ and \FileSystemSandboxContext\, ensuring that patch applications are executed within the sandboxed environment. It also adds support for parsing shell heredocs (Bash, PowerShell, Cmd) and handles Unicode normalization for context matching to improve patch application reliability.

codex-rs/apply-patch · high confidence

Introduce extension-owned turn item types for image generation, web search, and sleep

The \codex\_extension\_items\ crate now defines the structured data models for extension-owned turn items, including \ImageGenerationItem\, \WebSearchItem\, and \SleepItem\, all wrapped in a unified \ExtensionItem\ envelope. This change exposes structured web search results (including opaque JSON results for extensibility) and image generation details (such as transparency metadata and usage-limit failure states) as first-class display items. Internal analytics fields like request IDs are explicitly excluded from the wire format to maintain a stable client-facing schema, while the system now supports deserializing legacy items that may omit optional fields like results or transparency.

codex-rs/ext/items · high confidence

Introduce static templates for Default and Plan collaboration modes

The collaboration mode system now uses dedicated, static instruction templates for the Default and Plan modes, replacing previous legacy variants. The Default mode template enforces a preference for making reasonable assumptions and executing requests without unnecessary user interruptions, while the Plan mode template structures the workflow into three phases (grounding, intent chat, implementation chat) and strictly prohibits mutating actions until the plan is finalized. These changes provide a more consistent and explicit behavior for how the agent interacts with users in each mode.

codex-rs/collaboration-mode-templates · high confidence

Introduce unified execution handlers for exec\_command and write\_stdin

The unified execution subsystem now exposes dedicated tool handlers for \exec\_command\ and \write\_stdin\. The \exec\_command\ handler manages interactive and one-shot command lifetimes, enforcing sandbox permissions, TTY support, and environment resolution through the \UnifiedExecContext\. The \write\_stdin\ handler provides a mechanism to send input to existing execution sessions, handling approval rejections and output truncation. These changes centralize the execution logic, ensuring consistent permission checks and lifecycle management for shell interactions.

_codex-rs/core/src/tools/handlers/unified\exec · high confidence

Linux sandbox now bundles and compiles bubblewrap locally

The Linux sandbox implementation has been updated to compile and bundle the bubblewrap binary directly from vendored sources rather than relying on a system-installed version. This change introduces a new Rust crate (\codex\_bwrap\) that builds the bubblewrap C sources (including \libcap\ support) during the build process, ensuring the sandbox tool is self-contained and available on Linux targets without external dependencies. The build system (Bazel and Cargo) now handles the compilation and linking of bubblewrap, making the sandbox functionality more robust and portable across different Linux environments.

codex-rs/bwrap · high confidence

Refactor sandboxing to use Bubblewrap as the default Linux sandbox

The Linux sandboxing mechanism has been updated to use Bubblewrap (bwrap) as the default isolation tool, replacing the previous implementation. This change improves security boundaries and sandbox reliability for Linux users by leveraging a more robust containerization utility for command execution.

codex-rs/core · high confidence

SQLite state database schema evolution to version 58

The local SQLite state database has evolved through 58 migrations, introducing and refining the schema for threads, projects, and various subsystems. Key structural changes include the addition of thread sections and pinned items for organization, the introduction of projects with roots and idempotency keys, and the renaming of thread artifacts to attachments. The schema now supports agent goals with status tracking (including paused, blocked, and usage-limited states), remote control enrollments, and external agent config imports. Performance and sorting capabilities have been enhanced with numerous indexes on recency, archived status, and section ordering. Legacy tables for logs, agent jobs, and memory stages have been removed, while new columns track creator identity, originator, daybreak preferences, and history mode.

codex-rs/state/migrations · high confidence

Secure, cross-platform Unix socket rendezvous and directory management

The \codex-rs/uds\ crate introduces a unified, async Unix domain socket layer that enforces strict security on socket directories across platforms. On Unix, it creates and validates a fixed, owner-only (0700) daemon socket directory under \/tmp/codex-daemon-{uid}\ and resolves long symlink paths during connection to prevent failures. On Windows, it establishes a private, user-only directory with a protected DACL, validates existing directories against junctions and broad ACLs without repairing them, and authenticates socket peers by verifying that both the current and connecting processes run under the same non-elevated user token.

codex-rs/uds · high confidence

Switches rustls crypto provider to aws-lc-rs for broader certificate support

The application now uses the aws-lc-rs library as the default crypto provider for rustls instead of the previous default. This change enables support for ECDSA P-521/SHA-512 signature schemes, which are required by some enterprise TLS proxies. The new shared utility ensures the provider is installed process-wide while preserving any previously installed provider to maintain compatibility with embedded hosts.

codex-rs/utils/rustls-provider · high confidence

Unified Node.js entry point with platform-specific binary resolution

The codex-cli/bin/codex.js file now serves as the single entry point for the CLI, replacing previous platform-specific scripts. It dynamically resolves the correct native binary by mapping the current OS and architecture (Linux x64/arm64, macOS x64/arm64, Windows x64/arm64, and Android arm64) to specific npm packages (e.g., @openai/codex-linux-x64). The script also detects the package manager used for installation (npm, pnpm, bun, or Vite+) to provide accurate update instructions if the native binary is missing, and uses asynchronous spawning to ensure proper signal handling (e.g., Ctrl-C) for the child process.

codex-cli/bin · high confidence

Vendor bubblewrap 0.11.2 for Linux sandboxing

The \codex-rs/vendor\ directory now includes the source code for bubblewrap version 0.11.2, providing the underlying sandboxing engine for the Linux sandbox. This update incorporates critical security fixes, including [CVE redacted], which prevents ptracing of low-privileged setup processes in setuid mode. The vendored code is configured via \BUILD.bazel\ to expose C sources and headers for compilation, ensuring the sandbox binary is always built from this specific, audited version.

codex-rs/vendor · high confidence

Test coverage

Added Bazel test infrastructure for Wine-backed Windows exec-server integration tests; Added comprehensive integration tests for exec-server file system operations; Added comprehensive test suite for OpenTelemetry metrics and export behavior; Added comprehensive test suite for gRPC code-mode host; Added integration tests for API clients, models, and realtime WebSocket sessions; Added integration tests for MCP trace propagation and Responses API headers; Added integration tests for TUI backend and dependency constraints; Added integration tests for Windows remote environment execution via Wine; Added integration tests for Windows sandbox proxy routing and SID restrictions; Added integration tests for apply-patch CLI and security hardening; Added integration tests for cloud skill lifecycle and analytics; Added integration tests for execpolicy rule evaluation and network rules; Added integration tests for the exec event processor; Added integration tests for the login crate; Added integration tests for voice host lifecycle, installed client, and packaged runtime; Added test coverage for JSON schema policy fixtures; Added test fixture for OSS story session history; Added tests for context snapshot rendering and normalization; Added tests for extension API contracts and state management; Added tests for goal extension accounting, backend, and steering logic; Added tests for local agent message board persistence and subscription handling; Added tests for native user verification in MCP tool continuations; Added tests for shell snapshot replay and Windows MXC sandbox behavior; Added tests for step settings inheritance, budget preservation, and environment selection; Added tests for the Wine test harness library; Added tests for the skills extension and executor file system authority; Expanded CLI integration test coverage for daemon, config, and diagnostic commands; Expanded integration test coverage for TUI startup, daemon compatibility, and terminal rendering; Expanded integration tests for \codex exec\ capabilities; Expanded test coverage for MCP 2026 client capabilities and protocol modes; Expanded test coverage for app-server v2 integration scenarios; Expanded test coverage for exec-server capabilities and environment management; Integration test suite for Linux sandbox security and isolation; Migrate core integration tests to permission profiles; New Bazel test infrastructure for Wine, exec-server compatibility, and benchmarks; New integration tests for app-server authentication, logging, and configuration; New shared test support library for core integration tests; New test support infrastructure for exec-server integration tests; New test support library for app-server integration tests; New test support library for exec-server relay and environment testing; Removed obsolete agent loop test suite and fixtures; Snapshot tests for core conversation and context behaviors.

Dependencies

Upgrade Ratatui to 0.30.2

The TUI has been upgraded to use Ratatui version 0.30.2. This updates the underlying terminal UI framework, which may bring improvements to rendering stability, performance, or compatibility with terminal emulators.

(dependencies), codex-rs/tui · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 69.

Lenses

  • Code Health 77
  • Architecture 88
  • Maturity 74
  • Readiness 64
  • Security 75
  • Domain Modelling 91
  • Event Sourcing 100
  • Accessibility 68
  • Performance 85

Changes since last survey

  • 300 commits — 284 feature/other, 16 fixes

By area

  • codex-rs/core — 102 commits
  • codex-rs/tui — 65 commits
  • codex-rs/app-server — 16 commits
  • codex-rs/utils — 11 commits
  • codex-rs/exec-server — 9 commits
  • codex-rs/codex-api — 8 commits
  • codex-rs/ext — 7 commits
  • codex-rs/app-server-protocol — 6 commits
  • codex-rs/config — 6 commits
  • codex-rs/windows-sandbox-rs — 6 commits
  • codex-rs/linux-sandbox — 5 commits
  • (root) — 4 commits
  • codex-rs/app-server-daemon — 4 commits
  • codex-rs/mermaid — 4 commits
  • codex-rs/otel — 4 commits
  • codex-rs/cli — 3 commits
  • codex-rs/rmcp-client — 3 commits
  • .github/scripts — 2 commits
  • codex-rs/agent-message-board-client — 2 commits
  • codex-rs/app-server-client — 2 commits

Notable commits

  • fix: Fix ChatGPT browser sign-in for local app servers (#48502)
  • fix: Fix Guardian retained context spacing and empty assistant handling (#48158)
  • fix: Fix Mermaid shape, relationship, and state description parsing (#48489)
  • fix: Fix PID reservation test race and update guardian heartbeat snapshot (#47871)
  • fix: Fix SGR mouse reporting for Windows terminal capture (#48799)
  • fix: Fix TUI math rendering for zero and big wedge expressions (#48551)
  • fix: Fix Unix socket connections through long symlink paths (#48772)
  • fix: Fix a lost wakeup in the unified exec termination test (#47814)
  • fix: Fix attestation routing during thread startup (#47912)
  • fix: Fix macOS system-alias matching in patch permission checks (#47879)
  • fix: Fix no-reparse directory opens on Windows 10 (#47672)
  • fix: Fix read-only metadata mount ordering for nested writable roots (#47623)
  • fix: Fix sleep interruption test event handling and fixture lifetime (#47813)
  • fix: Fix spawn flag typing and isolate project configuration tests (#47704)
  • fix: Fix the session-start helper call in the command center test (#48646)
  • fix: Fix zsh alias quoting in sourced shell snapshots (#48187)
  • change: Add Pro Max plan support and update Pro display names (#47971)
  • change: Add Serde support to agent message board request types (#48077)
  • change: Add TUI composer support for prompt suggestions (#47911)
  • change: Add a keep-and-next action to the warnings viewer (#48206)
  • …and 280 more

Architecture

  • 0 containers · 1 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

openai/codex was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 69f7140559180269e2eb8f5be6e0c20eb37b0c85 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.