更新日志(中文)
[1.3.67] - 2026-10-11
新增
- API 服务与 API 账号卡片使用普通账号相同的代理按钮、预览和设置,支持跟随统一代理、选择独立代理或不使用代理。保留已有配置,设置控制启动的 Codex 桌面客户端出口,网关上游仍使用各自配置;所选代理准备失败时明确提示并阻止启动。
- Codex Responses WebSocket 支持转发中断请求,并在同一连接继续对话;HTTP 转发只中断对应响应,已知已结束回答(包括本地中断的 HTTP 回答与等待转发中断期间已结束的回答)的迟到中断会安全忽略,不会误停新回答,中断转发期间仍能及时处理客户端消息与断开。上游因托管工具等限制拒绝中断时,会保留原始错误,当前回答可继续完成,后续对话仍可进行。
- API 服务请求日志与详情显示受支持成功流式请求的近似输出 Token 速度,排除首响等待;已完整结束的回复在客户端随后断开时保留有效测量,中途取消或未完整结束的回复不测速度。当前日志页按有效样本计算加权速度,未测速度会说明短输出、缺少用量或计时、失败及取消等原因。
变更
-
Codex 顶部导航以主内容区为中心,在宽窗口中按可见页签收拢,避免尾部多余留白;会话管理收紧搜索筛选和日常操作,仅在存在会话时展示批量操作,禁用的删除操作使用中性样式。顶部排序支持本地保存失败提示与重试,并纳入配置备份。
-
恢复 Codex 账号卡片、清单、启动预览及 API 服务页的标准/快速选择。API 默认速度与账号速度分别保存,切号时将账号速度同步到目标实例,并写入客户端当前 profile。正确转发 Fast 请求别名,避免协议转换丢失客户端明确选择的标准档或将其统计为快速。默认保持标准档;请求显式档位与已有会话的独立速度设置优先。
-
Codex 会话可见性修复执行计划中的 rollout 文件时间校正,仅统计实际完成项;时间回滚保留当前文件内容,包括修复期间追加的历史。
-
API 服务新 OAuth 绑定默认保留 5 小时及周额度各 10%;绑定弹框以轻量行内摘要展示当前保留比例并支持编辑,已有保留比例及关闭状态保持不变。
-
API 服务请求日志按固定列对齐请求来源、账号、Token 用量、估算价值和性能;代理与请求 ID 列可按需显示并保存偏好,小窗口通过横向滚动保持字段对齐,固定操作列使用不透明背景。刷新期间保留当前列表或空状态,不再显示加载文案过渡;刷新失败时仍保留已有日志。
-
API 服务请求详情采用紧凑的耗时与速度卡片、层次清晰的账号尝试记录和独立快照区域,并适配小窗口布局;页面标题、速度控件和卡片操作保持清晰,避免互相挤压。
-
API 服务新配置默认每个账号允许 2 个并发请求;已有配置的限制保持不变,包括 0(不限制)。
修复
-
关闭应用内全局代理后恢复启动时继承的代理与绕过环境变量,首次以关闭状态启动时也保留原有环境。
-
Codex API 服务在取消或连接关闭与上游失败同时发生时保留已确认的限流冷却,包括首个流事件尚未输出的情况,及时停止向已取消的客户端输出,并避免影响较新的凭据。
-
Codex OAuth 续聊与本地上下文压缩回放搜索历史时补齐仅使用缓存的搜索工具声明,兼容 Responses Lite,并保留明确指定的工具选择。
-
Codex OAuth HTTP 请求遇到明确拒绝的历史推理或压缩密文时仅恢复重试一次,保留消息、推理摘要和工具结果;明确的错误目标不会清理未匹配的密文,Unicode 错误文本也能安全处理。被拒密文按账号、实际认证请求头与会话隔离,后续请求避免重复发送;恢复成功后的首响耗时包含重试等待。
-
Codex Chat 兼容请求缩短超长工具调用 ID,按原 ID 保持调用与结果配对,拒绝孤立结果误绑定,并避免与已有 ID 冲突。
-
使用 Chat 兼容供应商的实例网关在收到有效结束原因后支持正常 EOF,并保留末尾用量;未结束的候选回答、残缺函数参数、上游报错、读取失败与取消请求不会误判为完整回答,转换后的 Responses 事件保持正确的 SSE 分隔,空工具参数在各结束事件中保持一致。
-
Codex 紧凑账号视图在窄窗口保留账号名称和操作按钮,账号表格横向滚动不再受样式加载顺序影响,固定操作列不再透出底层文字。弹框内下拉菜单显示在所属弹框上方并适配视口,备份管理的关闭操作在滚动时保持可见。唤醒任务校验定位到错误字段;唤醒、OAuth 绑定、数据迁移、Codex 启动预览、公告和 API 服务使用风险提示弹框将键盘焦点保留在最上层,关闭后返回原控件;启动预览子弹框返回实际打开它的入口,点击遮罩丢失焦点后 Tab 会回到最上层弹框,Escape 按显示层级关闭当前弹框,即使低层弹框后打开也不会误关底层,待确认的唤醒请求显示在其他弹框上方。无效数据文件导入会明确提示 JSON 格式错误,不再误提示为空。状态、CLI、诊断和备份目录说明遵循所选语言及实际行为。
-
备份目录加载失败后仍可更换;旧备份不可读时可保留原文件,仅切换到可写目录,恢复选择在重启后保留,不移动账号或应用配置数据。备份读取过慢时显示可重试的超时提示,不再一直显示加载中。
-
Codex 账号授权过期、无效或被服务端撤销时,卡片、表格和紧凑视图保留重新授权入口,保存的错误提示不含原始错误码时也可重新登录。强制刷新 Token 遇到网络失败时,不再把仍有效的授权误报为已过期,也不会在没有授权失败依据时引导重新授权。
-
关闭 Responses WebSocket 传输后,已有 Codex 会话可自动回退 HTTP,保留上下文继续聊天,无需新建对话。
-
Codex 普通 OAuth 账号池的语音控制连接与通话创建统一使用同一本地网关,避免 404 失败,并保留用户明确设置的语音地址。
-
切换 Codex 对话后,额度与供应商余额徽章跟随当前可见输入区,位置及所选模型展示保持与当前对话一致。
-
API 服务在账号暂时读取失败时保留账号池与 Key 绑定,并自动限次重试恢复配置;部分账号不可读时,正常账号继续服务,受影响的 Key 保留原账号范围,账号重新保存后自动恢复。配置和凭据未变化且经本地核验的运行中服务可继续使用,恢复进度可见,恢复后清除旧提示;需要手动处理时提示检查账号与 Key 绑定。停用会取消恢复,已删除账号、撤销的 Key 和收紧的访问范围不会回退到旧配置。
-
Codex OAuth 账号选择“不使用代理”后,重启桌面客户端会直接联网,不再依赖 Cockpit 本地转接;退出 Cockpit 不再导致这些直连启动的客户端断网。
-
原生 Clash/Mihomo 订阅节点保留原始参数,不再使用 Cockpit 自行维护的协议或参数白名单,由已安装内核在测速和使用时判断兼容性。测速失败可重试,内核配置错误与连接失败分别提示,此前被拒绝的订阅缓存会提示刷新;继续保留本地文件访问、系统路由与持久化网络集成边界。
-
订阅下载区分 TLS 连接失败、链接被拒绝和跳转受限,避免把其他网络错误误提示为跨站跳转。
-
Codex 后台刷新配额、订阅或凭据时保留账号已保存的代理选择,切换节点、恢复跟随和禁用代理不会被覆盖。
-
Codex 历史修复与同步保留原始 rollout 字节和分页游标;已停止的实例可以接收相同历史的新增内容,不替换已有字节。拒绝无法安全重建的分页链部分转移、分叉合并、运行中目标的历史更新及旧日志备份覆盖。
-
Codex 会话导入拒绝清单与 rollout 会话 ID 不一致的包;批量导入后续会话保存索引失败时,保留此前成功导入会话的索引,仅移除当前失败会话的暂存文件。
-
设置为需要确认的 Codex 定时唤醒在确认后才发送;取消、关闭确认、超时和重启均不会发送或重放已认领请求。
-
删除导入或旧实例时保留原目录;注销实例时整目录移入回收站须匹配实例所有者,并有本应用创建目录的来源记录。
-
Grok OAuth 对话转发使用当前稳定版客户端版本,避免旧固定版本被上游拒绝;配额查询在本机 Grok CLI 版本检测失败时使用相同的新兜底版本。
-
客户端主动取消的 API 服务请求不再记成网关错误:请求日志按 499 与「客户端取消」归类,不再与网关故障混淆。
-
API 服务的模型不可用错误遵循所选语言,各请求路由使用一致的说明。
-
账号并发或用量冷却等重试类错误会带上可安全透出的
Retry-After重试时间,客户端可据此退避而不再盲目重试。
Changelog (English)
[1.3.67] - 2026-10-11
Added
-
API service and API account cards use the same proxy button, preview and settings as ordinary accounts: follow the unified proxy, select an independent proxy, or connect directly. Saved settings are preserved and control the launched Codex desktop client's route while gateway upstreams keep their own settings. Proxy preparation failures stop launch with an explicit error.
-
Codex Responses WebSocket connections forward response interruptions and support follow-up requests on the same connection. HTTP-backed turns interrupt only the matching response; late interrupts for known finished replies, including locally interrupted HTTP turns and replies completed while interruption forwarding waits, are safely ignored without stopping a newer reply, and interrupt forwarding keeps client reads and disconnect handling responsive. Upstream interruption rejections, including hosted-tool restrictions, are preserved without interrupting the current reply or preventing follow-up requests.
-
API Service request logs and details show approximate output token speed for supported successful streaming requests, excluding first-response waiting. Completed replies retain valid measurements when the client disconnects afterward; interrupted or incomplete replies remain unmeasured. A weighted average covers valid samples on the current page, and unmeasured speeds explain short output, missing usage or timing, and failed or canceled requests.
Changed
-
Restore Standard/Fast controls in Codex account cards, lists, launch previews and the API Service page. Keep API defaults separate from account speed, carry account speed into the target instance on switching, and update the selected client profile. Fast request aliases are forwarded correctly, and an explicit Standard choice is no longer lost during protocol conversion or recorded as Fast. Standard remains the default; explicit request tiers and existing chats' own speed settings take precedence.
-
Codex session visibility repair applies planned rollout timestamp corrections and reports only completed changes. Timestamp rollback preserves current rollout contents, including concurrent appends.
-
New API Service OAuth bindings reserve 10% of both the 5-hour and weekly quotas by default. The binding dialog displays the configured percentages in a compact inline summary for direct editing; existing saved percentages and disabled reservations remain unchanged.
-
Codex navigation centers its tab rail within the main content area and sizes it to visible tabs in wide windows. Session management uses compact search filters and maintenance actions; bulk actions appear only when sessions are available, and disabled destructive actions use a neutral style. Top-tab ordering reports local save failures with retry and is included in configuration backups.
-
API Service request logs use aligned columns for request sources, accounts, token usage, estimated values and performance. Proxy and request ID columns can be toggled with saved preferences; narrow windows keep columns aligned through horizontal scrolling, with opaque fixed action columns. Refreshing preserves the current rows or empty state without a loading-message transition; refresh failures keep existing logs visible.
-
API Service request details use compact latency and speed cards, clearer account attempt records and a dedicated snapshot view, with responsive layouts for small windows. Page titles, speed controls and card actions remain readable without squeezing each other.
-
New API Service configurations default to two concurrent requests per account. Existing saved limits, including 0 (unlimited), remain unchanged.
Fixed
-
Disabling the application proxy restores the proxy and bypass environment inherited at startup, including when the application first starts with the proxy disabled.
-
Codex API Service retains confirmed upstream rate-limit cooldowns when cancellation or a connection close overlaps an upstream failure, including before the first stream event is delivered, while stopping canceled client output promptly and keeping newer credentials unaffected.
-
Codex OAuth conversations declare cached-only search tools when replaying search history during continuation or local context compaction, including Responses Lite, while preserving explicit tool choices.
-
Codex OAuth HTTP requests recover once from specifically rejected historical reasoning or compaction ciphertext, preserving messages, reasoning summaries and tool results. Explicit error targets leave unmatched ciphertext untouched, and Unicode error text is handled safely. Rejected ciphertext is isolated by account, effective authentication headers and session so later requests can avoid resending it. Successful recovery includes the retry wait in first-response timing.
-
Codex Chat compatibility shortens oversized tool-call IDs while keeping each call paired with results matching its original ID, rejecting orphan results and avoiding collisions with existing IDs.
-
Instance gateways using Chat-compatible providers accept clean EOF after a valid finish reason and retain late usage data. Unfinished alternatives, incomplete function arguments, upstream errors, read failures and canceled requests are not mistaken for completed replies; translated Responses events retain valid SSE framing and consistent empty tool arguments across completion events.
-
Codex compact account views retain account names and actions in narrow windows; account tables keep horizontal scrolling regardless of stylesheet loading order, and fixed account-list actions do not show underlying text. Dialog dropdowns stay above their owning dialog and fit the viewport, and backup-manager close actions remain visible while scrolling. Wakeup-task validation locates the affected field. Wakeup, OAuth binding, data-transfer, Codex launch-preview, announcement and API Service risk-notice dialogs keep keyboard focus within the topmost dialog, restore the previous control on closing; launch-preview child dialogs return to the control that opened them, Tab recovers into the topmost dialog after backdrop focus loss, and Escape follows visible dialog layering even when a lower dialog opens later; pending wakeup confirmations remain visible above other dialogs. Malformed data imports report invalid JSON instead of empty input. Status, CLI, diagnostic and backup-folder descriptions follow the selected language and actual behavior.
-
Backup directory changes remain available after loading failures. Unreadable old backups can be left in place while switching to a writable folder; the recovery choice survives restarts without moving account or application configuration data. Slow backup reads show a retryable timeout instead of staying in a loading state.
-
Codex accounts with expired, invalid or server-revoked authorization retain their reauthorization action in card, table and compact views, including when the saved error message contains no original error code. A network failure during forced Token refresh no longer reports otherwise valid authorization as expired or directs users to reauthorize without an authentication failure.
-
Existing Codex conversations fall back to HTTP when Responses WebSocket transport is disabled, preserving conversation context without requiring a new chat.
-
Codex voice calls through ordinary OAuth account pools route their control connection through the same local gateway as call creation, avoiding 404 failures while preserving explicit user voice endpoints.
-
Codex quota and provider-balance badges follow the visible conversation composer after switching chats, keeping their position and selected-model display aligned with the current conversation.
-
API Service preserves account-pool and Key bindings during temporary account-read failures and retries configuration recovery automatically within a bounded budget. Available accounts keep serving when some accounts cannot be read; affected Keys retain their original account scopes and recover automatically after the accounts are saved again. Running services can remain available when their unchanged configuration and credentials pass local verification. Recovery progress is visible, stale messages clear after recovery, and cases requiring manual intervention point to account and Key bindings. Disabling cancels recovery; deleted accounts, revoked Keys and tightened access scopes never fall back to the previous configuration.
-
Codex OAuth accounts set to “No proxy” launch the desktop client with direct networking, without depending on Cockpit’s local relay after restart. Exiting Cockpit no longer disconnects these directly launched clients.
-
Native Clash/Mihomo subscription nodes preserve their parameters without a Cockpit-maintained protocol or parameter allowlist; the installed engine determines compatibility during testing and use. Failed tests remain retryable, engine configuration errors are distinguished from connection failures, and previously rejected cached subscriptions show a refresh prompt. Local file access, system routing and persistent network integration boundaries remain enforced.
-
Subscription download errors distinguish TLS failures, denied links and blocked redirects, avoiding a misleading redirect warning for unrelated network failures.
-
Codex account proxy choices remain saved during background quota, subscription and credential updates, including switching nodes, following shared settings or disabling proxies.
-
Codex history repair and synchronization preserve original rollout bytes and pagination cursors; stopped instances can receive matching history additions without replacing existing bytes. Unsafe partial paginated transfers, conflicting history merges, running-target history updates and stale rollout restores are rejected.
-
Codex session imports reject packages whose manifest and rollout session IDs disagree. If a later session cannot save its index, earlier successful imports retain their index entries and only the failed session's staged file is removed.
-
Scheduled Codex wakeups configured to require confirmation wait before sending. Cancellation, closing the confirmation, expiry, and restarts do not send or replay the claimed request.
-
Removing an imported or legacy instance preserves its directory. Trashing the directory while removing an instance requires a matching instance owner and a record that Cockpit created the directory.
-
Grok OAuth chat forwarding now sends the current stable client version to avoid rejection of the old pinned version. Quota queries use the same updated fallback when local Grok CLI version detection fails.
-
Client-canceled API Service requests are no longer recorded as gateway errors: request logs classify them as 499 with the client-canceled category instead of mixing them with gateway faults.
-
API Service model-unavailable errors follow the selected language, with consistent explanations across request routes.
-
Retry-class errors such as account concurrency or quota cooldown now carry a safely exposed
Retry-Aftertime so clients can back off instead of retrying blindly.