Changed
- Codex runtime simplified around workspace-write —
nah run codexnow
uses one protected local interactive preset: Codexworkspace-write,
on-request, user approvals, nahPermissionRequesthooks, and preflight.
Normal Codex UI flags still pass through, while sandbox/approval overrides
remain rejected because nah owns that safety boundary. (nah-908)
Removed
- Removed Codex flow/edit mode surface — removed nah-owned
--flow,
--auto-edits,--no-sandbox, explicit--sandbox, and hook-side safe
apply_patchauto-allow behavior fromnah run codex. Safe project edits
should flow through Codexworkspace-write; riskyapply_patchpermission
requests still ask or block after nah path/content checks. (nah-908)