New Features
- Added experimental
/voiceconversations with live transcripts and microphone controls on supported builds, enabled through/experimental. (#43581, #43651, #44331) - The TUI now shows live reasoning summaries in the status row and completion timestamps after successful turns. (#43558, #43921)
- Added task hiding, archiving, and deletion in the agents overview, plus worktree ownership details and confirmed deletion of clean managed worktrees. (#43942, #44424, #44433)
- Added Touch ID verification for MCP requests in local TUI sessions on supported Macs. (#43624, #43712, #43715)
- Added configurable daemon update schedules and
codex app-server daemon update; saved threads and active goals can recover after daemon restarts. (#43542, #43562, #44314) - Amazon Bedrock can now obtain AWS credentials from configured commands, with caching, expiration-based refresh, and authentication recovery. (#44028)
Bug Fixes
- Accepted prompts are now saved even when compaction fails before a turn starts. (#44487)
- Fixed missed tmux resizes, transcript viewport restoration, and stale history appearing after switching threads. (#43603, #43889, #43994)
- MCP servers now report expired OAuth credentials accurately and provide reconnect guidance when token refresh fails. (#43947, #44359)
- Automatic approval reviews now preserve complete actions and authorization evidence more reliably, retry transient failures, and distinguish review failures from unsafe-action findings. (#44482, #44569, #44570)
- Switching accounts now invalidates remote-control sessions, cached WebSocket state, and model catalogs belonging to the previous identity. (#43906, #44341, #44489)
- Blocked Windows-process escapes from restricted WSL sandboxes and hardened brokered shell snapshots against credential exposure. (#44286, #43909, #44040)
Chores
- Aligned Python SDK and runtime publishing with stable CLI releases, using matching versions and verifying runtime assets before SDK publication. (#44067)
Changelog
Full Changelog: rust-v0.154.0...rust-v0.155.0
- #43521 Preserve standalone release pins during daemon updates @copyberry
- #43524 Restrict MCP user verification and add workspace-scoped identity @copyberry
- #43527 Discount an approval's own code-mode wrapper from Guardian score lag @copyberry
- #43529 Ensure the standalone updater runs on managed daemon starts @copyberry
- #43533 Fix jemalloc tools and compiler flags for Bazel musl builds @copyberry
- #43534 Preserve Guardian context sections and share planned-action rendering @copyberry
- #43538 Move Guardian permission context into the shared section registry @copyberry
- #43540 Preserve the multi-agent version when forking at a turn cutoff @copyberry
- #43542 Make app-server daemon automatic updates configurable @copyberry
- #43545 Preserve fork runtime versions without loading full model context @copyberry
- #43547 Add user-verification provider abstractions and RPC adapters @copyberry
- #43552 Record the launched app-server executable identity in PID files @copyberry
- #43558 Show completion timestamps after successful TUI turns @copyberry
- #43562 Add an explicit app-server daemon update command @copyberry
- #43568 Wire app-server user verification RPCs to the native provider @copyberry
- #43570 Manage synchronous Guardian reviewers through the thread manager @copyberry
- #43572 Make the managed app-server shutdown grace period configurable @copyberry
- #43576 Group adjacent computer actions in the TUI @copyberry
- #43581 Add live WebRTC voice conversations to the TUI @copyberry
- #43584 Remove a stale transcript field assignment from the TUI @copyberry
- #43595 Centralize bounded Guardian review evidence in guardian-context @copyberry
- #43597 Move trusted tool metadata into shared Guardian context @copyberry
- #43599 Move trusted skill evidence into the Guardian context registry @copyberry
- #43601 Move Guardian image selection into shared context sections @copyberry
- #43602 Move Guardian REPL evidence rendering into the shared context registry @copyberry
- #43603 Recover missed tmux resize notifications in the TUI @copyberry
- #43604 Exclude base instructions from the bundled model catalog @copyberry
- #43619 Add a stable TUI/app-server version comparison helper @copyberry
- #43621 Add worktree classification to thread telemetry @copyberry
- #43622 Warn when the connected Codex service is older than the CLI @copyberry
- #43624 Add macOS user verification with Secure Enclave signing @copyberry
- #43645 Expand TUI regression coverage for realtime voice conversations @copyberry
- #43651 Add voice mute shortcut and recording activity indicators @copyberry
- #43656 Animate live voice transcripts with split-flap tiles @copyberry
- #43676 Style spoken prompts and link workspace files in voice transcripts @copyberry
- #43683 Move voice controls into a dedicated composer strip @copyberry
- #43690 Make the voice mute shortcut configurable in the TUI @copyberry
- #43695 Stabilize realtime voice meter sampling across redraws @copyberry
- #43698 Make older app-server notices configurable in the TUI @copyberry
- #43699 Preserve split-flap animation state when voice transcripts scroll @copyberry
- #43702 Add a TUI user verification prompt component @copyberry
- #43704 Disable clock synchronization in the voice audio sink @copyberry
- #43708 Add TUI request bookkeeping for user verification @copyberry
- #43712 Enable MCP user verification in the TUI @copyberry
- #43715 Enable user verification for the bundled TUI on supported devices @copyberry
- #43790 Limit app-server storage metrics to session directories @copyberry
- #43795 Pin request reasoning effort while configuration overrides are active @copyberry
- #43796 Preserve reasoning effort through compaction and reset it on success @copyberry
- #43797 Add configurable memory versions with isolated storage @copyberry
- #43798 Batch non-user history eviction to preserve Guardian transcript deltas @copyberry
- #43799 Prioritize human evidence in memory v2 extraction @copyberry
- #43800 Add summary-only extraction for memory v2 @copyberry
- #43805 Centralize Guardian context composition @copyberry
- #43806 Centralize Guardian transcript policy in context profiles @copyberry
- #43808 Move v2 extraction chunking into the memory writer @copyberry
- #43813 Add dedicated memory v2 consolidation and read prompts @copyberry
- #43827 Add memory dual writing and v2 readiness reporting @copyberry
- #43842 Wait for parent idle before rollback in guardian fork tests @copyberry
- #43844 Add staged enterprise OIDC login and coordinated logout @copyberry
- #43846 Include completed commentary in the
/copypicker @copyberry - #43848 Preserve runtime workspace roots across thread resume @copyberry
- #43853 Add canonical permission translation for MXC execution requests @copyberry
- #43870 Close MCP stderr readers on client teardown @copyberry
- #43873 Handle undefined values before JSON serialization in code mode @copyberry
- #43876 Detach Unix hook commands from the controlling terminal @copyberry
- #43884 Close active network proxy connections on teardown @copyberry
- #43889 Fix transcript viewer restoration and half-page scrolling @copyberry
- #43894 Preserve thread identity in code-mode tool dispatch traces @copyberry
- #43895 Preserve
__oailbrouting cookies in ChatGPT HTTP clients @copyberry - #43897 Persist provider and auth identity with model catalog caches @copyberry
- #43900 Propagate Apps tool refreshes to existing threads @copyberry
- #43903 Extract Windows deny-read glob scan planning into protocol @copyberry
- #43906 Scope model catalog caches to the current provider and auth identity @copyberry
- #43907 Preserve complete shell snapshot exports through filtering and replay @copyberry
- #43909 Protect shell snapshots when credential brokerage is enabled @copyberry
- #43912 Keep Guardian reviewers on summary-based compaction @copyberry
- #43913 Add tracing for project instructions and filesystem sandbox operations @copyberry
- #43915 Remove the repository devcontainer configurations @copyberry
- #43918 Expose the queued event count on
CodexThread@copyberry - #43921 Show streaming reasoning summaries in the TUI status row @copyberry
- #43925 Add cancellation for native user-verification RPCs @copyberry
- #43927 Rename thread artifacts to attachments in the state database @copyberry
- #43930 Avoid Windows sandbox setup for irrelevant proxy port changes @copyberry
- #43934 Track voice session lifecycle metrics in the TUI @copyberry
- #43936 Stabilize subagent and unified exec test fixtures @copyberry
- #43937 Tag TUI startup metrics with terminal and multiplexer categories @copyberry
- #43939 Add executor-context filesystem permission helpers @copyberry
- #43942 Show worktree owner details and add confirmed deletion @copyberry
- #43943 Gate new turn submissions on host shutdown admission @copyberry
- #43947 Surface MCP reconnect signals when expired OAuth tokens cannot refresh @copyberry
- #43948 Show configured app-server updater settings in doctor @copyberry
- #43949 Add transactional thread attachment mutations to the state runtime @copyberry
- #43950 Keep app-server thread RPCs active until delegated work completes @copyberry
- #43953 Preserve per-image generation IDs in image generation analytics @copyberry
- #43954 Cache protected shell snapshots and harden capture cleanup @copyberry
- #43956 Increase the TUI thread capability test stack to 12 MiB @copyberry
- #43959 Gate new app-server work during graceful shutdown @copyberry
- #43961 Use curly apostrophes in protocol error messages @copyberry
- #43966 Heap-allocate the resume future in the legacy history test @copyberry
- #43983 Bundle signed voice resources in macOS releases @copyberry
- #43994 Clear stale transcript history when switching threads @copyberry
- #44002 Encapsulate executed tool call metadata recording @copyberry
- #44025 Refresh workspace lockfile before building macOS voice releases @copyberry
- #44027 Support image attachments in agents overview background tasks @copyberry
- #44028 Add AWS credential export commands for Amazon Bedrock @copyberry
- #44032 Generate Python SDK types from repository app-server schemas @copyberry
- #44038 Handle copied credentials in the broker and shell snapshots @copyberry
- #44040 Harden credential handling in shell snapshots and replay @copyberry
- #44043 Use
StartThreadOptionsacross thread fork APIs @copyberry - #44049 Extract credential broker environment and registry helpers @copyberry
- #44053 Test Python SDK against the built CLI and installed runtime @copyberry
- #44055 Gate Python SDK publishing on runtime availability and verify PyPI files @copyberry
- #44056 Add configurable credential providers to the network proxy @copyberry
- #44060 Raise Guardian's action review limit to 200,000 bytes @copyberry
- #44061 Build Python SDK artifacts before publishing the runtime @copyberry
- #44062 Fix voice runtime release builds and packaging @copyberry
- #44066 Extend configured credential brokerage to embedded aliases @copyberry
- #44067 Publish Python packages after stable CLI releases @copyberry
- #44068 Preserve credential broker destinations across environment filtering @copyberry
- #44070 Reject empty audio payloads in data URLs @copyberry
- #44072 Support configured credential providers across shell snapshots @copyberry
- #44077 Refactor credential-broker tunnel protocol detection @copyberry
- #44080 Make staged macOS voice runtimes writable before packaging @copyberry
- #44084 Expose Python SDK history selection and per-turn options @copyberry
- #44086 Add untrusted external messages to the Python SDK @copyberry
- #44089 Support credential brokering in plaintext HTTP tunnels @copyberry
- #44101 Handle empty voice arguments in macOS release packaging @copyberry
- #44121 Reuse MCP bindings while cached servers remain dormant @copyberry
- #44138 Coordinate rollout compression with active thread writers @copyberry
- #44164 Add Guardian context cost and request token telemetry @copyberry
- #44166 Add aggregate budget enforcement for Guardian context @copyberry
- #44175 Attach compressed rollouts to diagnostic reports as JSONL @copyberry
- #44176 Reduce TUI stack usage during session transitions @copyberry
- #44181 Use explicit histogram buckets for Guardian context metrics @copyberry
- #44183 Release persistent writers when session startup is cancelled @copyberry
- #44198 Preserve voice indicator styles during composer sparkle effects @copyberry
- #44200 Use captured step settings when building model context @copyberry
- #44202 Use captured step model settings for extension context @copyberry
- #44207 Measure total exec-server request duration including queueing @copyberry
- #44226 Continue rollout searches when a compressed rollout cannot be searched @copyberry
- #44227 Extract Guardian review policy into a dedicated crate @copyberry
- #44238 Fix MCP elicitation cancellation and reset state on reconnect @copyberry
- #44241 Handle credential provider source remapping across config layers @copyberry
- #44242 Use captured step settings for tool planning and execution @copyberry
- #44243 Use the originating model when recording conversation history @copyberry
- #44248 Preserve tool output truncation budgets across resume and fork @copyberry
- #44249 Normalize image detail for the receiving model @copyberry
- #44250 Remove retired model entries while preserving migration prompts @copyberry
- #44252 Move synchronous Guardian orchestration into the reviewer extension @copyberry
- #44255 Always use streamed remote compaction for supported providers @copyberry
- #44259 Remove the Windows
/sandbox-add-read-dirslash command @copyberry - #44273 Remove the unused legacy remote compaction implementation @copyberry
- #44276 Avoid duplicate reasoning effort updates during turn recovery @copyberry
- #44277 Surface environment startup failure reasons to the model @copyberry
- #44281 Enforce complete request budgets for Guardian reviews @copyberry
- #44283 Persist loaded threads before managed daemon shutdown @copyberry
- #44284 Add telemetry for the Windows system config namespace @copyberry
- #44285 Preserve prewarmed reasoning effort across replay and early rollback @copyberry
- #44286 Block WSL interop escapes from restricted filesystem sandboxes @copyberry
- #44288 Prevent command hooks from hanging on blocked stdin @copyberry
- #44289 Expand MXC volume grants and resolve deny globs @copyberry
- #44290 Allow user-requested goal pauses through
update_goal@copyberry - #44293 Enforce the async Guardian classifier's complete input budget @copyberry
- #44297 Isolate the hook pipe I/O timeout test from shell startup files @copyberry
- #44298 Set turn triggers for guardian and memory requests @copyberry
- #44299 Record thread recovery candidates on managed daemon shutdown @copyberry
- #44307 Add opt-in provisioned macOS CLI release candidates @copyberry
- #44311 Honor shared Retry-After deadlines for remote control @copyberry
- #44314 Restore saved threads when the managed daemon restarts @copyberry
- #44318 Give hosted Codex Apps an independent MCP protocol opt-in @copyberry
- #44320 Block goals after three empty automatic continuation turns @copyberry
- #44325 Return the prompt hash in upload responses @copyberry
- #44327 Prevent filesystem-root read denies in the Windows sandbox @copyberry
- #44328 Clear pending TUI questions when accepting a new prompt @copyberry
- #44330 Add paginated thread attachment listing to the state runtime @copyberry
- #44331 Expose voice conversations in experimental features @copyberry
- #44332 Persist disabled plugin IDs in thread settings @copyberry
- #44336 Add bounded tool-result metadata support to executed tool calls @copyberry
- #44337 Return to the agent command center after archiving on shared servers @copyberry
- #44341 Bind remote-control sessions to their authentication owner @copyberry
- #44344 Open tasks with Right from the agents overview @copyberry
- #44346 Support native verification in MCP tool continuations @copyberry
- #44349 Distinguish forked sessions in session-start hooks @copyberry
- #44350 Add thread attachment operations with coordinated deletion @copyberry
- #44352 Remove path-bearing fields from Guardian review analytics @copyberry
- #44354 Extract shared footer hint wrapping in the TUI @copyberry
- #44359 Report OAuth authentication failures in MCP status snapshots @copyberry
- #44360 Return focus to the agents overview composer on Escape @copyberry
- #44377 Update the forked-thread hook test to use
StartThreadOptions@copyberry - #44392 Add opt-in model discovery for OpenAI API keys @copyberry
- #44400 Start Python SDK turn subscriptions at their attachment point @copyberry
- #44424 Add a hide shortcut to the agents overview @copyberry
- #44433 Add archive and delete actions to the agents overview @copyberry
- #44472 Harden Code Mode tool-call completeness tracking @copyberry
- #44482 Improve Guardian retries and review failure reporting @copyberry
- #44487 Preserve incoming prompts when pre-turn compaction fails @copyberry
- #44489 Reset cached WebSocket state when auth ownership changes @copyberry
- #44492 Distinguish HTTP quota errors from rate limits @copyberry
- #44493 Bound MCP descriptions separately from Guardian action JSON @copyberry
- #44521 Decouple session isolation from subagent attribution @copyberry
- #44523 Bound app-server stdio shutdown and handle Unix SIGTERM gracefully @copyberry
- #44536 Move Guardian reviewer settings and execution into the reviewer crate @copyberry
- #44544 Move Guardian reporting and denial accounting into the extension @copyberry
- #44548 Add MIME-filtered resource listing for Codex Apps @copyberry
- #44564 Add app-server APIs for stored thread attachments @copyberry
- #44569 Preserve complete actions in Guardian approval reviews @copyberry
- #44570 Preserve Guardian authorization evidence until request budgeting @copyberry
- #44571 Allow extensions to select MCP protocol mode per HTTP server @copyberry
- #44574 Use captured action settings for Guardian reviews @copyberry
- #44575 Tie network approval reviews to their originating execution @copyberry
- #44580 Support symbolic
:rootfilesystem policies in MXC @copyberry - #44586 Remove
repo_urlfrom skill invocation analytics events @copyberry