Skip to content

Codex 0.160.0; repo hooks and project config inert - #456

Merged
renmengye merged 2 commits into
mainfrom
chore/codex-0.160.0
Oct 3, 2026
Merged

renmengye merged 2 commits into
mainfrom
chore/codex-0.160.0

Conversation

@renmengye

Copy link
Copy Markdown
Member

Bumps the pinned Codex CLI from 0.130.0 to 0.160.0 and keeps repository-supplied hooks and project config from reaching kernel sessions.

Why

0.130.0 is thirty releases old. 0.160.0 adds lifecycle hooks, including project-level hook configs, and auto-trusts a writable working directory, so a tree can now carry .codex/config.toml and .codex/hooks.json that a Codex session started in it will load. Agent-written trees are untrusted: an author's line must not instruct its successor, and a judge must never run code or read instructions planted in the tree it reviews.

What changes

  • harnesses.toml: codex 0.160.0 with the published SHA-256 of codex-x86_64-unknown-linux-musl.tar.gz.
  • Contained Codex sessions (authors and judges, fresh and resumed) bind a packaged requirements.toml read-only at /etc/codex/requirements.toml with allow_managed_hooks_only = true (0.160.0 reads requirements only from that path). Uncontained sessions pass -c features.hooks=false -c features.plugins=false after operator args.
  • Every launch rebuilds $CODEX_HOME/config.toml (no symlink following), so persisted hook trust from a previous session never survives a resume. --dangerously-bypass-hook-trust in operator args is refused.
  • .codex joins INSTRUCTION_FILES: judge checkouts rename it and line branches reset it to the base version, like .claude and AGENTS.md.
  • SECURITY.md documents the hook and project-config behavior.

Verification

  • codex exec --help / codex exec resume --help diffed against 0.130.0: no flags removed.
  • --json events unchanged (thread.started → thread_id, turn.completed usage, with two new usage fields); codex exec resume <thread_id> recalls the session. Checked on Linux against a Responses endpoint.
  • Real-binary mutation probe (opt-in test, darwin build, mock Responses server): a planted project hook writes no marker under the guard on fresh and resumed launches, and does write it with the guard removed.
  • New sanitizer test for .codex; fails with .codex removed from the list.
  • Gate: ruff check, ruff format --check, mypy, pytest (2943 passed, 12 skipped).

Not verified here: the real binary under Apptainer (the policy bind and launch wiring are unit-tested).

Upgrading: no manual action.

Built by Codex (gpt-5.6); the .codex sanitizer addition and review by Claude.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head 701b046c — reviewer summarizer:hermes/gpt-5.6-terra over coverage+credentials+deployment+general+lifecycle+prose.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: 4 blocking, 1 advisory.

4 findings attached to the lines below.

Advisory (non-blocking):

  • Suggestion: Line .codex reset has no regression test. [coverage] The only line-checkout test seeds CLAUDE.md, .mcp.json, and .claude, so removing .codex from INSTRUCTION_FILES would leave all tests here passing and let a line preserve project config into its next author session. (tests/test_attempt.py:4333; high confidence)

Four blocking configuration-isolation findings and one advisory test-coverage gap were merged. No submitted finding was rejected: the credentials, general, lifecycle, and prose lenses identify distinct execution or restoration paths; the prose item is retained as a suggestion per the brief.

Comment thread src/outerloop/harness.py
Comment thread src/outerloop/harness.py
Comment thread src/outerloop/review_agent.py
Comment thread src/outerloop/harness.py

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head 8f60495c — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: no defects found.

@renmengye
renmengye merged commit 87b4dc7 into main Oct 3, 2026
5 checks passed
@renmengye
renmengye deleted the chore/codex-0.160.0 branch October 3, 2026 04:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant