Repository navigation
Codex 0.160.0; repo hooks and project config inert - #456
Merged
Merged
Conversation
There was a problem hiding this comment.
Round 1 — reviewed head 701b046c — reviewer summarizer:hermes/gpt-5.6-terra over coverage+credentials+deployment+general+lifecycle+prose.
terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.
Verdict: 4 blocking, 1 advisory.
4 findings attached to the lines below.
Advisory (non-blocking):
- Suggestion: Line .codex reset has no regression test. [coverage] The only line-checkout test seeds CLAUDE.md, .mcp.json, and .claude, so removing .codex from INSTRUCTION_FILES would leave all tests here passing and let a line preserve project config into its next author session. (
tests/test_attempt.py:4333; high confidence)
Four blocking configuration-isolation findings and one advisory test-coverage gap were merged. No submitted finding was rejected: the credentials, general, lifecycle, and prose lenses identify distinct execution or restoration paths; the prose item is retained as a suggestion per the brief.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the pinned Codex CLI from 0.130.0 to 0.160.0 and keeps repository-supplied hooks and project config from reaching kernel sessions.
Why
0.130.0 is thirty releases old. 0.160.0 adds lifecycle hooks, including project-level hook configs, and auto-trusts a writable working directory, so a tree can now carry
.codex/config.tomland.codex/hooks.jsonthat a Codex session started in it will load. Agent-written trees are untrusted: an author's line must not instruct its successor, and a judge must never run code or read instructions planted in the tree it reviews.What changes
harnesses.toml: codex 0.160.0 with the published SHA-256 ofcodex-x86_64-unknown-linux-musl.tar.gz.requirements.tomlread-only at/etc/codex/requirements.tomlwithallow_managed_hooks_only = true(0.160.0 reads requirements only from that path). Uncontained sessions pass-c features.hooks=false -c features.plugins=falseafter operator args.$CODEX_HOME/config.toml(no symlink following), so persisted hook trust from a previous session never survives a resume.--dangerously-bypass-hook-trustin operator args is refused..codexjoinsINSTRUCTION_FILES: judge checkouts rename it and line branches reset it to the base version, like.claudeandAGENTS.md.Verification
codex exec --help/codex exec resume --helpdiffed against 0.130.0: no flags removed.--jsonevents unchanged (thread.started→thread_id,turn.completedusage, with two new usage fields);codex exec resume <thread_id>recalls the session. Checked on Linux against a Responses endpoint..codex; fails with.codexremoved from the list.Not verified here: the real binary under Apptainer (the policy bind and launch wiring are unit-tested).
Upgrading: no manual action.
Built by Codex (gpt-5.6); the
.codexsanitizer addition and review by Claude.