## 新功能
- 远程插件现已默认启用,拥有更丰富的目录行、npm 市场来源,并显示远程/本地版本。(#30297, #26705, #29375, #30981)
- Codex 现在可以路由身份验证和 Responses API 流量通过 macOS 和 Windows 系统代理,包括 PAC 和 WPAD 配置。(#26708, #26709, #31335)
- 新增 `codex remote-control pair` 命令,用于从正在运行的守护进程生成手动配对码。(#29913)
- 新增 Amazon Bedrock GPT-5.6 Sol、Terra 和 Luna 模型,并对 `max` 推理努力提供一等支持。(#30285, #30467)
- MCP 工具现在默认使用工具搜索,ChatGPT 托管的 MCP 服务器可以明确使用会话身份验证。(#29486, #29733)
- 应用服务器客户端可以检查环境、列出子线程,并通过特定轮次进行历史分支。(#30291, #29591, #30277)
## 错误修复
- 修复了 Windows ConPTY 输入处理中的换行和退格问题,以及沙箱凭据重试的边界情况。(#29734, #29624, #29637)
- 修复了过时的 TUI 安全提示和已取消的审查可能导致 MCP 启动显示繁忙状态的问题。(#30490, #31189)
- 改进了执行服务器暂时离线时的恢复能力,防止了远程控制令牌刷新的重试风暴。(#30098, #30201)
- 在关闭时保留尾随的实时转录文本和终端滚动事件。(#29918, #30144)
- 通过忽略比较中的响应元数据,提高了增量 WebSocket 请求的成功率。(#30770)
- 通过复用发布元数据,减少了因 GitHub API 速率限制导致的安装失败。(#31056)
## 文档
- 记录了 UUID7 线程和轮次 ID,以及推荐的远程执行器集成测试工作流。(#27714, #29790)
## 杂项
- 更新了 OpenSSL、Hono、fast-uri、quick-xml 和 crossbeam-epoch,以解决安全公告问题。(#29487, #29650, #30941, #31308)
## 更新日志
完整更新日志:https://github.com/openai/codex/compare/rust-v0.142.0...rust-v0.143.0
- #26708 PAC 3 - 添加 Windows 系统代理解析器 @canvrno-oai
- #28769 注册完整的 CDP 需求特性 @syuan-oai
- #29485 [codex] 获取远程插件的特色 ID @ericning-o
- #29487 将捆绑的 OpenSSL 升级到 3.6.3 @jif-oai
- #29489 [codex] 更新 esbuild 到 0.28.1 @pakrym-oai
- #29488 [plugins] 添加深色模式徽标元数据 @drewschuster-openai
- #29249 [codex] 将环境上下文迁移到模型世界状态 @pakrym-oai
- #29494 core: 包装令牌预算窗口上下文 @bolinfest
- #29417 [codex] 用模型可见的错误文本替换远程图像 @rka-oai
- #28360 feat(core): 在 ResponseItem 元数据中存储 turn_id @owenlin0
- #29486 [codex] 默认对 MCP 工具使用工具搜索 @sayan-oai
- #29501 path-uri: 阐明主机原生路径转换 @anp-oai
- #29504 fix: 世界状态响应项测试 @celia-oai
- #26704 TUI 插件共享 4 - 覆盖远程插件目录流程 @canvrno-oai
- #29419 [codex] 在应用服务器入口拒绝远程图像 @rka-oai
- #28992 chore: 改进过期的 Bedrock 凭据错误 @celia-oai
- #29467 使格式化程序在成功时输出静默 @anp-oai
- #26709 PAC 4 - 添加 macOS 系统代理解析器 @canvrno-oai
- #29490 chore: 当代码模式缺少模型元数据时发出警告 @celia-oai
- #29493 mcp: 接受远程 stdio 的外部绝对 cwd @anp-oai
- #29473 传播安全缓冲处理元数据 @fc-oai
- #24092 [codex] 拒绝未降低的 PowerShell AST 区域 @bookholt-oai
- #29155 [codex] 在 OTEL 中暴露服务层级和推理努力 @daniel-oai
- #29068 [codex] 样式更改 @rka-oai
- #29518 移除冗余的 Codex Apps 管理器标志 @aibrahim-oai
- #27946 [codex] 为 Responses Lite 工具使用输入项 @rka-oai
- #29528 集中化 Codex Apps 客户端处理 @aibrahim-oai
- #29577 处理图像 URL 验证中的附加工具 @aibrahim-oai
- #29575 移除冗余的 Codex Apps 缓存保护 @aibrahim-oai
- #29583 分组 Codex Apps 客户端设置 @aibrahim-oai
- #29358 允许 codex 沙箱消费 MCP 沙箱状态 @jif-oai
- #29599 停止持久化桥接的日志事件 @jif-oai
- #29615 修复 Codex Apps 认证诱导挂起 @jif-oai
- #29067 在协作命名空间下组织多代理 v2 工具 @jif-oai
- #29614 path-uri: 添加词汇包含 @jif-oai
- #28426 共享恢复的滚动历史 @charliemarsh-oai
- #29634 更新 rmcp 到 1.8.0 @jif-oai
- #29650 更新易受攻击的 Hono 和 fast-uri 依赖 @jif-oai
- #29498 [codex] 检测滚动持久化字节 @wiltzius-openai
- #29659 [core] 按经过时间去抖动当前时间提醒 @rka-oai
- #29608 在刷新时关闭被取代的 MCP 管理器 @jif-oai
- #29527 core: 使用轮次拥有的世界状态进行内联压缩 @sayan-oai
- #29672 [codex] 处理滚动持久化指标中的附加工具 @rka-oai
- #29669 处理滚动持久化指标中的附加工具 @winston-openai
- #29680 回滚“处理滚动持久化指标中的附加工具” @rasmusrygaard
- #27714 app-server: 记录线程和轮次 ID 为 UUID7 @owenlin0
- #29456 准备托管网络沙箱上下文 @jif-oai
- #28418 chore(core) 移除 AskForApproval::OnFailure @dylan-hurd-oai
- #29675 core: 向 Thread 结构添加额外元数据字段 @kumquatexpress
- #29013 将托管的 MITM CA 私钥保留在代理内存中 @winston-openai
- #29495 分离本地和远程插件分析 ID @jameswt-oai
- #29671 [codex] 为文件系统沙箱助手保留代理状态 @iceweasel-oai
- #29513 [codex] 允许使用提供者认证进行图像生成 @richardopenai
- #29526 core: 在选定环境中解析 view_image 路径 @anp-oai
- #29696 [codex] 修复 MCP 测试中的过期批准策略 @sayan-oai
- #29704 [codex] 修复 MCP 测试中的过期批准策略 @kumquatexpress
- #29547 core: 为工具使用当前步骤环境 @sayan-oai
- #28976 添加 MCP 工具调用错误指标 @stevenlee-oai
- #27045 feat(guardian): 在应用审查中包含连接账户电子邮件 @viyatb-oai
- #29620 解耦插件清单路径解析 @jif-oai
- #29666 [codex] 报告执行服务器工作目录 @rasmusrygaard
- #29705 feat(app-server): thread/turns/items/list -> thread/items/list @owenlin0
- #29716 code-mode: 重命名 codex_code_mode::CodeModeService @cconger
- #29712 test: 根据目标操作系统而非运行环境进行分支 @anp-oai
- #29728 core 测试: 重命名自动环境构建器 @anp-oai
- #29158 path-uri: 移除遗留路径反序列化 @anp-oai
- #29519 core: 持久化初始上下文窗口元数据 @bolinfest
- #28918 使选定的插件根路径 URI 原生 @jif-oai
- #29515 [codex] 定义代码模式主机握手协议 @cconger
- #29715 [codex] 表面滚动预算耗尽 @rka-oai
- #29732 code-mode: 移除 Session::is_alive() @cconger
- #29626 加载执行器技能而不进行主机路径转换 @jif-oai
- #29714 protocol: 分离应用和执行 RPC 所有权 @anp-oai
- #29664 refactor: 提取上下文窗口令牌状态 @bolinfest
- #29665 fix: 将上下文剩余限制在正文窗口内 @bolinfest
- #29744 [codex] 将滚动预算错误重命名为会话预算错误 @rka-oai
- #29739 更新 new_context_window 说明 @andmis
- #29743 core: 为令牌预算压缩重置上下文 @bolinfest
- #29477 支持线程级发起者覆盖 @alexsong-oai
- #29745 core: 添加 wait_for_environment 以启动环境 @sayan-oai
- #28630 [codex] 追踪 MCP 启动延迟 @rphilizaire-openai
- #29750 chore: 为代理消息分配 `amsg_` ID @bolinfest
- #29746 test: 添加应用服务器自动环境助手 @anp-oai
- #29711 让图像生成扩展主机控制输出持久化 @won-openai
- #29762 [codex] 为新上下文窗口复用压缩历史替换 @pakrym-oai
- #29768 [codex] 更新捆绑技能安装指南 @sayan-oai
- #29690 [plugins] 添加市场来源要求 @xl-openai
- #29765 [codex] 远程目录激活时忽略本地策划插件 @xl-openai
- #29767 [codex] 在分支历史中分配响应项 ID @pakrym-oai
- #29721 auth: 将域模式移动到应用线缆类型之下 @anp-oai
- #29753 [plugins] 强制执行市场来源准入要求 @xl-openai
- #29722 config: 拥有层来源类型 @anp-oai
- #29723 connectors: 拥有应用元数据类型 @anp-oai
- #29788 test: 在 Wine 下运行应用服务器集成测试 @anp-oai
- #29789 test: 在应用服务器集成测试中使用自动环境 @anp-oai
- #29790 docs: 记录远程执行器集成测试 @anp-oai
- #29815 [codex] 移除自动压缩选择退出 @rhan-oai
- #29628 保持执行器插件 MCP 路径为 URI 原生 @jif-oai
- #29731 [codex] 为支持读取发射隐式技能使用 @alexsong-oai
- #29829 将代理消息持久化为响应项 @jif-oai
- #29841 添加有界文件系统遍历 RPC @jif-oai
- #29842 使用 fs/walk 进行环境技能发现 @jif-oai
- #29567 [codex] 显示外部导入结果计数 @charlesgong-openai
- #29831 在执行器技能发现期间缓存插件命名空间 @jif-oai
- #29720 ci: 失败会弄脏工作树的作业 @anp-oai
- #29887 修复合并后的环境技能发现 @jif-oai
- #29734 [codex] 修复 Windows ConPTY 输入处理 @iceweasel-oai
- #28593 [codex] 当有可用信用时抑制低使用量剩余警告 @brooks-oai
- #29624 在凭据重试期间保留 Windows 沙箱身份 @jif-oai
- #27466 [codex] 追踪执行服务器 JSON-RPC 请求 @richardopenai
- #29844 在文件系统遍历中跟随目录符号链接 @jif-oai
- #29637 跳过 WindowsApps 启动失败的凭据刷新 @jif-oai
- #29591 feat(app-server): 按祖先列出后代线程 @btraut-openai
- #28034 feat(network-proxy): 实验性本地凭据代理 @winston-openai
- #29736 [codex] 将代理图存储注入 ThreadManager @wiltzius-openai
- #29889 [apps] 通过应用列表传递结构化图标资产 @drewschuster-openai
- #29724 mcp: 将诱导请求保持在应用线缆类型之下 @anp-oai
- #29684 [plugins] 按 ID 跟踪插件安装请求 @adaley-openai
- #29870 管道有界 AGENTS.md 和 Git 根探测 @jif-oai
- #29893 [codex] 去重远程控制账户标头 @shuo-openai
- #29851 添加连接器声明快照 @jif-oai
- #29903 path-uri: 规范化绝对连接中的父段 @anp-oai
- #29852 从执行器插件读取连接器声明 @jif-oai
- #29785 隔离策划插件同步 Git 环境 @etraut-openai
- #29907 [codex] 将 sleep 命名空间置于 clock 下 @rka-oai
- #29910 [codex] 将 sleep 配置嵌套在当前时间提醒下 @rka-oai
- #29913 feat(remote-control): 添加守护进程配对命令 @apanasenko-oai
- #29936 core: 添加可配置的 <context_window_guidance> 消息 @bolinfest
- #26705 TUI 插件共享 5 - 打磨远程插件目录行 @canvrno-oai
- #29733 允许 ChatGPT 托管的 MCP 服务器使用会话认证 @aibrahim-oai
- #29833 [1/3] core: 使世界状态快照可序列化 @sayan-oai
- #29919 TUI 支持缓冲体验 @etraut-openai
- #29924 用枚举表示 MCP 认证 @aibrahim-oai
- #29804 code-mode: 定义进程主机线缆协议 @cconger
- #29956 [codex] 填充远程插件本地版本 @abhinav-oai
- #29835 [2/3] core: 在滚动中持久化世界状态 @sayan-oai
- #29899 [codex] 更新推理努力 @shijie-oai
- #29837 [3/3] core: 重放持久化的世界状态 @sayan-oai
- #29969 报告带有服务器归属的 MCP 错误码 @aibrahim-oai
- #29970 core: 提高令牌预算消息限制 @bolinfest
- #29973 [codex] 通过时间提供者路由 sleep @rka-oai
- #19051 feat: 使用运行代理任务认证进行推理 @adrian-openai
- #29810 core: 使 AGENTS.md 对环境变化做出反应 @sayan-oai
- #29997 core: 协调遗留 WorldState 部分 @sayan-oai
- #29990 并行化环境技能加载 @anp-oai
- #28522 支持来自选定执行器插件的 HTTP MCP 服务器 @jif-oai
- #28529 支持来自选定执行器插件的 HTTP MCP 服务器的 OAuth @jif-oai
- #29656 测试执行器路由的 MCP OAuth 令牌交换 @jif-oai
- #29928 chore(app-server): 标记 thread/rollback 为已弃用 @owenlin0
- #29856 持久化选定的能力根,并按模型步骤解析可用性 @jif-oai
- #27467 [codex] 记录执行服务器生命周期指标 @richardopenai
- #29942 feat: 在线程启动时添加感知提供者的模型回退 @celia-oai
- #30095 cli: 重命名沙箱权限配置文件标志 @bolinfest
- #30029 [codex] 将当前时间提醒间隔设置为 0 @rka-oai
- #29941 core: 向 shell 工具暴露权限配置文件 @bolinfest
- #30031 [codex] 添加当前时间提醒传递模式配置 @rka-oai
- #30098 [codex] 重试临时离线执行服务器恢复 @richardopenai
- #30033 [codex] 实现 delivery_mode: 在响应边界上的当前时间提醒 @rka-oai
- #30108 [codex] 扩展代码模式主机 IPC 传输 @cconger
- #27470 [codex] 观察远程执行服务器生命周期 @richardopenai
- #30113 [codex] 在 sleep 期间轮询外部时钟 @rka-oai
- #29003 feat(core, mcp): 在内存中缓存 codex_apps 工具 @owenlin0
- #30114 release: 发布独立 zsh 工件 @bolinfest
- #30116 release: 消费独立 zsh 工件 @bolinfest
- #29648 [codex] 添加托管的 MCP 服务器匹配器 @felixxia-oai
- #30100 让扩展贡献世界状态部分 @jif-oai
- #30124 fix(app-server): 抑制 TUI 滚动警告 @fcoury-oai
- #29877 [codex] 表面 MCP 重新认证所需的启动失败 @felixxia-oai
- #29988 识别 Work 网页和移动线程发起者 @chiam-oai
- #30110 [codex] 添加代码模式主机失败监督钩子 @cconger
- #30088 通过世界状态项目执行器技能 @jif-oai
- #30117 [codex] 通过执行服务器 HTTP 传播追踪 @wiltzius-openai
- #30101 将 MCP 运行时固定到模型步骤 @jif-oai
- #30134 ci: 缩小 Windows 测试跳过范围 @anp-oai
- #30093 根据环境可用性项目选定的插件运行时 @jif-oai
- #30145 为环境技能元数据复用遍历清单 @jif-oai
- #30111 [codex] 实现独立的代码模式进程主机 @cconger
- #29935 [codex] 按线程发起者归属应用服务器分析 @alexsong-oai
- #30152 在恢复时重新注入缺失的世界状态片段 @jif-oai
- #30127 使 MCP 诱导在运行时刷新间保持可路由 @jif-oai
- #29934 在应用上下文中暴露 MCP 应用标识 @martinauyeung-oai
- #29909 [codex] 允许 CCA 图像生成和网页搜索扩展 @won-openai
- #30157 测试跨可用性和恢复的选定能力 @jif-oai
- #30144 [codex] 修复终端滚动事件持久性 @wiltzius-openai
- #29920 重试失败的 Codex Apps MCP 启动 @kbazzi
- #29516 为 MCP HTTP 持久化 Cloudflare 亲和性 cookies @stevenlee-oai
- #30112 [codex] 添加进程拥有的代码模式会话客户端 @cconger
- #30142 [codex] 将进程拥有的代码模式主机接入 core @cconger
- #30198 [codex] 修复 CreateThreadParams 测试初始化器 @anp-oai
- #30148 当选定可用性无变化时复用 MCP 运行时 @jif-oai
- #30215 测试跨不可用恢复的选定能力 @jif-oai
- #29991 [codex] 缩小未使用技能介绍导出 @aibrahim-oai
- #30229 放宽 hooks.json 顶层元数据验证 @charlesgong-openai
- #29927 feat(app-server): 向线程添加 history_mode @owenlin0
- #30276 修复主分支 @owenlin0
- #29683 [codex] 添加托管的 new-thread 模型设置 @hefuc-oai
- #30225 将执行器技能读取与命名空间发现重叠 @jif-oai
- #30274 [codex] 允许 AGENTS.md 和技能授权委派 @charlesdu-openai
- #30147 [codex] 对 TUI 线程使用托管默认值 @hefuc-oai
- #30261 确保 thread.history_mode 不可变 @owenlin0
- #30277 feat(app-server): 向 thread/fork 添加可选 turn_id @owenlin0
- #30143 让 Codex 查阅用户级别的 code-review-* 技能 @anp-oai
- #30285 feat: 向 Bedrock 目录添加 GPT-5.6 变体 @celia-oai
- #30173 当提交通道关闭时关闭线程持久化 @alfozan
- #30257 [codex] 分类嵌套 MCP 认证启动错误 @felixxia-oai
- #29375 [codex] 支持 npm 市场插件来源 @charlesgong-openai
- #30146 [codex] 分组阻塞和后合并 CI 工作流 @anp-oai
- #30282 feat(protocol): 定义缺失的滚动轮次项 @owenlin0
- #30201 fix(remote-control): 避免服务器令牌刷新重试风暴 @apanasenko-oai
- #30273 [codex] 消费推送的执行服务器进程事件 @richardopenai
- #30286 core: 将差异根发现与世界状态重叠 @anp-oai
- #30314 app-server: 构造并测试 JSON 关闭日志 @bolinfest
- #30317 更新安全检查措辞 @etraut-openai
- #30302 在自定义工具调用上保留命名空间 @nhamidi-oai
- #30327 core: 稳定合成调用输出 ID @bolinfest
- #30291 [app-server] 暴露环境信息 RPC @maxj-oai
- #29691 [plugins] 在运行时强制执行市场来源策略 @xl-openai
- #30384 [app-server] 增加 currentTime/read 超时 @rka-oai
- #30297 [codex] 默认启用远程插件 @xl-openai
- #30490 fix(tui): 清除完成的安全缓冲提示 @fcoury-oai
- #29740 [codex] 为技能使用指令使用模型元数据 @ani-oai
- #30511 [codex] 恢复 v1 委派指导 @aibrahim-oai
- #30508 回滚“使自动审查按请求提示更主动” @dylan-hurd-oai
- #30467 [codex] 将 max 视为一等推理努力 @shijie-oai
- #30491 更新安全检查链接 @etraut-openai
- #30607 [codex] 自动标记 AWS Bedrock 问题 @etraut-openai
- #30269 [codex] 在 Rendezvous WebSocket 上禁用 Nagle @richardopenai
- #30645 [codex] 更新安全通知措辞 @etraut-openai
- #30757 fix(core) 移除全文 WebSocket 追踪 @dylan-hurd-oai
- #30851 docs: 为围栏代码块添加标签 @bolinfest
- #30643 [codex] 绑定 Rendezvous WebSocket 存活 @richardopenai
- #30867 整合多代理 v2 通信发送 @bolinfest
- #30872 记录多代理通信生命周期 @bolinfest
- #30883 [codex] 发出每请求 TTFT 完成遥测 @xli-oai
- #30897 修复 Bedrock 模型继承的可用性元数据 @shijie-oai
- #30941 fix: 处理 quick-xml 安全公告 @bolinfest
- #30770 fix(websockets) 忽略增量请求的元数据 @dylan-hurd-oai
- #30334 telemetry: 记录结构化的直接工具调用时序 @bolinfest
- #30493 [codex] 添加可配置的多代理模式提示文本 @shijie-oai
- #30796 修复路径支持的反馈附件的 MIME 类型 @btraut-openai
- #31056 fix(install): 复用 GitHub 发布元数据 @bolinfest
- #30981 [codex] 暴露远程插件版本 @ericning-o
- #31066 chore: 移除未使用的 git-cliff 配置 @bolinfest
- #31064 [codex] 从响应事件读取缓冲元数据 @fc-oai
- #30223 使插件指导对环境就绪做出反应 @sayan-oai
- #31189 修复已取消审查导致 MCP 启动繁忙 @charliemarsh-oai
- #30876 [core] 支持交错响应项 @alexi-openai
- #31262 [codex] 从缓冲事件读取重试模型 @fc-oai
- #31261 回滚“[core] 支持交错响应项” @alexi-openai
- #31253 为刚加载的线程配置发出执行策略警告 @etraut-openai
- #31179 移除 TUI 执行策略核心导出 @etraut-openai
- #29959 条件 codex_home dotenv @canvrno-oai
- #30627 诱导: 迁移到共享的 ElicitationService @cconger
- #30318 core: 追踪执行器技能发现 @anp-oai
- #31276 回滚“条件 codex_home dotenv” @canvrno-oai
- #30956 refactor(protocol): 隔离遗留项扇出 @owenlin0
- #30395 [app-server] 在速率限制中包含重置信用详情 @jayp-oai
- #31267 chore(approvals) 整合 shell 工具的 guardian 调用 @dylan-hurd-oai
- #31252 [tui] 在对话历史中截断钩子上下文 @abhinav-oai
- #29918 [codex] 刷新尾随实时转录尾部 @guinness-oai
- #30226 使 Apps 指导对 MCP 可用性做出反应 @sayan-oai
- #31190 使用弹出令牌范围进行自动完成插入 @charliemarsh-oai
- #29697 fix: 在 Linux 上将网络请求归因于确切执行 @jif-oai
- #31303 feat(code-mode): 允许禁用 V8 JIT @cconger
- #31271 chore: 为用户 Bazel 配置使用 .worktreeinclude @anp-oai
- #31308 fix: 更新 crossbeam-epoch 以解决 RUSTSEC-2026-0204 @cconger
- #30202 [codex] 在发布包中捆绑代码模式主机 @cconger
- #31293 [codex] app-server: 暴露插件安装策略来源 @ericning-o
- #31318 ci: 共享通用工作流设置 @anp-oai
- #29992 app-server: 在集成测试中覆盖选定环境 @anp-oai
- #31284 当配置的服务层级不受支持时发出警告 @etraut-openai
- #31323 将共享的 HTTP 传输提取到 codex-http-client @bolinfest
- #31331 将直接 HTTP 消费者迁移到 codex-http-client @bolinfest
- #31337 fix: 恢复 Codex 环境设置表 @anp-oai
- #31188 在规则解析错误后保留托管执行策略 @etraut-openai
- #31306 [codex] 支持顺序截止推理摘要 @ashwinnathan-openai
- #31344 exec-server: 在 Noise 中继测试中使用虚拟时间 @bolinfest
- #31296 refactor(protocol): 将规范工具项映射到遗留事件 @owenlin0
- #31335 core: 通过系统代理路由 Responses API @bolinfest
## New Features
- Remote plugins are now enabled by default, with richer catalog rows, npm marketplace sources, and visible remote/local versions. (#30297, #26705, #29375, #30981)
- Codex can route authentication and Responses API traffic through macOS and Windows system proxies, including PAC and WPAD configurations. (#26708, #26709, #31335)
- Added `codex remote-control pair` for generating manual pairing codes from a running daemon. (#29913)
- Added Amazon Bedrock GPT-5.6 Sol, Terra, and Luna models, with first-class support for `max` reasoning effort. (#30285, #30467)
- MCP tools now use tool search by default, and ChatGPT-hosted MCP servers can explicitly use session authentication. (#29486, #29733)
- App-server clients can inspect environments, list descendant threads, and fork history through a specific turn. (#30291, #29591, #30277)
## Bug Fixes
- Fixed Windows ConPTY input handling for line endings and backspace, plus sandbox credential retry edge cases. (#29734, #29624, #29637)
- Fixed stale TUI safety prompts and cancelled reviews that could leave MCP startup appearing busy. (#30490, #31189)
- Improved recovery when exec servers are temporarily offline and prevented remote-control token refresh retry storms. (#30098, #30201)
- Preserved trailing realtime transcript text and terminal rollout events during shutdown. (#29918, #30144)
- Improved incremental WebSocket request success by ignoring response metadata during comparisons. (#30770)
- Reduced installer failures from GitHub API rate limits by reusing release metadata. (#31056)
## Documentation
- Documented UUID7 thread and turn IDs, plus recommended remote-executor integration-test workflows. (#27714, #29790)
## Chores
- Updated OpenSSL, Hono, fast-uri, quick-xml, and crossbeam-epoch to address security advisories. (#29487, #29650, #30941, #31308)
## Changelog
Full Changelog: https://github.com/openai/codex/compare/rust-v0.142.0...rust-v0.143.0
- #26708 PAC 3 - Add Windows system proxy resolver @canvrno-oai
- #28769 Register full CDP requirements feature @syuan-oai
- #29485 [codex] fetch featured IDs for remote plugins @ericning-o
- #29487 Upgrade bundled OpenSSL to 3.6.3 @jif-oai
- #29489 [codex] Update esbuild to 0.28.1 @pakrym-oai
- #29488 [plugins] Add dark-mode logo metadata @drewschuster-openai
- #29249 [codex] migrate environment context to model world state @pakrym-oai
- #29494 core: wrap token budget window context @bolinfest
- #29417 [codex] replace remote images with model-visible error text @rka-oai
- #28360 feat(core): store turn_id on ResponseItem metadata @owenlin0
- #29486 [codex] Use tool search for MCP tools by default @sayan-oai
- #29501 path-uri: clarify host-native path conversion @anp-oai
- #29504 fix: world state response item test @celia-oai
- #26704 TUI Plugin Sharing 4 - cover remote plugin catalog flows @canvrno-oai
- #29419 [codex] reject remote images at app-server ingress @rka-oai
- #28992 chore: improve expired Bedrock credential errors @celia-oai
- #29467 Make formatter output quiet on success @anp-oai
- #26709 PAC 4 - Add macOS system proxy resolver @canvrno-oai
- #29490 chore: warn when Code Mode lacks model metadata @celia-oai
- #29493 mcp: accept foreign absolute cwd for remote stdio @anp-oai
- #29473 Propagate safety buffering treatment metadata @fc-oai
- #24092 [codex] Reject unlowered PowerShell AST regions @bookholt-oai
- #29155 [codex] Expose service tier and reasoning effort in OTEL @daniel-oai
- #29068 [codex] stylistic changes @rka-oai
- #29518 Remove redundant Codex Apps manager flag @aibrahim-oai
- #27946 [codex] Use input items for Responses Lite tools @rka-oai
- #29528 Centralize Codex Apps client handling @aibrahim-oai
- #29577 Handle additional tools in image URL validation @aibrahim-oai
- #29575 Remove redundant Codex Apps cache guard @aibrahim-oai
- #29583 Group Codex Apps client setup @aibrahim-oai
- #29358 Allow codex sandbox to consume MCP sandbox state @jif-oai
- #29599 Stop persisting bridged log events @jif-oai
- #29615 Fix Codex Apps auth elicitation hang @jif-oai
- #29067 Namespace multi-agent v2 tools under collaboration @jif-oai
- #29614 path-uri: add lexical containment @jif-oai
- #28426 Share resumed rollout history @charliemarsh-oai
- #29634 Update rmcp to 1.8.0 @jif-oai
- #29650 Update vulnerable Hono and fast-uri dependencies @jif-oai
- #29498 [codex] Instrument rollout persistence bytes @wiltzius-openai
- #29659 [core] debounce current-time reminders by elapsed time @rka-oai
- #29608 Shut down superseded MCP managers on refresh @jif-oai
- #29527 core: use turn-owned world state for inline compaction @sayan-oai
- #29672 [codex] Handle additional tools in rollout persistence metrics @rka-oai
- #29669 Handle additional tools in rollout persistence metrics @winston-openai
- #29680 Revert "Handle additional tools in rollout persistence metrics" @rasmusrygaard
- #27714 app-server: document thread and turn IDs are UUID7 @owenlin0
- #29456 Prepare managed network sandbox context @jif-oai
- #28418 chore(core) rm AskForApproval::OnFailure @dylan-hurd-oai
- #29675 core: add extra metadata field to Thread struct @kumquatexpress
- #29013 Keep managed MITM CA private keys in proxy memory @winston-openai
- #29495 Separate local and remote plugin analytics IDs @jameswt-oai
- #29671 [codex] Preserve proxy state for filesystem sandbox helpers @iceweasel-oai
- #29513 [codex] allow image generation with provider auth @richardopenai
- #29526 core: resolve view_image paths in selected environment @anp-oai
- #29696 [codex] Fix stale approval policy in MCP test @sayan-oai
- #29704 [codex] Fix stale approval policy in MCP test @kumquatexpress
- #29547 core: use current step environments for tools @sayan-oai
- #28976 Add MCP tool call error metrics @stevenlee-oai
- #27045 feat(guardian): include connected account email in app reviews @viyatb-oai
- #29620 Decouple plugin manifest path resolution @jif-oai
- #29666 [codex] Report the exec-server working directory @rasmusrygaard
- #29705 feat(app-server): thread/turns/items/list -> thread/items/list @owenlin0
- #29716 code-mode: Rename codex_code_mode::CodeModeService @cconger
- #29712 test: branch on target OS instead of runner flavor @anp-oai
- #29728 core tests: rename automatic environment builder @anp-oai
- #29158 path-uri: remove legacy path deserialization @anp-oai
- #29519 core: persist initial context window metadata @bolinfest
- #28918 Make selected plugin roots URI-native @jif-oai
- #29515 [codex] define code mode host handshake protocol @cconger
- #29715 [codex] surface rollout budget exhaustion @rka-oai
- #29732 code-mode: Remove Session::is_alive() @cconger
- #29626 Load executor skills without host path conversion @jif-oai
- #29714 protocol: separate app and exec RPC ownership @anp-oai
- #29664 refactor: extract context window token status @bolinfest
- #29665 fix: scope context remaining to body window @bolinfest
- #29744 [codex] rename rollout budget error to session budget error @rka-oai
- #29739 Update new_context_window instructions @andmis
- #29743 core: reset context for token budget compaction @bolinfest
- #29477 Support thread-level originator overrides @alexsong-oai
- #29745 core: add wait_for_environment for starting environments @sayan-oai
- #28630 [codex] trace MCP startup latency @rphilizaire-openai
- #29750 chore: assign `amsg_` IDs to agent messages @bolinfest
- #29746 test: add app-server auto environment helper @anp-oai
- #29711 Let image generation extension hosts control output persistence @won-openai
- #29762 [codex] Reuse compacted history replacement for new context windows @pakrym-oai
- #29768 [codex] Update bundled skill installer guidance @sayan-oai
- #29690 [plugins] Add marketplace source requirements @xl-openai
- #29765 [codex] Ignore local curated plugins when remote catalog is active @xl-openai
- #29767 [codex] Assign response item IDs in forked history @pakrym-oai
- #29721 auth: move domain mode below app wire types @anp-oai
- #29753 [plugins] Enforce marketplace source admission requirements @xl-openai
- #29722 config: own layer provenance types @anp-oai
- #29723 connectors: own app metadata types @anp-oai
- #29788 test: run app-server integration tests under Wine @anp-oai
- #29789 test: use automatic environments in app-server integration tests @anp-oai
- #29790 docs: document remote executor integration testing @anp-oai
- #29815 [codex] Remove auto-compaction opt-out @rhan-oai
- #29628 Keep executor plugin MCP paths URI-native @jif-oai
- #29731 [codex] Emit implicit skill usage for support reads @alexsong-oai
- #29829 Persist agent messages as response items @jif-oai
- #29841 Add a bounded filesystem walk RPC @jif-oai
- #29842 Use fs/walk for environment skill discovery @jif-oai
- #29567 [codex] show external import result counts @charlesgong-openai
- #29831 Cache plugin namespace during executor skill discovery @jif-oai
- #29720 ci: fail jobs that dirty the worktree @anp-oai
- #29887 Fix environment skill discovery after merge @jif-oai
- #29734 [codex] fix Windows ConPTY input handling @iceweasel-oai
- #28593 [codex] suppress low usage remaining warnings when credits are available @brooks-oai
- #29624 Preserve Windows sandbox identity during credential retry @jif-oai
- #27466 [codex] Trace exec-server JSON-RPC requests @richardopenai
- #29844 Follow directory symlinks in filesystem walks @jif-oai
- #29637 Skip credential refresh for WindowsApps launch failures @jif-oai
- #29591 feat(app-server): list descendant threads by ancestor @btraut-openai
- #28034 feat(network-proxy): experimental local credential broker @winston-openai
- #29736 [codex] Inject agent graph store into ThreadManager @wiltzius-openai
- #29889 [apps] Thread structured icon assets through app list @drewschuster-openai
- #29724 mcp: keep elicitation requests below app wire types @anp-oai
- #29684 [plugins] Track plugin install requests by ID @adaley-openai
- #29870 Pipeline bounded AGENTS.md and Git root probes @jif-oai
- #29893 [codex] dedupe remote control account header @shuo-openai
- #29851 Add a connector declaration snapshot @jif-oai
- #29903 path-uri: normalize parent segments in absolute joins @anp-oai
- #29852 Read connector declarations from executor plugins @jif-oai
- #29785 Isolate curated plugin sync Git environment @etraut-openai
- #29907 [codex] namespace sleep under clock @rka-oai
- #29910 [codex] nest sleep config under current time reminder @rka-oai
- #29913 feat(remote-control): add daemon pairing command @apanasenko-oai
- #29936 core: add configurable <context_window_guidance> message @bolinfest
- #26705 TUI Plugin Sharing 5 - polish remote plugin catalog rows @canvrno-oai
- #29733 Allow ChatGPT-hosted MCP servers to use session auth @aibrahim-oai
- #29833 [1/3] core: make world state snapshots serializable @sayan-oai
- #29919 TUI support for buffer experience @etraut-openai
- #29924 Represent MCP authentication with an enum @aibrahim-oai
- #29804 code-mode: define process host wire protocol @cconger
- #29956 [codex] Populate remote plugin local versions @abhinav-oai
- #29835 [2/3] core: persist world state in rollouts @sayan-oai
- #29899 [codex] Update reasoning effort @shijie-oai
- #29837 [3/3] core: replay persisted world state @sayan-oai
- #29969 Report MCP error codes with server attribution @aibrahim-oai
- #29970 core: raise token budget message limits @bolinfest
- #29973 [codex] route sleep through time providers @rka-oai
- #19051 feat: use run agent task auth for inference @adrian-openai
- #29810 core: make AGENTS.md react to environment changes @sayan-oai
- #29997 core: reconcile legacy WorldState sections @sayan-oai
- #29990 Parallelize environment skill loading @anp-oai
- #28522 Support HTTP MCP servers from selected executor plugins @jif-oai
- #28529 Support OAuth for HTTP MCP servers from selected executor plugins @jif-oai
- #29656 Test executor-routed MCP OAuth token exchange @jif-oai
- #29928 chore(app-server): mark thread/rollback as deprecated @owenlin0
- #29856 Persist selected capability roots and resolve availability per model step @jif-oai
- #27467 [codex] Record exec-server lifecycle metrics @richardopenai
- #29942 feat: add provider-aware model fallback to thread start @celia-oai
- #30095 cli: rename sandbox permission profile flag @bolinfest
- #30029 [codex] current time reminder interval to be set to 0 @rka-oai
- #29941 core: expose permission profile to shell tools @bolinfest
- #30031 [codex] add current time reminder delivery mode config @rka-oai
- #30098 [codex] Retry temporarily offline exec-server recovery @richardopenai
- #30033 [codex] impl delivery_mode: current time reminders on response boundaries @rka-oai
- #30108 [codex] extend code-mode host IPC transport @cconger
- #27470 [codex] Observe remote exec-server lifecycle @richardopenai
- #30113 [codex] poll external clock during sleep @rka-oai
- #29003 feat(core, mcp): cache codex_apps tools in memory @owenlin0
- #30114 release: publish standalone zsh artifacts @bolinfest
- #30116 release: consume standalone zsh artifacts @bolinfest
- #29648 [codex] Add managed MCP server matchers @felixxia-oai
- #30100 Let extensions contribute World State sections @jif-oai
- #30124 fix(app-server): suppress TUI rollback warning @fcoury-oai
- #29877 [codex] Surface MCP reauthentication-required startup failures @felixxia-oai
- #29988 Recognize Work web and mobile thread originators @chiam-oai
- #30110 [codex] add code-mode host failure supervision hooks @cconger
- #30088 Project executor skills through World State @jif-oai
- #30117 [codex] Propagate traces through exec-server HTTP @wiltzius-openai
- #30101 Pin MCP runtimes to model steps @jif-oai
- #30134 ci: narrow Windows test skips @anp-oai
- #30093 Project selected plugin runtime by environment availability @jif-oai
- #30145 Reuse walk inventory for environment skill metadata @jif-oai
- #30111 [codex] implement standalone code-mode process host @cconger
- #29935 [codex] Attribute app-server analytics by thread originator @alexsong-oai
- #30152 Reinject missing World State fragments on resume @jif-oai
- #30127 Keep MCP elicitation routable across runtime refreshes @jif-oai
- #29934 Expose MCP app identity in app context @martinauyeung-oai
- #29909 [codex] allow CCA image generation and web search extensions @won-openai
- #30157 Test selected capabilities across availability and resume @jif-oai
- #30144 [codex] fix terminal rollout event durability @wiltzius-openai
- #29920 Retry failed Codex Apps MCP startup @kbazzi
- #29516 Persist Cloudflare affinity cookies for MCP HTTP @stevenlee-oai
- #30112 [codex] add process-owned code-mode session client @cconger
- #30142 [codex] wire process-owned code mode host into core @cconger
- #30198 [codex] fix CreateThreadParams test initializer @anp-oai
- #30148 Reuse MCP runtimes when selected availability changes nothing @jif-oai
- #30215 Test selected capabilities across unavailable resume @jif-oai
- #29991 [codex] narrow unused skills intro export @aibrahim-oai
- #30229 Relax hooks.json top-level metadata validation @charlesgong-openai
- #29927 feat(app-server): add history_mode to thread @owenlin0
- #30276 fix main @owenlin0
- #29683 [codex] Add managed new-thread model settings @hefuc-oai
- #30225 Overlap executor skill reads with namespace discovery @jif-oai
- #30274 [codex] allow AGENTS.md and skills to authorize delegation @charlesdu-openai
- #30147 [codex] Use managed defaults for TUI threads @hefuc-oai
- #30261 ensure thread.history_mode is immutable @owenlin0
- #30277 feat(app-server): add optional turn_id to thread/fork @owenlin0
- #30143 Let Codex consult user-level code-review-* skills. @anp-oai
- #30285 feat: add GPT-5.6 variants to Bedrock catalog @celia-oai
- #30173 Close thread persistence when submission channel closes @alfozan
- #30257 [codex] Classify nested MCP authentication startup errors @felixxia-oai
- #29375 [codex] Support npm marketplace plugin sources @charlesgong-openai
- #30146 [codex] group blocking and postmerge CI workflows @anp-oai
- #30282 feat(protocol): define missing rollout turn items @owenlin0
- #30201 fix(remote-control): avoid server token refresh retry storms @apanasenko-oai
- #30273 [codex] consume pushed exec-server process events @richardopenai
- #30286 core: overlap diff root discovery with world state @anp-oai
- #30314 app-server: structure and test JSON shutdown logs @bolinfest
- #30317 Update security check wording @etraut-openai
- #30302 Preserve namespaces on custom tool calls @nhamidi-oai
- #30327 core: stabilize synthesized call output IDs @bolinfest
- #30291 [app-server] expose environment info RPC @maxj-oai
- #29691 [plugins] Enforce marketplace source policy at runtime @xl-openai
- #30384 [app-server] increase currentTime/read timeout @rka-oai
- #30297 [codex] Enable remote plugins by default @xl-openai
- #30490 fix(tui): clear completed safety buffering prompt @fcoury-oai
- #29740 [codex] Use model metadata for skills usage instructions @ani-oai
- #30511 [codex] Restore v1 delegation guidance @aibrahim-oai
- #30508 Revert "Make auto-review on-request prompt more proactive" @dylan-hurd-oai
- #30467 [codex] Treat max as a first-class reasoning effort @shijie-oai
- #30491 Update safety check links @etraut-openai
- #30607 [codex] auto-label AWS Bedrock issues @etraut-openai
- #30269 [codex] disable Nagle on Rendezvous WebSockets @richardopenai
- #30645 [codex] Update safety notice wording @etraut-openai
- #30757 fix(core) Remove full text websocket trace @dylan-hurd-oai
- #30851 docs: add tag to fenced code block @bolinfest
- #30643 [codex] bound Rendezvous WebSocket liveness @richardopenai
- #30867 Consolidate multi-agent v2 communication sends @bolinfest
- #30872 Log multi-agent communication lifecycle @bolinfest
- #30883 [codex] emit per-request TTFT completion telemetry @xli-oai
- #30897 Fix inherited availability metadata for Bedrock models @shijie-oai
- #30941 fix: address quick-xml security advisories @bolinfest
- #30770 fix(websockets) ignore metadata for incremental requests @dylan-hurd-oai
- #30334 telemetry: log structured direct tool-call timing @bolinfest
- #30493 [codex] Add configurable multi-agent mode hint text @shijie-oai
- #30796 Fix MIME types for path-backed feedback attachments @btraut-openai
- #31056 fix(install): reuse GitHub release metadata @bolinfest
- #30981 [codex] expose remote plugin versions @ericning-o
- #31066 chore: remove unused git-cliff configuration @bolinfest
- #31064 [codex] Read buffering metadata from response events @fc-oai
- #30223 Make plugin guidance react to environment readiness @sayan-oai
- #31189 Fix cancelled review leaving MCP startup busy @charliemarsh-oai
- #30876 [core] Support interleaved response items @alexi-openai
- #31262 [codex] Read retry model from buffering events @fc-oai
- #31261 Revert "[core] Support interleaved response items" @alexi-openai
- #31253 Emit exec-policy warnings for freshly loaded thread config @etraut-openai
- #31179 Remove TUI exec-policy core exports @etraut-openai
- #29959 Conditional codex_home dotenv @canvrno-oai
- #30627 elicitations: Move to shared ElicitationService @cconger
- #30318 core: trace executor skill discovery @anp-oai
- #31276 Revert "Conditional codex_home dotenv" @canvrno-oai
- #30956 refactor(protocol): isolate legacy item fanout @owenlin0
- #30395 [app-server] Include reset-credit details in rate limits @jayp-oai
- #31267 chore(approvals) consolidate guardian calls for shell tools @dylan-hurd-oai
- #31252 [tui] Truncate hook context in conversation history @abhinav-oai
- #29918 [codex] Flush trailing realtime transcript tail @guinness-oai
- #30226 Make Apps guidance react to MCP availability @sayan-oai
- #31190 Use popup token ranges for autocomplete insertion @charliemarsh-oai
- #29697 fix: attribut network requests to the exact exec on linux @jif-oai
- #31303 feat(code-mode): allow disabling V8 JIT @cconger
- #31271 chore: use .worktreeinclude for user Bazel config @anp-oai
- #31308 fix: update crossbeam-epoch for RUSTSEC-2026-0204 @cconger
- #30202 [codex] bundle code mode host in release packages @cconger
- #31293 [codex] app-server: expose plugin install policy source @ericning-o
- #31318 ci: share common workflow setup @anp-oai
- #29992 app-server: cover selected environments in integration tests @anp-oai
- #31284 Warn when configured service tiers are unsupported @etraut-openai
- #31323 Extract shared HTTP transport into codex-http-client @bolinfest
- #31331 Migrate direct HTTP consumers to codex-http-client @bolinfest
- #31337 fix: restore Codex environment setup table @anp-oai
- #31188 Preserve managed exec policy after rules parse errors @etraut-openai
- #31306 [codex] Support sequential cutoff reasoning summaries @ashwinnathan-openai
- #31344 exec-server: use virtual time in Noise relay test @bolinfest
- #31296 refactor(protocol): map canonical tool items to legacy events @owenlin0
- #31335 core: route Responses API through system proxy @bolinfest