chore(agent-tools): bump codex pin 0.133.0 → 0.146.0 — Tier-2 compat re-verification first #252
No reviewers
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Cloonar/coding-lab!252
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "afk/249"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Moves the agent-tools codex pin
0.133.0 → 0.146.0(13 stable releases), re-verifying the Tier-2 compat record FIRST perversions.env/docs/ops.md § Agent-tools images/ ADR-0051. Version + sha256 + compat-record land in this one commit.Re-verification performed (in-container, 2026-07-31)
build.shfetches —5ba3b9405543953081f661d0854d266f76e2abbe51d41349355a36de7673776a(114169492 bytes), matching the issue's value. Binary runs (codex-cli 0.146.0) and is still static-pie (noPT_INTERP, zeroDT_NEEDED) — the ADR-0051 FROM-scratch injection contract holds.LAB_COMPAT_LIVE=1 go test ./internal/compat/codex/ -run Live -v):loginStatusParses(logged-out leg),debugModelsProbe(§1 schema clean; catalog values moved — new spawn defaultgpt-5.6-sol— which the probe design absorbs), andlocateTranscriptagainst a genuine 0.146.0 rollout produced by an unauthenticatedcodex execprobe turn on this host.rust-v0.133.0 → rust-v0.146.0(both tarballs), refuting the two release-note risks: the 0.145.0 "consistent full-access confirmation" triggers ONLY from the interactive permissions menu (single sender in the tree;run_mainmaps--sandbox/--ask-for-approvalstraight into config) — unattended--ask-for-approval never --sandbox danger-full-accessspawns hit no new prompt; and bare/new+/cleardispatch is unchanged (the 0.146.0 naming change is an additive optional inline argument, no overlay) — the chat-safe rows and lab's clear path stay valid.neverstill parses; nowritesapproval value exists (deprecatedon-failurewas removed; unused by lab).codex features list, full flag inventory, §11 recipe parse-through to a genuine 401.Drift recorded in
internal/compat/codex/compat.md(all absorbed)§2 device-auth caution line reworded (new fixture
device-auth-0.146.0.txt); §5 additive grammar — newworld_state/inter_agent_communication*record types, newsession_meta/user_message/task_completekeys, per-lineordinal— pinned by the new REAL-capture fixturerollout-authfail-0.146.0.jsonl+TestCompat_RolloutAuthFail146Fixture_maps, plus two default-off watch items (paginated history mode,.zstrollout compression); §6 mentions-v2 now stable-on (bare trailing@in a paste newly triggers the popup; Enter-inserts hazard class existed at 0.133.0 too); §7 popup gainedimport/archive/delete/usage— all 40 pinned rows byte-identical (source diff + binary strings), table deliberately stays the 0.133.0 live scrape until the dev-host re-scrape re-curates; §8plugin_hooksretired upstream (LiveSignals substrate is the corehooksfeature only now); §9 attribution is no longer absent at source — 0.146.0 ships a server-side-gated instruction extension emittingCo-authored-by: Codex <noreply@openai.com>/Generated with Codex.under ChatGPT auth; the existing ScrubPatterns cover exactly these strings and graduate to load-bearing; §10codex doctorexits 1 logged-out, and the first real turn git-clones a ~5300-file plugin-marketplace repo into$CODEX_HOME/.tmp/plugins(egress/disk note for containerized sessions); §11 recipe flags re-confirmed.Outstanding dev-host merge gate (recorded in compat.md, per the 2.1.220 claude-bump precedent)
The probing container has no codex login and no tmux, so these stay owed to the dev host: the §6 by-hand hazard sweep (now incl. paste-ending-in-
@tokenand bare-trailing-@), the §7 live popup re-scrape + row-by-row curation of the four new rows, the §3/§4 live seeding legs, one real authenticated spawn (argv banner + the three §1 sandbox traps), and the §9 real-commitgit loginspection.Verification
go test ./...green (47 packages),golangci-lint run(2.12.2, CI's version) — 0 issues.containers/**and will build the codex image + run the injection smoke test on this PR; the static-pie check above is the local predictor (no podman in this container).nix/module.nixuntouched by design —container.toolsImagesderives its default tag fromversions.envat eval time.Closes #249
🤖 Generated with Claude Code
[autoland] verdict: pass
Verdict: PASS with CONCERNS — validated, awaiting human confirm. Not auto-merged: the concerns below want a maintainer's eye before this publishes to main.
Verification signal relied on:
labctl pr checks 252aggregatesuccess—ci / native(14m23s; the repo'sgo test ./...+golangci-lintgate) andagent-tools / smoke(13m58s; path-gated oncontainers/**, triggered by theversions.envedit, so it actually fetched the new digest and ran the ADR-0051 injection smoke test against the real 0.146.0 artifact). Nothing re-run locally.Conventions: title is Conventional Commits (
chore(agent-tools): …); body carriesCloses #249; headafk/249is a direct descendant oforigin/main(no conflict, no resolution commit). Diff touches exactly the files the issue's scope table names —versions.env,compat.md,compat_test.go,doc.go, two new fixtures,docs/ops.md— plus nothing else. Version + sha256 + compat record land in one commit, asversions.env/docs/ops.mdand the issue both require.Concerns (non-blocking, for the human):
§1 spawn posture is source-verified, not live-verified —
internal/compat/codex/compat.md(0.146.0 note, §1). Issue #249 named the 0.145.0 "consistent full-access confirmation" (#33464) the highest-risk item in this bump and said "verify first; if it reproduces, this bump is blocked." The evidence here is an upstream source diff (single sender ofOpenFullAccessConfirmationis the interactive permissions-menu action builder;run_mainmaps--sandbox/--ask-for-approvalstraight into config; trust-screen predicate byte-identical) plus a livecodex execturn that did start without a prompt — but that turn ran--sandbox read-only, not--sandbox danger-full-access. The exact unattended spawn posture is therefore reasoned, not observed. If the reasoning is wrong, every unattended codex spawn hangs at start. The PR records this honestly as an owed dev-host leg.Issue #249's "Done means" checkboxes for the live-TUI legs are unmet by design — the §6 by-hand hazard sweep (incl. the newly-widened bare-trailing-
@trigger), the §7 popup re-scrape + row-by-row ChatSafe curation of the four new rows (import/archive/delete/usage), the §3/§4 live seeding legs, and the §9 real-commitgit loginspection. The probing container had no codex login and no tmux. These are deferred to a recorded dev-host merge gate, which follows the merged 2.1.220 Claude-Code precedent (commit52a9176/ PR #246 deferred its live recipe suite the same way) — but that is a maintainer's call to ratify, not a lander's.§9 attribution changed posture and
ScrubPatternsare now load-bearing —internal/compat/codex/compat.md§9 note. 0.146.0 ships a server-side-gated instruction extension emittingCo-authored-by: Codex <noreply@openai.com>/Generated with Codex.under ChatGPT auth, with no local off switch;SeedOpts.Incognistays a no-op and the previously-defensive scrub patterns become the operative incogni mechanism. The patterns do cover both strings, but this is a real change in what protects incogni — verified from source only, with the real-commit inspection owed.§7 catalog table deliberately still describes 0.133.0 —
internal/provider/codex/commands.gois untouched while the shipped binary moves to 0.146.0. The PR's argument (all 40 pinned rows byte-identical by source diff + binary strings; four new rows simply "not offered in the composer") is sound and degrades safely, but the table's provenance and the running binary now disagree by 13 releases until the re-scrape lands.None of these are marked blocking. Merging is the human's call.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.