Skip to content

Sync Codex Lab with current openai/codex substrate #230

Description

@shiny-code-bot

Objective

Converge Codex Lab onto a current openai/codex tree while preserving only explicit, contract-backed Every Code product behavior. Upstream snapshots become the integration unit; historical commit ledgers remain provenance evidence rather than a prerequisite to implementation.

Finish Line

Codex Lab main descends from a recorded current upstream checkpoint, passes the Every Code convergence contract matrix, preserves both histories through reviewed merges, and can absorb ongoing upstream changes with a product-main lag target under three days.

Current Status

State: active as of August 23, 2026.

The first post-release exact-ref catch-up candidate remains checkpointed in draft PR #782. Provenance: local baseline 0eed1a86c783c474a009cb8b548ab58e18513614, upstream 343074d4207d572809bd8cea15f4be1d09d98e0b, merge base a7b8c074b577f897111c14de3a5e127b91e2a479, candidate head 15b9c8f373982767f741911e32179c5851d5c171, canonical remote git@github.com:openai/codex.git.

The candidate resolved 90 textual conflicts across 479 upstream-only commits and recorded append-only snapshot upstream/openai-codex/a7b8c074-343074d4. Strict convergence validation passes with seven reproducible snapshots, 493 guarded paths, 25 valid waivers, zero violations, and zero stale waivers. just bazel-lock-check, stable/experimental schema generation, and just test -p codex-app-server-protocol (309 passed, one skipped) were previously green.

Commits de00c66929770358fb0257029ebb68b2893f0711, cb5a4375f22d3177a94bb8f546912f5ed916e668, f6ce09ffce0e65d18e301ab30c4df1864ba2f457, and 15b9c8f373982767f741911e32179c5851d5c171 complete the bounded auth/workload-identity compatibility sequence on code-review evidence: typed fallible initialization, direct and indirect caller propagation, fail-closed app-server launch routing, persisted-login restriction isolation, and login-status/onboarding isolation now align with pinned upstream while preserving Every Code auth-profile and ordinary remote-session behavior.

All five focused package gates still stop before package test execution at the same five known codex-hooks errors. Current CI independently reports only those hooks errors before later crates. just fmt passed. Changed-files IntelliJ inspection found only pre-existing typo noise outside changed hunks.

Automatic Validation selected the correct package-scoped TUI Cargo check but timed out after 30,012 ms; #785 owns provider cache/budget. Background Review produced a P2 remote/WI onboarding finding after handoff. Two independent reviews rejected it as unreachable because workload identity cannot coexist with a remote app-server target in any active launch path; #784 records lifecycle/adjudication. Applicable AGENTS.md context was again truncated from 26,473 to 9,216 bytes; #787 owns that reliability gap.

Next action: repair the bounded codex-hooks API-shape synthesis, then rerun the focused auth/TUI/exec/app-server/CLI gates so the accumulated compatibility sequence finally compiles and its tests execute. Only after hooks is green should the candidate restore displaced downstream-only protocol tests and continue the remaining focused contract gates.

Blocked by: codex-hooks; then displaced downstream-only protocol tests and remaining focused contract gates.

Dogfood follow-ups remain #783 update-channel identity, #784 post-turn completion/review scope, #785 installed Validation provider cache/budget, #786 trace credential redaction, and #787 Background Review instruction context.

Last verified: August 23, 2026, PR #782 head 15b9c8f373982767f741911e32179c5851d5c171.

Scope

  • In: upstream-first snapshot integration; explicit Every Code ownership contracts; risk-lane conflict handling; subsystem port/validation trains; history-preserving cutover; continuous mirror/canary operation.
  • Out: force-pushing main; replaying every local commit; requiring all historical upstream commits to be individually classified; importing stale worktrees; or preserving undocumented divergence by default.

Acceptance Criteria

Relationships

Validation

Decisions

Open Questions

Metadata

Metadata

Assignees

No one assigned

    Labels

    planDurable planning issueplan:activePlan is actionable now

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions