Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package openai-codex for openSUSE:Factory 
checked in at 2026-09-22 20:52:21
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/openai-codex (Old)
 and      /work/SRC/openSUSE:Factory/.openai-codex.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "openai-codex"

Tue Sep 22 20:52:21 2026 rev:11 rq:1379727 version:0.155.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/openai-codex/openai-codex.changes        
2026-09-11 18:04:45.903445919 +0200
+++ /work/SRC/openSUSE:Factory/.openai-codex.new.383539/openai-codex.changes    
2026-09-22 20:52:30.496413295 +0200
@@ -1,0 +2,64 @@
+Tue Sep 22 14:56:52 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to version 0.155.1:
+  * New local TUI sessions leave reasoning summaries disabled by
+    default, so providers that do not support them stop
+    rejecting the request; explicit settings are still respected
+- Changes from version 0.155.0:
+  * The TUI shows live reasoning summaries in the status row and
+    completion timestamps after successful turns
+  * Task hiding, archiving and deletion in the agents overview,
+    plus worktree ownership details and confirmed deletion of
+    clean managed worktrees
+  * Amazon Bedrock can take AWS credentials from a configured
+    command, with caching and expiry-based refresh
+  * Automatic approval reviews keep complete actions and
+    authorization evidence, retry transient failures and tell
+    review failures apart from unsafe-action findings
+  * Fixed missed tmux resizes, transcript viewport restoration
+    and stale history showing up after a thread switch
+  * Accepted prompts are saved even when compaction fails before
+    a turn starts
+  * MCP servers report expired OAuth credentials accurately and
+    say how to reconnect when a token refresh fails
+  * Switching accounts invalidates remote-control sessions,
+    cached WebSocket state and the model catalogue of the old
+    identity
+  * Brokered shell snapshots are hardened against credential
+    exposure
+- Upstream's two headline 0.155.0 features are not reachable
+  here: /voice needs a separate codex-voice-host helper and a
+  bundled GStreamer runtime, neither of which is built, and
+  "codex app-server daemon update" only drives the standalone
+  install upstream's own installer lays down
+- Pull rustls 0.23.45 into the vendored tree: 0.23.36 accepts
+  TLS 1.3 handshake messages across encryption level boundaries
+  (RUSTSEC-2026-0285, GHSA-2mjx-qc3c-rqvc). It is linked through
+  aws-smithy-http-client, aws-config and codex-aws-auth, and
+  unlike the four linked advisories recorded in _service its fix
+  is semver-compatible, so it can be pulled forward
+- That pull moves three more crates, because rustls 0.23.45
+  floors aws-lc-rs at 1.18: aws-lc-rs 1.16.2 to 1.18.1,
+  aws-lc-sys 0.39.0 to 0.45.0 and rustls-webpki 0.103.13 to
+  0.103.15. The statically linked aws-lc goes 1.71.0 to 5.7.0,
+  so bundled(aws-lc) follows
+- cargo-audit on a bare copy of the lockfile reports six
+  advisories at 0.155.1; five remain in the shipped tree,
+  unchanged in status from 0.154.0 and all documented in _service
+- CVE-2026-63127 (boo#1281061): not affected, the vendored and
+  linked rmcp is 3.2.0 and the fix landed in 2.0.0
+- CVE-2026-63128 (boo#1281061): not affected, the vendored and
+  linked rmcp is 3.2.0 and the fix landed in 2.0.0
+- CVE-2026-64684 (boo#1281061): not affected, the vendored and
+  linked rmcp is 3.2.0 and the fix landed in 2.1.0
+- Legal-Review-Notice: linked-crate count 880/882 to 884/886 on
+  aarch64/x86_64, of which 751 are third-party on aarch64 (was
+  750, the addition is rand_regex) and 133 are codex workspace
+  members (was 130). The licence set is unchanged - the tally
+  moves only by Apache-2.0 651 to 654 and MIT 176 to 177 - and
+  the only bundled() version that moves is aws-lc, above
+- Rebase codex-drop-v8-code-mode.patch: upstream added a
+  user-verification workspace member next to the entries it
+  drops
+
+-------------------------------------------------------------------

Old:
----
  codex-rust-v0.154.0.tar.gz

New:
----
  codex-rust-v0.155.1.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ openai-codex.spec ++++++
--- /var/tmp/diff_new_pack.eecbbr/_old  2026-09-22 20:52:51.720303147 +0200
+++ /var/tmp/diff_new_pack.eecbbr/_new  2026-09-22 20:52:51.722303231 +0200
@@ -17,20 +17,20 @@
 
 
 Name:           openai-codex
-Version:        0.154.0
+Version:        0.155.1
 Release:        0
 Summary:        OpenAI Codex coding agent for the terminal
 # Legal-Review-Notice: upstream codex is Apache-2.0. Everything after that
 # covers the Rust crates statically linked into the shipped
 # %%{_bindir}/codex binary, enumerated with
 #   cargo tree --offline -p codex-cli -e normal,no-proc-macro
-# against the vendored tree (880 crates on aarch64, 882 on x86_64: 750
-# third-party vendored deps on aarch64 and 752 on x86_64, plus 130
+# against the vendored tree (884 crates on aarch64, 886 on x86_64: 751
+# third-party vendored deps on aarch64 and 753 on x86_64, plus 133
 # first-party codex workspace members, which are Apache-2.0 like upstream.
 # Every one declares a licence, none is missing; only the third-party count
 # is a licence signal, the workspace one moves whenever upstream adds a
 # crate). Electing Apache-2.0 where it is offered and MIT otherwise, the
-# aarch64 tally is Apache-2.0 651, MIT 176,
+# aarch64 tally is Apache-2.0 654, MIT 177,
 # Unicode-3.0 20, MPL-2.0 12, ISC 7, BSD-3-Clause 6, Zlib 5, BSD-2-Clause 1,
 # CC0-1.0 1, CDLA-Permissive-2.0 1.
 #  - self_cell 1.2.2 is "Apache-2.0 OR GPL-2.0-only" and is the ONLY crate
@@ -108,7 +108,7 @@
 # the DT_NEEDED assertion in %%install); those C sources stay inside
 # vendor.tar.zst, hence in the src.rpm, but end up in no binary package and so
 # get no bundled() Provides.
-Provides:       bundled(aws-lc) = 1.71.0
+Provides:       bundled(aws-lc) = 5.7.0
 ExclusiveArch:  %{rust_tier1_arches}
 
 %description

++++++ _service ++++++
--- /var/tmp/diff_new_pack.eecbbr/_old  2026-09-22 20:52:51.789306040 +0200
+++ /var/tmp/diff_new_pack.eecbbr/_new  2026-09-22 20:52:51.792306166 +0200
@@ -11,11 +11,11 @@
     feature and leaves the lockfile, hence the vendored set, untouched.
     To regenerate:
 
-      tar xf codex-rust-v0.154.0.tar.gz
-      patch -p1 -d codex-rust-v0.154.0 < codex-drop-v8-code-mode.patch
-      rm -rf codex-rust-v0.154.0/codex-rs/vendor
+      tar xf codex-rust-v0.155.1.tar.gz
+      patch -p1 -d codex-rust-v0.155.1 < codex-drop-v8-code-mode.patch
+      rm -rf codex-rust-v0.155.1/codex-rs/vendor
       osc service manualrun cargo_vendor
-      rm -rf codex-rust-v0.154.0
+      rm -rf codex-rust-v0.155.1
 
     The codex-rs/vendor removal drops the bundled bubblewrap 0.11.2 C sources,
     which %prep removes as well - codex uses the system bubblewrap instead.
@@ -31,8 +31,11 @@
 
     cargo-audit is NOT clean, and running it inside codex-rs hides most of it:
     upstream's codex-rs/.cargo/audit.toml ignores 11 advisories, which drops
-    the count from 5 to 1.  Audit a bare copy of Cargo.lock instead.  As of
-    0.154.0, and unchanged since 0.151.0:
+    the count from 6 to 2 on upstream's own lockfile, and from 5 to 1 on the
+    shipped one where rustls is already pulled forward.  Audit a bare copy of
+    Cargo.lock instead.  As of 0.155.1, the bare lock reports six; five
+    survive in the shipped tree because the sixth (rustls) is pulled forward
+    below:
       RUSTSEC-2026-0185 / CVE-2026-25800 (quinn-proto 0.11.14, fixed
         0.11.15) - NOT linked.  reqwest gates dep:quinn behind its "http3"
         feature, which the workspace leaves off, so it never reaches
@@ -50,9 +53,23 @@
     not anything this package can vendor around.
   -->
   <service name="cargo_vendor" mode="manual">
-    <param name="srcdir">codex-rust-v0.154.0/codex-rs</param>
+    <param name="srcdir">codex-rust-v0.155.1/codex-rs</param>
     <param name="compression">zst</param>
     <param name="update">false</param>
+    <!--
+      rustls 0.23.36 is RUSTSEC-2026-0285 (GHSA-2mjx-qc3c-rqvc): TLS 1.3
+      handshake messages accepted across encryption level boundaries.  It is
+      linked (aws-smithy-http-client -> aws-config -> codex-aws-auth ->
+      codex-cli) and, unlike the four linked advisories above, its fix is
+      semver-compatible, so it can be pulled forward instead of waiting for
+      upstream.  It is NOT collateral-free: rustls 0.23.45 floors aws-lc-rs
+      at 1.18, so this also moves aws-lc-rs 1.16.2 -> 1.18.1, aws-lc-sys
+      0.39.0 -> 0.45.0 (bundled aws-lc 1.71.0 -> 5.7.0 - keep the spec's
+      Provides in step) and rustls-webpki 0.103.13 -> 0.103.15.  Four crates,
+      which is still not the wholesale re-resolution update=true would do.
+      Drop this line once upstream's lockfile carries 0.23.45 or newer.
+    -->
+    <param name="update-crate">[email protected]</param>
   </service>
 </services>
 

++++++ codex-drop-v8-code-mode.patch ++++++
--- /var/tmp/diff_new_pack.eecbbr/_old  2026-09-22 20:52:51.806306753 +0200
+++ /var/tmp/diff_new_pack.eecbbr/_new  2026-09-22 20:52:51.810306920 +0200
@@ -13,7 +13,7 @@
 
 --- a/codex-rs/Cargo.toml
 +++ b/codex-rs/Cargo.toml
-@@ -24,9 +24,7 @@
+@@ -25,9 +25,7 @@
      "install-context",
      "codex-backend-openapi-models",
      "code-mode",
@@ -23,16 +23,15 @@
      "codex-home",
      "cloud-config",
      "cloud-tasks",
-@@ -101,8 +99,7 @@
-     "otel-trace-websocket",
+@@ -104,7 +102,6 @@
      "tui",
+     "user-verification",
      "tools",
 -    "v8-poc",
      "websocket-client",
      "windows-sandbox-service",
      "worktree",
-     "workload-identity",
-@@ -185,7 +182,6 @@
+@@ -191,7 +188,6 @@
  codex-cloud-tasks-mock-client = { path = "cloud-tasks-mock-client" }
  codex-code-mode = { path = "code-mode" }
  codex-code-mode-protocol = { path = "code-mode-protocol" }
@@ -40,15 +39,15 @@
  codex-home = { path = "codex-home" }
  codex-http-client = { path = "http-client" }
  codex-websocket-client = { path = "websocket-client" }
-@@ -290,7 +286,6 @@
- codex-utils-stream-parser = { path = "utils/stream-parser" }
+@@ -299,7 +295,6 @@
  codex-utils-string = { path = "utils/string" }
  codex-utils-template = { path = "utils/template" }
+ codex-user-verification = { path = "user-verification" }
 -codex-v8-poc = { path = "v8-poc" }
  codex-workload-identity = { path = "workload-identity" }
  codex-windows-sandbox = { path = "windows-sandbox-rs" }
  core_test_support = { path = "core/tests/common" }
-@@ -501,7 +496,6 @@
+@@ -517,7 +512,6 @@
  url = "2"
  urlencoding = "2.1"
  uuid = "1"
@@ -56,7 +55,7 @@
  vt100 = "0.16.2"
  walkdir = "2.5.0"
  webbrowser = "1.2.2"
-@@ -562,7 +556,6 @@
+@@ -578,7 +572,6 @@
  ignored = [
      "icu_provider",
      "openssl-sys",

++++++ codex-rust-v0.154.0.tar.gz -> codex-rust-v0.155.1.tar.gz ++++++
/work/SRC/openSUSE:Factory/openai-codex/codex-rust-v0.154.0.tar.gz 
/work/SRC/openSUSE:Factory/.openai-codex.new.383539/codex-rust-v0.155.1.tar.gz 
differ: char 22, line 1

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/openai-codex/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.openai-codex.new.383539/vendor.tar.zst differ: char 
7, line 1

Reply via email to