Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package openai-codex for openSUSE:Factory checked in at 2026-09-22 20:52:21 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/openai-codex (Old) and /work/SRC/openSUSE:Factory/.openai-codex.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "openai-codex" Tue Sep 22 20:52:21 2026 rev:11 rq:1379727 version:0.155.1 Changes: -------- --- /work/SRC/openSUSE:Factory/openai-codex/openai-codex.changes 2026-09-11 18:04:45.903445919 +0200 +++ /work/SRC/openSUSE:Factory/.openai-codex.new.383539/openai-codex.changes 2026-09-22 20:52:30.496413295 +0200 @@ -1,0 +2,64 @@ +Tue Sep 22 14:56:52 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to version 0.155.1: + * New local TUI sessions leave reasoning summaries disabled by + default, so providers that do not support them stop + rejecting the request; explicit settings are still respected +- Changes from version 0.155.0: + * The TUI shows live reasoning summaries in the status row and + completion timestamps after successful turns + * Task hiding, archiving and deletion in the agents overview, + plus worktree ownership details and confirmed deletion of + clean managed worktrees + * Amazon Bedrock can take AWS credentials from a configured + command, with caching and expiry-based refresh + * Automatic approval reviews keep complete actions and + authorization evidence, retry transient failures and tell + review failures apart from unsafe-action findings + * Fixed missed tmux resizes, transcript viewport restoration + and stale history showing up after a thread switch + * Accepted prompts are saved even when compaction fails before + a turn starts + * MCP servers report expired OAuth credentials accurately and + say how to reconnect when a token refresh fails + * Switching accounts invalidates remote-control sessions, + cached WebSocket state and the model catalogue of the old + identity + * Brokered shell snapshots are hardened against credential + exposure +- Upstream's two headline 0.155.0 features are not reachable + here: /voice needs a separate codex-voice-host helper and a + bundled GStreamer runtime, neither of which is built, and + "codex app-server daemon update" only drives the standalone + install upstream's own installer lays down +- Pull rustls 0.23.45 into the vendored tree: 0.23.36 accepts + TLS 1.3 handshake messages across encryption level boundaries + (RUSTSEC-2026-0285, GHSA-2mjx-qc3c-rqvc). It is linked through + aws-smithy-http-client, aws-config and codex-aws-auth, and + unlike the four linked advisories recorded in _service its fix + is semver-compatible, so it can be pulled forward +- That pull moves three more crates, because rustls 0.23.45 + floors aws-lc-rs at 1.18: aws-lc-rs 1.16.2 to 1.18.1, + aws-lc-sys 0.39.0 to 0.45.0 and rustls-webpki 0.103.13 to + 0.103.15. The statically linked aws-lc goes 1.71.0 to 5.7.0, + so bundled(aws-lc) follows +- cargo-audit on a bare copy of the lockfile reports six + advisories at 0.155.1; five remain in the shipped tree, + unchanged in status from 0.154.0 and all documented in _service +- CVE-2026-63127 (boo#1281061): not affected, the vendored and + linked rmcp is 3.2.0 and the fix landed in 2.0.0 +- CVE-2026-63128 (boo#1281061): not affected, the vendored and + linked rmcp is 3.2.0 and the fix landed in 2.0.0 +- CVE-2026-64684 (boo#1281061): not affected, the vendored and + linked rmcp is 3.2.0 and the fix landed in 2.1.0 +- Legal-Review-Notice: linked-crate count 880/882 to 884/886 on + aarch64/x86_64, of which 751 are third-party on aarch64 (was + 750, the addition is rand_regex) and 133 are codex workspace + members (was 130). The licence set is unchanged - the tally + moves only by Apache-2.0 651 to 654 and MIT 176 to 177 - and + the only bundled() version that moves is aws-lc, above +- Rebase codex-drop-v8-code-mode.patch: upstream added a + user-verification workspace member next to the entries it + drops + +------------------------------------------------------------------- Old: ---- codex-rust-v0.154.0.tar.gz New: ---- codex-rust-v0.155.1.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ openai-codex.spec ++++++ --- /var/tmp/diff_new_pack.eecbbr/_old 2026-09-22 20:52:51.720303147 +0200 +++ /var/tmp/diff_new_pack.eecbbr/_new 2026-09-22 20:52:51.722303231 +0200 @@ -17,20 +17,20 @@ Name: openai-codex -Version: 0.154.0 +Version: 0.155.1 Release: 0 Summary: OpenAI Codex coding agent for the terminal # Legal-Review-Notice: upstream codex is Apache-2.0. Everything after that # covers the Rust crates statically linked into the shipped # %%{_bindir}/codex binary, enumerated with # cargo tree --offline -p codex-cli -e normal,no-proc-macro -# against the vendored tree (880 crates on aarch64, 882 on x86_64: 750 -# third-party vendored deps on aarch64 and 752 on x86_64, plus 130 +# against the vendored tree (884 crates on aarch64, 886 on x86_64: 751 +# third-party vendored deps on aarch64 and 753 on x86_64, plus 133 # first-party codex workspace members, which are Apache-2.0 like upstream. # Every one declares a licence, none is missing; only the third-party count # is a licence signal, the workspace one moves whenever upstream adds a # crate). Electing Apache-2.0 where it is offered and MIT otherwise, the -# aarch64 tally is Apache-2.0 651, MIT 176, +# aarch64 tally is Apache-2.0 654, MIT 177, # Unicode-3.0 20, MPL-2.0 12, ISC 7, BSD-3-Clause 6, Zlib 5, BSD-2-Clause 1, # CC0-1.0 1, CDLA-Permissive-2.0 1. # - self_cell 1.2.2 is "Apache-2.0 OR GPL-2.0-only" and is the ONLY crate @@ -108,7 +108,7 @@ # the DT_NEEDED assertion in %%install); those C sources stay inside # vendor.tar.zst, hence in the src.rpm, but end up in no binary package and so # get no bundled() Provides. -Provides: bundled(aws-lc) = 1.71.0 +Provides: bundled(aws-lc) = 5.7.0 ExclusiveArch: %{rust_tier1_arches} %description ++++++ _service ++++++ --- /var/tmp/diff_new_pack.eecbbr/_old 2026-09-22 20:52:51.789306040 +0200 +++ /var/tmp/diff_new_pack.eecbbr/_new 2026-09-22 20:52:51.792306166 +0200 @@ -11,11 +11,11 @@ feature and leaves the lockfile, hence the vendored set, untouched. To regenerate: - tar xf codex-rust-v0.154.0.tar.gz - patch -p1 -d codex-rust-v0.154.0 < codex-drop-v8-code-mode.patch - rm -rf codex-rust-v0.154.0/codex-rs/vendor + tar xf codex-rust-v0.155.1.tar.gz + patch -p1 -d codex-rust-v0.155.1 < codex-drop-v8-code-mode.patch + rm -rf codex-rust-v0.155.1/codex-rs/vendor osc service manualrun cargo_vendor - rm -rf codex-rust-v0.154.0 + rm -rf codex-rust-v0.155.1 The codex-rs/vendor removal drops the bundled bubblewrap 0.11.2 C sources, which %prep removes as well - codex uses the system bubblewrap instead. @@ -31,8 +31,11 @@ cargo-audit is NOT clean, and running it inside codex-rs hides most of it: upstream's codex-rs/.cargo/audit.toml ignores 11 advisories, which drops - the count from 5 to 1. Audit a bare copy of Cargo.lock instead. As of - 0.154.0, and unchanged since 0.151.0: + the count from 6 to 2 on upstream's own lockfile, and from 5 to 1 on the + shipped one where rustls is already pulled forward. Audit a bare copy of + Cargo.lock instead. As of 0.155.1, the bare lock reports six; five + survive in the shipped tree because the sixth (rustls) is pulled forward + below: RUSTSEC-2026-0185 / CVE-2026-25800 (quinn-proto 0.11.14, fixed 0.11.15) - NOT linked. reqwest gates dep:quinn behind its "http3" feature, which the workspace leaves off, so it never reaches @@ -50,9 +53,23 @@ not anything this package can vendor around. --> <service name="cargo_vendor" mode="manual"> - <param name="srcdir">codex-rust-v0.154.0/codex-rs</param> + <param name="srcdir">codex-rust-v0.155.1/codex-rs</param> <param name="compression">zst</param> <param name="update">false</param> + <!-- + rustls 0.23.36 is RUSTSEC-2026-0285 (GHSA-2mjx-qc3c-rqvc): TLS 1.3 + handshake messages accepted across encryption level boundaries. It is + linked (aws-smithy-http-client -> aws-config -> codex-aws-auth -> + codex-cli) and, unlike the four linked advisories above, its fix is + semver-compatible, so it can be pulled forward instead of waiting for + upstream. It is NOT collateral-free: rustls 0.23.45 floors aws-lc-rs + at 1.18, so this also moves aws-lc-rs 1.16.2 -> 1.18.1, aws-lc-sys + 0.39.0 -> 0.45.0 (bundled aws-lc 1.71.0 -> 5.7.0 - keep the spec's + Provides in step) and rustls-webpki 0.103.13 -> 0.103.15. Four crates, + which is still not the wholesale re-resolution update=true would do. + Drop this line once upstream's lockfile carries 0.23.45 or newer. + --> + <param name="update-crate">[email protected]</param> </service> </services> ++++++ codex-drop-v8-code-mode.patch ++++++ --- /var/tmp/diff_new_pack.eecbbr/_old 2026-09-22 20:52:51.806306753 +0200 +++ /var/tmp/diff_new_pack.eecbbr/_new 2026-09-22 20:52:51.810306920 +0200 @@ -13,7 +13,7 @@ --- a/codex-rs/Cargo.toml +++ b/codex-rs/Cargo.toml -@@ -24,9 +24,7 @@ +@@ -25,9 +25,7 @@ "install-context", "codex-backend-openapi-models", "code-mode", @@ -23,16 +23,15 @@ "codex-home", "cloud-config", "cloud-tasks", -@@ -101,8 +99,7 @@ - "otel-trace-websocket", +@@ -104,7 +102,6 @@ "tui", + "user-verification", "tools", - "v8-poc", "websocket-client", "windows-sandbox-service", "worktree", - "workload-identity", -@@ -185,7 +182,6 @@ +@@ -191,7 +188,6 @@ codex-cloud-tasks-mock-client = { path = "cloud-tasks-mock-client" } codex-code-mode = { path = "code-mode" } codex-code-mode-protocol = { path = "code-mode-protocol" } @@ -40,15 +39,15 @@ codex-home = { path = "codex-home" } codex-http-client = { path = "http-client" } codex-websocket-client = { path = "websocket-client" } -@@ -290,7 +286,6 @@ - codex-utils-stream-parser = { path = "utils/stream-parser" } +@@ -299,7 +295,6 @@ codex-utils-string = { path = "utils/string" } codex-utils-template = { path = "utils/template" } + codex-user-verification = { path = "user-verification" } -codex-v8-poc = { path = "v8-poc" } codex-workload-identity = { path = "workload-identity" } codex-windows-sandbox = { path = "windows-sandbox-rs" } core_test_support = { path = "core/tests/common" } -@@ -501,7 +496,6 @@ +@@ -517,7 +512,6 @@ url = "2" urlencoding = "2.1" uuid = "1" @@ -56,7 +55,7 @@ vt100 = "0.16.2" walkdir = "2.5.0" webbrowser = "1.2.2" -@@ -562,7 +556,6 @@ +@@ -578,7 +572,6 @@ ignored = [ "icu_provider", "openssl-sys", ++++++ codex-rust-v0.154.0.tar.gz -> codex-rust-v0.155.1.tar.gz ++++++ /work/SRC/openSUSE:Factory/openai-codex/codex-rust-v0.154.0.tar.gz /work/SRC/openSUSE:Factory/.openai-codex.new.383539/codex-rust-v0.155.1.tar.gz differ: char 22, line 1 ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/openai-codex/vendor.tar.zst /work/SRC/openSUSE:Factory/.openai-codex.new.383539/vendor.tar.zst differ: char 7, line 1
