Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package openai-codex for openSUSE:Factory 
checked in at 2026-09-24 22:59:24
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/openai-codex (Old)
 and      /work/SRC/openSUSE:Factory/.openai-codex.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "openai-codex"

Thu Sep 24 22:59:24 2026 rev:12 rq:1380121 version:0.156.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/openai-codex/openai-codex.changes        
2026-09-22 20:52:30.496413295 +0200
+++ /work/SRC/openSUSE:Factory/.openai-codex.new.383539/openai-codex.changes    
2026-09-24 23:01:23.628099271 +0200
@@ -1,0 +2,13 @@
+Wed Sep 23 17:02:03 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to version 0.156.1:
+  * Hotfix adding GPT-6 Sol and Luna to the model catalog
+  * Refresh the vendored dependencies (quinn-proto 0.11.15,
+    rustls 0.23.45: earlier RUSTSEC advisories fixed upstream;
+    drop the now-redundant rustls pull-forward)
+  * Raise the recursion limit for codex-chatgpt: current
+    rustc overflows its query-depth limit on the
+    list_connectors async state machine otherwise
+  * codex-recursion-limit-chatgpt.patch
+
+-------------------------------------------------------------------

Old:
----
  codex-rust-v0.155.1.tar.gz

New:
----
  codex-recursion-limit-chatgpt.patch
  codex-rust-v0.156.1.tar.gz

----------(New B)----------
  New:    list_connectors async state machine otherwise
  * codex-recursion-limit-chatgpt.patch
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ openai-codex.spec ++++++
--- /var/tmp/diff_new_pack.oS0bhf/_old  2026-09-24 23:01:29.074326999 +0200
+++ /var/tmp/diff_new_pack.oS0bhf/_new  2026-09-24 23:01:29.080327250 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           openai-codex
-Version:        0.155.1
+Version:        0.156.1
 Release:        0
 Summary:        OpenAI Codex coding agent for the terminal
 # Legal-Review-Notice: upstream codex is Apache-2.0. Everything after that
@@ -77,6 +77,8 @@
 Patch1:         codex-no-startup-update-check.patch
 # PATCH-FIX-OPENSUSE codex-system-libzstd.patch [email protected] -- link 
zstd-sys against the system libzstd instead of its bundled copy
 Patch2:         codex-system-libzstd.patch
+# PATCH-FIX-OPENSUSE codex-recursion-limit-chatgpt.patch [email protected] -- 
raise the query-depth limit rustc overflows on codex-chatgpt's list_connectors 
async state machine (toolchain workaround, upstream pins its own toolchain)
+Patch3:         codex-recursion-limit-chatgpt.patch
 BuildRequires:  cargo
 BuildRequires:  cargo-packaging >= 1.2.0
 BuildRequires:  cmake

++++++ _service ++++++
--- /var/tmp/diff_new_pack.oS0bhf/_old  2026-09-24 23:01:29.187331724 +0200
+++ /var/tmp/diff_new_pack.oS0bhf/_new  2026-09-24 23:01:29.195332058 +0200
@@ -11,11 +11,11 @@
     feature and leaves the lockfile, hence the vendored set, untouched.
     To regenerate:
 
-      tar xf codex-rust-v0.155.1.tar.gz
-      patch -p1 -d codex-rust-v0.155.1 < codex-drop-v8-code-mode.patch
-      rm -rf codex-rust-v0.155.1/codex-rs/vendor
+      tar xf codex-rust-v0.156.1.tar.gz
+      patch -p1 -d codex-rust-v0.156.1 < codex-drop-v8-code-mode.patch
+      rm -rf codex-rust-v0.156.1/codex-rs/vendor
       osc service manualrun cargo_vendor
-      rm -rf codex-rust-v0.155.1
+      rm -rf codex-rust-v0.156.1
 
     The codex-rs/vendor removal drops the bundled bubblewrap 0.11.2 C sources,
     which %prep removes as well - codex uses the system bubblewrap instead.
@@ -31,15 +31,10 @@
 
     cargo-audit is NOT clean, and running it inside codex-rs hides most of it:
     upstream's codex-rs/.cargo/audit.toml ignores 11 advisories, which drops
-    the count from 6 to 2 on upstream's own lockfile, and from 5 to 1 on the
-    shipped one where rustls is already pulled forward.  Audit a bare copy of
-    Cargo.lock instead.  As of 0.155.1, the bare lock reports six; five
-    survive in the shipped tree because the sixth (rustls) is pulled forward
-    below:
-      RUSTSEC-2026-0185 / CVE-2026-25800 (quinn-proto 0.11.14, fixed
-        0.11.15) - NOT linked.  reqwest gates dep:quinn behind its "http3"
-        feature, which the workspace leaves off, so it never reaches
-        "cargo tree -p codex-cli -e normal,no-proc-macro".
+    the count from 4 to 1 on upstream's own lockfile.  Audit a bare copy of
+    Cargo.lock instead.  As of 0.156.1, the bare lock reports four (the
+    0.155.1 quinn-proto and rustls advisories are fixed upstream in
+    0.11.15 and 0.23.45):
       RUSTSEC-2026-0194, RUSTSEC-2026-0195 (quick-xml 0.39.4, DoS) - linked
         via codex-tui -> syntect -> plist.  Fixed in 0.41.0, which is
         semver-incompatible for plist, so update-crate cannot reach it.
@@ -47,29 +42,15 @@
         linked via codex-network-proxy -> rama-tcp -> rama-dns ->
         hickory-resolver.  0118 has no fixed release at all; 0119 needs
         0.26.1, semver-incompatible for hickory-resolver.
-    Only 0185 carries a CVE id; the other four are GHSA/RUSTSEC-only, so
-    there is no security-tracker exposure.  Re-run the bare-lockfile audit on
+    None of the four carries a CVE id (GHSA/RUSTSEC-only), so there is no
+    security-tracker exposure.  Re-run the bare-lockfile audit on
     each bump - the fix for the linked four is an upstream dependency bump,
     not anything this package can vendor around.
   -->
   <service name="cargo_vendor" mode="manual">
-    <param name="srcdir">codex-rust-v0.155.1/codex-rs</param>
+    <param name="srcdir">codex-rust-v0.156.1/codex-rs</param>
     <param name="compression">zst</param>
     <param name="update">false</param>
-    <!--
-      rustls 0.23.36 is RUSTSEC-2026-0285 (GHSA-2mjx-qc3c-rqvc): TLS 1.3
-      handshake messages accepted across encryption level boundaries.  It is
-      linked (aws-smithy-http-client -> aws-config -> codex-aws-auth ->
-      codex-cli) and, unlike the four linked advisories above, its fix is
-      semver-compatible, so it can be pulled forward instead of waiting for
-      upstream.  It is NOT collateral-free: rustls 0.23.45 floors aws-lc-rs
-      at 1.18, so this also moves aws-lc-rs 1.16.2 -> 1.18.1, aws-lc-sys
-      0.39.0 -> 0.45.0 (bundled aws-lc 1.71.0 -> 5.7.0 - keep the spec's
-      Provides in step) and rustls-webpki 0.103.13 -> 0.103.15.  Four crates,
-      which is still not the wholesale re-resolution update=true would do.
-      Drop this line once upstream's lockfile carries 0.23.45 or newer.
-    -->
-    <param name="update-crate">[email protected]</param>
   </service>
 </services>
 

++++++ codex-recursion-limit-chatgpt.patch ++++++
From: Martin Pluskal <[email protected]>
Subject: [PATCH] Raise the recursion limit for codex-chatgpt

rustc (1.98, aarch64) overflows its query-depth limit computing the
layout of the list_connectors async state machine in this crate:

  error: queries overflow the depth limit!
   = help: consider increasing the recursion limit by adding a
     `#![recursion_limit = "256"]` attribute to your crate
     (`codex_chatgpt`)

The code is unchanged since 0.155.1 which built fine, so this is a
toolchain behavior change, not an upstream regression.  Upstream pins
its own toolchain via rust-toolchain.toml (dropped in %prep), so this
workaround stays downstream.
---
 codex-rs/chatgpt/src/lib.rs | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/codex-rs/chatgpt/src/lib.rs b/codex-rs/chatgpt/src/lib.rs
index 12345678..9abcdef0 100644
--- a/codex-rs/chatgpt/src/lib.rs
+++ b/codex-rs/chatgpt/src/lib.rs
@@ -1,3 +1,7 @@
+// The list_connectors async state machine overflows rustc's query-depth
+// limit on some toolchains/arches; raise it per the compiler's suggestion.
+#![recursion_limit = "256"]
+
 pub mod apply_command;
 mod chatgpt_client;
 pub mod connectors;

++++++ codex-rust-v0.155.1.tar.gz -> codex-rust-v0.156.1.tar.gz ++++++
/work/SRC/openSUSE:Factory/openai-codex/codex-rust-v0.155.1.tar.gz 
/work/SRC/openSUSE:Factory/.openai-codex.new.383539/codex-rust-v0.156.1.tar.gz 
differ: char 22, line 1

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/openai-codex/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.openai-codex.new.383539/vendor.tar.zst differ: char 
7, line 1

Reply via email to