Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package openai-codex for openSUSE:Factory checked in at 2026-09-24 22:59:24 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/openai-codex (Old) and /work/SRC/openSUSE:Factory/.openai-codex.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "openai-codex" Thu Sep 24 22:59:24 2026 rev:12 rq:1380121 version:0.156.1 Changes: -------- --- /work/SRC/openSUSE:Factory/openai-codex/openai-codex.changes 2026-09-22 20:52:30.496413295 +0200 +++ /work/SRC/openSUSE:Factory/.openai-codex.new.383539/openai-codex.changes 2026-09-24 23:01:23.628099271 +0200 @@ -1,0 +2,13 @@ +Wed Sep 23 17:02:03 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to version 0.156.1: + * Hotfix adding GPT-6 Sol and Luna to the model catalog + * Refresh the vendored dependencies (quinn-proto 0.11.15, + rustls 0.23.45: earlier RUSTSEC advisories fixed upstream; + drop the now-redundant rustls pull-forward) + * Raise the recursion limit for codex-chatgpt: current + rustc overflows its query-depth limit on the + list_connectors async state machine otherwise + * codex-recursion-limit-chatgpt.patch + +------------------------------------------------------------------- Old: ---- codex-rust-v0.155.1.tar.gz New: ---- codex-recursion-limit-chatgpt.patch codex-rust-v0.156.1.tar.gz ----------(New B)---------- New: list_connectors async state machine otherwise * codex-recursion-limit-chatgpt.patch ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ openai-codex.spec ++++++ --- /var/tmp/diff_new_pack.oS0bhf/_old 2026-09-24 23:01:29.074326999 +0200 +++ /var/tmp/diff_new_pack.oS0bhf/_new 2026-09-24 23:01:29.080327250 +0200 @@ -17,7 +17,7 @@ Name: openai-codex -Version: 0.155.1 +Version: 0.156.1 Release: 0 Summary: OpenAI Codex coding agent for the terminal # Legal-Review-Notice: upstream codex is Apache-2.0. Everything after that @@ -77,6 +77,8 @@ Patch1: codex-no-startup-update-check.patch # PATCH-FIX-OPENSUSE codex-system-libzstd.patch [email protected] -- link zstd-sys against the system libzstd instead of its bundled copy Patch2: codex-system-libzstd.patch +# PATCH-FIX-OPENSUSE codex-recursion-limit-chatgpt.patch [email protected] -- raise the query-depth limit rustc overflows on codex-chatgpt's list_connectors async state machine (toolchain workaround, upstream pins its own toolchain) +Patch3: codex-recursion-limit-chatgpt.patch BuildRequires: cargo BuildRequires: cargo-packaging >= 1.2.0 BuildRequires: cmake ++++++ _service ++++++ --- /var/tmp/diff_new_pack.oS0bhf/_old 2026-09-24 23:01:29.187331724 +0200 +++ /var/tmp/diff_new_pack.oS0bhf/_new 2026-09-24 23:01:29.195332058 +0200 @@ -11,11 +11,11 @@ feature and leaves the lockfile, hence the vendored set, untouched. To regenerate: - tar xf codex-rust-v0.155.1.tar.gz - patch -p1 -d codex-rust-v0.155.1 < codex-drop-v8-code-mode.patch - rm -rf codex-rust-v0.155.1/codex-rs/vendor + tar xf codex-rust-v0.156.1.tar.gz + patch -p1 -d codex-rust-v0.156.1 < codex-drop-v8-code-mode.patch + rm -rf codex-rust-v0.156.1/codex-rs/vendor osc service manualrun cargo_vendor - rm -rf codex-rust-v0.155.1 + rm -rf codex-rust-v0.156.1 The codex-rs/vendor removal drops the bundled bubblewrap 0.11.2 C sources, which %prep removes as well - codex uses the system bubblewrap instead. @@ -31,15 +31,10 @@ cargo-audit is NOT clean, and running it inside codex-rs hides most of it: upstream's codex-rs/.cargo/audit.toml ignores 11 advisories, which drops - the count from 6 to 2 on upstream's own lockfile, and from 5 to 1 on the - shipped one where rustls is already pulled forward. Audit a bare copy of - Cargo.lock instead. As of 0.155.1, the bare lock reports six; five - survive in the shipped tree because the sixth (rustls) is pulled forward - below: - RUSTSEC-2026-0185 / CVE-2026-25800 (quinn-proto 0.11.14, fixed - 0.11.15) - NOT linked. reqwest gates dep:quinn behind its "http3" - feature, which the workspace leaves off, so it never reaches - "cargo tree -p codex-cli -e normal,no-proc-macro". + the count from 4 to 1 on upstream's own lockfile. Audit a bare copy of + Cargo.lock instead. As of 0.156.1, the bare lock reports four (the + 0.155.1 quinn-proto and rustls advisories are fixed upstream in + 0.11.15 and 0.23.45): RUSTSEC-2026-0194, RUSTSEC-2026-0195 (quick-xml 0.39.4, DoS) - linked via codex-tui -> syntect -> plist. Fixed in 0.41.0, which is semver-incompatible for plist, so update-crate cannot reach it. @@ -47,29 +42,15 @@ linked via codex-network-proxy -> rama-tcp -> rama-dns -> hickory-resolver. 0118 has no fixed release at all; 0119 needs 0.26.1, semver-incompatible for hickory-resolver. - Only 0185 carries a CVE id; the other four are GHSA/RUSTSEC-only, so - there is no security-tracker exposure. Re-run the bare-lockfile audit on + None of the four carries a CVE id (GHSA/RUSTSEC-only), so there is no + security-tracker exposure. Re-run the bare-lockfile audit on each bump - the fix for the linked four is an upstream dependency bump, not anything this package can vendor around. --> <service name="cargo_vendor" mode="manual"> - <param name="srcdir">codex-rust-v0.155.1/codex-rs</param> + <param name="srcdir">codex-rust-v0.156.1/codex-rs</param> <param name="compression">zst</param> <param name="update">false</param> - <!-- - rustls 0.23.36 is RUSTSEC-2026-0285 (GHSA-2mjx-qc3c-rqvc): TLS 1.3 - handshake messages accepted across encryption level boundaries. It is - linked (aws-smithy-http-client -> aws-config -> codex-aws-auth -> - codex-cli) and, unlike the four linked advisories above, its fix is - semver-compatible, so it can be pulled forward instead of waiting for - upstream. It is NOT collateral-free: rustls 0.23.45 floors aws-lc-rs - at 1.18, so this also moves aws-lc-rs 1.16.2 -> 1.18.1, aws-lc-sys - 0.39.0 -> 0.45.0 (bundled aws-lc 1.71.0 -> 5.7.0 - keep the spec's - Provides in step) and rustls-webpki 0.103.13 -> 0.103.15. Four crates, - which is still not the wholesale re-resolution update=true would do. - Drop this line once upstream's lockfile carries 0.23.45 or newer. - --> - <param name="update-crate">[email protected]</param> </service> </services> ++++++ codex-recursion-limit-chatgpt.patch ++++++ From: Martin Pluskal <[email protected]> Subject: [PATCH] Raise the recursion limit for codex-chatgpt rustc (1.98, aarch64) overflows its query-depth limit computing the layout of the list_connectors async state machine in this crate: error: queries overflow the depth limit! = help: consider increasing the recursion limit by adding a `#![recursion_limit = "256"]` attribute to your crate (`codex_chatgpt`) The code is unchanged since 0.155.1 which built fine, so this is a toolchain behavior change, not an upstream regression. Upstream pins its own toolchain via rust-toolchain.toml (dropped in %prep), so this workaround stays downstream. --- codex-rs/chatgpt/src/lib.rs | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/codex-rs/chatgpt/src/lib.rs b/codex-rs/chatgpt/src/lib.rs index 12345678..9abcdef0 100644 --- a/codex-rs/chatgpt/src/lib.rs +++ b/codex-rs/chatgpt/src/lib.rs @@ -1,3 +1,7 @@ +// The list_connectors async state machine overflows rustc's query-depth +// limit on some toolchains/arches; raise it per the compiler's suggestion. +#![recursion_limit = "256"] + pub mod apply_command; mod chatgpt_client; pub mod connectors; ++++++ codex-rust-v0.155.1.tar.gz -> codex-rust-v0.156.1.tar.gz ++++++ /work/SRC/openSUSE:Factory/openai-codex/codex-rust-v0.155.1.tar.gz /work/SRC/openSUSE:Factory/.openai-codex.new.383539/codex-rust-v0.156.1.tar.gz differ: char 22, line 1 ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/openai-codex/vendor.tar.zst /work/SRC/openSUSE:Factory/.openai-codex.new.383539/vendor.tar.zst differ: char 7, line 1
