Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package openai-codex for openSUSE:Factory 
checked in at 2026-09-29 17:50:42
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/openai-codex (Old)
 and      /work/SRC/openSUSE:Factory/.openai-codex.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "openai-codex"

Tue Sep 29 17:50:42 2026 rev:13 rq:1381272 version:0.158.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/openai-codex/openai-codex.changes        
2026-09-24 23:01:23.628099271 +0200
+++ /work/SRC/openSUSE:Factory/.openai-codex.new.383539/openai-codex.changes    
2026-09-29 17:52:01.005811727 +0200
@@ -1,0 +2,51 @@
+Mon Sep 28 15:20:51 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to version 0.158.0:
+  * Copy-on-select and configurable right-click paste in the
+    fullscreen TUI; copied transcript selections keep their
+    Markdown formatting
+  * MCP servers needing pre-registered OAuth client secrets are
+    supported, including via codex mcp add --oauth-client-secret
+  * Direct exec-server WebSocket connections can be secured with
+    bearer tokens, including when configured through app-server
+  * Image generation and editing can request transparent
+    backgrounds, and edits accept file-backed conversation images
+  * Terminal input approval is enabled by default for commands
+    running with elevated permissions
+  * Linux sandbox starts correctly with nested writable roots, and
+    Git metadata protections are preserved across writable roots
+  * Approval reviews retry when new user input arrives instead of
+    aborting a pending action
+  * Mermaid flowcharts render quoted labels and ampersands
+  * Command completion events carry early output and report
+    process-launch failures
+  * Many more fixes and improvements; see upstream's release notes
+    for the full list
+  * Vendored dependency set is unchanged - no third-party crate
+    moved - so the bare-lockfile audit still reports the same four
+    RUSTSEC advisories
+  * CVE-2026-93657 (boo#1282184): not affected, the vendored and
+    linked hickory-resolver is 0.25.2 and resolves with no dnssec
+    feature, which this CVE and RUSTSEC-2026-0118 both require
+  * CVE-2026-91986 (boo#1281744): not affected, the vendored and
+    linked gix-transport is 0.55.1 and is pulled in with default
+    features only, so the git-daemon connect request this CVE
+    injects into is never compiled
+  * codex-drop-v8-code-mode.patch: refresh the context around the
+    new websocket-auth workspace member upstream added
+- Fix the build OOM that declined 0.157.0: ask _constraints for a
+  32 GB worker instead of 16, size %limit_build so a 16 GB worker
+  builds -j1 rather than the -j2 that is still fatal, and cap the
+  test phase, which %limit_build does not reach
+
+-------------------------------------------------------------------
+Fri Sep 25 14:56:22 UTC 2026 - Martin Pluskal <[email protected]>
+
+- Update to version 0.157.0:
+  * GPT-6 Sol/Luna model support incl. Bedrock, fullscreen
+    transcripts, background-server autostart, fork shortcut,
+    remote/local import, terminal rendering improvements
+  * Refresh the vendored dependencies (no new advisories in
+    the bare-lockfile audit)
+
+-------------------------------------------------------------------

Old:
----
  codex-rust-v0.156.1.tar.gz

New:
----
  codex-rust-v0.158.0.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ openai-codex.spec ++++++
--- /var/tmp/diff_new_pack.rsKViR/_old  2026-09-29 17:52:51.660926935 +0200
+++ /var/tmp/diff_new_pack.rsKViR/_new  2026-09-29 17:52:51.666927186 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           openai-codex
-Version:        0.156.1
+Version:        0.158.0
 Release:        0
 Summary:        OpenAI Codex coding agent for the terminal
 # Legal-Review-Notice: upstream codex is Apache-2.0. Everything after that
@@ -171,11 +171,18 @@
 %build
 # %%cargo_build otherwise fans out one job per CPU, which OOM-kills the build
 # on many-core workers. Cap the job count by available memory (paired with
-# _constraints). 4000 rather than the usual 2000 because a single rustc here
-# wants 4-5 GB: at 2000 an aarch64 worker with 22 GB took -j8 and the kernel
-# OOM-killed rustc while compiling codex-tui, whereas -j4 on a 16 GB x86_64
-# worker (3.9 GB per job) was fine.
-%limit_build -m 4000
+# _constraints). %%limit_build counts swap, so the 16 GB x86_64 worker that
+# OOM-killed 0.157.0 (devel:tools srcmd5 76da4e11, 2026-09-25) had 20.5 GB to
+# spend, and -m 4000 gave it -j4. 12000 is the smallest value that still
+# gives such a worker -j1: codex-tui peaks at 16 GB and the final codex link
+# at 19 GB, the peak of the whole build, so even two of them do not fit in
+# 20.5 GB and at -j2 cargo guarantees a live sibling. Not the 19000 that
+# 19 GB peak suggests - it is one crate out of 850, and charging it to
+# every job would serialise a 4-core worker. _constraints asks for 32 G
+# instead, where 12000 gives -j3. That same srcmd5 built fine on a 32 GB
+# aarch64 worker: the limit was worker size, not the sources. Do not lower
+# this again without re-measuring those two peaks.
+%limit_build -m 12000
 # Belt and braces: the bwrap crate is not in codex-cli's dependency graph, but
 # should it ever become one, this keeps its build script from compiling and
 # bundling a private bubblewrap. The sandbox launcher looks up the system bwrap
@@ -253,6 +260,11 @@
 # these the test profile would rebuild them with the library bundled.
 export LIBSQLITE3_SYS_USE_PKG_CONFIG=1
 export RUSTONIG_SYSTEM_LIBONIG=1
+# %%limit_build reaches %%build alone: it sets _threads inside that section's
+# shell, so %%check expands %%{?_smp_mflags} back to -j$(nproc) and links the
+# test harnesses with every core - 33 GB measured at -j32, on top of what
+# %%build already peaked at. Cap this section too.
+%global _smp_mflags -j2
 cd codex-rs
 # Deliberately an allowlist rather than --workspace. --workspace cannot be used
 # at all: it reaches the members Patch0 removes. Beyond that the choice is one

++++++ _constraints ++++++
--- /var/tmp/diff_new_pack.rsKViR/_old  2026-09-29 17:52:51.757930985 +0200
+++ /var/tmp/diff_new_pack.rsKViR/_new  2026-09-29 17:52:51.774931695 +0200
@@ -2,12 +2,14 @@
 <constraints>
   <!-- Around 850 crates are compiled and linked into one binary, with the
        distribution's -C debuginfo=2 on top, so both the peak rustc and the
-       vendored-sources-plus-target tree are large. (Upstream's thin LTO is
-       turned off in %build precisely because its single link step needed far
-       more memory than any worker has - see the comment there.) -->
+       vendored-sources-plus-target tree are large. 32 G, not 16: a single
+       rustc peaks at 19 GB here, so 16 is under what one job needs - that
+       is what OOM-killed 0.157.0. (Upstream's thin LTO is turned off in
+       %build precisely because its single link step needed far more memory
+       than any worker has - see the comment there.) -->
   <hardware>
     <physicalmemory>
-      <size unit="G">16</size>
+      <size unit="G">32</size>
     </physicalmemory>
     <disk>
       <size unit="G">30</size>

++++++ _service ++++++
--- /var/tmp/diff_new_pack.rsKViR/_old  2026-09-29 17:52:51.842934534 +0200
+++ /var/tmp/diff_new_pack.rsKViR/_new  2026-09-29 17:52:51.850934868 +0200
@@ -11,11 +11,11 @@
     feature and leaves the lockfile, hence the vendored set, untouched.
     To regenerate:
 
-      tar xf codex-rust-v0.156.1.tar.gz
-      patch -p1 -d codex-rust-v0.156.1 < codex-drop-v8-code-mode.patch
-      rm -rf codex-rust-v0.156.1/codex-rs/vendor
+      tar xf codex-rust-v0.158.0.tar.gz
+      patch -p1 -d codex-rust-v0.158.0 < codex-drop-v8-code-mode.patch
+      rm -rf codex-rust-v0.158.0/codex-rs/vendor
       osc service manualrun cargo_vendor
-      rm -rf codex-rust-v0.156.1
+      rm -rf codex-rust-v0.158.0
 
     The codex-rs/vendor removal drops the bundled bubblewrap 0.11.2 C sources,
     which %prep removes as well - codex uses the system bubblewrap instead.
@@ -32,9 +32,9 @@
     cargo-audit is NOT clean, and running it inside codex-rs hides most of it:
     upstream's codex-rs/.cargo/audit.toml ignores 11 advisories, which drops
     the count from 4 to 1 on upstream's own lockfile.  Audit a bare copy of
-    Cargo.lock instead.  As of 0.156.1, the bare lock reports four (the
-    0.155.1 quinn-proto and rustls advisories are fixed upstream in
-    0.11.15 and 0.23.45):
+    Cargo.lock instead.  As of 0.158.0, the bare lock still reports
+    the same four (the 0.155.1 quinn-proto and rustls advisories are
+    fixed upstream in 0.11.15 and 0.23.45):
       RUSTSEC-2026-0194, RUSTSEC-2026-0195 (quick-xml 0.39.4, DoS) - linked
         via codex-tui -> syntect -> plist.  Fixed in 0.41.0, which is
         semver-incompatible for plist, so update-crate cannot reach it.
@@ -42,13 +42,25 @@
         linked via codex-network-proxy -> rama-tcp -> rama-dns ->
         hickory-resolver.  0118 has no fixed release at all; 0119 needs
         0.26.1, semver-incompatible for hickory-resolver.
-    None of the four carries a CVE id (GHSA/RUSTSEC-only), so there is no
-    security-tracker exposure.  Re-run the bare-lockfile audit on
-    each bump - the fix for the linked four is an upstream dependency bump,
-    not anything this package can vendor around.
+    None of the four carries a CVE id, but they are not invisible to the
+    security tracker either: RUSTSEC-2026-0118 is aliased
+    GHSA-3v94-mw7p-v465, and boo#1282184 (CVE-2026-93657) is filed
+    against this package for hickory-resolver 0.25.2, the crate the
+    advisories above are reached through.  0118 is unreachable here even
+    so - the linked hickory-resolver resolves with system-config and tokio
+    and no dnssec-ring/dnssec-aws-lc-rs feature, which is 0118's own
+    precondition, and the same missing feature keeps CVE-2026-93657 out
+    (it needs DNSSEC validation on).  boo#1281744 (CVE-2026-91986) is the
+    same story for the other linked crate: the linked gix-transport 0.55.1
+    is pulled in with default features only, so the git-daemon connect
+    builder the CVE injects into is never compiled.  All three bugs are
+    WONTFIX on those grounds and are cited in openai-codex.changes, so the
+    next sweep does not redo the triage.  Re-run the bare-lockfile audit
+    on each bump - the fix for the linked four is an upstream dependency
+    bump, not anything this package can vendor around.
   -->
   <service name="cargo_vendor" mode="manual">
-    <param name="srcdir">codex-rust-v0.156.1/codex-rs</param>
+    <param name="srcdir">codex-rust-v0.158.0/codex-rs</param>
     <param name="compression">zst</param>
     <param name="update">false</param>
   </service>

++++++ codex-drop-v8-code-mode.patch ++++++
--- /var/tmp/diff_new_pack.rsKViR/_old  2026-09-29 17:52:51.887936413 +0200
+++ /var/tmp/diff_new_pack.rsKViR/_new  2026-09-29 17:52:51.897936831 +0200
@@ -9,11 +9,18 @@
 does not change the behaviour of the shipped codex binary.  Dropping them also
 keeps ~213 MB of unbuilt V8 sources out of the vendor bundle.
 
+The code_mode_host flag naming one of the dropped members is Stage::Stable and
+on by default, but it only selects the session provider in
+core/src/thread_manager.rs, and the surviving provider spawns the very
+codex-code-mode-host binary this patch drops; the in-process alternative lived
+in the removed code-mode-runtime.  Either way the code_mode tool is registered
+only when the UnderDevelopment code_mode flag is on.
+
 Downstream-only distribution policy, not suitable for upstream submission.
 
 --- a/codex-rs/Cargo.toml
 +++ b/codex-rs/Cargo.toml
-@@ -25,9 +25,7 @@
+@@ -26,9 +26,7 @@
      "install-context",
      "codex-backend-openapi-models",
      "code-mode",
@@ -23,23 +30,23 @@
      "codex-home",
      "cloud-config",
      "cloud-tasks",
-@@ -104,7 +102,6 @@
+@@ -109,7 +107,6 @@
      "tui",
      "user-verification",
      "tools",
 -    "v8-poc",
+     "websocket-auth",
      "websocket-client",
      "windows-sandbox-service",
-     "worktree",
-@@ -191,7 +188,6 @@
+@@ -197,7 +194,6 @@
  codex-cloud-tasks-mock-client = { path = "cloud-tasks-mock-client" }
  codex-code-mode = { path = "code-mode" }
  codex-code-mode-protocol = { path = "code-mode-protocol" }
 -codex-code-mode-runtime = { path = "code-mode-runtime" }
  codex-home = { path = "codex-home" }
  codex-http-client = { path = "http-client" }
- codex-websocket-client = { path = "websocket-client" }
-@@ -299,7 +295,6 @@
+ codex-websocket-auth = { path = "websocket-auth" }
+@@ -310,7 +306,6 @@
  codex-utils-string = { path = "utils/string" }
  codex-utils-template = { path = "utils/template" }
  codex-user-verification = { path = "user-verification" }
@@ -47,7 +54,7 @@
  codex-workload-identity = { path = "workload-identity" }
  codex-windows-sandbox = { path = "windows-sandbox-rs" }
  core_test_support = { path = "core/tests/common" }
-@@ -517,7 +512,6 @@
+@@ -534,7 +529,6 @@
  url = "2"
  urlencoding = "2.1"
  uuid = "1"
@@ -55,7 +62,7 @@
  vt100 = "0.16.2"
  walkdir = "2.5.0"
  webbrowser = "1.2.2"
-@@ -578,7 +572,6 @@
+@@ -595,7 +589,6 @@
  ignored = [
      "icu_provider",
      "openssl-sys",

++++++ codex-no-startup-update-check.patch ++++++
--- /var/tmp/diff_new_pack.rsKViR/_old  2026-09-29 17:52:51.928938125 +0200
+++ /var/tmp/diff_new_pack.rsKViR/_new  2026-09-29 17:52:51.943938751 +0200
@@ -12,7 +12,7 @@
 
 --- a/codex-rs/core/src/config/mod.rs
 +++ b/codex-rs/core/src/config/mod.rs
-@@ -3942,7 +3942,7 @@
+@@ -4049,7 +4049,7 @@
  
          let review_model = override_review_model.or(cfg.review_model);
  

++++++ codex-rust-v0.156.1.tar.gz -> codex-rust-v0.158.0.tar.gz ++++++
/work/SRC/openSUSE:Factory/openai-codex/codex-rust-v0.156.1.tar.gz 
/work/SRC/openSUSE:Factory/.openai-codex.new.383539/codex-rust-v0.158.0.tar.gz 
differ: char 12, line 1

++++++ codex-system-libzstd.patch ++++++
--- /var/tmp/diff_new_pack.rsKViR/_old  2026-09-29 17:52:52.035942593 +0200
+++ /var/tmp/diff_new_pack.rsKViR/_new  2026-09-29 17:52:52.046943052 +0200
@@ -11,7 +11,7 @@
 
 --- a/codex-rs/Cargo.toml
 +++ b/codex-rs/Cargo.toml
-@@ -504,7 +504,7 @@
+@@ -543,7 +543,7 @@
  wildmatch = "2.6.1"
  winapi-util = "0.1.11"
  zip = "2.4.2"

++++++ vendor.tar.zst ++++++
/work/SRC/openSUSE:Factory/openai-codex/vendor.tar.zst 
/work/SRC/openSUSE:Factory/.openai-codex.new.383539/vendor.tar.zst differ: char 
7, line 1

Reply via email to