Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package openai-codex for openSUSE:Factory checked in at 2026-09-29 17:50:42 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/openai-codex (Old) and /work/SRC/openSUSE:Factory/.openai-codex.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "openai-codex" Tue Sep 29 17:50:42 2026 rev:13 rq:1381272 version:0.158.0 Changes: -------- --- /work/SRC/openSUSE:Factory/openai-codex/openai-codex.changes 2026-09-24 23:01:23.628099271 +0200 +++ /work/SRC/openSUSE:Factory/.openai-codex.new.383539/openai-codex.changes 2026-09-29 17:52:01.005811727 +0200 @@ -1,0 +2,51 @@ +Mon Sep 28 15:20:51 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to version 0.158.0: + * Copy-on-select and configurable right-click paste in the + fullscreen TUI; copied transcript selections keep their + Markdown formatting + * MCP servers needing pre-registered OAuth client secrets are + supported, including via codex mcp add --oauth-client-secret + * Direct exec-server WebSocket connections can be secured with + bearer tokens, including when configured through app-server + * Image generation and editing can request transparent + backgrounds, and edits accept file-backed conversation images + * Terminal input approval is enabled by default for commands + running with elevated permissions + * Linux sandbox starts correctly with nested writable roots, and + Git metadata protections are preserved across writable roots + * Approval reviews retry when new user input arrives instead of + aborting a pending action + * Mermaid flowcharts render quoted labels and ampersands + * Command completion events carry early output and report + process-launch failures + * Many more fixes and improvements; see upstream's release notes + for the full list + * Vendored dependency set is unchanged - no third-party crate + moved - so the bare-lockfile audit still reports the same four + RUSTSEC advisories + * CVE-2026-93657 (boo#1282184): not affected, the vendored and + linked hickory-resolver is 0.25.2 and resolves with no dnssec + feature, which this CVE and RUSTSEC-2026-0118 both require + * CVE-2026-91986 (boo#1281744): not affected, the vendored and + linked gix-transport is 0.55.1 and is pulled in with default + features only, so the git-daemon connect request this CVE + injects into is never compiled + * codex-drop-v8-code-mode.patch: refresh the context around the + new websocket-auth workspace member upstream added +- Fix the build OOM that declined 0.157.0: ask _constraints for a + 32 GB worker instead of 16, size %limit_build so a 16 GB worker + builds -j1 rather than the -j2 that is still fatal, and cap the + test phase, which %limit_build does not reach + +------------------------------------------------------------------- +Fri Sep 25 14:56:22 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to version 0.157.0: + * GPT-6 Sol/Luna model support incl. Bedrock, fullscreen + transcripts, background-server autostart, fork shortcut, + remote/local import, terminal rendering improvements + * Refresh the vendored dependencies (no new advisories in + the bare-lockfile audit) + +------------------------------------------------------------------- Old: ---- codex-rust-v0.156.1.tar.gz New: ---- codex-rust-v0.158.0.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ openai-codex.spec ++++++ --- /var/tmp/diff_new_pack.rsKViR/_old 2026-09-29 17:52:51.660926935 +0200 +++ /var/tmp/diff_new_pack.rsKViR/_new 2026-09-29 17:52:51.666927186 +0200 @@ -17,7 +17,7 @@ Name: openai-codex -Version: 0.156.1 +Version: 0.158.0 Release: 0 Summary: OpenAI Codex coding agent for the terminal # Legal-Review-Notice: upstream codex is Apache-2.0. Everything after that @@ -171,11 +171,18 @@ %build # %%cargo_build otherwise fans out one job per CPU, which OOM-kills the build # on many-core workers. Cap the job count by available memory (paired with -# _constraints). 4000 rather than the usual 2000 because a single rustc here -# wants 4-5 GB: at 2000 an aarch64 worker with 22 GB took -j8 and the kernel -# OOM-killed rustc while compiling codex-tui, whereas -j4 on a 16 GB x86_64 -# worker (3.9 GB per job) was fine. -%limit_build -m 4000 +# _constraints). %%limit_build counts swap, so the 16 GB x86_64 worker that +# OOM-killed 0.157.0 (devel:tools srcmd5 76da4e11, 2026-09-25) had 20.5 GB to +# spend, and -m 4000 gave it -j4. 12000 is the smallest value that still +# gives such a worker -j1: codex-tui peaks at 16 GB and the final codex link +# at 19 GB, the peak of the whole build, so even two of them do not fit in +# 20.5 GB and at -j2 cargo guarantees a live sibling. Not the 19000 that +# 19 GB peak suggests - it is one crate out of 850, and charging it to +# every job would serialise a 4-core worker. _constraints asks for 32 G +# instead, where 12000 gives -j3. That same srcmd5 built fine on a 32 GB +# aarch64 worker: the limit was worker size, not the sources. Do not lower +# this again without re-measuring those two peaks. +%limit_build -m 12000 # Belt and braces: the bwrap crate is not in codex-cli's dependency graph, but # should it ever become one, this keeps its build script from compiling and # bundling a private bubblewrap. The sandbox launcher looks up the system bwrap @@ -253,6 +260,11 @@ # these the test profile would rebuild them with the library bundled. export LIBSQLITE3_SYS_USE_PKG_CONFIG=1 export RUSTONIG_SYSTEM_LIBONIG=1 +# %%limit_build reaches %%build alone: it sets _threads inside that section's +# shell, so %%check expands %%{?_smp_mflags} back to -j$(nproc) and links the +# test harnesses with every core - 33 GB measured at -j32, on top of what +# %%build already peaked at. Cap this section too. +%global _smp_mflags -j2 cd codex-rs # Deliberately an allowlist rather than --workspace. --workspace cannot be used # at all: it reaches the members Patch0 removes. Beyond that the choice is one ++++++ _constraints ++++++ --- /var/tmp/diff_new_pack.rsKViR/_old 2026-09-29 17:52:51.757930985 +0200 +++ /var/tmp/diff_new_pack.rsKViR/_new 2026-09-29 17:52:51.774931695 +0200 @@ -2,12 +2,14 @@ <constraints> <!-- Around 850 crates are compiled and linked into one binary, with the distribution's -C debuginfo=2 on top, so both the peak rustc and the - vendored-sources-plus-target tree are large. (Upstream's thin LTO is - turned off in %build precisely because its single link step needed far - more memory than any worker has - see the comment there.) --> + vendored-sources-plus-target tree are large. 32 G, not 16: a single + rustc peaks at 19 GB here, so 16 is under what one job needs - that + is what OOM-killed 0.157.0. (Upstream's thin LTO is turned off in + %build precisely because its single link step needed far more memory + than any worker has - see the comment there.) --> <hardware> <physicalmemory> - <size unit="G">16</size> + <size unit="G">32</size> </physicalmemory> <disk> <size unit="G">30</size> ++++++ _service ++++++ --- /var/tmp/diff_new_pack.rsKViR/_old 2026-09-29 17:52:51.842934534 +0200 +++ /var/tmp/diff_new_pack.rsKViR/_new 2026-09-29 17:52:51.850934868 +0200 @@ -11,11 +11,11 @@ feature and leaves the lockfile, hence the vendored set, untouched. To regenerate: - tar xf codex-rust-v0.156.1.tar.gz - patch -p1 -d codex-rust-v0.156.1 < codex-drop-v8-code-mode.patch - rm -rf codex-rust-v0.156.1/codex-rs/vendor + tar xf codex-rust-v0.158.0.tar.gz + patch -p1 -d codex-rust-v0.158.0 < codex-drop-v8-code-mode.patch + rm -rf codex-rust-v0.158.0/codex-rs/vendor osc service manualrun cargo_vendor - rm -rf codex-rust-v0.156.1 + rm -rf codex-rust-v0.158.0 The codex-rs/vendor removal drops the bundled bubblewrap 0.11.2 C sources, which %prep removes as well - codex uses the system bubblewrap instead. @@ -32,9 +32,9 @@ cargo-audit is NOT clean, and running it inside codex-rs hides most of it: upstream's codex-rs/.cargo/audit.toml ignores 11 advisories, which drops the count from 4 to 1 on upstream's own lockfile. Audit a bare copy of - Cargo.lock instead. As of 0.156.1, the bare lock reports four (the - 0.155.1 quinn-proto and rustls advisories are fixed upstream in - 0.11.15 and 0.23.45): + Cargo.lock instead. As of 0.158.0, the bare lock still reports + the same four (the 0.155.1 quinn-proto and rustls advisories are + fixed upstream in 0.11.15 and 0.23.45): RUSTSEC-2026-0194, RUSTSEC-2026-0195 (quick-xml 0.39.4, DoS) - linked via codex-tui -> syntect -> plist. Fixed in 0.41.0, which is semver-incompatible for plist, so update-crate cannot reach it. @@ -42,13 +42,25 @@ linked via codex-network-proxy -> rama-tcp -> rama-dns -> hickory-resolver. 0118 has no fixed release at all; 0119 needs 0.26.1, semver-incompatible for hickory-resolver. - None of the four carries a CVE id (GHSA/RUSTSEC-only), so there is no - security-tracker exposure. Re-run the bare-lockfile audit on - each bump - the fix for the linked four is an upstream dependency bump, - not anything this package can vendor around. + None of the four carries a CVE id, but they are not invisible to the + security tracker either: RUSTSEC-2026-0118 is aliased + GHSA-3v94-mw7p-v465, and boo#1282184 (CVE-2026-93657) is filed + against this package for hickory-resolver 0.25.2, the crate the + advisories above are reached through. 0118 is unreachable here even + so - the linked hickory-resolver resolves with system-config and tokio + and no dnssec-ring/dnssec-aws-lc-rs feature, which is 0118's own + precondition, and the same missing feature keeps CVE-2026-93657 out + (it needs DNSSEC validation on). boo#1281744 (CVE-2026-91986) is the + same story for the other linked crate: the linked gix-transport 0.55.1 + is pulled in with default features only, so the git-daemon connect + builder the CVE injects into is never compiled. All three bugs are + WONTFIX on those grounds and are cited in openai-codex.changes, so the + next sweep does not redo the triage. Re-run the bare-lockfile audit + on each bump - the fix for the linked four is an upstream dependency + bump, not anything this package can vendor around. --> <service name="cargo_vendor" mode="manual"> - <param name="srcdir">codex-rust-v0.156.1/codex-rs</param> + <param name="srcdir">codex-rust-v0.158.0/codex-rs</param> <param name="compression">zst</param> <param name="update">false</param> </service> ++++++ codex-drop-v8-code-mode.patch ++++++ --- /var/tmp/diff_new_pack.rsKViR/_old 2026-09-29 17:52:51.887936413 +0200 +++ /var/tmp/diff_new_pack.rsKViR/_new 2026-09-29 17:52:51.897936831 +0200 @@ -9,11 +9,18 @@ does not change the behaviour of the shipped codex binary. Dropping them also keeps ~213 MB of unbuilt V8 sources out of the vendor bundle. +The code_mode_host flag naming one of the dropped members is Stage::Stable and +on by default, but it only selects the session provider in +core/src/thread_manager.rs, and the surviving provider spawns the very +codex-code-mode-host binary this patch drops; the in-process alternative lived +in the removed code-mode-runtime. Either way the code_mode tool is registered +only when the UnderDevelopment code_mode flag is on. + Downstream-only distribution policy, not suitable for upstream submission. --- a/codex-rs/Cargo.toml +++ b/codex-rs/Cargo.toml -@@ -25,9 +25,7 @@ +@@ -26,9 +26,7 @@ "install-context", "codex-backend-openapi-models", "code-mode", @@ -23,23 +30,23 @@ "codex-home", "cloud-config", "cloud-tasks", -@@ -104,7 +102,6 @@ +@@ -109,7 +107,6 @@ "tui", "user-verification", "tools", - "v8-poc", + "websocket-auth", "websocket-client", "windows-sandbox-service", - "worktree", -@@ -191,7 +188,6 @@ +@@ -197,7 +194,6 @@ codex-cloud-tasks-mock-client = { path = "cloud-tasks-mock-client" } codex-code-mode = { path = "code-mode" } codex-code-mode-protocol = { path = "code-mode-protocol" } -codex-code-mode-runtime = { path = "code-mode-runtime" } codex-home = { path = "codex-home" } codex-http-client = { path = "http-client" } - codex-websocket-client = { path = "websocket-client" } -@@ -299,7 +295,6 @@ + codex-websocket-auth = { path = "websocket-auth" } +@@ -310,7 +306,6 @@ codex-utils-string = { path = "utils/string" } codex-utils-template = { path = "utils/template" } codex-user-verification = { path = "user-verification" } @@ -47,7 +54,7 @@ codex-workload-identity = { path = "workload-identity" } codex-windows-sandbox = { path = "windows-sandbox-rs" } core_test_support = { path = "core/tests/common" } -@@ -517,7 +512,6 @@ +@@ -534,7 +529,6 @@ url = "2" urlencoding = "2.1" uuid = "1" @@ -55,7 +62,7 @@ vt100 = "0.16.2" walkdir = "2.5.0" webbrowser = "1.2.2" -@@ -578,7 +572,6 @@ +@@ -595,7 +589,6 @@ ignored = [ "icu_provider", "openssl-sys", ++++++ codex-no-startup-update-check.patch ++++++ --- /var/tmp/diff_new_pack.rsKViR/_old 2026-09-29 17:52:51.928938125 +0200 +++ /var/tmp/diff_new_pack.rsKViR/_new 2026-09-29 17:52:51.943938751 +0200 @@ -12,7 +12,7 @@ --- a/codex-rs/core/src/config/mod.rs +++ b/codex-rs/core/src/config/mod.rs -@@ -3942,7 +3942,7 @@ +@@ -4049,7 +4049,7 @@ let review_model = override_review_model.or(cfg.review_model); ++++++ codex-rust-v0.156.1.tar.gz -> codex-rust-v0.158.0.tar.gz ++++++ /work/SRC/openSUSE:Factory/openai-codex/codex-rust-v0.156.1.tar.gz /work/SRC/openSUSE:Factory/.openai-codex.new.383539/codex-rust-v0.158.0.tar.gz differ: char 12, line 1 ++++++ codex-system-libzstd.patch ++++++ --- /var/tmp/diff_new_pack.rsKViR/_old 2026-09-29 17:52:52.035942593 +0200 +++ /var/tmp/diff_new_pack.rsKViR/_new 2026-09-29 17:52:52.046943052 +0200 @@ -11,7 +11,7 @@ --- a/codex-rs/Cargo.toml +++ b/codex-rs/Cargo.toml -@@ -504,7 +504,7 @@ +@@ -543,7 +543,7 @@ wildmatch = "2.6.1" winapi-util = "0.1.11" zip = "2.4.2" ++++++ vendor.tar.zst ++++++ /work/SRC/openSUSE:Factory/openai-codex/vendor.tar.zst /work/SRC/openSUSE:Factory/.openai-codex.new.383539/vendor.tar.zst differ: char 7, line 1
