fix(codex): track code-mode status lifecycle - #161
Conversation
graykode
left a comment
There was a problem hiding this comment.
Thanks for the comprehensive lifecycle work. The status ordering and custom tool-call tracking are generally well structured, and the full test suite, clippy, and release build pass locally. However, I found two blocking issues in the current Code Mode path.
-
The user-input wait detection does not match the event shape emitted by Code Mode. tool_waits_for_user checks the recorded tool name for request_user_input or AskUserQuestion, but current Code Mode records this as a custom_tool_call whose name is exec and whose input contains tools.request_user_input(...). call_names therefore stores exec, waiting_for_user remains false, and the open custom call is reported as Executing instead of Waiting. In sampled current rollouts, the user-input requests were custom-wrapped and there were no standalone function_call events for request_user_input. The new regression test uses the standalone function_call shape, so it does not reproduce the actual failure. Please add a fixture using custom_tool_call name exec with tools.request_user_input in input and make that path resolve to Waiting.
-
The new custom-tool branch copies the entire raw JavaScript input into ToolCall.arg after only secret-prefix redaction and a 120-character truncation. sanitize_tool_arg does not call sanitize_terminal_text and does not extract a bounded safe argument. This value reaches current_task, the TUI timeline, and JSON snapshots. Ordinary Code Mode inputs are multiline, and attacker-controlled ANSI/control or bidi characters can pass through as well; the raw source can also contain request bodies or other content that should not be treated as a short argument preview. Please sanitize terminal controls and bidi marks, and preferably extract only an allowlisted path or command preview. If a safe preview cannot be derived, display the tool name without the raw input. Add regression coverage for multiline input, terminal control characters, bidi marks, and sensitive inline content.
The lifecycle changes outside these two paths look sound. My requested changes are limited to matching the real custom-wrapped user-input event and keeping raw Code Mode source out of display and snapshot fields.
graykode
left a comment
There was a problem hiding this comment.
The custom-tool payload disclosure is fixed by 559dc1c: opaque inputs no longer reach task descriptions or tool argument previews, with regression coverage. The latest head is exactly that reviewed change merged with main, and CI passes. The previously noted custom-wrapped user-input detection remains a functional limitation (Executing instead of Waiting); I am treating it as a non-blocking follow-up rather than a security blocker. Approving this revision for merge.
…≥ ~0.149 (#170) Codex rollouts using `event_msg.item_completed` were missing chat, tool history, and file activity in abtop. This adds parsing for UserMessage, AgentMessage, CommandExecution, FileChange, and Extension items while retaining the existing event formats and Code Mode handling from #161. Progress messages and completed tools keep an active turn running. A final_answer message, task_complete, or turn_aborted ends it; a new user item clears the previous completion state. Command durations accept timestamps on either the item or its wrapper. Tool previews contain only a known operation and sanitized, bounded path metadata. Raw commands, scripts, patch bodies, and extension queries are omitted. Unknown operations use a fixed label. File-access history is bounded, and missing or unknown fields are tolerated. No new dependencies, external requests, or command execution are introduced. Validation: full `cargo test --locked`, `cargo clippy --locked --all-targets -- -D warnings`, and `cargo build --release --locked`. Regression tests cover turn lifecycle, private payload exclusion, terminal control/bidi sanitization, malformed items, history limits, and the custom-tool privacy protection from #161.
Summary
custom_tool_callandcustom_tool_call_outputevents emitted by current Codex Code Modetask_started/user_messagethroughtask_complete, including automatic turns with no user messageexec_command/write_stdintrackingRoot cause
The collector treated every
agent_messageas the end of a turn and only parsed the olderfunction_callevent shape. Codex CLI 0.144.6 emits intermediate progress messages and routes Code Mode tools through custom tool-call events, so the parsed state frequently disagreed with the live turn.Testing
cargo clippy --all-targets -- -D warningscargo test(207 unit tests and 1 doc test)abtop --jsonvalidation against active Codex CLI 0.144.6 sessions covering active tools, post-tool reasoning, completed turns, andrequest_user_inputCloses #160