Skip to content

Restrict TUI MCP startup notifications to owned threads - #50781

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/6f78f237f7441aadf10b491ed191357df75c3a6a
Oct 4, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/6f78f237f7441aadf10b491ed191357df75c3a6a

Conversation

@copyberry

@copyberry copyberry Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Restrict TUI MCP startup notifications to owned threads

Why

MCP startup notifications from unrelated threads could create TUI event channels, allowing subsequent approval requests from those threads to appear in the current session.

What changed

Check the parent of an untracked subagent before accepting its MCP startup notifications. Read thread metadata with bounded retries for threads that are not yet found or loaded, and ignore notifications unless the parent belongs to the TUI.

Share thread ownership checks across notification and approval routing, including side threads.

Testing

Extend approval-routing coverage to verify that owned subagent approvals are preserved both before thread-start notifications and after MCP startup notifications, while unrelated threads do not create event channels or display approval prompts.

## Why

MCP startup notifications from unrelated threads could create TUI event channels, allowing subsequent approval requests from those threads to appear in the current session.

## What changed

Check the parent of an untracked subagent before accepting its MCP startup notifications. Read thread metadata with bounded retries for threads that are not yet found or loaded, and ignore notifications unless the parent belongs to the TUI.

Share thread ownership checks across notification and approval routing, including side threads.

## Testing

Extend approval-routing coverage to verify that owned subagent approvals are preserved both before thread-start notifications and after MCP startup notifications, while unrelated threads do not create event channels or display approval prompts.

GitOrigin-RevId: 6f78f237f7441aadf10b491ed191357df75c3a6a
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/6f78f237f7441aadf10b491ed191357df75c3a6a branch from b9617b5 to f365d57 Compare October 4, 2026 03:52
@copyberry
copyberry Bot merged commit f365d57 into main Oct 4, 2026
13 of 19 checks passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/6f78f237f7441aadf10b491ed191357df75c3a6a branch October 4, 2026 03:52
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 4, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant