You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit a984839
Browse filesBrowse the repository at this point in the historyBrowse files
Resolves the four genuinely-OPEN fork-affected upstream items from
docs/upstream-tracking/2026-05-20-open-vs-fixed-matrix.md (handoff B2).
- openai#59 FIXED — state cross-read/write. Manual port of upstream PR openai#125.
`resolveStateDir` now migrates state written to the tmpdir fallback (a
`/codex:*` Bash command run without CLAUDE_PLUGIN_DATA) into the
persistent plugin-data dir when CLAUDE_PLUGIN_DATA is set, rewriting
absolute path references in state.json + jobs/*.json. Previously the two
contexts saw different state dirs and jobs appeared lost across them.
Adds a migration test; also wraps the tmpdir-fallback test with a
CLAUDE_PLUGIN_DATA guard (fixes the TROUBLESHOOTING #14 local flakiness).
- openai#113 FIXED (docs) — commands/setup.md gains Windows install error
handling: a garbled/mojibake `npm install` stderr on a non-UTF-8 console
must not be reported as failure; the setup rerun is the source of truth.
- openai#238 FIXED (docs) — README FAQ explains the nine `disable-model-invocation`
commands (why the assistant cannot auto-invoke them) and the workaround
(run them yourself, or use `/codex:rescue` for assistant-driven work).
- openai#75 DOCUMENTED — a full host-permission ↔ Codex-approval bridge is a
size-L design change; TROUBLESHOOTING #15 now documents the limitation
(host `.claude/settings.json` deny rules are separate from the plugin's
Codex approval system) so users govern Codex via `--sandbox` / approvals.
Also updates the open-vs-fixed matrix (11 FIXED / 1 DOCUMENTED / 1 PARTIAL
/ 0 OPEN) and handoff ultraplan §5 B2.
Verified: full suite 332 tests green (clean env, openai#59 state change no regression).
Copy file name to clipboardExpand all lines: README.md
+12Lines changed: 12 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -445,3 +445,15 @@ Yes. If you already use Codex, the plugin picks up the same [configuration](#com
445
445
Yes. Because the plugin uses your local Codex CLI, your existing sign-in method and config still apply.
446
446
447
447
If you need to point the built-in OpenAI provider at a different endpoint, set `openai_base_url` in your [Codex config](https://developers.openai.com/codex/config-advanced/#config-and-state-locations).
448
+
449
+
### Why can't Claude run `/codex:status` (or `/codex:review`, `/codex:cancel`, …) on its own?
450
+
451
+
Nine commands — `/codex:review`, `/codex:adversarial-review`, `/codex:agent`, `/codex:continue`, `/codex:status`, `/codex:result`, `/codex:cancel`, `/codex:approve`, `/codex:deny` — are marked `disable-model-invocation: true`. Claude Code's harness will not let the assistant auto-invoke them mid-reasoning; **only you (the human) can type them**.
452
+
453
+
This is deliberate: these commands start or steer Codex runs (which cost tokens), mutate job state, or gate session-end review. Letting the assistant fire them autonomously could burn budget or take side-effecting actions without your explicit intent.
454
+
455
+
What this means in practice:
456
+
457
+
- To act on a Codex job, **run the command yourself** (e.g. type `/codex:status`), then ask Claude — it can read the printed output and reason about it.
458
+
- For work you *do* want Claude to drive autonomously, use **`/codex:rescue`** — it is model-invocable (it delegates through the `codex:codex-rescue` subagent via the Agent tool) and is the intended entry point for assistant-driven Codex delegation.
459
+
- There is no flag to flip this per-session; the policy is set in each command's frontmatter by design.
Copy file name to clipboardExpand all lines: docs/TROUBLESHOOTING.md
+37-1Lines changed: 37 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,6 +23,7 @@ For BREAKING changes from v1.x, see [MIGRATION_v2.0.md](MIGRATION_v2.0.md) first
23
23
| Plugin sessions burying real chats in Codex Desktop |[#11 Codex Desktop history pollution](#11-codex-desktop-history-pollution)|
24
24
|`/codex:setup` reports `loggedIn: false` even though `codex login` succeeded |[#12 Plugin loggedIn false after codex login (v2.0.0 home isolation)](#12-plugin-says-loggedin-false-after-a-successful-codex-login-v200-home-isolation)|
25
25
|`node --test` fails ~5 tests locally that pass in CI |[#14 Local test failures inside a Claude Code session](#14-local-node---test-fails-5-tests-inside-a-claude-code-session)|
26
+
| Host `.claude/settings.json` deny rule does not block a Codex action |[#15 Codex approvals separate from host deny rules](#15-codex-approvals-are-separate-from-host-claudesettingsjson-deny-rules-75)|
26
27
27
28
---
28
29
@@ -491,6 +492,41 @@ failure is a real defect or this interference.
491
492
492
493
---
493
494
495
+
## 15. Codex approvals are separate from host `.claude/settings.json` deny rules (#75)
496
+
497
+
**Symptom**: You added a `permissions.deny` rule (or an `Edit`/`Bash` deny
498
+
pattern) to your project or user `.claude/settings.json`, expecting it to
499
+
also block the matching action when Codex runs it through this plugin — but
500
+
Codex still performs (or still prompts for) that action.
501
+
502
+
**Cause**: this is a **known design limitation**, not a bug. The plugin runs
503
+
Codex as a local subprocess with its **own** approval system
504
+
(`plugins/codex/scripts/lib/approvals.mjs`): a hard-deny ruleset plus the
505
+
interactive `/codex:approve` / `/codex:deny` flow, scoped by the Codex
506
+
`--sandbox` / `--approval` settings. That system is **not bridged** to Claude
507
+
Code's host `.claude/settings.json``permissions.deny` rules. The two
508
+
permission models are independent:
509
+
510
+
- A command/path you denied for **Claude** is *not* automatically denied for
511
+
**Codex** tool calls.
512
+
- The plugin's own hard-deny rules (e.g. broad recursive deletes) and
513
+
workspace-scoped path grants apply to Codex regardless of host settings.
514
+
515
+
**What to do**: do not treat host `.claude/settings.json` deny rules as a
516
+
safety boundary for Codex subprocess actions. Govern Codex instead with:
517
+
518
+
- the `--sandbox` setting (`read-only` / `workspace-write` /
519
+
`danger-full-access`) — the primary blast-radius control;
520
+
- the `--approval` mode and the `/codex:approve` / `/codex:deny` prompts —
521
+
review each approval request rather than auto-approving;
522
+
- the plugin's hard-deny rules for outright-dangerous operations.
523
+
524
+
A full host-permission ↔ Codex-approval bridge is a sizable design change
525
+
tracked as upstream issue #75 and fork backlog item B2; until it lands, the
526
+
two systems remain separate by design.
527
+
528
+
---
529
+
494
530
Known investigations in progress (not yet fixed in v2.0.0, no plugin-side mitigation yet):
495
531
496
532
-#295`CreateProcessAsUserW failed: 1920` on Windows + sandbox=elevated
@@ -501,7 +537,7 @@ Known investigations in progress (not yet fixed in v2.0.0, no plugin-side mitiga
501
537
502
538
## A. Diagnostic data to gather for the spike-grade open issues
503
539
504
-
Sections #1-#14 ship plugin-side fixes / mitigations. The remaining items in the "Known investigations" list are **spike-grade** — root cause is in the OS layer, the codex CLI, or an upstream protocol, and the fix needs a dedicated investigation we have not yet been able to run. While that work is pending, the most useful thing a reporter can do is capture diagnostic data the next investigation can replay against. This section enumerates what to capture per issue so the eventual fix lands faster.
540
+
Sections #1-#15 ship plugin-side fixes / mitigations / documented limitations. The remaining items in the "Known investigations" list are **spike-grade** — root cause is in the OS layer, the codex CLI, or an upstream protocol, and the fix needs a dedicated investigation we have not yet been able to run. While that work is pending, the most useful thing a reporter can do is capture diagnostic data the next investigation can replay against. This section enumerates what to capture per issue so the eventual fix lands faster.
505
541
506
542
### #295 — Windows `CreateProcessAsUserW failed: 1920`
Copy file name to clipboardExpand all lines: docs/ultraplan/2026-05-20-codex-plugin-cc-handoff-ultraplan.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -134,7 +134,7 @@ codex-plugin-cc/
134
134
| ID | 항목 | 상태 | 비고 / 의도된 종료상태 |
135
135
|---|---|---|---|
136
136
| B1 | upstream Tier 2 (13 MEDIUM) **평가 + cherry-pick/수동포트**| deferred | scope/policy 검토 필요. 각 건을 cherry-pick vs 수동포트 vs 기각으로 판정 후 진행 |
137
-
| B2 | fork-affected 실제 OPEN: **#59** state cross-rw, **#75**permission-deny bridge, **#113** install stderr decode, **#238** disable-model-invocation docs | deferred |`docs/upstream-tracking/2026-05-20-open-vs-fixed-matrix.md` 로 재검증 완료 — `#23 ANSI` 는 이미 FIXED(목록 제거), `#250` 은 PARTIAL(per-turn watchdog 가 상위 bound). 진짜 OPEN 은 이 4건만|
| B3 | codex-plugin-cc `/code-review` LOW 미해결 | open | (a) `invalidateTaskSession` — wire 하거나 제거 (현재 half-wired, **먼저 조사 후 결정**) (b) 신규 코드 테스트 추가 — auto capsule key·path-containment·secret-refusal 케이스 (동작은 이미 존재, 테스트만 부재) — `docs/code-review/2026-05-19-184449.md`|
| B5 | 운영-모델 UltraPlan 2건 구현 | plan 존재, 미착수 | ① `2026-05-18-...token-efficiency` — Codex 호출 토큰 효율화 ② `2026-05-20-...competitive-pair` — Claude×Codex 경쟁 페어 운영 모델 (7-PR 로드맵 내장). 둘 다 L+ 규모, 사용자 우선순위 결정 필요 |
Copy file name to clipboardExpand all lines: docs/upstream-tracking/2026-05-20-open-vs-fixed-matrix.md
+10-10Lines changed: 10 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,18 +16,18 @@
16
16
| (A1) | approval-loop unbounded hang |**FIXED**| 본 세션 — `waitForApprovalDecision` timeout (`CODEX_PLUGIN_APPROVAL_WAIT_MS`, 기본 30 min) |
17
17
| (A3) | broker teardown zombie |**FIXED**| 본 세션 — `teardownBrokerSession` 기본 `terminateProcessTree` killer |
18
18
|#250| per-tool timeout |**PARTIAL**| 전용 per-tool timeout 없음 (`codex.mjs` grep 0). 단 #312 per-turn watchdog(A2 기본 on) + finalizing-phase 5 min bound 이 silent-tool hang 을 상위에서 bound — per-tool 세분화는 미구현 |
19
-
|#59| state cross-read/write |**OPEN**|`state.mjs` 는 `CLAUDE_PLUGIN_DATA`/temp fallback 만, 워크스페이스 간 cross-read/write 없음|
20
-
|#75| permission-deny bridge |**OPEN**|`approvals.mjs` 의 approval 이 host `.claude/settings.json` deny rule 과 분리 — 별도 권한 시스템. bridge 또는 limitation 명시 필요|
21
-
|#113| install stderr decode |**OPEN**|`commands/setup.md` 에 install stderr decode 처리 부재|
22
-
|#238| disable-model-invocation 문서 |**OPEN (docs)**|feature 자체는 9개 커맨드에 적용됨. 미흡한 것은 README 의 workaround 설명 — 코드 아닌 docs 갭|
19
+
|#59| state cross-read/write |**FIXED**|upstream PR #125 manual port — `resolveStateDir` 가 tmpdir fallback state 를 plugin-data dir 로 자동 migrate + JSON 경로 rewrite. `state.test.mjs` 에 migration 테스트 추가|
20
+
|#75| permission-deny bridge |**DOCUMENTED**|full bridge 는 size-L design. matrix 가 제시한 "limitation 명시" 채택 — `TROUBLESHOOTING.md`#15 에 host `.claude/settings.json` deny ↔ Codex approval 분리를 명문화. bridge 구현은 백로그 잔존|
21
+
|#113| install stderr decode |**FIXED (docs)**|`commands/setup.md` 에 Windows mojibake install stderr 처리 추가 — garbled stderr 를 실패로 오판 말고 rerun 을 SoT 로|
22
+
|#238| disable-model-invocation 문서 |**FIXED (docs)**|`README.md` FAQ 에 9개 `disable-model-invocation` 커맨드 설명 + workaround(`/codex:rescue`) 추가|
23
23
24
24
## 요약
25
25
26
-
-**FIXED (8)**: #312·#190·#289·#290·#314·#24/#311/#23 + A1 + A3 — handoff §5 B2 가 deferred 로 나열한 `#23 ANSI`·env sanitization·git `--end-of-options`·UTF-8 truncation 은 **이미 해결됨**. B2 목록에서 제거 대상.
0 commit comments