* feat(ui): select Ultrafast for supported accounts
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(gateway): preserve Ultrafast compatibility and account authority
Negotiate speed decoding per connection and keep canonical session state intact. Fence personal-account catalog requests at final guarded HTTP dispatch. Refresh the measured UI boot manifest without changing performance limits.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* refactor(openai): keep account catalog outcomes together
Move the existing account-scoped result projection into the already imported catalog helper without changing its behavior. Keep the provider owner below its existing line-count ratchet.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test: refresh Ultrafast tool prompt fixtures
Regenerate the canonical Codex dynamic-tool fixtures for the authorized Ultrafast speed value. Update only that enum value and its derived size/hash metadata; keep snapshot checks enabled.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: stop account catalog requests after default unlink
Bind automatic account selections to the canonical profile writer's committed link authority and carry the real request scope through final guarded dispatch. Keep explicit retained account selections usable after unlink and evict failed discovery custody. Preserve the existing active Auto Ultrafast opt-in while explicit Fast stays priority.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* refactor(codex): use narrowed Auto activation flag
Keep the reviewed Auto tier predicate while satisfying the typed boolean lint contract.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): share speed applicability for optional Ultrafast
Respect the selected request mapping before offering an optional entitled tier. Preserve all three choices on eligible routes and clearable stored preferences on unsupported routes. Reproduced the contradictory catalog regression and passed 59 unit/Chromium cases; scoped independent review found no actionable P0/P1.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ci): export manifest in same-revision preflight harness
Restore the trusted file omitted when the inline manifest moved out of ci.yml in 9d75a8fe87. Actual preflight job109720001696 failed before tests with MODULE_NOT_FOUND; real Git push and PR materialization fixtures reproduce the same omission. Keep the canonical index export owner, regenerate its workflow projection, and preserve all source/credential guards. Fifteen materialization variants, five import/size checks, root test types, and focused independent review pass.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ci): satisfy extracted manifest static contracts
Repair inherited check-lint failures from the manifest extraction without changing CI routing: avoid namespace shadowing, retain error cause and the diagnostic callback string contract, preserve nonmutating shard copies, and apply required branch syntax. All1259 scripts lint clean;45 planner/import/size cases, formatting, UI i18n, styles, ratchet and independent review pass.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ci): centralize dependency-free workflow flag parsing
Remove the extracted manifest local coercion helper and preserve its exact narrow Boolean grammar under the existing script argument owner. Register the canonical declaration rather than weakening the guard, and carry its runtime through trusted preflight materialization and fixtures.77 argument cases,11 declaration-guard cases,71 scoped integration cases, types, lint, export scans and remaining guard commands pass; independent review has no actionable P0/P1.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(gateway): separate model publication authority from selection scope
Keep the actual request lifetime in selected-account HTTP assertions without treating every anonymous unscoped catalog read as a personal account projection. Restore the established models.list response shape; no assertions weakened.177 model/catalog/session cases and10physical HTTP authority cases pass, together with types, lint, ratchet and independent review.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: preserve session response argument tuples
Forward the original response tuple while projecting successful legacy payloads, without appending optional undefined arguments.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(codex): preserve existing Ultrafast opt-ins
Keep the v2026.9.7 Fast and active Auto opt-in semantics while adding explicit per-session Ultrafast. Standard still clears the tier. Cover cold and warm native turn requests without requiring a migration.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(ui): distinguish speed labels from model names
Match the complete Effort and Speed section labels rather than the Speed only fixture model. Retain the independent absence assertions for reasoning and speed controls. All four failures reproduced before the repair; the complete 13-case bundled browser file passes afterward.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(openai): intercept the shared transcription socket
Update the two stale socket mock registrations after the upstream transport consolidation. Keep the actual provider/session code, fake peers, assertions, timeouts, and Bun transport guard unchanged. All 86 OpenAI shard files pass: 1263 passed and one existing skip.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(gateway): construct complete session reset callers
Replace partial caller objects cast as never with the existing typed session mutation client fixture. Preserve provenance and required-sandbox assertions and the production client capability contract. Both CI failures reproduce before the repair; all 15 reset-model cases pass afterward.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: confirm the selected Ultrafast command mode
Share the direct command, directive reply, and system-event confirmation formatter so the saved Ultrafast tier is named accurately. Include the accepted manual value in help and docs without advertising an unverified optional native-menu choice. Preserve boolean Fast, Auto, reset, authorization and persistence behavior. Three regressions fail before repair; 274 focused cases pass afterward.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
---------
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
18 KiB
| summary | read_when | title | sidebarTitle | |||
|---|---|---|---|---|---|---|
| Top-level and appServer config fields for the Codex plugin |
|
Codex plugin config fields | Config fields |
Supported plugins.entries.codex.config fields and their defaults. Part of the Codex harness guide; Where each section moved lists every section.
Config fields
Supported top-level Codex plugin fields:
| Field | Default | Meaning |
|---|---|---|
codexDynamicToolsLoading |
"searchable" |
Use "direct" to put OpenClaw dynamic tools directly in the initial Codex tool context. |
codexDynamicToolsExclude |
[] |
Additional OpenClaw dynamic tool names to omit from Codex app-server turns. |
codexPlugins |
disabled | Native Codex plugin/app support for migrated source-installed curated plugins. |
sessionCatalog |
enabled | Sidebar discovery for native Codex sessions on this Gateway and eligible paired nodes. |
supervision |
disabled | Agent-facing native-session transcript and write-control policy. |
Supported appServer fields:
| Field | Default | Meaning |
|---|---|---|
transport |
"stdio" |
"stdio" spawns Codex; explicit "unix" connects to the local control socket; "websocket" connects to url. |
homeScope |
"agent" |
"agent" isolates ordinary harness state per OpenClaw agent. "user" is an explicit opt-in that shares the native $CODEX_HOME or ~/.codex, uses native auth, and enables owner-only thread management. User scope supports local stdio or Unix transport. For the separate supervision connection, an unset value resolves to "user" for stdio or Unix and "agent" for WebSocket. |
command |
managed Codex binary | Executable for stdio transport. Leave unset to use the managed binary; set it only for an explicit override. |
args |
["app-server", "--listen", "stdio://"] |
Arguments for stdio transport. |
url |
unset | WebSocket App Server URL or unix:// URL. An empty explicit Unix path selects the canonical user-home control socket. |
authToken |
unset | Bearer token for WebSocket transport. Accepts a literal string or SecretInput such as ${CODEX_APP_SERVER_TOKEN}. |
headers |
{} |
Extra WebSocket headers. Header values accept literal strings or SecretInput values, for example x-codex-client-session-token: "${CODEX_CLIENT_SESSION_TOKEN}". |
clearEnv |
[] |
Extra environment variable names removed from the spawned stdio app-server process after OpenClaw builds its inherited environment. OpenClaw keeps the selected CODEX_HOME and inherited HOME for local launches. |
codeModeOnly |
false |
Opt into Codex's code-mode-only tool surface. Ordinary OpenClaw dynamic tools remain available through nested tools.* calls; openclaw_direct tools stay directly model-visible. |
remoteWorkspaceRoot |
unset | Remote Codex app-server workspace root. OpenClaw maps the local cwd into this root and transfers authoritative remote attachments over an output-capped, no-shell command/exec reader. Paths escaping either workspace, symbolic links, oversized files, and unbounded attachment batches fail closed; uploads retain the configured channel identity and app-server request timeout. |
requestTimeoutMs |
60000 |
Timeout for app-server control-plane calls. |
mode |
"yolo" unless local Codex requirements disallow YOLO |
Preset for YOLO or guardian-reviewed execution. Local stdio requirements that omit danger-full-access, never approval, or the user reviewer make the implicit default guardian. |
approvalPolicy |
"never" or an allowed guardian approval policy |
Native Codex approval policy sent to thread start/resume/turn. Guardian defaults prefer "on-request" when allowed. |
sandbox |
"danger-full-access" or an allowed guardian sandbox |
Native Codex sandbox mode sent to thread start/resume. Guardian defaults prefer "workspace-write" when allowed, otherwise "read-only". When an OpenClaw sandbox is active, danger-full-access turns use Codex workspace-write with network access derived from the OpenClaw sandbox egress setting. |
approvalsReviewer |
"user" or an allowed guardian reviewer |
Use "auto_review" to let Codex review native approval prompts when allowed, otherwise guardian_subagent or user. guardian_subagent remains a legacy alias. |
serviceTier |
unset | Native Codex app-server preference only. Any non-empty string passes through for forward compatibility; documented values are "priority" and "flex". null clears the override, and legacy "fast" normalizes to "priority". This is neither the shared Fast-mode setting nor a direct embedded OpenAI setting. A shared Fast run control supersedes it with priority or null, or decides per model call in auto mode. |
enableUltrafast |
false |
Prefer ultrafast when the shared Fast-mode control is on, active Auto, or unspecified, and the authenticated app-server catalog advertises it for the selected native model. Standard remains off. Existing opted-in Fast sessions retain this behavior. Unsupported models and unavailable catalogs keep the baseline tier. |
cyberFailover |
automatic Daybreak Blue escalation | Controls the automatic retry after an OpenAI cyber-policy refusal. mode ("auto" default, or "off") enables it, model (default "gpt-daybreak-blue-latest") is the escalation target, and cooloffMs (default 600000) bounds the session window that follows an attempt. Escalation retries a refused turn once, never changes the stored model selection, and treats an unauthorized target as unavailable rather than retrying it. See Runtime behavior. |
networkProxy |
disabled | Opt into Codex permissions-profile networking for app-server commands. OpenClaw defines the selected permissions.<profile>.network config and selects it with default_permissions instead of sending sandbox. |
experimental.sandboxExecServer |
false |
Preview opt-in that registers an OpenClaw sandbox-backed Codex environment with the supported Codex app-server so native Codex execution can run inside the active OpenClaw sandbox. |
appServer.networkProxy is explicit because it changes the Codex sandbox
contract. When enabled, OpenClaw also sets features.network_proxy.enabled
and default_permissions in the Codex thread config so the generated
permission profile can start Codex managed networking. By default, OpenClaw
generates a collision-resistant openclaw-network-<fingerprint> profile
name from the profile body; use profileName only when a stable local name
is required.
{
plugins: {
entries: {
codex: {
config: {
appServer: {
approvalPolicy: "never",
sandbox: "workspace-write",
networkProxy: {
enabled: true,
domains: {
"api.openai.com": "allow",
"blocked.example.com": "deny",
},
unixSockets: {
"/tmp/proxy.sock": "allow",
"/tmp/blocked.sock": "none",
},
allowUpstreamProxy: true,
proxyUrl: "http://127.0.0.1:3128",
},
},
},
},
},
},
}
With enabled: true, domains uses Codex's native host matching. Hosts absent
from the effective native allowlist are denied unless the configured approval
policy permits an explicit exception. Set approvalPolicy: "never", as above,
to prevent approval-based exceptions. Native system requirements can contribute
allowed domains or select a managed allowlist, so this map does not replace the
system's network policy. Explicit denies in the effective policy take precedence
over overlapping allows and cannot be approved.
Use *.example.com for subdomains or **.example.com for both the apex domain
and subdomains. These restrictions apply to commands run through the Codex
sandbox. They do not restrict Gateway traffic, model-provider requests, or
unrelated MCP processes.
With networkProxy.enabled: true, invalid configuration fails with the rejected
field path, without logging configuration values. After a plugin update, saved
configuration with blank optional networkProxy.profileName or
remoteWorkspaceRoot values needs an explicit openclaw doctor --fix before
Codex can run. Doctor removes those blank values while keeping the domain policy.
Fix other invalid fields manually before retrying. Valid configurations need no
repair.
If the normal app-server runtime would be danger-full-access, enabling
networkProxy uses workspace-style filesystem access for the generated
permission profile: Codex managed network enforcement is sandboxed
networking, so a full-access profile would not protect outbound traffic.
Domain entries use allow or deny. Unix socket entries use allow or none;
OpenClaw translates none to Codex's native deny permission.