openclaw/extensions/codex
Josh Lehman a9f675839a
feat(memory): resolve the memory audience in the host (#162176)
* feat(memory): resolve the memory audience in the host

Memory providers had to re-derive whether a caller acts for the agent
owner privately or for one conversation, walking spawn lineage through
session lookups.

When the memory slot owner registers providerRuntime, the host mints a
MemoryAudience (owner-private, or one exact conversation) from the
admitted turn entry and, for spawned children, the exact parent key,
session ID, lifecycle revision (or its recorded absence), and captured
owner bit of every hop. Memory Core and other legacy owners resolve no
audience: their turns take no session leases, read no lineage, and log
nothing new. Native, ACP, and realtime voice consult children record the trusted
spawning sender's owner status and parent incarnation so that lineage
survives session creation, reset, and rollover. The receipt stores the
parent session id as spawnedBySessionId, so navigation's parentSessionId
and sessions.list stay unchanged; a child of a parent without a lifecycle revision,
such as a channel-created group row, records that absence. Incomplete or
stale lineage yields no audience; only a spawned row without the owner
receipt predates the lineage receipts, and it logs a respawn
instruction. A parent without a stored row spawns as before. Spawn rechecks
a stored parent on the session read worker immediately before the child
commits. Parent rows are read on the session read worker, and every captured hop holds
a session generation lease, so currency checks stay synchronous and
read-free. Audiences are bound to their session, released when the
owning attempt or run ends, and delegated to same-agent children bound
to the child's current incarnation. The host checks currency before and
after opening a provider and around every provider call, and the guard
it passes to a provider includes audience currency. The memory slot
owner's own tools, Active Memory, and project recall also recheck it
before their effects; other plugin tools reach memory only through the
provider guard and do not fail on a stale audience.

Session authority, plugin tool contexts, hook contexts, and Codex
dynamic tools carry the audience. Native consumers cut over to it:
Active Memory trigger, deep, and summary recall (caches keyed by
audience; default deep-recall tools from the slot owner's
recallToolNames; trigger recall runs only while tool policy allows every
recall tool the provider declares), project recall, Memory Wiki,
post-compaction provider refresh, doctor memory status and recall/search
checks, and the status scan, which report provider health instead of
legacy index counters. Legacy owners keep their trigger-recall gate,
doctor and status ordering, and post-compaction sync without loading or
calling the slot plugin to decide.

* test(memory): consolidate memory audience tests

Fold the real session-owner audience test into the shared real-lineage
fixture, drop the spawn lineage unit test that the real-SQLite spawn tests
already cover, share spawn parameters, and remove cases that only mirrored
implementation (log text, mock passthrough, per-kind passthrough).

* test(talk): expect lineage receipts on consult children
2026-10-02 15:19:58 -07:00
..
assets
src feat(memory): resolve the memory audience in the host (#162176) 2026-10-02 15:19:58 -07:00
api.ts fix(doctor): Codex bwrap check misses loopback denials that break sandboxed shells (#161692) 2026-09-30 02:53:32 -07:00
auth-profile-health.test.ts
catalog-page-worker-entrypoint.ts
catalog-page.worker.ts
cli-metadata.test.ts
cli-metadata.ts
doctor-contract-api.cold.test.ts perf(codex): keep empty Doctor scans lightweight (#162215) 2026-09-30 19:41:09 -07:00
doctor-contract-api.native-assignments.test.ts refactor: remove Tasks and TaskFlow runtime (#159179) 2026-09-27 10:40:29 -07:00
doctor-contract-api.network-proxy.test.ts
doctor-contract-api.test.ts test(core,plugins,ui): remove low-value tests (batch d014) (#158714) 2026-09-26 16:11:01 +00:00
doctor-contract-api.ts refactor(codex): deslop Codex harness (#163707) 2026-10-02 11:44:55 -07:00
harness.cyber-failover.test.ts test(browser, codex, clickclack, quickjs): remove low-value tests (batch d054) (#159369) 2026-09-27 03:25:54 +00:00
harness.session-runtime-ownership.test.ts fix(test): session-store suites fail teardown with ENOTEMPTY while agent-database workers are live (#161871) 2026-10-01 17:10:24 +00:00
harness.test.ts fix(test): session-store suites fail teardown with ENOTEMPTY while agent-database workers are live (#161871) 2026-10-01 17:10:24 +00:00
harness.ts feat: use MCP plugin apps across conversations and workspace files (#161747) 2026-10-02 07:02:35 -05:00
index-services.test.ts test(browser, codex, clickclack, quickjs): remove low-value tests (batch d054) (#159369) 2026-09-27 03:25:54 +00:00
index.test.ts refactor(codex): deslop Codex harness (#163707) 2026-10-02 11:44:55 -07:00
index.ts refactor(providers): deslop provider glue (#162897) 2026-10-01 18:03:40 +00:00
media-understanding-provider.test.ts fix(test): remaining suites time out on their first test or hook while compiled worker subprocesses prepare (#163254) 2026-10-02 03:37:13 -05:00
media-understanding-provider.ts refactor(codex): deslop Codex plugin fifth pass (#159726) 2026-09-27 16:54:26 -07:00
migration-provider-api.ts
native-hook-test-api.ts fix: act for the person who asked when several people steer a turn (#160525) 2026-09-28 22:16:34 -07:00
native-tool-policy.ts
openclaw.plugin.json feat(codex): request Ultrafast by default when the catalog advertises it (#163320) 2026-10-02 06:53:00 +00:00
package.json fix(codex): update managed runtime to 0.160.0 (#163560) 2026-10-02 22:36:54 +07:00
provider-discovery.ts
README.md fix(codex): preserve payload keys and current inventory diagnostics (#162032) 2026-09-30 18:49:38 +00:00
registration-imports.test.ts
session-history-worker-runtime.ts
session-history.worker.ts
test-api.ts fix(codex): restore persona on remote app-server connections (#162156) 2026-09-30 16:05:21 -07:00
tsconfig.json
web-search-contract-api.ts

OpenClaw Codex

Official OpenClaw plugin for OpenAI Codex app-server integration. It exposes the Codex-managed GPT model catalog, the Codex runtime surfaces used by OpenClaw agents, and opt-in supervision of native Codex sessions.

Install from OpenClaw:

openclaw plugins install @openclaw/codex

Use this plugin when you want OpenClaw to run Codex-backed model turns, media understanding, and prompt overlays through the Codex app-server harness, or to browse non-archived Codex CLI, VS Code, Atlas, and ChatGPT sessions and paginated transcripts across paired computers.

Guided onboarding attempts to install and enable supervision after it detects a native Codex installation and the selected inference backend passes its live check; Codex does not need to be the primary backend. Supervision activates when that opportunistic plugin setup succeeds. App Server availability is checked when supervision connects. An explicit Codex plugin disable, plugin-policy block, or supervision.enabled: false prevents opportunistic enablement. Manual setups enable plugins.entries.codex.config.supervision.enabled. Without explicit App Server connection settings, supervision uses a managed user-home stdio connection; explicit appServer settings are honored.

The Gateway-backed operator CLI is:

openclaw codex sessions [--search <text>] [--host <id>] [--limit <count>] [--cursor <cursor>] [--json] [--url <url>] [--token <token>] [--timeout <ms>] [--expect-final]
openclaw codex continue <thread-id> [--json] [--url <url>] [--token <token>] [--timeout <ms>] [--expect-final]
openclaw codex archive <thread-id> --confirm-no-other-runner [--json] [--url <url>] [--token <token>] [--timeout <ms>] [--expect-final]

The catalog never includes archived threads and has no archived or include-archived option. Rows appear in the normal Control UI sessions sidebar and open in the normal Chat pane. Transcript history requires a recent Codex App Server with thread/turns/list and is fetched 20 full-item turns at a time through opaque cursors; OpenClaw does not fall back to an unbounded thread/read, and rejects a serialized transcript page above 20 MiB before transport. --limit defaults to 50 sessions per host, --cursor requires --host, and the sessions Gateway timeout defaults to 75,000 ms so cold paired-node catalogs can complete. Continue and archive retain the shared 30,000 ms default. All operator surfaces require operator.write. Paired-node rows can be listed and read; continue and archive operate only on the Gateway-local host, and archive requires the no-other-runner confirmation. Catalog registration does not require supervision.enabled; that setting gates agent-facing supervision tools.

Local discovery reads native provenance from plain or compressed rollouts. A failed read can fall back to the other representation and does not cache an unknown originator as a permanent unmanaged result.

With appServer.remoteWorkspaceRoot, OpenClaw maps workspace-relative paths to the remote root. Local filesystem-root workspaces, including / and Windows drive roots, follow the same mapping.

A supervised OpenClaw Chat cannot be deleted while its model-selection lock protects the native binding. Before native archive, OpenClaw checks the exact target and every non-archived spawned descendant reported by Codex; any active OpenClaw binding blocks the operation. Descendant pagination errors, cycles, and safety-limit exhaustion also fail closed. Codex still does not expose a conditional archive operation or cross-process runner lease, so the confirmation covers unknown native clients and the race between the status read and archive request.

Disabling or uninstalling the plugin leaves supervised Chats locked and unavailable rather than rerouting them. Reinstall or re-enable the same plugin and restart the Gateway to resume those Chats.

These shell commands differ from the in-chat /codex runtime commands. In particular, /codex sessions --host <node> lists Codex CLI session files on one node, /codex threads uses the current conversation's App Server connection, and /codex resume or /codex bind changes that conversation's binding. There is no /codex archive runtime command.

Native Codex plugin catalogs are discoverable with /codex plugins available, including repository marketplaces declared in .agents/plugins/marketplace.json in the bound workspace. An owner or operator.admin can install and authorize an exact plugin with /codex plugins install <plugin>@<marketplace>. The owner-scoped codex_plugins agent tool only reads marketplace metadata; installation and policy changes stay on authenticated /codex management commands. Explicitly installing a plugin trusts its skills, apps, MCP servers, and hooks.

Cached app inventory diagnostics reflect the current refresh or invalidation. Failures from superseded requests remain logged without replacing that newer status.

For a supervised branch, Codex App Server selects the snapshot fork's model and provider from its current native configuration. OpenClaw starts the canonical harness thread with exactly that returned pair. Codex persists the canonical thread's native selection, and later resumes preserve it because OpenClaw omits model and provider overrides. OpenClaw cannot substitute its outer runtime, model, or fallback. The returned initial pair can differ from the source's last recorded model.

The visible-history mirror keeps at most 200 user or assistant messages, 512 KiB total, and 64 KiB per message. Image inputs become [Image attachment]; image data and local paths are not copied.

When assembled context bootstraps a Codex thread, redacted tool payloads retain literal JSON field names. Tool inputs retain their shape; tool results retain redacted content.

Settled-turn finalization uses the same configured Codex App Server transport as the supervised conversation. Remote websocket App Server configurations stay on their configured transport. Managed user-home stdio launches running inside an Agent home, and not through the proxy launcher, use a private stdio side turn for native-tool isolation. The bounded finalizer preserves the selected model, provider, and native authorization returned by Codex, and rejects native tool evidence outside the finalization contract. It may mirror a final answer after completed tool work; it does not diagnose why a model omitted a visible final message.

When settled-turn recovery rejects history, the codex settled-turn finalization context capture failed warning includes a stable reason, such as item_limit, byte_limit, field_limit, unsupported_user_image, or snapshot_invalidated. Unknown failures use history_read_failed. The warning excludes transcript content and exception text. Rejected history remains unavailable for finalization, and completed actions are never replayed.

See the Codex harness and Codex supervision guides.