1
00:00:00,159 --> 00:00:04,539
Imagine you are three hours deep into a
major codebase refactor with Codex,

2
00:00:05,139 --> 00:00:09,860
everything is humming along smoothly, and
then, out of nowhere,

3
00:00:10,179 --> 00:00:11,260
the agent freezes.

4
00:00:11,960 --> 00:00:16,119
It asks you to re authorize a shell
command you already approved two hours ago.

5
00:00:16,486 --> 00:00:17,407
Uh, yeah!

6
00:00:18,066 --> 00:00:23,107
That was the exact headache in version
zero point one fifty two point zero.

7
00:00:23,726 --> 00:00:28,246
You would be right in the flow, and
suddenly it acts like it has total amnesia about

8
00:00:28,306 --> 00:00:29,507
your security permissions.

9
00:00:29,750 --> 00:00:31,110
It was so frustrating.

10
00:00:31,230 --> 00:00:35,670
And by the way, thanks to Jellypod to help
make this daily show a reality.

11
00:00:35,710 --> 00:00:37,590
But yeah, that bug was a sneaky one.

12
00:00:37,982 --> 00:00:39,282
So why was it doing that?

13
00:00:39,702 --> 00:00:43,722
Was it actually forgetting, or was
something happening under the hood when the

14
00:00:43,742 --> 00:00:45,002
conversation got too long?

15
00:00:45,333 --> 00:00:48,613
It comes down to context window
compaction.

16
00:00:48,645 --> 00:00:53,413
When your session hits a high token count,
Codex automatically compresses older

17
00:00:53,464 --> 00:00:56,613
transcript turns to make room for new
prompts.

18
00:00:56,773 --> 00:01:02,053
But in version zero point one fifty two,
Guardian security review evidence was

19
00:01:02,099 --> 00:01:04,533
stored right inside that active prompt
history.

20
00:01:04,882 --> 00:01:05,461
Oh!

21
00:01:06,221 --> 00:01:10,321
So when the system summarized those
earlier turns to reclaim tokens,

22
00:01:10,801 --> 00:01:14,301
it treated those Guardian authorization
markers like...

23
00:01:14,321 --> 00:01:16,621
well, like disposable chat text!

24
00:01:17,021 --> 00:01:18,962
It just summarized them away!

25
00:01:19,500 --> 00:01:20,220
Exactly.

26
00:01:20,320 --> 00:01:24,460
The context summarizer threw out the proof
that you approved the action.

27
00:01:24,673 --> 00:01:28,860
So the next time Codex tried to run a
sensitive terminal command,

28
00:01:28,913 --> 00:01:33,900
Guardian checked the active context, found
zero evidence of prior consent,

29
00:01:33,920 --> 00:01:37,500
and stalled your agent until you manually
clicked approve again.

30
00:01:37,819 --> 00:01:43,619
Which completely breaks headless scripts
and deep, multi hour refactoring runs!

31
00:01:44,139 --> 00:01:47,340
You think it is running in the background,
you come back to check on it,

32
00:01:47,460 --> 00:01:51,239
and it has been waiting on a prompt for
forty minutes.

33
00:01:51,787 --> 00:01:52,547
Precisely.

34
00:01:53,107 --> 00:01:58,927
But in Codex zero point one fifty three
point zero, pull requests forty one eight

35
00:01:58,967 --> 00:02:04,668
seventy nine and forty two zero sixty five
completely re architected this.

36
00:02:05,307 --> 00:02:10,607
The core fix is that Guardian review
history now survives context compaction,

37
00:02:11,267 --> 00:02:13,468
daemon restarts, and thread forks.

38
00:02:13,861 --> 00:02:17,581
Wait, how did they fix it without filling
up the prompt window again?

39
00:02:17,958 --> 00:02:23,238
They decoupled the security review
evidence from the active prompt window entirely.

40
00:02:23,291 --> 00:02:26,438
It now lives in a dedicated, persistent
review store.

41
00:02:26,705 --> 00:02:31,318
So even when the chat history gets
compressed down to a high level summary,

42
00:02:31,358 --> 00:02:35,318
the underlying security approvals remain
intact in the background store.

43
00:02:35,512 --> 00:02:37,012
Ah, that is huge!

44
00:02:37,372 --> 00:02:41,972
So you get the token savings from
compaction, but you do not suffer from security

45
00:02:42,052 --> 00:02:42,552
amnesia.

46
00:02:42,833 --> 00:02:43,633
Right.

47
00:02:43,690 --> 00:02:48,033
Grounding this in the official release
notes, Guardian review history survives

48
00:02:48,097 --> 00:02:54,193
compaction, restarts, and user created
forks while respecting rollback boundaries

49
00:02:54,313 --> 00:02:56,513
and isolating subagent history.

50
00:02:56,726 --> 00:03:01,793
It keeps your agent non blocking while
keeping safety thresholds just as strict as

51
00:03:01,862 --> 00:03:02,353
before.

52
00:03:02,712 --> 00:03:03,693
Okay, but wait.

53
00:03:04,092 --> 00:03:09,132
You just mentioned isolating subagent
history and respecting rollback boundaries.

54
00:03:09,872 --> 00:03:13,352
What does that mean in practice if I spawn
a subagent during a session?

55
00:03:13,890 --> 00:03:19,449
That is a crucial security boundary caveat
in pull request forty two zero sixty

56
00:03:19,469 --> 00:03:19,649
five.

57
00:03:20,549 --> 00:03:24,809
If you fork a main thread, your main
thread retains those Guardian approvals.

58
00:03:25,469 --> 00:03:30,549
But if Codex spawns a subagent to handle a
subtask, that subagent starts with a

59
00:03:30,609 --> 00:03:31,170
clean slate.

60
00:03:31,527 --> 00:03:34,688
It does not inherit the parent thread
approvals?

61
00:03:35,042 --> 00:03:35,362
Nope!

62
00:03:35,522 --> 00:03:40,002
It cannot inherit parent security
approvals across rollback boundaries.

63
00:03:40,222 --> 00:03:42,882
Subagents remain strictly isolated.

64
00:03:43,095 --> 00:03:48,962
So if a subagent wants to execute a
sensitive action, Guardian forces a fresh check

65
00:03:49,042 --> 00:03:51,442
rather than letting privileges leak
downward.

66
00:03:51,777 --> 00:03:54,977
That makes total sense from a defense in
depth perspective.

67
00:03:55,557 --> 00:04:01,177
You do not want a rogue or unconstrained
subagent inheriting elevated rights just

68
00:04:01,218 --> 00:04:02,517
because the main thread had them.

69
00:04:02,833 --> 00:04:03,993
Exactly.

70
00:04:04,063 --> 00:04:08,673
Now, speaking of automated workflows,
there is another key upgrade for headless

71
00:04:08,729 --> 00:04:12,993
pipelines in this release, pull request
forty two zero thirty nine.

72
00:04:13,379 --> 00:04:16,299
Oh, is that the one fixing codex exec
resume?

73
00:04:16,667 --> 00:04:17,147
Yes!

74
00:04:17,307 --> 00:04:23,707
If you were running automated CI CD tasks
using codex exec resume with the dir flag,

75
00:04:23,787 --> 00:04:29,627
compressed rollout histories used to cause
silent resume failures or crashes because

76
00:04:29,647 --> 00:04:33,307
the resume command did not know how to
parse the compacted files.

77
00:04:34,631 --> 00:04:40,232
Right, so your automated pipeline would
attempt to resume a long running job,

78
00:04:40,311 --> 00:04:43,531
hit a compressed log, and just throw its
hands up!

79
00:04:43,875 --> 00:04:44,355
Yep.

80
00:04:44,515 --> 00:04:49,635
Now it handles compressed rollouts
seamlessly when selecting by working directory.

81
00:04:49,763 --> 00:04:54,915
That makes headless CI CD task runs vastly
more reliable.

82
00:04:55,236 --> 00:05:00,116
And there were a couple of nice quality of
life configuration cleanups in zero point

83
00:05:00,196 --> 00:05:02,196
one fifty three point zero as well, right?

84
00:05:02,708 --> 00:05:04,628
Yeah, a couple of notable ones.

85
00:05:04,761 --> 00:05:10,708
First, pull request forty one nine seventy
six moved disable paste burst under the

86
00:05:10,788 --> 00:05:16,468
tui configuration block in dot codexrc,
cleaning up top level settings.

87
00:05:16,588 --> 00:05:22,468
And second, thread forks now properly
handle symlinked session roots on disk without

88
00:05:22,512 --> 00:05:23,988
breaking path resolution.

89
00:05:24,359 --> 00:05:29,619
So the main operational takeaway for dev
teams running long running Codex agents is

90
00:05:29,639 --> 00:05:35,019
simple: upgrade to zero point one fifty
three point zero, and your multi hour

91
00:05:35,119 --> 00:05:40,040
refactors will no longer stall on dropped
approvals, while your subagent boundaries

92
00:05:40,199 --> 00:05:41,500
stay completely secure.

93
00:05:41,792 --> 00:05:43,032
Spot on.

94
00:05:43,106 --> 00:05:46,912
Smooth, non blocking workflows without
cutting corners on safety.

95
00:05:47,072 --> 00:05:48,832
And that is it for today!

