Skip to content

chore(codex): bump Codex CLI to 0.155.0 - #14052

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
backryun:chore/codex-0.155.0
Sep 22, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
backryun:chore/codex-0.155.0

Conversation

@backryun

@backryun backryun commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Bump the emulated Codex client fingerprint to the current @openai/codex release, in one lockstep change:

  • src/shared/constants/codexClient.ts — DEFAULT_CODEX_CLIENT_VERSION 0.153.4 → 0.155.0
  • Dockerfile — image install @openai/codex@0.155.0, kept in lockstep with the header fingerprint
  • .env.example, docs/reference/ENVIRONMENT.md, docs/security/STEALTH_GUIDE.md — documented defaults/overrides
  • tests/snapshots/provider/translate-path.json, tests/unit/executor-codex.test.ts — golden and header assertions

Split out of #12759 as requested in review: the catalog PR should not carry the client pin. Dropping the commit there left the pin at the deliberate #13026 value; this PR moves that pin forward in one coordinated bump instead, so the fingerprint OpenAI sees from the OAuth/Responses face matches the real client version installed in the image.

Supersedes #13815 — same content, branch renamed to chore/codex-0.155.0 so the PR reflects the current pin.

Validation

  • node --import tsx/esm --test tests/unit/executor-codex.test.ts tests/unit/provider-translate-path-golden.test.ts — 50/50
  • @openai/codex@0.155.0 is the current npm latest (0.156.0-alpha.1 is still a pre-release).
  • Live Codex OAuth smoke passed on this revision (0.155.0) — all seven gated gpt-6-astra tiers (low/medium/high/xhigh/max/ultra + base) returned 200 through the ChatGPT/Codex backend; details and timings in the smoke comment below.
  • The earlier 0.154.0 revision of this bump also passed a wider 33-model run (32×200; the single 400 was gpt-5.3-codex-spark, which upstream refuses for ChatGPT-account Codex regardless of client version).
  • check:env-doc-sync is currently red on the clean tip for unrelated vars (OMNIROUTE_STRIP_SYSTEM_PREAMBLE, COMBO_LOOP_SAFETY_TIMEOUT_MS); nothing in this PR touches that contract.

@backryun

Copy link
Copy Markdown
Contributor Author

0.155.0 live smoke — passed

Server built from this branch (DEFAULT_CODEX_CLIENT_VERSION = "0.155.0", no CODEX_CLIENT_VERSION override), single Codex OAuth connection. All seven gated GPT-6 Astra tiers requested back-to-back:

model status duration
gpt-6-astra 200 3.16s
gpt-6-astra-low 200 1.68s
gpt-6-astra-medium 200 2.26s
gpt-6-astra-high 200 1.73s
gpt-6-astra-xhigh 200 3.38s
gpt-6-astra-max 200 4.00s
gpt-6-astra-ultra 200 5.20s

No requires a newer version of Codex gate and zero errors in the run — this replaces the earlier 0.154.0 evidence with the current revision of the bump.

@backryun

Copy link
Copy Markdown
Contributor Author

@diegosouzapw — fresh split-out of the Codex client pin (branch renamed from #13815; 0.155.0 is the current npm latest). Live smoke passed on this revision: all seven gated gpt-6-astra tiers returned 200 (details above). Ready for review when you have a moment.

@backryun
backryun force-pushed the chore/codex-0.155.0 branch 14 times, most recently from 20cedd7 to 0f2882e Compare September 19, 2026 06:26
fenix007 pushed a commit to fenix007/OmniRoute that referenced this pull request Sep 21, 2026
Adapt upstream PR diegosouzapw#14052 at 0f2882e
to the frozen v3.8.48 helper and identity profile. Pin the existing optional
Docker CLI package and align catalog/header regressions and documentation.
Preserve validated environment overrides and account header precedence.

Extend combo integration coverage for default failover-first and explicit
retry-first behavior. Make the existing DeepInfra catalog fallback test
independent of live network timing, retaining its catalog assertions.

Upstream contribution: backryun (diegosouzapw#14052).
Co-Authored-By: GPT-6 <noreply@openai.com>
Keep the emulated client fingerprint in lockstep with the CLI pinned in the Dockerfile: shared client constant, .env.example overrides, provider translate-path golden, executor header assertions, the caller-version fallback assertions from diegosouzapw#13708, and the live env/stealth docs.
@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks @backryun — merging via the release merge-train. Validated in local merge-train (mt-train10c) on the devbox @ train tip 4d841aa1c740bbaa03868dc0a403c62099a99a42 with the 72 sibling PRs of this batch: typecheck:core, file-size, complexity, cognitive-complexity, changelog-integrity green; changed-area node:test 831/831 (0 failing) and vitest 480/482 — the two reds are autoCombo/provider-family-combos.test.ts timing out at 20s, which reproduces on the PURE release tip under the full vitest suite (and is already tracked by the Release-Green issue #13866), so it is inherited, not this batch's. Merged --admin per merge-gates §3/§4/§7.

@diegosouzapw
diegosouzapw merged commit 252d604 into diegosouzapw:release/v3.8.51 Sep 22, 2026
16 checks passed
@backryun
backryun deleted the chore/codex-0.155.0 branch September 22, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants