fix(codex): drop local_shell tool (no longer supported upstream) - #5250
diegosouzapw merged 2 commits into
Conversation
OpenAI removed the local_shell hosted tool type from the Responses API.
There was a problem hiding this comment.
Code Review
This pull request removes the local_shell tool from the Codex executor because OpenAI has deprecated and removed it from the Responses API. The changes ensure that local_shell is removed from the hosted tool types and that any tool_choice specifying local_shell is deleted before forwarding. A new unit test has been added to verify these changes. There are no review comments, so I have no feedback to provide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
…340→1347 Base-red inherited from diegosouzapw#5250 (codex local_shell drop), which added a regression test to executor-codex.test.ts but was merged with --admin so the frozen file-size baseline was never bumped. Syncing release/v3.8.40 into this PR surfaces the violation (1347 > frozen 1340). Reconcile the frozen cap to the current size so Fast Quality Gates is green. Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>
Integrated into release/v3.8.40 — shell tool kept caller-side in Chat→Responses translation (complements #5250).
…gosouzapw#5250) Integrated into release/v3.8.40 — codex local_shell drop validated (merge-result: eslint clean, 41/41 tests). FQG failure was stale base.
Integrated into release/v3.8.40 — shell tool kept caller-side in Chat→Responses translation (complements diegosouzapw#5250).
Summary
Drop the deprecated
local_shellhosted tool type from the Codex executor before forwarding requests to OpenAI's Responses API. This resolves the omni-combo400 "The local_shell tool is no longer supported."spike onPOST /v1/chat/completionsrouted through thecodexprovider.Context
OpenAI removed the
local_shellhosted tool type from the Responses API. When Codex CLI injects{ type: "local_shell" }intobody.tools(or setsbody.tool_choice = { type: "local_shell" }), OpenAI's Responses API now returns400with the error message:The Codex executor in OmniRoute whitelists a set of hosted tool types in
CODEX_HOSTED_TOOL_TYPES(file:open-sse/executors/codex.ts:399) so that thenormalizeCodexToolspreprocessor preserves them instead of stripping them. The set previously includedlocal_shell. Becauselocal_shellwas whitelisted, the executor forwarded the now-rejected type unchanged and the request 400'd.There is already a precedent in this file for handling tools that are in the whitelist but no longer accepted by upstream —
#2980adds adropImageGenerationoption for free-plan accounts that can't runimage_generation. The cleanest, least-invasive fix is to removelocal_shellfrom the whitelist entirely (it is rejected regardless of account plan) and add a defensive branch in thetool_choicecleanup so alocal_shellrequest-level tool choice is dropped instead of forwarded.Changes
open-sse/executors/codex.ts"local_shell"from theCODEX_HOSTED_TOOL_TYPESset.normalizeCodexToolswill now route it to the existingconsole.debug("dropping unknown hosted tool type: ...")branch and filter it frombody.toolsbefore the request reaches OpenAI.toolChoice.type === "local_shell"branch innormalizeCodexToolsthat deletesbody.tool_choice, mirroring the existing handling of staletool_choice = { type: "function", name: <unknown> }.local_shellis intentionally absent so future contributors don't accidentally re-add it.tests/unit/executor-codex.test.tsCodexExecutor.transformRequest drops Codex local_shell tool (no longer supported upstream)that asserts both:body.toolsentries withtype: "local_shell"are dropped while sibling tools are preserved.body.tool_choice = { type: "local_shell" }is dropped rather than forwarded.Key Implementation Details
dropImageGenerationpattern (#2980) but does not introduce a new option/flag —local_shellis universally rejected by upstream, so there is no per-account gating needed.console.debugbranch innormalizeCodexTools([Codex] dropping unknown hosted tool type: local_shell) gives operators visibility when the fix is exercised.OmniRoute-clean's pre-commit hooks (prettier, eslint, docs-sync,check:any-budget:t11,check-tracked-artifacts) all pass on the commit.Use Cases
/v1/chat/completionsrouting through thecodexexecutor that currently fails with400whenever Codex CLI is on the request path. Before this fix, most codex calls were failing (per the observed metrics); after this fix, they succeed.codex/gpt-5.4-miniand other Codex-CLI-spawned requests that automatically injectlocal_shell.Testing
The change was developed and validated against
OmniRoute-fresh2(which has the same executor), then cherry-picked cleanly ontoOmniRoute-cleanat theRelease v3.8.34base so the PR diff is minimal.Expected output:
To smoke-test end-to-end against a live Codex account, send any request that would have Codex CLI inject
local_shell(e.g. a tool-using prompt through Codex CLI routed viaomni-combo/ codex combo) and verify it returns200instead of400.Links
{ type: "local_shell" }into every Responses request regardless of plan; OpenAI has removed it from the Responses API and now 400s on it.dropImageGenerationpattern introduced in#2980forimage_generationon free-plan Codex accounts.