SaylorTwift HF Staff commited on
Commit
aada7ee
·
verified ·
1 Parent(s): 3b400a0

Add files using upload-large-folder tool

Browse files
.bazelignore ADDED
@@ -0,0 +1,4 @@
 
 
 
 
 
1
+ # Without this, Bazel will consider BUILD.bazel files in
2
+ # .git/sl/origbackups (which can be populated by Sapling SCM).
3
+ .git
4
+ codex-rs/target
.bazelrc ADDED
@@ -0,0 +1,229 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ common --repo_env=BAZEL_DO_NOT_DETECT_CPP_TOOLCHAIN=1
2
+ common --repo_env=BAZEL_NO_APPLE_CPP_TOOLCHAIN=1
3
+ # Dummy xcode config so we don't need to build xcode_locator in repo rule.
4
+ common --xcode_version_config=//:disable_xcode
5
+
6
+ common --disk_cache=~/.cache/bazel-disk-cache
7
+ common --repo_contents_cache=~/.cache/bazel-repo-contents-cache
8
+ common --repository_cache=~/.cache/bazel-repo-cache
9
+ common --remote_cache_compression
10
+ startup --experimental_remote_repo_contents_cache
11
+
12
+ common --experimental_platform_in_output_dir
13
+
14
+ build --workspace_status_command=./scripts/workspace-status.sh
15
+ build:windows --workspace_status_command=./scripts/workspace-status.cmd
16
+
17
+ # Runfiles strategy rationale: codex-rs/utils/cargo-bin/README.md
18
+ common --noenable_runfiles
19
+
20
+ common --enable_platform_specific_config
21
+ common:linux --host_platform=//:local_linux
22
+ common:windows --host_platform=//:local_windows
23
+ common --@rules_cc//cc/toolchains/args/archiver_flags:use_libtool_on_macos=False
24
+ common --@llvm//config:experimental_stub_libgcc_s
25
+
26
+ # TODO(zbarsky): rules_rust doesn't implement this flag properly with remote exec...
27
+ # common --@rules_rust//rust/settings:pipelined_compilation
28
+
29
+ common --incompatible_strict_action_env
30
+ # Not ideal, but We need to allow dotslash to be found
31
+ common:linux --test_env=PATH=/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin
32
+ common:macos --test_env=PATH=/opt/homebrew/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin
33
+ # Native pkg-config configure checks execute target programs.
34
+ common:macos --strategy=CcConfigureMakeRule=remote,sandboxed,local
35
+
36
+ # Pass through some env vars Windows needs to use powershell?
37
+ common:windows --test_env=SYSTEMROOT
38
+ common:windows --test_env=COMSPEC
39
+ common:windows --test_env=WINDIR
40
+ # Rust's libtest harness runs test bodies on std-spawned threads. The default
41
+ # 2 MiB stack can be too small for large async test futures on Windows CI; see
42
+ # https://github.com/openai/codex/pull/19067 for the motivating failure.
43
+ common --test_env=RUST_MIN_STACK=8388608 # 8 MiB
44
+
45
+ common --test_output=errors
46
+ common --nobuild_runfile_links
47
+ # These settings tune BuildBuddy/RBE behavior but do not contact a remote
48
+ # service unless a `buildbuddy-*` configuration below supplies an endpoint.
49
+ common --remote_download_toplevel
50
+ common --remote_timeout=3600
51
+ common --noexperimental_throttle_remote_action_building
52
+ common --experimental_remote_execution_keepalive
53
+ common --grpc_keepalive_time=30s
54
+
55
+ # Opt-in remote configurations selected by
56
+ # `.github/scripts/run_bazel_with_buildbuddy.py`. Plain Bazel commands do not
57
+ # contact BuildBuddy unless a user selects one of these configurations.
58
+ # Use the generic host for cache, BES, and downloads without remote execution.
59
+ common:buildbuddy-generic --bes_backend=grpcs://remote.buildbuddy.io
60
+ common:buildbuddy-generic --bes_results_url=https://app.buildbuddy.io/invocation/
61
+ common:buildbuddy-generic --remote_cache=grpcs://remote.buildbuddy.io
62
+ common:buildbuddy-generic --experimental_remote_downloader=grpcs://remote.buildbuddy.io
63
+
64
+ # Add remote execution on the generic host.
65
+ common:buildbuddy-generic-rbe --config=buildbuddy-generic
66
+ common:buildbuddy-generic-rbe --config=remote
67
+ common:buildbuddy-generic-rbe --remote_executor=grpcs://remote.buildbuddy.io
68
+
69
+ # Use the OpenAI tenant for cache, BES, and downloads without remote execution.
70
+ common:buildbuddy-openai --bes_backend=grpcs://openai.buildbuddy.io
71
+ common:buildbuddy-openai --bes_results_url=https://openai.buildbuddy.io/invocation/
72
+ common:buildbuddy-openai --remote_cache=grpcs://openai.buildbuddy.io
73
+ common:buildbuddy-openai --experimental_remote_downloader=grpcs://openai.buildbuddy.io
74
+
75
+ # Add remote execution on the OpenAI tenant.
76
+ common:buildbuddy-openai-rbe --config=buildbuddy-openai
77
+ common:buildbuddy-openai-rbe --config=remote
78
+ common:buildbuddy-openai-rbe --remote_executor=grpcs://openai.buildbuddy.io
79
+
80
+ # This limits both in-flight executions and concurrent downloads. Even with high number
81
+ # of jobs execution will still be limited by CPU cores, so this just pays a bit of
82
+ # memory in exchange for higher download concurrency.
83
+ common --jobs=30
84
+
85
+ # Shared remote execution policy. The endpoint-bearing `buildbuddy-*-rbe`
86
+ # configurations include this group; CI configs override TestRunner below
87
+ # when tests must remain local on their runner.
88
+ common:remote --strategy=remote
89
+ # Native Mac voice actions need the local Apple tools; Linux remains remote.
90
+ common:macos --strategy=VoiceNativePrefix=remote,sandboxed,local
91
+ common:macos --strategy=VoiceNativeRuntime=remote,sandboxed,local
92
+ common:remote --extra_execution_platforms=//:rbe
93
+ common:remote --jobs=800
94
+ # TODO(team): Evaluate if this actually helps, zbarsky is not sure, everything seems bottlenecked on `core` either way.
95
+ # Enable pipelined compilation since we are not bound by local CPU count.
96
+ #common:remote --@rules_rust//rust/settings:pipelined_compilation
97
+
98
+ # GitHub Actions CI configs.
99
+ common:ci --remote_download_minimal
100
+ common:ci --keep_going
101
+ common:ci --verbose_failures
102
+ common:ci --build_metadata=REPO_URL=https://github.com/openai/codex.git
103
+ common:ci --build_metadata=ROLE=CI
104
+ common:ci --build_metadata=VISIBILITY=PUBLIC
105
+
106
+ # Disable disk cache in CI since we have a remote one and aren't using persistent workers.
107
+ common:ci --disk_cache=
108
+
109
+ # Shared config for the main Bazel CI workflow.
110
+ common:ci-bazel --config=ci
111
+ common:ci-bazel --build_metadata=TAG_workflow=bazel
112
+
113
+ # Shared config for Bazel-backed Rust linting.
114
+ build:clippy --aspects=@rules_rust//rust:defs.bzl%rust_clippy_aspect
115
+ build:clippy --output_groups=+clippy_checks
116
+ build:clippy --@rules_rust//rust/settings:clippy.toml=//codex-rs:clippy.toml
117
+ # Keep this deny-list in sync with `codex-rs/Cargo.toml` `[workspace.lints.clippy]`.
118
+ # Cargo applies those lint levels to member crates that opt into `[lints] workspace = true`
119
+ # in their own `Cargo.toml`, but `rules_rust` Bazel clippy does not read Cargo lint levels.
120
+ # `clippy.toml` can configure lint behavior, but it cannot set allow/warn/deny/forbid levels.
121
+ build:clippy --@rules_rust//rust/settings:clippy_flag=-Dwarnings
122
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::await_holding_invalid_type
123
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::await_holding_lock
124
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::disallowed_methods
125
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::expect_used
126
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::identity_op
127
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_clamp
128
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_filter
129
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_find
130
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_flatten
131
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_map
132
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_memcpy
133
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_non_exhaustive
134
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_ok_or
135
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_range_contains
136
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_retain
137
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_strip
138
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_try_fold
139
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::manual_unwrap_or
140
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::needless_borrow
141
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::needless_borrowed_reference
142
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::needless_collect
143
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::needless_late_init
144
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::needless_option_as_deref
145
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::needless_question_mark
146
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::needless_update
147
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::redundant_clone
148
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::redundant_closure
149
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::redundant_closure_for_method_calls
150
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::redundant_static_lifetimes
151
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::trivially_copy_pass_by_ref
152
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::uninlined_format_args
153
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::unnecessary_filter_map
154
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::unnecessary_lazy_evaluations
155
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::unnecessary_sort_by
156
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::unnecessary_to_owned
157
+ build:clippy --@rules_rust//rust/settings:clippy_flag=--deny=clippy::unwrap_used
158
+
159
+ # Shared config for Bazel-backed argument-comment-lint.
160
+ build:argument-comment-lint --aspects=//tools/argument-comment-lint:lint_aspect.bzl%rust_argument_comment_lint_aspect
161
+ build:argument-comment-lint --output_groups=argument_comment_lint_checks
162
+ build:argument-comment-lint --@rules_rust//rust/toolchain/channel=nightly
163
+
164
+ # Rearrange caches on Windows so they're on the same volume as the checkout.
165
+ common:ci-windows --config=ci-bazel
166
+ common:ci-windows --build_metadata=TAG_os=windows
167
+ common:ci-windows --repo_contents_cache=D:/a/.cache/bazel-repo-contents-cache
168
+ # The hidden dynamic-tool callback currently times out on Windows, and ConPTY
169
+ # cannot reliably interrupt foreground processes on Windows Bazel runners.
170
+ common:ci-windows --test_env=CODEX_BAZEL_TEST_SKIP_FILTERS=suite::code_mode::code_mode_can_call_hidden_dynamic_tools,tests::windows_tests::conpty_ctrl_c_interrupts_powershell_foreground_child
171
+
172
+ # We prefer to run the build actions entirely remotely so we can dial up the concurrency.
173
+ # We have platform-specific tests, so we want to execute the tests on all platforms using the strongest sandboxing available on each platform.
174
+
175
+ # On linux, we can do a full remote build/test, by targeting the right (x86/arm) runners, so we have coverage of both.
176
+ # Linux crossbuilds don't work until we untangle the libc constraint mess.
177
+ common:ci-linux --config=ci-bazel
178
+ common:ci-linux --build_metadata=TAG_os=linux
179
+ common:ci-linux --platforms=//:rbe
180
+
181
+ # On mac, we can run all the build actions remotely but test actions locally.
182
+ common:ci-macos --config=ci-bazel
183
+ common:ci-macos --build_metadata=TAG_os=macos
184
+ common:ci-macos --strategy=TestRunner=darwin-sandbox,local
185
+
186
+ # On Windows, use Linux remote execution for build actions but keep test actions
187
+ # on the Windows runner so Bazel's normal test sharding and flaky-test retries
188
+ # still run against Windows binaries.
189
+ common:ci-windows-cross --config=ci-windows
190
+ common:ci-windows-cross --build_metadata=TAG_windows_cross_compile=true
191
+ common:ci-windows-cross --host_platform=//:rbe
192
+ common:ci-windows-cross --strategy=TestRunner=local
193
+ # V8 embeds IsolateData offsets in snapshot builtins; Windows snapshots must be
194
+ # generated by a Windows mksnapshot binary rather than the Linux RBE host tool.
195
+ common:ci-windows-cross --strategy=V8Mksnapshot=local
196
+ common:ci-windows-cross --local_test_jobs=8
197
+ common:ci-windows-cross --test_env=RUST_TEST_THREADS=1
198
+ # Native Windows CI still covers the PowerShell parser-process tests. The
199
+ # cross-built gnullvm binaries currently hang in those tests when run on the
200
+ # Windows runner. This replaces the Windows skip list, so retain its exclusions.
201
+ common:ci-windows-cross --test_env=CODEX_BAZEL_TEST_SKIP_FILTERS=command_safety::powershell_parser::tests::,suite::code_mode::code_mode_can_call_hidden_dynamic_tools,tests::windows_tests::conpty_ctrl_c_interrupts_powershell_foreground_child
202
+ common:ci-windows-cross --platforms=//:windows_x86_64_gnullvm
203
+ common:ci-windows-cross --extra_execution_platforms=//:rbe,//:windows_x86_64_msvc
204
+ common:ci-windows-cross --extra_toolchains=//:windows_gnullvm_tests_on_msvc_host_toolchain
205
+
206
+ # Linux-only V8 CI config.
207
+ common:ci-v8 --config=ci
208
+ common:ci-v8 --build_metadata=TAG_workflow=v8
209
+ common:ci-v8 --build_metadata=TAG_os=linux
210
+
211
+ # Source-built Bazel V8 artifacts use the in-process sandbox by default. This
212
+ # does not affect Cargo's default prebuilt rusty_v8 path.
213
+ common --@v8//:v8_enable_pointer_compression=True
214
+ common --@v8//:v8_enable_sandbox=True
215
+
216
+ # Keep currently published rusty_v8 release artifacts non-sandboxed until the
217
+ # artifact migration ships matching Rust feature selection for Cargo consumers.
218
+ common:v8-release-compat --@v8//:v8_enable_pointer_compression=False
219
+ common:v8-release-compat --@v8//:v8_enable_sandbox=False
220
+ common:v8-target-x64 --@v8//bazel/config:v8_target_cpu=x64
221
+ common:v8-target-arm64 --@v8//bazel/config:v8_target_cpu=arm64
222
+
223
+ # Match rusty_v8's upstream GN release contract for published artifacts: every
224
+ # target object uses Chromium's custom libc++ headers and the archive folds in
225
+ # the matching runtime objects.
226
+ common:rusty-v8-upstream-libcxx --@v8//:v8_use_rusty_v8_custom_libcxx=True
227
+
228
+ # Optional per-user local overrides.
229
+ try-import %workspace%/user.bazelrc
.bazelversion ADDED
@@ -0,0 +1 @@
 
 
1
+ 9.0.0
.codespellignore ADDED
@@ -0,0 +1,7 @@
 
 
 
 
 
 
 
 
1
+ iTerm
2
+ iTerm2
3
+ numer
4
+ psuedo
5
+ SOM
6
+ te
7
+ TE
.codespellrc ADDED
@@ -0,0 +1,6 @@
 
 
 
 
 
 
 
1
+ [codespell]
2
+ # Ref: https://github.com/codespell-project/codespell#using-a-config-file
3
+ skip = .git*,vendor,*-lock.yaml,*.lock,.codespellrc,*test.ts,*.jsonl,frame*.txt,*.snap,*.snap.new
4
+ check-hidden = true
5
+ ignore-regex = ^\s*"image/\S+": ".*|\b(afterAll)\b
6
+ ignore-words-list = ratatui,ser,iTerm,iterm2,iterm,te,TE,PASE,SEH
.gitattributes CHANGED
@@ -1,35 +1,3 @@
1
- *.7z filter=lfs diff=lfs merge=lfs -text
2
- *.arrow filter=lfs diff=lfs merge=lfs -text
3
- *.bin filter=lfs diff=lfs merge=lfs -text
4
- *.bz2 filter=lfs diff=lfs merge=lfs -text
5
- *.ckpt filter=lfs diff=lfs merge=lfs -text
6
- *.ftz filter=lfs diff=lfs merge=lfs -text
7
- *.gz filter=lfs diff=lfs merge=lfs -text
8
- *.h5 filter=lfs diff=lfs merge=lfs -text
9
- *.joblib filter=lfs diff=lfs merge=lfs -text
10
- *.lfs.* filter=lfs diff=lfs merge=lfs -text
11
- *.mlmodel filter=lfs diff=lfs merge=lfs -text
12
- *.model filter=lfs diff=lfs merge=lfs -text
13
- *.msgpack filter=lfs diff=lfs merge=lfs -text
14
- *.npy filter=lfs diff=lfs merge=lfs -text
15
- *.npz filter=lfs diff=lfs merge=lfs -text
16
- *.onnx filter=lfs diff=lfs merge=lfs -text
17
- *.ot filter=lfs diff=lfs merge=lfs -text
18
- *.parquet filter=lfs diff=lfs merge=lfs -text
19
- *.pb filter=lfs diff=lfs merge=lfs -text
20
- *.pickle filter=lfs diff=lfs merge=lfs -text
21
- *.pkl filter=lfs diff=lfs merge=lfs -text
22
- *.pt filter=lfs diff=lfs merge=lfs -text
23
- *.pth filter=lfs diff=lfs merge=lfs -text
24
- *.rar filter=lfs diff=lfs merge=lfs -text
25
- *.safetensors filter=lfs diff=lfs merge=lfs -text
26
- saved_model/**/* filter=lfs diff=lfs merge=lfs -text
27
- *.tar.* filter=lfs diff=lfs merge=lfs -text
28
- *.tar filter=lfs diff=lfs merge=lfs -text
29
- *.tflite filter=lfs diff=lfs merge=lfs -text
30
- *.tgz filter=lfs diff=lfs merge=lfs -text
31
- *.wasm filter=lfs diff=lfs merge=lfs -text
32
- *.xz filter=lfs diff=lfs merge=lfs -text
33
- *.zip filter=lfs diff=lfs merge=lfs -text
34
- *.zst filter=lfs diff=lfs merge=lfs -text
35
- *tfevents* filter=lfs diff=lfs merge=lfs -text
 
1
+ codex-rs/app-server-protocol/schema/** linguist-generated
2
+ codex-rs/hooks/schema/generated/** linguist-generated
3
+ third_party/voice/sources.json text eol=lf
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
.gitignore ADDED
@@ -0,0 +1,96 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # deps
2
+ # Node.js dependencies
3
+ node_modules
4
+ .pnpm-store
5
+ .pnpm-debug.log
6
+
7
+ # Keep pnpm-lock.yaml
8
+ !pnpm-lock.yaml
9
+
10
+ # build
11
+ dist/
12
+ bazel-*
13
+ user.bazelrc
14
+ build/
15
+ out/
16
+ storybook-static/
17
+
18
+ # ignore README for publishing
19
+ codex-cli/README.md
20
+
21
+ # ignore Nix derivation results
22
+ result
23
+
24
+ # editor
25
+ .vscode/
26
+ .idea/
27
+ .history/
28
+ .zed/
29
+ *.swp
30
+ *~
31
+
32
+ # cli tools
33
+ CLAUDE.md
34
+ .claude/
35
+ AGENTS.override.md
36
+
37
+ # caches
38
+ .cache/
39
+ .turbo/
40
+ .parcel-cache/
41
+ .eslintcache
42
+ .nyc_output/
43
+ .jest/
44
+ *.tsbuildinfo
45
+
46
+ # logs
47
+ *.log
48
+ npm-debug.log*
49
+ yarn-debug.log*
50
+ yarn-error.log*
51
+
52
+ # env
53
+ .env*
54
+ !.env.example
55
+ .venv/
56
+
57
+ # package
58
+ *.tgz
59
+
60
+ # ci
61
+ .vercel/
62
+ .netlify/
63
+ /.tmp/sdk-ci/
64
+ /upstream-rusty-v8/
65
+
66
+ # patches
67
+ apply_patch/
68
+
69
+ # coverage
70
+ coverage/
71
+
72
+ # personal files
73
+ personal/
74
+
75
+ # os
76
+ .DS_Store
77
+ Thumbs.db
78
+ Icon?
79
+ .Spotlight-V100/
80
+
81
+ # Unwanted package managers
82
+ .yarn/
83
+ yarn.lock
84
+
85
+ # release
86
+ package.json-e
87
+ session.ts-e
88
+ CHANGELOG.ignore.md
89
+
90
+ # nix related
91
+ .direnv
92
+ .envrc
93
+
94
+ # Python bytecode files
95
+ __pycache__/
96
+ *.pyc
.markdownlint-cli2.yaml ADDED
@@ -0,0 +1,6 @@
 
 
 
 
 
 
 
1
+ config:
2
+ MD013:
3
+ line_length: 100
4
+
5
+ globs:
6
+ - "docs/tui-chat-composer.md"
.npmrc ADDED
@@ -0,0 +1,4 @@
 
 
 
 
 
1
+ shamefully-hoist=true
2
+ strict-peer-dependencies=false
3
+ node-linker=hoisted
4
+ prefer-workspace-packages=true
.prettierignore ADDED
@@ -0,0 +1,7 @@
 
 
 
 
 
 
 
 
1
+ /codex-cli/dist
2
+ /codex-cli/node_modules
3
+ pnpm-lock.yaml
4
+
5
+ prompt.md
6
+ *_prompt.md
7
+ *_instructions.md
.prettierrc.toml ADDED
@@ -0,0 +1,8 @@
 
 
 
 
 
 
 
 
 
1
+ printWidth = 80
2
+ quoteProps = "consistent"
3
+ semi = true
4
+ tabWidth = 2
5
+ trailingComma = "all"
6
+
7
+ # Preserve existing behavior for markdown/text wrapping.
8
+ proseWrap = "preserve"
.worktreeinclude ADDED
@@ -0,0 +1 @@
 
 
1
+ user.bazelrc
AGENTS.md ADDED
@@ -0,0 +1,320 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # Rust/codex-rs
2
+
3
+ In the codex-rs folder where the rust code lives:
4
+
5
+ - Crate names are prefixed with `codex-`. For example, the `core` folder's crate is named `codex-core`
6
+ - When using format! and you can inline variables into {}, always do that.
7
+ - Install any commands the repo relies on (for example `just`, `rg`, or `cargo-insta`) if they aren't already available before running instructions here.
8
+ - Never add or modify any code related to `CODEX_SANDBOX_NETWORK_DISABLED_ENV_VAR` or `CODEX_SANDBOX_ENV_VAR`.
9
+ - You operate in a sandbox where `CODEX_SANDBOX_NETWORK_DISABLED=1` will be set whenever you use the `shell` tool. Any existing code that uses `CODEX_SANDBOX_NETWORK_DISABLED_ENV_VAR` was authored with this fact in mind. It is often used to early exit out of tests that the author knew you would not be able to run given your sandbox limitations.
10
+ - Similarly, when you spawn a process using Seatbelt (`/usr/bin/sandbox-exec`), `CODEX_SANDBOX=seatbelt` will be set on the child process. Integration tests that want to run Seatbelt themselves cannot be run under Seatbelt, so checks for `CODEX_SANDBOX=seatbelt` are also often used to early exit out of tests, as appropriate.
11
+ - Always collapse if statements per https://rust-lang.github.io/rust-clippy/master/index.html#collapsible_if
12
+ - Always inline format! args when possible per https://rust-lang.github.io/rust-clippy/master/index.html#uninlined_format_args
13
+ - Use method references over closures when possible per https://rust-lang.github.io/rust-clippy/master/index.html#redundant_closure_for_method_calls
14
+ - Avoid bool or ambiguous `Option` parameters that force callers to write hard-to-read code such as `foo(false)` or `bar(None)`. Prefer enums, named methods, newtypes, or other idiomatic Rust API shapes when they keep the callsite self-documenting.
15
+ - When you cannot make that API change and still need a small positional-literal callsite in Rust, follow the `argument_comment_lint` convention:
16
+ - Use an exact `/*param_name*/` comment before opaque literal arguments such as `None`, booleans, and numeric literals when passing them by position.
17
+ - A method's sole non-self argument is exempt when the method and parameter names match, such as `.enabled(false)` for `fn enabled(&self, enabled: bool)`.
18
+ - Do not add these comments for string or char literals unless the comment adds real clarity; those literals are intentionally exempt from the lint.
19
+ - The parameter name in the comment must exactly match the callee signature.
20
+ - You can run `just argument-comment-lint` to run the lint check locally. This is powered by Bazel, so running it the first time can be slow if Bazel is not warmed up, though incremental invocations should take <15s. Most of the time, it is best to update the PR and let CI take responsibility for checking this (or run it asynchronously in the background after submitting the PR). Note CI checks all three platforms, which the local run does not.
21
+ - When possible, make `match` statements exhaustive and avoid wildcard arms.
22
+ - Newly added traits should include doc comments that explain their role and how implementations are expected to use them.
23
+ - Discourage both `#[async_trait]` and `#[allow(async_fn_in_trait)]` in Rust traits.
24
+ - Prefer native RPITIT trait methods with explicit `Send` bounds on the returned future, as in `3c7f013f9735` / `#16630`.
25
+ - Preferred trait shape:
26
+ `fn foo(&self, ...) -> impl std::future::Future<Output = T> + Send;`
27
+ - Implementations may still use `async fn foo(&self, ...) -> T` when they satisfy that contract.
28
+ - Do not use `#[allow(async_fn_in_trait)]` as a shortcut around spelling the future contract explicitly.
29
+ - When writing tests, prefer comparing the equality of entire objects over fields one by one.
30
+ - Do not add tests for values that are statically defined.
31
+ - Do not add negative tests for logic that was removed.
32
+ - Do not add general product or user-facing documentation to the `docs/` folder. The official Codex documentation lives elsewhere. The exception is app-server API documentation, which is covered by the app-server guidance below.
33
+ - Prefer private modules and explicitly exported public crate API.
34
+ - If you change `ConfigToml` or nested config types, run `just write-config-schema` to update `codex-rs/core/config.schema.json`.
35
+ - When working with MCP tool calls, prefer using `codex-rs/codex-mcp/src/mcp_connection_manager.rs` to handle mutation of tools and tool calls. Aim to minimize the footprint of changes and leverage existing abstractions rather than plumbing code through multiple levels of function calls.
36
+ - Do not call `reset_client_session` unnecessarily; let the incremental check logic decide whether to reuse the previous request.
37
+ - If you change Rust dependencies (`Cargo.toml` or `Cargo.lock`), run `just bazel-lock-update` from the
38
+ repo root to refresh `MODULE.bazel.lock`, and include that lockfile update in the same change. CI
39
+ verifies lockfile drift.
40
+ - Bazel does not automatically make source-tree files available to compile-time Rust file access. If
41
+ you add `include_str!`, `include_bytes!`, `sqlx::migrate!`, or similar build-time file or
42
+ directory reads, update the crate's `BUILD.bazel` (`compile_data`, `build_script_data`, or test
43
+ data) or Bazel may fail even when Cargo passes.
44
+ - Do not create small helper methods that are referenced only once.
45
+ - For tracing async work, instrument the function or method definition with
46
+ `#[tracing::instrument(...)]` instead of attaching spans to futures with
47
+ `.instrument(...)` at call sites. Before adding instrumentation, check whether the callee—or
48
+ the implementation method it immediately delegates to—is already instrumented.
49
+ - Avoid large modules:
50
+ - Prefer adding new modules instead of growing existing ones.
51
+ - Target Rust modules under 500 LoC, excluding tests.
52
+ - If a file exceeds roughly 800 LoC, add new functionality in a new module instead of extending
53
+ the existing file unless there is a strong documented reason not to.
54
+ - This rule applies especially to high-touch files that already attract unrelated changes, such
55
+ as `codex-rs/tui/src/app.rs`, `codex-rs/tui/src/bottom_pane/chat_composer.rs`,
56
+ `codex-rs/tui/src/bottom_pane/footer.rs`, `codex-rs/tui/src/chatwidget.rs`,
57
+ `codex-rs/tui/src/bottom_pane/mod.rs`, and similarly central orchestration modules.
58
+ - When extracting code from a large module, move the related tests and module/type docs toward
59
+ the new implementation so the invariants stay close to the code that owns them.
60
+ - Avoid adding new standalone methods to `codex-rs/tui/src/chatwidget.rs` unless the change is
61
+ trivial; prefer new modules/files and keep `chatwidget.rs` focused on orchestration.
62
+ - When running Rust commands (e.g. `just fix` or `just test`) be patient with the command and never try to kill them using the PID. Rust lock can make the execution slow, this is expected.
63
+
64
+ Run `just fmt` (in the `codex-rs` directory) automatically after you have finished making code changes anywhere in this repository; do not ask for approval to run it. Additionally, run the tests:
65
+
66
+ 1. Do not run `cargo test` directly. Use `just test` so test execution follows the repo defaults.
67
+ 2. Run the test for the specific project that was changed. For example, if changes were made in `codex-rs/tui`, run `just test -p codex-tui`.
68
+ 3. Once those pass, if any changes were made in common, core, or protocol, run the complete test suite with `just test`. Avoid `--all-features` for routine local runs because it expands the build matrix and can significantly increase `target/` disk usage; use it only when you specifically need full feature coverage. project-specific or individual tests can be run without asking the user, but do ask the user before running the complete test suite.
69
+
70
+ Before finalizing a large change to `codex-rs`, run `just fix -p <project>` (in `codex-rs` directory) to fix any linter issues in the code. Prefer scoping with `-p` to avoid slow workspace‑wide Clippy builds; only run `just fix` without `-p` if you changed shared crates. Do not re-run tests after running `fix` or `fmt`.
71
+
72
+ ## The `codex-core` crate
73
+
74
+ Over time, the `codex-core` crate (defined in `codex-rs/core/`) has become bloated because it is the largest crate, so it is often easier to add something new to `codex-core` rather than refactor out the library code you need so your new code neither takes a dependency on, nor contributes to the size of, `codex-core`.
75
+
76
+ To that end: **resist adding code to codex-core**!
77
+
78
+ Particularly when introducing a new concept/feature/API, before adding to `codex-core`, consider whether:
79
+
80
+ - There is an existing crate other than `codex-core` that is an appropriate place for your new code to live.
81
+ - It is time to introduce a new crate to the Cargo workspace for your new functionality. Refactor existing code as necessary to make this happen.
82
+
83
+ Likewise, when reviewing code, do not hesitate to push back on PRs that would unnecessarily add code to `codex-core`.
84
+
85
+ ## Code Review Rules
86
+
87
+ ### Crate API surface
88
+
89
+ Keep crate API surfaces as small as possible. Avoid proliferating test-only helpers.
90
+
91
+ ### Model visible context
92
+
93
+ Codex maintains a context (history of messages) that is sent to the model in inference requests.
94
+
95
+ 1. No history rewrite - the context must be built up incrementally.
96
+ 2. Avoid frequent changes to context that cause cache misses.
97
+ 3. No unbounded items - everything injected in the model context must have a bounded size and a hard cap.
98
+ 4. No items larger than 10K tokens.
99
+ 5. Highlight new individual items that can cross >1k tokens as P0. These need an additional manual review.
100
+ 6. All injected fragments must be defined as structs in `core/context` and implement ContextualUserFragment trait
101
+
102
+ ### Breaking changes
103
+
104
+ Search for breaking changes in external integration surfaces:
105
+
106
+ - app-server APIs
107
+ - raw response item events (`rawResponseItem/*`), even while experimental
108
+ - CLI parameters
109
+ - configuration loading
110
+ - resuming sessions from existing rollouts
111
+
112
+ ### Test authoring guidance
113
+
114
+ For agent changes prefer integration tests over unit tests. Integration tests are under `core/suite` and use `test_codex` to set up a test instance of codex.
115
+
116
+ Features that change the agent logic MUST add an integration test:
117
+
118
+ - Provide a list of major logic changes and user-facing behaviors that need to be tested.
119
+
120
+ If unit tests are needed, put them in a dedicated test file (\*\_tests.rs).
121
+ Avoid test-only functions in the main implementation.
122
+
123
+ Check whether there are existing helpers to make tests more streamlined and readable.
124
+
125
+ ### Change size guidance (800 lines)
126
+
127
+ Unless the change is mechanical the total number of changed lines should not exceed 800 lines.
128
+ For complex logic changes the size should be under 500 lines.
129
+
130
+ If the change is larger, explore whether it can be split into reviewable stages and identify the smallest coherent stage to land first.
131
+ Base the staging suggestion on the actual diff, dependencies, and affected call sites.
132
+
133
+ ## TUI style conventions
134
+
135
+ See `codex-rs/tui/styles.md`.
136
+
137
+ ## TUI code conventions
138
+
139
+ - Use concise styling helpers from ratatui’s Stylize trait.
140
+ - Basic spans: use "text".into()
141
+ - Styled spans: use "text".red(), "text".green(), "text".magenta(), "text".dim(), etc.
142
+ - Prefer these over constructing styles with `Span::styled` and `Style` directly.
143
+ - Example: patch summary file lines
144
+ - Desired: vec![" └ ".into(), "M".red(), " ".dim(), "tui/src/app.rs".dim()]
145
+
146
+ ### TUI Styling (ratatui)
147
+
148
+ - Prefer Stylize helpers: use "text".dim(), .bold(), .cyan(), .italic(), .underlined() instead of manual Style where possible.
149
+ - Prefer simple conversions: use "text".into() for spans and vec![…].into() for lines; when inference is ambiguous (e.g., Paragraph::new/Cell::from), use Line::from(spans) or Span::from(text).
150
+ - Computed styles: if the Style is computed at runtime, using `Span::styled` is OK (`Span::from(text).set_style(style)` is also acceptable).
151
+ - Avoid hardcoded white: do not use `.white()`; prefer the default foreground (no color).
152
+ - Chaining: combine helpers by chaining for readability (e.g., url.cyan().underlined()).
153
+ - Single items: prefer "text".into(); use Line::from(text) or Span::from(text) only when the target type isn’t obvious from context, or when using .into() would require extra type annotations.
154
+ - Building lines: use vec![…].into() to construct a Line when the target type is obvious and no extra type annotations are needed; otherwise use Line::from(vec![…]).
155
+ - Avoid churn: don’t refactor between equivalent forms (Span::styled ↔ set_style, Line::from ↔ .into()) without a clear readability or functional gain; follow file‑local conventions and do not introduce type annotations solely to satisfy .into().
156
+ - Compactness: prefer the form that stays on one line after rustfmt; if only one of Line::from(vec![…]) or vec![…].into() avoids wrapping, choose that. If both wrap, pick the one with fewer wrapped lines.
157
+
158
+ ### Text wrapping
159
+
160
+ - Always use textwrap::wrap to wrap plain strings.
161
+ - If you have a ratatui Line and you want to wrap it, use the helpers in tui/src/wrapping.rs, e.g. word_wrap_lines / word_wrap_line.
162
+ - If you need to indent wrapped lines, use the initial_indent / subsequent_indent options from RtOptions if you can, rather than writing custom logic.
163
+ - If you have a list of lines and you need to prefix them all with some prefix (optionally different on the first vs subsequent lines), use the `prefix_lines` helper from line_utils.
164
+
165
+ ## Tests
166
+
167
+ ### Test module organization
168
+
169
+ - When adding a new test module, define its contents in a separate sibling file rather than inline in the implementation file.
170
+ - Use an explicit `#[path = "..._tests.rs"]` attribute so the test filename is descriptive and easy to locate:
171
+
172
+ ```rust
173
+ #[cfg(test)]
174
+ #[path = "parser_tests.rs"]
175
+ mod tests;
176
+ ```
177
+
178
+ - This applies only when introducing a new test module. Do not move or rewrite existing inline `#[cfg(test)] mod tests { ... }` modules solely to follow this convention.
179
+
180
+ ### Snapshot tests
181
+
182
+ This repo uses snapshot tests (via `insta`), especially in `codex-rs/tui`, to validate rendered output.
183
+
184
+ **Requirement:** any change that affects user-visible UI (including adding new UI) must include
185
+ corresponding `insta` snapshot coverage (add a new snapshot test if one doesn't exist yet, or
186
+ update the existing snapshot). Review and accept snapshot updates as part of the PR so UI impact
187
+ is easy to review and future diffs stay visual.
188
+
189
+ When UI or text output changes intentionally, update the snapshots as follows:
190
+
191
+ - Run tests to generate any updated snapshots:
192
+ - `just test -p codex-tui`
193
+ - Check what’s pending:
194
+ - `cargo insta pending-snapshots -p codex-tui`
195
+ - Review changes by reading the generated `*.snap.new` files directly in the repo, or preview a specific file:
196
+ - `cargo insta show -p codex-tui path/to/file.snap.new`
197
+ - Only if you intend to accept all new snapshots in this crate, run:
198
+ - `cargo insta accept -p codex-tui`
199
+
200
+ If you don’t have the tool:
201
+
202
+ - `cargo install --locked cargo-insta`
203
+
204
+ ### Benchmarks
205
+
206
+ cargo benchmarks can be run with `just bench`, use the divan crate to write new ones.
207
+
208
+ Use `just bench-smoke` to dry-run the benchmark for a single iteration to ensure it works.
209
+
210
+ ### Test assertions
211
+
212
+ - Tests should use pretty_assertions::assert_eq for clearer diffs. Import this at the top of the test module if it isn't already.
213
+ - Prefer deep equals comparisons whenever possible. Perform `assert_eq!()` on entire objects, rather than individual fields.
214
+ - Avoid mutating process environment in tests; prefer passing environment-derived flags or dependencies from above.
215
+
216
+ ### Spawning workspace binaries in tests (Cargo vs Bazel)
217
+
218
+ - Prefer `codex_utils_cargo_bin::cargo_bin("...")` over `assert_cmd::Command::cargo_bin(...)` or `escargot` when tests need to spawn first-party binaries.
219
+ - Under Bazel, binaries and resources may live under runfiles; use `codex_utils_cargo_bin::cargo_bin` to resolve absolute paths that remain stable after `chdir`.
220
+ - When locating fixture files or test resources under Bazel, avoid `env!("CARGO_MANIFEST_DIR")`. Prefer `codex_utils_cargo_bin::find_resource!` so paths resolve correctly under both Cargo and Bazel runfiles.
221
+
222
+ ### Integration tests
223
+
224
+ #### codex_core integration testing
225
+
226
+ - Prefer the utilities in `core_test_support::responses` when writing end-to-end Codex tests.
227
+ - Use `TestCodexBuilder::build_with_auto_env()` by default to ensure that new tests work with
228
+ foreign app/exec OSes. See $remote-tests for details.
229
+ - All `mount_sse*` helpers return a `ResponseMock`; hold onto it so you can assert against outbound `/responses` POST bodies.
230
+ - Use `ResponseMock::single_request()` when a test should only issue one POST, or `ResponseMock::requests()` to inspect every captured `ResponsesRequest`.
231
+ - `ResponsesRequest` exposes helpers (`body_json`, `input`, `function_call_output`, `custom_tool_call_output`, `call_output`, `header`, `path`, `query_param`) so assertions can target structured payloads instead of manual JSON digging.
232
+ - Build SSE payloads with the provided `ev_*` constructors and the `sse(...)`.
233
+ - Prefer `wait_for_event` over `wait_for_event_with_timeout`.
234
+ - Prefer `mount_sse_once` over `mount_sse_once_match` or `mount_sse_sequence`
235
+
236
+ - Typical pattern:
237
+
238
+ ```rust
239
+ let mock = responses::mount_sse_once(&server, responses::sse(vec![
240
+ responses::ev_response_created("resp-1"),
241
+ responses::ev_function_call(call_id, "shell", &serde_json::to_string(&args)?),
242
+ responses::ev_completed("resp-1"),
243
+ ])).await;
244
+
245
+ codex.submit(Op::UserTurn { ... }).await?;
246
+
247
+ // Assert request body if needed.
248
+ let request = mock.single_request();
249
+ // assert using request.function_call_output(call_id) or request.json_body() or other helpers.
250
+ ```
251
+
252
+ #### app-server integration testing
253
+
254
+ - Tests should exercise app-server's public JSON-RPC API.
255
+ - Use similar server mocking as for core integration tests.
256
+ - Use `TestAppServer::builder().build()` and `TestAppServer::send_thread_start_request_with_auto_env()`
257
+ by default to ensure that new tests work with foreign app/exec OSes. See `$remote-tests` for
258
+ details.
259
+
260
+ ## App-server API Development Best Practices
261
+
262
+ These guidelines apply to app-server protocol work in `codex-rs`, especially:
263
+
264
+ - `app-server-protocol/src/protocol/common.rs`
265
+ - `app-server-protocol/src/protocol/v2.rs`
266
+
267
+ ### Core Rules
268
+
269
+ - All active API development should happen in app-server v2. Do not add new API surface area to v1.
270
+ - Follow payload naming consistently:
271
+ `*Params` for request payloads, `*Response` for responses, and `*Notification` for notifications.
272
+ - Expose RPC methods as `<resource>/<method>` and keep `<resource>` singular (for example, `thread/read`, `app/list`).
273
+ - Always expose fields as camelCase on the wire with `#[serde(rename_all = "camelCase")]` unless a tagged union or explicit compatibility requirement needs a targeted rename.
274
+ - Always expose string enum values as camelCase on the wire with matching serde and TS `rename_all = "camelCase"` annotations unless an explicit compatibility requirement needs targeted renames.
275
+ - Exception: config RPC payloads are expected to use snake_case to mirror config.toml keys (see the config read/write/list APIs in `app-server-protocol/src/protocol/v2.rs`).
276
+ - Always set `#[ts(export_to = "v2/")]` on v2 request/response/notification types so generated TypeScript lands in the correct namespace.
277
+ - Never use `#[serde(skip_serializing_if = "Option::is_none")]` for v2 API payload fields.
278
+ Exception: client->server requests that intentionally have no params may use:
279
+ `params: #[ts(type = "undefined")] #[serde(skip_serializing_if = "Option::is_none")] Option<()>`.
280
+ - Keep Rust and TS wire renames aligned. If a field or variant uses `#[serde(rename = "...")]`, add matching `#[ts(rename = "...")]`.
281
+ - For discriminated unions, use explicit tagging in both serializers:
282
+ `#[serde(tag = "type", ...)]` and `#[ts(tag = "type", ...)]`.
283
+ - Prefer plain `String` IDs at the API boundary (do UUID parsing/conversion internally if needed).
284
+ - Timestamps should be integer Unix seconds (`i64`) and named `*_at` (for example, `created_at`, `updated_at`, `resets_at`).
285
+ - For experimental API surface area:
286
+ use `#[experimental("method/or/field")]`, derive `ExperimentalApi` when field-level gating is needed, and use `inspect_params: true` in `common.rs` when only some fields of a method are experimental.
287
+
288
+ ### Client->server request payloads (`*Params`)
289
+
290
+ - Every optional field must be annotated with `#[ts(optional = nullable)]`. Do not use `#[ts(optional = nullable)]` outside client->server request payloads (`*Params`).
291
+ - Optional collection fields (for example `Vec`, `HashMap`) must use `Option<...>` + `#[ts(optional = nullable)]`. Do not use `#[serde(default)]` to model optional collections, and do not use `skip_serializing_if` on v2 payload fields.
292
+ - When you want omission to mean `false` for boolean fields, use `#[serde(default, skip_serializing_if = "std::ops::Not::not")] pub field: bool` over `Option<bool>`.
293
+ - For new list methods, implement cursor pagination by default:
294
+ request fields `pub cursor: Option<String>` and `pub limit: Option<u32>`,
295
+ response fields `pub data: Vec<...>` and `pub next_cursor: Option<String>`.
296
+
297
+ ### Development Workflow
298
+
299
+ - Regenerate schema fixtures when API shapes change:
300
+ `just write-app-server-schema`
301
+ (and `just write-app-server-schema --experimental` when experimental API fixtures are affected).
302
+ - Validate with `just test -p codex-app-server-protocol`.
303
+ - Avoid boilerplate tests that only assert experimental field markers for individual
304
+ request fields in `common.rs`; rely on schema generation/tests and behavioral coverage instead.
305
+
306
+ ## Python Development Best Practices
307
+
308
+ ### Ignore Python 2 compatibility
309
+
310
+ This project uses Python 3+. You should not use the `__future__` module.
311
+
312
+ If you need to worry about feature compatibility between different 3.xx point releases, check the
313
+ closest `pyproject.toml`'s `requires-python` field to see what minimum runtime version is supported.
314
+
315
+ ## Platform Support
316
+
317
+ Tests and features must support Linux, macOS and Windows unless feature is explicitly OS-specific.
318
+
319
+ Codex supports running connected app-server and exec-server on different operating systems. See the
320
+ `$remote-tests` skill for details about integration testing these configurations.
BUILD.bazel ADDED
@@ -0,0 +1,79 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ load("@apple_support//xcode:xcode_config.bzl", "xcode_config")
2
+
3
+ xcode_config(name = "disable_xcode")
4
+
5
+ # We mark the local platform as glibc-compatible so that rust can grab a toolchain for us.
6
+ # TODO(zbarsky): Upstream a better libc constraint into rules_rust.
7
+ # We only enable this on linux though for sanity, and because it breaks remote execution.
8
+ platform(
9
+ name = "local_linux",
10
+ constraint_values = [
11
+ # We mark the local platform as glibc-compatible because musl-built rust cannot dlopen proc macros.
12
+ "@llvm//constraints/libc:gnu.2.28",
13
+ ],
14
+ parents = ["@platforms//host"],
15
+ )
16
+
17
+ platform(
18
+ name = "local_windows",
19
+ constraint_values = [
20
+ "@llvm//constraints/windows/abi:gnullvm",
21
+ "@llvm//constraints/windows/crt:msvcrt",
22
+ ],
23
+ parents = ["@platforms//host"],
24
+ )
25
+
26
+ platform(
27
+ name = "local_windows_msvc",
28
+ constraint_values = [
29
+ "@llvm//constraints/windows/abi:msvc",
30
+ ],
31
+ parents = ["@platforms//host"],
32
+ )
33
+
34
+ platform(
35
+ name = "windows_x86_64_gnullvm",
36
+ constraint_values = [
37
+ "@platforms//cpu:x86_64",
38
+ "@platforms//os:windows",
39
+ "@llvm//constraints/windows/abi:gnullvm",
40
+ "@llvm//constraints/windows/crt:msvcrt",
41
+ ],
42
+ )
43
+
44
+ platform(
45
+ name = "windows_x86_64_msvc",
46
+ constraint_values = [
47
+ "@platforms//cpu:x86_64",
48
+ "@platforms//os:windows",
49
+ "@llvm//constraints/windows/abi:msvc",
50
+ ],
51
+ )
52
+
53
+ toolchain(
54
+ name = "windows_gnullvm_tests_on_msvc_host_toolchain",
55
+ exec_compatible_with = [
56
+ "@platforms//cpu:x86_64",
57
+ "@platforms//os:windows",
58
+ "@llvm//constraints/windows/abi:msvc",
59
+ ],
60
+ target_compatible_with = [
61
+ "@platforms//cpu:x86_64",
62
+ "@platforms//os:windows",
63
+ "@llvm//constraints/windows/abi:gnullvm",
64
+ "@llvm//constraints/windows/crt:msvcrt",
65
+ ],
66
+ toolchain = "@bazel_tools//tools/test:empty_toolchain",
67
+ toolchain_type = "@bazel_tools//tools/test:default_test_toolchain_type",
68
+ )
69
+
70
+ alias(
71
+ name = "rbe",
72
+ actual = "@rbe_platform",
73
+ )
74
+
75
+ exports_files([
76
+ "AGENTS.md",
77
+ "workspace_root_test_launcher.bat.tpl",
78
+ "workspace_root_test_launcher.sh.tpl",
79
+ ])
CHANGELOG.md ADDED
@@ -0,0 +1 @@
 
 
1
+ The changelog can be found on the [releases page](https://github.com/openai/codex/releases).
LICENSE ADDED
@@ -0,0 +1,201 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ Apache License
2
+ Version 2.0, January 2004
3
+ http://www.apache.org/licenses/
4
+
5
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
6
+
7
+ 1. Definitions.
8
+
9
+ "License" shall mean the terms and conditions for use, reproduction,
10
+ and distribution as defined by Sections 1 through 9 of this document.
11
+
12
+ "Licensor" shall mean the copyright owner or entity authorized by
13
+ the copyright owner that is granting the License.
14
+
15
+ "Legal Entity" shall mean the union of the acting entity and all
16
+ other entities that control, are controlled by, or are under common
17
+ control with that entity. For the purposes of this definition,
18
+ "control" means (i) the power, direct or indirect, to cause the
19
+ direction or management of such entity, whether by contract or
20
+ otherwise, or (ii) ownership of fifty percent (50%) or more of the
21
+ outstanding shares, or (iii) beneficial ownership of such entity.
22
+
23
+ "You" (or "Your") shall mean an individual or Legal Entity
24
+ exercising permissions granted by this License.
25
+
26
+ "Source" form shall mean the preferred form for making modifications,
27
+ including but not limited to software source code, documentation
28
+ source, and configuration files.
29
+
30
+ "Object" form shall mean any form resulting from mechanical
31
+ transformation or translation of a Source form, including but
32
+ not limited to compiled object code, generated documentation,
33
+ and conversions to other media types.
34
+
35
+ "Work" shall mean the work of authorship, whether in Source or
36
+ Object form, made available under the License, as indicated by a
37
+ copyright notice that is included in or attached to the work
38
+ (an example is provided in the Appendix below).
39
+
40
+ "Derivative Works" shall mean any work, whether in Source or Object
41
+ form, that is based on (or derived from) the Work and for which the
42
+ editorial revisions, annotations, elaborations, or other modifications
43
+ represent, as a whole, an original work of authorship. For the purposes
44
+ of this License, Derivative Works shall not include works that remain
45
+ separable from, or merely link (or bind by name) to the interfaces of,
46
+ the Work and Derivative Works thereof.
47
+
48
+ "Contribution" shall mean any work of authorship, including
49
+ the original version of the Work and any modifications or additions
50
+ to that Work or Derivative Works thereof, that is intentionally
51
+ submitted to Licensor for inclusion in the Work by the copyright owner
52
+ or by an individual or Legal Entity authorized to submit on behalf of
53
+ the copyright owner. For the purposes of this definition, "submitted"
54
+ means any form of electronic, verbal, or written communication sent
55
+ to the Licensor or its representatives, including but not limited to
56
+ communication on electronic mailing lists, source code control systems,
57
+ and issue tracking systems that are managed by, or on behalf of, the
58
+ Licensor for the purpose of discussing and improving the Work, but
59
+ excluding communication that is conspicuously marked or otherwise
60
+ designated in writing by the copyright owner as "Not a Contribution."
61
+
62
+ "Contributor" shall mean Licensor and any individual or Legal Entity
63
+ on behalf of whom a Contribution has been received by Licensor and
64
+ subsequently incorporated within the Work.
65
+
66
+ 2. Grant of Copyright License. Subject to the terms and conditions of
67
+ this License, each Contributor hereby grants to You a perpetual,
68
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
69
+ copyright license to reproduce, prepare Derivative Works of,
70
+ publicly display, publicly perform, sublicense, and distribute the
71
+ Work and such Derivative Works in Source or Object form.
72
+
73
+ 3. Grant of Patent License. Subject to the terms and conditions of
74
+ this License, each Contributor hereby grants to You a perpetual,
75
+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable
76
+ (except as stated in this section) patent license to make, have made,
77
+ use, offer to sell, sell, import, and otherwise transfer the Work,
78
+ where such license applies only to those patent claims licensable
79
+ by such Contributor that are necessarily infringed by their
80
+ Contribution(s) alone or by combination of their Contribution(s)
81
+ with the Work to which such Contribution(s) was submitted. If You
82
+ institute patent litigation against any entity (including a
83
+ cross-claim or counterclaim in a lawsuit) alleging that the Work
84
+ or a Contribution incorporated within the Work constitutes direct
85
+ or contributory patent infringement, then any patent licenses
86
+ granted to You under this License for that Work shall terminate
87
+ as of the date such litigation is filed.
88
+
89
+ 4. Redistribution. You may reproduce and distribute copies of the
90
+ Work or Derivative Works thereof in any medium, with or without
91
+ modifications, and in Source or Object form, provided that You
92
+ meet the following conditions:
93
+
94
+ (a) You must give any other recipients of the Work or
95
+ Derivative Works a copy of this License; and
96
+
97
+ (b) You must cause any modified files to carry prominent notices
98
+ stating that You changed the files; and
99
+
100
+ (c) You must retain, in the Source form of any Derivative Works
101
+ that You distribute, all copyright, patent, trademark, and
102
+ attribution notices from the Source form of the Work,
103
+ excluding those notices that do not pertain to any part of
104
+ the Derivative Works; and
105
+
106
+ (d) If the Work includes a "NOTICE" text file as part of its
107
+ distribution, then any Derivative Works that You distribute must
108
+ include a readable copy of the attribution notices contained
109
+ within such NOTICE file, excluding those notices that do not
110
+ pertain to any part of the Derivative Works, in at least one
111
+ of the following places: within a NOTICE text file distributed
112
+ as part of the Derivative Works; within the Source form or
113
+ documentation, if provided along with the Derivative Works; or,
114
+ within a display generated by the Derivative Works, if and
115
+ wherever such third-party notices normally appear. The contents
116
+ of the NOTICE file are for informational purposes only and
117
+ do not modify the License. You may add Your own attribution
118
+ notices within Derivative Works that You distribute, alongside
119
+ or as an addendum to the NOTICE text from the Work, provided
120
+ that such additional attribution notices cannot be construed
121
+ as modifying the License.
122
+
123
+ You may add Your own copyright statement to Your modifications and
124
+ may provide additional or different license terms and conditions
125
+ for use, reproduction, or distribution of Your modifications, or
126
+ for any such Derivative Works as a whole, provided Your use,
127
+ reproduction, and distribution of the Work otherwise complies with
128
+ the conditions stated in this License.
129
+
130
+ 5. Submission of Contributions. Unless You explicitly state otherwise,
131
+ any Contribution intentionally submitted for inclusion in the Work
132
+ by You to the Licensor shall be under the terms and conditions of
133
+ this License, without any additional terms or conditions.
134
+ Notwithstanding the above, nothing herein shall supersede or modify
135
+ the terms of any separate license agreement you may have executed
136
+ with Licensor regarding such Contributions.
137
+
138
+ 6. Trademarks. This License does not grant permission to use the trade
139
+ names, trademarks, service marks, or product names of the Licensor,
140
+ except as required for reasonable and customary use in describing the
141
+ origin of the Work and reproducing the content of the NOTICE file.
142
+
143
+ 7. Disclaimer of Warranty. Unless required by applicable law or
144
+ agreed to in writing, Licensor provides the Work (and each
145
+ Contributor provides its Contributions) on an "AS IS" BASIS,
146
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
147
+ implied, including, without limitation, any warranties or conditions
148
+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
149
+ PARTICULAR PURPOSE. You are solely responsible for determining the
150
+ appropriateness of using or redistributing the Work and assume any
151
+ risks associated with Your exercise of permissions under this License.
152
+
153
+ 8. Limitation of Liability. In no event and under no legal theory,
154
+ whether in tort (including negligence), contract, or otherwise,
155
+ unless required by applicable law (such as deliberate and grossly
156
+ negligent acts) or agreed to in writing, shall any Contributor be
157
+ liable to You for damages, including any direct, indirect, special,
158
+ incidental, or consequential damages of any character arising as a
159
+ result of this License or out of the use or inability to use the
160
+ Work (including but not limited to damages for loss of goodwill,
161
+ work stoppage, computer failure or malfunction, or any and all
162
+ other commercial damages or losses), even if such Contributor
163
+ has been advised of the possibility of such damages.
164
+
165
+ 9. Accepting Warranty or Additional Liability. While redistributing
166
+ the Work or Derivative Works thereof, You may choose to offer,
167
+ and charge a fee for, acceptance of support, warranty, indemnity,
168
+ or other liability obligations and/or rights consistent with this
169
+ License. However, in accepting such obligations, You may act only
170
+ on Your own behalf and on Your sole responsibility, not on behalf
171
+ of any other Contributor, and only if You agree to indemnify,
172
+ defend, and hold each Contributor harmless for any liability
173
+ incurred by, or claims asserted against, such Contributor by reason
174
+ of your accepting any such warranty or additional liability.
175
+
176
+ END OF TERMS AND CONDITIONS
177
+
178
+ APPENDIX: How to apply the Apache License to your work.
179
+
180
+ To apply the Apache License to your work, attach the following
181
+ boilerplate notice, with the fields enclosed by brackets "[]"
182
+ replaced with your own identifying information. (Don't include
183
+ the brackets!) The text should be enclosed in the appropriate
184
+ comment syntax for the file format. We also recommend that a
185
+ file or class name and description of purpose be included on the
186
+ same "printed page" as the copyright notice for easier
187
+ identification within third-party archives.
188
+
189
+ Copyright 2025 OpenAI
190
+
191
+ Licensed under the Apache License, Version 2.0 (the "License");
192
+ you may not use this file except in compliance with the License.
193
+ You may obtain a copy of the License at
194
+
195
+ http://www.apache.org/licenses/LICENSE-2.0
196
+
197
+ Unless required by applicable law or agreed to in writing, software
198
+ distributed under the License is distributed on an "AS IS" BASIS,
199
+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
200
+ See the License for the specific language governing permissions and
201
+ limitations under the License.
MODULE.bazel ADDED
@@ -0,0 +1,843 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ module(name = "codex")
2
+
3
+ bazel_dep(name = "bazel_lib", version = "3.2.2")
4
+ bazel_dep(name = "bazel_skylib", version = "1.9.0")
5
+ bazel_dep(name = "platforms", version = "1.0.0")
6
+
7
+ # Expose the public protobuf rules already used transitively by rules_rs.
8
+ bazel_dep(name = "protobuf", version = "34.0.bcr.1", repo_name = "com_google_protobuf")
9
+ bazel_dep(name = "llvm", version = "0.8.11")
10
+ bazel_dep(name = "windows_support", version = "0.2.0")
11
+
12
+ # Patch hermetic LLVM for Codex's custom libc++ and Windows gnullvm runtime
13
+ # needs that have not landed upstream.
14
+ single_version_override(
15
+ module_name = "llvm",
16
+ patch_strip = 1,
17
+ patches = [
18
+ "//patches:llvm_rusty_v8_custom_libcxx.patch",
19
+ "//patches:llvm_windows_arm64_powl.patch",
20
+ "//patches:llvm_windows_mingw_compat.patch",
21
+ ],
22
+ )
23
+
24
+ # Preserve case-only SDK aliases when native Windows repository setup feeds
25
+ # case-sensitive remote executors.
26
+ single_version_override(
27
+ module_name = "windows_support",
28
+ patch_strip = 1,
29
+ patches = [
30
+ "//patches:windows-support-remote-case-aliases.patch",
31
+ "//patches:windows-support-native-tools.patch",
32
+ ],
33
+ version = "0.2.0",
34
+ )
35
+
36
+ # MSVC repository materialization fails closed until a user who has accepted
37
+ # Microsoft's Visual Studio terms explicitly supplies
38
+ # --repo_env=BAZEL_MSVC_RUNTIME_VISUAL_STUDIO_EULA=1. Do not configure that
39
+ # acceptance globally: Linux, macOS, and Windows GNU do not require it.
40
+ msvc_runtime = use_extension("@windows_support//windows:extensions.bzl", "msvc_runtime")
41
+ msvc_runtime.configure(
42
+ architectures = [
43
+ "x64",
44
+ "arm64",
45
+ ],
46
+ msvc_version = "14.50.35717",
47
+ visual_studio_installer_manifest_integrity = "sha256-qOhU+p8/uurCfXME4pfxZg1xN0ATid61fPeYPzPBb+8=",
48
+ visual_studio_installer_manifest_url = "https://download.visualstudio.microsoft.com/download/pr/fdc37f6e-59f6-4054-838a-b476eeaa6ec3/1d82370739911457e0a2f6be15d8b5f569531b352b2eabb961429eea1e99e356/VisualStudio.vsman",
49
+ )
50
+ use_repo(msvc_runtime, "msvc_runtime")
51
+
52
+ windows_sdk = use_extension("@windows_support//windows:extensions.bzl", "windows_sdk")
53
+ windows_sdk.configure(
54
+ architectures = [
55
+ "x64",
56
+ "arm64",
57
+ ],
58
+ transformations = {
59
+ "base/c/Include/10.0.26100.0/shared/driverspecs.h": "base/c/Include/10.0.26100.0/shared/DriverSpecs.h",
60
+ "base/c/Include/10.0.26100.0/shared/specstrings.h": "base/c/Include/10.0.26100.0/shared/SpecStrings.h",
61
+ "base/c/Include/10.0.26100.0/um/ole2.h": "base/c/Include/10.0.26100.0/um/Ole2.h",
62
+ "base/c/Include/10.0.26100.0/um/olectl.h": "base/c/Include/10.0.26100.0/um/OleCtl.h",
63
+ "**/*.h": "lowercase",
64
+ "**/*.lib": "lowercase",
65
+ "**/*.Lib": "lowercase",
66
+ },
67
+ windows_sdk_integrity = {
68
+ "Microsoft.Windows.SDK.CPP": "sha256-/0VWYL7gcadEcVqWZWZvopwHaBV509gVlZqe7FpVZCQ=",
69
+ "Microsoft.Windows.SDK.CPP.x64": "sha256-rWzpD/lAEGmdKVSLPCseUsieuBFD4hmRVdmlw4ABtSs=",
70
+ "Microsoft.Windows.SDK.CPP.arm64": "sha256-A7wMA9Q5zvhQdLvNQl+dXTptO0Z5Z6zSHaO6bf7q+mc=",
71
+ },
72
+ windows_sdk_version = "10.0.26100.7705",
73
+ )
74
+ use_repo(windows_sdk, "windows_sdk")
75
+
76
+ # Abseil picks a MinGW pthread TLS path that does not match our hermetic
77
+ # windows-gnullvm toolchain; force it onto the portable C++11 thread-local path.
78
+ single_version_override(
79
+ module_name = "abseil-cpp",
80
+ patch_strip = 1,
81
+ patches = [
82
+ "//patches:abseil_windows_gnullvm_thread_identity.patch",
83
+ ],
84
+ )
85
+
86
+ register_toolchains("@llvm//toolchain:all")
87
+
88
+ osx = use_extension("@llvm//extensions:osx.bzl", "osx")
89
+ osx.from_archive(
90
+ sha256 = "5f044578cd78a3a9b9c965a42d56bad609ee5d252e1d4e6aa7c42fc3f35fee7b",
91
+ strip_prefix = "Payload/Library/Developer/CommandLineTools/SDKs/MacOSX26.5.sdk",
92
+ type = "pkg",
93
+ urls = [
94
+ "https://swcdn.apple.com/content/downloads/09/08/047-91568-A_Y1CFZWQCD4/4xekpyz43i26dbp4enxfro8eb1q7wiujh5/CLTools_macOSNMOS_SDK.pkg",
95
+ ],
96
+ )
97
+ osx.frameworks(names = [
98
+ "ApplicationServices",
99
+ "AppKit",
100
+ "ColorSync",
101
+ "CoreFoundation",
102
+ "CoreGraphics",
103
+ "CoreImage",
104
+ "CoreMedia",
105
+ "CoreMIDI",
106
+ "CoreServices",
107
+ "CoreText",
108
+ "CoreVideo",
109
+ "DiskArbitration",
110
+ "AudioToolbox",
111
+ "AVFoundation",
112
+ "AVFAudio",
113
+ "AVRouting",
114
+ "CFNetwork",
115
+ "Cocoa",
116
+ "CoreData",
117
+ "PrintCore",
118
+ "Symbols",
119
+ "FontServices",
120
+ "AudioUnit",
121
+ "CoreAudio",
122
+ "CoreAudioTypes",
123
+ "Foundation",
124
+ "ImageIO",
125
+ "IOSurface",
126
+ "IOKit",
127
+ "Kernel",
128
+ "LocalAuthentication",
129
+ "Metal",
130
+ "MetalKit",
131
+ "OpenGL",
132
+ "OSLog",
133
+ "QuartzCore",
134
+ "ScreenCaptureKit",
135
+ "Security",
136
+ "SystemConfiguration",
137
+ "UniformTypeIdentifiers",
138
+ "VideoToolbox",
139
+ ])
140
+ use_repo(osx, "macos_sdk")
141
+
142
+ # Needed to disable xcode...
143
+ bazel_dep(name = "apple_support", version = "2.1.0")
144
+ bazel_dep(name = "rules_cc", version = "0.2.18")
145
+
146
+ # Windows voice jobs explicitly select the installed MSVC C toolchains.
147
+ cc_configure = use_extension("@rules_cc//cc:extensions.bzl", "cc_configure_extension")
148
+ use_repo(cc_configure, "local_config_cc")
149
+
150
+ single_version_override(
151
+ module_name = "rules_cc",
152
+ patch_strip = 1,
153
+ patches = [
154
+ "//patches:rules_cc_rusty_v8_custom_libcxx.patch",
155
+ ],
156
+ )
157
+
158
+ bazel_dep(name = "rules_platform", version = "0.1.0")
159
+ bazel_dep(name = "aws-lc", version = "5.1.0.bcr.1")
160
+ bazel_dep(name = "rules_rs", version = "0.0.96")
161
+ bazel_dep(name = "rules_foreign_cc", version = "0.15.1")
162
+ single_version_override(
163
+ module_name = "rules_foreign_cc",
164
+ patch_strip = 1,
165
+ patches = [
166
+ "//patches:rules_foreign_cc_make_cppflags.patch",
167
+ "//patches:rules_foreign_cc_make_xcompile.patch",
168
+ "//patches:rules_foreign_cc_make_msvc_stdint.patch",
169
+ ],
170
+ version = "0.15.1",
171
+ )
172
+
173
+ bazel_dep(name = "rules_python", version = "1.7.0")
174
+
175
+ voice_python = use_extension("@rules_python//python/extensions:python.bzl", "python")
176
+ voice_python.defaults(python_version = "3.11")
177
+ voice_python.toolchain(python_version = "3.12")
178
+ use_repo(voice_python, "python_3_12")
179
+
180
+ # Use the existing pinned Make build for foreign_cc consumers, including the
181
+ # native voice pkg-config bootstrap, instead of a PATH-provided Make.
182
+ register_toolchains("@rules_foreign_cc//toolchains:built_make_toolchain")
183
+
184
+ foreign_cc_tools = use_extension("@rules_foreign_cc//foreign_cc:extensions.bzl", "tools")
185
+ use_repo(foreign_cc_tools, "cmake-3.31.8-windows-x86_64", "pkgconfig_src")
186
+
187
+ single_version_override(
188
+ module_name = "rules_rs",
189
+ patch_strip = 1,
190
+ patches = [
191
+ "//patches:rules_rs_build_script_deps_annotation.patch",
192
+ "//patches:rules_rs_windows_msvc_linker.patch",
193
+ "//patches:rules_rs_zlib_snapshot_urls.patch",
194
+ ],
195
+ version = "0.0.96",
196
+ )
197
+
198
+ rules_rust = use_extension("@rules_rs//rs:rules_rust.bzl", "rules_rust")
199
+ rules_rust.patch(
200
+ patches = [
201
+ # Carry the OpenAI setup fix that makes build-script tools available
202
+ # through their runfiles after the rules_rs upgrade.
203
+ "//patches:rules_rust_build_script_tools_transition.patch",
204
+ # Prefer Rust's direct linker for Windows/MSVC and keep hermetic
205
+ # LLVM's non-.lib runtime artifacts compatible with it.
206
+ "//patches:rules_rust_windows_msvc_direct_link_args.patch",
207
+ # Skip transient native-Windows linker outputs while consolidating
208
+ # dependency search paths.
209
+ "//patches:rules_rust_windows_process_wrapper_skip_temp_outputs.patch",
210
+ # Group build-script argument files to avoid Windows command-line limits.
211
+ "//patches:rules_rust_group_build_script_arg_files.patch",
212
+ "//patches:rules_rust_windows_execroot_separators.patch",
213
+ ],
214
+ strip = 1,
215
+ )
216
+ use_repo(rules_rust, "rules_rust")
217
+
218
+ # argument-comment-lint uses rustc_private and needs nightly rustc-dev
219
+ # components. Keep that rules_rust-reexported toolchain separate from the
220
+ # default rules_rs toolchains below, which do not expose dev_components.
221
+ nightly_rust = use_extension(
222
+ "@rules_rs//rs:rules_rust_reexported_extensions.bzl",
223
+ "rust",
224
+ )
225
+ nightly_rust.toolchain(
226
+ dev_components = True,
227
+ edition = "2024",
228
+ versions = ["nightly/2025-09-18"],
229
+ )
230
+
231
+ # Keep the reexported extension's default Windows set constrained to MSVC so
232
+ # it cannot also match the gnullvm host platform.
233
+ nightly_rust.repository_set(
234
+ name = "rust_windows_x86_64",
235
+ dev_components = True,
236
+ edition = "2024",
237
+ exec_compatible_with = [
238
+ "@platforms//cpu:x86_64",
239
+ "@platforms//os:windows",
240
+ "@llvm//constraints/windows/abi:msvc",
241
+ ],
242
+ exec_triple = "x86_64-pc-windows-msvc",
243
+ target_compatible_with = [
244
+ "@platforms//cpu:x86_64",
245
+ "@platforms//os:windows",
246
+ "@llvm//constraints/windows/abi:msvc",
247
+ ],
248
+ target_triple = "x86_64-pc-windows-msvc",
249
+ versions = ["nightly/2025-09-18"],
250
+ )
251
+
252
+ # Also let that MSVC-exec set target gnullvm for existing cross lanes.
253
+ nightly_rust.repository_set(
254
+ name = "rust_windows_x86_64",
255
+ target_compatible_with = [
256
+ "@platforms//cpu:x86_64",
257
+ "@platforms//os:windows",
258
+ "@llvm//constraints/windows/abi:gnullvm",
259
+ "@llvm//constraints/windows/crt:msvcrt",
260
+ ],
261
+ target_triple = "x86_64-pc-windows-gnullvm",
262
+ )
263
+
264
+ # Give Windows lint a native gnullvm exec set so proc-macros link against the
265
+ # same ABI as hermetic LLVM and BCR AWS-LC.
266
+ nightly_rust.repository_set(
267
+ name = "rust_windows_x86_64_gnullvm",
268
+ dev_components = True,
269
+ edition = "2024",
270
+ exec_compatible_with = [
271
+ "@platforms//cpu:x86_64",
272
+ "@platforms//os:windows",
273
+ "@llvm//constraints/windows/abi:gnullvm",
274
+ "@llvm//constraints/windows/crt:msvcrt",
275
+ ],
276
+ exec_triple = "x86_64-pc-windows-gnullvm",
277
+ target_compatible_with = [
278
+ "@platforms//cpu:x86_64",
279
+ "@platforms//os:windows",
280
+ "@llvm//constraints/windows/abi:gnullvm",
281
+ "@llvm//constraints/windows/crt:msvcrt",
282
+ ],
283
+ target_triple = "x86_64-pc-windows-gnullvm",
284
+ versions = ["nightly/2025-09-18"],
285
+ )
286
+ use_repo(nightly_rust, "rust_toolchains")
287
+
288
+ toolchains = use_extension("@rules_rs//rs/toolchains:module_extension.bzl", "toolchains")
289
+ toolchains.toolchain(
290
+ edition = "2024",
291
+ version = "1.95.0",
292
+ )
293
+ use_repo(toolchains, "default_rust_toolchains")
294
+
295
+ register_toolchains("@default_rust_toolchains//:all")
296
+
297
+ register_toolchains("@rust_toolchains//:all")
298
+
299
+ rules_rust_bindgen = use_extension(
300
+ "@rules_rs//rs:rules_rust_bindgen.bzl",
301
+ "rules_rust_bindgen",
302
+ )
303
+ use_repo(rules_rust_bindgen, "rules_rust_bindgen")
304
+
305
+ register_toolchains("@rules_rust_bindgen//:all")
306
+
307
+ # Generate Rust protobuf/gRPC libraries against the workspace's prost/tonic
308
+ # versions instead of the versions bundled with rules_rs's default toolchain.
309
+ register_toolchains("//bazel/toolchains/prost:toolchain")
310
+
311
+ crate = use_extension("@rules_rs//rs:extensions.bzl", "crate")
312
+ crate.from_cargo(
313
+ cargo_lock = "//codex-rs:Cargo.lock",
314
+ cargo_toml = "//codex-rs:Cargo.toml",
315
+ platform_triples = [
316
+ "aarch64-unknown-linux-gnu",
317
+ "aarch64-unknown-linux-musl",
318
+ "aarch64-apple-darwin",
319
+ # Keep both Windows ABIs in the generated Cargo metadata: the V8
320
+ # experiment still consumes release assets that only exist under the
321
+ # MSVC names while targeting the GNU toolchain.
322
+ "aarch64-pc-windows-msvc",
323
+ "aarch64-pc-windows-gnullvm",
324
+ "x86_64-unknown-linux-gnu",
325
+ "x86_64-unknown-linux-musl",
326
+ "x86_64-apple-darwin",
327
+ "x86_64-pc-windows-msvc",
328
+ "x86_64-pc-windows-gnullvm",
329
+ ],
330
+ )
331
+ crate.from_cargo(
332
+ name = "argument_comment_lint_crates",
333
+ cargo_lock = "//tools/argument-comment-lint:Cargo.lock",
334
+ cargo_toml = "//tools/argument-comment-lint:Cargo.toml",
335
+ platform_triples = [
336
+ "aarch64-unknown-linux-gnu",
337
+ "aarch64-unknown-linux-musl",
338
+ "aarch64-apple-darwin",
339
+ "aarch64-pc-windows-msvc",
340
+ "aarch64-pc-windows-gnullvm",
341
+ "x86_64-unknown-linux-gnu",
342
+ "x86_64-unknown-linux-musl",
343
+ "x86_64-apple-darwin",
344
+ "x86_64-pc-windows-msvc",
345
+ "x86_64-pc-windows-gnullvm",
346
+ ],
347
+ )
348
+
349
+ bazel_dep(name = "zstd", version = "1.5.7")
350
+
351
+ crate.annotation(
352
+ # The Windows lint toolchain cannot reliably materialize blake3's native x86 assembly archives.
353
+ crate = "blake3",
354
+ crate_features_select = {
355
+ "x86_64-pc-windows-gnullvm": ["pure"],
356
+ },
357
+ )
358
+ crate.annotation(
359
+ crate = "zstd-sys",
360
+ gen_build_script = "on",
361
+ patch_args = ["-p1"],
362
+ patches = [
363
+ "//patches:zstd-sys_windows_msvc_include_dirs.patch",
364
+ ],
365
+ )
366
+ crate.annotation(
367
+ crate = "ring",
368
+ patch_args = ["-p1"],
369
+ patches = [
370
+ "//patches:ring_windows_msvc_include_dirs.patch",
371
+ ],
372
+ )
373
+ crate.annotation(
374
+ additive_build_file = "@rules_rs//3rd_party/aws-lc-sys:additive.BUILD.bazel",
375
+ crate = "aws-lc-sys",
376
+ extra_aliased_targets = {"aws_lc_sys_build_info": "aws_lc_sys_build_info"},
377
+ gen_build_script = "off",
378
+ repositories = ["crates"],
379
+ rustc_flags = ["--cfg=use_bindgen_pregenerated"],
380
+ deps = ["@crates//:aws_lc_sys_build_info"],
381
+ )
382
+ crate.annotation(
383
+ crate = "aws-lc-rs",
384
+ gen_build_script = "off",
385
+ repositories = ["crates"],
386
+ )
387
+ crate.annotation(
388
+ # The build script only validates embedded source/version metadata.
389
+ crate = "rustc_apfloat",
390
+ gen_build_script = "off",
391
+ )
392
+
393
+ inject_repo(crate, "aws-lc")
394
+
395
+ inject_repo(crate, "zstd")
396
+
397
+ use_repo(crate, "argument_comment_lint_crates")
398
+
399
+ bazel_dep(name = "bzip2", version = "1.0.8.bcr.3")
400
+ single_version_override(
401
+ module_name = "bzip2",
402
+ patch_strip = 1,
403
+ patches = [
404
+ "//patches:bzip2_windows_stack_args.patch",
405
+ ],
406
+ )
407
+
408
+ crate.annotation(
409
+ crate = "bzip2-sys",
410
+ gen_build_script = "off",
411
+ deps = ["@bzip2//:bz2"],
412
+ )
413
+
414
+ inject_repo(crate, "bzip2")
415
+
416
+ bazel_dep(name = "zlib", version = "1.3.1.bcr.8")
417
+
418
+ crate.annotation(
419
+ crate = "libz-sys",
420
+ gen_build_script = "on",
421
+ )
422
+
423
+ inject_repo(crate, "zlib")
424
+
425
+ bazel_dep(name = "xz", version = "5.4.5.bcr.8")
426
+ single_version_override(
427
+ module_name = "xz",
428
+ patch_strip = 1,
429
+ patches = [
430
+ "//patches:xz_windows_stack_args.patch",
431
+ ],
432
+ )
433
+
434
+ crate.annotation(
435
+ crate = "lzma-sys",
436
+ gen_build_script = "off",
437
+ deps = ["@xz//:lzma"],
438
+ )
439
+
440
+ bazel_dep(name = "openssl", version = "3.5.4.bcr.0")
441
+
442
+ inject_repo(crate, "xz")
443
+
444
+ crate.annotation(
445
+ build_script_data = [
446
+ "@openssl//:gen_dir",
447
+ ],
448
+ # Build scripts compile in Bazel's exec configuration, so target-specific
449
+ # optional build deps are otherwise dropped for the musl release platforms.
450
+ build_script_deps = [
451
+ "@crates//:openssl-src-300.6.1+3.6.3",
452
+ ],
453
+ build_script_env = {
454
+ "OPENSSL_DIR": "$(execpath @openssl//:gen_dir)",
455
+ "OPENSSL_NO_VENDOR": "1",
456
+ "OPENSSL_STATIC": "1",
457
+ },
458
+ crate = "openssl-sys",
459
+ data = ["@openssl//:gen_dir"],
460
+ gen_build_script = "on",
461
+ )
462
+
463
+ inject_repo(crate, "openssl")
464
+
465
+ crate.annotation(
466
+ crate = "runfiles",
467
+ workspace_cargo_toml = "rust/runfiles/Cargo.toml",
468
+ )
469
+
470
+ # MXC keeps its Rust workspace below the repository root.
471
+ [
472
+ crate.annotation(
473
+ crate = name,
474
+ workspace_cargo_toml = "src/Cargo.toml",
475
+ )
476
+ for name in [
477
+ "appcontainer_common",
478
+ "learning_mode_core",
479
+ "learning_mode_windows",
480
+ "mxc_config_contract",
481
+ "mxc_telemetry",
482
+ "process_security_environment_spec",
483
+ "sandbox_spec",
484
+ "wxc_common",
485
+ ]
486
+ ]
487
+
488
+ http_archive = use_repo_rule("@bazel_tools//tools/build_defs/repo:http.bzl", "http_archive")
489
+
490
+ codex_release_archive = use_extension(
491
+ "//bazel/extensions:codex_release_archive.bzl",
492
+ "codex_release_archive",
493
+ )
494
+ codex_release_archive.release(
495
+ sha256 = "0b7afd1de4ecf06a8633f1e4958ec5f8d57d4b7842773416d9cb9d8c816f2c84",
496
+ version = "0.153.1",
497
+ )
498
+ codex_release_archive.release(
499
+ sha256 = "71a28d362c96ac9829bf8203a2c71be451aeb726adb843167fdaf0eae8fe7dd9",
500
+ version = "0.145.0",
501
+ )
502
+ use_repo(
503
+ codex_release_archive,
504
+ "codex_release_0.145.0_linux_x86_64",
505
+ "codex_release_0.153.1_linux_x86_64",
506
+ )
507
+
508
+ http_file = use_repo_rule("@bazel_tools//tools/build_defs/repo:http.bzl", "http_file")
509
+
510
+ new_local_repository = use_repo_rule("@bazel_tools//tools/build_defs/repo:local.bzl", "new_local_repository")
511
+
512
+ include("//bazel/modules:wine.MODULE.bazel")
513
+
514
+ voice_sources = use_extension("//third_party/voice:extensions.bzl", "voice_sources")
515
+ use_repo(
516
+ voice_sources,
517
+ "voice_archive_glib",
518
+ "voice_archive_gst_plugins_base",
519
+ "voice_archive_gst_plugins_good",
520
+ "voice_archive_gstreamer",
521
+ "voice_archive_libffi",
522
+ "voice_archive_meson",
523
+ "voice_archive_ninja",
524
+ "voice_archive_opus",
525
+ "voice_archive_pcre2",
526
+ "voice_archive_proxy_libintl",
527
+ "voice_archive_zlib",
528
+ "voice_glib",
529
+ "voice_gst_plugins_base",
530
+ "voice_gst_plugins_good",
531
+ "voice_gstreamer",
532
+ "voice_libffi",
533
+ "voice_meson",
534
+ "voice_ninja",
535
+ "voice_opus",
536
+ "voice_pcre2",
537
+ "voice_proxy_libintl",
538
+ "voice_zlib",
539
+ )
540
+
541
+ new_local_repository(
542
+ name = "v8_targets",
543
+ build_file = "//third_party/v8:BUILD.bazel",
544
+ path = "third_party/v8",
545
+ )
546
+
547
+ crate.annotation(
548
+ build_script_data = [
549
+ "@v8_targets//:rusty_v8_archive_for_target",
550
+ "@v8_targets//:rusty_v8_binding_for_target",
551
+ ],
552
+ build_script_env = {
553
+ "RUSTY_V8_ARCHIVE": "$(execpath @v8_targets//:rusty_v8_archive_for_target)",
554
+ "RUSTY_V8_SRC_BINDING_PATH": "$(execpath @v8_targets//:rusty_v8_binding_for_target)",
555
+ },
556
+ crate = "v8",
557
+ # Keep the Rust feature aligned with the source-built Bazel artifacts.
558
+ # Windows MSVC still consumes upstream non-sandboxed prebuilts.
559
+ crate_features_select = {
560
+ "aarch64-apple-darwin": ["v8_enable_sandbox"],
561
+ "aarch64-pc-windows-gnullvm": ["v8_enable_sandbox"],
562
+ "aarch64-pc-windows-msvc": ["v8_enable_sandbox"],
563
+ "aarch64-unknown-linux-gnu": ["v8_enable_sandbox"],
564
+ "aarch64-unknown-linux-musl": ["v8_enable_sandbox"],
565
+ "x86_64-apple-darwin": ["v8_enable_sandbox"],
566
+ "x86_64-pc-windows-gnullvm": ["v8_enable_sandbox"],
567
+ "x86_64-pc-windows-msvc": ["v8_enable_sandbox"],
568
+ "x86_64-unknown-linux-gnu": ["v8_enable_sandbox"],
569
+ "x86_64-unknown-linux-musl": ["v8_enable_sandbox"],
570
+ },
571
+ gen_build_script = "on",
572
+ patch_args = ["-p1"],
573
+ patches = [
574
+ "//patches:rusty_v8_prebuilt_out_dir.patch",
575
+ ],
576
+ )
577
+
578
+ inject_repo(crate, "v8_targets")
579
+
580
+ llvm = use_extension("@llvm//extensions:llvm.bzl", "llvm")
581
+ use_repo(llvm, "llvm-project")
582
+
583
+ crate.annotation(
584
+ # Provide the hermetic SDK path so the build script doesn't try to invoke an unhermetic `xcrun --show-sdk-path`.
585
+ build_script_data = [
586
+ "@macos_sdk//sysroot",
587
+ ],
588
+ build_script_env = {
589
+ "BINDGEN_EXTRA_CLANG_ARGS": "-Xclang -internal-isystem -Xclang $(location @llvm//:builtin_resource_dir)/include",
590
+ "COREAUDIO_SDK_PATH": "$(location @macos_sdk//sysroot)",
591
+ "LIBCLANG_PATH": "$(location @llvm-project//clang:libclang_interface_output)",
592
+ },
593
+ build_script_tools = [
594
+ "@llvm-project//clang:libclang_interface_output",
595
+ "@llvm//:builtin_resource_dir",
596
+ ],
597
+ crate = "coreaudio-sys",
598
+ gen_build_script = "on",
599
+ )
600
+
601
+ inject_repo(crate, "llvm", "llvm-project", "macos_sdk")
602
+
603
+ # The bundled Opus encoder uses CMake; supply executable tools and their data,
604
+ # rather than relying on a build worker's PATH. Versions are pinned by the module.
605
+ crate.annotation(
606
+ build_script_data = ["//third_party/voice:opus-toolchain.cmake"],
607
+ build_script_env = {
608
+ "CMAKE": "$${pwd}/$(CMAKE)",
609
+ "CMAKE_GENERATOR": "Ninja",
610
+ "CMAKE_TOOLCHAIN_FILE": "$(execpath @@//third_party/voice:opus-toolchain.cmake)",
611
+ "CODEX_VOICE_NINJA": "$${pwd}/$(NINJA)",
612
+ },
613
+ build_script_toolchains = [
614
+ "@rules_foreign_cc//toolchains:current_cmake_toolchain",
615
+ "@rules_foreign_cc//toolchains:current_ninja_toolchain",
616
+ ],
617
+ build_script_tools = [
618
+ "@rules_foreign_cc//toolchains:current_cmake_toolchain",
619
+ "@rules_foreign_cc//toolchains:current_ninja_toolchain",
620
+ ],
621
+ crate = "opusic-sys",
622
+ )
623
+
624
+ # The musl CLI's allocator needs declared native tools and consistent header flags.
625
+ crate.annotation(
626
+ build_script_env = {
627
+ "MAKE": "$${pwd}/$(MAKE)",
628
+ "NM": "$${pwd}/$(execpath @llvm//tools:llvm-nm)",
629
+ "RANLIB": "$${pwd}/$(execpath @llvm//tools:llvm-ranlib)",
630
+ },
631
+ build_script_toolchains = ["@rules_foreign_cc//toolchains:current_make_toolchain"],
632
+ build_script_tools = [
633
+ "@llvm//tools:llvm-nm",
634
+ "@llvm//tools:llvm-ranlib",
635
+ "@rules_foreign_cc//toolchains:current_make_toolchain",
636
+ ],
637
+ crate = "tikv-jemalloc-sys",
638
+ patch_args = ["-p1"],
639
+ patches = [
640
+ "//patches:tikv-jemalloc-sys_make_env.patch",
641
+ "//patches:tikv-jemalloc-sys_dependency_flags.patch",
642
+ ],
643
+ )
644
+
645
+ inject_repo(crate, "rules_foreign_cc")
646
+
647
+ crate.annotation(
648
+ # Provide the hermetic SDK path so the build script doesn't try to invoke an unavailable `xcrun --show-sdk-path`.
649
+ build_script_data = [
650
+ "@macos_sdk//sysroot",
651
+ ],
652
+ build_script_env = {
653
+ "WEBRTC_SYS_DARWIN_SDK_PATH": "$(location @macos_sdk//sysroot)",
654
+ "WEBRTC_SYS_LINK_OUT_DIR": "1",
655
+ },
656
+ crate = "webrtc-sys",
657
+ gen_build_script = "on",
658
+ patch_args = ["-p1"],
659
+ patches = [
660
+ "//patches:webrtc-sys_hermetic_darwin_sysroot.patch",
661
+ ],
662
+ )
663
+
664
+ # Fix readme inclusions
665
+ crate.annotation(
666
+ crate = "windows-link",
667
+ patch_args = ["-p1"],
668
+ patches = [
669
+ "//patches:windows-link.patch",
670
+ ],
671
+ )
672
+
673
+ bazel_dep(name = "alsa_lib", version = "1.2.9.bcr.4")
674
+
675
+ crate.annotation(
676
+ crate = "alsa-sys",
677
+ gen_build_script = "off",
678
+ deps = ["@alsa_lib"],
679
+ )
680
+
681
+ inject_repo(crate, "alsa_lib")
682
+
683
+ # Keep upstream pkg-config version probes, but link only the prepared runtime.
684
+ # system-deps applies these path/flag overrides after a successful version probe.
685
+ [
686
+ crate.annotation(
687
+ build_script_data = [
688
+ "//third_party/voice:native_link",
689
+ "//third_party/voice:native_sdk",
690
+ ],
691
+ build_script_env = {
692
+ "PKG_CONFIG": "$(execpath @@//third_party/voice:pkg_config)",
693
+ "PKG_CONFIG_LIBDIR": "$(execpath @@//third_party/voice:native_sdk)/lib/pkgconfig",
694
+ "PKG_CONFIG_PATH": "",
695
+ } | {
696
+ "SYSTEM_DEPS_" + key + "_SEARCH_NATIVE": "$(execpath @@//third_party/voice:native_link)/.."
697
+ for key in keys
698
+ } | {
699
+ # GStreamer's .pc files add an absolute rpath; CcInfo supplies the
700
+ # relative Bazel runpath instead. Library/version checks still run.
701
+ "SYSTEM_DEPS_" + key + "_LDFLAGS": ""
702
+ for key in keys
703
+ if key.startswith("GSTREAMER_")
704
+ },
705
+ build_script_tools = ["//third_party/voice:pkg_config"],
706
+ crate = name,
707
+ gen_build_script = "on",
708
+ version = version,
709
+ deps = ["//third_party/voice:native_link"],
710
+ )
711
+ for name, version, keys in [
712
+ (
713
+ "glib-sys",
714
+ "0.22.8",
715
+ [
716
+ "GLIB_2_0",
717
+ "GOBJECT_2_0",
718
+ ],
719
+ ),
720
+ (
721
+ "gobject-sys",
722
+ "0.22.6",
723
+ ["GOBJECT_2_0"],
724
+ ),
725
+ (
726
+ "gio-sys",
727
+ "0.22.8",
728
+ ["GIO_2_0"],
729
+ ),
730
+ (
731
+ "gstreamer-sys",
732
+ "0.25.2",
733
+ ["GSTREAMER_1_0"],
734
+ ),
735
+ (
736
+ "gstreamer-base-sys",
737
+ "0.25.3",
738
+ ["GSTREAMER_BASE_1_0"],
739
+ ),
740
+ (
741
+ "gstreamer-app-sys",
742
+ "0.25.0",
743
+ ["GSTREAMER_APP_1_0"],
744
+ ),
745
+ (
746
+ "gstreamer-audio-sys",
747
+ "0.25.3",
748
+ ["GSTREAMER_AUDIO_1_0"],
749
+ ),
750
+ (
751
+ "glib-sys",
752
+ "0.22.9",
753
+ [
754
+ "GLIB_2_0",
755
+ "GOBJECT_2_0",
756
+ ],
757
+ ),
758
+ (
759
+ "gobject-sys",
760
+ "0.22.9",
761
+ ["GOBJECT_2_0"],
762
+ ),
763
+ (
764
+ "gio-sys",
765
+ "0.22.9",
766
+ ["GIO_2_0"],
767
+ ),
768
+ ]
769
+ ]
770
+
771
+ bazel_dep(name = "v8", version = "15.0.245.2")
772
+ archive_override(
773
+ module_name = "v8",
774
+ integrity = "sha256-Fk89PgqLTAKjhtOojRsRM9N+XCC+Ajn+zc3eQUpDQNU=",
775
+ patch_strip = 3,
776
+ patches = [
777
+ "//patches:v8_module_deps.patch",
778
+ "//patches:v8_bazel_rules.patch",
779
+ "//patches:v8_source_portability.patch",
780
+ ],
781
+ strip_prefix = "v8-15.0.245.2",
782
+ urls = ["https://github.com/v8/v8/archive/refs/tags/15.0.245.2.tar.gz"],
783
+ )
784
+
785
+ http_archive(
786
+ name = "v8_crate_150_4_0",
787
+ build_file = "//third_party/v8:v8_crate.BUILD.bazel",
788
+ sha256 = "42a978ff11f15b24e5c05a7123cf2b68f41e763546699781a924ef4e2cf43a49",
789
+ strip_prefix = "v8-150.4.0",
790
+ type = "tar.gz",
791
+ urls = ["https://static.crates.io/crates/v8/v8-150.4.0.crate"],
792
+ )
793
+
794
+ git_repository = use_repo_rule("@bazel_tools//tools/build_defs/repo:git.bzl", "git_repository")
795
+
796
+ git_repository(
797
+ name = "rusty_v8_libcxx",
798
+ build_file = "//third_party/v8:libcxx.BUILD.bazel",
799
+ commit = "5abc7f839700f0f17338434e1c1c6a8c87c00c11",
800
+ remote = "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libcxx.git",
801
+ )
802
+
803
+ git_repository(
804
+ name = "rusty_v8_libcxxabi",
805
+ build_file = "//third_party/v8:libcxxabi.BUILD.bazel",
806
+ commit = "8f11bb1d4438d0239d0dfc1bd9456a9f31629dda",
807
+ remote = "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libcxxabi.git",
808
+ )
809
+
810
+ git_repository(
811
+ name = "rusty_v8_llvm_libc",
812
+ build_file = "//third_party/v8:llvm_libc.BUILD.bazel",
813
+ commit = "9309c117ebae84dd2f9df1ef99de4782162527d5",
814
+ remote = "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libc.git",
815
+ )
816
+
817
+ http_file(
818
+ name = "rusty_v8_150_4_0_aarch64_pc_windows_msvc_archive",
819
+ downloaded_file_path = "rusty_v8_release_aarch64-pc-windows-msvc.lib.gz",
820
+ sha256 = "54722842af36b74248c403ff531254efac6ff65d281198bab0c6350fc1188ad4",
821
+ urls = [
822
+ "https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/rusty_v8_ptrcomp_sandbox_release_aarch64-pc-windows-msvc.lib.gz",
823
+ ],
824
+ )
825
+
826
+ http_file(
827
+ name = "rusty_v8_150_4_0_x86_64_pc_windows_msvc_archive",
828
+ downloaded_file_path = "rusty_v8_release_x86_64-pc-windows-msvc.lib.gz",
829
+ sha256 = "732ec5da4243aa166799780c8519a5eea6f32f6e47657a323342794dc3c239d6",
830
+ urls = [
831
+ "https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/rusty_v8_ptrcomp_sandbox_release_x86_64-pc-windows-msvc.lib.gz",
832
+ ],
833
+ )
834
+
835
+ use_repo(crate, "crates")
836
+
837
+ bazel_dep(name = "libcap", version = "2.27.bcr.1")
838
+
839
+ rbe_platform_repository = use_repo_rule("//:rbe.bzl", "rbe_platform_repository")
840
+
841
+ rbe_platform_repository(
842
+ name = "rbe_platform",
843
+ )
MODULE.bazel.lock ADDED
The diff for this file is too large to render. See raw diff
 
NOTICE ADDED
@@ -0,0 +1,6 @@
 
 
 
 
 
 
 
1
+ OpenAI Codex
2
+ Copyright 2025 OpenAI
3
+
4
+ This project includes code derived from [Ratatui](https://github.com/ratatui/ratatui), licensed under the MIT license.
5
+ Copyright (c) 2016-2022 Florian Dehau
6
+ Copyright (c) 2023-2025 The Ratatui Developers
README.md ADDED
@@ -0,0 +1,93 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ ---
2
+ license: apache-2.0
3
+ tags:
4
+ - agent
5
+ - coding-agent
6
+ - cli
7
+ - llm
8
+ - tool-use
9
+ ---
10
+
11
+ > **This is a source mirror.** This Hugging Face repository is not a model checkpoint — it's a read-only mirror of the [`openai/codex`](https://github.com/openai/codex) GitHub repository, OpenAI's local coding agent CLI. It is hosted here for visibility on the Hub; the canonical repository, issue tracker, and pull requests all live on GitHub. Please file issues and contribute there, not here.
12
+
13
+ <p align="center"><strong>Codex CLI</strong> is a coding agent from OpenAI that runs locally on your computer.
14
+ <p align="center">
15
+ <img src="https://github.com/openai/codex/blob/main/.github/codex-cli-splash.png" alt="Codex CLI splash" width="80%" />
16
+ </p>
17
+ </br>
18
+ If you want Codex in your code editor (VS Code, Cursor, Windsurf), <a href="https://developers.openai.com/codex/ide">install in your IDE.</a>
19
+ </br>If you want the desktop app experience, run <code>codex app</code> or visit <a href="https://chatgpt.com/codex?app-landing-page=true">the Codex App page</a>.
20
+ </br>If you are looking for the <em>cloud-based agent</em> from OpenAI, <strong>Codex Web</strong>, go to <a href="https://chatgpt.com/codex">chatgpt.com/codex</a>.</p>
21
+
22
+ ---
23
+
24
+ ## Quickstart
25
+
26
+ ### Installing and running Codex CLI
27
+
28
+ Run the following on Mac or Linux to install Codex CLI:
29
+
30
+ ```shell
31
+ curl -fsSL https://chatgpt.com/codex/install.sh | sh
32
+ ```
33
+
34
+ Run the following on Windows to install Codex CLI:
35
+
36
+ ```shell
37
+ powershell -ExecutionPolicy ByPass -c "irm https://chatgpt.com/codex/install.ps1 | iex"
38
+ ```
39
+
40
+ The standalone installers download from `https://releases.openai.com/codex` by default and fall back to GitHub Releases if a metadata or asset download is unavailable. To force GitHub Releases, set `CODEX_INSTALLER_USE_RELEASES_OPENAI_COM` to `false` (`0` and `no` are also accepted):
41
+
42
+ ```shell
43
+ curl -fsSL https://chatgpt.com/codex/install.sh | CODEX_INSTALLER_USE_RELEASES_OPENAI_COM=false sh
44
+ ```
45
+
46
+ ```powershell
47
+ $env:CODEX_INSTALLER_USE_RELEASES_OPENAI_COM='false'; irm https://chatgpt.com/codex/install.ps1 | iex
48
+ ```
49
+
50
+ Codex CLI can also be installed via the following package managers:
51
+
52
+ ```shell
53
+ # Install using npm
54
+ npm install -g @openai/codex
55
+ ```
56
+
57
+ ```shell
58
+ # Install using Homebrew
59
+ brew install --cask codex
60
+ ```
61
+
62
+ Then simply run `codex` to get started.
63
+
64
+ <details>
65
+ <summary>You can also go to the <a href="https://github.com/openai/codex/releases/latest">latest GitHub Release</a> and download the appropriate binary for your platform.</summary>
66
+
67
+ Each GitHub Release contains many executables, but in practice, you likely want one of these:
68
+
69
+ - macOS
70
+ - Apple Silicon/arm64: `codex-aarch64-apple-darwin.tar.gz`
71
+ - x86_64 (older Mac hardware): `codex-x86_64-apple-darwin.tar.gz`
72
+ - Linux
73
+ - x86_64: `codex-x86_64-unknown-linux-musl.tar.gz`
74
+ - arm64: `codex-aarch64-unknown-linux-musl.tar.gz`
75
+
76
+ Each archive contains a single entry with the platform baked into the name (e.g., `codex-x86_64-unknown-linux-musl`), so you likely want to rename it to `codex` after extracting it.
77
+
78
+ </details>
79
+
80
+ ### Using Codex with your ChatGPT plan
81
+
82
+ Run `codex` and select **Sign in with ChatGPT**. We recommend signing into your ChatGPT account to use Codex as part of your Plus, Pro, Business, Edu, or Enterprise plan. [Learn more about what's included in your ChatGPT plan](https://help.openai.com/en/articles/11369540-codex-in-chatgpt).
83
+
84
+ You can also use Codex with an API key, but this requires [additional setup](https://developers.openai.com/codex/auth#sign-in-with-an-api-key).
85
+
86
+ ## Docs
87
+
88
+ - [**Codex Documentation**](https://developers.openai.com/codex)
89
+ - [**Contributing**](./docs/contributing.md)
90
+ - [**Installing & building**](./docs/install.md)
91
+ - [**Open source fund**](./docs/open-source-fund.md)
92
+
93
+ This repository is licensed under the [Apache-2.0 License](LICENSE).
SECURITY.md ADDED
@@ -0,0 +1,17 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # Security Policy
2
+
3
+ Thank you for helping us keep Codex secure!
4
+
5
+ ## Reporting Security Issues
6
+
7
+ The security is essential to OpenAI's mission. We appreciate the work of security researchers acting in good faith to identify and responsibly report potential vulnerabilities, helping us maintain strong privacy and security standards for our users and technology.
8
+
9
+ Our security program is managed through Bugcrowd, and we ask that any validated vulnerabilities be reported via the [Bugcrowd program](https://bugcrowd.com/engagements/openai).
10
+
11
+ ## Vulnerability Disclosure Program
12
+
13
+ Our Vulnerability Program Guidelines are defined on our [Bugcrowd program page](https://bugcrowd.com/engagements/openai).
14
+
15
+ ## How to operate CODEX safely
16
+
17
+ For details on Codex security boundaries, including sandboxing, approvals, and network controls, see [Agent approvals & security](https://developers.openai.com/codex/agent-approvals-security).
announcement_tip.toml ADDED
@@ -0,0 +1,17 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # Example announcement tips for Codex TUI.
2
+ # Each [[announcements]] entry is evaluated in order; the last matching one is shown.
3
+ # Dates are UTC, formatted as YYYY-MM-DD. The from_date is inclusive and the to_date is exclusive.
4
+ # version_regex matches against the CLI version (env!("CARGO_PKG_VERSION")); omit to apply to all versions.
5
+ # target_app specify which app should display the announcement (cli, vsce, ...).
6
+
7
+ # Test announcement only for local build version until 2027-05-10 excluded
8
+ [[announcements]]
9
+ content = "This is a test announcement"
10
+ version_regex = "^0\\.0\\.0$"
11
+ to_date = "2027-05-10"
12
+
13
+ [[announcements]]
14
+ content = "Update Required - This version will no longer be supported starting May 8th. Please upgrade to the latest version (https://github.com/openai/codex/releases/latest) using your preferred package manager."
15
+ # Matches 0.x.y versions from 0.0.y through 0.119.y; excludes 0.120.0 and newer.
16
+ version_regex = "^0\\.(?:[0-9]|[1-9][0-9]|1[01][0-9])\\."
17
+ to_date = "2026-05-08"
codex-cli/.gitignore ADDED
@@ -0,0 +1 @@
 
 
1
+ /vendor/
codex-cli/package.json ADDED
@@ -0,0 +1,22 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "name": "@openai/codex",
3
+ "version": "0.0.0-dev",
4
+ "description": "Codex CLI is a coding agent from OpenAI that runs locally on your computer.",
5
+ "license": "Apache-2.0",
6
+ "bin": {
7
+ "codex": "bin/codex.js"
8
+ },
9
+ "type": "module",
10
+ "engines": {
11
+ "node": ">=16"
12
+ },
13
+ "files": [
14
+ "bin/codex.js"
15
+ ],
16
+ "repository": {
17
+ "type": "git",
18
+ "url": "git+https://github.com/openai/codex.git",
19
+ "directory": "codex-cli"
20
+ },
21
+ "packageManager": "pnpm@10.34.5+sha512.a4ee05f2f73658255bd6a89859c065a45c28a57daefae2c893a168ee2b73168c37b91e83e57ea67654ad03f03031746430e8bce38e362e042605fb8abc80192e"
22
+ }
codex-rs/.gitignore ADDED
@@ -0,0 +1,2 @@
 
 
 
1
+ /target/
2
+ /target-*/
codex-rs/BUILD.bazel ADDED
@@ -0,0 +1,26 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ exports_files([
2
+ "clippy.toml",
3
+ ])
4
+
5
+ filegroup(
6
+ name = "workspace-files",
7
+ srcs = glob(
8
+ [
9
+ "*",
10
+ ".cargo/**",
11
+ ],
12
+ exclude = [
13
+ "BUILD.bazel",
14
+ ],
15
+ ),
16
+ visibility = ["//visibility:public"],
17
+ )
18
+
19
+ test_suite(
20
+ name = "e2e-benchmarks",
21
+ tags = ["manual"],
22
+ tests = [
23
+ "//codex-rs/cli:codex-help-bench",
24
+ ],
25
+ visibility = ["//visibility:public"],
26
+ )
codex-rs/Cargo.lock ADDED
The diff for this file is too large to render. See raw diff
 
codex-rs/Cargo.toml ADDED
@@ -0,0 +1,632 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ [workspace]
2
+ members = [
3
+ "aws-auth",
4
+ "analytics",
5
+ "agent-graph-store",
6
+ "agent-identity",
7
+ "agent-roles",
8
+ "backend-client",
9
+ "bwrap",
10
+ "build-info",
11
+ "ansi-escape",
12
+ "attachment-store",
13
+ "async-utils",
14
+ "app-server",
15
+ "app-server-transport",
16
+ "app-server-daemon",
17
+ "app-server-client",
18
+ "app-server-protocol",
19
+ "app-server-protocol-noop-macros",
20
+ "app-server-test-client",
21
+ "apply-patch",
22
+ "arg0",
23
+ "feedback",
24
+ "features",
25
+ "install-context",
26
+ "codex-backend-openapi-models",
27
+ "code-mode",
28
+ "code-mode-host",
29
+ "code-mode-protocol",
30
+ "code-mode-runtime",
31
+ "codex-home",
32
+ "cloud-config",
33
+ "cloud-tasks",
34
+ "cloud-tasks-client",
35
+ "cloud-tasks-mock-client",
36
+ "cli",
37
+ "collaboration-mode-templates",
38
+ "connectors",
39
+ "config",
40
+ "config-schema",
41
+ "context-fragments",
42
+ "shell-command",
43
+ "shell-escalation",
44
+ "skills",
45
+ "core",
46
+ "core-api",
47
+ "core-plugins",
48
+ "diagnostics",
49
+ "guardian-context",
50
+ "hooks",
51
+ "history",
52
+ "http-client",
53
+ "secrets",
54
+ "exec",
55
+ "file-system",
56
+ "exec-server-protocol",
57
+ "exec-server",
58
+ "exec-server/tests/support",
59
+ "execpolicy",
60
+ "ext/agent",
61
+ "ext/connectors",
62
+ "ext/extension-api",
63
+ "ext/goal",
64
+ "ext/git-attribution",
65
+ "ext/guardian-reviewer",
66
+ "ext/guardian-v2",
67
+ "ext/history-notes",
68
+ "ext/image-generation",
69
+ "ext/items",
70
+ "ext/memories",
71
+ "ext/mcp",
72
+ "ext/queue",
73
+ "ext/skills",
74
+ "ext/web-search",
75
+ "external-agent-migration",
76
+ "keyring-store",
77
+ "file-search",
78
+ "file-watcher",
79
+ "linux-sandbox",
80
+ "lmstudio",
81
+ "login",
82
+ "codex-mcp",
83
+ "memories/read",
84
+ "memories/write",
85
+ "mermaid",
86
+ "model-provider-info",
87
+ "mxc-sandbox",
88
+ "models-manager",
89
+ "network-proxy",
90
+ "ollama",
91
+ "process-hardening",
92
+ "realtime-webrtc",
93
+ "voice-host",
94
+ "protocol",
95
+ "prompts",
96
+ "rollout",
97
+ "rollout-trace",
98
+ "rmcp-client",
99
+ "responses-api-proxy",
100
+ "response-debug-context",
101
+ "sandboxing",
102
+ "stdio-to-uds",
103
+ "otel",
104
+ "otel-trace-websocket",
105
+ "tcp-tunnel",
106
+ "tui",
107
+ "user-verification",
108
+ "tools",
109
+ "v8-poc",
110
+ "websocket-client",
111
+ "windows-sandbox-service",
112
+ "worktree",
113
+ "workload-identity",
114
+ "utils/absolute-path",
115
+ "utils/audio",
116
+ "utils/path-uri",
117
+ "utils/cargo-bin",
118
+ "git-utils",
119
+ "utils/cache",
120
+ "utils/git-discovery",
121
+ "utils/image",
122
+ "utils/json-to-toml",
123
+ "utils/home-dir",
124
+ "utils/pty",
125
+ "utils/readiness",
126
+ "utils/redacted-string",
127
+ "utils/rustls-provider",
128
+ "utils/string",
129
+ "utils/cli",
130
+ "utils/elapsed",
131
+ "utils/sandbox-summary",
132
+ "utils/sleep-inhibitor",
133
+ "utils/approval-presets",
134
+ "utils/oss",
135
+ "utils/output-truncation",
136
+ "utils/path-utils",
137
+ "utils/plugins",
138
+ "utils/fuzzy-match",
139
+ "utils/stream-parser",
140
+ "utils/template",
141
+ "codex-client",
142
+ "codex-api",
143
+ "state",
144
+ "terminal-detection",
145
+ "test-binary-support",
146
+ "thread-manager-sample",
147
+ "thread-store",
148
+ "uds",
149
+ "codex-experimental-api-macros",
150
+ "plugin",
151
+ "model-provider",
152
+ ]
153
+ resolver = "2"
154
+
155
+ [workspace.package]
156
+ version = "0.0.0"
157
+ # Track the edition for all workspace crates in one place. Individual
158
+ # crates can still override this value, but keeping it here means new
159
+ # crates created with `cargo new -w ...` automatically inherit the 2024
160
+ # edition.
161
+ edition = "2024"
162
+ license = "Apache-2.0"
163
+
164
+ [workspace.dependencies]
165
+ # Internal
166
+ codex-realtime-webrtc = { path = "realtime-webrtc" }
167
+ app_test_support = { path = "app-server/tests/common" }
168
+ codex-analytics = { path = "analytics" }
169
+ codex-agent-graph-store = { path = "agent-graph-store" }
170
+ codex-agent-identity = { path = "agent-identity" }
171
+ codex-agent-roles = { path = "agent-roles" }
172
+ codex-ansi-escape = { path = "ansi-escape" }
173
+ codex-api = { path = "codex-api" }
174
+ codex-attachment-store = { path = "attachment-store" }
175
+ codex-aws-auth = { path = "aws-auth" }
176
+ codex-app-server = { path = "app-server" }
177
+ codex-app-server-transport = { path = "app-server-transport" }
178
+ codex-app-server-daemon = { path = "app-server-daemon" }
179
+ codex-app-server-client = { path = "app-server-client" }
180
+ codex-app-server-protocol = { path = "app-server-protocol" }
181
+ codex-app-server-protocol-noop-macros = { path = "app-server-protocol-noop-macros" }
182
+ codex-app-server-test-client = { path = "app-server-test-client" }
183
+ codex-apply-patch = { path = "apply-patch" }
184
+ codex-arg0 = { path = "arg0" }
185
+ codex-async-utils = { path = "async-utils" }
186
+ codex-backend-client = { path = "backend-client" }
187
+ codex-build-info = { path = "build-info" }
188
+ codex-chatgpt = { path = "chatgpt" }
189
+ codex-client = { path = "codex-client" }
190
+ codex-collaboration-mode-templates = { path = "collaboration-mode-templates" }
191
+ codex-cloud-config = { path = "cloud-config" }
192
+ codex-cloud-tasks-client = { path = "cloud-tasks-client" }
193
+ codex-cloud-tasks-mock-client = { path = "cloud-tasks-mock-client" }
194
+ codex-code-mode = { path = "code-mode" }
195
+ codex-code-mode-protocol = { path = "code-mode-protocol" }
196
+ codex-code-mode-runtime = { path = "code-mode-runtime" }
197
+ codex-home = { path = "codex-home" }
198
+ codex-http-client = { path = "http-client" }
199
+ codex-websocket-client = { path = "websocket-client" }
200
+ codex-config = { path = "config" }
201
+ codex-connectors = { path = "connectors" }
202
+ codex-agent-extension = { path = "ext/agent" }
203
+ codex-connectors-extension = { path = "ext/connectors" }
204
+ codex-context-fragments = { path = "context-fragments" }
205
+ codex-core = { path = "core" }
206
+ codex-core-api = { path = "core-api" }
207
+ codex-core-plugins = { path = "core-plugins" }
208
+ codex-diagnostics = { path = "diagnostics" }
209
+ codex-exec = { path = "exec" }
210
+ codex-file-system = { path = "file-system" }
211
+ codex-exec-server-protocol = { path = "exec-server-protocol" }
212
+ codex-exec-server = { path = "exec-server" }
213
+ codex-exec-server-test-support = { path = "exec-server/tests/support" }
214
+ codex-execpolicy = { path = "execpolicy" }
215
+ codex-extension-api = { path = "ext/extension-api" }
216
+ codex-extension-items = { path = "ext/items" }
217
+ codex-goal-extension = { path = "ext/goal" }
218
+ codex-git-attribution = { path = "ext/git-attribution" }
219
+ codex-guardian-reviewer = { path = "ext/guardian-reviewer" }
220
+ codex-guardian-v2 = { path = "ext/guardian-v2" }
221
+ codex-history-notes-extension = { path = "ext/history-notes" }
222
+ codex-image-generation-extension = { path = "ext/image-generation" }
223
+ codex-external-agent-migration = { path = "external-agent-migration" }
224
+ codex-experimental-api-macros = { path = "codex-experimental-api-macros" }
225
+ codex-features = { path = "features" }
226
+ codex-feedback = { path = "feedback" }
227
+ codex-install-context = { path = "install-context" }
228
+ codex-file-search = { path = "file-search" }
229
+ codex-file-watcher = { path = "file-watcher" }
230
+ codex-git-utils = { path = "git-utils" }
231
+ codex-guardian-context = { path = "guardian-context" }
232
+ codex-hooks = { path = "hooks" }
233
+ codex-history = { path = "history" }
234
+ codex-keyring-store = { path = "keyring-store" }
235
+ codex-linux-sandbox = { path = "linux-sandbox" }
236
+ codex-lmstudio = { path = "lmstudio" }
237
+ codex-login = { path = "login" }
238
+ codex-message-history = { path = "message-history" }
239
+ codex-memories-extension = { path = "ext/memories" }
240
+ codex-web-search-extension = { path = "ext/web-search" }
241
+ codex-memories-read = { path = "memories/read" }
242
+ codex-memories-write = { path = "memories/write" }
243
+ codex-mcp = { path = "codex-mcp" }
244
+ codex-mcp-extension = { path = "ext/mcp" }
245
+ codex-model-provider-info = { path = "model-provider-info" }
246
+ codex-models-manager = { path = "models-manager" }
247
+ codex-mxc-sandbox = { path = "mxc-sandbox" }
248
+ codex-network-proxy = { path = "network-proxy" }
249
+ codex-ollama = { path = "ollama" }
250
+ codex-otel = { path = "otel" }
251
+ codex-otel-trace-websocket = { path = "otel-trace-websocket" }
252
+ codex-plugin = { path = "plugin" }
253
+ codex-model-provider = { path = "model-provider" }
254
+ codex-process-hardening = { path = "process-hardening" }
255
+ codex-protocol = { path = "protocol" }
256
+ codex-prompts = { path = "prompts" }
257
+ codex-queue-extension = { path = "ext/queue" }
258
+ codex-responses-api-proxy = { path = "responses-api-proxy" }
259
+ codex-response-debug-context = { path = "response-debug-context" }
260
+ codex-rmcp-client = { path = "rmcp-client" }
261
+ codex-rollout = { path = "rollout" }
262
+ codex-rollout-trace = { path = "rollout-trace" }
263
+ codex-sandboxing = { path = "sandboxing" }
264
+ codex-secrets = { path = "secrets" }
265
+ codex-shell-command = { path = "shell-command" }
266
+ codex-shell-escalation = { path = "shell-escalation" }
267
+ codex-skills-extension = { path = "ext/skills" }
268
+ codex-skills = { path = "skills" }
269
+ codex-state = { path = "state" }
270
+ codex-stdio-to-uds = { path = "stdio-to-uds" }
271
+ codex-terminal-detection = { path = "terminal-detection" }
272
+ codex-test-binary-support = { path = "test-binary-support" }
273
+ codex-thread-store = { path = "thread-store" }
274
+ codex-tools = { path = "tools" }
275
+ codex-tcp-tunnel = { path = "tcp-tunnel" }
276
+ codex-tui = { path = "tui" }
277
+ codex-uds = { path = "uds" }
278
+ codex-utils-absolute-path = { path = "utils/absolute-path" }
279
+ codex-utils-approval-presets = { path = "utils/approval-presets" }
280
+ codex-utils-audio = { path = "utils/audio" }
281
+ codex-utils-cache = { path = "utils/cache" }
282
+ codex-utils-cargo-bin = { path = "utils/cargo-bin" }
283
+ codex-utils-cli = { path = "utils/cli" }
284
+ codex-utils-elapsed = { path = "utils/elapsed" }
285
+ codex-utils-fuzzy-match = { path = "utils/fuzzy-match" }
286
+ codex-utils-git-discovery = { path = "utils/git-discovery" }
287
+ codex-utils-home-dir = { path = "utils/home-dir" }
288
+ codex-utils-image = { path = "utils/image" }
289
+ codex-utils-json-to-toml = { path = "utils/json-to-toml" }
290
+ codex-utils-oss = { path = "utils/oss" }
291
+ codex-utils-output-truncation = { path = "utils/output-truncation" }
292
+ codex-utils-path = { path = "utils/path-utils" }
293
+ codex-utils-path-uri = { path = "utils/path-uri" }
294
+ codex-utils-plugins = { path = "utils/plugins" }
295
+ codex-utils-pty = { path = "utils/pty" }
296
+ codex-utils-redacted-string = { path = "utils/redacted-string" }
297
+ codex-utils-rustls-provider = { path = "utils/rustls-provider" }
298
+ codex-utils-sandbox-summary = { path = "utils/sandbox-summary" }
299
+ codex-worktree = { path = "worktree" }
300
+ codex-utils-sleep-inhibitor = { path = "utils/sleep-inhibitor" }
301
+ codex-utils-stream-parser = { path = "utils/stream-parser" }
302
+ codex-utils-string = { path = "utils/string" }
303
+ codex-utils-template = { path = "utils/template" }
304
+ codex-user-verification = { path = "user-verification" }
305
+ codex-v8-poc = { path = "v8-poc" }
306
+ codex-workload-identity = { path = "workload-identity" }
307
+ codex-windows-sandbox = { path = "windows-sandbox-rs" }
308
+ core_test_support = { path = "core/tests/common" }
309
+
310
+ # External
311
+ learning_mode_windows = { git = "https://github.com/microsoft/mxc", rev = "6cd3d58f05d3447e67109cfb75e042803b843ca4" }
312
+ wxc_common = { git = "https://github.com/microsoft/mxc", rev = "6cd3d58f05d3447e67109cfb75e042803b843ca4" }
313
+ age = "0.11.1"
314
+ ansi-to-tui = "8.0.1"
315
+ anyhow = "1"
316
+ appcontainer_common = { git = "https://github.com/microsoft/mxc", rev = "6cd3d58f05d3447e67109cfb75e042803b843ca4" }
317
+ arboard = { version = "3", features = ["wayland-data-control"] }
318
+ arc-swap = "1.9.0"
319
+ assert_cmd = "2"
320
+ assert_matches = "1.5.0"
321
+ async-channel = "2.3.1"
322
+ async-io = "2.6.0"
323
+ async-stream = "0.3.6"
324
+ aws-config = "1"
325
+ aws-credential-types = "1"
326
+ aws-sigv4 = "1"
327
+ aws-types = "1"
328
+ axum = { version = "0.8", default-features = false }
329
+ base64 = "0.22.1"
330
+ bitflags = "2.13.1"
331
+ blake3 = "1.8.2"
332
+ bm25 = "2.3.2"
333
+ bytes = "1.10.1"
334
+ chardetng = "0.1.17"
335
+ chrono = "0.4.43"
336
+ clap = "4"
337
+ clap_complete = "4"
338
+ clatter = { version = "2.2.0", default-features = false, features = [
339
+ "alloc",
340
+ "getrandom",
341
+ "use-25519",
342
+ "use-aes-gcm",
343
+ "use-rust-crypto-ml-kem",
344
+ "use-sha",
345
+ ] }
346
+ color-eyre = "0.6.3"
347
+ constant_time_eq = "0.3.1"
348
+ crossbeam-channel = "0.5.15"
349
+ crypto_box = { version = "0.9.1", features = ["seal"] }
350
+ crossterm = "0.29.0"
351
+ ctor = "0.6.3"
352
+ deno_core_icudata = "0.77.0"
353
+ derive_more = "2"
354
+ diffy = "0.4.2"
355
+ dirs = "6"
356
+ divan = "0.1.21"
357
+ dns-lookup = "3.0.1"
358
+ dotenvy = "0.15.7"
359
+ dunce = "1.0.4"
360
+ ed25519-dalek = { version = "2.2.0", features = ["pkcs8"] }
361
+ encoding_rs = "0.8.35"
362
+ eventsource-stream = "0.2.3"
363
+ flate2 = "1.1.8"
364
+ futures = { version = "0.3", default-features = false }
365
+ gethostname = "1.1.0"
366
+ gix = { version = "0.81.0", default-features = false, features = ["sha1"] }
367
+ gix-url = "0.35.2"
368
+ glob = "0.3"
369
+ globset = "0.4"
370
+ hmac = "0.12.1"
371
+ http = "1.3.1"
372
+ httpdate = "1.0.3"
373
+ iana-time-zone = "0.1.64"
374
+ icu_decimal = "2.1"
375
+ icu_locale_core = "2.1"
376
+ icu_provider = { version = "2.1", features = ["sync"] }
377
+ ignore = "0.4.23"
378
+ image = { version = "^0.25.9", default-features = false }
379
+ include_dir = "0.7.4"
380
+ indexmap = "2.12.0"
381
+ insta = "1.46.3"
382
+ inventory = "0.3.19"
383
+ itertools = "0.14.0"
384
+ jsonptr = { version = "0.7.1", default-features = false }
385
+ jsonwebtoken = "9.3.1"
386
+ keyring = { version = "3.6", default-features = false }
387
+ landlock = "0.4.4"
388
+ lazy_static = "1"
389
+ libc = "0.2.182"
390
+ # Keep SQLx's bundled SQLite on a version containing the WAL-reset corruption fix:
391
+ # https://www.sqlite.org/wal.html#the_wal_reset_bug
392
+ libsqlite3-sys = { version = "0.37", default-features = false }
393
+ log = "0.4"
394
+ lru = "0.18.2"
395
+ maplit = "1.0.2"
396
+ memchr = "2.7.6"
397
+ mime_guess = "2.0.5"
398
+ multimap = "0.10.0"
399
+ notify = "8.2.0"
400
+ nucleo = { git = "https://github.com/helix-editor/nucleo.git", rev = "4253de9faabb4e5c6d81d946a5e35a90f87347ee" }
401
+ once_cell = "1.20.2"
402
+ openssl-sys = "*"
403
+ opentelemetry = "0.31.0"
404
+ opentelemetry-appender-tracing = "0.31.0"
405
+ opentelemetry-otlp = "0.31.0"
406
+ opentelemetry-semantic-conventions = "0.31.0"
407
+ opentelemetry_sdk = "0.31.0"
408
+ os_info = "3.12.0"
409
+ owo-colors = "4.3.0"
410
+ pathdiff = "0.2"
411
+ portable-pty = "0.9.0"
412
+ predicates = "3"
413
+ pretty_assertions = "1.4.1"
414
+ pulldown-cmark = { version = "0.10", default-features = false }
415
+ quick-xml = "0.41.0"
416
+ rand = "0.9"
417
+ rand_regex = "0.18.1"
418
+ ratatui = { version = "0.30.2", default-features = false, features = [
419
+ "crossterm",
420
+ "layout-cache",
421
+ "underline-color",
422
+ ] }
423
+ ratatui-macros = "0.7.2"
424
+ rcgen = { version = "0.14.7", default-features = false, features = [
425
+ "aws_lc_rs",
426
+ "pem",
427
+ ] }
428
+ regex = "1.12.3"
429
+ regex-automata = { version = "0.4.13", default-features = false, features = ["std", "syntax", "unicode", "nfa-pikevm"] }
430
+ regex-lite = "0.1.8"
431
+ regex-syntax = "0.8.8"
432
+ reqwest = { version = "0.12", features = ["cookies"] }
433
+ rmcp = { version = "=3.2.0", default-features = false }
434
+ runfiles = { git = "https://github.com/dzbarsky/rules_rust", rev = "b56cbaa8465e74127f1ea216f813cd377295ad81" }
435
+ rustix = { version = "1.1.4", features = ["net"] }
436
+ rustls = { version = "0.23.45", default-features = false, features = [
437
+ "aws_lc_rs",
438
+ "std",
439
+ ] }
440
+ rustls-native-certs = "0.8.3"
441
+ rustls-pki-types = "1.14.0"
442
+ schemars = "0.8.22"
443
+ seccompiler = "0.5.0"
444
+ semver = "1.0"
445
+ sentry = "0.46.0"
446
+ serde = { version = "1", features = ["rc"] }
447
+ serde_ignored = "0.1.14"
448
+ serde_json = "1"
449
+ serde_path_to_error = "0.1.20"
450
+ serde_with = "3.17"
451
+ serde_yaml = "0.9"
452
+ serial_test = "3.2.0"
453
+ sha1 = "0.10.6"
454
+ scopeguard = "1.2.0"
455
+ sha2 = "0.10"
456
+ shlex = "1.3.0"
457
+ signal-hook = "0.3.18"
458
+ similar = "2.7.0"
459
+ symphonia = { version = "0.6.0", default-features = false, features = [
460
+ "isomp4",
461
+ "mkv",
462
+ "mp3",
463
+ "ogg",
464
+ "wav",
465
+ ] }
466
+ socket2 = "0.6.1"
467
+ # When bumping sqlx, audit the SQLite constructor deny list in clippy.toml.
468
+ sqlx = { version = "0.9.0", default-features = false, features = [
469
+ "chrono",
470
+ "json",
471
+ "macros",
472
+ "migrate",
473
+ "runtime-tokio",
474
+ "tls-rustls",
475
+ "sqlite-bundled",
476
+ "time",
477
+ "uuid",
478
+ ] }
479
+ starlark = { version = "0.14.2", default-features = false }
480
+ strum = "0.27.2"
481
+ strum_macros = "0.28.0"
482
+ supports-color = "3.0.2"
483
+ syntect = "5"
484
+ sys-locale = "0.3.2"
485
+ system-configuration = "0.7"
486
+ tar = { version = "=0.4.45", default-features = false }
487
+ tempfile = "3.23.0"
488
+ test-log = "0.2.19"
489
+ textwrap = "0.16.2"
490
+ thiserror = "2.0.17"
491
+ tikv-jemallocator = "=0.7.0"
492
+ time = "0.3.47"
493
+ tiny_http = "0.12"
494
+ tokio = "1"
495
+ tokio-rustls = "0.26.4"
496
+ tokio-stream = "0.1.18"
497
+ tokio-test = "0.4"
498
+ tokio-tungstenite = { version = "0.28.0", features = [
499
+ "proxy",
500
+ "rustls-tls-native-roots",
501
+ ] }
502
+ tokio-util = "0.7.18"
503
+ toml = "0.9.5"
504
+ toml_edit = "0.24.0"
505
+ tracing = "0.1.44"
506
+ tracing-appender = "0.2.3"
507
+ tracing-opentelemetry = "0.32.0"
508
+ tracing-subscriber = "0.3.22"
509
+ tracing-test = "0.2.5"
510
+ tonic = { version = "0.14.3", default-features = false, features = ["channel", "codegen"] }
511
+ tonic-prost = "0.14.3"
512
+ tree-sitter = "0.25.10"
513
+ tree-sitter-bash = "0.25"
514
+ tree-sitter-powershell = "=0.26.4"
515
+ ts-rs = "11"
516
+ tungstenite = { version = "0.27.0", features = ["deflate", "proxy"] }
517
+ uds_windows = "1.1.0"
518
+ unicode-segmentation = "1.12.0"
519
+ unicode-width = "0.2"
520
+ url = "2"
521
+ urlencoding = "2.1"
522
+ uuid = "1"
523
+ v8 = "=150.4.0"
524
+ vt100 = "0.16.2"
525
+ walkdir = "2.5.0"
526
+ webbrowser = "1.2.2"
527
+ which = "8"
528
+ whoami = "1.6.1"
529
+ wildmatch = "2.6.1"
530
+ winapi-util = "0.1.11"
531
+ zip = "2.4.2"
532
+ zstd = "0.13"
533
+
534
+ wiremock = "0.6"
535
+ zeroize = "1.8.2"
536
+
537
+ [workspace.lints]
538
+ rust = {}
539
+
540
+ [workspace.lints.clippy]
541
+ await_holding_invalid_type = "deny"
542
+ await_holding_lock = "deny"
543
+ disallowed_methods = "deny"
544
+ expect_used = "deny"
545
+ identity_op = "deny"
546
+ manual_clamp = "deny"
547
+ manual_filter = "deny"
548
+ manual_find = "deny"
549
+ manual_flatten = "deny"
550
+ manual_map = "deny"
551
+ manual_memcpy = "deny"
552
+ manual_non_exhaustive = "deny"
553
+ manual_ok_or = "deny"
554
+ manual_range_contains = "deny"
555
+ manual_retain = "deny"
556
+ manual_strip = "deny"
557
+ manual_try_fold = "deny"
558
+ manual_unwrap_or = "deny"
559
+ needless_borrow = "deny"
560
+ needless_borrowed_reference = "deny"
561
+ needless_collect = "deny"
562
+ needless_late_init = "deny"
563
+ needless_option_as_deref = "deny"
564
+ needless_question_mark = "deny"
565
+ needless_update = "deny"
566
+ redundant_clone = "deny"
567
+ redundant_closure = "deny"
568
+ redundant_closure_for_method_calls = "deny"
569
+ redundant_static_lifetimes = "deny"
570
+ trivially_copy_pass_by_ref = "deny"
571
+ uninlined_format_args = "deny"
572
+ unnecessary_filter_map = "deny"
573
+ unnecessary_lazy_evaluations = "deny"
574
+ unnecessary_sort_by = "deny"
575
+ unnecessary_to_owned = "deny"
576
+ unwrap_used = "deny"
577
+
578
+ # cargo-shear cannot see the platform-specific openssl-sys usage, so we
579
+ # silence the false positive here instead of deleting a real dependency.
580
+ [workspace.metadata.cargo-shear]
581
+ ignored = [
582
+ "icu_provider",
583
+ "openssl-sys",
584
+ "codex-v8-poc",
585
+ ]
586
+
587
+ [profile.dev]
588
+ # Keep line tables/backtraces while avoiding expensive full variable debug info
589
+ # across local dev builds.
590
+ debug = "limited"
591
+
592
+ [profile.dev-small]
593
+ inherits = "dev"
594
+ opt-level = 0
595
+ debug = "none"
596
+ strip = "symbols"
597
+
598
+ [profile.release]
599
+ lto = "thin"
600
+ debug = "line-tables-only"
601
+ split-debuginfo = "off"
602
+ # Keep release binaries symbolicateable until packaging has archived the
603
+ # sidecar symbols and stripped the binaries.
604
+ strip = false
605
+
606
+ # Balance parallel release code generation against binary size.
607
+ codegen-units = 4
608
+
609
+ [profile.profiling]
610
+ inherits = "release"
611
+ debug = "full"
612
+ lto = false
613
+ strip = false
614
+
615
+ [profile.ci-test]
616
+ # Reduce binary size to reduce disk pressure.
617
+ debug = "limited"
618
+ inherits = "test"
619
+ opt-level = 0
620
+
621
+ [patch.crates-io]
622
+ # Uncomment to debug local changes.
623
+ # ratatui = { path = "../../ratatui" }
624
+ crossterm = { git = "https://github.com/openai-oss-forks/crossterm", rev = "45fecb9508105988f42fe6ff0441783ed3717f92" }
625
+ tokio-tungstenite = { git = "https://github.com/openai-oss-forks/tokio-tungstenite", rev = "0e5b2d73aa18dd9f0a50ee9ff199d5aef7594186" }
626
+ tungstenite = { git = "https://github.com/openai-oss-forks/tungstenite-rs", rev = "4fffad30fe373adbdcffab9545e9e9bf4f2fc19f" }
627
+
628
+ # Uncomment to debug local changes.
629
+ # rmcp = { path = "../../rust-sdk/crates/rmcp" }
630
+
631
+ [patch."ssh://git@github.com/openai-oss-forks/tungstenite-rs.git"]
632
+ tungstenite = { git = "https://github.com/openai-oss-forks/tungstenite-rs", rev = "4fffad30fe373adbdcffab9545e9e9bf4f2fc19f" }
codex-rs/README.md ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ # Codex CLI
2
+
3
+ [**Codex CLI Documentation**](https://developers.openai.com/codex/cli)
codex-rs/clippy.toml ADDED
@@ -0,0 +1,32 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ allow-expect-in-tests = true
2
+ allow-unwrap-in-tests = true
3
+ await-holding-invalid-types = [
4
+ "tokio::sync::MutexGuard",
5
+ "tokio::sync::RwLockReadGuard",
6
+ "tokio::sync::RwLockWriteGuard",
7
+ ]
8
+ disallowed-methods = [
9
+ { path = "ratatui::style::Color::Rgb", reason = "Use ANSI colors, which work better in various terminal themes." },
10
+ { path = "ratatui::style::Color::Indexed", reason = "Use ANSI colors, which work better in various terminal themes." },
11
+ { path = "ratatui::style::Stylize::white", reason = "Avoid hardcoding white; prefer default fg or dim/bold. Exception: Disable this rule if rendering over a hardcoded ANSI background." },
12
+ { path = "ratatui::style::Stylize::black", reason = "Avoid hardcoding black; prefer default fg or dim/bold. Exception: Disable this rule if rendering over a hardcoded ANSI background." },
13
+ { path = "ratatui::style::Stylize::yellow", reason = "Avoid yellow; prefer other colors in `tui/styles.md`." },
14
+ # Audited against workspace sqlx 0.9.0. Revisit this SQLite escape-hatch list when bumping sqlx.
15
+ { path = "sqlx::Pool::connect", reason = "Create SQLite pools through codex-state's sqlite shim." },
16
+ { path = "sqlx::Pool::connect_with", reason = "Create SQLite pools through codex-state's sqlite shim." },
17
+ { path = "sqlx::Pool::connect_lazy", reason = "Create SQLite pools through codex-state's sqlite shim." },
18
+ { path = "sqlx::Pool::connect_lazy_with", reason = "Create SQLite pools through codex-state's sqlite shim." },
19
+ { path = "sqlx::Pool::set_connect_options", reason = "Do not replace options on SQLite pools created by codex-state's sqlite shim." },
20
+ { path = "sqlx::pool::PoolOptions::connect", reason = "Create SQLite pools through codex-state's sqlite shim." },
21
+ { path = "sqlx::pool::PoolOptions::connect_with", reason = "Create SQLite pools through codex-state's sqlite shim." },
22
+ { path = "sqlx::pool::PoolOptions::connect_lazy", reason = "Create SQLite pools through codex-state's sqlite shim." },
23
+ { path = "sqlx::pool::PoolOptions::connect_lazy_with", reason = "Create SQLite pools through codex-state's sqlite shim." },
24
+ { path = "sqlx::Connection::connect", reason = "Create SQLite connections through codex-state's sqlite shim." },
25
+ { path = "sqlx::Connection::connect_with", reason = "Create SQLite connections through codex-state's sqlite shim." },
26
+ { path = "sqlx::ConnectOptions::connect", reason = "Create SQLite connections through codex-state's sqlite shim." },
27
+ { path = "sqlx::migrate::MigrateDatabase::create_database", reason = "Create SQLite databases through codex-state's sqlite shim." },
28
+ ]
29
+
30
+ # Increase the size threshold for result_large_err to accommodate
31
+ # richer error variants.
32
+ large-error-threshold = 256
codex-rs/config.md ADDED
@@ -0,0 +1,6 @@
 
 
 
 
 
 
 
1
+ # Configuration docs moved
2
+
3
+ This file has moved. Please see the latest configuration documentation here:
4
+
5
+ - Full config docs: [docs/config.md](https://github.com/openai/codex/blob/main/docs/config.md)
6
+ - MCP servers section: [docs/config.md#connecting-to-mcp-servers](https://github.com/openai/codex/blob/main/docs/config.md#connecting-to-mcp-servers)
codex-rs/default.nix ADDED
@@ -0,0 +1,55 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ cmake,
3
+ llvmPackages,
4
+ openssl,
5
+ libcap ? null,
6
+ rustPlatform,
7
+ pkg-config,
8
+ lib,
9
+ stdenv,
10
+ version ? "0.0.0",
11
+ ...
12
+ }:
13
+ rustPlatform.buildRustPackage (_: {
14
+ env.PKG_CONFIG_PATH = lib.makeSearchPathOutput "dev" "lib/pkgconfig" (
15
+ [ openssl ] ++ lib.optionals stdenv.isLinux [ libcap ]
16
+ );
17
+ pname = "codex-rs";
18
+ inherit version;
19
+ cargoLock.lockFile = ./Cargo.lock;
20
+ doCheck = false;
21
+ src = ./.;
22
+
23
+ # Patch the workspace Cargo.toml so that cargo embeds the correct version in
24
+ # CARGO_PKG_VERSION (which the binary reads via env!("CARGO_PKG_VERSION")).
25
+ # On release commits the Cargo.toml already contains the real version and
26
+ # this sed is a no-op.
27
+ postPatch = ''
28
+ sed -i 's/^version = "0\.0\.0"$/version = "${version}"/' Cargo.toml
29
+ '';
30
+ nativeBuildInputs = [
31
+ cmake
32
+ llvmPackages.clang
33
+ llvmPackages.libclang.lib
34
+ openssl
35
+ pkg-config
36
+ ] ++ lib.optionals stdenv.isLinux [
37
+ libcap
38
+ ];
39
+
40
+ cargoLock.outputHashes = {
41
+ "crossterm-0.29.0" = "sha256-ewiWWQPEU1lSUHzmZTiO5yes5luIaQ9TrvCNnTWhxpE=";
42
+ "nucleo-0.5.0" = "sha256-Hm4SxtTSBrcWpXrtSqeO0TACbUxq3gizg1zD/6Yw/sI=";
43
+ "nucleo-matcher-0.3.1" = "sha256-Hm4SxtTSBrcWpXrtSqeO0TACbUxq3gizg1zD/6Yw/sI=";
44
+ "runfiles-0.1.0" = "sha256-uJpVLcQh8wWZA3GPv9D8Nt43EOirajfDJ7eq/FB+tek=";
45
+ "tokio-tungstenite-0.28.0" = "sha256-hJAkvWxDjB9A9GqansahWhTmj/ekcelslLUTtwqI7lw=";
46
+ "tungstenite-0.27.0" = "sha256-AN5wql2X2yJnQ7lnDxpljNw0Jua40GtmT+w3wjER010=";
47
+ };
48
+
49
+ meta = with lib; {
50
+ description = "OpenAI Codex command‑line interface rust implementation";
51
+ license = licenses.asl20;
52
+ homepage = "https://github.com/openai/codex";
53
+ mainProgram = "codex";
54
+ };
55
+ })
codex-rs/deny.toml ADDED
@@ -0,0 +1,332 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # This template contains all of the possible sections and their default values
2
+
3
+ # Note that all fields that take a lint level have these possible values:
4
+ # * deny - An error will be produced and the check will fail
5
+ # * warn - A warning will be produced, but the check will not fail
6
+ # * allow - No warning or error will be produced, though in some cases a note
7
+ # will be
8
+
9
+ # The values provided in this template are the default values that will be used
10
+ # when any section or field is not specified in your own configuration
11
+
12
+ # Root options
13
+
14
+ # The graph table configures how the dependency graph is constructed and thus
15
+ # which crates the checks are performed against
16
+ [graph]
17
+ # If 1 or more target triples (and optionally, target_features) are specified,
18
+ # only the specified targets will be checked when running `cargo deny check`.
19
+ # This means, if a particular package is only ever used as a target specific
20
+ # dependency, such as, for example, the `nix` crate only being used via the
21
+ # `target_family = "unix"` configuration, that only having windows targets in
22
+ # this list would mean the nix crate, as well as any of its exclusive
23
+ # dependencies not shared by any other crates, would be ignored, as the target
24
+ # list here is effectively saying which targets you are building for.
25
+ targets = [
26
+ # The triple can be any string, but only the target triples built in to
27
+ # rustc (as of 1.40) can be checked against actual config expressions
28
+ #"x86_64-unknown-linux-musl",
29
+ # You can also specify which target_features you promise are enabled for a
30
+ # particular target. target_features are currently not validated against
31
+ # the actual valid features supported by the target architecture.
32
+ #{ triple = "wasm32-unknown-unknown", features = ["atomics"] },
33
+ ]
34
+ # When creating the dependency graph used as the source of truth when checks are
35
+ # executed, this field can be used to prune crates from the graph, removing them
36
+ # from the view of cargo-deny. This is an extremely heavy hammer, as if a crate
37
+ # is pruned from the graph, all of its dependencies will also be pruned unless
38
+ # they are connected to another crate in the graph that hasn't been pruned,
39
+ # so it should be used with care. The identifiers are [Package ID Specifications]
40
+ # (https://doc.rust-lang.org/cargo/reference/pkgid-spec.html)
41
+ #exclude = []
42
+ # If true, metadata will be collected with `--all-features`. Note that this can't
43
+ # be toggled off if true, if you want to conditionally enable `--all-features` it
44
+ # is recommended to pass `--all-features` on the cmd line instead
45
+ all-features = false
46
+ # If true, metadata will be collected with `--no-default-features`. The same
47
+ # caveat with `all-features` applies
48
+ no-default-features = false
49
+ # If set, these feature will be enabled when collecting metadata. If `--features`
50
+ # is specified on the cmd line they will take precedence over this option.
51
+ #features = []
52
+
53
+ # The output table provides options for how/if diagnostics are outputted
54
+ [output]
55
+ # When outputting inclusion graphs in diagnostics that include features, this
56
+ # option can be used to specify the depth at which feature edges will be added.
57
+ # This option is included since the graphs can be quite large and the addition
58
+ # of features from the crate(s) to all of the graph roots can be far too verbose.
59
+ # This option can be overridden via `--feature-depth` on the cmd line
60
+ feature-depth = 1
61
+
62
+ # This section is considered when running `cargo deny check advisories`
63
+ # More documentation for the advisories section can be found here:
64
+ # https://embarkstudios.github.io/cargo-deny/checks/advisories/cfg.html
65
+ [advisories]
66
+ # The path where the advisory databases are cloned/fetched into
67
+ #db-path = "$CARGO_HOME/advisory-dbs"
68
+ # The url(s) of the advisory databases to use
69
+ #db-urls = ["https://github.com/rustsec/advisory-db"]
70
+ # A list of advisory IDs to ignore. Note that ignored advisories will still
71
+ # output a note when they are encountered.
72
+ ignore = [
73
+ # Reviewed 2026-07-02. Keep this list in sync with .cargo/audit.toml.
74
+ # Each exception must identify the dependency path and removal condition.
75
+ { id = "RUSTSEC-2024-0388", reason = "derivative is unmaintained; pulled in via starlark/starlark_syntax v0.14.2 used by execpolicy/cli/core; no fixed starlark release yet" },
76
+ { id = "RUSTSEC-2025-0057", reason = "fxhash is unmaintained; pulled in via starlark_map under starlark v0.14.2 used by execpolicy/cli/core and bm25 used by core; remove when upstream dependencies drop fxhash" },
77
+ { id = "RUSTSEC-2024-0436", reason = "paste is unmaintained; pulled in via starlark/v8 used by execpolicy/code-mode; no fixed release yet" },
78
+ { id = "RUSTSEC-2023-0089", reason = "atomic-polyfill is unmaintained; pulled in via postcard/heapless/pagable under starlark v0.14.2 used by execpolicy/cli/core; no fixed starlark release yet" },
79
+ # TODO(fcoury): remove this exception when syntect drops yaml-rust and bincode, or updates to versions that have fixed the vulnerabilities.
80
+ { id = "RUSTSEC-2024-0320", reason = "yaml-rust is unmaintained; pulled in via syntect v5.3.0 used by codex-tui for syntax highlighting; no fixed release yet" },
81
+ { id = "RUSTSEC-2025-0141", reason = "bincode is unmaintained; pulled in via syntect v5.3.0 used by codex-tui for syntax highlighting; no fixed release yet" },
82
+ { id = "RUSTSEC-2026-0118", reason = "hickory-proto v0.25.2 is pulled in via rama-dns/rama-tcp used by codex-network-proxy; DNSSEC features are not enabled; remove when rama updates to hickory 0.26.1 or hickory-net" },
83
+ { id = "RUSTSEC-2026-0119", reason = "hickory-proto v0.25.2 is pulled in via rama-dns/rama-tcp used by codex-network-proxy; no fixed rama release is available yet; remove when rama updates to hickory 0.26.1 or hickory-net" },
84
+ { id = "RUSTSEC-2026-0173", reason = "proc-macro-error2 is unmaintained; pulled in via i18n-embed-fl/age used by codex-secrets local storage; remove when codex-secrets migrates off age or age drops i18n-embed-fl" },
85
+ { id = "RUSTSEC-2026-0194", reason = "quick-xml v0.39.4 remains via plist/syntect and wayland-scanner; plist does not exercise the affected APIs and wayland-scanner parses trusted build-time XML; remove when rust-plist#191 and wayland-rs#938 are released" },
86
+ { id = "RUSTSEC-2026-0195", reason = "quick-xml v0.39.4 remains via plist/syntect and wayland-scanner; plist does not exercise the affected APIs and wayland-scanner parses trusted build-time XML; remove when rust-plist#191 and wayland-rs#938 are released" },
87
+ ]
88
+ # If this is true, then cargo deny will use the git executable to fetch advisory database.
89
+ # If this is false, then it uses a built-in git library.
90
+ # Setting this to true can be helpful if you have special authentication requirements that cargo-deny does not support.
91
+ # See Git Authentication for more information about setting up git authentication.
92
+ #git-fetch-with-cli = true
93
+
94
+ # This section is considered when running `cargo deny check licenses`
95
+ # More documentation for the licenses section can be found here:
96
+ # https://embarkstudios.github.io/cargo-deny/checks/licenses/cfg.html
97
+ [licenses]
98
+ # List of explicitly allowed licenses
99
+ # See https://spdx.org/licenses/ for list of possible licenses
100
+ # [possible values: any SPDX 3.11 short identifier (+ optional exception)].
101
+ allow = [
102
+ # Apache-2.0 - https://www.apache.org/licenses/LICENSE-2.0
103
+ # Used by: allocative, anyhow, arboard, assert_cmd, assert_matches, async-channel, async-trait, base64, chardetng, chrono, clap, clap_complete, color-eyre, ctor, diffy, dirs, dunce, encoding_rs, env_logger, escargot, eventsource-stream, futures, http, image, indexmap, insta, itertools, keyring, landlock, lazy_static, libc, log, maplit, multimap, once_cell, opentelemetry, opentelemetry-appender-tracing, opentelemetry-otlp, opentelemetry-semantic-conventions, opentelemetry_sdk, pathdiff, predicates, pretty_assertions, rand, regex-lite, reqwest, seccompiler, serde, serde_json, serde_with, sha1, sha2, shlex, similar, socket2, starlark, supports-color, sys-locale, tempfile, test-log, thiserror, time, tiny_http, toml, toml_edit, unicode-segmentation, unicode-width, url, uuid, webbrowser, wiremock, zeroize
104
+ "Apache-2.0",
105
+ # Apache-2.0 WITH LLVM-exception - https://spdx.org/licenses/LLVM-exception.html
106
+ # Used by: target-lexicon
107
+ "Apache-2.0 WITH LLVM-exception",
108
+ # BSD-2-Clause - https://opensource.org/license/bsd-2-clause
109
+ # Used by: transitive only
110
+ "BSD-2-Clause",
111
+ # BSD-3-Clause - https://opensource.org/license/bsd-3-clause
112
+ # Used by: encoding_rs, seccompiler
113
+ "BSD-3-Clause",
114
+ # BSL-1.0 - https://www.boost.org/users/license.html
115
+ # Used by: transitive only
116
+ "BSL-1.0",
117
+ # CC0-1.0 - https://creativecommons.org/publicdomain/zero/1.0/
118
+ # Used by: dunce, notify
119
+ "CC0-1.0",
120
+ # CDLA-Permissive-2.0 - https://cdla.dev/permissive-2-0/
121
+ # Used by: transitive only
122
+ "CDLA-Permissive-2.0",
123
+ # ISC - https://opensource.org/license/isc-license-txt
124
+ # Used by: transitive only
125
+ "ISC",
126
+ # MIT - https://opensource.org/license/mit
127
+ # Used by: allocative, ansi-to-tui, anyhow, arboard, assert_cmd, assert_matches, async-channel, async-stream, async-trait, axum, base64, bytes, chardetng, chrono, clap, clap_complete, color-eyre, crossterm, ctor, derive_more, diffy, dirs, dotenvy, encoding_rs, env_logger, escargot, eventsource-stream, futures, http, ignore, image, indexmap, itertools, keyring, landlock, lazy_static, libc, log, lru, maplit, mime_guess, multimap, once_cell, openssl-sys, os_info, owo-colors, path-absolutize, pathdiff, portable-pty, predicates, pretty_assertions, pulldown-cmark, rand, ratatui, ratatui-macros, regex-lite, reqwest, rmcp, schemars, serde, serde_json, serde_with, serial_test, sha1, sha2, shlex, socket2, strum, strum_macros, sys-locale, tempfile, test-log, textwrap, thiserror, time, tiny_http, tokio, tokio-stream, tokio-test, tokio-util, toml, toml_edit, tonic, tracing, tracing-appender, tracing-subscriber, tracing-test, tree-sitter, tree-sitter-bash, tree-sitter-highlight, ts-rs, uds_windows, unicode-segmentation, unicode-width, url, urlencoding, uuid, vt100, walkdir, webbrowser, which, wildmatch, wiremock, zeroize
128
+ "MIT",
129
+ # MIT-0 - https://opensource.org/license/mit-0
130
+ # Used by: dunce
131
+ "MIT-0",
132
+ # MPL-2.0 - https://www.mozilla.org/MPL/2.0/
133
+ # Used by: nucleo-matcher
134
+ "MPL-2.0",
135
+ # OpenSSL - https://spdx.org/licenses/OpenSSL.html
136
+ # Used by: aws-lc-sys
137
+ "OpenSSL",
138
+ # Unicode-3.0 - https://opensource.org/license/unicode
139
+ # Used by: icu_decimal, icu_locale_core, icu_provider
140
+ "Unicode-3.0",
141
+ # Unlicense - https://opensource.org/license/unlicense/
142
+ # Used by: ignore, walkdir
143
+ "Unlicense",
144
+ # Zlib - https://opensource.org/license/zlib
145
+ # Used by: transitive only
146
+ "Zlib",
147
+ ]
148
+ # The confidence threshold for detecting a license from license text.
149
+ # The higher the value, the more closely the license text must be to the
150
+ # canonical license text of a valid SPDX license file.
151
+ # [possible values: any between 0.0 and 1.0].
152
+ confidence-threshold = 0.8
153
+ # Allow 1 or more licenses on a per-crate basis, so that particular licenses
154
+ # aren't accepted for every possible crate as with the normal allow list
155
+ exceptions = [
156
+ # Each entry is the crate and version constraint, and its specific allow
157
+ # list
158
+ #{ allow = ["Zlib"], crate = "adler32" },
159
+ ]
160
+
161
+ # Some crates don't have (easily) machine readable licensing information,
162
+ # adding a clarification entry for it allows you to manually specify the
163
+ # licensing information
164
+ #[[licenses.clarify]]
165
+ # The package spec the clarification applies to
166
+ #crate = "ring"
167
+ # The SPDX expression for the license requirements of the crate
168
+ #expression = "MIT AND ISC AND OpenSSL"
169
+ # One or more files in the crate's source used as the "source of truth" for
170
+ # the license expression. If the contents match, the clarification will be used
171
+ # when running the license check, otherwise the clarification will be ignored
172
+ # and the crate will be checked normally, which may produce warnings or errors
173
+ # depending on the rest of your configuration
174
+ #license-files = [
175
+ # Each entry is a crate relative path, and the (opaque) hash of its contents
176
+ #{ path = "LICENSE", hash = 0xbd0eed23 }
177
+ #]
178
+
179
+ [licenses.private]
180
+ # If true, ignores workspace crates that aren't published, or are only
181
+ # published to private registries.
182
+ # To see how to mark a crate as unpublished (to the official registry),
183
+ # visit https://doc.rust-lang.org/cargo/reference/manifest.html#the-publish-field.
184
+ ignore = false
185
+ # One or more private registries that you might publish crates to, if a crate
186
+ # is only published to private registries, and ignore is true, the crate will
187
+ # not have its license(s) checked
188
+ registries = [
189
+ #"https://sekretz.com/registry
190
+ ]
191
+
192
+ # This section is considered when running `cargo deny check bans`.
193
+ # More documentation about the 'bans' section can be found here:
194
+ # https://embarkstudios.github.io/cargo-deny/checks/bans/cfg.html
195
+ [bans]
196
+ # Lint level for when multiple versions of the same crate are detected
197
+ multiple-versions = "warn"
198
+ # Lint level for when a crate version requirement is `*`
199
+ wildcards = "allow"
200
+ # The graph highlighting used when creating dotgraphs for crates
201
+ # with multiple versions
202
+ # * lowest-version - The path to the lowest versioned duplicate is highlighted
203
+ # * simplest-path - The path to the version with the fewest edges is highlighted
204
+ # * all - Both lowest-version and simplest-path are used
205
+ highlight = "all"
206
+ # The default lint level for `default` features for crates that are members of
207
+ # the workspace that is being checked. This can be overridden by allowing/denying
208
+ # `default` on a crate-by-crate basis if desired.
209
+ workspace-default-features = "allow"
210
+ # The default lint level for `default` features for external crates that are not
211
+ # members of the workspace. This can be overridden by allowing/denying `default`
212
+ # on a crate-by-crate basis if desired.
213
+ external-default-features = "allow"
214
+ # List of crates that are allowed. Use with care!
215
+ allow = [
216
+ #"ansi_term@0.11.0",
217
+ #{ crate = "ansi_term@0.11.0", reason = "you can specify a reason it is allowed" },
218
+ ]
219
+ # List of crates to deny
220
+ deny = [
221
+ #"ansi_term@0.11.0",
222
+ #{ crate = "ansi_term@0.11.0", reason = "you can specify a reason it is banned" },
223
+ # Wrapper crates can optionally be specified to allow the crate when it
224
+ # is a direct dependency of the otherwise banned crate
225
+ #{ crate = "ansi_term@0.11.0", wrappers = ["this-crate-directly-depends-on-ansi_term"] },
226
+ # Removing async-trait materially improves debug build times:
227
+ # https://github.com/openai/codex/pull/27304
228
+ { crate = "async-trait", wrappers = [
229
+ "hickory-proto",
230
+ "opentelemetry-http",
231
+ "pagable",
232
+ "rmcp",
233
+ "tonic",
234
+ "webrtc",
235
+ "zbus",
236
+ ], reason = "first-party traits must use native async trait methods with explicit Send bounds" },
237
+ # Migration ratchet: `codex-http-client` is the intended reqwest owner. Remove each temporary
238
+ # wrapper when that crate's direct reqwest dependency is migrated to the shared abstraction.
239
+ { crate = "reqwest", wrappers = [
240
+ # Intended owner.
241
+ "codex-http-client",
242
+ # Intentional exception: gRPC uses reqwest directly as tonic's HTTP/2 transport.
243
+ "codex-code-mode",
244
+ # Intentional exception: this standalone, privileged Responses API proxy owns its blocking
245
+ # upstream HTTP transport independently of Codex.
246
+ "codex-responses-api-proxy",
247
+ # Temporary migration exceptions.
248
+ "codex-otel",
249
+ # Third-party crates that own their reqwest integration. These are not part of the
250
+ # first-party migration count above.
251
+ "oauth2",
252
+ "opentelemetry-http",
253
+ "opentelemetry-otlp",
254
+ "rmcp",
255
+ "sentry",
256
+ "webrtc-sys-build",
257
+ ], reason = "new direct reqwest dependencies must use codex-http-client; temporary wrappers track migration debt" },
258
+ ]
259
+
260
+ # List of features to allow/deny
261
+ # Each entry the name of a crate and a version range. If version is
262
+ # not specified, all versions will be matched.
263
+ #[[bans.features]]
264
+ #crate = "reqwest"
265
+ # Features to not allow
266
+ #deny = ["json"]
267
+ # Features to allow
268
+ #allow = [
269
+ # "rustls",
270
+ # "__rustls",
271
+ # "__tls",
272
+ # "hyper-rustls",
273
+ # "rustls",
274
+ # "rustls-pemfile",
275
+ # "rustls-tls-webpki-roots",
276
+ # "tokio-rustls",
277
+ # "webpki-roots",
278
+ #]
279
+ # If true, the allowed features must exactly match the enabled feature set. If
280
+ # this is set there is no point setting `deny`
281
+ #exact = true
282
+
283
+ # Certain crates/versions that will be skipped when doing duplicate detection.
284
+ skip = [
285
+ #"ansi_term@0.11.0",
286
+ #{ crate = "ansi_term@0.11.0", reason = "you can specify a reason why it can't be updated/removed" },
287
+ ]
288
+ # Similarly to `skip` allows you to skip certain crates during duplicate
289
+ # detection. Unlike skip, it also includes the entire tree of transitive
290
+ # dependencies starting at the specified crate, up to a certain depth, which is
291
+ # by default infinite.
292
+ skip-tree = [
293
+ #"ansi_term@0.11.0", # will be skipped along with _all_ of its direct and transitive dependencies
294
+ #{ crate = "ansi_term@0.11.0", depth = 20 },
295
+ ]
296
+
297
+ # This section is considered when running `cargo deny check sources`.
298
+ # More documentation about the 'sources' section can be found here:
299
+ # https://embarkstudios.github.io/cargo-deny/checks/sources/cfg.html
300
+ [sources]
301
+ # Lint level for what to happen when a crate from a crate registry that is not
302
+ # in the allow list is encountered
303
+ unknown-registry = "deny"
304
+ # Lint level for what to happen when a crate from a git repository that is not
305
+ # in the allow list is encountered
306
+ unknown-git = "deny"
307
+ # Git sources must be pinned to immutable revisions.
308
+ required-git-spec = "rev"
309
+ # List of URLs for allowed crate registries. Defaults to the crates.io index
310
+ # if not specified. If it is specified but empty, no registries are allowed.
311
+ allow-registry = ["https://github.com/rust-lang/crates.io-index"]
312
+ # List of URLs for allowed Git repositories
313
+ allow-git = [
314
+ "https://github.com/dzbarsky/rules_rust",
315
+ "https://github.com/helix-editor/nucleo.git",
316
+ # CONNECT request handling needs this pinned H3 revision until released.
317
+ "https://github.com/hyperium/h3",
318
+ "https://github.com/juberti-oai/rust-sdks.git",
319
+ "https://github.com/microsoft/mxc",
320
+ "https://github.com/openai-oss-forks/crossterm",
321
+ "https://github.com/openai-oss-forks/tokio-tungstenite",
322
+ "https://github.com/openai-oss-forks/tungstenite-rs",
323
+ ]
324
+
325
+ [sources.allow-org]
326
+ # github.com organizations to allow git sources for
327
+ github = [
328
+ ]
329
+ # gitlab.com organizations to allow git sources for
330
+ gitlab = []
331
+ # bitbucket.org organizations to allow git sources for
332
+ bitbucket = []
codex-rs/rust-toolchain.toml ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ [toolchain]
2
+ channel = "1.95.0"
3
+ components = ["clippy", "rustfmt", "rust-src"]
codex-rs/rustfmt.toml ADDED
@@ -0,0 +1,4 @@
 
 
 
 
 
1
+ edition = "2024"
2
+ # The warnings caused by this setting can be ignored.
3
+ # See https://github.com/openai/openai/pull/298039 for details.
4
+ imports_granularity = "Item"
defs.bzl ADDED
@@ -0,0 +1,707 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ load("@crates//:data.bzl", "DEP_DATA")
2
+ load("@crates//:defs.bzl", "all_crate_deps")
3
+ load("@rules_rust//cargo/private:cargo_build_script_wrapper.bzl", "cargo_build_script")
4
+ load("@rules_rust//rust:defs.bzl", "rust_binary", "rust_library", "rust_proc_macro", "rust_test")
5
+ load("//bazel/rules/testing:foreign_platform_binary.bzl", "foreign_platform_binary")
6
+ load("//bazel/rules/testing/wine:wine_runtime.bzl", "WINE_TEST_TARGET_COMPATIBLE_WITH", "wine_test_runtime")
7
+
8
+ # Match Cargo's Windows linker behavior so Bazel-built binaries and tests use
9
+ # the same stack reserve on both Windows ABIs and resolve UCRT imports on MSVC.
10
+ WINDOWS_GNULLVM_RUSTC_LINK_FLAGS = [
11
+ "-C",
12
+ "link-arg=-Wl,--stack,8388608", # 8 MiB
13
+ ]
14
+
15
+ WINDOWS_RUSTC_LINK_FLAGS = select({
16
+ "@llvm//constraints/windows/abi:gnullvm": WINDOWS_GNULLVM_RUSTC_LINK_FLAGS,
17
+ "@llvm//constraints/windows/abi:msvc": [
18
+ "-C",
19
+ "link-arg=/STACK:8388608", # 8 MiB
20
+ "-C",
21
+ "link-arg=/NODEFAULTLIB:libucrt.lib",
22
+ "-C",
23
+ "link-arg=ucrt.lib",
24
+ ],
25
+ "//conditions:default": [],
26
+ })
27
+
28
+ WINDOWS_GNULLVM_INCOMPATIBLE = select({
29
+ "@llvm//constraints/windows/abi:gnullvm": ["@platforms//:incompatible"],
30
+ "//conditions:default": [],
31
+ })
32
+
33
+ WINDOWS_GNULLVM_ONLY = select({
34
+ "@llvm//constraints/windows/abi:gnullvm": [],
35
+ "//conditions:default": ["@platforms//:incompatible"],
36
+ })
37
+
38
+ # libwebrtc uses Objective-C categories from native archives. Any Bazel-linked
39
+ # macOS binary/test that can pull it in must keep category symbols alive.
40
+ MACOS_WEBRTC_RUSTC_LINK_FLAGS = select({
41
+ "@platforms//os:macos": [
42
+ "-C",
43
+ "link-arg=-ObjC",
44
+ "-C",
45
+ "link-arg=-lc++",
46
+ ],
47
+ "//conditions:default": [],
48
+ })
49
+
50
+ def _workspace_root_test_impl(ctx):
51
+ is_windows = ctx.target_platform_has_constraint(ctx.attr._windows_constraint[platform_common.ConstraintValueInfo])
52
+ launcher = ctx.actions.declare_file(ctx.label.name + ".bat" if is_windows else ctx.label.name)
53
+ test_bin = ctx.executable.test_bin
54
+ workspace_root_marker = ctx.file.workspace_root_marker
55
+ launcher_template = ctx.file._windows_launcher_template if is_windows else ctx.file._bash_launcher_template
56
+ runfile_env_exports = _windows_runfile_env_exports(ctx) if is_windows else _bash_runfile_env_exports(ctx)
57
+ workspace_root_setup = _windows_workspace_root_setup(ctx) if is_windows else _bash_workspace_root_setup(ctx)
58
+ ctx.actions.expand_template(
59
+ template = launcher_template,
60
+ output = launcher,
61
+ is_executable = True,
62
+ substitutions = {
63
+ "__RUNFILE_ENV_EXPORTS__": runfile_env_exports,
64
+ "__TEST_BIN__": test_bin.short_path,
65
+ "__WORKSPACE_ROOT_SETUP__": workspace_root_setup,
66
+ "__WORKSPACE_ROOT_MARKER__": workspace_root_marker.short_path,
67
+ },
68
+ )
69
+
70
+ runfiles = ctx.runfiles(files = [test_bin, workspace_root_marker]).merge(ctx.attr.test_bin[DefaultInfo].default_runfiles)
71
+ for data_dep in ctx.attr.data:
72
+ runfiles = runfiles.merge(ctx.runfiles(files = data_dep[DefaultInfo].files.to_list()))
73
+ runfiles = runfiles.merge(data_dep[DefaultInfo].default_runfiles)
74
+ for runfile_dep in ctx.attr.runfile_env:
75
+ runfile = _runfile_env_file(runfile_dep)
76
+ runfiles = runfiles.merge(ctx.runfiles(files = [runfile]))
77
+ runfiles = runfiles.merge(runfile_dep[DefaultInfo].default_runfiles)
78
+
79
+ location_targets = {}
80
+ for target in (
81
+ ctx.attr.data +
82
+ [ctx.attr.test_bin, ctx.attr.workspace_root_marker] +
83
+ ctx.attr.runfile_env.keys()
84
+ ):
85
+ location_targets[target.label] = target
86
+ env = {
87
+ key: ctx.expand_location(value, targets = location_targets.values())
88
+ for key, value in ctx.attr.env.items()
89
+ }
90
+ if ctx.attr.test_threads:
91
+ env["RUST_TEST_THREADS"] = str(ctx.attr.test_threads)
92
+
93
+ return [
94
+ DefaultInfo(
95
+ executable = launcher,
96
+ files = depset([launcher]),
97
+ runfiles = runfiles,
98
+ ),
99
+ RunEnvironmentInfo(
100
+ environment = env,
101
+ ),
102
+ ]
103
+
104
+ def _bash_runfile_env_exports(ctx):
105
+ lines = []
106
+ for runfile_dep, env_var in ctx.attr.runfile_env.items():
107
+ runfile = _runfile_env_file(runfile_dep)
108
+ lines.append('RUNFILE_ENV_ARGS+=("{}=$(resolve_runfile "{}")")'.format(env_var, _runfile_logical_path(runfile)))
109
+ return "\n".join(lines)
110
+
111
+ def _windows_runfile_env_exports(ctx):
112
+ lines = []
113
+ for runfile_dep, env_var in ctx.attr.runfile_env.items():
114
+ runfile = _runfile_env_file(runfile_dep)
115
+ lines.append('call :resolve_runfile "{}"'.format(_runfile_logical_path(runfile)))
116
+ lines.append("if errorlevel 1 exit /b 1")
117
+ lines.append('set "{}=!resolve_runfile_result!"'.format(env_var))
118
+ return "\n".join(lines)
119
+
120
+ def _runfile_env_file(target):
121
+ executable = target[DefaultInfo].files_to_run.executable
122
+ if executable != None:
123
+ return executable
124
+
125
+ files = target[DefaultInfo].files.to_list()
126
+ if len(files) != 1:
127
+ fail("{} must provide an executable or exactly one file for runfile_env".format(target.label))
128
+ return files[0]
129
+
130
+ def _runfile_logical_path(file):
131
+ return file.short_path.removeprefix("../")
132
+
133
+ def _bash_workspace_root_setup(ctx):
134
+ if not ctx.attr.chdir_workspace_root:
135
+ return ""
136
+ return 'export INSTA_WORKSPACE_ROOT="${workspace_root}"\ncd "${workspace_root}"'
137
+
138
+ def _windows_workspace_root_setup(ctx):
139
+ if not ctx.attr.chdir_workspace_root:
140
+ return ""
141
+ return """set "INSTA_WORKSPACE_ROOT=%workspace_root%"
142
+ cd /d "%workspace_root%" || exit /b 1"""
143
+
144
+ workspace_root_test = rule(
145
+ implementation = _workspace_root_test_impl,
146
+ test = True,
147
+ toolchains = ["@bazel_tools//tools/test:default_test_toolchain_type"],
148
+ attrs = {
149
+ "chdir_workspace_root": attr.bool(
150
+ default = True,
151
+ ),
152
+ "data": attr.label_list(
153
+ allow_files = True,
154
+ ),
155
+ "env": attr.string_dict(),
156
+ "runfile_env": attr.label_keyed_string_dict(
157
+ cfg = "target",
158
+ ),
159
+ "test_bin": attr.label(
160
+ cfg = "target",
161
+ executable = True,
162
+ mandatory = True,
163
+ ),
164
+ "test_threads": attr.int(),
165
+ "workspace_root_marker": attr.label(
166
+ allow_single_file = True,
167
+ mandatory = True,
168
+ ),
169
+ "_windows_constraint": attr.label(
170
+ default = "@platforms//os:windows",
171
+ providers = [platform_common.ConstraintValueInfo],
172
+ ),
173
+ "_bash_launcher_template": attr.label(
174
+ allow_single_file = True,
175
+ default = "//:workspace_root_test_launcher.sh.tpl",
176
+ ),
177
+ "_windows_launcher_template": attr.label(
178
+ allow_single_file = True,
179
+ default = "//:workspace_root_test_launcher.bat.tpl",
180
+ ),
181
+ },
182
+ )
183
+
184
+ def codex_rust_crate(
185
+ name,
186
+ crate_name,
187
+ crate_features = [],
188
+ crate_srcs = None,
189
+ crate_edition = None,
190
+ proc_macro = False,
191
+ build_script_enabled = True,
192
+ build_script_data = [],
193
+ compile_data = [],
194
+ binary_compile_data_extra = {},
195
+ lib_data_extra = [],
196
+ rustc_flags_extra = [],
197
+ binary_rustc_flags_extra = {},
198
+ binaries_with_build_commit = [],
199
+ rustc_env = {},
200
+ rustc_env_files = [],
201
+ deps_extra = [],
202
+ integration_compile_data_extra = [],
203
+ integration_test_args = [],
204
+ unit_test_args = [],
205
+ binary_test_target_compatible_with = [],
206
+ integration_test_timeout = None,
207
+ test_data_extra = [],
208
+ test_shard_counts = {},
209
+ test_tags = [],
210
+ test_threads = 0,
211
+ unit_test_timeout = None,
212
+ extra_binaries = [],
213
+ extra_binaries_non_windows = [],
214
+ run_tests_with_wine_exec = False):
215
+ """Defines a Rust crate with library, binaries, and tests wired for Bazel + Cargo parity.
216
+
217
+ The macro mirrors Cargo conventions: it builds a library when `src/` exists,
218
+ wires build scripts, exports `CARGO_BIN_EXE_*` for integration tests, and
219
+ creates unit + integration test targets. Dependency buckets map to the
220
+ Cargo.lock resolution in `@crates`.
221
+
222
+ Args:
223
+ name: Bazel target name for the library, should be the directory name.
224
+ Example: `app-server`.
225
+ crate_name: Cargo crate name from Cargo.toml
226
+ Example: `codex_app_server`.
227
+ crate_features: Cargo features to enable for this crate.
228
+ Crates are only compiled in a single configuration across the workspace, i.e.
229
+ with all features in this list enabled. So use sparingly, and prefer to refactor
230
+ optional functionality to a separate crate.
231
+ crate_srcs: Optional explicit library srcs; [] disables the library target.
232
+ Defaults to `src/**/*.rs` excluding binary entrypoints.
233
+ crate_edition: Rust edition override, if not default.
234
+ You probably don't want this, it's only here for a single caller.
235
+ proc_macro: Whether this crate builds a proc-macro library.
236
+ build_script_data: Data files exposed to the build script at runtime.
237
+ compile_data: Non-Rust compile-time data for the library target.
238
+ binary_compile_data_extra: Mapping from binary names to extra non-Rust
239
+ compile-time data for those binary targets.
240
+ lib_data_extra: Extra runtime data for the library target.
241
+ binary_rustc_flags_extra: Mapping from binary names to extra rustc
242
+ flags for those binary targets.
243
+ binaries_with_build_commit: Binary names that embed STABLE_GIT_COMMIT from the
244
+ generated build-commit environment file. Other workspace status is
245
+ excluded from their compilation inputs.
246
+ rustc_env: Extra rustc_env entries to merge with defaults.
247
+ rustc_env_files: Generated compiler environment files for the library target.
248
+ deps_extra: Extra normal deps beyond @crates resolution.
249
+ Typically only needed when features add additional deps.
250
+ integration_compile_data_extra: Extra compile_data for integration tests.
251
+ integration_test_args: Optional args for integration test binaries.
252
+ unit_test_args: Optional args for the unit test binary.
253
+ binary_test_target_compatible_with: Platform constraints for binary unit tests.
254
+ integration_test_timeout: Optional Bazel timeout for integration test
255
+ targets generated from `tests/*.rs`.
256
+ test_data_extra: Extra runtime data for tests.
257
+ test_shard_counts: Mapping from generated test target name to Bazel
258
+ shard count. Matching tests use native Bazel sharding on the outer
259
+ workspace-root launcher, not rules_rust's inner sharding wrapper.
260
+ The launcher resolves the real Rust test binary through runfiles
261
+ and then assigns each libtest case to a stable bucket by hashing
262
+ the test name. Matching tests are also marked flaky, which gives
263
+ them Bazel's default three attempts.
264
+ test_tags: Tags applied to unit + integration test targets.
265
+ Typically used to disable the sandbox, but see https://bazel.build/reference/be/common-definitions#common.tags
266
+ test_threads: Optional Rust test thread limit for sharded integration tests.
267
+ unit_test_timeout: Optional Bazel timeout for the unit-test target
268
+ generated from `src/**/*.rs`.
269
+ extra_binaries: Additional binary labels to surface as test data and
270
+ `CARGO_BIN_EXE_*` environment variables. These are only needed for binaries from a different crate.
271
+ extra_binaries_non_windows: Like `extra_binaries`, but omitted from
272
+ Windows test data and environment variables. Tests using these
273
+ binaries must be excluded when targeting Windows.
274
+ run_tests_with_wine_exec: Boolean, defaults to False. Whether to emit a
275
+ Wine-exec variant for each integration test. Variants inherit the
276
+ native test's timeout, tags, and shard count.
277
+ """
278
+ test_env = {
279
+ # The launcher resolves an absolute workspace root at runtime so
280
+ # manifest-only platforms like macOS still point Insta at the real
281
+ # `codex-rs` checkout.
282
+ "INSTA_WORKSPACE_ROOT": ".",
283
+ "INSTA_SNAPSHOT_PATH": "src",
284
+ }
285
+
286
+ native.filegroup(
287
+ name = "package-files",
288
+ srcs = native.glob(
289
+ ["**"],
290
+ exclude = [
291
+ "**/BUILD.bazel",
292
+ "BUILD.bazel",
293
+ "target/**",
294
+ ],
295
+ allow_empty = True,
296
+ ),
297
+ visibility = ["//visibility:public"],
298
+ )
299
+
300
+ rustc_env = {
301
+ "BAZEL_PACKAGE": native.package_name(),
302
+ } | rustc_env
303
+
304
+ manifest_relpath = native.package_name()
305
+ if manifest_relpath.startswith("codex-rs/"):
306
+ manifest_relpath = manifest_relpath[len("codex-rs/"):]
307
+ manifest_path = manifest_relpath + "/Cargo.toml"
308
+
309
+ binaries = DEP_DATA.get(native.package_name())["binaries"]
310
+
311
+ lib_srcs = crate_srcs if crate_srcs != None else native.glob(["src/**/*.rs"], exclude = binaries.values(), allow_empty = True)
312
+
313
+ maybe_deps = []
314
+
315
+ if build_script_enabled and native.glob(["build.rs"], allow_empty = True):
316
+ cargo_build_script(
317
+ name = name + "-build-script",
318
+ srcs = ["build.rs"],
319
+ deps = all_crate_deps(build = True),
320
+ data = build_script_data,
321
+ # Some build script deps sniff version-related env vars...
322
+ version = "0.0.0",
323
+ )
324
+
325
+ maybe_deps += [name + "-build-script"]
326
+
327
+ if lib_srcs:
328
+ lib_rule = rust_proc_macro if proc_macro else rust_library
329
+ lib_rule(
330
+ name = name,
331
+ crate_name = crate_name,
332
+ crate_features = crate_features,
333
+ deps = all_crate_deps() + maybe_deps + deps_extra,
334
+ compile_data = compile_data,
335
+ data = lib_data_extra,
336
+ srcs = lib_srcs,
337
+ edition = crate_edition,
338
+ rustc_flags = rustc_flags_extra,
339
+ rustc_env = rustc_env,
340
+ rustc_env_files = rustc_env_files,
341
+ visibility = ["//visibility:public"],
342
+ )
343
+
344
+ unit_test_name = name + "-unit-tests"
345
+ unit_test_binary = name + "-unit-tests-bin"
346
+ unit_test_shard_count = _test_shard_count(test_shard_counts, unit_test_name)
347
+
348
+ # Shard at the workspace_root_test layer. rules_rust's sharding wrapper
349
+ # expects to run from its own runfiles cwd, while workspace_root_test
350
+ # deliberately changes cwd so Insta sees Cargo-like snapshot paths.
351
+ rust_test(
352
+ name = unit_test_binary,
353
+ crate = name,
354
+ crate_features = crate_features,
355
+ deps = all_crate_deps(normal = True, normal_dev = True) + maybe_deps + deps_extra,
356
+ # Unit tests also compile to standalone Windows executables, so
357
+ # keep their stack reserve aligned with binaries and integration
358
+ # tests under gnullvm.
359
+ # Bazel has emitted both `codex-rs/<crate>/...` and
360
+ # `../codex-rs/<crate>/...` paths for `file!()`. Strip either
361
+ # prefix so the workspace-root launcher sees Cargo-like metadata
362
+ # such as `tui/src/...`.
363
+ rustc_flags = rustc_flags_extra + WINDOWS_RUSTC_LINK_FLAGS + [
364
+ "--remap-path-prefix=../codex-rs=",
365
+ "--remap-path-prefix=codex-rs=",
366
+ ],
367
+ rustc_env = rustc_env,
368
+ data = test_data_extra,
369
+ tags = test_tags + ["manual"],
370
+ )
371
+
372
+ unit_test_kwargs = {}
373
+ if unit_test_args:
374
+ unit_test_kwargs["args"] = unit_test_args
375
+ if unit_test_timeout:
376
+ unit_test_kwargs["timeout"] = unit_test_timeout
377
+ if unit_test_shard_count:
378
+ unit_test_kwargs["shard_count"] = unit_test_shard_count
379
+ unit_test_kwargs["flaky"] = True
380
+
381
+ workspace_root_test(
382
+ name = unit_test_name,
383
+ env = test_env,
384
+ test_bin = ":" + unit_test_binary,
385
+ workspace_root_marker = "//codex-rs/utils/cargo-bin:repo_root.marker",
386
+ tags = test_tags,
387
+ **unit_test_kwargs
388
+ )
389
+
390
+ maybe_deps += [name]
391
+
392
+ sanitized_binaries = []
393
+ cargo_env = {}
394
+ cargo_env_runfiles = {}
395
+ for binary, main in binaries.items():
396
+ #binary = binary.replace("-", "_")
397
+ sanitized_binaries.append(binary)
398
+ cargo_env_runfiles[":" + binary] = "CARGO_BIN_EXE_" + binary
399
+ cargo_env["CARGO_BIN_EXE_" + binary] = "$(rlocationpath :%s)" % binary
400
+ rust_binary(
401
+ name = binary,
402
+ crate_name = binary.replace("-", "_"),
403
+ crate_root = main,
404
+ deps = all_crate_deps() + maybe_deps + deps_extra,
405
+ edition = crate_edition,
406
+ # Keep per-binary Cargo link behavior scoped to the matching
407
+ # generated rust_binary instead of leaking it to sibling binaries.
408
+ compile_data = binary_compile_data_extra.get(binary, []),
409
+ rustc_flags = rustc_flags_extra + binary_rustc_flags_extra.get(binary, []) + WINDOWS_RUSTC_LINK_FLAGS,
410
+ # Keep stamp = 0: rules_rust otherwise makes stable-status.txt and
411
+ # volatile-status.txt compiler inputs, even though we only consume
412
+ # STABLE_GIT_COMMIT. BUILD_USER and BUILD_HOST vary across developers
413
+ # and CI workers, while BUILD_TIMESTAMP varies across builds; these
414
+ # unrelated values prevent remote cache reuse for the same commit.
415
+ # Isolate status inputs in build-commit-env's cheap action so its
416
+ # output, and hence this compiler input, changes only with the commit.
417
+ rustc_env_files = ["//bazel/build-info:build-commit-env"] if binary in binaries_with_build_commit else [],
418
+ srcs = native.glob(["src/**/*.rs"]),
419
+ stamp = 0,
420
+ visibility = ["//visibility:public"],
421
+ )
422
+
423
+ binary_unit_test_name = binary + "-bin-unit-tests"
424
+ binary_unit_test_binary = binary_unit_test_name + "-bin"
425
+ binary_unit_test_shard_count = _test_shard_count(test_shard_counts, binary_unit_test_name)
426
+
427
+ # Keep the Rust test manual so the repo-root wrapper owns filtering and
428
+ # sharding while Clippy can still discover the underlying test crate.
429
+ rust_test(
430
+ name = binary_unit_test_binary,
431
+ crate = ":" + binary,
432
+ crate_features = crate_features,
433
+ deps = all_crate_deps(normal_dev = True),
434
+ rustc_flags = rustc_flags_extra + WINDOWS_RUSTC_LINK_FLAGS + [
435
+ "--remap-path-prefix=../codex-rs=",
436
+ "--remap-path-prefix=codex-rs=",
437
+ ],
438
+ rustc_env = rustc_env,
439
+ data = test_data_extra,
440
+ tags = test_tags + ["manual"],
441
+ )
442
+
443
+ binary_unit_test_kwargs = {}
444
+ if unit_test_args:
445
+ binary_unit_test_kwargs["args"] = unit_test_args
446
+ if unit_test_timeout:
447
+ binary_unit_test_kwargs["timeout"] = unit_test_timeout
448
+ if binary_unit_test_shard_count:
449
+ binary_unit_test_kwargs["shard_count"] = binary_unit_test_shard_count
450
+ binary_unit_test_kwargs["flaky"] = True
451
+
452
+ workspace_root_test(
453
+ name = binary_unit_test_name,
454
+ env = test_env,
455
+ test_bin = ":" + binary_unit_test_binary,
456
+ workspace_root_marker = "//codex-rs/utils/cargo-bin:repo_root.marker",
457
+ target_compatible_with = binary_test_target_compatible_with,
458
+ tags = test_tags,
459
+ **binary_unit_test_kwargs
460
+ )
461
+
462
+ for binary_label in extra_binaries:
463
+ sanitized_binaries.append(binary_label)
464
+ binary = Label(binary_label).name
465
+ cargo_env_runfiles[binary_label] = "CARGO_BIN_EXE_" + binary
466
+ cargo_env["CARGO_BIN_EXE_" + binary] = "$(rlocationpath %s)" % binary_label
467
+
468
+ integration_test_binaries = sanitized_binaries
469
+ integration_test_cargo_env = cargo_env
470
+ integration_test_cargo_env_runfiles = cargo_env_runfiles
471
+ integration_test_files = native.glob(["tests/**"], allow_empty = True)
472
+ integration_test_data_extra = [
473
+ data
474
+ for data in test_data_extra
475
+ if data not in cargo_env_runfiles and data not in integration_test_files
476
+ ]
477
+ non_windows_sanitized_binaries = []
478
+ non_windows_cargo_env = {}
479
+ non_windows_cargo_env_runfiles = {}
480
+ if extra_binaries_non_windows:
481
+ for binary_label in extra_binaries_non_windows:
482
+ non_windows_sanitized_binaries.append(binary_label)
483
+ binary = Label(binary_label).name
484
+ non_windows_cargo_env_runfiles[binary_label] = "CARGO_BIN_EXE_" + binary
485
+ non_windows_cargo_env["CARGO_BIN_EXE_" + binary] = "$(rlocationpath %s)" % binary_label
486
+
487
+ integration_test_binaries = sanitized_binaries + select({
488
+ "@platforms//os:windows": [],
489
+ "//conditions:default": non_windows_sanitized_binaries,
490
+ })
491
+ integration_test_cargo_env = select({
492
+ "@platforms//os:windows": cargo_env,
493
+ "//conditions:default": cargo_env | non_windows_cargo_env,
494
+ })
495
+ integration_test_cargo_env_runfiles = select({
496
+ "@platforms//os:windows": cargo_env_runfiles,
497
+ "//conditions:default": cargo_env_runfiles | non_windows_cargo_env_runfiles,
498
+ })
499
+
500
+ wine_host_binaries = {
501
+ env_var.removeprefix("CARGO_BIN_EXE_"): binary_label
502
+ for binary_label, env_var in (cargo_env_runfiles | non_windows_cargo_env_runfiles).items()
503
+ }
504
+
505
+ integration_test_kwargs = {}
506
+ if integration_test_args:
507
+ integration_test_kwargs["args"] = integration_test_args
508
+ if integration_test_timeout:
509
+ integration_test_kwargs["timeout"] = integration_test_timeout
510
+
511
+ for test in native.glob(["tests/*.rs"], allow_empty = True):
512
+ test_file_stem = test.removeprefix("tests/").removesuffix(".rs")
513
+ test_crate_name = test_file_stem.replace("-", "_")
514
+ test_name = name + "-" + test_file_stem.replace("/", "-")
515
+ if not test_name.endswith("-test"):
516
+ test_name += "-test"
517
+ windows_cross_test_binary = test_name + "-windows-cross-bin"
518
+
519
+ test_kwargs = {}
520
+ test_kwargs.update(integration_test_kwargs)
521
+ test_shard_count = _test_shard_count(test_shard_counts, test_name)
522
+ if test_shard_count:
523
+ # Put Bazel sharding on the label users/CI invoke. Do not set
524
+ # rules_rust's experimental_enable_sharding on the Rust test
525
+ # binary: that creates an intermediate wrapper that expects a
526
+ # symlink runfiles tree, while this repo intentionally runs with
527
+ # --noenable_runfiles and usually has only a runfiles manifest.
528
+ test_kwargs["shard_count"] = test_shard_count
529
+ test_kwargs["flaky"] = True
530
+
531
+ integration_test_binary = test_name + "-bin"
532
+
533
+ # There are four generated integration-test shapes:
534
+ #
535
+ # 1. Unsharded native tests keep the plain rust_test label for minimal
536
+ # churn and the usual rules_rust Cargo-like environment.
537
+ # 2. Sharded native tests split into a manual rust_test binary plus an
538
+ # outer workspace_root_test. The outer test action receives Bazel's
539
+ # sharding environment, resolves the real binary through the
540
+ # runfiles manifest, and implements stable libtest sharding itself.
541
+ # 3. Windows cross tests always use the workspace_root_test wrapper so
542
+ # runfile env vars become Windows-native absolute paths before the
543
+ # Rust process starts.
544
+ # 4. Wine-exec tests reuse the native Rust test binary behind a shared
545
+ # Linux runner. The runner starts the cross-built Windows exec server
546
+ # under pinned Wine, injects its URL into the test environment, and
547
+ # owns cleanup. The outer workspace_root_test resolves the runner,
548
+ # test, and server from runfiles, sets a Cargo-like cwd, and applies
549
+ # the native test's shard count.
550
+ if test_shard_count:
551
+ # This target is intentionally a binary-like helper, not the public
552
+ # test target. The wrapper below owns cwd setup, runfile env
553
+ # materialization, sharding, and flaky retry behavior.
554
+ rust_test(
555
+ name = integration_test_binary,
556
+ crate_name = test_crate_name,
557
+ crate_root = test,
558
+ srcs = [test],
559
+ data = integration_test_files + integration_test_binaries + integration_test_data_extra,
560
+ compile_data = integration_test_files + integration_compile_data_extra,
561
+ deps = all_crate_deps(normal = True, normal_dev = True) + maybe_deps + deps_extra,
562
+ # Bazel has emitted both `codex-rs/<crate>/...` and
563
+ # `../codex-rs/<crate>/...` paths for `file!()`. Strip either
564
+ # prefix so Insta records Cargo-like metadata such as `core/tests/...`.
565
+ rustc_flags = rustc_flags_extra + WINDOWS_RUSTC_LINK_FLAGS + [
566
+ "--remap-path-prefix=../codex-rs=",
567
+ "--remap-path-prefix=codex-rs=",
568
+ ],
569
+ rustc_env = rustc_env,
570
+ target_compatible_with = WINDOWS_GNULLVM_INCOMPATIBLE,
571
+ tags = test_tags + ["manual"],
572
+ )
573
+
574
+ workspace_root_test(
575
+ name = test_name,
576
+ env = test_env,
577
+ # CARGO_BIN_EXE_* values are rlocation paths at analysis time.
578
+ # The launcher rewrites them to absolute paths at execution
579
+ # time so tests keep working after chdir_workspace_root and on
580
+ # manifest-only platforms.
581
+ runfile_env = integration_test_cargo_env_runfiles,
582
+ test_bin = ":" + integration_test_binary,
583
+ test_threads = test_threads,
584
+ workspace_root_marker = "//codex-rs/utils/cargo-bin:repo_root.marker",
585
+ target_compatible_with = WINDOWS_GNULLVM_INCOMPATIBLE,
586
+ tags = test_tags,
587
+ **test_kwargs
588
+ )
589
+ else:
590
+ # For unsharded tests, the direct rust_test rule is still fine:
591
+ # there is no rules_rust sharding wrapper to bypass, and env can
592
+ # use rlocation paths directly because the test starts under
593
+ # Bazel's normal test environment.
594
+ rust_test(
595
+ name = test_name,
596
+ crate_name = test_crate_name,
597
+ crate_root = test,
598
+ srcs = [test],
599
+ data = integration_test_files + integration_test_binaries + integration_test_data_extra,
600
+ compile_data = integration_test_files + integration_compile_data_extra,
601
+ deps = all_crate_deps(normal = True, normal_dev = True) + maybe_deps + deps_extra,
602
+ # Bazel has emitted both `codex-rs/<crate>/...` and
603
+ # `../codex-rs/<crate>/...` paths for `file!()`. Strip either
604
+ # prefix so Insta records Cargo-like metadata such as `core/tests/...`.
605
+ rustc_flags = rustc_flags_extra + WINDOWS_RUSTC_LINK_FLAGS + [
606
+ "--remap-path-prefix=../codex-rs=",
607
+ "--remap-path-prefix=codex-rs=",
608
+ ],
609
+ rustc_env = rustc_env,
610
+ env = integration_test_cargo_env,
611
+ target_compatible_with = WINDOWS_GNULLVM_INCOMPATIBLE,
612
+ tags = test_tags,
613
+ **test_kwargs
614
+ )
615
+
616
+ if run_tests_with_wine_exec:
617
+ wine_test_name = test_name.removesuffix("-test") + "-wine-exec-test"
618
+ native_test_binary = ":" + (integration_test_binary if test_shard_count else test_name)
619
+ wine_test_binaries = dict(wine_host_binaries)
620
+
621
+ wine_exec_server = wine_test_name + "-windows-exec-server"
622
+ foreign_platform_binary(
623
+ name = wine_exec_server,
624
+ binary = "//codex-rs/exec-server/testing:exec-server",
625
+ extra_rustc_flags = WINDOWS_GNULLVM_RUSTC_LINK_FLAGS,
626
+ platform = "//:windows_x86_64_gnullvm",
627
+ tags = ["manual"],
628
+ target_compatible_with = [
629
+ "@platforms//cpu:x86_64",
630
+ "@platforms//os:linux",
631
+ ],
632
+ testonly = True,
633
+ visibility = ["//visibility:private"],
634
+ )
635
+ wine_test_binaries["wine-windows-exec-server"] = ":" + wine_exec_server
636
+ wine_runtime = wine_test_runtime(wine_test_binaries)
637
+ wine_runfile_env = dict(wine_runtime.runfile_env)
638
+ wine_runfile_env[native_test_binary] = "CODEX_WINE_EXEC_TEST_BINARY"
639
+
640
+ wine_test_kwargs = {}
641
+ wine_test_kwargs.update(integration_test_kwargs)
642
+ if test_shard_count:
643
+ wine_test_kwargs["shard_count"] = test_shard_count
644
+ wine_test_kwargs["flaky"] = True
645
+
646
+ # The Wine runner is a binary rather than a rust_test, but it still
647
+ # needs a Cargo-like cwd, Bazel sharding, and absolute runfile paths.
648
+ # `workspace_root_test` establishes all three before Wine starts.
649
+ workspace_root_test(
650
+ name = wine_test_name,
651
+ data = wine_runtime.data,
652
+ env = test_env,
653
+ runfile_env = wine_runfile_env,
654
+ test_bin = "//codex-rs/exec-server/testing:wine-exec-test-runner",
655
+ workspace_root_marker = "//codex-rs/utils/cargo-bin:repo_root.marker",
656
+ target_compatible_with = WINE_TEST_TARGET_COMPATIBLE_WITH,
657
+ # This wrapper has no Rust sources and transitions a data
658
+ # dependency to a Windows toolchain the lint does not register.
659
+ tags = test_tags + ["no-argument-comment-lint"],
660
+ **wine_test_kwargs
661
+ )
662
+
663
+ windows_cross_test_kwargs = {}
664
+ windows_cross_test_kwargs.update(integration_test_kwargs)
665
+ if test_shard_count:
666
+ windows_cross_test_kwargs["shard_count"] = test_shard_count
667
+ windows_cross_test_kwargs["flaky"] = True
668
+
669
+ rust_test(
670
+ name = windows_cross_test_binary,
671
+ crate_name = test_crate_name,
672
+ crate_root = test,
673
+ srcs = [test],
674
+ data = integration_test_files + integration_test_binaries + integration_test_data_extra,
675
+ compile_data = integration_test_files + integration_compile_data_extra,
676
+ deps = all_crate_deps(normal = True, normal_dev = True) + maybe_deps + deps_extra,
677
+ rustc_flags = rustc_flags_extra + WINDOWS_RUSTC_LINK_FLAGS + [
678
+ "--remap-path-prefix=../codex-rs=",
679
+ "--remap-path-prefix=codex-rs=",
680
+ ],
681
+ rustc_env = rustc_env,
682
+ env = integration_test_cargo_env,
683
+ target_compatible_with = WINDOWS_GNULLVM_ONLY,
684
+ tags = test_tags + ["manual"],
685
+ )
686
+
687
+ workspace_root_test(
688
+ name = test_name + "-windows-cross",
689
+ chdir_workspace_root = False,
690
+ env = integration_test_cargo_env,
691
+ runfile_env = integration_test_cargo_env_runfiles,
692
+ test_bin = ":" + windows_cross_test_binary,
693
+ workspace_root_marker = "//codex-rs/utils/cargo-bin:repo_root.marker",
694
+ target_compatible_with = WINDOWS_GNULLVM_ONLY,
695
+ tags = test_tags,
696
+ **windows_cross_test_kwargs
697
+ )
698
+
699
+ def _test_shard_count(test_shard_counts, test_name):
700
+ shard_count = test_shard_counts.get(test_name)
701
+ if shard_count == None:
702
+ return None
703
+
704
+ if shard_count < 1:
705
+ fail("test_shard_counts[{}] must be a positive integer".format(test_name))
706
+
707
+ return shard_count
flake.lock ADDED
@@ -0,0 +1,48 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "nodes": {
3
+ "nixpkgs": {
4
+ "locked": {
5
+ "lastModified": 1769461804,
6
+ "narHash": "sha256-msG8SU5WsBUfVVa/9RPLaymvi5bI8edTavbIq3vRlhI=",
7
+ "owner": "NixOS",
8
+ "repo": "nixpkgs",
9
+ "rev": "bfc1b8a4574108ceef22f02bafcf6611380c100d",
10
+ "type": "github"
11
+ },
12
+ "original": {
13
+ "owner": "NixOS",
14
+ "ref": "nixos-unstable",
15
+ "repo": "nixpkgs",
16
+ "type": "github"
17
+ }
18
+ },
19
+ "root": {
20
+ "inputs": {
21
+ "nixpkgs": "nixpkgs",
22
+ "rust-overlay": "rust-overlay"
23
+ }
24
+ },
25
+ "rust-overlay": {
26
+ "inputs": {
27
+ "nixpkgs": [
28
+ "nixpkgs"
29
+ ]
30
+ },
31
+ "locked": {
32
+ "lastModified": 1769828398,
33
+ "narHash": "sha256-zmnvRUm15QrlKH0V1BZoiT3U+Q+tr+P5Osi8qgtL9fY=",
34
+ "owner": "oxalica",
35
+ "repo": "rust-overlay",
36
+ "rev": "a1d32c90c8a4ea43e9586b7e5894c179d5747425",
37
+ "type": "github"
38
+ },
39
+ "original": {
40
+ "owner": "oxalica",
41
+ "repo": "rust-overlay",
42
+ "type": "github"
43
+ }
44
+ }
45
+ },
46
+ "root": "root",
47
+ "version": 7
48
+ }
flake.nix ADDED
@@ -0,0 +1,87 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ description = "Development Nix flake for OpenAI Codex CLI";
3
+
4
+ inputs = {
5
+ nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
6
+ rust-overlay = {
7
+ url = "github:oxalica/rust-overlay";
8
+ inputs.nixpkgs.follows = "nixpkgs";
9
+ };
10
+ };
11
+
12
+ outputs = { self, nixpkgs, rust-overlay, ... }:
13
+ let
14
+ systems = [
15
+ "x86_64-linux"
16
+ "aarch64-linux"
17
+ "x86_64-darwin"
18
+ "aarch64-darwin"
19
+ ];
20
+ forAllSystems = f: nixpkgs.lib.genAttrs systems f;
21
+
22
+ # Read the version from the workspace Cargo.toml (the single source of
23
+ # truth used by the release workflow).
24
+ cargoToml = builtins.fromTOML (builtins.readFile ./codex-rs/Cargo.toml);
25
+ cargoVersion = cargoToml.workspace.package.version;
26
+
27
+ # When building from a release commit the Cargo.toml already carries the
28
+ # real version (e.g. "0.101.0"). On the main branch it is the placeholder
29
+ # "0.0.0", so we fall back to a dev version derived from the flake source.
30
+ version =
31
+ if cargoVersion != "0.0.0"
32
+ then cargoVersion
33
+ else "0.0.0-dev+${self.shortRev or "dirty"}";
34
+ in
35
+ {
36
+ packages = forAllSystems (system:
37
+ let
38
+ pkgs = import nixpkgs {
39
+ inherit system;
40
+ overlays = [ rust-overlay.overlays.default ];
41
+ };
42
+ codex-rs = pkgs.callPackage ./codex-rs {
43
+ inherit version;
44
+ rustPlatform = pkgs.makeRustPlatform {
45
+ cargo = pkgs.rust-bin.stable.latest.minimal;
46
+ rustc = pkgs.rust-bin.stable.latest.minimal;
47
+ };
48
+ };
49
+ in
50
+ {
51
+ codex-rs = codex-rs;
52
+ default = codex-rs;
53
+ }
54
+ );
55
+
56
+ devShells = forAllSystems (system:
57
+ let
58
+ pkgs = import nixpkgs {
59
+ inherit system;
60
+ overlays = [ rust-overlay.overlays.default ];
61
+ };
62
+ rust = pkgs.rust-bin.stable.latest.default.override {
63
+ extensions = [ "rust-src" "rust-analyzer" ];
64
+ };
65
+ in
66
+ {
67
+ default = pkgs.mkShell {
68
+ buildInputs = [
69
+ rust
70
+ pkgs.pkg-config
71
+ pkgs.openssl
72
+ pkgs.cmake
73
+ pkgs.llvmPackages.clang
74
+ pkgs.llvmPackages.libclang.lib
75
+ ];
76
+ PKG_CONFIG_PATH = "${pkgs.openssl.dev}/lib/pkgconfig";
77
+ LIBCLANG_PATH = "${pkgs.llvmPackages.libclang.lib}/lib";
78
+ # Use clang for BoringSSL compilation (avoids GCC 15 warnings-as-errors)
79
+ shellHook = ''
80
+ export CC=clang
81
+ export CXX=clang++
82
+ '';
83
+ };
84
+ }
85
+ );
86
+ };
87
+ }
justfile ADDED
@@ -0,0 +1,205 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ set working-directory := "codex-rs"
2
+ set positional-arguments
3
+ export CODEX_REPO_ROOT := justfile_directory()
4
+ export JUST_SHELL := justfile_directory() / "scripts/just-shell.py"
5
+ set shell := ["python3", "-c", 'import os, runpy; runpy.run_path(os.environ["JUST_SHELL"], run_name="__main__")']
6
+ set windows-shell := ["python", "-c", 'import os, runpy; runpy.run_path(os.environ["JUST_SHELL"], run_name="__main__")']
7
+
8
+ rust_min_stack := "8388608" # 8 MiB
9
+ python := if os_family() == "windows" { "python" } else { "python3" }
10
+
11
+ # Display help
12
+ help:
13
+ just -l
14
+
15
+ # `codex`
16
+ alias c := codex
17
+ codex *args:
18
+ cargo run --bin codex -- {args}
19
+
20
+ # `codex exec`
21
+ exec *args:
22
+ cargo run --bin codex -- exec {args}
23
+
24
+ # Start `codex exec-server` and run codex-tui.
25
+ [no-cd]
26
+ [positional-arguments]
27
+ [unix]
28
+ tui-with-exec-server *args:
29
+ {{ justfile_directory() }}/scripts/run_tui_with_exec_server.sh "$@"
30
+
31
+ # Run the CLI version of the file-search crate.
32
+ file-search *args:
33
+ cargo run --bin codex-file-search -- {args}
34
+
35
+ # Run the standalone code-mode host from source.
36
+ code-mode-host *args:
37
+ cargo run --bin codex-code-mode-host -- {args}
38
+
39
+ # Assemble a local Codex package.
40
+ [no-cd]
41
+ assemble-codex-package *args:
42
+ {{ python }} {{ justfile_directory() }}/scripts/build_codex_package.py {args}
43
+
44
+ # Build the CLI and run the app-server test client
45
+ app-server-test-client *args:
46
+ cargo build -p codex-cli
47
+ cargo run -p codex-app-server-test-client -- --codex-bin ./target/debug/codex {args}
48
+
49
+ # Format the justfile, Rust, Bazel/Starlark, Python SDK code, and Python scripts.
50
+ fmt:
51
+ @{{ python }} ../scripts/format.py
52
+
53
+ # Check formatting without modifying files.
54
+ fmt-check:
55
+ @{{ python }} ../scripts/format.py --check
56
+
57
+ fix *args:
58
+ cargo clippy --fix --tests --allow-dirty {args}
59
+
60
+ clippy *args:
61
+ cargo clippy --tests {args}
62
+
63
+ [unix]
64
+ install:
65
+ rustup show active-toolchain
66
+ cargo fetch
67
+
68
+ [windows]
69
+ install:
70
+ #!powershell.exe -File
71
+ $pwsh = Get-Command pwsh.exe -ErrorAction SilentlyContinue
72
+ if (-not $pwsh) {
73
+ winget install --exact --id Microsoft.PowerShell --source winget --accept-package-agreements --accept-source-agreements
74
+ if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
75
+ }
76
+ rustup show active-toolchain
77
+ if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
78
+ cargo fetch
79
+ exit $LASTEXITCODE
80
+
81
+ # Run nextest with --no-fail-fast so all tests are run.
82
+ #
83
+ # Run `cargo install --locked cargo-nextest` if you don't have it installed.
84
+ # Prefer this for routine local runs. Workspace crate features are banned, so
85
+ # there should be no need to add `--all-features`.
86
+ [unix]
87
+ test *args:
88
+ RUST_MIN_STACK={{ rust_min_stack }} NEXTEST_PROFILE=local cargo nextest run --no-fail-fast "$@"
89
+
90
+ [windows]
91
+ test *args:
92
+ $env:RUST_MIN_STACK = "{{ rust_min_stack }}"; $env:NEXTEST_PROFILE = "local"; cargo nextest run --no-fail-fast @($args | Select-Object -Skip 1)
93
+
94
+ # Run from the repository root so scripts that resolve paths from `cwd` see
95
+ # the same layout they use in GitHub Actions.
96
+ [no-cd]
97
+ test-github-scripts:
98
+ {{ python }} -m unittest discover -s {{ justfile_directory() }}/.github/scripts -p 'test_*.py'
99
+
100
+ # Run explicit workspace benchmark targets.
101
+ bench *args:
102
+ cargo bench --workspace --bench '*' {args}
103
+
104
+ # Run benchmark targets once to ensure they start successfully.
105
+ bench-smoke:
106
+ just bench -- --test
107
+
108
+ # Run Bazel-backed end-to-end macrobenchmarks with optimized binaries.
109
+ bench-e2e:
110
+ # Keep measured binaries comparable to production-style optimized builds.
111
+ bazel test --compilation_mode=opt --cache_test_results=no --test_output=streamed //codex-rs:e2e-benchmarks
112
+
113
+ # Run Bazel-backed end-to-end macrobenchmarks once per case with release-like
114
+ # Rust cfg paths but fastbuild codegen.
115
+ bench-e2e-smoke:
116
+ # Avoid optimizer cost because smoke runs only check that benchmarks work.
117
+ # Compile target Rust code through the same release-only cfg paths as opt.
118
+ # Compile exec-platform Rust tools through those release-only cfg paths too.
119
+ bazel test --compilation_mode=fastbuild --@rules_rust//rust/settings:extra_rustc_flag=-Cdebug-assertions=no --@rules_rust//rust/settings:extra_exec_rustc_flag=-Cdebug-assertions=no --cache_test_results=no --test_output=streamed --test_arg=--test //codex-rs:e2e-benchmarks
120
+
121
+ # Build and run Codex from source using Bazel.
122
+ # On Unix, use `[no-cd]` and `--run_under="cd $PWD &&"` to ensure Bazel runs
123
+ # the command in the current working directory.
124
+ [no-cd]
125
+ [unix]
126
+ bazel-codex *args:
127
+ bazel run //codex-rs/cli:codex --run_under="cd $PWD &&" -- "$@"
128
+
129
+ [windows]
130
+ bazel-codex *args:
131
+ bazel run //codex-rs/cli:codex --run_under='cd /d "{{ invocation_directory_native() }}" &&' -- @($args | Select-Object -Skip 1)
132
+
133
+ # Build and run the standalone code-mode host from source using Bazel.
134
+ [no-cd]
135
+ [unix]
136
+ bazel-code-mode-host *args:
137
+ bazel run //codex-rs/code-mode-host:codex-code-mode-host --run_under="cd $PWD &&" -- "$@"
138
+
139
+ [windows]
140
+ bazel-code-mode-host *args:
141
+ bazel run //codex-rs/code-mode-host:codex-code-mode-host --run_under='cd /d "{{ invocation_directory_native() }}" &&' -- @($args | Select-Object -Skip 1)
142
+
143
+ [no-cd]
144
+ bazel-lock-update:
145
+ bazel mod deps --lockfile_mode=update
146
+
147
+ [no-cd]
148
+ [unix]
149
+ bazel-lock-check:
150
+ {{ justfile_directory() }}/scripts/check-module-bazel-lock.sh
151
+
152
+ [windows]
153
+ bazel-lock-check:
154
+ bazel mod deps --lockfile_mode=error; if ($LASTEXITCODE -ne 0) { Write-Error "MODULE.bazel.lock is out of date. Run 'just bazel-lock-update' and commit the updated lockfile."; exit 1 }
155
+
156
+ bazel-test:
157
+ bazel test --test_tag_filters=-argument-comment-lint //... --keep_going
158
+
159
+ [no-cd]
160
+ [unix]
161
+ bazel-clippy:
162
+ bazel_targets="$({{ justfile_directory() }}/scripts/list-bazel-clippy-targets.sh)" && bazel build --config=clippy -- ${bazel_targets}
163
+
164
+ [no-cd]
165
+ [unix]
166
+ bazel-argument-comment-lint:
167
+ bazel build --config=argument-comment-lint -- $({{ justfile_directory() }}/tools/argument-comment-lint/list-bazel-targets.sh)
168
+
169
+ build-for-release:
170
+ bazel build //codex-rs/cli:release_binaries
171
+
172
+ # Regenerate the json schema for config.toml from the current config types.
173
+ write-config-schema:
174
+ cargo run -p codex-config-schema --bin codex-write-config-schema
175
+
176
+ # Regenerate app-server protocol schemas and the Python SDK derived from them.
177
+ write-app-server-schema *args:
178
+ {{ python }} app-server-protocol/scripts/write_schema_fixtures.py {args}
179
+
180
+ [no-cd]
181
+ write-hooks-schema:
182
+ cargo run --manifest-path {{ justfile_directory() }}/codex-rs/Cargo.toml -p codex-hooks --bin write_hooks_schema_fixtures
183
+
184
+ # Run the argument-comment Dylint checks across codex-rs.
185
+ [no-cd]
186
+ [unix]
187
+ argument-comment-lint *args:
188
+ if [ "$#" -eq 0 ]; then \
189
+ bazel build --config=argument-comment-lint -- $({{ justfile_directory() }}/tools/argument-comment-lint/list-bazel-targets.sh); \
190
+ else \
191
+ {{ justfile_directory() }}/tools/argument-comment-lint/run-prebuilt-linter.py "$@"; \
192
+ fi
193
+
194
+ [no-cd]
195
+ argument-comment-lint-from-source *args:
196
+ {{ python }} {{ justfile_directory() }}/tools/argument-comment-lint/run.py {args}
197
+
198
+ # Tail logs from the state SQLite database
199
+ [unix]
200
+ log *args:
201
+ if [ "${1:-}" = "--" ]; then shift; fi; cargo run -p codex-cli --bin logs_client -- "$@"
202
+
203
+ [windows]
204
+ log *args:
205
+ $forwarded_args = @($args | Select-Object -Skip 1); if ($forwarded_args.Count -gt 0 -and $forwarded_args[0] -eq "--") { $forwarded_args = @($forwarded_args | Select-Object -Skip 1) }; cargo run -p codex-cli --bin logs_client -- @forwarded_args
package.json ADDED
@@ -0,0 +1,39 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "name": "codex-monorepo",
3
+ "private": true,
4
+ "description": "Tools for repo-wide maintenance.",
5
+ "scripts": {
6
+ "format": "prettier --check *.json *.md docs/*.md .github/workflows/*.yml **/*.js",
7
+ "format:fix": "prettier --write *.json *.md docs/*.md .github/workflows/*.yml **/*.js",
8
+ "write-hooks-schema": "cargo run --manifest-path ./codex-rs/Cargo.toml -p codex-hooks --bin write_hooks_schema_fixtures"
9
+ },
10
+ "devDependencies": {
11
+ "prettier": "^3.5.3"
12
+ },
13
+ "resolutions": {
14
+ "@modelcontextprotocol/sdk": "1.26.0",
15
+ "braces": "^3.0.3",
16
+ "esbuild": "0.28.1",
17
+ "fast-uri": "3.1.1",
18
+ "flatted": "3.4.2",
19
+ "glob@10.4.5": "10.5.0",
20
+ "handlebars": "4.7.9",
21
+ "hono": "4.12.25",
22
+ "micromatch": "^4.0.8",
23
+ "minimatch@3.1.2": "3.1.4",
24
+ "minimatch@9.0.5": "9.0.7",
25
+ "path-to-regexp": "8.4.0",
26
+ "picomatch@2.3.1": "2.3.2",
27
+ "picomatch@4.0.3": "4.0.4",
28
+ "rollup": "4.59.0",
29
+ "semver": "^7.7.1"
30
+ },
31
+ "overrides": {
32
+ "punycode": "^2.3.1"
33
+ },
34
+ "engines": {
35
+ "node": ">=22",
36
+ "pnpm": ">=10.34.5"
37
+ },
38
+ "packageManager": "pnpm@10.34.5+sha512.a4ee05f2f73658255bd6a89859c065a45c28a57daefae2c893a168ee2b73168c37b91e83e57ea67654ad03f03031746430e8bce38e362e042605fb8abc80192e"
39
+ }
patches/rules_rust_build_script_tools_transition.patch ADDED
@@ -0,0 +1,19 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ diff --git a/cargo/private/cargo_build_script.bzl b/cargo/private/cargo_build_script.bzl
2
+ --- a/cargo/private/cargo_build_script.bzl
3
+ +++ b/cargo/private/cargo_build_script.bzl
4
+ @@ -396,3 +396,8 @@ def _cargo_build_script_impl(ctx):
5
+ + script_tools = []
6
+ + for target in ctx.attr.tools:
7
+ + script_tools.append(target[DefaultInfo].files)
8
+ + script_tools.append(target[DefaultInfo].default_runfiles.files)
9
+ +
10
+ workspace_name = ctx.label.workspace_name
11
+ if not workspace_name:
12
+ workspace_name = ctx.workspace_name
13
+ @@ -581,5 +586,5 @@ def _cargo_build_script_impl(ctx):
14
+ direct = [
15
+ ctx.executable._cargo_build_script_runner,
16
+ ] + ([toolchain.target_json] if toolchain.target_json else []),
17
+ - transitive = script_data + toolchain_tools,
18
+ + transitive = script_data + script_tools + toolchain_tools,
19
+ )
patches/v8_bazel_rules.patch ADDED
@@ -0,0 +1,502 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # What: adapt upstream V8 Bazel rules to this workspace's hermetic toolchains
2
+ # and externally provided dependencies.
3
+ # Scope: Bazel BUILD/defs/BUILD.icu integration only, including dependency
4
+ # wiring, generated sources, and visibility; no standalone V8 source patching.
5
+
6
+ diff --git a/orig/v8-15.0.245.2/bazel/defs.bzl b/mod/v8-15.0.245.2/bazel/defs.bzl
7
+ index bbe1495..6673518 100644
8
+ --- a/orig/v8-15.0.245.2/bazel/defs.bzl
9
+ +++ b/mod/v8-15.0.245.2/bazel/defs.bzl
10
+ @@ -33,9 +33,21 @@ _create_option_int = rule(
11
+ )
12
+
13
+ def v8_flag(name, default = False):
14
+ - _create_option_flag(name = name, build_setting_default = default)
15
+ - native.config_setting(name = "is_" + name, flag_values = {name: "True"})
16
+ - native.config_setting(name = "is_not_" + name, flag_values = {name: "False"})
17
+ + _create_option_flag(
18
+ + name = name,
19
+ + build_setting_default = default,
20
+ + visibility = ["//visibility:public"],
21
+ + )
22
+ + native.config_setting(
23
+ + name = "is_" + name,
24
+ + flag_values = {name: "True"},
25
+ + visibility = ["//visibility:public"],
26
+ + )
27
+ + native.config_setting(
28
+ + name = "is_not_" + name,
29
+ + flag_values = {name: "False"},
30
+ + visibility = ["//visibility:public"],
31
+ + )
32
+
33
+ def v8_string(name, default = ""):
34
+ _create_option_string(name = name, build_setting_default = default)
35
+ @@ -97,7 +109,13 @@ v8_config = rule(
36
+
37
+ def _default_args():
38
+ return struct(
39
+ - deps = [":define_flags", "@libcxx//:libc++"],
40
+ + deps = [":define_flags"] + select({
41
+ + "@v8//:is_v8_use_rusty_v8_custom_libcxx": [
42
+ + "@@//third_party/v8:rusty_v8_custom_libcxx_headers",
43
+ + "@@//third_party/v8:rusty_v8_custom_libcxx_runtime",
44
+ + ],
45
+ + "//conditions:default": [],
46
+ + }),
47
+ defines = select({
48
+ "@v8//bazel/config:is_windows": [
49
+ "UNICODE",
50
+ @@ -127,12 +145,15 @@ def _default_args():
51
+ ],
52
+ "//conditions:default": [],
53
+ }) + select({
54
+ - "@v8//bazel/config:is_clang": [
55
+ - "-Wno-invalid-offsetof",
56
+ - "-Wno-deprecated-this-capture",
57
+ - "-Wno-deprecated-declarations",
58
+ - "-std=c++20",
59
+ + "@v8//:is_v8_use_rusty_v8_custom_libcxx": [
60
+ + "-nostdinc++",
61
+ + "-D_LIBCPP_DISABLE_VISIBILITY_ANNOTATIONS",
62
+ + "-D_LIBCPP_HARDENING_MODE=_LIBCPP_HARDENING_MODE_EXTENSIVE",
63
+ + "-D_LIBCPP_INSTRUMENTED_WITH_ASAN=0",
64
+ + "-D_LIBCXXABI_DISABLE_VISIBILITY_ANNOTATIONS",
65
+ ],
66
+ + "//conditions:default": [],
67
+ + }) + select({
68
+ "@v8//bazel/config:is_gcc": [
69
+ "-Wno-extra",
70
+ "-Wno-array-bounds",
71
+ @@ -152,9 +173,17 @@ def _default_args():
72
+ "-std=gnu++2a",
73
+ ],
74
+ "@v8//bazel/config:is_windows": [
75
+ - "/std:c++20",
76
+ + "-Wno-invalid-offsetof",
77
+ + "-Wno-deprecated-this-capture",
78
+ + "-Wno-deprecated-declarations",
79
+ + "-std=c++20",
80
+ + ],
81
+ + "//conditions:default": [
82
+ + "-Wno-invalid-offsetof",
83
+ + "-Wno-deprecated-this-capture",
84
+ + "-Wno-deprecated-declarations",
85
+ + "-std=c++20",
86
+ ],
87
+ - "//conditions:default": [],
88
+ }) + select({
89
+ "@v8//bazel/config:is_gcc_fastbuild": [
90
+ # Non-debug builds without optimizations fail because
91
+ @@ -178,12 +207,12 @@ def _default_args():
92
+ includes = ["include"],
93
+ linkopts = select({
94
+ "@v8//bazel/config:is_windows": [
95
+ - "Winmm.lib",
96
+ - "DbgHelp.lib",
97
+ - "Advapi32.lib",
98
+ + "-lwinmm",
99
+ + "-ldbghelp",
100
+ + "-ladvapi32",
101
+ ],
102
+ "@v8//bazel/config:is_macos": ["-pthread"],
103
+ - "//conditions:default": ["-Wl,--no-as-needed -ldl -latomic -pthread"],
104
+ + "//conditions:default": ["-Wl,--no-as-needed -ldl -pthread"],
105
+ }) + select({
106
+ ":should_add_rdynamic": ["-rdynamic"],
107
+ "//conditions:default": [],
108
+ @@ -459,6 +488,11 @@
109
+ def _mksnapshot(ctx):
110
+ prefix = ctx.attr.prefix
111
+ suffix = ctx.attr.suffix
112
+ + # Windows cross-builds use Linux for the exec configuration, but the
113
+ + # snapshot generator must match the target ABI and run on the Windows
114
+ + # runner. Action strategies only choose where an action runs; they cannot
115
+ + # change this executable from the exec to the target configuration.
116
+ + tool = ctx.executable.target_tool if ctx.attr.target_os == "win" else ctx.executable.tool
117
+ outs = [
118
+ ctx.actions.declare_file(prefix + "/snapshot" + suffix + ".cc"),
119
+ ctx.actions.declare_file(prefix + "/embedded" + suffix + ".S"),
120
+ @@ -477,6 +511,6 @@
121
+ outs[1].path,
122
+ ] + ctx.attr.args,
123
+ - executable = ctx.executable.tool,
124
+ + executable = tool,
125
+ progress_message = "Running mksnapshot",
126
+ )
127
+ return [DefaultInfo(files = depset(outs))]
128
+ @@ -491,6 +525,12 @@
129
+ executable = True,
130
+ cfg = "exec",
131
+ ),
132
+ + "target_tool": attr.label(
133
+ + mandatory = True,
134
+ + allow_files = True,
135
+ + executable = True,
136
+ + cfg = "target",
137
+ + ),
138
+ "target_os": attr.string(mandatory = True),
139
+ "prefix": attr.string(mandatory = True),
140
+ "suffix": attr.string(mandatory = True),
141
+ @@ -504,6 +544,7 @@
142
+ args = args,
143
+ prefix = "noicu",
144
+ tool = ":noicu/mksnapshot" + suffix,
145
+ + target_tool = ":noicu/mksnapshot" + suffix,
146
+ suffix = suffix,
147
+ target_os = select({
148
+ "@v8//bazel/config:is_macos": "mac",
149
+ @@ -516,6 +557,7 @@
150
+ args = args,
151
+ prefix = "icu",
152
+ tool = ":icu/mksnapshot" + suffix,
153
+ + target_tool = ":icu/mksnapshot" + suffix,
154
+ suffix = suffix,
155
+ target_os = select({
156
+ "@v8//bazel/config:is_macos": "mac",
157
+ diff --git a/orig/v8-15.0.245.2/BUILD.bazel b/mod/v8-15.0.245.2/BUILD.bazel
158
+ index b432f86..28c567b 100644
159
+ --- a/orig/v8-15.0.245.2/BUILD.bazel
160
+ +++ b/mod/v8-15.0.245.2/BUILD.bazel
161
+ @@ -148,6 +148,10 @@ v8_flag(name = "v8_enable_trace_maps")
162
+
163
+ v8_flag(name = "v8_enable_v8_checks")
164
+
165
+ +v8_flag(name = "v8_enable_sandbox")
166
+ +
167
+ +v8_flag(name = "v8_use_rusty_v8_custom_libcxx")
168
+ +
169
+ v8_flag(name = "v8_enable_verify_csa")
170
+
171
+ v8_flag(name = "v8_enable_verify_heap")
172
+ @@ -313,7 +317,7 @@ v8_int(
173
+ # If no explicit value for v8_enable_pointer_compression, we set it to 'none'.
174
+ v8_string(
175
+ name = "v8_enable_pointer_compression",
176
+ - default = "none",
177
+ + default = "False",
178
+ )
179
+
180
+ # Default setting for v8_enable_pointer_compression.
181
+ @@ -513,6 +517,7 @@ v8_config(
182
+ "v8_enable_slow_dchecks": "ENABLE_SLOW_DCHECKS",
183
+ "v8_enable_runtime_call_stats": "V8_RUNTIME_CALL_STATS",
184
+ "v8_enable_snapshot_native_code_counters": "V8_SNAPSHOT_NATIVE_CODE_COUNTERS",
185
+ + "v8_enable_sandbox": "V8_ENABLE_SANDBOX",
186
+ "v8_enable_trace_maps": "V8_TRACE_MAPS",
187
+ "v8_enable_turbofan": "V8_ENABLE_TURBOFAN",
188
+ "v8_enable_v8_checks": "V8_ENABLE_CHECKS",
189
+ @@ -4125,28 +4130,14 @@ filegroup(
190
+ }),
191
+ )
192
+
193
+ -v8_library(
194
+ - name = "lib_dragonbox",
195
+ - srcs = ["third_party/dragonbox/src/include/dragonbox/dragonbox.h"],
196
+ - hdrs = [
197
+ - "third_party/dragonbox/src/include/dragonbox/dragonbox.h",
198
+ - ],
199
+ - includes = [
200
+ - "third_party/dragonbox/src/include",
201
+ - ],
202
+ +alias(
203
+ + name = "lib_dragonbox",
204
+ + actual = "@dragonbox//:dragonbox",
205
+ )
206
+
207
+ -v8_library(
208
+ - name = "lib_fp16",
209
+ - srcs = ["third_party/fp16/src/include/fp16.h"],
210
+ - hdrs = [
211
+ - "third_party/fp16/src/include/fp16/fp16.h",
212
+ - "third_party/fp16/src/include/fp16/bitcasts.h",
213
+ - "third_party/fp16/src/include/fp16/macros.h",
214
+ - ],
215
+ - includes = [
216
+ - "third_party/fp16/src/include",
217
+ - ],
218
+ +alias(
219
+ + name = "lib_fp16",
220
+ + actual = "@fp16//:fp16",
221
+ )
222
+
223
+ filegroup(
224
+ @@ -4441,6 +4432,20 @@ genrule(
225
+ srcs = [
226
+ "include/js_protocol.pdl",
227
+ "src/inspector/inspector_protocol_config.json",
228
+ + "third_party/inspector_protocol/code_generator.py",
229
+ + "third_party/inspector_protocol/pdl.py",
230
+ + "third_party/inspector_protocol/lib/Forward_h.template",
231
+ + "third_party/inspector_protocol/lib/Object_cpp.template",
232
+ + "third_party/inspector_protocol/lib/Object_h.template",
233
+ + "third_party/inspector_protocol/lib/Protocol_cpp.template",
234
+ + "third_party/inspector_protocol/lib/ValueConversions_cpp.template",
235
+ + "third_party/inspector_protocol/lib/ValueConversions_h.template",
236
+ + "third_party/inspector_protocol/lib/Values_cpp.template",
237
+ + "third_party/inspector_protocol/lib/Values_h.template",
238
+ + "third_party/inspector_protocol/templates/Exported_h.template",
239
+ + "third_party/inspector_protocol/templates/Imported_h.template",
240
+ + "third_party/inspector_protocol/templates/TypeBuilder_cpp.template",
241
+ + "third_party/inspector_protocol/templates/TypeBuilder_h.template",
242
+ ],
243
+ outs = [
244
+ "include/inspector/Debugger.h",
245
+ @@ -4462,15 +4467,19 @@ genrule(
246
+ "src/inspector/protocol/Schema.cpp",
247
+ "src/inspector/protocol/Schema.h",
248
+ ],
249
+ - cmd = "$(location :code_generator) --jinja_dir . \
250
+ - --inspector_protocol_dir third_party/inspector_protocol \
251
+ + cmd = "INSPECTOR_PROTOCOL_DIR=$$(dirname $(execpath third_party/inspector_protocol/code_generator.py)); \
252
+ + PYTHONPATH=$$INSPECTOR_PROTOCOL_DIR:external/rules_python++pip+v8_python_deps_311_jinja2/site-packages:external/rules_python++pip+v8_python_deps_311_markupsafe/site-packages:$${PYTHONPATH-} \
253
+ + $(execpath @rules_python//python/bin:python) $(execpath third_party/inspector_protocol/code_generator.py) --jinja_dir . \
254
+ + --inspector_protocol_dir $$INSPECTOR_PROTOCOL_DIR \
255
+ --config $(location :src/inspector/inspector_protocol_config.json) \
256
+ --config_value protocol.path=$(location :include/js_protocol.pdl) \
257
+ + --config_value crdtp.dir=third_party/inspector_protocol/crdtp \
258
+ --output_base $(@D)/src/inspector",
259
+ - local = 1,
260
+ message = "Generating inspector files",
261
+ tools = [
262
+ - ":code_generator",
263
+ + "@rules_python//python/bin:python",
264
+ + requirement("jinja2"),
265
+ + requirement("markupsafe"),
266
+ ],
267
+ )
268
+
269
+ @@ -4484,6 +4493,35 @@ filegroup(
270
+ ],
271
+ )
272
+
273
+ +cc_library(
274
+ + name = "rusty_v8_internal_headers",
275
+ + hdrs = [
276
+ + "src/libplatform/default-platform.h",
277
+ + ],
278
+ + strip_include_prefix = "",
279
+ + visibility = ["//visibility:public"],
280
+ +)
281
+ +
282
+ +cc_library(
283
+ + name = "rusty_v8_crdtp_headers",
284
+ + hdrs = [
285
+ + "third_party/inspector_protocol/crdtp/cbor.h",
286
+ + "third_party/inspector_protocol/crdtp/dispatch.h",
287
+ + "third_party/inspector_protocol/crdtp/error_support.h",
288
+ + "third_party/inspector_protocol/crdtp/export.h",
289
+ + "third_party/inspector_protocol/crdtp/find_by_first.h",
290
+ + "third_party/inspector_protocol/crdtp/frontend_channel.h",
291
+ + "third_party/inspector_protocol/crdtp/json.h",
292
+ + "third_party/inspector_protocol/crdtp/parser_handler.h",
293
+ + "third_party/inspector_protocol/crdtp/protocol_core.h",
294
+ + "third_party/inspector_protocol/crdtp/serializable.h",
295
+ + "third_party/inspector_protocol/crdtp/span.h",
296
+ + "third_party/inspector_protocol/crdtp/status.h",
297
+ + ],
298
+ + strip_include_prefix = "",
299
+ + visibility = ["//visibility:public"],
300
+ +)
301
+ +
302
+ filegroup(
303
+ name = "d8_files",
304
+ srcs = [
305
+ @@ -4576,12 +4614,10 @@ cc_library(
306
+ strip_include_prefix = "noicu",
307
+ )
308
+ -
309
+ +
310
+ -cc_library(
311
+ - name = "llvm_libc_headers",
312
+ - hdrs = glob(["third_party/llvm-libc/src/shared/**/*.h"]),
313
+ - includes = ["third_party/llvm-libc/src"],
314
+ - defines = ["LIBC_NAMESPACE=__llvm_libc_cr"],
315
+ -)
316
+ +alias(
317
+ + name = "llvm_libc_headers",
318
+ + actual = "@@//third_party/v8:rusty_v8_llvm_libc_headers",
319
+ +)
320
+ -
321
+ +
322
+ v8_library(
323
+ name = "v8_libbase",
324
+ @@ -4603,16 +4641,9 @@ cc_library(
325
+ ],
326
+ )
327
+
328
+ -cc_library(
329
+ - name = "simdutf",
330
+ - srcs = ["third_party/simdutf/simdutf.cpp"],
331
+ - hdrs = ["third_party/simdutf/simdutf.h"],
332
+ - copts = select({
333
+ - "@v8//bazel/config:is_clang": ["-std=c++20"],
334
+ - "@v8//bazel/config:is_gcc": ["-std=gnu++2a"],
335
+ - "@v8//bazel/config:is_windows": ["/std:c++20"],
336
+ - "//conditions:default": [],
337
+ - }),
338
+ +alias(
339
+ + name = "simdutf",
340
+ + actual = "@simdutf//:simdutf",
341
+ )
342
+
343
+ v8_library(
344
+ @@ -4629,7 +4660,7 @@ v8_library(
345
+ copts = ["-Wno-implicit-fallthrough"],
346
+ icu_deps = [
347
+ ":icu/generated_torque_definitions_headers",
348
+ - "//external:icu",
349
+ + "@icu//:icu",
350
+ ],
351
+ icu_srcs = [
352
+ ":generated_regexp_special_case",
353
+ @@ -4644,7 +4675,7 @@ v8_library(
354
+ ],
355
+ deps = [
356
+ ":lib_dragonbox",
357
+ - "//third_party/fast_float/src:fast_float",
358
+ + "@fast_float//:fast_float",
359
+ ":lib_fp16",
360
+ ":simdutf",
361
+ ":v8_libbase",
362
+ @@ -4700,6 +4731,7 @@ alias(
363
+ alias(
364
+ name = "core_lib_icu",
365
+ actual = "icu/v8",
366
+ + visibility = ["//visibility:public"],
367
+ )
368
+
369
+ v8_library(
370
+ @@ -4751,7 +4783,7 @@ v8_binary(
371
+ ],
372
+ deps = [
373
+ ":v8_libbase",
374
+ - "//external:icu",
375
+ + "@icu//:icu",
376
+ ],
377
+ )
378
+
379
+ @@ -4791,9 +4823,20 @@ v8_binary(
380
+ ":icu/generated_torque_initializers",
381
+ ":icu/v8_initializers_files",
382
+ ],
383
+ + # Match GN's mksnapshot `disable_icf` config. If the linker folds distinct
384
+ + # external-reference helpers together while producing the snapshot, the
385
+ + # final embedder binary may not fold the same pair and startup
386
+ + # deserialization will reject the snapshot.
387
+ + # GN also increases the x64 Windows stack reserve because constructing the
388
+ + # snapshot overflows the linker's 1 MiB default.
389
+ linkopts = select({
390
+ "@v8//bazel/config:is_android": ["-llog"],
391
+ - "//conditions:default": [],
392
+ + "@v8//bazel/config:is_macos": ["-Wl,-no_deduplicate"],
393
+ + "@v8//bazel/config:is_windows": [
394
+ + "-Wl,/OPT:NOICF",
395
+ + "-Wl,/STACK:2097152",
396
+ + ],
397
+ + "//conditions:default": ["-Wl,--icf=none"],
398
+ }),
399
+ noicu_deps = [":v8_libshared_noicu"],
400
+ noicu_srcs = [
401
+ diff --git a/orig/v8-15.0.245.2/bazel/BUILD.icu b/mod/v8-15.0.245.2/bazel/BUILD.icu
402
+ index 5fda2f4..8c3c372 100644
403
+ --- a/orig/v8-15.0.245.2/bazel/BUILD.icu
404
+ +++ b/mod/v8-15.0.245.2/bazel/BUILD.icu
405
+ @@ -1,3 +1,24 @@
406
+ +load("@rules_cc//cc:defs.bzl", "cc_library")
407
+ +
408
+ +CUSTOM_LIBCXX_COPTS = select({
409
+ + "@v8//:is_v8_use_rusty_v8_custom_libcxx": [
410
+ + "-nostdinc++",
411
+ + "-D_LIBCPP_DISABLE_VISIBILITY_ANNOTATIONS",
412
+ + "-D_LIBCPP_HARDENING_MODE=_LIBCPP_HARDENING_MODE_EXTENSIVE",
413
+ + "-D_LIBCPP_INSTRUMENTED_WITH_ASAN=0",
414
+ + "-D_LIBCXXABI_DISABLE_VISIBILITY_ANNOTATIONS",
415
+ + ],
416
+ + "//conditions:default": [],
417
+ +})
418
+ +
419
+ +CUSTOM_LIBCXX_DEPS = select({
420
+ + "@v8//:is_v8_use_rusty_v8_custom_libcxx": [
421
+ + "@@//third_party/v8:rusty_v8_custom_libcxx_headers",
422
+ + "@@//third_party/v8:rusty_v8_custom_libcxx_runtime",
423
+ + ],
424
+ + "//conditions:default": [],
425
+ +})
426
+ +
427
+ # Copyright 2021 the V8 project authors. All rights reserved.
428
+ # Use of this source code is governed by a BSD-style license that can be
429
+ # found in the LICENSE file.
430
+ @@ -16,15 +37,12 @@ cc_library(
431
+ ]),
432
+ copts = select({
433
+ "@platforms//os:windows": [
434
+ - "/wd4005", # Macro redefinition.
435
+ - "/wd4068", # Unknown pragmas.
436
+ - "/wd4267", # Conversion from size_t on 64-bits.
437
+ - "/utf-8", # ICU source files are in UTF-8.
438
+ + "-Wno-deprecated-declarations",
439
+ ],
440
+ "//conditions:default": [
441
+ "-Wno-deprecated-declarations",
442
+ ],
443
+ - }),
444
+ + }) + CUSTOM_LIBCXX_COPTS,
445
+ data = [":icudata"],
446
+ defines = [
447
+ "HAVE_DLOPEN=0",
448
+ @@ -54,6 +72,7 @@ cc_library(
449
+ "U_ICUDATAENTRY_IN_COMMON",
450
+ ],
451
+ tags = ["requires-rtti"],
452
+ + deps = CUSTOM_LIBCXX_DEPS,
453
+ alwayslink = 1,
454
+ )
455
+
456
+ @@ -65,19 +84,16 @@ cc_library(
457
+ ]),
458
+ copts = select({
459
+ "@platforms//os:windows": [
460
+ - "/wd4005", # Macro redefinition.
461
+ - "/wd4068", # Unknown pragmas.
462
+ - "/wd4267", # Conversion from size_t on 64-bits.
463
+ - "/utf-8", # ICU source files are in UTF-8.
464
+ + "-Wno-deprecated-declarations",
465
+ ],
466
+ "//conditions:default": [
467
+ "-Wno-deprecated-declarations",
468
+ ],
469
+ - }),
470
+ + }) + CUSTOM_LIBCXX_COPTS,
471
+ local_defines = [
472
+ "U_I18N_IMPLEMENTATION",
473
+ ],
474
+ - deps = [":icuuc"],
475
+ + deps = [":icuuc"] + CUSTOM_LIBCXX_DEPS,
476
+ alwayslink = 1,
477
+ )
478
+
479
+ @@ -93,13 +109,10 @@ cc_library(
480
+ ]),
481
+ copts = select({
482
+ "@platforms//os:windows": [
483
+ - "/wd4005", # Macro redefinition.
484
+ - "/wd4068", # Unknown pragmas.
485
+ - "/wd4267", # Conversion from size_t on 64-bits.
486
+ - "/utf-8", # ICU source files are in UTF-8.
487
+ + "-Wno-deprecated-declarations",
488
+ ],
489
+ "//conditions:default": [],
490
+ - }),
491
+ + }) + CUSTOM_LIBCXX_COPTS,
492
+ include_prefix = "third_party/icu",
493
+ local_defines = [
494
+ "U_COMMON_IMPLEMENTATION",
495
+ @@ -108,6 +121,6 @@ cc_library(
496
+ deps = [
497
+ ":icui18n",
498
+ ":icuuc",
499
+ - ],
500
+ + ] + CUSTOM_LIBCXX_DEPS,
501
+ alwayslink = 1,
502
+ )
patches/v8_source_portability.patch ADDED
@@ -0,0 +1,316 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ # What: make upstream V8 sources build cleanly in this hermetic toolchain setup.
2
+ # Scope: minimal source-level portability fixes only, such as libexecinfo guards,
3
+ # weak glibc symbol handling, and warning annotations; no dependency
4
+ # include-path rewrites or intentional V8 feature changes.
5
+ diff --git a/orig/v8-15.0.245.2/src/base/bits.h b/mod/v8-15.0.245.2/src/base/bits.h
6
+ index 179a10f..4791e96 100644
7
+ --- a/orig/v8-15.0.245.2/src/base/bits.h
8
+ +++ b/mod/v8-15.0.245.2/src/base/bits.h
9
+ @@ -270,11 +270,17 @@ inline constexpr uint32_t RoundDownToPowerOfTwo32(uint32_t value) {
10
+ }
11
+
12
+ // Precondition: 0 <= shift < 32
13
+ +#ifdef RotateRight32
14
+ +#undef RotateRight32
15
+ +#endif
16
+ inline constexpr uint32_t RotateRight32(uint32_t value, uint32_t shift) {
17
+ return (value >> shift) | (value << ((32 - shift) & 31));
18
+ }
19
+
20
+ // Precondition: 0 <= shift < 32
21
+ +#ifdef RotateLeft32
22
+ +#undef RotateLeft32
23
+ +#endif
24
+ inline constexpr uint32_t RotateLeft32(uint32_t value, uint32_t shift) {
25
+ return (value << shift) | (value >> ((32 - shift) & 31));
26
+ }
27
+ diff --git a/orig/v8-15.0.245.2/src/base/debug/stack_trace_posix.cc b/mod/v8-15.0.245.2/src/base/debug/stack_trace_posix.cc
28
+ index 6176ed4..a02043d 100644
29
+ --- a/orig/v8-15.0.245.2/src/base/debug/stack_trace_posix.cc
30
+ +++ b/mod/v8-15.0.245.2/src/base/debug/stack_trace_posix.cc
31
+ @@ -64,6 +64,7 @@ namespace {
32
+ volatile sig_atomic_t in_signal_handler = 0;
33
+ bool dump_stack_in_signal_handler = true;
34
+
35
+ +#if HAVE_EXECINFO_H
36
+ // The prefix used for mangled symbols, per the Itanium C++ ABI:
37
+ // http://www.codesourcery.com/cxx-abi/abi.html#mangling
38
+ const char kMangledSymbolPrefix[] = "_Z";
39
+ @@ -73,7 +74,6 @@ const char kMangledSymbolPrefix[] = "_Z";
40
+ const char kSymbolCharacters[] =
41
+ "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789_";
42
+
43
+ -#if HAVE_EXECINFO_H
44
+ // Demangles C++ symbols in the given text. Example:
45
+ //
46
+ // "out/Debug/base_unittests(_ZN10StackTraceC1Ev+0x20) [0x817778c]"
47
+ diff --git a/orig/v8-15.0.245.2/src/base/export-template.h b/mod/v8-15.0.245.2/src/base/export-template.h
48
+ index 861cfe4..1e73954 100644
49
+ --- a/orig/v8-15.0.245.2/src/base/export-template.h
50
+ +++ b/mod/v8-15.0.245.2/src/base/export-template.h
51
+ @@ -153,8 +153,10 @@
52
+
53
+ EXPORT_TEMPLATE_TEST(DEFAULT, );
54
+ EXPORT_TEMPLATE_TEST(DEFAULT, __attribute__((visibility("default"))));
55
+ +#if defined(_MSC_VER)
56
+ EXPORT_TEMPLATE_TEST(MSVC_HACK, __declspec(dllexport));
57
+ EXPORT_TEMPLATE_TEST(DEFAULT, __declspec(dllimport));
58
+ +#endif
59
+
60
+ #undef EXPORT_TEMPLATE_TEST
61
+ #undef EXPORT_TEMPLATE_TEST_DEFAULT_DEFAULT
62
+ diff --git a/orig/v8-15.0.245.2/src/base/platform/platform-posix.cc b/mod/v8-15.0.245.2/src/base/platform/platform-posix.cc
63
+ index dfb30b6..6ce12a5 100644
64
+ --- a/orig/v8-15.0.245.2/src/base/platform/platform-posix.cc
65
+ +++ b/mod/v8-15.0.245.2/src/base/platform/platform-posix.cc
66
+ @@ -95,7 +95,7 @@ extern int madvise(caddr_t, size_t, int);
67
+ #endif
68
+
69
+ #if defined(V8_LIBC_GLIBC)
70
+ -extern "C" void* __libc_stack_end;
71
+ +extern "C" void* __libc_stack_end V8_WEAK;
72
+ #endif
73
+
74
+ namespace v8 {
75
+ @@ -1476,7 +1476,8 @@ Stack::StackSlot Stack::ObtainCurrentThreadStackStart() {
76
+ // __libc_stack_end is process global and thus is only valid for
77
+ // the main thread. Check whether this is the main thread by checking
78
+ // __libc_stack_end is within the thread's stack.
79
+ - if ((base <= __libc_stack_end) && (__libc_stack_end <= stack_start)) {
80
+ + if (__libc_stack_end != nullptr &&
81
+ + (base <= __libc_stack_end) && (__libc_stack_end <= stack_start)) {
82
+ DCHECK(MainThreadIsCurrentThread());
83
+ return __libc_stack_end;
84
+ }
85
+ diff --git a/orig/v8-15.0.245.2/src/base/platform/platform-win32.cc b/mod/v8-15.0.245.2/src/base/platform/platform-win32.cc
86
+ index 11f9772..854a682 100644
87
+ --- a/orig/v8-15.0.245.2/src/base/platform/platform-win32.cc
88
+ +++ b/mod/v8-15.0.245.2/src/base/platform/platform-win32.cc
89
+ @@ -20,7 +20,11 @@
90
+ #include <windows.h>
91
+
92
+ // This has to come after windows.h.
93
+ +#ifdef __MINGW32__
94
+ +#include <versionhelpers.h>
95
+ +#else
96
+ #include <VersionHelpers.h>
97
+ +#endif
98
+ #include <dbghelp.h> // For SymLoadModule64 and al.
99
+ #include <malloc.h> // For _msize()
100
+ #include <mmsystem.h> // For timeGetTime().
101
+ @@ -69,9 +73,7 @@ static_assert(offsetof(V8_CRITICAL_SECTION, SpinCount) ==
102
+ // Extra functions for MinGW. Most of these are the _s functions which are in
103
+ // the Microsoft Visual Studio C++ CRT.
104
+ #ifdef __MINGW32__
105
+ -
106
+ -
107
+ -#ifndef __MINGW64_VERSION_MAJOR
108
+ +#if !defined(__MINGW64_VERSION_MAJOR)
109
+
110
+ #define _TRUNCATE 0
111
+ #define STRUNCATE 80
112
+ @@ -81,9 +83,6 @@ inline void MemoryFence() {
113
+ __asm__ __volatile__("xchgl %%eax,%0 ":"=r" (barrier));
114
+ }
115
+
116
+ -#endif // __MINGW64_VERSION_MAJOR
117
+ -
118
+ -
119
+ int localtime_s(tm* out_tm, const time_t* time) {
120
+ tm* posix_local_time_struct = localtime_r(time, out_tm);
121
+ if (posix_local_time_struct == nullptr) return 1;
122
+ @@ -134,6 +133,8 @@ int strncpy_s(char* dest, size_t dest_size, const char* source, size_t count) {
123
+ return 0;
124
+ }
125
+
126
+ +#endif // !defined(__MINGW64_VERSION_MAJOR)
127
+ +
128
+ #endif // __MINGW32__
129
+
130
+ namespace v8 {
131
+ @@ -743,8 +744,10 @@ void OS::StrNCpy(char* dest, int length, const char* src, size_t n) {
132
+ }
133
+
134
+
135
+ +#if defined(__MINGW32__) && !defined(__MINGW64_VERSION_MAJOR)
136
+ #undef _TRUNCATE
137
+ #undef STRUNCATE
138
+ +#endif
139
+
140
+ DEFINE_LAZY_LEAKY_OBJECT_GETTER(RandomNumberGenerator,
141
+ GetPlatformRandomNumberGenerator)
142
+ @@ -1943,3 +1946,4 @@ Stack::StackSlot Stack::GetCurrentStackPosition() {
143
+
144
+ } // namespace base
145
+ } // namespace v8
146
+ +
147
+ diff --git a/orig/v8-15.0.245.2/src/base/platform/time.cc b/mod/v8-15.0.245.2/src/base/platform/time.cc
148
+ index 8c824e3..f8144d0 100644
149
+ --- a/orig/v8-15.0.245.2/src/base/platform/time.cc
150
+ +++ b/mod/v8-15.0.245.2/src/base/platform/time.cc
151
+ @@ -782,12 +782,12 @@ bool ThreadTicks::IsSupported() {
152
+ #elif defined(__PASE__)
153
+ // Thread CPU time accounting is unavailable in PASE
154
+ return false;
155
+ +#elif defined(V8_OS_WIN)
156
+ + return IsSupportedWin();
157
+ #elif (defined(_POSIX_THREAD_CPUTIME) && (_POSIX_THREAD_CPUTIME >= 0)) || \
158
+ defined(V8_OS_DARWIN) || defined(V8_OS_ANDROID) || \
159
+ defined(V8_OS_SOLARIS) || defined(V8_OS_ZOS)
160
+ return true;
161
+ -#elif defined(V8_OS_WIN)
162
+ - return IsSupportedWin();
163
+ #else
164
+ return false;
165
+ #endif
166
+ @@ -804,13 +804,13 @@ ThreadTicks ThreadTicks::Now() {
167
+ return ThreadTicks(ComputeThreadTicks());
168
+ #elif V8_OS_FUCHSIA
169
+ return ThreadTicks(GetFuchsiaThreadTicks());
170
+ +#elif V8_OS_WIN
171
+ + return ThreadTicks::GetForThread(::GetCurrentThread());
172
+ #elif (defined(_POSIX_THREAD_CPUTIME) && (_POSIX_THREAD_CPUTIME >= 0)) || \
173
+ defined(V8_OS_ANDROID) || defined(V8_OS_ZOS)
174
+ return ThreadTicks(ClockNow(CLOCK_THREAD_CPUTIME_ID));
175
+ #elif V8_OS_SOLARIS
176
+ return ThreadTicks(gethrvtime() / Time::kNanosecondsPerMicrosecond);
177
+ -#elif V8_OS_WIN
178
+ - return ThreadTicks::GetForThread(::GetCurrentThread());
179
+ #else
180
+ UNREACHABLE();
181
+ #endif
182
+ diff --git a/orig/v8-15.0.245.2/src/heap/base/asm/x64/push_registers_masm.asm b/mod/v8-15.0.245.2/src/heap/base/asm/x64/push_registers_masm.asm
183
+ index d0d0563..f3f5952 100644
184
+ --- a/orig/v8-15.0.245.2/src/heap/base/asm/x64/push_registers_masm.asm
185
+ +++ b/mod/v8-15.0.245.2/src/heap/base/asm/x64/push_registers_masm.asm
186
+ @@ -1,70 +1,47 @@
187
+ -;; Copyright 2020 the V8 project authors. All rights reserved.
188
+ -;; Use of this source code is governed by a BSD-style license that can be
189
+ -;; found in the LICENSE file.
190
+ -
191
+ -;; MASM syntax
192
+ -;; https://docs.microsoft.com/en-us/cpp/assembler/masm/microsoft-macro-assembler-reference?view=vs-2019
193
+ -
194
+ -public PushAllRegistersAndIterateStack
195
+ -
196
+ -.code
197
+ -PushAllRegistersAndIterateStack proc frame
198
+ - ;; Push all callee-saved registers to get them on the stack for conservative
199
+ - ;; stack scanning.
200
+ - ;;
201
+ - ;; We maintain 16-byte alignment at calls. There is an 8-byte return address
202
+ - ;; on the stack and we push 232 bytes which maintains 16-byte stack
203
+ - ;; alignment at the call.
204
+ - ;; Source: https://docs.microsoft.com/en-us/cpp/build/x64-calling-convention
205
+ - ;;
206
+ - ;; rbp is callee-saved. Maintain proper frame pointer for debugging.
207
+ - push rbp
208
+ - .pushreg rbp
209
+ - mov rbp, rsp
210
+ - .setframe rbp, 0
211
+ - push 0CDCDCDh ;; Dummy for alignment.
212
+ - .allocstack 8
213
+ - push rsi
214
+ - .pushreg rsi
215
+ - push rdi
216
+ - .pushreg rdi
217
+ - push rbx
218
+ - .pushreg rbx
219
+ - push r12
220
+ - .pushreg r12
221
+ - push r13
222
+ - .pushreg r13
223
+ - push r14
224
+ - .pushreg r14
225
+ - push r15
226
+ - .pushreg r15
227
+ - sub rsp, 160
228
+ - .allocstack 160
229
+ - .endprolog
230
+ - ;; Use aligned instrs as we are certain that the stack is properly aligned.
231
+ - movdqa xmmword ptr [rsp + 144], xmm6
232
+ - movdqa xmmword ptr [rsp + 128], xmm7
233
+ - movdqa xmmword ptr [rsp + 112], xmm8
234
+ - movdqa xmmword ptr [rsp + 96], xmm9
235
+ - movdqa xmmword ptr [rsp + 80], xmm10
236
+ - movdqa xmmword ptr [rsp + 64], xmm11
237
+ - movdqa xmmword ptr [rsp + 48], xmm12
238
+ - movdqa xmmword ptr [rsp + 32], xmm13
239
+ - movdqa xmmword ptr [rsp + 16], xmm14
240
+ - movdqa xmmword ptr [rsp], xmm15
241
+ - ;; Pass 1st parameter (rcx) unchanged (Stack*).
242
+ - ;; Pass 2nd parameter (rdx) unchanged (StackVisitor*).
243
+ - ;; Save 3rd parameter (r8; IterateStackCallback)
244
+ - mov r9, r8
245
+ - ;; Pass 3rd parameter as rsp (stack pointer).
246
+ - mov r8, rsp
247
+ - ;; Call the callback.
248
+ - call r9
249
+ - ;; Pop the callee-saved registers.
250
+ - add rsp, 224
251
+ - ;; Restore rbp as it was used as frame pointer.
252
+ - pop rbp
253
+ - ret
254
+ - PushAllRegistersAndIterateStack endp
255
+ -
256
+ -end
257
+ +.text
258
+ +.globl PushAllRegistersAndIterateStack
259
+ +.seh_proc PushAllRegistersAndIterateStack
260
+ +PushAllRegistersAndIterateStack:
261
+ + push %rbp
262
+ + .seh_pushreg %rbp
263
+ + mov %rsp, %rbp
264
+ + .seh_setframe %rbp, 0
265
+ + push $0xCDCDCD
266
+ + .seh_stackalloc 8
267
+ + push %rsi
268
+ + .seh_pushreg %rsi
269
+ + push %rdi
270
+ + .seh_pushreg %rdi
271
+ + push %rbx
272
+ + .seh_pushreg %rbx
273
+ + push %r12
274
+ + .seh_pushreg %r12
275
+ + push %r13
276
+ + .seh_pushreg %r13
277
+ + push %r14
278
+ + .seh_pushreg %r14
279
+ + push %r15
280
+ + .seh_pushreg %r15
281
+ + sub $160, %rsp
282
+ + .seh_stackalloc 160
283
+ + # Preserve Windows unwind metadata even though this is now GNU syntax.
284
+ + # Without the .seh_* directives, SEH and stack walking can mis-handle
285
+ + # unwinding across this callback frame.
286
+ + .seh_endprologue
287
+ + movdqa %xmm6, 144(%rsp)
288
+ + movdqa %xmm7, 128(%rsp)
289
+ + movdqa %xmm8, 112(%rsp)
290
+ + movdqa %xmm9, 96(%rsp)
291
+ + movdqa %xmm10, 80(%rsp)
292
+ + movdqa %xmm11, 64(%rsp)
293
+ + movdqa %xmm12, 48(%rsp)
294
+ + movdqa %xmm13, 32(%rsp)
295
+ + movdqa %xmm14, 16(%rsp)
296
+ + movdqa %xmm15, 0(%rsp)
297
+ + mov %r8, %r9
298
+ + mov %rsp, %r8
299
+ + call *%r9
300
+ + add $224, %rsp
301
+ + pop %rbp
302
+ + ret
303
+ +.seh_endproc
304
+ diff --git a/orig/v8-15.0.245.2/src/libplatform/default-thread-isolated-allocator.cc b/mod/v8-15.0.245.2/src/libplatform/default-thread-isolated-allocator.cc
305
+ index bda0e43..b44f1d9 100644
306
+ --- a/orig/v8-15.0.245.2/src/libplatform/default-thread-isolated-allocator.cc
307
+ +++ b/mod/v8-15.0.245.2/src/libplatform/default-thread-isolated-allocator.cc
308
+ @@ -23,7 +23,7 @@ extern int pkey_free(int pkey) V8_WEAK;
309
+
310
+ namespace {
311
+
312
+ -bool KernelHasPkruFix() {
313
+ +[[maybe_unused]] bool KernelHasPkruFix() {
314
+ // PKU was broken on Linux kernels before 5.13 (see
315
+ // https://lore.kernel.org/all/20210623121456.399107624@linutronix.de/).
316
+ // A fix is also included in the 5.4.182 and 5.10.103 versions ("x86/fpu:
pnpm-lock.yaml ADDED
The diff for this file is too large to render. See raw diff
 
pnpm-workspace.yaml ADDED
@@ -0,0 +1,19 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ packages:
2
+ - codex-cli
3
+ - codex-rs/responses-api-proxy/npm
4
+ - sdk/typescript
5
+
6
+ ignoredBuiltDependencies:
7
+ - esbuild
8
+
9
+ minimumReleaseAge: 10080
10
+ minimumReleaseAgeExclude: []
11
+
12
+ blockExoticSubdeps: true
13
+ strictDepBuilds: true
14
+ trustPolicy: no-downgrade
15
+ trustPolicyIgnoreAfter: 10080
16
+ trustPolicyExclude: []
17
+ allowBuilds:
18
+ # Build only the official MCP conformance CLI pinned by the TypeScript SDK.
19
+ "@modelcontextprotocol/conformance@https://codeload.github.com/modelcontextprotocol/conformance/tar.gz/49103de6ed70804e940637bf3e9e29e4a3f54e64": true
rbe.bzl ADDED
@@ -0,0 +1,42 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ def _rbe_platform_repo_impl(rctx):
2
+ arch = rctx.os.arch
3
+ if arch in ["x86_64", "amd64"]:
4
+ cpu = "x86_64"
5
+ exec_arch = "amd64"
6
+ image_sha = "0a8e56bfaa3b2e5279db0d3bb2d62b44ba5e5d63a37d97eb8790f49da570af70"
7
+ elif arch in ["aarch64", "arm64"]:
8
+ cpu = "aarch64"
9
+ exec_arch = "arm64"
10
+ image_sha = "136487cc4b7cf6f1021816ca18ed00896daed98404ea91dc4d6dd9e9d1cf9564"
11
+ else:
12
+ fail("Unsupported host arch for rbe platform: {}".format(arch))
13
+
14
+ rctx.file("BUILD.bazel", """\
15
+ platform(
16
+ name = "rbe_platform",
17
+ constraint_values = [
18
+ "@platforms//cpu:{cpu}",
19
+ "@platforms//os:linux",
20
+ "@bazel_tools//tools/cpp:clang",
21
+ "@llvm//constraints/libc:gnu.2.28",
22
+ ],
23
+ exec_properties = {{
24
+ # Ubuntu-based image that includes git, python3, dotslash, and other
25
+ # tools that various integration tests need.
26
+ # Verify at https://hub.docker.com/layers/mbolin491/codex-bazel/latest/images/sha256:{image_sha}
27
+ "container-image": "docker://docker.io/mbolin491/codex-bazel@sha256:{image_sha}",
28
+ "Arch": "{arch}",
29
+ "OSFamily": "Linux",
30
+ }},
31
+ visibility = ["//visibility:public"],
32
+ )
33
+ """.format(
34
+ cpu = cpu,
35
+ arch = exec_arch,
36
+ image_sha = image_sha,
37
+ ))
38
+
39
+ rbe_platform_repository = repository_rule(
40
+ implementation = _rbe_platform_repo_impl,
41
+ doc = "Sets up a platform for remote builds with an Arch exec_property matching the host.",
42
+ )
ruff.toml ADDED
@@ -0,0 +1 @@
 
 
1
+ extend-exclude = ["sdk/python", "codex-rs/vendor"]
tools/buildifier ADDED
@@ -0,0 +1,73 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ #!/usr/bin/env dotslash
2
+
3
+ {
4
+ "name": "buildifier",
5
+ "platforms": {
6
+ "macos-aarch64": {
7
+ "size": 7565746,
8
+ "hash": "sha256",
9
+ "digest": "62836a9667fa0db309b0d91e840f0a3f2813a9c8ea3e44b9cd58187c90bc88ba",
10
+ "path": "buildifier",
11
+ "providers": [
12
+ {
13
+ "url": "https://github.com/bazelbuild/buildtools/releases/download/v8.5.1/buildifier-darwin-arm64"
14
+ }
15
+ ]
16
+ },
17
+ "macos-x86_64": {
18
+ "size": 7737072,
19
+ "hash": "sha256",
20
+ "digest": "31de189e1a3fe53aa9e8c8f74a0309c325274ad19793393919e1ca65163ca1a4",
21
+ "path": "buildifier",
22
+ "providers": [
23
+ {
24
+ "url": "https://github.com/bazelbuild/buildtools/releases/download/v8.5.1/buildifier-darwin-amd64"
25
+ }
26
+ ]
27
+ },
28
+ "linux-aarch64": {
29
+ "size": 7483831,
30
+ "hash": "sha256",
31
+ "digest": "947bf6700d708026b2057b09bea09abbc3cafc15d9ecea35bb3885c4b09ccd04",
32
+ "path": "buildifier",
33
+ "providers": [
34
+ {
35
+ "url": "https://github.com/bazelbuild/buildtools/releases/download/v8.5.1/buildifier-linux-arm64"
36
+ }
37
+ ]
38
+ },
39
+ "linux-x86_64": {
40
+ "size": 7757842,
41
+ "hash": "sha256",
42
+ "digest": "887377fc64d23a850f4d18a077b5db05b19913f4b99b270d193f3c7334b5a9a7",
43
+ "path": "buildifier",
44
+ "providers": [
45
+ {
46
+ "url": "https://github.com/bazelbuild/buildtools/releases/download/v8.5.1/buildifier-linux-amd64"
47
+ }
48
+ ]
49
+ },
50
+ "windows-aarch64": {
51
+ "size": 7451648,
52
+ "hash": "sha256",
53
+ "digest": "55a276ad8b1ff46be48bf64e432264034ea69a45aa3914e89c1d1936f5c2d85c",
54
+ "path": "buildifier.exe",
55
+ "providers": [
56
+ {
57
+ "url": "https://github.com/bazelbuild/buildtools/releases/download/v8.5.1/buildifier-windows-arm64.exe"
58
+ }
59
+ ]
60
+ },
61
+ "windows-x86_64": {
62
+ "size": 7861760,
63
+ "hash": "sha256",
64
+ "digest": "f4ecb9c73de2bc38b845d4ee27668f6248c4813a6647db4b4931a7556052e4e1",
65
+ "path": "buildifier.exe",
66
+ "providers": [
67
+ {
68
+ "url": "https://github.com/bazelbuild/buildtools/releases/download/v8.5.1/buildifier-windows-amd64.exe"
69
+ }
70
+ ]
71
+ }
72
+ }
73
+ }
workspace_root_test_launcher.bat.tpl ADDED
@@ -0,0 +1,177 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ @echo off
2
+ setlocal EnableExtensions EnableDelayedExpansion
3
+
4
+ call :resolve_runfile "__WORKSPACE_ROOT_MARKER__"
5
+ if errorlevel 1 exit /b 1
6
+ set "workspace_root_marker=!resolve_runfile_result!"
7
+
8
+ for %%I in ("%workspace_root_marker%") do set "workspace_root_marker_dir=%%~dpI"
9
+ for %%I in ("%workspace_root_marker_dir%..\..") do set "workspace_root=%%~fI"
10
+
11
+ call :resolve_runfile "__TEST_BIN__"
12
+ if errorlevel 1 exit /b 1
13
+ set "test_bin=!resolve_runfile_result!"
14
+
15
+ __RUNFILE_ENV_EXPORTS__
16
+
17
+ if not defined test_bin (
18
+ >&2 echo resolved test binary was lost while exporting runfile environment variables
19
+ exit /b 1
20
+ )
21
+
22
+ __WORKSPACE_ROOT_SETUP__
23
+
24
+ set "TOTAL_SHARDS=%RULES_RUST_TEST_TOTAL_SHARDS%"
25
+ if not defined TOTAL_SHARDS set "TOTAL_SHARDS=%TEST_TOTAL_SHARDS%"
26
+ if defined TESTBRIDGE_TEST_ONLY if "%~1"=="" (
27
+ "%test_bin%" "%TESTBRIDGE_TEST_ONLY%"
28
+ exit /b !ERRORLEVEL!
29
+ )
30
+ if defined CODEX_BAZEL_TEST_SKIP_FILTERS (
31
+ call :run_selected_libtest %*
32
+ exit /b !ERRORLEVEL!
33
+ )
34
+ if defined TOTAL_SHARDS if not "%TOTAL_SHARDS%"=="0" (
35
+ call :run_selected_libtest %*
36
+ exit /b !ERRORLEVEL!
37
+ )
38
+
39
+ "%test_bin%" %*
40
+ exit /b %ERRORLEVEL%
41
+
42
+ :run_selected_libtest
43
+ if defined TEST_SHARD_STATUS_FILE if defined TEST_TOTAL_SHARDS if not "%TEST_TOTAL_SHARDS%"=="0" (
44
+ type nul > "%TEST_SHARD_STATUS_FILE%"
45
+ )
46
+
47
+ if not "%~1"=="" (
48
+ "%test_bin%" %*
49
+ exit /b !ERRORLEVEL!
50
+ )
51
+
52
+ set "SHARD_INDEX=%RULES_RUST_TEST_SHARD_INDEX%"
53
+ if not defined SHARD_INDEX set "SHARD_INDEX=%TEST_SHARD_INDEX%"
54
+ set "HAS_SHARDS="
55
+ if defined TOTAL_SHARDS if not "%TOTAL_SHARDS%"=="0" set "HAS_SHARDS=1"
56
+ if defined HAS_SHARDS if not defined SHARD_INDEX (
57
+ >&2 echo TEST_SHARD_INDEX or RULES_RUST_TEST_SHARD_INDEX must be set when sharding is enabled
58
+ exit /b 1
59
+ )
60
+
61
+ set "TEMP_ROOT=%TEST_TMPDIR%"
62
+ if not defined TEMP_ROOT set "TEMP_ROOT=%TEMP%"
63
+ if not defined TEMP_ROOT set "TEMP_ROOT=."
64
+ :CREATE_TEMP_DIR
65
+ set "TEMP_DIR=%TEMP_ROOT%\workspace_root_test_sharding_!RANDOM!_!RANDOM!_!RANDOM!"
66
+ mkdir "!TEMP_DIR!" 2>nul
67
+ if errorlevel 1 goto :CREATE_TEMP_DIR
68
+ set "TEMP_LIST=!TEMP_DIR!\list.txt"
69
+ set "TEMP_SHARD_LIST=!TEMP_DIR!\shard.txt"
70
+
71
+ "%test_bin%" --list --format terse > "!TEMP_LIST!"
72
+ if errorlevel 1 (
73
+ rmdir /s /q "!TEMP_DIR!" 2>nul
74
+ exit /b 1
75
+ )
76
+
77
+ powershell.exe -NoProfile -ExecutionPolicy Bypass -Command ^
78
+ "$ErrorActionPreference = 'Stop';" ^
79
+ "$tests = @(Get-Content -LiteralPath $env:TEMP_LIST | Where-Object { $_.EndsWith(': test') } | ForEach-Object { $_.Substring(0, $_.Length - 6) });" ^
80
+ "[Array]::Sort($tests, [StringComparer]::Ordinal);" ^
81
+ "$hasShards = -not [string]::IsNullOrEmpty($env:HAS_SHARDS);" ^
82
+ "$skipFilters = @();" ^
83
+ "if (-not [string]::IsNullOrEmpty($env:CODEX_BAZEL_TEST_SKIP_FILTERS)) { $skipFilters = @($env:CODEX_BAZEL_TEST_SKIP_FILTERS -split ',' | Where-Object { $_ -ne '' }) };" ^
84
+ "if ($hasShards) { $totalShards = [uint32]$env:TOTAL_SHARDS; $shardIndex = [uint32]$env:SHARD_INDEX };" ^
85
+ "$fnvPrime = [uint64]16777619; $u32Mask = [uint64]4294967295;" ^
86
+ "foreach ($test in $tests) { $skip = $false; foreach ($filter in $skipFilters) { if ($test.Contains($filter)) { $skip = $true; break } }; if ($skip) { continue }; if ($hasShards) { $hash = [uint32]2166136261; foreach ($byte in [Text.Encoding]::UTF8.GetBytes($test)) { $hash = [uint32](([uint64]($hash -bxor $byte) * $fnvPrime) -band $u32Mask) }; if (($hash %% $totalShards) -eq $shardIndex) { $test } } else { $test } }" ^
87
+ > "!TEMP_SHARD_LIST!"
88
+ if errorlevel 1 (
89
+ rmdir /s /q "!TEMP_DIR!" 2>nul
90
+ exit /b 1
91
+ )
92
+
93
+ powershell.exe -NoProfile -ExecutionPolicy Bypass -Command ^
94
+ "$ErrorActionPreference = 'Stop';" ^
95
+ "$testBin = $env:test_bin;" ^
96
+ "$tests = @(Get-Content -LiteralPath $env:TEMP_SHARD_LIST);" ^
97
+ "$failed = $false; $limit = 7000; $batch = @(); $batchChars = $testBin.Length + 8;" ^
98
+ "function Invoke-TestBatch { if ($script:batch.Count -eq 0) { return }; & $script:testBin @script:batch '--exact'; if ($LASTEXITCODE -ne 0) { $script:failed = $true }; $script:batch = @(); $script:batchChars = $script:testBin.Length + 8 }" ^
99
+ "foreach ($test in $tests) { $argChars = $test.Length + 3; if (($batch.Count -gt 0) -and ($batchChars + $argChars -gt $limit)) { Invoke-TestBatch }; $batch += $test; $batchChars += $argChars }" ^
100
+ "Invoke-TestBatch; if ($failed) { exit 1 }"
101
+ set "TEST_EXIT=%ERRORLEVEL%"
102
+
103
+ rmdir /s /q "!TEMP_DIR!" 2>nul
104
+ exit /b !TEST_EXIT!
105
+
106
+ :resolve_runfile
107
+ set "resolve_runfile_result="
108
+ set "resolve_runfile_logical_path=%~1"
109
+ set "resolve_runfile_workspace_logical_path=!resolve_runfile_logical_path!"
110
+ if defined TEST_WORKSPACE set "resolve_runfile_workspace_logical_path=%TEST_WORKSPACE%/!resolve_runfile_logical_path!"
111
+ set "resolve_runfile_native_logical_path=!resolve_runfile_logical_path:/=\!"
112
+ set "resolve_runfile_native_workspace_logical_path=!resolve_runfile_workspace_logical_path:/=\!"
113
+
114
+ for %%R in ("%RUNFILES_DIR%" "%TEST_SRCDIR%") do (
115
+ set "resolve_runfile_root=%%~R"
116
+ if defined resolve_runfile_root (
117
+ if exist "!resolve_runfile_root!\!resolve_runfile_native_logical_path!" (
118
+ set "resolve_runfile_result=!resolve_runfile_root!\!resolve_runfile_native_logical_path!"
119
+ goto :resolve_runfile_success
120
+ )
121
+ if exist "!resolve_runfile_root!\!resolve_runfile_native_workspace_logical_path!" (
122
+ set "resolve_runfile_result=!resolve_runfile_root!\!resolve_runfile_native_workspace_logical_path!"
123
+ goto :resolve_runfile_success
124
+ )
125
+ )
126
+ )
127
+
128
+ set "resolve_runfile_manifest=%RUNFILES_MANIFEST_FILE%"
129
+ if not defined resolve_runfile_manifest if exist "%~f0.runfiles_manifest" set "resolve_runfile_manifest=%~f0.runfiles_manifest"
130
+ if not defined resolve_runfile_manifest if exist "%~dpn0.runfiles_manifest" set "resolve_runfile_manifest=%~dpn0.runfiles_manifest"
131
+ if not defined resolve_runfile_manifest if exist "%~f0.exe.runfiles_manifest" set "resolve_runfile_manifest=%~f0.exe.runfiles_manifest"
132
+
133
+ if defined resolve_runfile_manifest if exist "!resolve_runfile_manifest!" (
134
+ rem Read the manifest directly instead of shelling out to findstr. In the
135
+ rem GitHub Windows runner, the nested `findstr` path produced
136
+ rem `FINDSTR: Cannot open D:MANIFEST`, which then broke runfile resolution for
137
+ rem Bazel tests even though the manifest file was present.
138
+ rem A one-field manifest entry maps to itself, so fall back to %%A when the
139
+ rem optional mapped path in %%B is empty.
140
+ for /f "usebackq tokens=1,* delims= " %%A in ("!resolve_runfile_manifest!") do (
141
+ if "%%A"=="!resolve_runfile_logical_path!" (
142
+ set "resolve_runfile_manifest_path=%%B"
143
+ if not defined resolve_runfile_manifest_path set "resolve_runfile_manifest_path=%%A"
144
+ set "resolve_runfile_result=!resolve_runfile_manifest_path!"
145
+ goto :resolve_runfile_success
146
+ )
147
+ if "%%A"=="!resolve_runfile_workspace_logical_path!" (
148
+ set "resolve_runfile_manifest_path=%%B"
149
+ if not defined resolve_runfile_manifest_path set "resolve_runfile_manifest_path=%%A"
150
+ set "resolve_runfile_result=!resolve_runfile_manifest_path!"
151
+ goto :resolve_runfile_success
152
+ )
153
+ )
154
+ )
155
+
156
+ >&2 echo failed to resolve runfile: !resolve_runfile_logical_path!
157
+ call :clear_resolve_runfile_state
158
+ exit /b 1
159
+
160
+ :resolve_runfile_success
161
+ if not defined resolve_runfile_result (
162
+ >&2 echo resolved runfile has an empty path: !resolve_runfile_logical_path!
163
+ call :clear_resolve_runfile_state
164
+ exit /b 1
165
+ )
166
+ call :clear_resolve_runfile_state
167
+ exit /b 0
168
+
169
+ :clear_resolve_runfile_state
170
+ set "resolve_runfile_logical_path="
171
+ set "resolve_runfile_workspace_logical_path="
172
+ set "resolve_runfile_native_logical_path="
173
+ set "resolve_runfile_native_workspace_logical_path="
174
+ set "resolve_runfile_root="
175
+ set "resolve_runfile_manifest="
176
+ set "resolve_runfile_manifest_path="
177
+ exit /b 0
workspace_root_test_launcher.sh.tpl ADDED
@@ -0,0 +1,169 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ #!/usr/bin/env bash
2
+ set -euo pipefail
3
+
4
+ resolve_runfile() {
5
+ local logical_path="$1"
6
+ local workspace_logical_path="${logical_path}"
7
+ if [[ -n "${TEST_WORKSPACE:-}" ]]; then
8
+ workspace_logical_path="${TEST_WORKSPACE}/${logical_path}"
9
+ fi
10
+
11
+ for runfiles_root in "${RUNFILES_DIR:-}" "${TEST_SRCDIR:-}"; do
12
+ if [[ -n "${runfiles_root}" && -e "${runfiles_root}/${logical_path}" ]]; then
13
+ printf '%s\n' "${runfiles_root}/${logical_path}"
14
+ return 0
15
+ fi
16
+ if [[ -n "${runfiles_root}" && -e "${runfiles_root}/${workspace_logical_path}" ]]; then
17
+ printf '%s\n' "${runfiles_root}/${workspace_logical_path}"
18
+ return 0
19
+ fi
20
+ done
21
+
22
+ local manifest="${RUNFILES_MANIFEST_FILE:-}"
23
+ if [[ -z "${manifest}" ]]; then
24
+ if [[ -f "$0.runfiles_manifest" ]]; then
25
+ manifest="$0.runfiles_manifest"
26
+ elif [[ -f "$0.exe.runfiles_manifest" ]]; then
27
+ manifest="$0.exe.runfiles_manifest"
28
+ fi
29
+ fi
30
+
31
+ if [[ -n "${manifest}" && -f "${manifest}" ]]; then
32
+ local resolved=""
33
+ resolved="$(awk -v key="${logical_path}" '$1 == key { $1 = ""; sub(/^ /, ""); print; exit }' "${manifest}")"
34
+ if [[ -z "${resolved}" ]]; then
35
+ resolved="$(awk -v key="${workspace_logical_path}" '$1 == key { $1 = ""; sub(/^ /, ""); print; exit }' "${manifest}")"
36
+ fi
37
+ if [[ -n "${resolved}" ]]; then
38
+ printf '%s\n' "${resolved}"
39
+ return 0
40
+ fi
41
+ fi
42
+
43
+ echo "failed to resolve runfile: $logical_path" >&2
44
+ return 1
45
+ }
46
+
47
+ workspace_root_marker="$(resolve_runfile "__WORKSPACE_ROOT_MARKER__")"
48
+ workspace_root="$(dirname "$(dirname "$(dirname "${workspace_root_marker}")")")"
49
+ test_bin="$(resolve_runfile "__TEST_BIN__")"
50
+ RUNFILE_ENV_ARGS=()
51
+
52
+ __RUNFILE_ENV_EXPORTS__
53
+
54
+ run_test_bin() {
55
+ if (( ${#RUNFILE_ENV_ARGS[@]} > 0 )); then
56
+ env "${RUNFILE_ENV_ARGS[@]}" "${test_bin}" "$@"
57
+ else
58
+ "${test_bin}" "$@"
59
+ fi
60
+ }
61
+
62
+ exec_test_bin() {
63
+ if (( ${#RUNFILE_ENV_ARGS[@]} > 0 )); then
64
+ exec env "${RUNFILE_ENV_ARGS[@]}" "${test_bin}" "$@"
65
+ else
66
+ exec "${test_bin}" "$@"
67
+ fi
68
+ }
69
+
70
+ libtest_args=("$@")
71
+ if [[ ${#libtest_args[@]} -eq 0 && -n "${TESTBRIDGE_TEST_ONLY:-}" ]]; then
72
+ libtest_args+=("${TESTBRIDGE_TEST_ONLY}")
73
+ fi
74
+
75
+ test_shard_index() {
76
+ local test_name="$1"
77
+ # FNV-1a 32-bit hash. Keep this stable so adding one test does not reshuffle
78
+ # unrelated tests between shards.
79
+ local hash=2166136261
80
+ local byte
81
+ local char
82
+ local i
83
+ local LC_ALL=C
84
+
85
+ for ((i = 0; i < ${#test_name}; i++)); do
86
+ char="${test_name:i:1}"
87
+ printf -v byte "%d" "'$char"
88
+ hash=$(( ((hash ^ byte) * 16777619) & 0xffffffff ))
89
+ done
90
+
91
+ echo $(( hash % TOTAL_SHARDS ))
92
+ }
93
+
94
+ run_selected_libtest() {
95
+ if [[ -n "${TEST_SHARD_STATUS_FILE:-}" && "${TEST_TOTAL_SHARDS:-0}" != "0" ]]; then
96
+ touch "${TEST_SHARD_STATUS_FILE}"
97
+ fi
98
+
99
+ # Extra libtest args are usually ad-hoc local filters. Preserve those exactly
100
+ # rather than combining them with generated exact filters.
101
+ if [[ ${#libtest_args[@]} -gt 0 ]]; then
102
+ exec_test_bin "${libtest_args[@]}"
103
+ fi
104
+
105
+ local has_shards=0
106
+ if [[ -n "${TOTAL_SHARDS}" && "${TOTAL_SHARDS}" != "0" ]]; then
107
+ has_shards=1
108
+ fi
109
+
110
+ if [[ "${has_shards}" == "1" && -z "${SHARD_INDEX}" ]]; then
111
+ echo "TEST_SHARD_INDEX or RULES_RUST_TEST_SHARD_INDEX must be set when sharding is enabled" >&2
112
+ exit 1
113
+ fi
114
+
115
+ local list_output
116
+ local test_list
117
+ list_output="$(run_test_bin --list --format terse)"
118
+ test_list="$(printf '%s\n' "${list_output}" | grep ': test$' | sed 's/: test$//' | LC_ALL=C sort || true)"
119
+
120
+ if [[ -z "${test_list}" ]]; then
121
+ exit 0
122
+ fi
123
+
124
+ local skip_filters="${CODEX_BAZEL_TEST_SKIP_FILTERS:-}"
125
+
126
+ local shard_tests=()
127
+ local test_name
128
+ while IFS= read -r test_name; do
129
+ local skip=0
130
+ if [[ -n "${skip_filters}" ]]; then
131
+ local filter
132
+ local old_ifs="${IFS}"
133
+ IFS=','
134
+ for filter in ${skip_filters}; do
135
+ if [[ -n "${filter}" && "${test_name}" == *"${filter}"* ]]; then
136
+ skip=1
137
+ break
138
+ fi
139
+ done
140
+ IFS="${old_ifs}"
141
+ fi
142
+ if [[ "${skip}" == "1" ]]; then
143
+ continue
144
+ fi
145
+ if [[ "${has_shards}" == "0" || $(test_shard_index "${test_name}") == "${SHARD_INDEX}" ]]; then
146
+ shard_tests+=("${test_name}")
147
+ fi
148
+ done <<< "${test_list}"
149
+
150
+ if [[ ${#shard_tests[@]} -eq 0 ]]; then
151
+ exit 0
152
+ fi
153
+
154
+ exec_test_bin "${shard_tests[@]}" --exact
155
+ }
156
+
157
+ __WORKSPACE_ROOT_SETUP__
158
+
159
+ TOTAL_SHARDS="${RULES_RUST_TEST_TOTAL_SHARDS:-${TEST_TOTAL_SHARDS:-}}"
160
+ SHARD_INDEX="${RULES_RUST_TEST_SHARD_INDEX:-${TEST_SHARD_INDEX:-}}"
161
+ if [[ -n "${CODEX_BAZEL_TEST_SKIP_FILTERS:-}" || ( -n "${TOTAL_SHARDS}" && "${TOTAL_SHARDS}" != "0" ) ]]; then
162
+ run_selected_libtest
163
+ fi
164
+
165
+ if [[ ${#libtest_args[@]} -gt 0 ]]; then
166
+ exec_test_bin "${libtest_args[@]}"
167
+ else
168
+ exec_test_bin
169
+ fi