Skip to content

Make thread-owned Guardian context always enabled - #47686

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/a65936c9e0b912e7667d1385a2ec53df726565de
Sep 23, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/a65936c9e0b912e7667d1385a2ec53df726565de

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Make thread-owned Guardian context always enabled

What changed

  • Deprecate and ignore features.guardianv2.thread_context, including profile overrides, with a migration notice. Ignore managed requirements for the removed flag with a warning.
  • Preserve surviving legacy root instructions across compaction and resume when retained instructions are incomplete. Include unmatched instructions in worker authorization context with an explicit unknown-ordering notice, without replacing newer retained facts or expanding the reviewer's model window.
  • Use surviving source calls to roll back verified answers from older checkpoints that lack acceptance-order metadata.

Testing

Add regression coverage for legacy instruction recovery, compaction and resume, source matching, and answer rollback around same-turn user input. Update configuration and Guardian review tests to verify that the deprecated opt-out still uses thread-owned context and rejects incompatible compaction evidence.

## What changed

- Deprecate and ignore `features.guardianv2.thread_context`, including profile overrides, with a migration notice. Ignore managed requirements for the removed flag with a warning.
- Preserve surviving legacy root instructions across compaction and resume when retained instructions are incomplete. Include unmatched instructions in worker authorization context with an explicit unknown-ordering notice, without replacing newer retained facts or expanding the reviewer's model window.
- Use surviving source calls to roll back verified answers from older checkpoints that lack acceptance-order metadata.

## Testing

Add regression coverage for legacy instruction recovery, compaction and resume, source matching, and answer rollback around same-turn user input. Update configuration and Guardian review tests to verify that the deprecated opt-out still uses thread-owned context and rejects incompatible compaction evidence.

GitOrigin-RevId: a65936c9e0b912e7667d1385a2ec53df726565de
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/a65936c9e0b912e7667d1385a2ec53df726565de branch from 080a629 to a6df738 Compare September 23, 2026 22:45
@copyberry
copyberry Bot merged commit a6df738 into main Sep 23, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/a65936c9e0b912e7667d1385a2ec53df726565de branch September 23, 2026 22:45
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 23, 2026

This branch was successfully deployed

1 active deployment
issue-triage — a6df7385 Deployed Sep 23, 2026 by joegreensecure-ops via Translate non-English issue #14807
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants