Repository navigation
Add opt-in conversation history retrieval to Guardian reviews - #49036
Merged
copyberry[bot] merged 1 commit intoSep 28, 2026
Conversation
## Why The transcript supplied to Guardian may omit earlier user instructions, restrictions, or revoked permissions. History retrieval lets the reviewer check relevant authorization before approving actions with side effects. ## What changed - Add the disabled-by-default `guardian_conversation_history_tools` feature. With Apps enabled, expose `user_message.search_messages` and `user_message.read_messages` through the parent's live Apps connection and conversation identity. - Recheck the parent's current app and tool policy on each call, rejecting disabled tools and calls requiring approval. - Add retrieval instructions that distinguish user authorization from assistant context and account for later revocations and incomplete results. Allow overrides through `auto_review.experimental_conversation_history_prompt`. - Limit history responses to an estimated 4,000 tokens by default, configurable through `auto_review.conversation_history_max_output_tokens`, while preserving stricter parent and reviewer limits. - Allow explicit extension registries for isolated sessions and prevent those sessions from inheriting the implicit Apps connection. ## Testing Add scenarios covering history tool exposure, parent connection and identity reuse, custom prompts, output truncation, stricter reviewer budgets, and live permission changes on a reused reviewer. Extend configuration coverage for blank prompt overrides. GitOrigin-RevId: 055a69b113c8548bd58e7d5618ea026ba6d1ffb1
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/055a69b113c8548bd58e7d5618ea026ba6d1ffb1
branch
from
September 28, 2026 17:30
4c52f84 to
41ed72c
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/055a69b113c8548bd58e7d5618ea026ba6d1ffb1
branch
September 28, 2026 17:30
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add opt-in conversation history retrieval to Guardian reviews
Why
The transcript supplied to Guardian may omit earlier user instructions, restrictions, or revoked permissions. History retrieval lets the reviewer check relevant authorization before approving actions with side effects.
What changed
guardian_conversation_history_toolsfeature. With Apps enabled, exposeuser_message.search_messagesanduser_message.read_messagesthrough the parent's live Apps connection and conversation identity.auto_review.experimental_conversation_history_prompt.auto_review.conversation_history_max_output_tokens, while preserving stricter parent and reviewer limits.Testing
Add scenarios covering history tool exposure, parent connection and identity reuse, custom prompts, output truncation, stricter reviewer budgets, and live permission changes on a reused reviewer. Extend configuration coverage for blank prompt overrides.