Skip to content

Add opt-in conversation history retrieval to Guardian reviews - #49036

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/055a69b113c8548bd58e7d5618ea026ba6d1ffb1
Sep 28, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/055a69b113c8548bd58e7d5618ea026ba6d1ffb1

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Add opt-in conversation history retrieval to Guardian reviews

Why

The transcript supplied to Guardian may omit earlier user instructions, restrictions, or revoked permissions. History retrieval lets the reviewer check relevant authorization before approving actions with side effects.

What changed

  • Add the disabled-by-default guardian_conversation_history_tools feature. With Apps enabled, expose user_message.search_messages and user_message.read_messages through the parent's live Apps connection and conversation identity.
  • Recheck the parent's current app and tool policy on each call, rejecting disabled tools and calls requiring approval.
  • Add retrieval instructions that distinguish user authorization from assistant context and account for later revocations and incomplete results. Allow overrides through auto_review.experimental_conversation_history_prompt.
  • Limit history responses to an estimated 4,000 tokens by default, configurable through auto_review.conversation_history_max_output_tokens, while preserving stricter parent and reviewer limits.
  • Allow explicit extension registries for isolated sessions and prevent those sessions from inheriting the implicit Apps connection.

Testing

Add scenarios covering history tool exposure, parent connection and identity reuse, custom prompts, output truncation, stricter reviewer budgets, and live permission changes on a reused reviewer. Extend configuration coverage for blank prompt overrides.

## Why

The transcript supplied to Guardian may omit earlier user instructions, restrictions, or revoked permissions. History retrieval lets the reviewer check relevant authorization before approving actions with side effects.

## What changed

- Add the disabled-by-default `guardian_conversation_history_tools` feature. With Apps enabled, expose `user_message.search_messages` and `user_message.read_messages` through the parent's live Apps connection and conversation identity.
- Recheck the parent's current app and tool policy on each call, rejecting disabled tools and calls requiring approval.
- Add retrieval instructions that distinguish user authorization from assistant context and account for later revocations and incomplete results. Allow overrides through `auto_review.experimental_conversation_history_prompt`.
- Limit history responses to an estimated 4,000 tokens by default, configurable through `auto_review.conversation_history_max_output_tokens`, while preserving stricter parent and reviewer limits.
- Allow explicit extension registries for isolated sessions and prevent those sessions from inheriting the implicit Apps connection.

## Testing

Add scenarios covering history tool exposure, parent connection and identity reuse, custom prompts, output truncation, stricter reviewer budgets, and live permission changes on a reused reviewer. Extend configuration coverage for blank prompt overrides.

GitOrigin-RevId: 055a69b113c8548bd58e7d5618ea026ba6d1ffb1
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/055a69b113c8548bd58e7d5618ea026ba6d1ffb1 branch from 4c52f84 to 41ed72c Compare September 28, 2026 17:30
@copyberry
copyberry Bot merged commit 41ed72c into main Sep 28, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/055a69b113c8548bd58e7d5618ea026ba6d1ffb1 branch September 28, 2026 17:30
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 28, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant