Codex Source Notes

Codex Source Notes

This series reads openai/codex by following one ordinary request: how it becomes a typed operation, enters a session and turn, assembles context, exposes tools, checks permissions, updates clients, writes recovery records, and extracts lessons that later threads can reuse.

The English pages are standalone articles, not route stubs. Source claims are tied to a fixed openai/codex public snapshot; product contracts come from OpenAI documentation.

Source Notes · Part I Follow one request through the Codex runtime

Follow one request through sessions, step context, optional tool calls, client notifications, and durable recovery records.

Source Notes · Part II How session history becomes a model request

See how history and StepContext are prepared separately, with for_prompt, WorldState updates, and compaction shaping the next model input.

Source Notes · Part III Protocol and Event Stream

Distinguish starting or steering a turn, input acceptance and completion, and live notifications from filtered durable records.

Source Notes · Part IV How a tool request becomes local execution

Follow tool registration and routing into UnifiedExec, separating call results, still-running processes, and output returned to the model.

Source Notes · Part V How Codex authorizes and sandboxes a tool

See how approval policy, centralized review, and SandboxAttempt govern execution, rejection, and controlled retries after sandbox denial.

Source Notes · Part VI How runtime events become client UI

Trace events through core, app-server, and clients, separating streamed views, approval requests, and turn/item reconstruction from rollout.

Source Notes · Part VII How skills, plugins, MCP, and subagents enter a turn

Separate skill instructions, plugin resources, MCP tool exposure, and child tasks as they enter the current step.

Source Notes · Part VIII When hooks run and what they can change

Follow the separate triggers for prompt, tool, permission, compaction, stop, interrupt, and session-end hooks.

Source Notes · Part IX How Codex keeps request prefixes reusable

Separate reusable prefixes, cache accounting, and WebSocket continuation across model-specific cache contracts and Responses / Lite request shapes.

Source Notes · Part X Rebuilding sessions and forks from rollout records

Follow JSONL writes, reverse scanning, and tail replay to understand session recovery, forks, and compatibility with old rollback records.

Source Notes · Part XI How SDKs turn external calls into threads and turns

Follow initialization, thread and turn requests into app-server, distinguishing subscriptions, accepted input, and completed work.

Source Notes · Part XII How Codex extracts and reuses lessons from old threads

Follow two background stages through separate v1/v2 memories, polluted-source removal, and selective reuse in later requests.

Source Notes · Part XIII How Codex limits file writes and network access on Windows

See how restricted accounts, tokens, ACLs, network rules, and service ownership checks constrain Windows command execution.