Codex Source Notes
Codex Source Notes
This series reads openai/codex by following one ordinary request: how it becomes a typed operation, enters a session and turn, assembles context, exposes tools, checks permissions, updates clients, writes recovery records, and extracts lessons that later threads can reuse.
The English pages are standalone articles, not route stubs. Source claims are tied to a fixed openai/codex public snapshot; product contracts come from OpenAI documentation.
Follow one request through sessions, step context, optional tool calls, client notifications, and durable recovery records.
Source Notes · Part II How session history becomes a model requestSee how history and StepContext are prepared separately, with for_prompt, WorldState updates, and compaction shaping the next model input.
Source Notes · Part III Protocol and Event StreamDistinguish starting or steering a turn, input acceptance and completion, and live notifications from filtered durable records.
Source Notes · Part IV How a tool request becomes local executionFollow tool registration and routing into UnifiedExec, separating call results, still-running processes, and output returned to the model.
Source Notes · Part V How Codex authorizes and sandboxes a toolSee how approval policy, centralized review, and SandboxAttempt govern execution, rejection, and controlled retries after sandbox denial.
Source Notes · Part VI How runtime events become client UITrace events through core, app-server, and clients, separating streamed views, approval requests, and turn/item reconstruction from rollout.
Source Notes · Part VII How skills, plugins, MCP, and subagents enter a turnSeparate skill instructions, plugin resources, MCP tool exposure, and child tasks as they enter the current step.
Source Notes · Part VIII When hooks run and what they can changeFollow the separate triggers for prompt, tool, permission, compaction, stop, interrupt, and session-end hooks.
Source Notes · Part IX How Codex keeps request prefixes reusableSeparate reusable prefixes, cache accounting, and WebSocket continuation across model-specific cache contracts and Responses / Lite request shapes.
Source Notes · Part X Rebuilding sessions and forks from rollout recordsFollow JSONL writes, reverse scanning, and tail replay to understand session recovery, forks, and compatibility with old rollback records.
Source Notes · Part XI How SDKs turn external calls into threads and turnsFollow initialization, thread and turn requests into app-server, distinguishing subscriptions, accepted input, and completed work.
Source Notes · Part XII How Codex extracts and reuses lessons from old threadsFollow two background stages through separate v1/v2 memories, polluted-source removal, and selective reuse in later requests.
Source Notes · Part XIII How Codex limits file writes and network access on WindowsSee how restricted accounts, tokens, ACLs, network rules, and service ownership checks constrain Windows command execution.