Skip to content
Documentation

Pinned Codex revision

All current Codex execution adapters use the Git submodule in third_party/codex. A fixed commit makes their shared implementation reproducible. It does not automatically update when upstream publishes a release.

Deployment pin

FieldValue
ProjectOpenAI Codex
LicenseApache-2.0; attribution in NOTICE
Tagrust-v0.154.0
Commit6b9826e3aa83b1a5947db50f4332cb9c65f1b340
Paththird_party/codex
ConsumersPatch, runtime worker, PTY, filesystem, Linux sandbox and proxy adapters
Patch optionsPreserveLineEndings, follow_symlinks: false

See connected components for the exact adapter responsibilities. Patch tests cover selected parity cases, not the entire upstream suite or all Codex behavior.

Workspace and lockfiles

Adapters have isolated Cargo workspaces so upstream workspace dependencies remain usable without copying and maintaining a forked patch parser. Preserve adapter lockfiles and required upstream Cargo patches. The filesystem and sandbox adapters pin matching Rama alpha dependencies to avoid resolving an incompatible mixture of alpha and stable releases.

The patch adapter calls the library inside codespace-patch; it does not invoke upstream's standalone apply_patch executable. LOCAL_FS and path utilities are implementation dependencies. Codex user settings do not grant workspace access.

Check and update

bash
PIN_ONLY=1 ./scripts/check-upstream-pin.sh

This checks only the submodule revision against this document. Without PIN_ONLY, the script also runs patch tests; it does not replace the other adapter gates. Use the complete update procedure before changing the pin. Do not use git submodule update --remote as a deployment step.