Daily harness signal

Re-attest execution authority after model changes

August 7, 2026 · JST One fresh finding Codex · permissions · model transitions
Model selection is now an execution-authority transition. Codex 0.146.1 narrows new cyber-model threads automatically, but unattended harnesses should pin the intended profile and verify the transition receipt.
01 · Fresh · source date 2026-08-05

Treat a model switch as a permission transition

Use when: a Codex TUI session can switch models, especially before unattended security, repository, or infrastructure work. Model capability is no longer merely an inference choice: a cyber-specialty selection can change the thread's permission profile, approval policy, and reviewer.

Action: pin Codex 0.146.1 or later. For unattended cyber-capable sessions, set default_permissions=":workspace", approval_policy="on-request", and approvals_reviewer="auto_review" in trusted configuration. In managed requirements, set allowed_permission_profiles={":read-only"=true,":workspace"=true}, allowed_approval_policies=["on-request"], and allowed_approvals_reviewers=["auto_review"]; omit :danger-full-access. Start a new thread after changing policy. At every later model switch, capture model ID, specialty, effective profile, approval policy, and reviewer before the next tool call.

Acceptance check: in a disposable repository, start a clean TUI thread. Record the permission banner, select a catalog model marked cyber, then change only reasoning effort. Pass if state remains workspace-write, on-request, and Auto-review; the notice is visible; and reasoning changes do not reset the profile. Next, edit one workspace sentinel and request one write to a disposable path outside the workspace. The first should run inside the sandbox; the second must emit an Auto-review request and decision before dispatch. Fail on silent full access, a reviewer-free escape, or any unexplained profile change.

Evidence: OpenAI shipped 0.146.1 as a stable patch. Merged PR #37055 propagates modelSpecialty, applies requirement-aware cyber defaults, warns on Auto-review and full access, and adds tests for defaults, fallbacks, reasoning preservation, and notices. The versioned backport changes 34 files, including 309 added TUI-test lines. Official docs define Auto-review as a reviewer swap, not a permission grant.

Caveat: the backport records only git-diff validation, not published test-run output, so confidence is Likely until the local matrix passes. Auto-review is model-based, not deterministic, and sees only boundary-crossing requests; already-allowed sandbox actions bypass it. It adds model calls, while Computer Use app approvals still reach a person. Assert effective state, not desired configuration text.

Compact source notes

  1. Codex 0.146.1 (published 2026-08-05 15:55 UTC / 2026-08-06 00:55 JST). Official stable release and primary fresh claim.
  2. PR #37055, stable backport PR #37057, and verified commit 7558bed (2026-08-05). Merged implementation, changed-file inventory, and versioned tests.
  3. Auto-review documentation, permission-profile documentation, and cyber-safety documentation (retrieved 2026-08-07). Current official semantics and limits.
  4. Method: anchor lens—stable release, merged diff, tests, and observable permission receipts; unity lens—model selection and execution authority form one transition boundary. A reviewer-free out-of-workspace dispatch falsifies the claim. Confidence: Likely.