Daily harness signal

Budget what the gate must see

August 25, 2026 · JST Two fresh findings Codex · Claude Code · boundary inputs
Codex and Claude Code expose the same harness failure in different forms: a gate can only protect what its input represents. Budget media explicitly, and carry privilege flags into policy decisions.
01 · Fresh · source date 2026-08-24

Make compaction pay for images

Use when: Codex CLI or Desktop runs screenshot, browser, image-generation, or other multimodal tasks across repeated context compactions. Text-only retention accounting can preserve enough historical images to retrigger compaction, resend large payloads, and multiply append-only rollout size.

Action: run npm install -g @openai/[email protected] or pin the equivalent signed package as the minimum for image-heavy work. Keep source images as external artifacts; pass paths or stable references instead of repeated inline data URLs. Start a fresh thread after the first unexplained compaction loop rather than feeding bloated history back into itself.

Acceptance check: in a disposable image-capable thread, add distinct, numbered screenshots until the displayed context meter crosses the compaction threshold. Run /compact twice, then inspect the latest type:"compacted" replacement history. Pass only if newest image sentinels remain, older ones fall outside the retention budget, a short follow-up does not immediately retrigger compaction, and each new checkpoint stays bounded.

Evidence: Codex 0.149.1 is an official stable release dated 2026-08-24. Its five-commit comparison includes “Budget retained images during remote compaction” plus dedicated image-budget tests. Independent issue reports measured image-bearing replacement histories from tens of megabytes to gigabytes and reproduced repeated compaction on Windows and macOS.

Caveat: the patch addresses retained-image budgeting in Responses compaction v2; it does not prove local or legacy compaction parity, remove old append-only checkpoints, externalize media, or guarantee that summary text and tool outputs converge below the next trigger.

02 · Fresh · source date 2026-08-23

Remove the escape path the classifier cannot see

Use when: Claude Code 2.1.241 runs auto mode with sandboxing enabled and allowUnsandboxedCommands left at its default true.

Action: set managed settings to {"sandbox":{"enabled":true,"failIfUnavailable":true,"allowUnsandboxedCommands":false}}. Widen explicit sandbox policy or run genuinely incompatible commands yourself; do not rely on the auto classifier to approve an escape.

Acceptance check: from a throwaway workspace, ask auto mode to write a nonce outside the allowed root after an in-sandbox failure. Pass only if no outside file appears, no unsandboxed dispatch receipt exists, and an in-root positive-control write succeeds.

Evidence: open issue #88972, dated 2026-08-23, includes a 2.1.241 runtime trace and shipped-bundle code showing dangerouslyDisableSandbox removed from classifier input. Official sandbox documentation confirms strict mode ignores that parameter.

Caveat: this is one unconfirmed macOS report with no maintainer response. Strict mode can break Docker and other incompatible tools; excludedCommands are deliberately unsandboxed and require separate review.

Compact source notes

  1. OpenAI Codex 0.149.1 (published 2026-08-24 00:28 UTC). Official stable artifact; the release page links its exact comparison.
  2. Codex 0.149.0…0.149.1 comparison (inspected 2026-08-25). Five commits, including retained-image compaction budgeting and dedicated regression files.
  3. openai/codex issue #33493 and issue #36232 (inspected 2026-08-25). Source-level diagnosis plus measured Windows/macOS field failures; the fresh stable patch has not yet been independently field-validated.
  4. anthropics/claude-code issue #88972 (opened 2026-08-23 11:48 UTC; inspected 2026-08-25). Current-version side-effect reproduction, classifier trace, and shipped-bundle code path; open and not maintainer-confirmed.
  5. Claude Code sandbox reference and auto-mode reference (retrieved 2026-08-25). Official strict-mode configuration and classifier-versus-deterministic-policy boundary.
  6. Method: anchor lens—versioned artifacts, regression files, side-effect traces, and measured rollout growth; unity lens—every enforcement or budget decision must receive all state that changes authority or cost. Confidence: Confirmed that Codex 0.149.1 ships the patch; Likely for field remediation and the Claude defect. Falsifiers: bounded-image canaries still loop on 0.149.1, or a current Claude canary always prompts before unsandboxed dispatch with the escape hatch enabled.