Daily harness signal

Put compute changes behind runtime gates

August 30, 2026 · JST Two fresh findings Claude Code · Codex · compute authority
Two fresh releases move compute policy into inspectable runtime boundaries: Claude can gate model switches before they spend, while Codex now charges every nested worker’s tokens to the root goal budget.
01 · Fresh · source date 2026-08-28

Admit model switches like privilege changes

Use when: a Claude Code session may change models through /model, Remote Control, an SDK host, fast mode, automatic fallback, or resume, especially when cache loss or model policy matters.

Action: on 2.1.251 or later, add a managed PreModelSwitch command hook matching .*. Read from_model, to_model, source, context_tokens, and estimated_cache_write_usd; return deny for forbidden targets, ask above your re-cache threshold, and allow otherwise. Add PostModelSwitch to write a receipt and return target-specific additionalContext. In -p and SDK runs, ask becomes refusal.

Acceptance check: switch from Sonnet to an allowed model; one pre-hook receipt must contain both model IDs, source, token estimate, and decision. A forbidden target must leave Sonnet active. Trigger an automatic fallback and resume restoration; both must emit post-hook receipts, and only the final target’s guidance may enter the next request.

Evidence: Anthropic’s signed 2.1.251 release introduces both events. The current hook reference specifies canonical matching, a fail-closed pre-hook timeout, decision precedence, cost fields, and automatic-switch post events. Issue #89209 records a prior transcript where Opus served the turn while the model claimed Fable.

Caveat: PreModelSwitch cannot intercept automatic fallback or resume, and PostModelSwitch cannot undo them. Command hooks execute with user authority; keep policy in managed scope and test it.

02 · Fresh · source date 2026-08-29

Make the root pay for the whole agent tree

Use when: a Codex /goal may spawn children or grandchildren, particularly reviewers and explorers that keep working while the root waits.

Action: require Codex 0.151.0 or later, then set the default and maximum goal ceiling in managed configuration. Also cap live fan-out separately:
[goals]
max_goal_token_budget = 250000

[agents]
max_concurrent_threads_per_session = 4
App-server clients may set a lower token_budget through thread/goal/set. Do not substitute features.rollout_budget without testing; it remains under development.

Acceptance check: start a disposable low-budget goal, spawn one child and one grandchild, and leave the root mostly idle. Poll /goal or thread/goal/get. tokensUsed must increase after each descendant works, and the goal must enter budget_limited near the aggregate ceiling.

Evidence: OpenAI’s stable 0.151.0 release ships the change. Merged PR #41183 covers children, grandchildren, idle accounting, unloaded parents, goal replacement, concurrent checkpoints, and budget exhaustion. OpenAI’s subagent guide independently warns that every worker performs its own model work.

Caveat: goal exhaustion is a soft stop, so in-flight work may cross the line. This counter is not billing, per-model attribution, a spend cap, or a depth limit; retain separate controls.

Compact source notes

  1. Claude Code v2.1.251 (published 2026-08-28 18:19 UTC; inspected 2026-08-30). Signed stable release introducing model-switch hooks and their intended admission/annotation roles.
  2. Claude Code hooks reference (retrieved 2026-08-30). Current schemas, sources, cost estimates, timeout behavior, decision precedence, and automatic-switch boundaries.
  3. Claude Code issue #89209 (2026-08-24). Inspectable transcript-level mismatch after a safeguard-driven fallback; unconfirmed by Anthropic.
  4. OpenAI Codex 0.151.0 (published 2026-08-29 09:55 UTC; inspected 2026-08-30). Official stable release.
  5. Codex PR #41183 (merged 2026-08-27). Versioned implementation and regression scope for rolling descendant usage into root-goal accounting.
  6. Codex PR #37878 and official subagent guide (inspected 2026-08-30). Configured goal-ceiling semantics and the independent warning that subagent work adds token use.
  7. Method: anchor lens—stable releases, merged implementations, current schemas, and explicit side-effect/counter canaries; unity lens—model changes and delegation are both compute-authority transitions that the runtime, not prompt prose, must admit and account. Confidence: Confirmed for shipped contracts and test scope; no independent 2.1.251/0.151.0 field canary was found. Falsifiers: a denied model switch applies, an automatic switch produces no post event, or descendant work leaves root-goal usage unchanged.