Daily harness signal

Bind the policy. Reap the process.

September 2, 2026 · JST Two fresh findings Codex · Guardian · MCP · subagents
Two fresh Codex failures share one rule: indirect execution must carry its effective policy into review, and every spawned runtime must return to a measured baseline after ownership ends.
01 · Fresh · source dates 2026-08-31 / 2026-09-01

Key Guardian history to the effective REPL policy

Use when: Codex Auto-review may approve node_repl or cua_repl actions, especially with a custom model_catalog_json, JavaScript can nest browser, computer-use, and MCP effects, so generic tool-call review is insufficient.

Action: require Codex 0.152.1 or later. For every custom Guardian reviewer model, set a non-empty model_messages.auto_review.node_repl_policy containing the complete nested-effect review policy. Omit the field only to accept Codex’s bundled fallback; an explicit empty string disables injection. Bind the resolved policy text into the review-session reuse key.

Acceptance check: create catalog variants A and B with unique policy sentinels. Trigger two approval-required REPL calls under A: the first Guardian developer input contains A exactly once, and the second may reuse that reviewer thread. Switch to B; the next review must use a new thread, contain B, and omit A.

Evidence: stable 0.152.1 contains only this behavioral repair. Merged PR #41919 adds the catalog field, bundled fallback, explicit-empty semantics, policy-aware reuse, and tests for Node/CUA, cache invalidation, and unsafe fallback rejection.

Caveat: this is a review-prompt identity fix, not a security proof. Auto-review remains probabilistic; keep the OS sandbox, network policy, MCP approval modes, and effect-level canaries independent.

02 · Fresh · source date 2026-09-01

Make terminal child state include process teardown

Use when: local Codex Desktop or CLI fans out subagents while stdio MCP servers are configured. A child’s completed status does not currently prove its runtime was released.

Action: before multi-agent rollout, disable every unused stdio server in the effective root configuration, then fully restart the desktop app. Do not rely on a custom-agent-local enabled=false override.
[mcp_servers.unused_local]
enabled = false
If workers need the same server, prefer one shared, authenticated Streamable HTTP bridge; otherwise serialize the work or set agents.enabled=false until the gate below passes.

Acceptance check: record the live Codex/app-server descendant process baseline. Spawn eight children that never call MCP, wait for terminal receipts, and require the count to return to baseline within thirty seconds. Then let one designated child call one server: exactly one owned runtime may appear, it must disappear after completion, Fail the rollout on monotonic growth.

Evidence: current Windows Desktop issue #42000 reports eight unused-MCP children leaving 39 node.exe, 11 node_repl.exe, and nine memory-server frontends despite per-agent disables. one Windows capture reached 245 Node processes and 18.3 GB.

Caveat: the fresh report has no maintainer confirmation, and client builds differ. Never kill processes by name; cleanup must follow spawn-captured ownership.

Compact source notes

  1. Codex 0.152.1 (published 2026-09-01 22:33 UTC; inspected 2026-09-02 11:00 JST) and exact stable comparison. Official patch release; three commits, with the Guardian repair as the sole behavioral change.
  2. Codex PR #41919 and stable-branch commit 796a151 (merged/source-dated 2026-08-31). Inspectable schema, resolution semantics, reuse-key change, and regression matrix.
  3. Official Auto-review reference (retrieved 2026-09-02). Establishes that Auto-review is a reviewer swap rather than a permission grant and remains non-deterministic.
  4. Codex issue #42000 and #42005 (2026-09-01). Current Windows Desktop reproduction with exact disabled configurations, eight-child workload, descendant counts, and no-use condition.
  5. Issue #34658, #38247, and #38754. Independent Windows/Linux/macOS process, memory, FD, source-path, and reference-patch evidence; all remain open. Official MCP docs confirm root-level disable and Streamable HTTP support.
  6. Method: anchor lens—stable release diff, merged tests, current process censuses, terminal records, and cross-platform reproductions; unity lens—review authority and runtime ownership both become identity-bound transition postconditions. Confidence: Confirmed for the 0.152.1 behavior and test scope; Likely for the MCP lifecycle failure family. Falsifiers: policy A survives a switch to B, an empty policy still injects text, no-use fan-out returns to baseline, or the reported growth disappears on current affected builds.