Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for Codex Subagent

Pod holds 18 of 20 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to Codex Subagent.

Most discussed

Shutdown exits before delegations stop, and stdin EOF does not shut the server down

Status: confirmed

This was parked as an investigation. Step 1 of "What would settle it" has now been done, and the concern is real.

Reproduction (verified 2026-09-30, macOS, no Codex quota)

runCodex from build/codex/runner.js against test/fixtures/stubborn-codex.mjs (ignores SIGTERM), then the same sequence as src/index.ts: abort, then process.exit(143) as soon as the server has closed. The server exits with 143; the stand-in is still running 7 seconds later, past the…

Read the thread · 2026-09-14 · closed · 3 comments

Report what the run actually did: effective directory, command count, uncached input

Problem

Three things the caller needs are missing or wrong in a result.

  1. The effective working directory is invisible when working_dir was omitted: the run inherits the MCP process's directory, which in a desktop client may be nowhere near the repository the user has in mind. The applied-settings block only speaks up when it differs from what was requested, and an omitted value matches by construction.
  2. The command count is capped. result.commands retains the newest 500,…

Read the thread · 2026-09-17 · closed · 1 comment

Optional output_schema for parseable delegation results

Problem

A delegation returns prose. When the orchestrator needs to act on the answer — a list of findings with file, line and severity, a yes/no verdict with evidence — it has to re-read that prose, and a second model call is the usual way to turn it into something usable. codex exec --output-schema <FILE> constrains Codex's final message to a JSON Schema, which removes that step.

Verified (2026-09-30, no quota beyond two gpt-5.6-luna runs at low)

Read the thread · 2026-09-12 · closed · 1 comment

A cancellation that arrives during the preflight is lost

What happens

Cancelling a delegation while the preflight is still running has no effect: the delegation starts anyway and runs to completion or timeout.

src/codex/runner.ts:142 attaches the abort listener without first checking signal.aborted. An AbortSignal does not replay the event, so a signal that was already aborted when the runner attached is a signal the runner never hears.

The window is real, not theoretical: the handler awaits model resolution and the CLI preflight at…

Read the thread · 2026-09-12 · closed · 1 comment

The timeout does not fire when the child exits but a descendant keeps the pipes open

What happens

The run can outlive its timeout, and in the worst case never settle at all.

terminate() at src/codex/runner.ts:126 returns early once child.exitCode is set, on the assumption that a child which has exited needs no killing. But settlement waits for the close event at src/codex/runner.ts:173, and close only fires when the stdio pipes are closed — not when the process exits.

If the Codex process starts a descendant that inherits stdout and stderr and then exits, the…

Read the thread · 2026-09-12 · closed · 1 comment

Output retention is unbounded, so a runaway delegation can exhaust memory

What happens

Nothing caps how much of the child's stdout this server keeps in memory.

STDERR_LIMIT caps stderr and command previews are truncated, but neither of those bounds this.

Reproduction

Feeding 64 MiB with no newline retained exactly…

Read the thread · 2026-09-12 · closed · 1 comment

An allow-list of only commas or blank entries silently allows every model

Problem

CODEX_SUBAGENT_ALLOWED_MODELS drops empty entries (readList in src/config.ts), and an empty allow-list means no restriction. So a value meant to restrict that ends up with no names in it, such as , or a template whose variables expanded to nothing (${A},${B}), removes the restriction instead of reporting a mistake. Verified on main (2026-10-01): loadConfig({ CODEX_SUBAGENT_ALLOWED_MODELS: "," }) returns allowedModels: [] with no configuration error, and…

Read the thread · 2026-10-01 · closed · 0 comments

Shutdown test measures machine speed, and the forced stage has no time bound

Problem

test/shutdown.test.ts "AC-1 stops every run, forcing the stubborn ones, and exits within 350 ms" (#40) measures wall-clock time from the shutdown request to the exit and compares it with 350 ms, then checks 100 ms later that no process is alive. That mixes what the code decides with how fast the machine is:

Read the thread · 2026-09-30 · closed · 0 comments

Most recent

Shutdown can exit before sending SIGKILL to every stubborn run

Problem

test/shutdown.test.ts "AC-1 stops every run, forcing the stubborn ones, and exits within 350 ms" (#40) fails intermittently, and on 2026-09-30 it failed in every npm run verify run on macOS while passing when the suite ran alone. It was first filed as a test that measures the machine's load. It is not: it is catching a real defect in the shutdown, with too little margin to catch it every time.

Measured on macOS, Node 24, with the test file alone and no load, three runs out of…

Read the thread · 2026-09-30 · closed · 0 comments

codex_job_result reports 'unknown error' for a job still stopping after a cancel

Problem

Right after codex_job_cancel, codex_job_status reports the job as cancelled and says "Read the full output with codex_job_result", but codex_job_result answers Job … produced no result: unknown error. The job's partial result only exists once the runner has settled (up to the grace period plus one second, #96), and until then the registry has neither a result nor an error to show. Found in /smoke-test on 2026-09-30 (extra step 10).

Acceptance criteria

Read the thread · 2026-09-30 · closed · 0 comments

Commands Codex runs survive cancellation, timeout and shutdown

Problem

Commands Codex runs survive every way this server stops a run: cancellation, timeout and shutdown. #96 made termination signal the Codex process group, which its tests confirmed with a stand-in. The real CLI does not keep its commands in that group: each command, and each helper, is started as the leader of a group of its own, so the group signal never reaches it. A sleep 45 started by a delegation outlived a cancel, a 10-second timeout and a server shutdown, reparented to PID…

Read the thread · 2026-09-30 · closed · 0 comments

Check every new Codex CLI release against this server's argv and catalog in CI

Problem

Nothing tells us when a new Codex CLI release breaks this server. The CLI shipped eleven releases between 2026-09-09 (0.154.0) and 2026-09-30 (0.159.2). The unit suite runs against output captured from 0.154.0, codex_doctor only flags versions older than the verified one, and /smoke-test and /verify-catalog run only when someone remembers to. Argv breakage has already reached users once: --search was never valid after exec (#48), found by real use. codex-mcp-server…

Read the thread · 2026-09-30 · closed · 0 comments

Run the preflight and model catalog in the delegation's working directory

Problem

Codex resolves configuration against the working directory: a trusted project's .codex/config.toml applies only when Codex runs inside it. Verified on codex-cli 0.154.0: debug models honours a project model_catalog_json only when run in that project. The server runs the preflight and the catalog in its own process cwd, but the delegation in working_dir, so the catalog used to validate a model and effort can differ from the one the run uses. Both caches ignore the context…

Read the thread · 2026-09-14 · closed · 0 comments

Surface failed turns, usage-limit errors and configuration notices from the event stream

Problem

Observed during a real delegation on 2026-09-14 and verified with scratch runs on codex-cli 0.154.0:

Read the thread · 2026-09-14 · closed · 0 comments

Keep a follow-up on its thread's model, effort and working directory

Problem

Verified against codex-cli 0.154.0 (scratch CODEX_HOME, no quota spent; the applied values were read from the rollout's turn_context):

Read the thread · 2026-09-14 · closed · 0 comments

Report Codex configuration errors instead of a sign-in problem or a stale catalog

Problem

Verified against codex-cli 0.154.0 with a scratch CODEX_HOME:

Read the thread · 2026-09-14 · closed · 0 comments

web_search always fails: --search is a global codex flag, not an exec flag

What happens

Any delegation with web_search: true fails immediately, before Codex runs:

error: unexpected argument '--search' found

  tip: to pass '--search' as a value, use '-- --search'

Usage: codex exec [OPTIONS] [PROMPT]

src/codex/args.ts:102 appends --search after exec. On the installed CLI (codex-cli 0.154.0), --search is listed by codex --help as a top-level option and does not appear in codex exec --help at all, so the subcommand rejects it. No quota…

Read the thread · 2026-09-14 · closed · 0 comments

Bound the command, error and file-change lists retained per run

#36 capped retained agent messages but not the other per-run lists: commands, errors and file changes still grow without limit (src/codex/runner.ts). Cap each, collapse repeated errors, de-duplicate file changes by path and kind, and report what was omitted through the result's errors. Separately, finished jobs are only evicted when a job starts or the list is read (src/jobs.ts); evict on status and result reads too. Found by the planning review of 2026-09-14 and confirmed against the code.

Read the thread · 2026-09-14 · closed · 0 comments

The remaining reports are on the project's issue tracker.