# Reported issues for Codex Subagent

Pod holds 18 of 20 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [Codex Subagent](/mcp/codex-subagent).

## Most discussed

### Shutdown exits before delegations stop, and stdin EOF does not shut the server down

## Status: confirmed

This was parked as an investigation. Step 1 of "What would settle it" has now been done, and the concern is real.

## Reproduction (verified 2026-09-30, macOS, no Codex quota)

`runCodex` from `build/codex/runner.js` against `test/fixtures/stubborn-codex.mjs` (ignores SIGTERM), then the same sequence as `src/index.ts`: abort, then `process.exit(143)` as soon as the server has closed. The server exits with 143; the stand-in is still running 7 seconds later, past the…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/40) · 2026-09-14 · closed · 3 comments

### Report what the run actually did: effective directory, command count, uncached input

## Problem

Three things the caller needs are missing or wrong in a result.

1. **The effective working directory is invisible** when `working_dir` was omitted: the run inherits the MCP process's directory, which in a desktop client may be nowhere near the repository the user has in mind. The applied-settings block only speaks up when it *differs* from what was requested, and an omitted value matches by construction.
2. **The command count is capped.** `result.commands` retains the newest 500,…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/82) · 2026-09-17 · closed · 1 comment

### Optional output_schema for parseable delegation results

## Problem

A delegation returns prose. When the orchestrator needs to act on the answer — a list of findings with file, line and severity, a yes/no verdict with evidence — it has to re-read that prose, and a second model call is the usual way to turn it into something usable. `codex exec --output-schema <FILE>` constrains Codex's final message to a JSON Schema, which removes that step.

## Verified (2026-09-30, no quota beyond two `gpt-5.6-luna` runs at `low`)

- `--output-schema` exists on…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/28) · 2026-09-12 · closed · 1 comment

### A cancellation that arrives during the preflight is lost

## What happens

Cancelling a delegation while the preflight is still running has no effect: the delegation starts
anyway and runs to completion or timeout.

`src/codex/runner.ts:142` attaches the abort listener without first checking `signal.aborted`. An
`AbortSignal` does not replay the event, so a signal that was already aborted when the runner
attached is a signal the runner never hears.

The window is real, not theoretical: the handler awaits model resolution and the CLI preflight at…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/26) · 2026-09-12 · closed · 1 comment

### The timeout does not fire when the child exits but a descendant keeps the pipes open

## What happens

The run can outlive its timeout, and in the worst case never settle at all.

`terminate()` at `src/codex/runner.ts:126` returns early once `child.exitCode` is set, on the
assumption that a child which has exited needs no killing. But settlement waits for the `close`
event at `src/codex/runner.ts:173`, and `close` only fires when the stdio pipes are closed — not
when the process exits.

If the Codex process starts a descendant that inherits stdout and stderr and then exits, the…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/25) · 2026-09-12 · closed · 1 comment

### Output retention is unbounded, so a runaway delegation can exhaust memory

## What happens

Nothing caps how much of the child's stdout this server keeps in memory.

- `src/codex/events.ts:92` appends every incomplete chunk to the line buffer with no limit, so
  output that never contains a newline is retained in full.
- `src/codex/runner.ts:90` accumulates completed agent messages without a bound.

`STDERR_LIMIT` caps stderr and command previews are truncated, but neither of those bounds this.

## Reproduction

Feeding 64 MiB with no newline retained exactly…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/24) · 2026-09-12 · closed · 1 comment

### An allow-list of only commas or blank entries silently allows every model

## Problem

`CODEX_SUBAGENT_ALLOWED_MODELS` drops empty entries (`readList` in `src/config.ts`), and an empty allow-list means no restriction. So a value meant to restrict that ends up with no names in it, such as `,` or a template whose variables expanded to nothing (`${A},${B}`), removes the restriction instead of reporting a mistake. Verified on main (2026-10-01): `loadConfig({ CODEX_SUBAGENT_ALLOWED_MODELS: "," })` returns `allowedModels: []` with no configuration error, and…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/128) · 2026-10-01 · closed · 0 comments

### Shutdown test measures machine speed, and the forced stage has no time bound

## Problem

`test/shutdown.test.ts` "AC-1 stops every run, forcing the stubborn ones, and exits within 350 ms" (#40) measures wall-clock time from the shutdown request to the exit and compares it with 350 ms, then checks 100 ms later that no process is alive. That mixes what the code decides with how fast the machine is:

- The time includes a synchronous `ps` read before the forced stage (#107, #112): about 32 ms on a developer Mac, about 130 ms on GitHub's macOS runner. On PR #115 the exit…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/116) · 2026-09-30 · closed · 0 comments

## Most recent

### Shutdown can exit before sending SIGKILL to every stubborn run

## Problem

`test/shutdown.test.ts` "AC-1 stops every run, forcing the stubborn ones, and exits within 350 ms" (#40) fails intermittently, and on 2026-09-30 it failed in every `npm run verify` run on macOS while passing when the suite ran alone. It was first filed as a test that measures the machine's load. It is not: it is catching a real defect in the shutdown, with too little margin to catch it every time.

Measured on macOS, Node 24, with the test file alone and no load, three runs out of…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/112) · 2026-09-30 · closed · 0 comments

### codex_job_result reports 'unknown error' for a job still stopping after a cancel

## Problem

Right after `codex_job_cancel`, `codex_job_status` reports the job as `cancelled` and says "Read the full output with codex_job_result", but `codex_job_result` answers `Job … produced no result: unknown error`. The job's partial result only exists once the runner has settled (up to the grace period plus one second, #96), and until then the registry has neither a result nor an error to show. Found in `/smoke-test` on 2026-09-30 (extra step 10).

## Acceptance criteria

- **AC-1**…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/108) · 2026-09-30 · closed · 0 comments

### Commands Codex runs survive cancellation, timeout and shutdown

## Problem

Commands Codex runs survive every way this server stops a run: cancellation, timeout and shutdown. #96 made termination signal the Codex process *group*, which its tests confirmed with a stand-in. The real CLI does not keep its commands in that group: each command, and each helper, is started as the leader of a group of its own, so the group signal never reaches it. A `sleep 45` started by a delegation outlived a cancel, a 10-second timeout and a server shutdown, reparented to PID…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/107) · 2026-09-30 · closed · 0 comments

### Check every new Codex CLI release against this server's argv and catalog in CI

## Problem

Nothing tells us when a new Codex CLI release breaks this server. The CLI shipped eleven releases between 2026-09-09 (0.154.0) and 2026-09-30 (0.159.2). The unit suite runs against output captured from 0.154.0, `codex_doctor` only flags versions older than the verified one, and `/smoke-test` and `/verify-catalog` run only when someone remembers to. Argv breakage has already reached users once: `--search` was never valid after `exec` (#48), found by real use. `codex-mcp-server`…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/99) · 2026-09-30 · closed · 0 comments

### Run the preflight and model catalog in the delegation's working directory

## Problem

Codex resolves configuration against the working directory: a trusted project's `.codex/config.toml` applies only when Codex runs inside it. Verified on codex-cli 0.154.0: `debug models` honours a project `model_catalog_json` only when run in that project. The server runs the preflight and the catalog in its own process cwd, but the delegation in `working_dir`, so the catalog used to validate a model and effort can differ from the one the run uses. Both caches ignore the context…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/56) · 2026-09-14 · closed · 0 comments

### Surface failed turns, usage-limit errors and configuration notices from the event stream

## Problem

Observed during a real delegation on 2026-09-14 and verified with scratch runs on codex-cli 0.154.0:

- A follow-up hit the ChatGPT plan's usage limit. The rollout recorded `task_complete.error.codex_error_info = "usage_limit_exceeded"` with the reset time, and the JSONL stream carries `turn.failed` and top-level `{"type":"error"}` events. `src/codex/events.ts` handles neither, so the server reported only "Truncated Codex output: discarded 1 oversized JSONL line(s)" and exit 1. The…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/53) · 2026-09-14 · closed · 0 comments

### Keep a follow-up on its thread's model, effort and working directory

## Problem

Verified against codex-cli 0.154.0 (scratch `CODEX_HOME`, no quota spent; the applied values were read from the rollout's `turn_context`):

- `codex exec resume` without `--model` takes the model from the **config layers of the directory it is resumed in**, not from the recorded session. A thread recorded on `gpt-5.5` and resumed in a trusted project whose config says `gpt-5.6-luna` emitted "This session was recorded with model `gpt-5.5` but is resuming with `gpt-5.6-luna`" and…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/52) · 2026-09-14 · closed · 0 comments

### Report Codex configuration errors instead of a sign-in problem or a stale catalog

## Problem

Verified against codex-cli 0.154.0 with a scratch `CODEX_HOME`:

- A config the CLI cannot load (TOML syntax error, an invalid enum such as `sandbox_mode="bogus"`, or the removed top-level `profile = "x"` selector) makes `codex login status` exit 1 with `Error loading configuration: ...`, and `codex debug models` exit 1. `codex --version` still exits 0.
- `runDoctor` treats any non-zero `login status` as signed out, so the user is told to sign in (`src/codex/doctor.ts`, login…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/51) · 2026-09-14 · closed · 0 comments

### web_search always fails: --search is a global codex flag, not an exec flag

## What happens

Any delegation with `web_search: true` fails immediately, before Codex runs:

```text
error: unexpected argument '--search' found

  tip: to pass '--search' as a value, use '-- --search'

Usage: codex exec [OPTIONS] [PROMPT]
```

`src/codex/args.ts:102` appends `--search` after `exec`. On the installed CLI (`codex-cli 0.154.0`),
`--search` is listed by `codex --help` as a top-level option and does not appear in
`codex exec --help` at all, so the subcommand rejects it. No quota…

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/48) · 2026-09-14 · closed · 0 comments

### Bound the command, error and file-change lists retained per run

#36 capped retained agent messages but not the other per-run lists: commands, errors and file changes still grow without limit (src/codex/runner.ts). Cap each, collapse repeated errors, de-duplicate file changes by path and kind, and report what was omitted through the result's errors. Separately, finished jobs are only evicted when a job starts or the list is read (src/jobs.ts); evict on status and result reads too. Found by the planning review of 2026-09-14 and confirmed against the code.

[Read the thread](https://github.com/parisbs/codex-subagent-mcp/issues/42) · 2026-09-14 · closed · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/parisbs/codex-subagent-mcp/issues).
