Skip to content

fix: redact blocked tool outputs from replay state - #4507

Merged
seratch merged 12 commits into
mainfrom
fix/redact-blocked-tool-output
Aug 19, 2026
Merged

seratch merged 12 commits into
mainfrom
fix/redact-blocked-tool-output

Conversation

@seratch

@seratch seratch commented Aug 18, 2026 •

Copy link
Copy Markdown
Member

This pull request fixes a replay-safety issue for terminal tool output rejected by an output guardrail. Non-streaming final results already waited for output guardrails to complete, and a trip did not return a normal final result; the issue was that rejected terminal tool output could still remain reachable through Session history, RunState, streaming replay state, sandbox memory, the tripwire exception, or a subsequent model request. The fix also applies the guardrail verdict to the persistence and replay boundary for the terminal-tool-derived current response: passing responses are saved normally, rejected current suffixes are sanitized or discarded when they cannot be reconstructed safely, and ordinary guardrail exceptions preserve the existing completed-turn persistence behavior.

Solution

  • Delays client-managed Session persistence until the output guardrail completes, then preserves the existing persistence behavior for passing verdicts and ordinary guardrail exceptions.
  • Identifies the rejected current response using trusted turn boundaries and object ownership, without joining historical items by provider or call ID.
  • Reconstructs supported function-call pairs from allowlisted fields and replaces rejected output with provider-valid, data-free payloads.
  • Applies the sanitized current-turn snapshot across Session persistence, RunState, streaming replay state, and sandbox memory while preserving previously accepted history.
  • Removes rejected output aliases from guardrail results and the public tripwire exception while preserving the original tool guardrail verdict.
  • Discards only the rejected current suffix when it contains an unsupported, malformed, or reasoning-bearing variant that cannot be reconstructed safely.
  • Preserves structurally verifiable approval checkpoints when resuming without their previously attached Session.
  • Preserves the existing Chat Completions adapter behavior for unsupported conversation parameters.

Unaffected existing paths

  • Runs without output guardrails retain their existing execution behavior.
  • Client-managed Session persistence without output guardrails retains its released behavior.
  • HITL interruption and resume without output guardrails retain their released suffix-persistence behavior.
  • Ordinary assistant and max-turn output-guardrail failures preserve their existing output_info, run_data, and guardrail results.
  • When an output guardrail passes, normal Session persistence and backend-error behavior remain unchanged.
  • When an output guardrail raises an ordinary exception, completed terminal tool calls and outputs remain persisted according to the existing released contract.
  • Immediate cancellation and process-control exceptions retain their existing behavior.
  • Previously accepted turns, completed side effects, handoffs, tool guardrail verdicts, and consumed turns remain available for replay; sanitization or suffix removal applies only to the rejected current response.
  • Chat Completions retains its existing warning-and-ignore behavior for unsupported conversation parameters and its optional strict rejection mode.

Guardrail-specific limitations

These limitations apply only to configurations that use output guardrails:

  • An approval checkpoint cannot be resumed when its existing state does not contain enough trusted structural provenance to identify the current response safely. Structurally provable live or serialized checkpoints remain supported when resumed without an unsafe previously attached Session; partial-approval resume without output guardrails is unaffected.
  • A checkpoint with an attached Session that already contains persisted current-turn history fails closed when the SDK cannot safely exclude rejected output from that history.
  • If a terminal tool side effect completes but the run is immediately cancelled while its output guardrail is running, the completed side effect might not appear in Session history. Ordinary guardrail exceptions continue to preserve the completed turn.
  • A server-managed conversation fails closed only when output guardrails are enabled and the SDK cannot guarantee that rejected output is excluded from server-owned history. Server-managed conversations without output guardrails are unaffected, and Chat Completions configurations that ignore these parameters retain their existing adapter behavior.
  • If a rejected terminal response cannot be reconstructed safely, the SDK prioritizes preventing raw-output replay over preserving that current response for later resume.

Out of scope

The following are separate extensions to the output-guardrail persistence and replay contract; they do not remove existing functionality from runs without output guardrails:

  • Retracting streaming deltas that were already delivered.
  • Rolling back external side effects performed by terminal tools.
  • Durable response provenance or a pending/accepted/rejected persistence lifecycle.
  • Complete resume support for ambiguous serialized partial-approval states used with output guardrails.
  • Atomic Session replacement, leases, or compare-and-swap coordination.
  • Migration of legacy serialized states that lack trusted provenance.
  • Physical deletion or at-rest erasure of records already stored by a backend.
  • Mutation of raw objects retained by external application references.
  • Reconstruction or deletion of server-managed conversation history.
  • Redaction of tracing or other telemetry that was already emitted.
  • Complete resumability after every output-guardrail trip, cancellation, or unsupported response variant.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 529b9d1d1d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run_internal/run_loop.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a6f48d34e9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run_internal/run_loop.py Outdated
Comment thread src/agents/run.py Outdated
@seratch
seratch force-pushed the fix/redact-blocked-tool-output branch 2 times, most recently from 23eea88 to e8cf656 Compare August 18, 2026 22:00

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e8cf6564f3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run.py
Comment thread src/agents/run_internal/run_loop.py Outdated
Comment thread src/agents/run_internal/blocked_output.py Outdated
@seratch
seratch force-pushed the fix/redact-blocked-tool-output branch from e8cf656 to 2c00703 Compare August 19, 2026 00:55
@seratch seratch modified the milestones: 0.21.x, 0.22.x Aug 19, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 93e2668312

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run_internal/blocked_output.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 669c461511

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run_internal/blocked_output.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cfaffef005

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run_internal/run_loop.py Outdated
Comment thread src/agents/run_internal/blocked_output.py Outdated
Comment thread src/agents/run_internal/blocked_output.py Outdated
Comment thread src/agents/run_internal/agent_runner_helpers.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6aec076e74

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run_internal/blocked_output.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f0a1a46d79

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f0a1a46d79

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/agents/run_internal/blocked_output.py
@seratch
seratch merged commit ed644fc into main Aug 19, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant