Skip to content

release: 0.22.2 - #4935

Merged
seratch merged 1 commit into
mainfrom
release/v0.22.2
Sep 9, 2026
Merged

seratch merged 1 commit into
mainfrom
release/v0.22.2

Conversation

@seratch

@seratch seratch commented Sep 9, 2026

Copy link
Copy Markdown
Member

Release readiness review (v0.22.1 -> TARGET c8a3573)

This is a release readiness report done by $final-release-review skill.

Diff

v0.22.1...c8a3573

Release intent

  • Review mode: final candidate
  • Intended release: patch 0.22.2
  • Minimum required release type: patch
  • Versioning verdict: compatible

Release call

🟢 GREEN LIGHT TO SHIP Candidate metadata is consistent, no concrete release-blocking regression was established, and the branch contains exactly one release commit above refreshed origin/main.

Scope summary

  • 94 files changed (+5632/-3563): UnixLocal file-operation hardening, compaction response-chain invalidation after pop, image-generation configuration typing, tests, and documentation with translations.
  • The release commit changes only pyproject.toml, uv.lock, and tests/fixtures/released_api_contract.json.

Risk assessment (ordered by impact)

  1. UnixLocal file operations resist symlink replacement

    • Risk: 🟢 LOW. Stable authorized paths and grants remain supported. User-scoped listing and writing now require sudo access to system python3 and its standard library.
    • Evidence: fix(sandbox): prevent UnixLocal file API symlink races #4931 introduces descriptor-relative O_NOFOLLOW traversal, pins root and grant aliases, and retains worker ownership through cancellation. Coverage includes stable symlinks, grant permissions, replacement races, and cleanup.
    • Files: src/agents/sandbox/sandboxes/unix_local.py, src/agents/sandbox/sandboxes/_unix_local_files.py, src/agents/sandbox/sandboxes/_unix_local_file_ops.py.
    • Action: Document the system-Python prerequisite after release and preserve the beta backend's existing host-isolation qualifications.
  2. Compaction invalidates retained response IDs after history is popped

    • Risk: 🟢 LOW. Manual previous-response compaction needs a new valid response ID after a successful or uncertain pop; auto/input compaction can use current local history.
    • Evidence: fix(sessions): reset compaction response chain after pop #4934 clears cached, deferred, and unstored response IDs under the existing mutation lock after a nonempty pop or an exception/cancellation. A pop returning None preserves them. Coverage includes committed SQLite deletion followed by failed or cancelled acknowledgement. The normal Runner supplies the next response ID through its existing persistence path.
    • Files: src/agents/memory/openai_responses_compaction_session.py, tests/memory/test_openai_responses_compaction_session.py.
    • Action: Explain that manual previous_response_id compaction must receive a new valid response ID matching corrected history, or callers can use auto/input mode. No public signature or durable schema changes are required.
  3. Image-generation typing expands without changing forwarding

    • Risk: 🟢 LOW. Existing upstream typed configurations, positional construction, mutable field behavior, and runtime dataclass layout remain supported.
    • Evidence: feat: support current image generation tool options #4932 adds ImageGenerationToolConfig with wider model, size, and quality annotations. Responses conversion still forwards the original mapping. The frozen contract adds the new export and TypedDict fields without removing existing entries.
    • Files: src/agents/tool.py, src/agents/__init__.py, src/agents/models/openai_responses.py, examples/tools/image_generator.py.
    • Action: Explain the configuration type and unchanged API validation boundary. Existing callers require no migration.

Documentation coverage (non-blocking)

  • Coverage source: Current read-only inspection of all 22 open PR file lists found no docs/ changes. The target includes merged docs: document v0.22.1 behavior updates #4577 and its translation refresh.
  • Status: partially covered
  • Covered obligations: The image example and API field docstring describe expanded options. The UnixLocal class docstring states the system-Python prerequisite. Existing session docs explain the three compaction modes.
  • Gaps or post-release suggestions:
    • In docs/tools.md, under Hosted tools, show ImageGenerationToolConfig, required type, expanded model/size/quality options, unchanged forwarding, and provider validation.
    • In docs/sandbox/clients.md, under Unix-local, explain symlink-race protection and the sudo/system-python3 prerequisite for ls(..., user=...) and write(..., user=...), independently of the application virtual environment.
    • In docs/sessions/index.md, under OpenAI Responses compaction, explain response-ID invalidation after successful or uncertain failed/cancelled pops, preservation after an empty pop, and the new-response-ID or auto/input alternatives.
  • Publication timing: Publish new 0.22.2 behavior guidance after package release.

Notes

  • The checked-out branch, project version, editable lock entry, and contract baseline agree on 0.22.2.
  • The contract baseline_commit and release commit parent are 25af629b3c877ba3d0e95189141bb636b21167a5.
  • No live model request was made during release preparation.

@seratch seratch added this to the 0.22.x milestone Sep 9, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-09T09:47:51.622545Z c8a3573 PR opened
🔒 Security Review ✅ Completed 2026-09-09T09:49:51.883084Z c8a3573 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@seratch
seratch merged commit 83c737f into main Sep 9, 2026
18 checks passed
@seratch
seratch deleted the release/v0.22.2 branch September 9, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant