The Codex Changelog
All Episodes
Codex Instant Interrupt Changes How Agents Respond

Codex Instant Interrupt Changes How Agents Respond

0:00|0:00

Codex 0.159.0 adds instant_interrupt, letting new input steer long-running responses without restarting the session, plus fixes for WebSocket continuity, Guardian reviews, and interruption notices. We also cover the release’s security hardening for .aws directories, retained filesystem denials, and the follow-up patch notes for 0.159.1 and 0.159.2.

Show Notes


Chapter 1

Steering Agents Mid Turn

Ethan Park

Picture this. You ask a coding agent for a small change, and it starts streaming dozens of lines down the wrong architectural path. And you just... watch it go.

Maya

Oh, I've been there. You get two choices. Let the tokens burn, or hit Control C and kill the whole turn.

Ethan Park

Right. So, um, Codex 0.159.0 has an answer. Quick thanks to Jellypod for helping make this daily briefing happen, and everything I'm quoting comes from the release notes on the Codex GitHub page.

Maya

Okay, so what's the answer?

Ethan Park

An opt in setting called instant_interrupt. You set it to true in config.toml, and then new input can steer Codex during model responses, or during long running Code Mode calls. The notes credit pakrym-oai, pull requests 48135 and 48141. One lets Code Mode yield on new input, the other preempts the model response.

Maya

Preempts. So it stops the stream mid sentence?

Ethan Park

That's my reading of it, yeah. The model's turn gets cut in on, rather than you waiting for it to finish.

Maya

Hmm, but here's my worry. If I interrupt, don't I lose everything? Fresh session, the agent forgets what we were doing.

Ethan Park

That's the part I, I, I wanted to check. Two other entries matter here. Pull request 48508 says it preserves WebSocket continuations when steering a turn. So the live connection carries on instead of resetting.

Maya

So it's a nudge, not a restart.

Ethan Park

Exactly that. Think of a batch job versus a conversation. Before, a turn was a batch job. You submit, you wait. Now it's more like tapping a colleague on the shoulder while they're typing.

Maya

And the security side? Codex has that Guardian review thing.

Ethan Park

Pull request 48725. It retains confirmed Code Mode messages for Guardian reviews. So the reviewer doesn't get amnesia when you redirect mid turn.

Maya

Okay, good. Now my tester brain kicks in, because there's a caveat. When you interrupt, what shows up on screen?

Ethan Park

A short, neutral notice. Pull request 48830. Not an error state.

Maya

Which I like, because an interruption you caused on purpose shouldn't look like a crash. But, uh, and this is me reasoning, not something the notes say, a clean banner doesn't undo anything. If a bash command already wrote files to disk before your interrupt landed, those files are still there.

Ethan Park

Yeah, that's fair. Steering changes what happens next. It doesn't rewind what already happened.

Maya

Right. So check your working tree after you steer. Don't assume the slate is clean.

Chapter 2

Sandbox Lockdowns and Everyday Upgrades

Ethan Park

Okay, so that's the headline feature. But 0.159.0 has a security piece I think people will skip past.

Maya

The AWS thing?

Ethan Park

Yep. Pull request 48176 protects .aws directories by default under sandbox writable roots. So if you've given Codex a writable folder that happens to contain your AWS credentials, those stay protected.

Maya

Which is the kind of mistake that happens at five p.m. on a Friday.

Ethan Park

Totally. And pull request 48155 says approved commands keep explicit filesystem denials. So approving a command doesn't quietly wipe out a rule you set.

Maya

Wait, that could happen before?

Ethan Park

The fix exists, so I'd assume it was a gap. I can't say how often it bit anyone.

Maya

Fair. What about the patch releases? There were a couple right behind it.

Ethan Park

Two. 0.159.1 added GPT 6.1 Sol as the default model in the bundled catalog and Amazon Bedrock Mantle and Runtime catalogs. Pull requests 49323 and 49342. Then 0.159.2, pull request 49385, suppressed console windows flashing on Windows when Codex launches background processes and sandboxed commands.

Maya

I love that one. Little black boxes popping up and vanishing. Nobody writes a blog post about it, but everyone on Windows notices.

Ethan Park

Yeah, the boring fixes are the ones you feel.

Maya

Speaking of feel, there are some nice small ones. You can scroll the transcript with the mouse wheel while a plan approval modal is open. Pull request 48805. Before, you'd have to decide whether to implement a plan without rereading it.

Ethan Park

That's a, a, a real annoyance fixed.

Maya

And in the warnings viewer, closing it dismisses the warnings you've looked at, and pressing k keeps one for later. Pull request 48205.

Ethan Park

And something got removed, right?

Maya

The automatic follow up prompt suggestions, and the tui.prompt_suggestions setting with them. Pull request 48621. Less clutter.

Ethan Park

Okay, so here's what I keep wondering. If steering is cheap, does it change how people work? Like, do you start typing half a thought and fix it as you go?

Maya

Or do you burn more context with a dozen tiny corrections? Every nudge is more text in the session.

Ethan Park

Hmm. That's the tradeoff. The notes don't measure it, so I'm guessing. But I'd say exploratory wins when the early direction is cheap to fix.

Maya

I'd put it differently. Steer early, when the wrong path is ten lines long. Not when it's two hundred, and already touched your files.

Ethan Park

Ha, okay. Steer early. That's the takeaway.

Maya

Good chat. Go check your config.