Skip to content

feat(context-guard): support Codex Stop/SubagentStop hooks (2.1.0) - #44

Merged
cdeust merged 2 commits into
mainfrom
feat/context-guard-codex
Sep 26, 2026
Merged

cdeust merged 2 commits into
mainfrom
feat/context-guard-codex

Conversation

@cdeust

@cdeust cdeust commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

The context guard now supports Codex sessions. Stop hooks read current context occupancy from Codex rollouts and ask the parent agent to persist the checkpoint. SubagentStop reads each child transcript and reports cumulative billed tokens without counting cached input twice. Codex dollar cost remains unavailable until a verified tariff is supplied.

The bundled thresholds include Astra at 180K WARN / 220K hard. Existing unchanged bundled tables receive that row; custom model rows and defaults remain authoritative. Codex installation instructions include hook trust, which is required for execution.

Validation on codex-cli 0.157.1:

  • 125 Python tests passed with 95% coverage. Ruff, lock consistency, 75 shell tests and ShellCheck 0.11.0 passed.
  • Independent review approved after fixing a custom-default regression.
  • A trusted plugin in an isolated Codex app-server session blocked Stop, delivered hook feedback, caused the model to write a checkpoint, then completed the next Stop and parent turn.
  • A native SubagentStop recorded one delegated child and surfaced its billed tokens in the parent's checkpoint message. Synthetic regression fixtures cover inherited parent metadata and repeated usage records.

The README documents primary evidence and native reproduction steps. No private transcripts are included.

cdeust and others added 2 commits September 26, 2026 12:25
The Stop guard was inert on Codex: it only understood Claude transcript
records. Host detection now peeks the transcript's first JSONL record
(type == "session_meta" -> Codex reader, anything else -> the pre-existing
Claude path, byte-identical) and dispatches to two new sibling modules,
transcript_codex.py (Codex line predicates) and host_detect.py, via a third,
usage_reader.py, which extracts the two transcript reads' I/O out of
stop-context-guard.py so that file shrinks instead of growing past its
500-line budget.

Every fact this integration relies on -- the Stop/SubagentStop payload
schema, the block/reason output contract, token semantics (cached_input_
tokens is a subset, not additive; turn/thread_token_usage are cumulative
cost counters, not context size), the activity-gate predicate, and the
gpt-6-astra context window -- is cited at its primary source (the codex
binary's own embedded JSON Schemas, extracted via strings; a real
~/.codex/sessions/**/*.jsonl rollout) in plugins/context-guard/README.md's
new "Codex support" table, not assumed from documentation.

Verified: existing 84+ Claude-path tests unchanged and green; the installed
hook (via a temp CODEX_HOME marketplace/plugin install) fires a decision:
block payload against a Codex-shaped Stop input; codex exec itself does not
invoke the hook lifecycle (empirically confirmed, documented) so the plugin
is tested via direct subprocess invocation, the same shape codex uses.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@cdeust
cdeust merged commit 52fe593 into main Sep 26, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant