Repository navigation
Keep output deterministic and add quiet and verbose controls - #392
Conversation
Castiron custom codeEvaluated main: ✅ No new custom-code files detected. 2 mixed files remain; 0 existing customizations changed. Compared 2 existing customizations unchanged
A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 37908606254 --repo openai/openai-cli \
--name castiron-custom-code-37908606254-1 --dir /tmp/castiron-custom-code-37908606254-1
git apply --stat /tmp/castiron-custom-code-37908606254-1/custom-code.patch
cat /tmp/castiron-custom-code-37908606254-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin 217ff2ea1e853040ba08c3c170e05586424386aa 44f75644aa0f1dadb481a251a92b25600cbc6057
python3 scripts/castiron/custom_code_report.py report \
--base 217ff2ea1e853040ba08c3c170e05586424386aa \
--head 44f75644aa0f1dadb481a251a92b25600cbc6057 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-44f75644aa0f
cat /tmp/castiron-custom-code-44f75644aa0f/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
|
@codex review Please review commit |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. Nice work! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cd1449a5cb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af738605da
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed cd44152959d582cab48e95c426b90d8de5d1a85c against 390a9c3d68e93f7348509ffec169bb5ab38d68cc. I found no blocking issue in output separation, quiet/verbose policy, stream ownership, save receipts, or manpage completion. The earlier receipt, image-progress, and startup-reporting findings are addressed. One P3 comment removes an unreachable error branch.
Hosted tests, build, artifact, lint, platform help, CodeQL, and Castiron checks passed. The exact-head Help compatibility workflow also passed. This was a source-only review; I did not run local tests, native consoles, recordings, or live API calls.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 68a3e87171
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Reviewed deterministic output selection, quiet/verbose controls, error propagation and request IDs, stream cleanup, color and diagnostic routing, image feedback, and manpage output/lifecycle. No blocking findings; the previously reported issues appear addressed.
On the exact head, focused custom output/deterministic/manpage/request-ID/readable/table tests and public output/manpage/request-ID tests pass. Focused vet and changed-file gofmt checks are clean. Removing the quiet-mode table-hint guard caused TestRenderListNavigationPageHintPolicy to fail as expected; restored source passed. Hosted checks pass. I did not independently run native Windows tests.
The existing upload alias requires `--file`; metadata and contents use `retrieve` and `content`. This adds a plain upload path, `get` for metadata, and `download` for contents. Help shows the workflow and gives runnable examples. This inherits the merged output, stdin, and save policies from openai#392 and openai#395. ### What changes - Upload accepts one quoted local path and keeps purpose explicit. - Files help lists upload, get, and download in workflow order. - Shell completion supports the first upload path and preserves literal leading `@` filenames. - Bash completion also preserves colon-separated filename prefixes and Readline's replacement suffix. - Interactive uploads show returned values and a safely quoted, read-only metadata command. - Suggestions reuse the executable or development checkout, including `go run` and `scripts/run`. - Suggested commands preserve the selected project, organization, and safe base URL. Sensitive overrides suppress the suggestion. - Error-output options leave successful upload receipts unchanged. Processing errors retain complete details through JSON inspection. - Malformed known receipt fields use complete response output. Existing null values and large integer timestamps remain supported. - Interactive `get` shows complete metadata, full IDs, and UTC timestamps. - Existing names, flags, machine output, extraction, and download bytes remain available. ### Commands `get` and `download` are new routes. The existing `upload` route gains positional paths. ```sh openai files --help openai files upload "upload space.txt" --purpose user_data openai files get file-example openai files download file-example --output "downloaded copy.txt" openai files download file-example > copy.txt openai files get file-example --format json # complete metadata for scripts cat upload.bin | openai files upload --file - --purpose user_data ``` Use one positional path or `--file PATH`. `create`, `retrieve`, `content`, `-o`, and extraction options remain available. Paths are literal. Quote a leading `@` in PowerShell, or use `./@name`. Reload an existing completion adapter after updating the CLI. Receipts and readable timestamps require terminal stdout and stderr, text/auto output, and no extraction or raw output. `--quiet` suppresses the upload receipt and retains selected metadata. The suggested inspection command never selects a download destination or overwrites the upload source. Keep the same environment when copying it; credentials are never included in suggestions. Development hints retain their checkout with `go -C CHECKOUT run ./cmd/openai`. After an uncertain upload, inspect its known ID or recent same-project files before uploading again. Upload acceptance does not imply processing completion. Streamed uploads do not retry automatically. The [Files recovery guide](https://github.com/openai/openai-cli/blob/bcd5af538bf254c80dd5884a1c1cbbb37389bc96/docs/files.md#recover-from-a-failed-command) gives concrete recovery steps. ### Code `pkg/custom` adds routes, request-context capture, and terminal presentation over existing decorated handlers. `pkg/transformers` formats file timestamps without changing machine data. `internal/autocomplete` opts upload into first-path completion and preserves literal filenames across four shell adapters. `internal/clihelp` keeps fallback example notes out of command-owned examples. Files receipt hints can follow one recognized Go parent through platform process metadata. Unknown callers, lookup errors, cancellation, or unavailable checkout paths omit the optional hint. Image and setup callers keep their existing shell detection. Existing terminal escaping, shell quoting, input handling, save policy, and download code remain in use. No new package, external dependency, generated-source change, or startup change is required against main. ### Tested Candidate: `bcd5af5` against main `866d8770`. Its complete source tree matches tested `48aee722`; the final merge changes ancestry only. Local checks used Go 1.26.9 on macOS arm64 with synthetic loopback APIs. The latest two findings reproduced in eight public processes before correction. Independent review checked `3ae27da` and executed 31 corrected public processes. That matrix covered 24 uploads and seven metadata requests. `go run` and copied hints passed through Bash, zsh, fish, and PowerShell on macOS. `scripts/run` passed in Bash and zsh. An absolute `scripts/run` invocation remained copyable from outside the checkout. Unknown wrappers did not use a misleading SHELL value. Malformed, nullable, omitted, signed, and large fields retained their expected output, including a 17 MiB fallback. At `3ae27da`, custom/transformer checks passed 165 results, public Files/help passed 109, and manpage integration passed 18. None of those runs skipped tests. Windows and Linux custom-package test compilation passed at `3ae27da`. Native ancestry checks remain unverified on those systems. At runtime `10c10cb`, eight independent binary probes passed, including partial-page and receipt-write failures. That composition passed 128 public Files/local-utility results and 14 additional output/routing results. The custom run passed 193 results; five unavailable-shell checks passed after adding the existing cached shells to PATH. That focused rerun passed 29 results without skips. Go module verification passed. The trusted budget passed with 21/1000 custom lines against current main `866d8770`. Earlier focused vet passed at `3ae27da`. Earlier Bash completion coverage passed 74 results at `520dc58`; the completion source remains unchanged. The earlier three findings retain their separately recorded before/after and context/byte-preservation evidence. The previous published head `ae2ad9e` passed hosted tests, builds, platform help, permissions, cancellation, and baseline checks. See the [CI run](https://github.com/openai/openai-cli/actions/runs/37907274504) and [platform help run](https://github.com/openai/openai-cli/actions/runs/37907274438). Current-head CI will run after publication and retargeting to main. At `48aee722`, the final table-policy update passed 55 focused results and seven public Files results, with zero skips. Independent review confirms all 44 Files feature files remain unchanged through the parent update and final main alignment. Live API acceptance and native Windows Files workflows remain unverified. PowerShell execution on macOS does not establish Windows filesystem behavior. The inherited save policy stages explicit ordinary downloads and reports successful saves on stderr. Quiet and structured error modes suppress optional save receipts; receipt-write failures return nonzero after retaining completed files. Final local copies remain non-atomic. Redirection and automatic or special destinations can retain partial output. Malformed HTTP 200 metadata can still return success. The guide explains these limits without promising rollback. ### Demo macOS arm64, Bash, Menlo 18px, terminal replay, and a synthetic loopback API. Before: Output production `7901147`. After: Files `2d482e3`. The recorded ordinary workflow remains unchanged in this candidate. Separate public-process checks cover the later development-launcher and malformed-response corrections. Workflow uses 110×46 cells; discovery uses 110×54 cells. The workflow verifies twelve requests and eight exact text/binary download comparisons.  Before:  After:  Command discovery verifies workflow ordering, runnable examples, and zero API requests.  Before:  After:  [Recording recipes](https://github.com/openai/openai-cli/blob/2d482e3f62adf109bca5dfbb8bee6565c277701e/scripts/demos/files-workflow/README.md).
Forced color could put ANSI escapes into piped JSON. Structured streams could also wait for another event before printing.
This keeps piped results undecorated and emits stream events promptly.
Quiet and verbose controls cover command setup, API saves, image feedback, and local manpage generation.
What changes
p. Quiet keeps graceful Ctrl+C status 130 and suppresses fallback hints.Commands
The new flags are
--quietand--verbose, grouped under Output in root help.Quiet overrides verbose.
-vstill means version.The default remains readable text, including pipes. A destination filename does not select a format.
JSON lists still emit independent values. This change introduces no arrays, JSON/raw aliases, or CI output mode.
Explicit explore retains terminal interaction in CI. Quiet does not disable requested interaction.
--debugremains a separate troubleshooting control.Manpage formats and filenames stay the same. Disabling both formats creates no files and emits no save receipt.
Code
pkg/customowns feedback policy, human errors, image orchestration, and local manpage file completion.main.gowraps the existing request-configuration runner so verbose reporting includes setup and cleanup failures.The manpage action retains generated flags and uses the existing document renderer through the existing flattened command view.
One private helper finishes compression and closes each file before the shared receipt.
Future generated manpage flag or output changes require compatibility review with this local action.
Models selection/viewer hooks and Images stop/stage callbacks remain intact.
Output and binary receipts reuse the same diagnostic predicate. Transformers remain unchanged against main.
This adds no package or dependency and does not change generated sources.
Tested
Candidate:
44f7564against main217ff2ea, including merged Tokenizer #386.Independent adversarial review approved the committed source and its focused evidence.
Focused custom, public, and race checks pass without skips.
These include 45 new cases for local utility data, quiet/verbose, machine errors, offline startup, and private helper protocols.
Manpage checks include the new public commands and exclude both private helpers.
Build, focused vet, module verification, and trusted local budget checks pass. The budget remains 21/1000 lines.
At
68a3e87, a macOS native comparison reproduced 77 unwanted stderr bytes after Tokenizer SIGHUP.The corrected binary passed all five signal cases, preserving statuses 129/130/143, terminal bytes, restoration, and helper cleanup.
Both focused hangup tests fail before the correction and pass afterward.
These signal checks use drained output; native Linux/Windows editor behavior remains outside this probe.
The table-hint follow-up passes 42 parsed-policy cases, preserving exact table/fallback data and metadata.
Fifteen cases fail before the correction. Focused rendering/navigation/Models checks, race checks, and vet pass afterward.
Those tests exercise the dormant renderer; current generated Files/Batches/Projects commands still use their existing iterator path.
Earlier API, large-payload, binary-save, Models, Images, and manpage evidence retains its recorded source identities.
Current native checks pass on macOS, Linux, and Windows at
44f7564.Each platform passes all 45 utility composition cases and 16 manpage cases; required shells also pass.
Windows passes all eight console lifecycle cases. Optional and platform-specific skips remain documented.
Full tests and artifacts, CodeQL, and the trusted budget check pass at the same head.
Automatic code and security reviews completed. No new public automated findings appeared after the corrections.
Broader graphics appearance remains outside this scoped validation.
Demo
The retained demo compares real CLI binaries against a synthetic loopback API on macOS.
Before uses
da762ff; After usesaf738605.It shows piped JSON parsing, event timing, quiet data preservation, and verbose stderr separation.
Current integration checks cover Models, Images, Shell, manpages, and Tokenizer.
The Tokenizer signal correction preserves identical terminal content and removes the unwanted stderr report.
The capture validator checked exact bytes, request counts, event timing, and all process statuses.
The terminal replay uses Menlo on macOS. Separate quality captures cover 40 and 100 columns.
The manpage compatibility checks compare complete generated files and stdout/stderr separately.
Before:
After:
Recording recipe.
Current output contract.
Recordings remain outside Git.