Skip to content

fix(images): recover interrupted Kitty previews - #342

Merged
saioai merged 12 commits into
mainfrom
codex/image-native-coverage
Oct 3, 2026
Merged

saioai merged 12 commits into
mainfrom
codex/image-native-coverage

Conversation

@saioai

@saioai saioai commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

For people previewing images in Kitty or Ghostty, Ctrl-C during an image could dump encoded text into the terminal and break the next preview. This stops interrupted output safely, preserves saved images, and keeps repeated picker generations working when an update replaces the CLI.

What changes

  • Own the terminal writer directly so helper crashes cannot leave an orphan writing after cancellation.
  • Prepare two workers before input or API waits. Normal images reuse one; the idle reserve can reset an interrupted transfer even after executable replacement.
  • Wait for active output before returning to text or the picker. Terminate and reap failed writers before recovery, using two-second reset and shutdown deadlines. Preserve ordinary Ctrl-C flushing and terminal settings.
  • Ignore failures from an unused reserve after successful output. Report failures when a worker is actually needed.
  • Keep existing platform support. System cat is no longer required.
  • Honor cancellation before fallback cleanup writes, including partial-frame cleanup, so cancellation cannot start another uncontrolled write.
  • Make CodeQL validate the current PR merge and its parents; its trusted publisher is unchanged.

Commands

No new public commands or flags.

openai images preview --inline on image.png # preview an existing image
openai images generate                    # generate and return to the picker

Inline settings, progress previews, explicit formats, extraction and piped output retain their behavior. Neither #360 nor #361 is required.

Code

pkg/custom owns command and picker lifetime. The existing internal/terminalimage package owns writer processes, cancellation and protocol recovery. Only those isolated workers change their SIGINT disposition. main.go adds early helper dispatch; generated commands and transformers are unchanged. No new packages or module dependencies.

On macOS and Linux, two helpers remain resident during eligible command input and API waits. A failed worker is retired; the command reports the failure and exits after cleanup. Other platforms and custom writers use direct output: cancellation stops additional writes, but cannot interrupt an already blocked writer or guarantee protocol repair. Normal output has no new timeout or payload limit.

Tested

  • Two independent adversarial reviews pass on ee7b882. The fallback hang reproduces before the fix; six independent cancellation cases pass after it. Uncanceled cleanup errors and retry behavior remain covered.
  • 24 focused race-test groups pass on Mac arm64; the same 24 groups pass in native Linux amd64 and 386 processes. Fresh public CLI checks cover helper death, cancellation, saved originals, executable replacement and repeated picker generations.
  • Windows fallback tests compile; hosted shell checks execute on Windows, macOS and Linux. Other architecture checks are compilation only. Earlier Linux amd64 typed Ctrl-C trials passed 20/20 on the unchanged native worker implementation.
  • CI, native shell help and CodeQL all pass on ee7b882, including artifact builds, tests and native shell checks. The trusted main budget passes at 435/1000.

The scoped native Ghostty capture and two independent visual reviews pass. Mac Kitty and Windows native graphics remain unverified; the full platform campaign remains deferred. Required SDK CODEOWNER approval remains outstanding.

Demo

Ghostty 1.3.1 on macOS 26.6.2 arm64, using live CLI output and synthetic local PNGs. Before is current main 759464e; after is final commit ee7b882. Two independent reviewers checked all eight original screenshots, raw output, unchanged image pixels and process cleanup. Picker return has separate PTY coverage.

No GIF was recorded. These are unmodified native screenshots.

Before: Ctrl-C spills encoded text; the next preview fails to render.

Before cancellation

After: cancellation leaves readable text and preserves the earlier image.

After cancellation

After retry: the new image renders and the earlier image remains.

After retry

Native evidence and reproducible recipe, capture run, helper lifecycle regression, picker and executable replacement recipe.

@saioai
saioai requested a review from HAYDEN-OAI September 30, 2026 21:19
@saioai

saioai commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T21:29:33.258080Z ee7b882 Draft marked ready
🔒 Security Review ✅ Completed 2026-10-03T21:27:35.419241Z ee7b882 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Bravo.

Reviewed commit: bdb3fa1fee

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@saioai
saioai removed the request for review from HAYDEN-OAI September 30, 2026 21:22
@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: bdb3fa1fee

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Castiron custom code

Evaluated main: 759464ea24c4cd86b6803c31361b83f43dfed3b9.

✅ No new custom-code files detected.

6 mixed files remain; 0 existing customizations changed.

Compared 759464ea24c4 → ee7b882fb738. Generated baselines verified.

6 existing customizations unchanged
  • pkg/cmd/adminorganizationcertificate.go
  • pkg/cmd/audiovoice.go
  • pkg/cmd/image.go
  • scripts/castiron/README.md
  • scripts/castiron/custom_code_report.py
  • scripts/castiron/test_custom_code_report.py

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37155025937 --repo openai/openai-cli \
  --name castiron-custom-code-37155025937-1 --dir /tmp/castiron-custom-code-37155025937-1
git apply --stat /tmp/castiron-custom-code-37155025937-1/custom-code.patch
cat /tmp/castiron-custom-code-37155025937-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 759464ea24c4cd86b6803c31361b83f43dfed3b9 ee7b882fb738589c5ecaf354071c72d8993ab941
python3 scripts/castiron/custom_code_report.py report \
  --base 759464ea24c4cd86b6803c31361b83f43dfed3b9 \
  --head ee7b882fb738589c5ecaf354071c72d8993ab941 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-ee7b882fb738
cat /tmp/castiron-custom-code-ee7b882fb738/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@saioai
saioai force-pushed the codex/image-native-coverage branch from 35fa12c to 9321b76 Compare October 1, 2026 02:10
@saioai saioai closed this Oct 1, 2026
@saioai saioai reopened this Oct 1, 2026
Comment thread scripts/check-image-output-lifecycle.py Fixed
Comment thread scripts/check-image-output-lifecycle.py Fixed
@saioai
saioai marked this pull request as ready for review October 3, 2026 21:01
@saioai
saioai requested a review from a team as a code owner October 3, 2026 21:01

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 98e832772f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/terminalimage/image.go Outdated
@saioai
saioai marked this pull request as draft October 3, 2026 21:11
@saioai
saioai marked this pull request as ready for review October 3, 2026 21:24

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed ee7b882fb738589c5ecaf354071c72d8993ab941. No blocking findings in behavior or code structure.

The command owns its workers across input and API waits. Cancellation kills and reaps the active writer before the reset attempt. The picker reuses those workers after executable replacement. Fallback cleanup now honors cancellation. CodeQL still checks that published results belong to the current commit.

Verified passing CI, native shell help, and CodeQL checks on this head. I read the regression tests but did not run tests or builds locally. I did not independently verify native graphics in Kitty, Ghostty, or Windows terminals.

@saioai
saioai added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit b6895bd Oct 3, 2026
26 checks passed
@saioai
saioai deleted the codex/image-native-coverage branch October 3, 2026 23:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants