feat(cli): save picker shortcuts for future shell sessions - #360
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsAdvisory findings (3)
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b1a062578e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d067361335
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c49d503e05
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: c49d503e05
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cd53e42046
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f8806ea69c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: 52f57372ae
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
52f5737 to
2902f6a
Compare
2902f6a to
a9b8ba4
Compare
Castiron custom codeEvaluated main: ✅ No new custom-code files detected. 6 mixed files remain; 0 existing customizations changed. Compared 6 existing customizations unchanged
A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 37158280329 --repo openai/openai-cli \
--name castiron-custom-code-37158280329-1 --dir /tmp/castiron-custom-code-37158280329-1
git apply --stat /tmp/castiron-custom-code-37158280329-1/custom-code.patch
cat /tmp/castiron-custom-code-37158280329-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin 759464ea24c4cd86b6803c31361b83f43dfed3b9 3cca018ef2a7fe9edd9612a52894da2e43c3a90d
python3 scripts/castiron/custom_code_report.py report \
--base 759464ea24c4cd86b6803c31361b83f43dfed3b9 \
--head 3cca018ef2a7fe9edd9612a52894da2e43c3a90d --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-3cca018ef2a7
cat /tmp/castiron-custom-code-3cca018ef2a7/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a9b8ba4b9a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: 70b461f94a
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 70b461f94a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 75973eef7a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed 75973eef7a3f2e84dbff5059d2e9c1a0bd38d0bd. One new P2 needs a fix: macOS setup can reinstall the shortcut after another process removes it. The setup locks do not match the shared opt-out file; see the inline comment.
The existing Unix profile alias and unexported ZDOTDIR findings also remain on this head. A symlink in a parent directory can change the profile hash without changing the actual profile. This blocks refresh and removal. An unexported ZDOTDIR sends default setup to a startup file the shell does not read. Please address both cases and add regression coverage.
Validation: immutable source review and hosted CI for this head. The test, build, lint, macOS and Windows jobs passed. I did not run local tests or builds.
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 316f7886c7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0979028da9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0709518f0d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 22361d6d6c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
For people previewing images in Kitty or Ghostty, Ctrl-C during an image could dump encoded text into the terminal and break the next preview. This stops interrupted output safely, preserves saved images, and keeps repeated picker generations working when an update replaces the CLI. ### What changes - Own the terminal writer directly so helper crashes cannot leave an orphan writing after cancellation. - Prepare two workers before input or API waits. Normal images reuse one; the idle reserve can reset an interrupted transfer even after executable replacement. - Wait for active output before returning to text or the picker. Terminate and reap failed writers before recovery, using two-second reset and shutdown deadlines. Preserve ordinary Ctrl-C flushing and terminal settings. - Ignore failures from an unused reserve after successful output. Report failures when a worker is actually needed. - Keep existing platform support. System `cat` is no longer required. - Honor cancellation before fallback cleanup writes, including partial-frame cleanup, so cancellation cannot start another uncontrolled write. - Make CodeQL validate the current PR merge and its parents; its trusted publisher is unchanged. ### Commands No new public commands or flags. ```sh openai images preview --inline on image.png # preview an existing image openai images generate # generate and return to the picker ``` Inline settings, progress previews, explicit formats, extraction and piped output retain their behavior. Neither openai#360 nor openai#361 is required. ### Code `pkg/custom` owns command and picker lifetime. The existing `internal/terminalimage` package owns writer processes, cancellation and protocol recovery. Only those isolated workers change their SIGINT disposition. `main.go` adds early helper dispatch; generated commands and transformers are unchanged. No new packages or module dependencies. On macOS and Linux, two helpers remain resident during eligible command input and API waits. A failed worker is retired; the command reports the failure and exits after cleanup. Other platforms and custom writers use direct output: cancellation stops additional writes, but cannot interrupt an already blocked writer or guarantee protocol repair. Normal output has no new timeout or payload limit. ### Tested - Two independent adversarial reviews pass on `ee7b882`. The fallback hang reproduces before the fix; six independent cancellation cases pass after it. Uncanceled cleanup errors and retry behavior remain covered. - 24 focused race-test groups pass on Mac arm64; the same 24 groups pass in native Linux amd64 and 386 processes. Fresh public CLI checks cover helper death, cancellation, saved originals, executable replacement and repeated picker generations. - Windows fallback tests compile; hosted shell checks execute on Windows, macOS and Linux. Other architecture checks are compilation only. Earlier Linux amd64 typed Ctrl-C trials passed 20/20 on the unchanged native worker implementation. - [CI](https://github.com/openai/openai-cli/actions/runs/37154504298), [native shell help](https://github.com/openai/openai-cli/actions/runs/37154504215) and [CodeQL](https://github.com/openai/openai-cli/actions/runs/37154504325) all pass on `ee7b882`, including artifact builds, tests and native shell checks. The [trusted main budget](https://github.com/openai/openai-cli/actions/runs/37154525348) passes at 435/1000. The scoped native Ghostty capture and two independent visual reviews pass. Mac Kitty and Windows native graphics remain unverified; the full platform campaign remains deferred. Required SDK CODEOWNER approval remains outstanding. ### Demo Ghostty 1.3.1 on macOS 26.6.2 arm64, using live CLI output and synthetic local PNGs. Before is current main `759464e`; after is final commit `ee7b882`. Two independent reviewers checked all eight original screenshots, raw output, unchanged image pixels and process cleanup. Picker return has separate PTY coverage. No GIF was recorded. These are unmodified native screenshots. Before: Ctrl-C spills encoded text; the next preview fails to render.  After: cancellation leaves readable text and preserves the earlier image.  After retry: the new image renders and the earlier image remains.  [Native evidence and reproducible recipe](https://github.com/user-attachments/files/33012233/pr342-ghostty-ee7b882-proof.zip), [capture run](https://github.com/openai/openai-cli/actions/runs/37154549218), [helper lifecycle regression](https://github.com/openai/openai-cli/blob/ee7b882fb738589c5ecaf354071c72d8993ab941/scripts/check-image-output-lifecycle.py), [picker and executable replacement recipe](https://github.com/openai/openai-cli/blob/ee7b882fb738589c5ecaf354071c72d8993ab941/scripts/check-image-picker-native.py).
Automated Release PR --- ## [1.36.0](openai/openai-cli@v1.35.0...v1.36.0) (2026-10-03) ### Features * **cli:** save picker shortcuts for future shell sessions ([openai#360](openai#360)) ([814316e](openai@814316e)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
The Tab shortcut previously needed activation in each shell session. This saves it for future Bash, zsh and fish sessions, with explicit removal and quiet first-use setup when the terminal and profile are eligible.
What changes
.openai/shell, independently of XDG or AppData changes. Valid older preferences in the current root migrate there.--pickerremain available.ZDOTDIRfor default zsh targeting; otherwise use an explicit profile. Automatic setup skips ambiguous zsh locations. PowerShell retains ordinary Tab completion and Enter access to the picker.Commands
The existing
@completioncommand gains setup options:Run the zsh examples in zsh so it expands its own startup location, including unexported
ZDOTDIR. Bash and fish accept installation/removal without--profile. Omitted shell uses the immediate parent for explicit setup. On Windows, default targeting requiresHOMEto identify the native user home; otherwise use--profile. Bash's Tab shortcut needs 4.3 or later; Enter remains available in Bash 3.2. Open a new terminal after setup. Setup guide.Code
Built on merged #358 and #359, rebased onto main
759464e.pkg/customowns eligibility, profile selection, flags and consent.internal/autocompleteowns scripts, locks, profile transactions and metadata checks. Existing shell detection, rendering and private state helpers are reused. Main adds first-use wiring and exempts actual local setup actions from API configuration initialization. Generated commands, dependencies and packaging are unchanged.Tested
At
6ee29f3, 572 focused race test/subtest results, 58 public command results and 22 independent CLI probes pass. Recovery regressions cover late atomic and in-place editor saves, held file handles, process exit after capture, competing publication, cancellation, failed completion recording, 32-copy capacity, ambiguous profile aliases, and independent pending captures. The installed-profile recipe passes in Bash 5.3, zsh, fish 4.9.3 and Bash 3.2 fallback. One local case-sensitive-volume test skips on this macOS filesystem.All packages compile, native vet and Windows test compilation pass. Module verification and the trusted-main custom-code budget pass. All 21 hosted checks pass at final head
3cca018, with two expected skips. Native Windows passes 474 results with 20 platform skips; native macOS passes 524 results with 19 environment skips. All recovery and Windows editor denial/retry cases pass. The full Linux suite, artifact build, lint, CodeQL and native help checks pass. Automated code and security reviews completed without new findings; all review threads are resolved. The test-only follow-up has 40 fresh local recovery results and an independent 62-result review; runtime source is unchanged from6ee29f3. Synthetic SELinux label/error tests pass; the native Linux SELinux lifecycle check skips because the runner assigns no labels, and an enforcing SELinux host has not been tested. Special-mode checks run outside the sandbox because it strips fixture bits. All profile writes use synthetic temporary locations.Older unguarded fish scripts need one refresh in their original root to honor the new opt-out. An unknown historical preference root must be selected once for migration. Actual stalled network filesystems and the full platform/package-manager campaign remain untested. Already-issued filesystem operations may finish after the foreground timeout; unprovably owned files are retained. Windows junction/reparse ancestry requires manual setup.
Demo
macOS arm64, native zsh in a synthetic PTY, base
562318dto candidate1000ca7. Installation writes only a temporary test profile; a new zsh reads it and Tab opens the picker. No real profile or API request. This recording demonstrates the original setup flow; the follow-up lifecycle fixes are covered by the checks above.Before:
After:
Recording recipe and original captures, using the shared capture/render workflow. Native shell regression recipe.