Skip to content

Let Codex inspect vault files during multi-agent answers - #3377

Open
logancyang wants to merge 3 commits into
masterfrom
codex/3376-codex-fanout-vault-read
Open

logancyang wants to merge 3 commits into
masterfrom
codex/3376-codex-fanout-vault-read

Conversation

@logancyang

@logancyang logancyang commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Relates to #3376

Why

In multi-agent answers, Codex sometimes says it cannot see the vault while another agent can list its files. The same Codex setup can read those files in a regular chat. The multi-agent instructions told agents not to use shell tools, which is how Codex inspects local files.

What

Before: Asked to identify a file at the vault root in a multi-agent answer, Codex could decline to inspect it.

After: Codex is told it may use read-only shell commands to list, read, and search vault files. The instruction still forbids edits and state-changing commands.

Non goal

This does not change backend permissions or add a security sandbox. Multi-agent research remains advisory read-only guidance.

Screenshot

No visual change; this changes instructions sent to agents.

Risk

High

Criterion Status Reason
No behavior change, or a cosmetic/copy/docs/config change visible where it renders, or deterministic tests cover the changed behavior ❌ A test checks the instruction, but Codex's response to it is nondeterministic.
A defect would fail CI or be obvious on first use ❌ CI catches wording regressions, but an agent may still decline to inspect files.
A revert fully restores prior state, including persisted data ✅ No stored data or migration changes.
No auth, permissions, secrets, or input-handling surface changes ❌ The instruction now encourages read-only shell use; permission handling itself is unchanged.
No public API, plugin API, message, or on-disk contract changes ✅ The change is limited to the internal multi-agent instruction.
No core-path concurrency, async-lifecycle, or state-machine changes ✅ Dispatch and session lifecycle are unchanged.
No hot-path behavior lacks deterministic coverage ❌ The instruction is tested, but third-party agent tool choice cannot be determined in CI.
No new dependency ✅ Dependency manifests are unchanged.
Human-only behavior stays in one feature area and surfaces quickly ✅ A vault listing request exposes the result in the next multi-agent answer.

Review: inspect FANOUT_READONLY_PREAMBLE in src/agentMode/session/fanout/fanoutTypes.ts and its regression test in src/agentMode/session/fanout/fanoutTypes.test.ts line by line. Then run Verification steps 2–3, including the attempted write.

Verification

  1. Load this branch in a disposable Obsidian test vault with Codex available, then select Codex alongside another agent in multi-agent chat.
  2. Ask both agents to identify a file at the vault root from direct inspection. Codex should name an actual entry rather than say it cannot access the filesystem.
  3. Ask the agents to create a note in that test vault. They should decline, and the vault should remain unchanged.

Note

Blocked for merge: The live Obsidian test confirmed that Codex lists vault files, but review found that Codex ACP 1.13.0's read-only mode still permits workspace writes. This draft needs an enforced read-only boundary before it is safe to ship. See the inline review thread for the finding.

@vercel

vercel Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
obsidian-copilot-docs Ignored Ignored Sep 28, 2026 6:09am UTC

Request Review

@logancyang

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T06:13:00.982933Z 4cee20f New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6c14115eb0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +21 to +22
"commands that change state, or use write tools. You may use read-only " +
"shell commands to list directories, read files, search, and grep. " +

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Put shell inspection behind a real read-only boundary

When an agent follows this new instruction and emits a shell command, the fan-out gate auto-allows every execute tool call without inspecting the command; Claude classifies Bash as execute, while Codex's advertised read-only mode explicitly still permits workspace edits. Consequently, if an agent emits something like echo ... > note.md or rm note.md—whether due to the user request, vault instructions, or model error—it runs without a permission card and can alter the vault, and shell reads also bypass VaultClient's out-of-vault and hidden-file checks. Prompt wording alone cannot preserve the feature's read-only contract, so shell use should only be advertised after commands are constrained by an actual read-only filesystem boundary.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed. In codex-acp 1.13.0, the advertised read-only mode still uses a writable workspace sandbox. A real Obsidian multi-agent run also showed Codex executing a shell listing. I’m treating this as a blocker and keeping the PR draft while I replace the shell path with an enforceable read-only boundary.

@logancyang
logancyang marked this pull request as ready for review September 27, 2026 00:19

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant