OctoLink GEO

Codex 0.162.0 Adds Managed Worktrees and Tightens the Linux Sandbox

Author Editor

The 8 October 2026 release adds Git worktree tools for trusted local projects and rejects writable sandbox-construction executables.

Harness Engineering Codex Sandbox

Direct answer

Codex rust-v0.162.0, published 8 October 2026, adds tools to create and list managed Git worktrees from trusted local projects when that feature is enabled, and it rejects writable executables used to construct the sandbox.

Codex rust-v0.162.0 was published on 8 October 2026 at 18:55:59Z. The first new feature adds tools for creating and listing managed Git worktrees from trusted local projects, and only when the worktrees feature is enabled. The notes attach that work to pull request 50148. A worktree is a second checkout of the same repository. Putting it behind a feature flag and a trusted-project check is the harness boundary: the tool is not offered for every folder the process can see.

The bug-fix section tightens the Linux sandbox in the same release. It says startup is fixed when several files are denied, writable executables used to construct the sandbox are rejected, and ripgrep configuration is kept from weakening deny-glob masks. Those items are listed as pull requests 50059, 51211, 51407, and 51527. A writable helper that builds the sandbox is a different risk from a denied path inside it. The note says that class of executable is rejected.

Line endings and retry timing

apply_patch now preserves existing CRLF line endings without an opt-in, in pull request 51203. Retryable Responses and WebSocket failures honor the server Retry-After header, in pull requests 50418 and 51440. The compare range on the page is rust-v0.161.0 to rust-v0.162.0.

Source: Codex rust-v0.162.0.

FAQ

Does apply_patch still rewrite CRLF files?
The notes say existing CRLF line endings are preserved in apply_patch updates, and that this no longer requires an opt-in.
Which pull request covers the worktree tools?
The release lists pull request 50148 for creating and listing managed Git worktrees.