← Back to Payloads
AI News2026-09-29

OpenAI Codex rust-v0.159.0 (Sep 29): Opt-in `instant_interrupt` Live-Steering, Mermaid Edge Expansion, and `.aws` Protected by Default

OpenAI shipped rust-v0.159.0 with opt-in `instant_interrupt` (preempt in-flight Codex turns on new user input), app-server thread-history pagination, Mermaid edge expansion, and `.aws` directory protection under sandbox writable roots by default.

OpenAI Codex rust-v0.159.0 (Sep 29): Opt-in instant_interrupt Live-Steering, Mermaid Edge Expansion, and .aws Protected by Default

Originally published: 2026-09-29 14:08 UTC / 16:08 Berlin / 10:08 EDT

What Happened

OpenAI shipped rust-v0.159.0 as a stable Codex CLI release on September 29, 2026. The headline is an opt-in capability called instant_interrupt that lets a new user message steer Codex while a response is in progress or while a long-running code-mode call is executing. The release also expands native Mermaid rendering, hardens Windows / macOS / Linux launch paths, adds app-server paginated thread history, and protects .aws directories under sandbox-writable roots by default.

This report is a documentation comparison against the v0.159.0 release notes and the Codex config docs. No firsthand API call was made.

What Actually Changed

Opt-in instant_interrupt (PRs #48135, #48141). The setting — shipped behind an opt-in flag, not on by default — adds code-mode yielding on new user input. When you send a message while a Codex turn is mid-flight, Codex now preempts the in-progress model response (or the running code-mode call) instead of queueing your message until the current step finishes. PR #48141 ("Preempt model responses when new user input arrives") is the wire-side change; PR #48135 is the executor change.

App-server thread-history pagination (PR #48151). App-server clients can now anchor thread-history pagination to a specific item. Downstream UIs and IDE integrations that pull transcripts no longer have to page from the start.

TUI refresh. New sessions get a compact welcome screen and consistent borderless headers (PRs #48513, #48562, #48352), turn tips show during and after work, the warnings viewer dismisses reviewed warnings on close and lets you press k to keep one for later (PRs #48205, #48206), and you can scroll the transcript while deciding whether to implement a plan (PR #48805).

Native Mermaid (PRs #48814, #48895, #48489). More flowchart edges, labels, and node groups render in the TUI; shape, relationship, and state-description parsing is fixed.

Sandbox / host fixes worth surfacing:

  • .aws directories are now protected by default under sandbox-writable roots (PR #48176) — closes an obvious credential-exfiltration path through writable-root whitelists.
  • macOS TLS trust evaluation works in network-enabled Seatbelt profiles and remote environments that require proxy access (PRs #48565, #48198).
  • Windows launches no longer spawn stray console windows for MCP servers, code-mode hosts, and piped commands; restrictive launchers fall back to embedded mode (PRs #48138, #48238, #48483, #48491).

TUI copy quality (PRs #48548, #48549, #48469). Copying transcript selections now preserves Markdown tables, formatting, and significant whitespace. More terminals auto-copy on selection.

Durability and lifecycle. Blank sessions retain drafts when switching tasks; threads can be archived and listed before their first turn (PRs #48628, #48828, #48199). Approved commands retain explicit filesystem denials (PR #48155). ChatGPT local sign-in opens the browser reliably; onboarding provides a shortcut to copy the login link (PRs #48502, #48544). Local ChatGPT sign-in opens the browser reliably; onboarding also provides a shortcut to copy the login link.

Chores that matter.

  • tui.prompt_suggestions setting and the auto follow-up prompt suggestions are removed (PR #48621).
  • The bundled plugin-creator skill is removed (PR #48604).

Full Changelog (compare base): rust-v0.158.0...rust-v0.159.0.

Why Developers and Founders Should Care

instant_interrupt is the change that affects your day-to-day. Codex turns previously could lock for tens of seconds while a long tool call ran; sending a corrective message in that window just enqueued, so a typo or a "stop, switch approach" usually cost you a wasted cycle. With the opt-in setting on, a fresh user message will preempt the in-flight response and steer the next step. This is the kind of capability that matters most on the autonomous-agent side of the desk: long code-mode sweeps, multi-step refactors, and overnight batch runs are the places where "I want to redirect now" beats "I want to wait 90 seconds and then redirect."

The .aws default-protection is the second change worth pulling out. Anyone running Codex against an AWS-backed stack used to have to remember to add .aws to the explicit-deny list; missing that turn meant any writable-root whitelist could swallow your credentials directory. That is now the safe default.

Evidence and Test Results

All claims above are quoted or paraphrased from the v0.159.0 release notes, which lists the high-level changes, and from the linked PR descriptions. The full PR list (80+ entries) is in the compare view. No first-hand API call was run for this report; the changelog text and PR descriptions are the documentation sources.

Verification level: documentation comparison. The PR list is on GitHub; the high-level changelog text is the Markdown body of the GitHub release. We did not pull down the binary, exercise instant_interrupt against a live model, or audit which exact prompt-prefix invalidations still hold once the preemption path is wired up. If you depend on those answers, run the release against your regression suite before shipping it as a default for autonomous workers.

Cost, Risk, and Limitations

  • instant_interrupt is opt-in, not default. If you want the new behavior, you have to enable it. If you rely on turn-by-turn durability (no mid-turn redirects), leaving the default off keeps the old "queue until current step finishes" semantics. Either way, enable deliberately and document the choice in your internal agent config.
  • Preemption cost is unstated. The changelog does not document whether the preempted partial response is billed, partially billed, or discarded. For interactive use this is irrelevant; for batched autonomous work where you sometimes inject steering messages mid-run, expect to test your provider bill before assuming zero cost for preempted tokens.
  • .aws protection is now the default — but only under "writable roots." If your sandbox config does not list your working tree as a writable root, this change does not affect you. If you have an unusually permissive writable-root list, this change closes one path but you should still audit the rest.
  • Bundled plugin-creator skill is removed. If your team's onboarding docs reference the in-tree plugin-creator skill, update them. Plugins still work — you just author them yourself or pull them from a marketplace.
  • Auto follow-up prompt suggestions are gone. Anyone who scripted their workflow to skip the suggestions UI needs to remove that step. The relevant setting (tui.prompt_suggestions) was removed alongside the behavior.

Mr. Technology Verdict

This is a quality-of-life and safety release with one capability drop that matters: instant_interrupt. It is not a marketing-grade "AI now does X" headline — it is a wire-protocol change that turns a class of wasted autonomous-agent turns into actually-correctable mid-run turns. Combined with the .aws default protection, the Mermaid edge expansion, and the app-server thread-history pagination, v0.159.0 is a release that the long-running-agent side of the Codex audience should adopt on the next maintenance window.

Recommended Action

1. Read the v0.159.0 high-level changelog and skim the 80-PR diff against your last stable version. 2. If you run autonomous-agent Codex workers, decide deliberately whether to turn instant_interrupt on or leave it off. Document the choice in your internal agent config. 3. If you run Codex on Windows or in restricted launchers, validate the embedded-mode fallback against your launcher policy before promoting the version. 4. Update internal onboarding docs to drop references to the bundled plugin-creator skill and tui.prompt_suggestions. 5. Re-run your prompt-cache invalidation tests — the preemption path touches executor / TUI credential boundary preservation (PR #48143) and your test suite should cover that.

Sources

Last verified: 2026-09-29 14:08 UTC. No corrections on file.

Related Dispatches