Encrypt multi-agent v2 message payloads (#26210)

## Why

Multi-agent v2 currently routes agent instructions through normal tool
arguments and inter-agent context. That means the parent model can emit
plaintext task text, Codex can persist it in history/rollouts, and the
recipient can receive it as ordinary assistant-message JSON.

This changes the v2 path so agent instructions stay encrypted between
model calls: Responses encrypts the `message` argument returned by the
model, Codex forwards only that ciphertext, and Responses decrypts it
internally for the recipient model.

## What changed

- Mark the v2 `message` parameter as encrypted for `spawn_agent`,
`send_message`, and `followup_task`.
- Treat multi-agent v2 tool `message` values as ciphertext
unconditionally.
- Store v2 inter-agent task text in
`InterAgentCommunication.encrypted_content` with empty plaintext
`content`.
- Convert encrypted inter-agent communications into the Responses
`agent_message` input item before sending the child request.
- Preserve `agent_message` items across history, rollout, compaction,
telemetry, and app-server schema paths.
- Leave multi-agent v1 unchanged.

## Message shape

The model still calls the v2 tools with a `message` argument, but that
value is now ciphertext:

```json
{
  "name": "spawn_agent",
  "arguments": {
    "task_name": "worker",
    "message": "<ciphertext>"
  }
}
```

Codex stores the task as encrypted inter-agent communication:

```json
{
  "author": "/root",
  "recipient": "/root/worker",
  "content": "",
  "encrypted_content": "<ciphertext>",
  "trigger_turn": true
}
```

When Codex builds the recipient request, it forwards the ciphertext
using the new Responses input item:

```json
{
  "type": "agent_message",
  "author": "/root",
  "recipient": "/root/worker",
  "content": [
    {
      "type": "encrypted_content",
      "encrypted_content": "<ciphertext>"
    }
  ]
}
```

Responses decrypts that item internally for the recipient model.

## Context impact

- Parent context no longer carries plaintext v2 agent task instructions
from these tool arguments.
- Codex rollout/history stores ciphertext for v2 agent instructions.
- Recipient requests receive an `agent_message` item instead of
assistant commentary JSON for encrypted task delivery.
- Plaintext completion/status notifications are still plaintext because
they are Codex-generated status messages, not encrypted model tool
arguments.

## Validation

- `just test -p codex-tools`
- `just test -p codex-protocol`
- `just test -p codex-rollout`
- `just test -p codex-rollout-trace`
- `just test -p codex-otel`
- `just write-app-server-schema`
This commit is contained in:
jif
2026-06-05 10:25:57 +02:00
committed by GitHub
parent 6a6a5f925e
commit 5f4d06ef18
34 changed files with 674 additions and 59 deletions
@@ -34,6 +34,30 @@
],
"type": "string"
},
"AgentMessageInputContent": {
"oneOf": [
{
"properties": {
"encrypted_content": {
"type": "string"
},
"type": {
"enum": [
"encrypted_content"
],
"title": "EncryptedContentAgentMessageInputContentType",
"type": "string"
}
},
"required": [
"encrypted_content",
"type"
],
"title": "EncryptedContentAgentMessageInputContent",
"type": "object"
}
]
},
"ApprovalsReviewer": {
"description": "Configures who approval requests are routed to for review. Examples include sandbox escapes, blocked network access, MCP approval prompts, and ARC escalations. Defaults to `user`. `auto_review` uses a carefully prompted subagent to gather relevant context and apply a risk-based decision framework before approving or denying the request. The legacy value `guardian_subagent` is accepted for compatibility.",
"enum": [
@@ -2120,6 +2144,37 @@
"title": "MessageResponseItem",
"type": "object"
},
{
"properties": {
"author": {
"type": "string"
},
"content": {
"items": {
"$ref": "#/definitions/AgentMessageInputContent"
},
"type": "array"
},
"recipient": {
"type": "string"
},
"type": {
"enum": [
"agent_message"
],
"title": "AgentMessageResponseItemType",
"type": "string"
}
},
"required": [
"author",
"content",
"recipient",
"type"
],
"title": "AgentMessageResponseItem",
"type": "object"
},
{
"properties": {
"content": {
@@ -288,8 +288,8 @@
"environmentId": {
"default": null,
"type": [
"null",
"string"
"string",
"null"
]
},
"itemId": {
@@ -326,4 +326,4 @@
],
"title": "PermissionsRequestApprovalParams",
"type": "object"
}
}
+3 -3
View File
@@ -1593,8 +1593,8 @@
"environmentId": {
"default": null,
"type": [
"null",
"string"
"string",
"null"
]
},
"itemId": {
@@ -2005,4 +2005,4 @@
}
],
"title": "ServerRequest"
}
}
@@ -5900,6 +5900,30 @@
"title": "AgentMessageDeltaNotification",
"type": "object"
},
"AgentMessageInputContent": {
"oneOf": [
{
"properties": {
"encrypted_content": {
"type": "string"
},
"type": {
"enum": [
"encrypted_content"
],
"title": "EncryptedContentAgentMessageInputContentType",
"type": "string"
}
},
"required": [
"encrypted_content",
"type"
],
"title": "EncryptedContentAgentMessageInputContent",
"type": "object"
}
]
},
"AgentPath": {
"type": "string"
},
@@ -14050,6 +14074,37 @@
"title": "MessageResponseItem",
"type": "object"
},
{
"properties": {
"author": {
"type": "string"
},
"content": {
"items": {
"$ref": "#/definitions/v2/AgentMessageInputContent"
},
"type": "array"
},
"recipient": {
"type": "string"
},
"type": {
"enum": [
"agent_message"
],
"title": "AgentMessageResponseItemType",
"type": "string"
}
},
"required": [
"author",
"content",
"recipient",
"type"
],
"title": "AgentMessageResponseItem",
"type": "object"
},
{
"properties": {
"content": {
@@ -265,6 +265,30 @@
"title": "AgentMessageDeltaNotification",
"type": "object"
},
"AgentMessageInputContent": {
"oneOf": [
{
"properties": {
"encrypted_content": {
"type": "string"
},
"type": {
"enum": [
"encrypted_content"
],
"title": "EncryptedContentAgentMessageInputContentType",
"type": "string"
}
},
"required": [
"encrypted_content",
"type"
],
"title": "EncryptedContentAgentMessageInputContent",
"type": "object"
}
]
},
"AgentPath": {
"type": "string"
},
@@ -10572,6 +10596,37 @@
"title": "MessageResponseItem",
"type": "object"
},
{
"properties": {
"author": {
"type": "string"
},
"content": {
"items": {
"$ref": "#/definitions/AgentMessageInputContent"
},
"type": "array"
},
"recipient": {
"type": "string"
},
"type": {
"enum": [
"agent_message"
],
"title": "AgentMessageResponseItemType",
"type": "string"
}
},
"required": [
"author",
"content",
"recipient",
"type"
],
"title": "AgentMessageResponseItem",
"type": "object"
},
{
"properties": {
"content": {
@@ -1,6 +1,30 @@
{
"$schema": "http://json-schema.org/draft-07/schema#",
"definitions": {
"AgentMessageInputContent": {
"oneOf": [
{
"properties": {
"encrypted_content": {
"type": "string"
},
"type": {
"enum": [
"encrypted_content"
],
"title": "EncryptedContentAgentMessageInputContentType",
"type": "string"
}
},
"required": [
"encrypted_content",
"type"
],
"title": "EncryptedContentAgentMessageInputContent",
"type": "object"
}
]
},
"ContentItem": {
"oneOf": [
{
@@ -369,6 +393,37 @@
"title": "MessageResponseItem",
"type": "object"
},
{
"properties": {
"author": {
"type": "string"
},
"content": {
"items": {
"$ref": "#/definitions/AgentMessageInputContent"
},
"type": "array"
},
"recipient": {
"type": "string"
},
"type": {
"enum": [
"agent_message"
],
"title": "AgentMessageResponseItemType",
"type": "string"
}
},
"required": [
"author",
"content",
"recipient",
"type"
],
"title": "AgentMessageResponseItem",
"type": "object"
},
{
"properties": {
"content": {
@@ -1,6 +1,30 @@
{
"$schema": "http://json-schema.org/draft-07/schema#",
"definitions": {
"AgentMessageInputContent": {
"oneOf": [
{
"properties": {
"encrypted_content": {
"type": "string"
},
"type": {
"enum": [
"encrypted_content"
],
"title": "EncryptedContentAgentMessageInputContentType",
"type": "string"
}
},
"required": [
"encrypted_content",
"type"
],
"title": "EncryptedContentAgentMessageInputContent",
"type": "object"
}
]
},
"ApprovalsReviewer": {
"description": "Configures who approval requests are routed to for review. Examples include sandbox escapes, blocked network access, MCP approval prompts, and ARC escalations. Defaults to `user`. `auto_review` uses a carefully prompted subagent to gather relevant context and apply a risk-based decision framework before approving or denying the request. The legacy value `guardian_subagent` is accepted for compatibility.",
"enum": [
@@ -436,6 +460,37 @@
"title": "MessageResponseItem",
"type": "object"
},
{
"properties": {
"author": {
"type": "string"
},
"content": {
"items": {
"$ref": "#/definitions/AgentMessageInputContent"
},
"type": "array"
},
"recipient": {
"type": "string"
},
"type": {
"enum": [
"agent_message"
],
"title": "AgentMessageResponseItemType",
"type": "string"
}
},
"required": [
"author",
"content",
"recipient",
"type"
],
"title": "AgentMessageResponseItem",
"type": "object"
},
{
"properties": {
"content": {
@@ -0,0 +1,5 @@
// GENERATED CODE! DO NOT MODIFY BY HAND!
// This file was generated by [ts-rs](https://github.com/Aleph-Alpha/ts-rs). Do not edit this file manually.
export type AgentMessageInputContent = { "type": "encrypted_content", encrypted_content: string, };
@@ -1,6 +1,7 @@
// GENERATED CODE! DO NOT MODIFY BY HAND!
// This file was generated by [ts-rs](https://github.com/Aleph-Alpha/ts-rs). Do not edit this file manually.
import type { AgentMessageInputContent } from "./AgentMessageInputContent";
import type { ContentItem } from "./ContentItem";
import type { FunctionCallOutputBody } from "./FunctionCallOutputBody";
import type { LocalShellAction } from "./LocalShellAction";
@@ -10,7 +11,7 @@ import type { ReasoningItemContent } from "./ReasoningItemContent";
import type { ReasoningItemReasoningSummary } from "./ReasoningItemReasoningSummary";
import type { WebSearchAction } from "./WebSearchAction";
export type ResponseItem = { "type": "message", role: string, content: Array<ContentItem>, phase?: MessagePhase, } | { "type": "reasoning", summary: Array<ReasoningItemReasoningSummary>, content?: Array<ReasoningItemContent>, encrypted_content: string | null, } | { "type": "local_shell_call",
export type ResponseItem = { "type": "message", role: string, content: Array<ContentItem>, phase?: MessagePhase, } | { "type": "agent_message", author: string, recipient: string, content: Array<AgentMessageInputContent>, } | { "type": "reasoning", summary: Array<ReasoningItemReasoningSummary>, content?: Array<ReasoningItemContent>, encrypted_content: string | null, } | { "type": "local_shell_call",
/**
* Set when using the Responses API.
*/
+1
View File
@@ -1,6 +1,7 @@
// GENERATED CODE! DO NOT MODIFY BY HAND!
export type { AbsolutePathBuf } from "./AbsolutePathBuf";
export type { AgentMessageInputContent } from "./AgentMessageInputContent";
export type { AgentPath } from "./AgentPath";
export type { ApplyPatchApprovalParams } from "./ApplyPatchApprovalParams";
export type { ApplyPatchApprovalResponse } from "./ApplyPatchApprovalResponse";