What happened

OpenAI shipped Codex 0.154.0 on September 9. Codex is OpenAI’s command-line coding agent, the closest tool it has to Claude Code: you run it in a terminal and it reads, writes, and executes code on your machine.

The headline addition is worktree support, which OpenAI labels experimental. Normally, a git repository (the folder that tracks your project’s full history) only has one working copy of your files checked out at a time. If you run two Codex sessions on the same project at once, both are editing that same working copy, so one session’s changes can land on top of the other’s before you’ve reviewed either. A worktree is a second, separate working copy of the same repository, checked out on its own branch (a named, independent line of changes inside the same project), that still shares the project’s full history with the original.

Codex can now create one of these for you. Start a new session with the --worktree flag, or type /worktree inside a forked session, Codex’s existing feature for spinning a copy of your current session off into its own separate one, and Codex sets up an isolated checkout instead of reusing your main one. You can then browse and resume past worktree sessions, per OpenAI’s release notes.

The same release ships two smaller, safety-relevant fixes. Codex’s startup process now avoids running “workspace-controlled helpers,” meaning scripts or programs whose behavior the project itself defines, before you’ve confirmed you trust that project folder. And on macOS, Codex’s sandbox (a restricted mode that limits what a program can touch on your machine) now blocks terminal input injection, a technique where output printed to your terminal tries to fake additional keystrokes to trigger actions you never typed.

Why it matters

Worktrees aren’t a new idea. Developers running multiple AI coding sessions in parallel have been setting up separate git worktrees by hand for a while, using raw git commands, specifically to stop two agents from clobbering each other’s edits in the same folder. Codex turning that into a built-in flag removes a manual step, not a new capability.

That matters more as running several agent sessions on one project at once becomes normal. Without separate checkouts, starting two Codex sessions in the same folder means both are reading and writing the same files. If one session finishes a change while the other is still mid-edit, the second session’s work can overwrite the first’s without either of you noticing until you check the diff.

The startup fix is worth reading in the same light as a flaw BuilderWithin covered earlier this month, where researchers found several coding agents, Codex included, would run code defined in a project’s own git settings the instant you opened the folder, before any trust prompt appeared. Codex had already been patched against that specific trigger by the time researchers confirmed it. OpenAI hasn’t said this new startup check targets the same mechanism, but it belongs to the same broader pattern: don’t execute anything the project itself controls until the person opening it has agreed to trust it.

Who should care

Anyone already running more than one Codex session against the same repository, for example one session fixing a bug while another builds a separate feature. If you’ve been managing that split manually with your own git worktree commands, the built-in flag replaces that setup. Anyone who opens Codex on projects they didn’t write themselves should also note the startup fix, since it narrows one more path for a project’s own files to run code before you’ve approved anything.

What builders should do next

Since OpenAI calls worktree support experimental, test it on something disposable before relying on it for real work. Pick a bounded task you can split into two independent halves, like building a new UI component in one Codex session while writing its tests in another, on a throwaway copy of a real repository.

Run the split once the old way, both sessions working in the same checkout, and once using --worktree for each session. Compare two things: how many times you have to manually resolve one session’s edits overwriting the other’s, and how much extra time it takes to bring both worktrees’ changes back into a single branch afterward. If the worktree version eliminates the overwrites but adds a slow merge step, that’s the real trade-off, not what the release notes say about it.

To update, run npm install -g @openai/codex@latest if you installed Codex through npm, brew upgrade --cask codex if you installed it through Homebrew, or codex update to use Codex’s own built-in updater. Then confirm with codex --version that you’re on 0.154.0 or later.


End of article