Repository navigation
[Bug]: Codex 0.154.0 Computer Use can bypass T3 collaborative browser #11579
Description
Activity
Triage
This looks like a real Codex 0.154.0 regression, not a T3 preview outage.
T3 already attaches
t3-codewithpreview_*when agent browser access is on, and already injects developer instructions that prefer those tools and forbid falling back to Chrome / Node REPL / Playwright / agent-browser. That list does not name the new bundled surface (cua_repl,unified-computer-use@openai-bundled, IAB). So Codex can skip T3 preview entirely, fail withBrowser is not available: iab, and report that the live browser is down whilePreviewAutomationBrokeris healthy.This is not a duplicate of #6355 (detached T3 tab after leaving a thread) or #7212 (blank floating preview; no Computer Use).
Where a T3 fix belongs
apps/server/src/provider/CodexDeveloperInstructions.ts— harden the collaborative-browser block only when preview tools are attachedapps/server/src/provider/Layers/CodexSessionRuntime.ts— already gates the block on MCP +previewcapability; keep thatapps/server/src/provider/Layers/CodexSessionRuntime.test.ts— existing “T3 browser developer instructions” tests
There is currently no T3 host control that disables Codex bundled plugins. Uninstalling
unified-computer-usewould also remove legitimate desktop Computer Use, so that is not the first fix.Proposed T3 mitigation
When
preview_*is attached:- explicitly treat
cua_repl/unified-computer-use/ IAB as a separate browser surface - require
preview_status/preview_openbefore concluding the browser is unavailable - do not treat
Browser is not available: iabas evidence that T3 preview failed - do not fall back to bundled Computer Use for browser work unless T3 preview itself returns unsupported/unavailable, or the user asks for another browser
Omit this entire block when preview tools are not attached.
Prompt steering is only a mitigation. A durable fix needs Codex app-server support to suppress or deprioritize bundled Computer Use/browser tools when an embedding host supplies its own browser MCP.
Accepting for the instruction + test change; marking
upstreamfor the Codex host-control follow-up.- addedbugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.acceptedfeature request acceptedfeature request acceptedvia-triageFiled through npx t3 triageFiled through npx t3 triage
on Sep 13, 2026
Before submitting
Area
apps/server / Codex provider
Summary
With Codex CLI 0.154.0, Codex can choose its bundled
cua_repl/unified-computer-usebrowser path instead of T3 Code's attachedt3-codecollaborative browser MCP, even when T3 has exposedpreview_*tools and explicitly instructs Codex to use them.When that bundled path has no available IAB browser,
cua_replfails withBrowser is not available: iab. The model can then incorrectly report that the live browser is unavailable even though T3's own preview automation broker is healthy and thet3-codeMCP is attached.Steps to reproduce
preview_status,preview_open,preview_navigate, and related tools.This has been observed with both
gpt-6-astraandgpt-5.6-sol.Expected behavior
When the
t3-codeMCP exposespreview_*tools, T3's collaborative browser should be the authoritative browser route for the session. Codex should callpreview_statusfirst andpreview_openwhen needed before deciding browser automation is unavailable.A failure from an unrelated bundled Computer Use browser should not be interpreted as failure of T3's collaborative browser.
Actual behavior
On affected turns Codex makes no T3 preview call and instead selects the bundled Computer Use path, for example:
It may then run:
and receive:
The assistant can then conclude that "the live browser connection is unavailable" even though this error belongs to the bundled IAB/Computer Use path, not T3's
preview_*tools.Evidence / regression boundary
v0.0.41-nightly.20260913.16460.154.0t3-codeMCP was attached successfully and MCPtools/listcompleted.0.150.1correctly selectedt3-codetools such aspreview_status,preview_open,preview_navigate, andpreview_snapshot.preview_*, so the new overlapping browser-capable tool surface can still win tool selection despite the existing generic guidance.Impact
Major degradation for Codex browser tasks in T3 Code. The user can be told that live browser access is unavailable when T3's browser is actually available, and the agent never attempts the product-native preview route.
Proposed T3-side mitigation
Harden the Codex developer instructions when
preview_*tools are actually attached:cua_repl,unified-computer-use, and IAB as a separate browser surface;preview_status/preview_openbefore any conclusion that the browser is unavailable;Browser is not available: iabis not evidence that T3 preview is unavailable;This should be covered by regression tests in the Codex developer-instruction tests.
Upstream follow-up
Prompt steering is only a mitigation. It would be better if Codex app-server exposed a supported host/session control to suppress or deprioritize bundled Computer Use/browser tools when an embedding host supplies its own authoritative browser MCP. That likely warrants a corresponding OpenAI/Codex issue once the T3 reproducer is public.
Related issues