PuppyIP Resource Center
AI Tool Updates 5 min read Published 2026-10-07

VS Code 1.141: Continue Codex Chats and Understand Terminal Sandboxing

Want to move from a terminal conversation into the editor to inspect code? VS Code 1.141 can continue Codex chats on the same computer. Release sending control in the original app first, identify the integration you're using, and configure sandboxing for the actual execution host.

VS Code Codex Agent Host Terminal sandbox GitHub Copilot

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • 1.141 is a stable release, but Codex Agent Host in Agents window remains Experimental. Not every included feature is stable.
  • Enable the relevant Codex integration and show Created Externally sessions to continue same-computer ChatGPT app or CLI histories.
  • Only one application can send to a chat at a time. Fully exit the original app or CLI session, then choose Retry when occupied.
  • Terminal sandbox documentation covers Copilot Agent Host's default tools. Verify platform prerequisites, effective policy, and network permissions separately.

Continue the conversation without rebuilding context

VS Code 1.141 became Stable on October 7, 2026. Same-computer Codex handoff brings chats started in ChatGPT or Codex CLI into Agents window with history, and lets you return to the original application afterward.

A useful workflow is discussing a change in the terminal and inspecting files and diffs in the editor. Hypothetically, after CLI analysis you continue code adjustments in VS Code. Handoff retains context but does not let two applications send instructions simultaneously.

The feature concerns external chats on the same computer, not automatic synchronization of arbitrary cloud or other-computer sessions. A stable editor release does not remove the integration's Experimental status.

Make external Codex chats visible

Use Check for Updates to confirm 1.141 or a later supporting version. In Agents window, inspect the selected agent. Codex is not listed directly by default; complete the corresponding integration.

Enable chat.agentHost.codexAgent.enabled for experimental Codex Agent Host. The OpenAI Codex extension's Chat view is a separate integration; do not combine their switches and behavior.

In Filter Sessions, show Created Externally and filter sources with Created In. Eligible same-computer ChatGPT/CLI chat creations and updates appear within seconds, without repeated window reloads.

Model groups determine which allowance pays. Copilot-backed Agent Host Codex needs Copilot Pro+; ChatGPT-backed uses a ChatGPT account. The selected group uses that subscription. Switching interfaces does not merge quotas.

When another application holds the chat, use Retry

This chat is open in another app means the original still holds sending control. Check running work and files, then fully exit ChatGPT or the relevant CLI session. Closing a panel alone is not the documented exit.

Choose Retry in VS Code. Release notes say drafts and attachments are retained, and Retry only checks takeover without sending the draft. Continue once control transfers rather than creating another chat to rebuild context.

Before switching back to CLI or the original app, release the current application's sending control. A shared conversation history and several agents on different tasks are different workflows; competing for the same chat does not implement the latter.

Which agent does the terminal sandbox constrain?

Sandboxing bounds command access to files and networks. The 1.141 change concerns Copilot Agent Host, whose documentation limits the rules to default Copilot SDK tool implementations, not Local chat harness or custom terminal overrides.

A similarly named switch does not establish equal isolation for the Codex extension, experimental Codex Agent Host, or all MCP tools. Check Codex permission presets and the actual integration separately; successful handoff does not automatically tighten permissions.

Agent Host runs the session; windows mainly display and control it. Remote tools use the remote host's sandbox paths, dependencies, and restrictions. Installing local components does not establish remote readiness.

Windows and WSL prerequisites

Windows sandbox support is Experimental and requires applicable September 8, 2026 security updates: KB5124008 for Windows 11 24H2/25H2, or KB5124012 for 26H1. Match the actual OS to official support guidance; these identifiers do not apply to every system.

Linux and WSL2 require bubblewrap and socat; WSL1 does not support this path. The prerequisite table lists no extra macOS dependencies. For remote execution, check the system running Agent Host.

Set chat.agent.sandbox.enabled to on on the execution host once prerequisites are met, then start a new Agent Host session. Values are on/off, default off. Updating the editor alone does not prove a current session is sandboxed.

Inspect effective policy after enabling

Submit /sandbox policy in the Agent Host session to inspect execution host, enabled status, and effective file/network rules. It starts no model turn and changes no settings. Grant only needed directories or services and check policy again after changes.

Sandboxing does not block outbound traffic by default: chat.agent.sandbox.network.allowNetwork defaults to true. Domain allow/deny rules still constrain destinations. Configure network policy separately when outbound restrictions are required.

Approval and sandboxing answer different questions: whether an action needs confirmation versus what resources supported actions can access. The sandbox adds protection without replacing a virtual machine, separate user account, or endpoint security. Retain normal review and permission rules.

Sources

Frequently Asked Questions

Can I continue with Copilot after exhausting ChatGPT usage?

Release notes describe continuing with Copilot models, subject to eligibility. Copilot-backed Agent Host Codex requires Pro+. This uses another subscription rather than resetting ChatGPT and does not guarantee every model or plan.

Can this version clean up old session disk usage?

Use Chat: Open Worktree Cleanup and select unused sessions by idle time and size. Cleanup marks them completed and removes worktrees; restoring a session rebuilds them. Save necessary work first. Active, running, awaiting-input, and pinned sessions are protected.

Can two VS Code windows observe one agent?

Agent Host supports synchronized observation by multiple clients. External Codex handoff still permits only one application to send at a time; visibility is not simultaneous sending permission.