Skip to content

Declare the Codex agent-host view - #354

Merged
SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/view-codex
Oct 1, 2026
Merged

SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/view-codex

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

The Codex adapter declares its agent-host view (lane L5-codex), following the Runtime–Harness View declaration merged in #350. Nothing launches a view yet. The agent-host library (L5a) and end-to-end qualification (L7) follow.

View declaration (apps/daemon/internal/agent/codex/view.go)

  • When a view is declared: only for the pinned release, and only when the resolved codex is a static ELF. Otherwise View is nil: on macOS and Windows, with a dynamic binary, or with no install.
  • Closure: the binary's directory, mounted as codex.
  • LocalExec: codex, plus codex-code-mode-host when that file sits beside it and is also static.
  • Shims: git only. rg is not declared, so Codex takes its ENOENT fallback.
  • ShimPaths: /bin/bash, the passwd shell.
  • Mask: /etc/codex.
  • ForwardEnv: terminal, pager and locale variables, plus CODEX_CI, CODEX_THREAD_ID, CODEX_SESSION_ID and GIT_OPTIONAL_LOCKS.
  • Proxy: ViewProxyEnv.

Executor in a view

  • Paths: CODEX_HOME and TMPDIR are sibling 0700 directories in the Session home.

  • config.toml: holds the gateway base_url with no path, the placeholder bearer, and only HTTP MCP servers from ViewSession.MCP. A stdio binding fails with ErrUnsupportedOperation.

  • Overrides:

    • features.{shell_snapshot,hooks,plugins,memories,skill_mcp_dependency_install}=false;
    • allow_login_shell=false;
    • project_root_markers=[], so there is no ancestor walk over the mount.

    danger-full-access and approval never are unchanged. No trust entry is written, so the project stays untrusted.

  • Environment: closed.

    • PATH is the shim directory only.
    • HOME and TMPDIR are set as above.
    • All four proxy variables are set.
    • NO_PROXY and no_proxy are 127.0.0.1,localhost.
    • DISABLE_TELEMETRY=1.
  • Launch: Codex starts through ViewSession.Launch, and the exit status comes from Process.ExitCode().

  • Home writes: every read, write, create and remove in CODEX_HOME goes through one os.Root opened on its parent, on the in-sandbox path as well. A link the Harness leaves in its home can no longer redirect a root write.

  • Model catalog: it is created with O_EXCL inside that Root.

  • Rejected in a view: environment:none, a request with no workspace, installed Capabilities, hosted skills and the skills option.

  • model_verbosity probe: runs the trusted host install outside the view, with a scratch CODEX_HOME that holds only the gateway and the placeholder.

Coverage ledger

contracts/agents-api/README.md records that, behind the gateway, pinned Codex compacts locally and never calls /responses/compact.

Checks

  • TestViewExecutorLaunchesInTheSessionView resolves the view with ResolveView and covers:
    • the declaration, the -c overrides, the closed environment, the gateway config and the rejection of stdio bindings;
    • a symlink planted at codex/config.toml, which is replaced, never followed. An appendConfigTOML through a planted link fails.
  • go test -race ./apps/daemon/internal/agent/codex/.
  • go test ./apps/daemon/internal/agent/....
  • go vet ./apps/daemon/..., gofmt, and the darwin and windows builds.

Fourteen behaviours need the real Harness. They are listed for L7 qualification, among them the proxy, the shims and the code-mode host inside the closure.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Codex declares a View when discovery finds the pinned release as a static
binary: its install directory as the closure, codex and the code-mode host as
LocalExec, a git shim, /bin/bash as the passwd shell, /etc/codex masked, and
the proxy variables pointed at the Session proxy.

The view Executor lays CODEX_HOME and TMPDIR out in the Session home, writes
the gateway provider with the placeholder bearer, configures MCP only from the
Session bindings, disables the features that run local programs, and launches
app-server through the Session with a closed environment.
@SaladDay
SaladDay merged commit eb728bf into feature/agent-outside-sandbox Oct 1, 2026
6 checks passed
The Session user owns a view home and can leave links in it between turns,
while the daemon writes config.toml, the MCP section and the model catalog
there as root. Every read, write, create and remove in CODEX_HOME now goes
through a Root opened from the home's parent, so a link resolves only inside
the home. The model catalog is created with O_EXCL inside that Root.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant