Declare the Codex agent-host view - #354
Merged
Merged
Conversation
Codex declares a View when discovery finds the pinned release as a static binary: its install directory as the closure, codex and the code-mode host as LocalExec, a git shim, /bin/bash as the passwd shell, /etc/codex masked, and the proxy variables pointed at the Session proxy. The view Executor lays CODEX_HOME and TMPDIR out in the Session home, writes the gateway provider with the placeholder bearer, configures MCP only from the Session bindings, disables the features that run local programs, and launches app-server through the Session with a closed environment.
The Session user owns a view home and can leave links in it between turns, while the daemon writes config.toml, the MCP section and the model catalog there as root. Every read, write, create and remove in CODEX_HOME now goes through a Root opened from the home's parent, so a link resolves only inside the home. The model catalog is created with O_EXCL inside that Root.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The Codex adapter declares its agent-host view (lane L5-codex), following the Runtime–Harness
Viewdeclaration merged in #350. Nothing launches a view yet. The agent-host library (L5a) and end-to-end qualification (L7) follow.View declaration (
apps/daemon/internal/agent/codex/view.go)codexis a static ELF. OtherwiseViewis nil: on macOS and Windows, with a dynamic binary, or with no install.codex.codex, pluscodex-code-mode-hostwhen that file sits beside it and is also static.gitonly.rgis not declared, so Codex takes its ENOENT fallback./bin/bash, the passwd shell./etc/codex.CODEX_CI,CODEX_THREAD_ID,CODEX_SESSION_IDandGIT_OPTIONAL_LOCKS.ViewProxyEnv.Executor in a view
Paths:
CODEX_HOMEandTMPDIRare sibling 0700 directories in the Session home.config.toml: holds the gatewaybase_urlwith no path, the placeholder bearer, and only HTTP MCP servers fromViewSession.MCP. A stdio binding fails withErrUnsupportedOperation.Overrides:
features.{shell_snapshot,hooks,plugins,memories,skill_mcp_dependency_install}=false;allow_login_shell=false;project_root_markers=[], so there is no ancestor walk over the mount.danger-full-accessand approvalneverare unchanged. No trust entry is written, so the project stays untrusted.Environment: closed.
PATHis the shim directory only.HOMEandTMPDIRare set as above.NO_PROXYandno_proxyare127.0.0.1,localhost.DISABLE_TELEMETRY=1.Launch: Codex starts through
ViewSession.Launch, and the exit status comes fromProcess.ExitCode().Home writes: every read, write, create and remove in
CODEX_HOMEgoes through oneos.Rootopened on its parent, on the in-sandbox path as well. A link the Harness leaves in its home can no longer redirect a root write.Model catalog: it is created with
O_EXCLinside that Root.Rejected in a view:
environment:none, a request with no workspace, installed Capabilities, hosted skills and theskillsoption.model_verbosityprobe: runs the trusted host install outside the view, with a scratchCODEX_HOMEthat holds only the gateway and the placeholder.Coverage ledger
contracts/agents-api/README.mdrecords that, behind the gateway, pinned Codex compacts locally and never calls/responses/compact.Checks
TestViewExecutorLaunchesInTheSessionViewresolves the view withResolveViewand covers:-coverrides, the closed environment, the gateway config and the rejection of stdio bindings;codex/config.toml, which is replaced, never followed. AnappendConfigTOMLthrough a planted link fails.go test -race ./apps/daemon/internal/agent/codex/.go test ./apps/daemon/internal/agent/....go vet ./apps/daemon/...,gofmt, and the darwin and windows builds.Fourteen behaviours need the real Harness. They are listed for L7 qualification, among them the proxy, the shims and the code-mode host inside the closure.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.