Repository navigation
Managed providers: Codex app-server adapter; Codex/OpenCode/Remote Control evidence (#339, #340) - #380
Draft
raiseCatError wants to merge 2 commits into
Draft
Managed providers: Codex app-server adapter; Codex/OpenCode/Remote Control evidence (#339, #340)#380raiseCatError wants to merge 2 commits into
raiseCatError wants to merge 2 commits into
Conversation
…dex, OpenCode and Remote Control #339 and #340. src/agents/sessions/codexAdapter.ts drives `codex app-server` (JSON-RPC over stdio, shapes from the protocol schema codex-cli 0.162.1 generates) with the same contract as the Claude adapter: - Codex's own approval policy, sandbox and model are not overridden; - messages sent before the thread exists are queued; the thread is reported once whatever order thread/started and the thread/start response arrive in; - approvals are answered only with the person's choice, `accept` once or `decline`, never "for the session" or a policy amendment; - every server request NMSh does not implement is refused with a JSON-RPC error, so Codex never waits on NMSh; - cancellation is reported only when the turn completes as `interrupted`; - a failed turn carries Codex's own error message, never an invented one; - frames are bounded; unknown or malformed messages produce nothing. The CLI's `[experimental]` label is kept as a capability so it can be shown. The adapter is not wired into the session manager or harness registry yet: both are changed by the managed-agent workspace PR (#347). Tests drive it against a fixture server speaking the documented shapes: handshake, queued message, approve, decline, refused request, interrupt acknowledgement, failure reason, refused initialization, hostile output. docs/design/managed-providers.md records the per-provider evidence matrix, why OpenCode gets no adapter yet (v1 docs vs. the v2 server), and the Remote Control findings: no-go for Managed targets (the stream-json transport is not documented as Remote Control capable), pass-through for raw Claude, no Never/Ask/Always policy until a probe or documentation shows support.
…labelled reasons From a security review of the Codex adapter; the same pattern was in the Claude adapter's permission prompts. - A command approval showed only the command's first line, so a harmless first line could hide what followed. Approval targets now show every line (line breaks as " ⏎ "), cut at 600 characters with an explicit "N more characters; see details"; the complete command stays in the details. This applies to Codex command approvals and Claude permission prompts (approvalTarget; tool rows keep their compact form, now with "+N more lines"). - A Codex file-change approval named no files, only Codex's own reason. It now names the files of the fileChange item it refers to, or says "files not reported by Codex". - Codex's reason is model-written: it is kept as `reasonFromCodex`, never presented as NMSh's own words. - A response-order assertion in the session test no longer races.
17 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#339 and #340. Based on
release/v0.18.0. New files only; the session manager and harness registry are untouched because #347 changes them.Codex adapter (
src/agents/sessions/codexAdapter.ts), same contract asClaudeSession:codex app-serverover stdio, JSON-RPC shapes taken from the schema codex-cli 0.162.1 generates (codex app-server generate-json-schema); the CLI marksapp-serverexperimental, whichcodexCapabilitieskeeps so the UI can say so.acceptonce ordecline, neveracceptForSessionor policy amendments); unimplemented server requests get a JSON-RPC error so Codex never waits; cancellation is reported only whenturn/completedsaysinterrupted; failed turns carry Codex's own message; frames bounded to 8 MiB.tests/codexAdapter.test.ts) run it againsttests/fixtures/fake-codex-app-server.mjs: handshake, queued first message, approve, decline, refused unsupported request, interrupt acknowledgement, failure reason, refused initialization, garbage and an oversized frame.Research (
docs/design/managed-providers.md): capability evidence matrix for Claude / Codex / OpenCode; OpenCode stays "shown, not controlled" (its server page documents v1 endpoints while 2.0.18 serves "the v2 API"; the next step is pinning to a running server's/doc); Remote Control: no-go for Managed targets (the documented modes are interactive and server mode; the stream-json transport is not documented as capable), pass-through for raw Claude, no Never/Ask/Always policy until a probe or documentation shows support.Remaining (listed in the doc): wiring
codex-app-serverinto the harness registry and manager after #347; plan/token-usage normalization with #332's task model; physical QA with signed-in Codex/OpenCode/Claude accounts (not performed).Security fix (8854bb7), found by review: approval prompts could hide what they approve. A command approval showed only its first line (a harmless first line could hide
curl … | shbelow it) — now every line is shown (⏎between lines, cut at 600 characters with an explicit remainder count); this also fixes the shipped Claude adapter's permission prompts (approvalTarget, a narrow change outside the lines #347 edits). A Codex file-change approval named no files — it now names the files of itsfileChangeitem or says they were not reported. Codex's model-written reason is labelledreasonFromCodex.