Skip to content

Add precision Codex runner probes - #26

Merged
KeyffMS merged 3 commits into
mainfrom
diag/codex-runner-precision-probes
Sep 4, 2026
Merged

Add precision Codex runner probes#26
KeyffMS merged 3 commits into
mainfrom
diag/codex-runner-precision-probes

Conversation

@KeyffMS

@KeyffMS KeyffMS commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Summary

Adds a second, precision diagnostic matrix for the remaining Codex CLI 0.152 runtime questions exposed by diagnostic run #14. It does not change C01-C16 capability results or the release gate.

Precision probes

  • absolute external sidecars for PreToolUse, PreCompact/PostCompact, and SubagentStart; no git rev-parse inside hook recorders;
  • real PreToolUse allow and deny controls for canonical Bash, including JSON and TOML hook representations;
  • hooks-disabled negative control and trusted-project/no-bypass comparison;
  • compaction single-step control plus forced two-step probes for body_after_prefix and total with TokenBudget disabled only inside disposable fixtures;
  • SubagentStart comparison across ephemeral project agent, controlled non-ephemeral project agent, and controlled non-ephemeral isolated-home agent;
  • per-run opaque context token known only to the SubagentStart hook; child instructions contain only the prefix/protocol, never the value;
  • recursive token redaction from evidence;
  • each variant is failure-isolated so one probe cannot abort the matrix artifact.

Workflow

Adds mode=precision to the already runner-allowlisted PlanAnvil Codex qualification workflow. Precision observations are diagnostic-only; the workflow gates only harness completion and artifact creation.

Safety

No runner policy changes, no privilege expansion, no raw transcript persistence, no release-gate weakening, and no product-contract changes in this PR.

@KeyffMS
KeyffMS merged commit 828f7ec into main Sep 4, 2026
7 checks passed
KeyffMS added a commit that referenced this pull request Sep 7, 2026
…ure (#35)

Documentation-only alignment with the existing full-archive production validator. Record the merged finite C08 repair and the automated run #26 rejected by the local initiating-actor policy before Codex. Require a fresh main/full run by an allowed account; retain runner security and distinguish offline conformance from live evidence. Preserve archived run #25 and leave all product, runtime, tests and release guards unchanged. PR CI #120 passed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant