Repository navigation
live: Codex TUI actor fanout and live observer dogfood #28
Description
Activity
- addedenhancementNew feature or requestNew feature or requestproof-requiredCannot close without command, artifact, review, or run-bundle proof.Cannot close without command, artifact, review, or run-bundle proof.privacy-boundaryPII, PHI, secret, token, or future-public safety boundary.PII, PHI, secret, token, or future-public safety boundary.area:observerObserver, report, and mission-control surfaces.Observer, report, and mission-control surfaces.area:actorsActor/runtime adapters such as scripted, terminal, Codex, and computer-use.Actor/runtime adapters such as scripted, terminal, Codex, and computer-use.risk:credential-boundaryWork touches credential, auth, secret, network, or spend boundaries.Work touches credential, auth, secret, network, or spend boundaries.next:specNext step is spec or split.Next step is spec or split.
on Jun 1, 2026 Added a local spec on branch/worktree
codex/oss-meta-completion:docs/architecture/local-codex-tui-actor.md
The spec scopes the smallest safe local Codex TUI actor before 4x fanout:
- explicit opt-in for live local actor work;
- deterministic lifecycle events (
actor.spawned,actor.prompt.submitted,actor.observation,actor.artifact,actor.verdict,actor.exited,actor.timeout,actor.cancelled); - ignored runtime artifact layout under
.mimetic/runs/<run-id>/; - redaction and stop conditions;
- first-slice proof commands for a 1x actor.
Proof for the spec slice:
pnpm public-surface:scan git diff --check
This intentionally does not implement the live local actor yet. The next implementation slice should keep non-dry-run fail-closed unless
--actor codex-tuior an equivalent explicit opt-in is present, then prove 1x before splitting/attempting 4x fanout.Updated #28 on PR #37 with the first implementation slice:
mimetic run --actor codex-tui --sims 1 --timeout-ms <ms>now explicitly opts into one local actor.- Non-dry-run still fails closed unless
--actor codex-tuiorMIMETIC_ENABLE_LOCAL_CODEX_TUI=1is present. - The actor writes deterministic lifecycle events:
actor.spawned,actor.prompt.submitted,actor.observation,actor.artifact,actor.verdict, andactor.exited/actor.timeout. - Actor output is redacted before persistence; the bundle links a sanitized transcript and actor trace under ignored
.mimetic/runtime state. verifyandwatch --run ... --detach --no-opennow accept/render live-mode actor bundles.- Linux real-TUI launch uses a
scriptPTY wrapper because Codex TUI requires a terminal.
Proof:
pnpm check pnpm public-surface:scan git diff --check MIMETIC_CODEX_ACTOR_COMMAND=... pnpm mimetic -- run --actor codex-tui --sims 1 --timeout-ms 5000 --run-id codex-local-fixture-proof --json pnpm mimetic -- verify --run codex-local-fixture-proof --json pnpm mimetic -- watch --run codex-local-fixture-proof --detach --no-open --json
Real local TUI attempt:
- The first no-PTY attempt failed with
stdin is not a terminal. - After adding the PTY wrapper, the TUI launched but timed out at Codex workspace trust before autonomous completion.
- The timeout bundle still verified and rendered through Observer with public-safe sanitized evidence.
Next #28 slice: add an explicit Codex workspace-trust preflight/recovery command, or split a separate non-TUI
codex execactor mode while keeping the TUI contract honest about PTY/trust requirements. This comment intentionally excludes raw logs, secrets, and local private transcript content.Follow-up on the #28 implementation slice in PR #37: added fail-fast Codex workspace-trust preflight.
Current behavior for the default real TUI actor:
- If the Codex trust root is not explicitly trusted,
mimetic run --actor codex-tui --sims 1blocks before spawning the TUI. - The run still writes a public-safe
blockedbundle withactor.preflight.blocked,actor.verdict, andactor.blockedlifecycle events. - That blocked bundle passes
mimetic verifyand renders withmimetic watch --run ... --detach --no-open. - Fixture actor proof still passes through
MIMETIC_CODEX_ACTOR_COMMAND=..., so CI does not need real provider/auth state.
Final proof for this slice now includes:
pnpm check pnpm public-surface:scan git diff --check MIMETIC_CODEX_ACTOR_COMMAND=... pnpm mimetic -- run --actor codex-tui --sims 1 --timeout-ms 5000 --run-id codex-local-fixture-proof --json pnpm mimetic -- verify --run codex-local-fixture-proof --json pnpm mimetic -- watch --run codex-local-fixture-proof --detach --no-open --json pnpm mimetic -- run --actor codex-tui --sims 1 --timeout-ms 90000 --run-id codex-local-trust-preflight-proof-2 --json pnpm mimetic -- verify --run codex-local-trust-preflight-proof-2 --json pnpm mimetic -- watch --run codex-local-trust-preflight-proof-2 --detach --no-open --json
Remaining #28 work: add an explicit trust bootstrap or a separately-scoped
codex execactor mode, then prove autonomous completion rather than a preflight block. No raw logs, secrets, stream URLs, or private transcript content included here.- If the Codex trust root is not explicitly trusted,
Added the next #28 slice in PR #38: noninteractive local
codex-execactor support.What changed:
mimetic run --actor codex-exec --sims 1is now a supported explicit live actor mode.- The actor runs
codex execwith read-only sandbox, JSON event output, ephemeral session mode, and ignored project rules, then persists a sanitized JSONL transcript plusactor.jsontrace under.mimetic/runs/<run-id>/. - The resulting live bundle verifies and renders in Observer like the TUI actor bundle.
codex-tuiremains the PTY/trust-gated visual actor contract;codex-execis the autonomous noninteractive local completion path, not a replacement for TUI proof.- The committed
mimetic/dogfood config now reflects the current actor boundary instead of saying all live actors are unsupported.
Proof:
pnpm check pnpm public-surface:scan git diff --check pnpm mimetic -- doctor --json pnpm mimetic -- watch --json --no-open --run-id watch-post-37-baseline pnpm mimetic -- lab oss --dry-run --json --no-open --run-id oss-dry-post-37-baseline pnpm mimetic -- lab oss-smoke --limit 4 --json --run-id oss-smoke-post-37-baseline pnpm mimetic -- lab oss --detach --no-open --json --run-id oss-live-post-37-baseline --repos developit/mitt,lukeed/clsx,sindresorhus/is-plain-obj,ai/nanoid --count 4 pnpm mimetic -- verify --run oss-live-post-37-baseline --json pnpm mimetic -- run --actor codex-exec --sims 1 --timeout-ms 90000 --run-id codex-exec-real-proof-3 --json pnpm mimetic -- verify --run codex-exec-real-proof-3 --json pnpm mimetic -- watch --run codex-exec-real-proof-3 --detach --no-open --json
The live E2B OSS lab classified 4/4 target repos as passed and captured 4/4 screenshot fallbacks. The real local
codex-execactor passed in a bounded run and produced a verified Observer-renderable live bundle.Remaining #28 work: TUI trust bootstrap, live Observer follow while actors are still running, and 4x fanout. No raw transcripts, stream URLs, sandbox IDs, or secret-bearing material included here.
Progress update for #28: PR #39 adds explicit noninteractive
codex-execfanout.Public-safe proof from the branch:
codex-execnow supports--sims 1..4;codex-tuiremains single-lane with trust preflight.- Four bounded read-only lane focuses are emitted: install/readability, public-safety/trust, Observer/evidence, and verification/release.
- Fanout bundles now include 4 terminal streams, 4 sanitized transcript artifacts, 4 actor traces, per-lane lifecycle events, and aggregate review status.
- The existing 1x
codex-execartifact contract is preserved:transcripts/codex-exec-sanitized.jsonlandactor.json.
Verification completed:
pnpm check-> 10 test files / 48 tests passed, build passed.pnpm public-surface:scan-> 72 candidate text files checked.git diff --check-> passed.pnpm mimetic -- doctor --json-> passed.- Env-sourced real fanout run
codex-exec-fanout-real-proof-env-> passed, 4/4 lanes. pnpm mimetic -- verify --run codex-exec-fanout-real-proof-env --json-> 5/5 checks passed.pnpm mimetic -- watch --run codex-exec-fanout-real-proof-env --detach --no-open --json-> Observer rendered.- Env-sourced 1x regression
codex-exec-1x-regression-env-> passed and preserved original 1x artifact paths.
No raw transcripts, secrets, sandbox URLs, or target OSS mutations are included here.
PR: #39
PR #39 is merged to main as
a996b589138ebaf88883e9002f76aee2573d6690.Merged slice:
- Explicit
codex-exec --sims 1..4fanout. - Per-lane sanitized terminal evidence, actor traces, lifecycle events, and aggregate review status.
- Preserved 1x exec artifact paths.
- Updated dogfood docs/coverage/scenario language.
Remote CI passed on Node 22.14.0 and Node 24. Local proof also passed with env-sourced real 4-lane fanout, verify, Observer render, and 1x regression.
Still open for #28:
- Codex TUI trust bootstrap beyond fail-fast blocked bundles.
- Live Observer follow while local actors are still running.
- Deeper repeated OSS lab loops using the new fanout path.
- Explicit
Progress update for #28: PR #40 adds active-run Observer snapshots for local
codex-exec.Public-safe behavior added:
- Local
codex-execruns now write a provisional runningrun.jsonandobserver/observer-data.jsonbefore actor completion. - Each lane emits
actor.runninginevents.ndjson. - The same Observer data path is refreshed after sanitized transcripts, actor traces, and final verdict events are available.
- This is scoped to noninteractive
codex-exec; Codex TUI trust bootstrap and TUI live-follow remain separate work.
Verification completed:
pnpm check-> 10 test files / 49 tests passed, build passed.pnpm public-surface:scan-> 72 candidate text files checked.git diff --check-> passed.pnpm mimetic -- doctor --json-> passed.- Env-sourced real fanout run
codex-exec-live-follow-real-proof-env-> passed, 4/4 lanes. pnpm mimetic -- verify --run codex-exec-live-follow-real-proof-env --json-> 5/5 checks passed.pnpm mimetic -- watch --run codex-exec-live-follow-real-proof-env --detach --no-open --json-> Observer rendered.- Metadata check: 4
actor.runningevents, 4 passed streams, final Observer active count 0. - Fixture regression proves the intermediate active state with a slow fake actor: running Observer data appears while actors are still active, then refreshes to passed after completion.
No raw transcripts, secrets, sandbox URLs, or target OSS mutations are included here.
PR: #40
- Local
PR #40 is merged to main as
b37179386b9a68d1716938150f460b3ad697307b.Merged slice:
- Local
codex-execruns publish runningrun.jsonandobserver/observer-data.jsonbefore actor completion. - Each exec lane emits
actor.runningevents. - Final Observer data refreshes after sanitized transcript/trace artifacts and verdicts are available.
- Dogfood coverage now distinguishes exec active-run snapshots from the still-open Codex TUI live-follow path.
Remote CI passed on Node 22.14.0 and Node 24. Local proof passed with the active slow-actor fixture, env-sourced real 4-lane fanout, verify, and Observer render.
Still open for #28:
- Codex TUI trust bootstrap beyond fail-fast blocked bundles.
- Codex TUI live-follow once trusted TUI launch is available.
- Deeper repeated OSS lab loops using
codex-execfanout plus active Observer snapshots.
- Local
Progress update for #28: the post-#40 OSS lab loop found and fixed a result-classification gap in PR #41.
Post-merge lab run on current main:
pnpm check-> 10 test files / 49 tests passed, build passed.pnpm mimetic -- doctor --json-> passed.pnpm mimetic -- watch --json --no-open --run-id watch-post-live-follow-main-> Observer rendered.pnpm mimetic -- lab oss --dry-run --json --no-open --run-id oss-dry-post-live-follow-main-> passed.pnpm mimetic -- lab oss-smoke --limit 4 --json --run-id oss-smoke-post-live-follow-main-> 4/4 disposable public clones passed.- Env-sourced live lab
oss-live-post-live-follow-main-> 3 lanes passed, 1 lane timed out waiting for remote bootstrap completion marker, 4/4 screenshots captured, bundle verified.
Finding:
- The mixed live result still returned
ok: trueand reviewcontract_proof_only, which made a timed-out live lane look too green.
PR #41 fix:
- Live OSS meta-lab terminal
failed,blocked, andtimed_outlanes now propagate into top-level JSONokand bundle review verdict. - Dry-run remains
contract_proof_only. - Missing-key live attempts remain command-successful
blockedevidence. - All-passed live terminal completions become review
pass.
Proof for PR #41:
pnpm vitest run tests/oss-lab.test.ts-> 9 tests passed.pnpm check-> 10 test files / 50 tests passed, build passed.pnpm public-surface:scan-> 72 candidate text files checked.git diff --check-> passed.
No raw remote logs, sandbox IDs, stream URLs, secrets, or target OSS mutations are included here.
PR: #41
PR #41 is merged to main as
025edbbf2bf5c300f09de90e8df2dbc5f0d70931.Merged slice:
- Live OSS meta-lab terminal
failed,blocked, andtimed_outlanes now propagate into top-level JSONokand bundle review verdict. - Dry-run remains
contract_proof_only. - Missing-key live attempts remain command-successful
blockedevidence. - All-passed live terminal completions become review
pass.
Proof:
pnpm vitest run tests/oss-lab.test.ts-> 9 tests passed.pnpm check-> 10 test files / 50 tests passed, build passed.pnpm public-surface:scan-> 72 candidate text files checked.git diff --check-> passed.
GitHub registered no CI checks for PR #41; local proof was the available merge gate. No raw remote logs, sandbox IDs, stream URLs, secrets, or target OSS mutations were included.
Next loop should rerun the live OSS lab on
025edbband confirm that any future timed-out lane is reported as non-green instead of neutral contract proof.- Live OSS meta-lab terminal
Post-PR #41 confirmation on fresh main
025edbb:pnpm vitest run tests/oss-lab.test.ts-> 9 tests passed.pnpm mimetic -- doctor --json-> passed.- Env-sourced live lab
oss-live-post-classifier-mainacrossdevelopit/mitt,lukeed/clsx,sindresorhus/is-plain-obj, andai/nanoid-> 4/4 lanes passed. pnpm mimetic -- verify --run oss-live-post-classifier-main --json-> 5/5 checks passed.pnpm mimetic -- watch --run oss-live-post-classifier-main --detach --no-open --json-> Observer rendered.- Metadata check: review verdict
pass, 4 passed simulation statuses, 4 passed stream completions, 4 bootstrap passed events, and 4 screenshot fallbacks captured.
This confirms the positive side of the classifier: all-passed live OSS terminal completions now produce
passrather than neutralcontract_proof_only.Remaining #28 work is now concentrated on Codex TUI trust bootstrap and true TUI live-follow after trust, plus further repeated OSS lab hardening as new failures emerge.
Progress update for #28: PR #42 moves the Codex TUI boundary from false preflight block to trusted launch with timeout evidence.
What changed:
- Codex workspace trust preflight now accepts an exact trusted project entry or an explicit trusted ancestor project entry in
$CODEX_HOME/config.toml. - Missing trust still fails closed before spawn and writes a blocked bundle.
- A new regression test exercises the default TUI command path with a fake
codexbinary onPATH, so preflight is not bypassed byMIMETIC_CODEX_ACTOR_COMMAND.
Proof:
pnpm vitest run tests/run.test.ts-> 12 tests passed.pnpm vitest run tests/run.test.ts tests/dogfood.test.ts-> 15 tests passed.pnpm check-> 10 test files / 51 tests passed, build passed.pnpm public-surface:scan-> 72 candidate text files checked.git diff --check-> passed.- Env-sourced real TUI proof
codex-tui-trusted-ancestor-real-proof-> no preflight block; actor spawned and then timed out at the actor timeout. pnpm mimetic -- verify --run codex-tui-trusted-ancestor-real-proof --json-> 5/5 checks passed.pnpm mimetic -- watch --run codex-tui-trusted-ancestor-real-proof --detach --no-open --json-> Observer rendered.- Metadata check:
actor.spawned,actor.prompt.submitted,actor.timeout; noactor.preflight.blocked.
This does not claim autonomous Codex TUI completion yet. Remaining #28 work: make the trusted TUI path produce a final verdict instead of timing out, and then add TUI live-follow after that.
PR: #42
- Codex workspace trust preflight now accepts an exact trusted project entry or an explicit trusted ancestor project entry in
PR #42 is merged to main as
55076a8f0fa3aa25d0f6394e526155af06efcc7e.Merged slice:
- Codex TUI trust preflight honors exact trusted project entries and explicit trusted ancestor project entries.
- Missing trust still blocks before spawn and writes a verifiable blocked bundle.
- Trusted launch now gets past the previous false preflight block.
Proof:
pnpm check-> 10 test files / 51 tests passed, build passed.pnpm public-surface:scan-> 72 candidate text files checked.git diff --check-> passed.- Remote CI passed on Node 22.14.0 and Node 24.
- Env-sourced real TUI proof
codex-tui-trusted-ancestor-real-proof-> no preflight block; actor spawned and timed out at the actor timeout. pnpm mimetic -- verify --run codex-tui-trusted-ancestor-real-proof --json-> 5/5 checks passed.pnpm mimetic -- watch --run codex-tui-trusted-ancestor-real-proof --detach --no-open --json-> Observer rendered.
Remaining #28 work is now narrower: make the trusted TUI path produce a final verdict instead of timing out, then add TUI live-follow after that.
Status update after merged PR #43 (
f61348a): the trusted Codex TUI autonomous completion slice is now green, but I am reopening this issue because live TUI Observer follow remains a separate open slice.What landed:
- exact Codex project-root trust is required for default TUI launch; ancestor-only trust is now blocked before spawn because the real Codex TUI still prompts internally;
- the local actor runner answers minimal terminal cursor/color queries, normalizes captured TUI output, and records sanitized evidence;
- TUI actor completion now uses a nonce-bearing final marker:
MIMETIC_ACTOR_VERDICT=<status> MIMETIC_ACTOR_NONCE=<run-nonce>; - the actor is terminated after the final marker instead of drifting to timeout;
- TUI
latest.jsonis published only after final run/review artifacts exist; - the TUI prompt is now read-only-sandbox aware, so it inspects committed config/existing evidence instead of trying write-producing commands.
Proof:
- PR Complete trusted Codex TUI actor runs #43 CI passed on Node 22.14.0 and Node 24.
- Local
pnpm checkpassed with 54 tests, typecheck, and build. pnpm public-surface:scanpassed: 72 candidate text files checked.pnpm mimetic -- doctor --jsonpassed.- Real env-backed Codex TUI proof passed with run id
codex-tui-readonly-real-proof:run --actor codex-tui --sims 1 --timeout-ms 240000returned ok true;verify --run codex-tui-readonly-real-proofpassed 5/5 checks;watch --run codex-tui-readonly-real-proof --detach --json --no-openreturned ok true;- sanitized metadata: review verdict pass, stream status passed, reason
actor reported passed verdict marker, duration 35066ms, transcript bytes 217067, nonce marker passed=true / blocked=false / failed=false.
Remaining for this issue:
- live Observer follow while the Codex TUI actor is still running;
- if desired, a TUI-specific fanout design beyond the current 1x TUI + 1-4x
codex-execfanout split.
No target OSS repos, GitHub issues, or production/private artifacts were mutated by this proof.
Final status after merged PR #44 (
4bdcc86): #28 acceptance is complete.What is now covered:
- real local 1x Codex TUI actor dogfood run without
--dry-run; - exact project-root trust preflight for the TUI actor;
- terminal startup responses, sanitized transcript capture, nonce-bearing final verdict markers, and marker-based actor shutdown;
- active-run TUI Observer snapshots while the actor is still running;
- final TUI Observer data refresh with transcript/verdict artifacts;
- completed bundle verification;
- 1-4 lane noninteractive
codex-execfanout from prior PR Add Codex exec fanout #39, which satisfies the “prove fanout or split after 1x” acceptance path.
PR #44 proof:
- CI passed on Node 22.14.0 and Node 24.
- Local
pnpm checkpassed with 54 tests, typecheck, and build. pnpm public-surface:scanpassed: 72 candidate text files checked.pnpm mimetic -- doctor --jsonpassed.
Real env-backed TUI live-follow proof, run id
codex-tui-live-follow-final-proof:- Active snapshot while actor was running:
- review verdict
contract_proof_only; - stream/completion status
running; - lifecycle and events included
actor.running; observer/observer-data.jsonstream statusrunning;latest.jsonpointed to the valid active run;- transcript artifact absent while active.
- review verdict
- Final result:
run --actor codex-tui --sims 1 --timeout-ms 240000returned ok true;verify --run codex-tui-live-follow-final-proofpassed 5/5 checks;watch --run codex-tui-live-follow-final-proof --detach --json --no-openreturned ok true;- sanitized metadata: review verdict pass, stream status passed, Observer stream status passed, reason
actor reported passed verdict marker, duration 44256ms, transcript bytes 193232, nonce marker passed=true / blocked=false.
Remaining boundaries are now documented as future scope, not #28 blockers: raw interactive terminal streaming and any TUI-specific fanout beyond the current 1x TUI plus 1-4x
codex-execsplit.No target OSS repos, GitHub issues, or production/private artifacts were mutated by this proof.
- real local 1x Codex TUI actor dogfood run without
Goal
Make
mimetic-clidogfood itself with real local Codex TUI actors and a live observer, starting from the committedmimetic/dogfood config.Current state
mimetic run --dry-runworks and produces public-safe synthetic bundles.mimetic watch --no-openrenders a static observer for a completed bundle.mimetic runwithout--dry-runcorrectly fails closed withMIMETIC_LIVE_RUN_UNIMPLEMENTED.Scope to spec first
.mimetic/.Public-safety requirements
Acceptance proof
pnpm mimetic:doctorpnpm mimetic:runruns a real local 1x Codex TUI dogfood actor without--dry-run.pnpm mimetic:watchopens or serves a live observer that updates during the run.pnpm mimetic:verify --run latestverifies the completed bundle.pnpm checkpasses.