Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

# Architecture

> **Status: suspended as an implementation directive.** The target CS-RG structure under Planned execution coordination must not be implemented; the current behavior described there and the rest of this page are unaffected. This is pending the CS-RG integration-boundary revalidation, an owner-directed review of the CodeSpace integration plan; it is not a work unit. No replacement architecture has been approved; the owner decides after reviewing its results. This notice suspends directives only and relaxes no safety requirement. The text below is retained unchanged for historical traceability.

[English](architecture.md) | [한국어](ko/architecture.md)

CodeSpace separates the agent's decisions from workspace execution. The MCP server owns authorization and operation records. A Runner performs already-authorized filesystem and process work. Codex libraries stay behind adapters.
Expand Down Expand Up @@ -53,6 +55,8 @@ MCP request completion does not end a managed process. Clients continue with its

## Planned execution coordination

> **Status: suspended as an implementation directive.** The target CS-RG structure in this section must not be implemented while the CS-RG integration-boundary revalidation is pending; the current behavior paragraph describes implemented code. No replacement architecture has been approved. The text is retained unchanged for historical traceability.

**Current behavior.** The Runner's process supervisor starts pipe commands with Tokio (`tokio::process`) and `tty: true` commands through the `codespace-pty` adapter over Codex `codex-utils-pty` at the [pinned revision](upstream-lock.md) `6b9826e3aa83b1a5947db50f4332cb9c65f1b340` (`rust-v0.154.0`). The pinned PTY spawn reaps its child internally. On the pipe path, the exit waiter, the timeout task and the kill request each call `try_wait`.

**Target CS-RG structure.** DevGuard [design revision 1](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/design-revision-1.md) plans one Runner coordination layer that CodeSpace owns for every execution: execution identity, the link between approval and execution, state transitions, timeout, termination requests, output recording and cleanup coordination. Platform differences stay behind a narrow backend boundary: child creation, terminal setup, I/O wiring, exit observation and the actual reap. None of this is implemented, and the names below are design concepts, not current APIs. DevGuard client types and Codex types stay out of public MCP types.
Expand Down
4 changes: 4 additions & 0 deletions docs/codex-reuse.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

# How CodeSpace uses Codex

> **Status: suspended as an implementation directive.** The managed-execution decisions under Reuse decisions for managed execution, including the default of a CodeSpace-owned Unix transport for `required` execution and DevGuard's planned legacy-backend decision, must not be implemented. This is pending the CS-RG integration-boundary revalidation, an owner-directed review of the CodeSpace integration plan; it is not a work unit. No replacement architecture has been approved; the owner decides after reviewing its results. This notice suspends directives only and relaxes no safety requirement. The text below is retained unchanged for historical traceability.

[English](codex-reuse.md) | [한국어](ko/codex-reuse.md)

CodeSpace uses selected libraries from a pinned Codex checkout to implement execution. The external agent still plans and generates code. CodeSpace owns MCP, workspace permissions, operation identity, and process management.
Expand Down Expand Up @@ -66,6 +68,8 @@ All reused components currently come from the [same pinned revision](upstream-lo

## Reuse decisions for managed execution

> **Status: suspended as an implementation directive.** Do not implement from this section while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved, and no safety requirement is relaxed. The text is retained unchanged for historical traceability.

DevGuard [design revision 1](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/design-revision-1.md) and its [ADR-006](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/planning/decisions.md) record how CS-RG treats Codex reuse. These are decisions for planned work; the connected adapters above are unchanged.

- **Finding.** The pinned high-level spawn functions of `codex-utils-pty` reap the child in their own task and keep only descriptors that are already inheritable, so they cannot carry a DevGuard-managed execution unchanged. This is a mismatch in the reap-ownership and descriptor-passing contracts, not a finding that Codex cannot be reused.
Expand Down
8 changes: 8 additions & 0 deletions docs/devguard-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

# DevGuard integration roadmap

> **Status: suspended as an implementation directive.** The CS-RG work order, the planned consumer boundary and the design revision 1 references on this page must not be implemented as described; current status and prerequisites are unaffected. This is pending the CS-RG integration-boundary revalidation, an owner-directed review of the CodeSpace integration plan; it is not a work unit. No replacement architecture has been approved; the owner decides after reviewing its results. This notice suspends directives only and relaxes no safety requirement. The text below is retained unchanged for historical traceability.

[English](devguard-integration.md) | [한국어](ko/devguard-integration.md)

[DevGuard](https://github.com/novelKR/DevGuard) is an independent resource authority for development workloads, licensed under Apache-2.0 like CodeSpace. Its approved integration path adds a shared admission and accounting layer while CodeSpace keeps process ownership, PTY, input/output, permissions, approval holds and workspace coordination.
Expand Down Expand Up @@ -33,6 +35,8 @@ DG-1 is delivered as six sequential PR groups, each reviewed, checked on its cur

## CS-RG work order

> **Status: suspended as an implementation directive.** Do not implement from this section while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved, and no safety requirement is relaxed. The text is retained unchanged for historical traceability.

Design revision 1 plans CS-RG as 10 work units in six logical PR groups. The IDs are DevGuard planning labels, not commits or GitHub PR numbers, and no unit is implemented.

| Proposed group | Units | Planned content |
Expand Down Expand Up @@ -67,6 +71,8 @@ Every participating consumer on the actual execution host shares one normal auth

## Consumer boundary

> **Status: suspended as an implementation directive.** Do not implement from this section while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved, and no safety requirement is relaxed. The text is retained unchanged for historical traceability.

Development consumption uses DevGuard's independent CLI, `devguard exec` from DG-1, to govern builds and tests in both repositories. Product consumption belongs in the Runner on the actual execution host; it does not turn DevGuard into a process or PTY broker. The current UDS worker is on the same host as the gateway, not a remote worker.

The execution-owning **Runner registers once**. InProcess registers with the Gateway PID; UDS registers from the worker PID. One static control reservation covers both Gateway and Runner costs. DG-1 has no separate `service-exec` path: the Gateway passes the consumer credential to a UDS worker through `CredentialHandoff`, InProcess reads it directly, and each bounded session registers that same instance again. Service/subordinate-worker registration is deferred until multiple Runners or shared service reservations require it.
Expand Down Expand Up @@ -97,6 +103,8 @@ Runner or host loss remains uncertain until actual termination is established. P

## Design revision 1 references

> **Status: suspended as an implementation directive.** Do not implement from this section while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved, and no safety requirement is relaxed. The text is retained unchanged for historical traceability.

These immutable links identify the documents that apply design revision 1. They are design provenance, not a runtime client pin.

| Document at `d4981b4` (English) | Use |
Expand Down
4 changes: 4 additions & 0 deletions docs/execution-substrate.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

# Execution contracts

> **Status: suspended as an implementation directive.** The planned managed-execution contracts on this page must not be implemented as described; the implemented contracts are unaffected. This is pending the CS-RG integration-boundary revalidation, an owner-directed review of the CodeSpace integration plan; it is not a work unit. No replacement architecture has been approved; the owner decides after reviewing its results. This notice suspends directives only and relaxes no safety requirement. The text below is retained unchanged for historical traceability.

[English](execution-substrate.md) | [한국어](ko/execution-substrate.md)

An external Agent Loop owns planning, model context, and completion decisions. CodeSpace supplies deterministic tool operations and observable state. Adding an execution feature must not require an internal model call or a Codex agent session.
Expand Down Expand Up @@ -72,6 +74,8 @@ When the operator sets workspace `approvals` to `confirm`, a policy-allowed `app

## Planned managed-execution contracts

> **Status: suspended as an implementation directive.** Do not implement from this section while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved, and no safety requirement is relaxed. The text is retained unchanged for historical traceability.

The rules in this section are the **target** CS-RG contracts from DevGuard [design revision 1](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/design-revision-1.md) and its [CodeSpace integration specification](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/planning/codespace-integration.md). None is implemented; current behavior is described in the sections above, and the planned structure in [architecture](architecture.md).

**One-time preparation.** A planned `PreparedExecution` owns the execution identity, command meaning, execution slot, workspace occupancy, resource state and original deadline. Its `LaunchPlan` is consumed exactly once or cancelled. It is never cloned or rebuilt from stored argv, there is no automatic re-execution, and the Drop of a cancelled task is not assumed to return a resource lease.
Expand Down
4 changes: 4 additions & 0 deletions docs/ko/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@

# 아키텍처

> **상태: 구현 지시로서 효력 중지.** ‘계획된 실행 조정 구조’ 절의 목표 CS-RG 구조는 구현하지 않습니다. 그 절의 현재 동작 설명과 이 페이지의 나머지는 영향이 없습니다. CodeSpace 통합 계획에 대해 소유자가 지시한 검토인 CS-RG 통합 경계 재검증(작업 단위가 아닙니다)이 끝날 때까지 적용됩니다. 대체 구조는 승인되지 않았으며, 소유자가 재검증 결과를 검토한 뒤 결정합니다. 이 표기는 지시의 효력만 중지하며 어떤 안전 요구도 완화하지 않습니다. 아래 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.

[English](../architecture.md) | [한국어](architecture.md)

CodeSpace는 에이전트의 판단과 작업 공간의 실행을 분리합니다. MCP 서버가 권한과 작업 기록을 관리하고, Runner가 허용된 파일·프로세스 작업을 수행합니다. Codex 라이브러리는 어댑터 뒤에서 사용합니다.
Expand Down Expand Up @@ -60,6 +62,8 @@ MCP 요청이 끝나도 관리 중인 프로세스는 유지됩니다. 클라이

## 계획된 실행 조정 구조

> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 이 절의 목표 CS-RG 구조를 구현하지 않습니다. 현재 동작 문단은 구현된 코드를 설명합니다. 대체 구조는 승인되지 않았습니다. 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.

**현재 동작.** Runner의 프로세스 관리는 파이프 명령을 Tokio(`tokio::process`)로 시작하고, `tty: true` 명령은 [고정 버전](upstream-lock.md) `6b9826e3aa83b1a5947db50f4332cb9c65f1b340`(`rust-v0.154.0`)의 Codex `codex-utils-pty` 위에 있는 `codespace-pty` 어댑터로 시작합니다. 고정 버전의 PTY spawn은 자식 프로세스를 내부에서 reap합니다. 파이프 경로에서는 종료 대기, 제한 시간 작업, 종료 요청이 각각 `try_wait`를 호출합니다.

**CS-RG 목표 구조.** DevGuard [설계 개정 1](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/ko/design-revision-1.md)은 모든 실행에 대해 CodeSpace가 소유하는 Runner 조정 계층 하나를 계획합니다. 이 계층은 실행 식별자, 승인과 실행의 연결, 상태 전이, 제한 시간, 종료 요청, 출력 기록, 정리 조정을 담당합니다. 플랫폼별 차이인 자식 프로세스 생성, 터미널 설정, 입출력 연결, 종료 관측, 실제 reap은 좁은 백엔드 경계 뒤에 둡니다. 이 구조는 구현되지 않았으며 아래 이름은 현재 API가 아니라 설계 개념입니다. DevGuard client 타입과 Codex 타입은 공개 MCP 타입에 들어가지 않습니다.
Expand Down
4 changes: 4 additions & 0 deletions docs/ko/codex-reuse.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@

# CodeSpace의 Codex 재사용 범위

> **상태: 구현 지시로서 효력 중지.** ‘관리 실행의 재사용 결정’ 절의 결정, 곧 `required` 실행의 기본값을 CodeSpace 소유 Unix transport로 둔 결정과 DevGuard가 계획한 legacy backend 결정은 구현하지 않습니다. CodeSpace 통합 계획에 대해 소유자가 지시한 검토인 CS-RG 통합 경계 재검증(작업 단위가 아닙니다)이 끝날 때까지 적용됩니다. 대체 구조는 승인되지 않았으며, 소유자가 재검증 결과를 검토한 뒤 결정합니다. 이 표기는 지시의 효력만 중지하며 어떤 안전 요구도 완화하지 않습니다. 아래 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.

[English](../codex-reuse.md) | [한국어](codex-reuse.md)

CodeSpace는 특정 버전에 고정한 Codex 소스의 실행 라이브러리를 선택적으로 사용합니다. 계획과 코드 생성은 외부 에이전트가 담당합니다. MCP, 작업 공간 권한, 작업 식별자, 프로세스 관리는 CodeSpace가 담당합니다.
Expand Down Expand Up @@ -84,6 +86,8 @@ Linux 샌드박스 도우미는 실행 파일만 제공합니다. `codespace-lin

## 관리 실행의 재사용 결정

> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 이 절을 근거로 구현하지 않습니다. 대체 구조는 승인되지 않았고, 어떤 안전 요구도 완화되지 않습니다. 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.

DevGuard [설계 개정 1](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/ko/design-revision-1.md)과 [ADR-006](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/ko/planning/decisions.md)은 CS-RG에서 Codex 재사용을 다루는 방식을 기록합니다. 계획된 작업에 대한 결정이며 위에서 설명한 연결 어댑터는 바뀌지 않습니다.

- **확인 결과.** 고정 버전 `codex-utils-pty`의 고수준 spawn 함수는 자체 작업에서 자식 프로세스를 reap하고 이미 상속 가능한 descriptor만 유지하므로, DevGuard가 관리하는 실행을 그대로 처리할 수 없습니다. 이는 reap 소유권과 descriptor 전달 계약의 불일치이며 Codex를 재사용할 수 없다는 결론이 아닙니다.
Expand Down
8 changes: 8 additions & 0 deletions docs/ko/devguard-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

# DevGuard 결합 로드맵

> **상태: 구현 지시로서 효력 중지.** 이 페이지의 ‘CS-RG 작업 순서’, ‘소비 경계’, ‘설계 개정 1 참조’ 절은 적힌 대로 구현하지 않습니다. 현재 상태와 선행 조건은 영향이 없습니다. CodeSpace 통합 계획에 대해 소유자가 지시한 검토인 CS-RG 통합 경계 재검증(작업 단위가 아닙니다)이 끝날 때까지 적용됩니다. 대체 구조는 승인되지 않았으며, 소유자가 재검증 결과를 검토한 뒤 결정합니다. 이 표기는 지시의 효력만 중지하며 어떤 안전 요구도 완화하지 않습니다. 아래 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.

[English](../devguard-integration.md) | [한국어](devguard-integration.md)

[DevGuard](https://github.com/novelKR/DevGuard)는 개발 작업의 자원을 중앙에서 관리하는 독립 시스템이며 CodeSpace와 동일한 Apache-2.0 라이선스를 적용한다. 승인된 결합 경로에 따라 실행 허용과 자원 회계를 공통 계층에 맡기고, CodeSpace는 프로세스 소유권, PTY, 입출력, 권한, 승인 hold와 workspace 조정을 계속 담당한다.
Expand Down Expand Up @@ -33,6 +35,8 @@ DG-1은 6개 PR 묶음을 순차 전달한다. 각 PR의 검토, 현재 head 검

## CS-RG 작업 순서

> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 이 절을 근거로 구현하지 않습니다. 대체 구조는 승인되지 않았고, 어떤 안전 요구도 완화되지 않습니다. 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.

설계 개정 1은 CS-RG를 6개 논리 PR 묶음의 10개 작업 단위로 계획한다. ID는 DevGuard 계획 라벨이며 commit이나 GitHub PR 번호가 아니다. 구현을 마친 단위는 없다.

| 예정 묶음 | 단위 | 계획 내용 |
Expand Down Expand Up @@ -67,6 +71,8 @@ CSRG-C09는 최종 qualification 전에 반드시 내려야 하는 결정이다.

## 소비 경계

> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 이 절을 근거로 구현하지 않습니다. 대체 구조는 승인되지 않았고, 어떤 안전 요구도 완화되지 않습니다. 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.

개발 과정에서는 DG-1에서 제공한 독립 CLI인 `devguard exec`로 두 저장소의 빌드와 테스트를 관리한다. 제품 런타임의 소비 지점은 실제 실행 호스트의 Runner다. DevGuard가 프로세스나 PTY 관제를 대신 소유하지 않는다. 현재 UDS worker는 gateway와 같은 호스트에서 실행되며 원격 worker가 아니다.

실행을 소유하는 **Runner가 한 번만 등록**한다. InProcess는 Gateway PID, UDS는 worker PID로 등록한다. 정적 제어 예약 하나에 Gateway와 Runner 비용을 함께 포함한다. DG-1에는 별도의 `service-exec` 경로가 없다. Gateway는 `CredentialHandoff`로 UDS worker에 소비자 자격을 전달하고 InProcess는 이를 직접 읽으며, 상한이 있는 각 세션은 같은 인스턴스를 다시 등록한다. 서비스·하위 worker 등록 모델은 여러 Runner나 공유 서비스 예약이 실제로 필요해질 때 재검토한다.
Expand Down Expand Up @@ -97,6 +103,8 @@ Runner나 호스트 손실은 실제 종료가 확인될 때까지 불확실 상

## 설계 개정 1 참조

> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 이 절을 근거로 구현하지 않습니다. 대체 구조는 승인되지 않았고, 어떤 안전 요구도 완화되지 않습니다. 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.

아래 고정 링크는 설계 개정 1을 반영한 문서를 가리킨다. 설계 출처이며 런타임 client pin이 아니다.

| `d4981b4`의 한국어 대응 문서 | 용도 |
Expand Down
Loading
Loading