Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion docs/codex-reuse.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,14 +68,17 @@ All reused components currently come from the [same pinned revision](upstream-lo

## Reuse decisions for managed execution

> **Status: suspended as an implementation directive.** Do not implement from this section while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved, and no safety requirement is relaxed. The text is retained unchanged for historical traceability.
> **Status: suspended as an implementation directive.** Do not implement from this section while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved, and no safety requirement is relaxed. The text is retained unchanged for historical traceability; the dated annotation on D3 below marks its DevGuard dependency statement as superseded on 2026-09-28, so that statement is no longer current.

DevGuard [design revision 1](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/design-revision-1.md) and its [ADR-006](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/planning/decisions.md) record how CS-RG treats Codex reuse. These are decisions for planned work; the connected adapters above are unchanged.

- **Finding.** The pinned high-level spawn functions of `codex-utils-pty` reap the child in their own task and keep only descriptors that are already inheritable, so they cannot carry a DevGuard-managed execution unchanged. This is a mismatch in the reap-ownership and descriptor-passing contracts, not a finding that Codex cannot be reused.
- **D1, `required` execution.** The default is a CodeSpace-owned Unix transport at the current pin. Before new code is written, record the reuse options and their contract differences in this order: an existing public API, an upstream candidate with the same contract, limited adaptation, then in-house code.
- **D2, legacy `off` backends.** The current PTY adapter and Tokio pipe path may stay for initial compatibility. CSRG-C09 decides, before final qualification, between integrating them and keeping a limited compatibility backend on recorded grounds.
- **D3, DevGuard.** No Codex dependency is added to DevGuard now. Its core and shared client stay Codex-free; reusing a low-level utility in a DevGuard execution or platform adapter is decided by the code it actually replaces, contract fit, dependency propagation, recovery path and requalification cost, and a feature name alone never adopts a dependency.

> **Dated annotation (2026-09-30).** Superseded on 2026-09-28 by the owner's dependency policy, now recorded normatively in [DevGuard design revision 2](https://github.com/novelKR/DevGuard/blob/9d223bbd3529d6996fb8ebabeedae5458d31f498/docs/design-revision-2.md): DevGuard may consume Codex and other external implementations behind declared adapters with reviewed, immutable pins. CodeSpace's generic resource client imports no Codex types, and CodeSpace's own pin process is unchanged.

- **`ProcessDriver`.** Codex's `ProcessDriver` is an optional candidate, not a default: at the pin its bridge skips lagged output and `ProcessHandle` terminates on Drop. It is adopted only once its output-loss, backpressure and Drop criteria are proven; otherwise CodeSpace uses its own output and handle abstractions.
- **Limited adaptation.** Permitted only for clearly separated execution mechanisms such as PTY allocation, terminal setup, resize and limited I/O helpers. It is never permitted for `codex-core` product semantics, session authority, the agent loop, broad crate copies or duplication that evades dependency checks. Each adaptation records its provenance (source repository, full SHA and file path), scope, intentional divergence from upstream, tests, and its re-examination and removal conditions; [upstream updates](upstream-update.md) re-examine it on each pin change. Copying crates to hide dependencies from the checks remains forbidden.
- **Pin.** Revision 1 keeps pin `6b9826e3aa83b1a5947db50f4332cb9c65f1b340`. A pin change is a separate decision based on verification, not part of adopting a newer API.
5 changes: 4 additions & 1 deletion docs/ko/codex-reuse.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,14 +86,17 @@ Linux 샌드박스 도우미는 실행 파일만 제공합니다. `codespace-lin

## 관리 실행의 재사용 결정

> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 이 절을 근거로 구현하지 않습니다. 대체 구조는 승인되지 않았고, 어떤 안전 요구도 완화되지 않습니다. 내용은 이력 추적을 위해 바꾸지 않고 남깁니다.
> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 이 절을 근거로 구현하지 않습니다. 대체 구조는 승인되지 않았고, 어떤 안전 요구도 완화되지 않습니다. 내용은 이력 추적을 위해 바꾸지 않고 남깁니다. 아래 D3의 날짜가 붙은 주석은 그 DevGuard 의존 서술이 2026-09-28에 대체되었음을 표시하며, 그 서술은 더 이상 현행이 아닙니다.

DevGuard [설계 개정 1](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/ko/design-revision-1.md)과 [ADR-006](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/ko/planning/decisions.md)은 CS-RG에서 Codex 재사용을 다루는 방식을 기록합니다. 계획된 작업에 대한 결정이며 위에서 설명한 연결 어댑터는 바뀌지 않습니다.

- **확인 결과.** 고정 버전 `codex-utils-pty`의 고수준 spawn 함수는 자체 작업에서 자식 프로세스를 reap하고 이미 상속 가능한 descriptor만 유지하므로, DevGuard가 관리하는 실행을 그대로 처리할 수 없습니다. 이는 reap 소유권과 descriptor 전달 계약의 불일치이며 Codex를 재사용할 수 없다는 결론이 아닙니다.
- **D1, `required` 실행.** 기본값은 현재 고정 버전에서 CodeSpace가 소유하는 Unix 전송입니다. 새 코드를 작성하기 전에 기존 공개 API, 같은 계약을 제공하는 업스트림 후보, 제한적 adaptation, 자체 구현 순서로 재사용 가능성과 계약 차이를 기록합니다.
- **D2, 기존 `off` 백엔드.** 현재 PTY 어댑터와 Tokio 파이프 경로는 초기 호환을 위해 유지할 수 있습니다. 최종 qualification 전에 CSRG-C09가 통합할지, 근거를 기록한 제한적 호환 백엔드로 유지할지 결정합니다.
- **D3, DevGuard.** 지금은 DevGuard에 Codex 의존성을 추가하지 않습니다. DevGuard의 핵심 계층과 공유 client는 Codex 없이 유지합니다. DevGuard 실행·플랫폼 어댑터에서 저수준 유틸리티를 재사용할지는 실제로 대체하는 코드, 계약 적합성, 의존성 전파, 복구 경로, 재검증 비용으로 판단하며 기능 이름만으로 의존성을 도입하지 않습니다.

> **날짜가 붙은 주석(2026-09-30).** 소유자의 의존성 정책이 2026-09-28에 이를 대체했으며, 그 정책은 이제 [DevGuard 설계 개정 2](https://github.com/novelKR/DevGuard/blob/9d223bbd3529d6996fb8ebabeedae5458d31f498/docs/ko/design-revision-2.md)에 규범으로 기록되어 있습니다. DevGuard는 검토된 불변 고정 버전을 가진 선언된 어댑터 뒤에서 Codex와 그 밖의 외부 구현을 소비할 수 있습니다. CodeSpace의 범용 자원 client는 Codex 타입을 가져오지 않으며, CodeSpace 자체의 고정 버전 절차는 바뀌지 않습니다.

- **`ProcessDriver`.** Codex의 `ProcessDriver`는 기본 선택이 아닌 선택적 후보입니다. 고정 버전에서 그 bridge는 뒤처진 출력을 건너뛰고 `ProcessHandle`은 Drop 시 프로세스를 종료합니다. 출력 손실, 역압, Drop 기준을 충족한다고 증명된 뒤에만 도입하며, 그렇지 않으면 CodeSpace 자체의 출력·핸들 추상화를 사용합니다.
- **제한적 adaptation.** PTY 할당, 터미널 설정, 크기 변경, 제한된 입출력 도우미처럼 명확히 분리된 실행 기능에만 허용합니다. `codex-core` 제품 의미, 세션 권한, 에이전트 루프, 넓은 crate 복사, 의존성 검사를 피하려는 중복에는 허용하지 않습니다. 각 adaptation은 출처(소스 저장소, full SHA, 파일 경로), 가져온 범위, 업스트림과 의도적으로 다른 동작, 테스트, 재검토·제거 조건을 기록하며 [업스트림 업데이트](upstream-update.md)에서 고정 버전을 바꿀 때마다 다시 검토합니다. 검사에서 의존성을 숨기기 위해 crate를 복사하는 것은 계속 금지합니다.
- **고정 버전.** 설계 개정 1은 `6b9826e3aa83b1a5947db50f4332cb9c65f1b340`을 유지합니다. 고정 버전 변경은 새 API 도입에 포함되지 않는, 검증에 근거한 별도 결정입니다.
10 changes: 9 additions & 1 deletion docs/ko/upstream-update.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ SHA와 패치 테스트만 확인하며 전체 검증 명령을 대체하지 않

## 향후 crate와 백엔드의 경계

> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 아래에서 언급한 CS-RG의 새 실행 backend 계획을 구현하지 않습니다. 대체 구조는 승인되지 않았습니다. 이 절의 의존성과 CI 규칙은 그대로입니다.
> **상태: 구현 지시로서 효력 중지.** CS-RG 통합 경계 재검증이 끝날 때까지 아래에서 언급한 CS-RG의 새 실행 backend 계획을 구현하지 않습니다. 대체 구조는 승인되지 않았습니다. 이 절의 의존성과 CI 규칙은 그대로입니다. 다만 이 절 끝에 2026-09-30 날짜로 추가한 항목은 DevGuard binding의 Codex 정체성에 대한 DevGuard 설계 개정 2의 규칙을 기록합니다.

CS-RG는 DevGuard 자원 client crate와 새 실행 백엔드를 계획합니다
([CS-RG 작업 패키지](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/ko/planning/milestones/CS-RG.md)의
Expand Down Expand Up @@ -127,3 +127,11 @@ lockfile, `PRODUCTS`(분리된 workspace이면 `ADAPTERS`도), 직접 Codex 키
`FORBIDDEN`, `RUNNER_FORBIDDEN`, 전체 그래프 검증이나 다른 검사를 제거하거나 좁히지
않습니다. 계획된 자원 client는 간접 Codex 의존성을 가져오면 안 되며, DevGuard
client 타입은 공개 MCP 타입에 들어가지 않습니다.

*2026-09-30 추가,
[DevGuard 설계 개정 2](https://github.com/novelKR/DevGuard/blob/9d223bbd3529d6996fb8ebabeedae5458d31f498/docs/ko/design-revision-2.md#33-실행-파일-정체성)에서:*
CodeSpace 실행 파일에 링크되는 DevGuard binding은 이 저장소의 gitlink를 통해 Codex를
소비하므로, 그 실행 파일은 검토된 Codex 소스 정체성을 하나만 유지합니다. 제품 root
안에서 각 `codex-*` package를 gitlink 경로에서만 받아들이는 실행 파일 단일 정체성
검사는 DevGuard crate를 CodeSpace graph에 처음 넣는 PR에서 추가됩니다. 그때까지 이
규칙은 실행 가능한 검사가 아니라 문서 정책입니다.
8 changes: 4 additions & 4 deletions docs/translations.json
Original file line number Diff line number Diff line change
Expand Up @@ -594,8 +594,8 @@
"핀-6b9826e의-후보",
"핵심-대-어댑터"
],
"source_sha256": "f1d2a492ec7b13aad3e2cc9aa29bdf7a1521df485df5474101249b092b604e1c",
"translation_sha256": "446c4ac2183b0a307bf183656b2283994c66cf0ada0a0398fa8071614a4f40f4"
"source_sha256": "d7f313bf569e680832371c35790f591495a2b33d781bb1f6e789477267132b2d",
"translation_sha256": "a94df107ad3e3d5be1a6f146ab282af0d46ac6b85e03bf0701ef6770998a70a2"
},
{
"id": "upstream-lock",
Expand Down Expand Up @@ -665,8 +665,8 @@
"향후-crate와-백엔드의-경계",
"후보-검토"
],
"source_sha256": "a17d0070fc199006e4ca38b23a0168cc565b0fde0c0ee5fb9bf6b33f7ad1ba4d",
"translation_sha256": "14b1e931b267d73d89bc32434ec664dea58abaf5175bdc79d3a2a72245d00db9"
"source_sha256": "51748e34ef4a224843f800b579707a7912deb2ace6d712e86fd79b7d6035f9e1",
"translation_sha256": "69d7226a096ae2d641ede6aa177f268e6f9a3240382f2d017546dc6384dd957d"
},
{
"id": "documentation",
Expand Down
11 changes: 10 additions & 1 deletion docs/upstream-update.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@ checks only SHA and patch tests; it is not a complete qualification command.

## Boundaries for future crates and backends

> **Status: suspended as an implementation directive.** The CS-RG plan for new execution backends mentioned below must not be implemented while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved. The dependency and CI rules in this section are unchanged.
> **Status: suspended as an implementation directive.** The CS-RG plan for new execution backends mentioned below must not be implemented while the CS-RG integration-boundary revalidation is pending. No replacement architecture has been approved. The dependency and CI rules in this section are unchanged; a dated addition of 2026-09-30 at the end of this section records DevGuard design revision 2's rule for a DevGuard binding's Codex identity.

CS-RG plans a DevGuard resource client crate and new execution backends
([CS-RG work packages](https://github.com/novelKR/DevGuard/blob/d4981b4c241cff42687f5c2c681b583c7847776e/docs/planning/milestones/CS-RG.md),
Expand Down Expand Up @@ -129,3 +129,12 @@ every leg that builds it; and the tests that cover it. It never removes or
narrows `FORBIDDEN`, `RUNNER_FORBIDDEN`, full-graph validation or any other
check. The planned resource client must bring no transitive Codex dependency,
and DevGuard client types stay out of public MCP types.

*Added 2026-09-30, from
[DevGuard design revision 2](https://github.com/novelKR/DevGuard/blob/9d223bbd3529d6996fb8ebabeedae5458d31f498/docs/design-revision-2.md#33-executable-identity):*
a DevGuard binding linked into a CodeSpace executable consumes Codex through
this repository's gitlink, so that executable keeps one reviewed Codex source
identity. The executable single-identity check, which accepts each `codex-*`
package only from the gitlink path within a product root, arrives with the
first PR that puts a DevGuard crate into a CodeSpace graph. Until then this rule
is documentation policy, not an executable gate.
Loading