Launch the rehearsal through Codex CLI on Linux
Type: types/instruction.md
Run one supplied rehearsal prompt in an isolated Codex CLI process and retain its execution evidence.
The orchestrator loads this branch from test-installed-commonplace.md only
when its selected runtime is Codex CLI on Linux. Keep the parent procedure's
scope, budgets, scenario selection, and assessment in force. This branch
supplies launch mechanics; it does not select stages or assign verdicts.
Installation-stage boundary
Stage 0 uses scripts/run_isolated_codex.py --access installation. The outer
Bubblewrap namespace supplies its filesystem boundary: the source is read-only;
project, tool, executable, cache, and build directories are writable; the real
checkout and evaluator inputs remain hidden. Codex runs with its inner sandbox
set to danger-full-access only in this outer namespace. Its ordinary
workspace-write sandbox protects .agents/ and prevents init from installing
skill stubs. Never use this installation mode outside the helper's outer sandbox.
Supply a native uv executable with --uv-binary. If that executable requires a
separate system runtime, mount it read-only using --uv-runtime; do not pass a
personal or project directory. For this host's snap installation, these are
/snap/astral-uv/current/bin/uv and /snap/core24/current. The probe checks uv,
Python, and Codex startup, source immutability, hidden paths, writable output
directories, and creation of .agents/skills/. It requires no Commonplace
installation and removes its temporary probe files.
python3 scripts/run_isolated_codex.py --run-dir <run> --record 0-exec --access installation --uv-binary <native-uv> --model <model> --effort medium --timeout 900 --prompt-file <run>/inputs/0.txt
After installation passes, use workspace-write for editing stages and
read-only for answer stages. Those modes restore the inner Codex sandbox,
hide source/build/cache inputs, and make installed tools immutable.
Prepare the launcher
Use the source checkout's scripts/run_isolated_codex.py. The orchestrator
invokes it; test agents never load it. Use run-directory names project/,
tools/, bin/, source/, cache/, tmp/, fixtures/, inputs/, and records/. Keep prompts and
evaluator evidence outside project/. Choose a unique record name on every
call; the helper refuses to overwrite an existing record.
The stage-0 runtime must supply UV_TOOL_DIR=<run>/tools,
UV_TOOL_BIN_DIR=<run>/bin, UV_CACHE_DIR=<run>/cache, and
TMPDIR=<run>/tmp. Provide /usr/bin/python3 as the installation interpreter
so it remains available inside the post-installation sandbox. The snapshot pack needs no
capture-tool installation. Do not expose developer tool environments to
supply missing commands.
Launch one isolated process
run_isolated_codex.py requires Bubblewrap with working user namespaces and a
native Codex distribution. It detects the npm-installed distribution, or takes
--codex-vendor <directory-containing-bin/codex>. Verify the CLI supports the
helper's flags; the initial implementation targets version 0.156.1.
After the installation agent completes stage 0, probe the later-stage boundary.
This probe starts commonplace-validate; it cannot run before installation:
python3 scripts/run_isolated_codex.py --run-dir <run> --record preflight --access workspace-write --probe-only
Write only your selected stage prompt to <run>/inputs/1.txt. Then launch,
substituting your chosen record name, access mode, and remaining time allowance:
python3 scripts/run_isolated_codex.py --run-dir <run> --record 1-exec --access workspace-write --model <model> --effort medium --timeout 900 --prompt-file <run>/inputs/1.txt
Use --access read-only for answer stages. Access mode and timeout are explicit
inputs; the helper chooses neither from scenario content. Each launch probes
hidden paths, denied tool-directory writes, project write mode, and executable
startup before sending the prompt. Do not bypass a failed probe.
Saved CLI authentication is mounted read-only by default. Select --auth env
to use CODEX_API_KEY or OPENAI_API_KEY from the supervisor environment.
The helper does not copy credentials into records. The launcher shares its
caller's network boundary. Before launching, use available runtime evidence
to determine whether the outer sandbox permits model-service access. If it
disables networking, obtain the required outer execution approval; the child
network setting cannot override that restriction. Keep Bubblewrap isolation
in place. Do not add a separate model conversation or source-network test.
Classify authentication failure as a runtime blocker, not a Commonplace
failure. A successful codex --version probe does not verify API access.
If model discovery or workspace routing fails before a response, retain the
failed trace. When the outer network restriction can be resolved with approval,
verify that the project is unchanged and retry the same prompt in a fresh
session with a new record name, within the remaining time budget. Otherwise
report a runtime-connectivity blocker. Record the retry as runtime setup,
separately from the stage's substantive outcome.
The process receives separate filesystem and process namespaces containing
system binaries/certificates, Codex, read-only installed tools, and the project.
The original HOME and CODEX_HOME values remain intact, with fresh filesystem
contents apart from selected authentication and this invocation's session logs.
The checkout and disposable source/build/cache directories, personal
instructions/configuration/memory/skills, evaluator
files, and prior transcripts are not mounted. Codex starts a fresh
exec --ignore-user-config session with memory, plugins, apps, hooks, and
external browser/computer integrations disabled. Project skills and worker
delegation remain available.
The helper writes prompt.txt, isolation.json, launch.json, trace.jsonl,
stderr.txt, and execution.json under records/<record>/. Execution metadata
contains the process exit code, timeout and interruption flags, received stop
signal, and elapsed seconds. Send SIGINT or SIGTERM to stop the launcher; it
terminates the child process group and retains partial evidence. SIGKILL
cannot produce final metadata; recover state under the parent procedure. Launch or
probe exceptions produce error.json. These are process facts, not stage
verdicts. Interpret error events and missing responses in the raw trace even
when the process exits 0.
The initially empty records/<record>/sessions/ is mounted at Codex's session
log path. Audit these logs for model identity, loaded instructions, worker
launch settings and parent/child relationships. Workers can see the current
invocation's runtime logs; earlier logs and evaluator files remain unmounted.
Do not use --ephemeral, which suppresses these audit records.
Network access is shared with the caller for model API calls. Policy inputs are local snapshots; no fixture server is needed. This helper establishes filesystem/session isolation. If the test needs network isolation or another OS, use a separately verified launcher and record its boundary; otherwise report that runtime as unsupported.