diff --git a/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java b/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java index c1816df..3f3b8d9 100644 --- a/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java +++ b/bridged/src/main/java/dev/ltms/bridged/config/BridgedConfig.java @@ -126,6 +126,12 @@ public record BridgedConfig( public static final String KIND_CLAUDE_CODE = "claude-code"; /** Peer kind spawned by the opencode adapter (CB-402). */ public static final String KIND_OPENCODE = "opencode"; + /** + * Peer kind spawned by the Codex adapter (CB-528). Like {@link #KIND_OPENCODE} it carries + * its own argv and never inherits the Claude binary, and it sits outside the + * {@code ANTHROPIC_BASE_URL} subscription guard because Codex has no such seam. + */ + public static final String KIND_CODEX = "codex"; public Worker { // A claude-code worker defaults its launch command to `claude`; other kinds carry their own diff --git a/bridged/src/main/java/dev/ltms/bridged/worker/CodexHome.java b/bridged/src/main/java/dev/ltms/bridged/worker/CodexHome.java new file mode 100644 index 0000000..52cba32 --- /dev/null +++ b/bridged/src/main/java/dev/ltms/bridged/worker/CodexHome.java @@ -0,0 +1,48 @@ +package dev.ltms.bridged.worker; + +import dev.ltms.bridged.config.BridgedConfig; + +import java.nio.file.Path; + +/** + * Provisions an isolated {@code CODEX_HOME} for one Codex peer (CB-528). + * + *
Codex reads everything from {@code CODEX_HOME} — its config, credentials, sessions, + * skills, plugins, and state. Pointing a peer at the operator's own {@code ~/.codex} would give it + * the operator's tool surface and let it write into the operator's session history, which is the + * same class of failure CB-525 exists to prevent on the Claude side. So every peer gets its own + * directory, and this is the seam that builds it. + * + *
It is an interface rather than a method on the launcher for two reasons: provisioning is + * filesystem work with its own failure modes (a missing credential is the most common, and it + * surfaces as an opaque {@code 401} from Codex rather than a spawn error), and keeping it separate + * lets the launcher be tested without touching a real home directory. + * + *
Three things the implementation must put in the home, because Codex has no launch flag for + * any of them: + *