ef49835c4f
Codex reads everything from CODEX_HOME — config, credentials, sessions, skills, plugins, state. Pointing a peer at the operator's own ~/.codex would hand it the operator's tool surface and let it write into the operator's session history: the same failure CB-525 exists to prevent on the Claude side, in a runtime where there is no --mcp-config to neutralize. Extracted as an interface rather than a launcher method because provisioning is filesystem work with its own failure modes. The common one is a missing credential, which Codex surfaces as an opaque 401 mid-turn instead of a spawn error — so the contract says provision() must fail loudly there. Splitting it also lets the launcher be tested without touching a real home directory. Lands before the adapter so the launcher and the provisioner can be built against a fixed seam instead of against each other.