Skip to content

Add Codex Desktop orchestration backend boundary - #69

Closed
tommy230 wants to merge 8 commits into
kunchenguid:mainfrom
tommy230:fm/codex-desktop-orchestration
Closed

tommy230 wants to merge 8 commits into
kunchenguid:mainfrom
tommy230:fm/codex-desktop-orchestration

Conversation

@tommy230

Copy link
Copy Markdown

What

Adds Codex Desktop orchestration groundwork while preserving the current tmux-treehouse worker behavior.

Why

Firstmate needs an explicit worker backend seam before native Codex Desktop project/thread workers can be introduced. The current implementation remains tmux plus treehouse until a real Desktop API is available.

Changes

  • Clarifies Fast Gate, PR-readiness, and worker backend metadata guidance for the orchestration migration.
  • Records current worker metadata for tmux-treehouse spawns.
  • Adds a minimal fm-spawn.sh backend boundary that selects tmux-treehouse by default and fails closed for codex-desktop until a real API exists.
  • Adds spawn backend behavior tests for ship/scout metadata, output, and unsupported Desktop backend side effects.

Validation

  • bash -n bin/*.sh tests/*.sh - passed
  • shellcheck bin/*.sh tests/*.sh - passed
  • for test_script in tests/*.test.sh; do "$test_script"; done - passed
  • Independent read-only review gate - APPROVE across requirements, tests, security/secrets, and repo patterns
  • GitHub checks: unavailable before PR creation

Notes

The current implemented worker backend remains tmux-treehouse. This does not fake Codex Desktop project or thread creation.

@tommy230

Copy link
Copy Markdown
Author

Closing: opened against the wrong target.

@tommy230 tommy230 closed this Jun 24, 2026
@pranaypratyush

Copy link
Copy Markdown

Thanks for the updated review. Agreed that #68, #70, and #71 materially changed the remaining recovery problem.

We will not rebase or continue the proposed v2 in this PR. Durable inbox delivery and programmatic OMP wake now cover the original freeze-driven recovery case, while this branch conflicts with the current launch surface and carries substantially more transaction and rollback machinery than genuine endpoint-death recovery warrants.

We are replacing this direction with a separate, smaller explicit clean-commit relaunch path built from current main. That path proves the original endpoint is absent, requires an exact clean source commit, creates a fresh isolated task identity, preserves the original task evidence, and refuses dirty, ambiguous, unreadable, or validation-custody-unsafe cases. It does not revive the in-place recovery transaction from this PR.

This PR is superseded; its branch and review history will remain preserved. Thanks for the detailed review—it directly informed the narrower replacement.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants