Skip to content

fix(bin): pin Codex workers to the standard service tier - #31

Merged
rub-a-dub-dub merged 2 commits into
mainfrom
fm/firstmate-codex-worker-standard-tier
Sep 27, 2026
Merged

rub-a-dub-dub merged 2 commits into
mainfrom
fm/firstmate-codex-worker-standard-tier

Conversation

@rub-a-dub-dub

Copy link
Copy Markdown
Owner

Intent

The captain's Codex config (~/.codex/config.toml) sets service_tier = "priority" (shown as "fast" in the Codex status bar), and every Firstmate-launched Codex worker inherits it. Firstmate recommended keeping the model (gpt-5.6-sol, Codex's configured default) and the current effort choices, but turning priority speed off for unattended workers while keeping it for the captain's own interactive Codex sessions, because workers run with nobody waiting and priority likely spends the weekly allowance faster. Today that split is impossible: Firstmate's per-worker profile carries harness, model, and effort, not speed. The two options offered were (1) change the captain's global Codex default, or (2) have Firstmate pass standard speed only to the workers it launches. Captain's words: "Agreed with your rec" - option 2.

What Changed

  • bin/fm-spawn.sh now appends -c 'service_tier="default"' to both codex launch templates, so every Firstmate-launched codex worker (ship, scout, secondmate, and relaunch) overrides a user-level priority tier for that process only, leaving the captain's own Codex config and interactive sessions untouched; a header comment records the rationale and notes that model and effort remain the profile's axes.
  • The harness-adapters codex reference gains a "Service tier" row documenting the flag and the codex-cli 0.154.0 behavior it relies on (session flags win over a user-level priority, and the bundled catalog leaves the default tier unset).
  • Spawn, secondmate, and relaunch tests assert the new flag in the launch line — including a new test_codex_scout_uses_standard_service_tier case and secondmate/relaunch assertions — and the claude launch test asserts service_tier never leaks into non-codex launches.

Risk Assessment

✅ Low: A one-flag, well-bounded addition to the single codex launch template that covers every Firstmate-launched codex path (ship, scout, secondmate, relaunch), leaves the captain's global Codex config untouched, and is confirmed by the installed codex 0.154.0 catalog to yield standard tier — exactly the authorized option 2.

Testing

I ran the three targeted suites the change touches (fm-spawn-dispatch-profile, fm-secondmate-harness, fm-control-relaunch) and all pass, then went past unit-level confirmation: I captured the literal command Firstmate types into a worker pane for all four Codex launch paths plus a Claude control, and the same capture against base 6ad419d shows no tier flag at all, so the before/after difference is visible at the end-user surface; the pre-fix script also fails the updated suite, making the new assertions real regression coverage. To show the emitted flag actually does what the captain asked, I exercised the real codex-cli 0.154.0 against his live service_tier = "priority" config: an unadorned session runs on priority silently, -c 'service_tier="default"' runs clean on the configured default model gpt-5.6-sol, and an intentionally unsupported session value makes the CLI warn about the session value rather than the config file — which is the observable proof that the per-launch override wins over the user-level priority. His ~/.codex/config.toml is unchanged after every run, so interactive Codex keeps "fast". The one thing no local artifact can show is the downstream billing effect (slower weekly-allowance burn), since tier consumption is only observable on OpenAI's side; the tier selection itself is demonstrated. No linting or formatting was run and the worktree is clean, with all evidence written to the run's evidence directory.

Evidence: Worker pane launch command, before (base) vs after (target), all four Codex paths + Claude control

Source: Worker pane launch command, before (base) vs after (target), all four Codex paths + Claude control

BEFORE (base 6ad419d): codex --model 'gpt-5' -c 'model_reasoning_effort="high"' --dangerously-bypass-approvals-and-sandbox [...] codex --dangerously-bypass-approvals-and-sandbox [...] # scout codex --dangerously-bypass-approvals-and-sandbox [...] # secondmate AFTER (target 8755b0c): codex --model 'gpt-5' -c 'model_reasoning_effort="high"' -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox [...] codex -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox [...] # scout codex -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox [...] # secondmate claude --dangerously-skip-permissions --settings '{...}' --model 'sonnet' --effort 'high' [...] # control: no tier flag

Literal command Firstmate types into each worker pane (paths/notify args elided)
captured with the repo's spawn fixtures + fake tmux; no real harness started

############ BEFORE (base 6ad419d) - workers inherit the captain's priority tier ############

[1] codex ship worker (profile: model gpt-5, effort high):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex --model 'gpt-5' -c 'model_reasoning_effort="high"' --dangerously-bypass-approvals-and-sandbox [...]

[2] codex ship worker (no model/effort tokens; Codex default model):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex --dangerously-bypass-approvals-and-sandbox [...]

[3] codex scout:
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex --dangerously-bypass-approvals-and-sandbox [...]

[4] codex secondmate:
  FM_ROOT_OVERRIDE= FM_STATE_OVERRIDE= FM_DATA_OVERRIDE= FM_PROJECTS_OVERRIDE= FM_CONFIG_OVERRIDE= FM_PUBLIC_FOLLOWUP_PRIMARY_HOME='/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.mykCp4/ev-codex-sm/home' FM_HOME='/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.mykCp4/ev-codex-sm/secondmate-home' FM_TRACE_CONTEXT=off FM_SUPERVISION_MODEL=persistent env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex --dangerously-bypass-approvals-and-sandbox [...]

[5] control - claude ship worker (must carry no service-tier override):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=false CLAUDE_CODE_SEND_FEEDBACK=0 claude --dangerously-skip-permissions --settings '{"feedbackDrafts":"off","attribution":{"commit":"","pr":"","sessionUrl":false}}' --model 'sonnet' --effort 'high' [...]

############ AFTER (target 8755b0c) - workers pinned to the standard tier ############

[1] codex ship worker (profile: model gpt-5, effort high):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex --model 'gpt-5' -c 'model_reasoning_effort="high"' -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox [...]

[2] codex ship worker (no model/effort tokens; Codex default model):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox [...]

[3] codex scout:
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox [...]

[4] codex secondmate:
  FM_ROOT_OVERRIDE= FM_STATE_OVERRIDE= FM_DATA_OVERRIDE= FM_PROJECTS_OVERRIDE= FM_CONFIG_OVERRIDE= FM_PUBLIC_FOLLOWUP_PRIMARY_HOME='/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-sm/home' FM_HOME='/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-sm/secondmate-home' FM_TRACE_CONTEXT=off FM_SUPERVISION_MODEL=persistent env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox [...]

[5] control - claude ship worker (must carry no service-tier override):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=false CLAUDE_CODE_SEND_FEEDBACK=0 claude --dangerously-skip-permissions --settings '{"feedbackDrafts":"off","attribution":{"commit":"","pr":"","sessionUrl":false}}' --model 'sonnet' --effort 'high' [...]
Evidence: Real codex-cli 0.154.0 transcript: session override resolves over the captain's priority tier, config untouched

Source: Real codex-cli 0.154.0 transcript: session override resolves over the captain's priority tier, config untouched

$ grep service_tier ~/.codex/config.toml # captain's interactive default 6:service_tier = "priority" A) no override -> model: gpt-5.6-sol, no warning, TIER_OK B) -c 'service_tier="default"' -> model: gpt-5.6-sol, no warning, TIER_OK C) -c 'service_tier="bogus-tier"' -> warning: Configured service tier bogus-tier is not advertised as supported for model gpt-5.6-sol and will be omitted from requests. (the warning names the SESSION value, so -c replaced the user-level priority during config resolution) $ grep service_tier ~/.codex/config.toml # after all three runs 6:service_tier = "priority"

$ codex --version
codex-cli 0.154.0

$ grep service_tier ~/.codex/config.toml   # captain's interactive default
6:service_tier = "priority"

--- A) captain's own session: no session override (inherits priority) ---
$ codex exec --skip-git-repo-check 'Reply with exactly: TIER_OK'
Reading additional input from stdin...
OpenAI Codex v0.154.0
--------
workdir: /private/tmp
model: gpt-5.6-sol
provider: openai
approval: on-request
sandbox: read-only
reasoning effort: high
reasoning summaries: none
session id: 01a0e004-bd10-78d0-919c-1917568841fa
--------
user
Reply with exactly: TIER_OK
hook: SessionStart
hook: SessionStart
hook: SessionStart
hook: SessionStart Failed
hook: SessionStart Failed
hook: SessionStart Failed
codex
TIER_OK
tokens used
15 627
TIER_OK

--- B) Firstmate worker launch: session override to the standard tier ---
$ codex exec -c 'service_tier="default"' --skip-git-repo-check 'Reply with exactly: TIER_OK'
Reading additional input from stdin...
OpenAI Codex v0.154.0
--------
workdir: /private/tmp
model: gpt-5.6-sol
provider: openai
approval: on-request
sandbox: read-only
reasoning effort: high
reasoning summaries: none
session id: 01a0e005-008f-7401-92a2-55af1e962e34
--------
user
Reply with exactly: TIER_OK
hook: SessionStart
hook: SessionStart
hook: SessionStart
hook: SessionStart Failed
hook: SessionStart Failed
hook: SessionStart Failed
codex
TIER_OK
tokens used
12 043
TIER_OK

--- C) precedence control: an unsupported session value overrides the user-level priority and is reported ---
$ codex exec -c 'service_tier="bogus-tier"' --skip-git-repo-check 'Reply with exactly: TIER_OK'
Reading additional input from stdin...
OpenAI Codex v0.154.0
--------
workdir: /private/tmp
model: gpt-5.6-sol
provider: openai
approval: on-request
sandbox: read-only
reasoning effort: high
reasoning summaries: none
session id: 01a0e005-148a-7d80-a032-4097ce32a6d1
--------
user
Reply with exactly: TIER_OK
warning: Configured service tier `bogus-tier` is not advertised as supported for model `gpt-5.6-sol` and will be omitted from requests.
hook: SessionStart
hook: SessionStart
hook: SessionStart
hook: SessionStart Failed
hook: SessionStart Failed
hook: SessionStart Failed
codex
TIER_OK
tokens used
12 043
TIER_OK

--- captain's config after all three runs (unchanged) ---
$ grep service_tier ~/.codex/config.toml
6:service_tier = "priority"
Evidence: Pre-fix suite failure (regression proof: updated assertions fail on base fm-spawn.sh)

Source: Pre-fix suite failure (regression proof: updated assertions fail on base fm-spawn.sh)

not ok - explicit harness launch did not thread model and effort (missing: 'codex --model 'gpt-5' -c 'model_reasoning_effort="high"' -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox') ---- output --- codex --model 'gpt-5' -c 'model_reasoning_effort="high"' --dangerously-bypass-approvals-and-sandbox [...]

ok - allowlist=absent preserves the operational floor and filters only when opted in
ok - allowlist=missing-config preserves the operational floor and filters only when opted in
ok - allowlist=enabled preserves the operational floor and filters only when opted in
ok - allowlist=empty preserves the operational floor and filters only when opted in
ok - invalid allowlist names refuse before launch or task publication
ok - inaccessible config with present allowlist refuses before launch or task publication
ok - inaccessible config with absent allowlist refuses before launch or task publication
ok - inaccessible ancestor with present allowlist refuses before launch or task publication
ok - inaccessible ancestor with absent allowlist refuses before launch or task publication
ok - secondmate launch inherits the allowlist for subsequent worker launches
ok - local inheritance preserves the allowlist on source errors and mirrors proven absence
ok - remote inheritance preserves the allowlist on source errors and mirrors proven absence
ok - fm-spawn: actual ship/scout launch commands deliver the worker role contract
ok - no --model/--effort records defaults and types the claude launch instructions
ok - non-cursor launches clear inherited Cursor identity markers
ok - relative home overrides ignore CDPATH and become absolute before spawn launch construction
ok - FM_HOME defaults resolve relative paths and preserve absolute spellings
ok - absolute override spellings are preserved in spawn launch paths
ok - unresolvable relative spawn overrides fail with named diagnostics
ok - active crew-dispatch profile requires an explicit harness for ship spawns
ok - active crew-dispatch profile requires an explicit harness for scout spawns
not ok - explicit harness launch did not thread model and effort (missing: 'codex --model 'gpt-5' -c 'model_reasoning_effort="high"' -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox')
--- output ---
env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex --model 'gpt-5' -c 'model_reasoning_effort="high"' --dangerously-bypass-approvals-and-sandbox -c "notify=[\"bash\",\"-c\",\"touch '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-spawn-dispatch-profile.2Y9kw6/profile-explicit/home/state/profile-explicit-z13.turn-ended'\"]" "$('~/.no-mistakes/worktrees/00644a303d6a/01M3FZ1JFZZ904JNWC394QCT0M/bin/fm-operational-input.sh' encode launch-brief < '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-spawn-dispatch-profile.2Y9kw6/profile-explicit/home/data/profile-explicit-z13/launch-brief.md')"
Evidence: Launch-line capture harness used for the before/after evidence

Source: Launch-line capture harness used for the before/after evidence

#!/usr/bin/env bash
# Evidence capture: print the literal command line Firstmate types into a worker
# pane for each Codex launch path, plus a Claude launch as the control.
# Uses the repository's own spawn fixtures and their fake tmux, which records the
# exact `tmux send-keys -l` payload without starting a real harness.
set -u
ROOT_WT=${1:?worktree}
# shellcheck source=/dev/null
. "$ROOT_WT/tests/fixtures.sh"
TMP_ROOT=$(fm_test_tmproot fm-evidence-codex-tier)

new_case() {
  local name=$1 harness=$2 id=$3
  CASE_DIR="$TMP_ROOT/$name"; HOME_DIR="$CASE_DIR/home"; PROJ_DIR="$CASE_DIR/project"
  WT_DIR="$CASE_DIR/wt"; LAUNCH_LOG="$CASE_DIR/launch.log"
  FAKEBIN_DIR=$(fm_test_make_spawn_fakebin "$CASE_DIR/fake" gh gh-axi pi cursor-agent)
  cat > "$FAKEBIN_DIR/timeout" <<'SH'
#!/usr/bin/env bash
shift
exec "$@"
SH
  chmod +x "$FAKEBIN_DIR/timeout"
  fm_test_spawn_home "$HOME_DIR" "$harness"
  fm_git_worktree "$PROJ_DIR" "$WT_DIR" "wt-$name"
  fm_test_spawn_brief "$HOME_DIR" "$id"
}

spawn() {
  : > "$LAUNCH_LOG"
  CLAUDE_CONFIG_DIR='' FM_FAKE_LAUNCH_LOG="$LAUNCH_LOG" \
    fm_test_run_spawn "$HOME_DIR" "$WT_DIR" "$FAKEBIN_DIR" "$@" >/dev/null 2>&1
}

show() { printf '%s\n  %s\n\n' "$1" "$(cat "$LAUNCH_LOG")"; }

id=ev-codex-ship
new_case ev-codex-ship codex "$id"
spawn "$id" "$PROJ_DIR" --mode no-mistakes --yolo off --model gpt-5 --effort high
show '[1] codex ship worker (profile: model gpt-5, effort high):'

id=ev-codex-plain
new_case ev-codex-plain codex "$id"
spawn "$id" "$PROJ_DIR" --mode no-mistakes --yolo off
show '[2] codex ship worker (no model/effort tokens; Codex default model):'

id=ev-codex-scout
new_case ev-codex-scout codex "$id"
spawn "$id" "$PROJ_DIR" --scout
show '[3] codex scout:'

id=ev-codex-sm
new_case ev-codex-sm codex "$id"
sm="$CASE_DIR/secondmate-home"
mkdir -p "$sm/bin" "$sm/data"
printf '# Firstmate\n' > "$sm/AGENTS.md"
printf '%s\n' "$id" > "$sm/.fm-secondmate-home"
printf 'charter for %s\n' "$id" > "$sm/data/charter.md"
spawn "$id" "$sm" --secondmate
show '[4] codex secondmate:'

id=ev-claude-ship
new_case ev-claude-ship claude "$id"
spawn "$id" "$PROJ_DIR" --mode no-mistakes --yolo off --model sonnet --effort high
show '[5] control - claude ship worker (must carry no service-tier override):'
Evidence: Full target-commit launch lines (unelided)

Source: Full target-commit launch lines (unelided)

[1] codex ship worker (profile: model gpt-5, effort high):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex --model 'gpt-5' -c 'model_reasoning_effort="high"' -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox -c "notify=[\"bash\",\"-c\",\"touch '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-ship/home/state/ev-codex-ship.turn-ended'\"]" "$('~/.no-mistakes/worktrees/00644a303d6a/01M3FZ1JFZZ904JNWC394QCT0M/bin/fm-operational-input.sh' encode launch-brief < '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-ship/home/data/ev-codex-ship/launch-brief.md')"

[2] codex ship worker (no model/effort tokens; Codex default model):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox -c "notify=[\"bash\",\"-c\",\"touch '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-plain/home/state/ev-codex-plain.turn-ended'\"]" "$('~/.no-mistakes/worktrees/00644a303d6a/01M3FZ1JFZZ904JNWC394QCT0M/bin/fm-operational-input.sh' encode launch-brief < '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-plain/home/data/ev-codex-plain/launch-brief.md')"

[3] codex scout:
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox -c "notify=[\"bash\",\"-c\",\"touch '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-scout/home/state/ev-codex-scout.turn-ended'\"]" "$('~/.no-mistakes/worktrees/00644a303d6a/01M3FZ1JFZZ904JNWC394QCT0M/bin/fm-operational-input.sh' encode launch-brief < '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-scout/home/data/ev-codex-scout/launch-brief.md')"

[4] codex secondmate:
  FM_ROOT_OVERRIDE= FM_STATE_OVERRIDE= FM_DATA_OVERRIDE= FM_PROJECTS_OVERRIDE= FM_CONFIG_OVERRIDE= FM_PUBLIC_FOLLOWUP_PRIMARY_HOME='/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-sm/home' FM_HOME='/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-sm/secondmate-home' FM_TRACE_CONTEXT=off FM_SUPERVISION_MODEL=persistent env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI codex -c 'service_tier="default"' --dangerously-bypass-approvals-and-sandbox "$('~/.no-mistakes/worktrees/00644a303d6a/01M3FZ1JFZZ904JNWC394QCT0M/bin/fm-operational-input.sh' encode launch-brief < '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-codex-sm/secondmate-home/data/charter.md')"

[5] control - claude ship worker (must carry no service-tier override):
  env -u CURSOR_AGENT -u CURSOR_INVOKED_AS -u GEMINI_CLI CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=false CLAUDE_CODE_SEND_FEEDBACK=0 claude --dangerously-skip-permissions --settings '{"feedbackDrafts":"off","attribution":{"commit":"","pr":"","sessionUrl":false}}' --model 'sonnet' --effort 'high' "$('~/.no-mistakes/worktrees/00644a303d6a/01M3FZ1JFZZ904JNWC394QCT0M/bin/fm-operational-input.sh' encode launch-brief < '/private/var/folders/f_/hcy8g0q91p9fdyghn_9ypx5r0000gn/T/fm-evidence-codex-tier.0jJw36/ev-claude-ship/home/data/ev-claude-ship/launch-brief.md')"

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

⚠️ **Review** - 1 info
  • ℹ️ bin/fm-spawn.sh:1610 - The standard-tier effect is achieved indirectly: service_tier=&#34;default&#34; is not an advertised tier id in codex's bundled catalog (each model advertises only {&#34;id&#34;:&#34;priority&#34;,&#34;name&#34;:&#34;Fast&#34;}, with default_service_tier: null), so codex-cli 0.154.0 logs "Configured service tier … is not advertised as supported for model … and will be omitted from requests" (core/src/session/thread_settings.rs) and sends no tier — which is standard speed and correctly overrides the user-level priority. Verified against the installed 0.154.0 catalog and binary; noted only because the mechanism is omission rather than an explicit standard-tier id. No action needed: if a future catalog ever advertises a default tier, it would be sent explicitly and still mean standard.
✅ **Test** - passed

✅ No issues found.

  • bin/fm-test-run.sh tests/fm-spawn-dispatch-profile.test.sh tests/fm-secondmate-harness.test.sh — both pass, including the new test_codex_scout_uses_standard_service_tier and the codex/secondmate/explicit-harness launch-shape assertions
  • bin/fm-test-run.sh tests/fm-control-relaunch.test.sh — passes, covering the new assertion that a relaunch onto codex carries the standard service-tier override
  • Regression proof: git checkout 6ad419d -- bin/fm-spawn.sh &amp;&amp; bash tests/fm-spawn-dispatch-profile.test.sh → not ok - explicit harness launch did not thread model and effort; restored with git checkout HEAD -- bin/fm-spawn.sh (worktree left clean)
  • Launch-command capture via the repo's spawn fixtures and fake tmux for codex ship worker (--model gpt-5 --effort high), codex ship worker with no profile tokens, --scout, --secondmate, and a claude control — script capture-codex-launch-lines.sh in the evidence directory, run against both base and target
  • Real CLI probe, codex exec --skip-git-repo-check &#39;Reply with exactly: TIER_OK&#39; on codex-cli 0.154.0, in three variants: no override (inherits priority, no warning), -c &#39;service_tier=&#34;default&#34;&#39; (clean run on gpt-5.6-sol), -c &#39;service_tier=&#34;bogus-tier&#34;&#39; (CLI warns that the session value is unsupported, proving -c overrides the user-level priority)
  • codex debug models — model catalog advertises priority as "Fast"; grep service_tier ~/.codex/config.toml before and after all runs shows service_tier = &#34;priority&#34; untouched
  • grep -rn dangerously-bypass-approvals-and-sandbox bin/ skills/ .agents/ — confirmed bin/fm-spawn.sh:1610 is the only codex launch-template owner, so no Firstmate codex launch path bypasses the override
⚠️ **Document** - 1 info
  • ℹ️ docs/configuration.md:309 - Judgment call, no edit made: the new Codex standard-service-tier behavior is operator-visible (it changes which allowance a worker spends), and configuration.md does carry one analogous non-configurable per-launch policy inline (the claude attribution-off sentence at line 409). I left configuration.md unchanged because its "Harness support" section already delegates launch mechanics to bin/fm-spawn.sh --help, whose header is the fact's single owner and now renders the full contract plus rationale; adding a prose copy would be synchronizing a third copy of the same fact. If the captain wants the tier called out in operator docs, the right move is one sentence in "Harness support" pointing at the spawn header, not a restatement.
✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

@rub-a-dub-dub
rub-a-dub-dub merged commit 4e5c8ee into main Sep 27, 2026
14 checks passed
rub-a-dub-dub added a commit that referenced this pull request Sep 27, 2026
Base advanced by three commits (#31, #30, #32) since this branch last took
origin/main at 929a366. Only 4e5c8ee (#31, pin Codex workers to the standard
service tier) overlapped the reconciliation, in three files:

- .agents/skills/harness-adapters/references/harness/codex.md: keep upstream's
  Effort flag row, which now advertises `max` for gpt-5.6-luna, and add the
  base's new Service tier row alongside it.
- bin/fm-spawn.sh: carry `-c 'service_tier="default"'` on both codex launch
  templates, keeping upstream's `--disable hooks` on the crewmate template, and
  take the base's service-tier rationale into the launch contract header.
- tests/fm-spawn-dispatch-profile.test.sh: register the base's new
  test_codex_scout_uses_standard_service_tier next to upstream's restructured
  max-effort and hook-layer cases, and thread the service-tier flag through
  upstream's own Luna max-effort launch assertion.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant