Skip to content

Pick Codex sandbox and approval in the session launcher - #1328

Merged
alexeyzimarev merged 3 commits into
mainfrom
codex-launcher-posture
Oct 6, 2026
Merged

alexeyzimarev merged 3 commits into
mainfrom
codex-launcher-posture

Conversation

@alexeyzimarev

@alexeyzimarev alexeyzimarev commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Closes #1327 — AI-3519

What & why

The daemon and server already accept a Codex launch posture, but the desktop launcher never sent one, so app-started Codex sessions always ran workspace-write / on-request. The launcher now shows Sandbox and Approvals chips for Codex only, beside the Claude permission chip.

Where to look

The daemon's default pair sends no codex_posture at all, so a daemon that predates the field still accepts an untouched launch. Changing either half sends both, since the daemon rejects a partial posture. on-failure is not offered: the daemon refuses it.

Verification

  • HomeViewModelTests 94/94, LaunchRequestTests 14/14, HostedHarnessCatalogTests 19/19, LauncherPaneViewSmokeTests 20/20.
  • The full App suite failed 15 tests, all in RemoteTranscriptFeedTests, which this change does not touch. That class passes 17/17 when run alone.
  • Not checked in the running app.

🤖 Generated with Claude Code

The default pair sends no posture, so a daemon that predates the field still accepts the launch; changing either half sends both, since the daemon rejects a partial posture.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T14:15:38.850495Z 4d81ad7 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Add Codex sandbox and approval choices to the session launcher

✨ Enhancement 🧪 Tests 🕐 20-40 Minutes

Grey Divider

AI Description

• Add Codex-only sandbox and approval chips so desktop launches can select a posture.
• Omit the daemon's default pair for compatibility; send both values when either changes.
• Test vendor visibility, accepted choices, launch behavior, and payload serialization.
Diagram

graph TD
    Chips["Codex chips"] --> ViewModel["Home view model"] --> Draft["Launch draft"] --> Request["Launch request"] --> Payload["Server payload"] --> Server["Launch server"] --> Daemon["Codex daemon"]
    Catalog["Posture catalog"] --> Chips
    Catalog --> ViewModel
Loading
High-Level Assessment

Keep the optional typed posture and omit the unchanged default pair. Always sending defaults would make untouched launches less compatible with older daemons; sending only the changed value would violate the daemon's complete-pair requirement.

Files changed (12) +257 / -9

Enhancement (8) +149 / -9
HostedHarnessCatalog.csDefine supported Codex posture choices and defaults +31/-2

Define supported Codex posture choices and defaults

• Adds sandbox and approval choices, their labels, daemon defaults, and a Codex vendor check. Excludes the unsupported on-failure approval value.

src/Capacitor.App/Services/HostedHarnessCatalog.cs

ILaunchClient.csCarry typed Codex posture into the launch payload +7/-4

Carry typed Codex posture into the launch payload

• Adds an optional CodexLaunchPosture to LaunchRequest and maps it to the existing codex_posture payload field.

src/Capacitor.App/Services/ILaunchClient.cs

HomeViewModel.csCapture and conditionally send Codex posture selections +25/-1

Capture and conditionally send Codex posture selections

• Stores sandbox and approval selections across vendor changes and captures them when launch begins. Sends a complete posture only for Codex when the selected pair differs from daemon defaults.

src/Capacitor.App/ViewModels/HomeViewModel.cs

LaunchDraft.csSnapshot Codex posture with launch settings +4/-2

Snapshot Codex posture with launch settings

• Adds the optional posture to the draft captured before uploads, preventing in-flight selection changes from altering the request.

src/Capacitor.App/ViewModels/LaunchDraft.cs

CodexPostureChipTextConverter.csLabel sandbox and approval chips +30/-0

Label sandbox and approval chips

• Formats each chip with its category and the readable label for its selected value.

src/Capacitor.App/Views/CodexPostureChipTextConverter.cs

CodexPostureChipVisibleConverter.csLimit posture-chip visibility to Codex +15/-0

Limit posture-chip visibility to Codex

• Uses the catalog's vendor check to show the new chips only for Codex.

src/Capacitor.App/Views/CodexPostureChipVisibleConverter.cs

LauncherPaneView.axamlAdd sandbox and approval chips to the launcher +14/-0

Add sandbox and approval chips to the launcher

• Adds two Codex-only buttons beside the existing permission chip, with bound labels and explanatory tooltips.

src/Capacitor.App/Views/LauncherPaneView.axaml

LauncherPaneView.axaml.csOpen Codex posture choice flyouts +23/-0

Open Codex posture choice flyouts

• Adds click handlers and a shared choice flyout that marks the current value and writes picks to the view model.

src/Capacitor.App/Views/LauncherPaneView.axaml.cs

Tests (4) +108 / -0
HomeViewModelTests.csTest default omission and complete Codex posture launches +40/-0

Test default omission and complete Codex posture launches

• Verifies untouched Codex launches send no posture, changed selections send both values, and Claude launches send none.

test/Capacitor.App.Tests.Unit/HomeViewModelTests.cs

HostedHarnessCatalogTests.csTest accepted Codex choices and vendor gating +19/-0

Test accepted Codex choices and vendor gating

• Checks the ordered daemon-supported tokens, inclusion of defaults, and Codex-only posture support.

test/Capacitor.App.Tests.Unit/HostedHarnessCatalogTests.cs

LaunchRequestTests.csTest Codex posture payload serialization +18/-0

Test Codex posture payload serialization

• Checks that a selected posture serializes as sandbox and approval fields and that an absent posture serializes as null.

test/Capacitor.App.Tests.Unit/LaunchRequestTests.cs

LauncherPaneViewSmokeTests.csTest Codex chip visibility and default labels +31/-0

Test Codex chip visibility and default labels

• Confirms both chips are hidden for Claude, visible for Codex, and display the daemon-default selections.

test/Capacitor.App.Tests.Unit/LauncherPaneViewSmokeTests.cs

@qodo-code-review

qodo-code-review Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Launch comments rely on daemon history ✓ Resolved
Description
The new CodexPostureFor documentation says a daemon predates the posture field instead of
describing only the current compatibility behavior. This historical wording is added in the launcher
source and repeated in the new test comment, so readers must interpret past-version context to
understand why null is sent.
Code

src/Capacitor.App/ViewModels/HomeViewModel.cs[R1411-1413]

+    /// Null for any vendor but codex, and for the daemon's own default pair: an unchanged launcher
+    /// sends nothing, so a daemon that predates the posture field still accepts it. Both halves go
+    /// together once either differs — the daemon rejects a partial posture.
Relevance

●●● Strong

Recent precedents accept rewriting historical comments into concise current-behavior explanations.

PR-#1029
PR-#703
PR-#766

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The changed comment describes a daemon that predates the posture field and the changed test
comment repeats that historical framing. The checklist prohibits change-history narration such as
references to behavior that used to exist or versions that predate the current implementation.

Rule 2897915: Avoid time-sensitive or process-reference metadata in code comments
src/Capacitor.App/ViewModels/HomeViewModel.cs[1411-1413]
test/Capacitor.App.Tests.Unit/HomeViewModelTests.cs[437-437]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The launcher comments use change-history language about daemons that predate the posture field, which makes the rationale depend on historical metadata.

## Fix Focus Areas
- src/Capacitor.App/ViewModels/HomeViewModel.cs[1411-1413]
- test/Capacitor.App.Tests.Unit/HomeViewModelTests.cs[437-437]

## Recommended Fix
Rewrite the comments to state the current invariant directly: the default Codex pair is represented by a null posture so launches remain compatible with servers that do not advertise or consume posture settings.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Compliance rules (platform): 64 rules
✅ Cross-repo context — repo relationships
  Explored: repo: kurrent-io/kcap-server (sha: 23a43213) — View relationship
Review mode: Auto: ⚖️ Balanced: Cross-layer launcher, serialization, UI, and compatibility behavior warrant careful review.

Grey Divider

Tip of the day
💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread src/Capacitor.App/ViewModels/HomeViewModel.cs Outdated
@alexeyzimarev
alexeyzimarev merged commit d39d1a4 into main Oct 6, 2026
15 of 17 checks passed
@alexeyzimarev
alexeyzimarev deleted the codex-launcher-posture branch October 6, 2026 15:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Desktop app: pick Codex sandbox and approval policy in the session launcher

1 participant