Skip to content

Use the colocated daemon as the V1 user-managed executor - #8

Merged
SaladDay merged 16 commits into
mainfrom
codex/self-hosted-onboarding
Sep 21, 2026
Merged

SaladDay merged 16 commits into
mainfrom
codex/self-hosted-onboarding

Conversation

@SaladDay

@SaladDay SaladDay commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Outcome

A user can create a self_hosted Session and connect the V1 Runtime using its returned Environment ID, unchanged remote_url and scoped executor credential. Our daemon is the executor, colocated with Codex, Claude Code or MiniMax Code, native tools and workspace. Core remains independently deployable.

Enrollment binds the credential, principal, Environment, Session and device atomically. WebSocket authentication uses the bearer header; current authority checks enforce rotation and revocation. Both user-managed and managed local execution reuse the existing Runtime lifecycle, Files/Artifacts and owned-history recovery. Session deletion does not reclaim caller-owned compute.

E2B provisioning, inspection, renewal and deletion now belong to the application through the official E2B SDK. The packaging example reuses the protected V1 Runtime. Core manages Docker only. Remove the former registry/Noise remote executor, service-side remote harness route, Core E2B provider and their obsolete configuration, dependencies and tests; preserve retained filesystem helpers, database history and historical evidence. Most of the diff removes that retired route.

Validation

  • Full server make check passed at ce11501: dedicated PostgreSQL, fixed official SDK, daemon/Core tests, generated SQL verification, standalone builds, native companion packaging and Rust helpers. The subsequent Environment-keyed connection-cache cleanup at 8f0cd25 passed the execution package regression suite and independent build.
  • All three user-managed Docker profiles passed real model execution, Files/Artifacts, tenant/credential isolation, daemon/Core restart, cancellation and continuation. Final wire-0.3 binaries passed a focused real native execution and Files/Artifacts/tenant regression.
  • Shared real credential lifecycle checks cover principal/tenant/Environment binding, caller/runtime role separation, key rotation/revocation, history-rebinding rejection and retained caller-owned compute after Session deletion.
  • All three final user-managed E2B profiles passed four real common execution/restart/cancel Turns plus a fifth native credential/history/PID/envd/privilege isolation Turn. Official SDK create/info/renew/kill receipts preserve exact ownership.
  • Independent GPT-6 Astra high review of the full diff, using existing context as explicitly authorized. One connection-cache ownership defect was corrected and re-reviewed. Final documentation and deployment evidence were also independently checked.

The qualification ledger distinguishes complete lifecycle runs, focused regressions, failed attempts and reused evidence. Failed operator attempts were retained; model effects were never replayed to repair a read-only assertion.

Boundaries

The public SDK/HTTP resource contract remains pinned. The returned connection target speaks our private daemon protocol, not stock exec-server; Core and daemon deploy together at private wire version 0.3.0. The qualified self-hosted workspace is /workspace; populated capability directories and service-origin HTTP MCP on self-hosted remain explicit gaps. This does not remove separately qualified none HTTP MCP or hosted Plugin MCP. No product work, HA, compute migration, replacement-history recovery or complete official-protocol compatibility claim.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit e56596f into main Sep 21, 2026
5 checks passed
SaladDay added a commit that referenced this pull request Sep 26, 2026
…ment test (#146)

Since #8 the daemon rejects a non-none CODEX_EXEC_SERVER_URL before setup,
so TestNativeNoExecutionEnvironment failed at agent creation. The daemon's
own retirement tests cover that rejection; the native test keeps its other
caller overrides and proves the no-environment path.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant