← Files NightshiftARCHIVED FILE

skills/nightshift/references/hosts/codex.md

1.25 KB · Oct 5, 2026 · 18:31 UTC

↓ Download file

# Start on Codex

Approvals are per launch, and unattended execution and sandbox scope are two separate choices. A
shift runs unattended under `-a never`; a contract that does not commit needs only
`-s workspace-write`, because ticks alone finish a night. Under Codex's `workspace-write` sandbox
`.git` is protected, so a contract that commits cannot run under it and is started
`codex -a never -s danger-full-access`. The guards remain the fence either way. For a scheduled
start the same grant travels in the generator's agent string: `--agent 'codex exec -s danger-full-access'`
on POSIX, `-Agent 'codex exec -s danger-full-access'` on native Windows.

A live conversation is handed back with `codex resume <id>`. Codex SessionEnd (reason `other`) is
pause-recovery: closing, archiving, or an idle unload stands the watchman down and Start re-arms;
the punch list stays. A crash that never fires SessionEnd still revives, but only when
`$NS/run/.shift-session` holds a resumable session id — a UUID or a long hex token. ChatGPT
thread/conversation handles, rollout paths and other non-resumable identities are refused: the
watchman stands down rather than starting an unrelated conversation. A missing id still falls back
to a fresh session whose handover is the punch list.

SHA-256: b89b76e782c2bab08cf60bea0f809f6644a41d12113a1d40eb6c04daef1efe69