← Codex Process JobsCONTENT HISTORY

Update to Codex Process Jobs

Snapshot Sep 30, 2026 · 23:13 UTC · version 0.5.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "start",
  "description": "Launch an ordinary finite local workload as a durable detached process job, then release the assigning Codex turn instead of monitoring it. Use proactively for downloads, builds, test suites, evaluations, benchmarks, inference/model A/B runs, data jobs, and repairs whose underlying work may exceed 60 seconds or has uncertain duration. The user-visible parent must launch the job directly; never delegate local process execution or monitoring to a subagent.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 195
    }
  ],
  "skill_md_contents": "---\nname: start\ndescription: Launch an ordinary finite local workload as a durable detached process job, then release the assigning Codex turn instead of monitoring it. Use proactively for downloads, builds, test suites, evaluations, benchmarks, inference/model A/B runs, data jobs, and repairs whose underlying work may exceed 60 seconds or has uncertain duration. The user-visible parent must launch the job directly; never delegate local process execution or monitoring to a subagent.\n---\n\n# Start Process Job\n\nResolve `<plugin-root>` as two directories above this `SKILL.md`.\n\nNever search memory for CPJ work; use validated CPJ state.\n\nThe user-visible parent owns every CPJ launch and completion. Never delegate\nlocal process execution, launch, waiting, monitoring, or CPJ ownership to a\nspawned subagent. A subagent can analyze independent material only.\n\n## Launch exactly once\n\nPrefer direct argv:\n\n```text\nnode \"<plugin-root>/scripts/job.mjs\" start \\\n  --name \"<label>\" --cwd \"<working-directory>\" --json -- \\\n  <command> [args...]\n```\n\nUse fixed non-login Bash only for a validated shell composition:\n\n```text\nnode \"<plugin-root>/scripts/job.mjs\" start \\\n  --name \"<label>\" --cwd \"<working-directory>\" --shell --json -- \\\n  '<single finite foreground command>'\n```\n\nAll controller options, including `--json`, MUST precede `--`; that separator\nends controller parsing. Shell mode requires exactly one command string after\nit. Never use `eval`.\n\nCPJ writes private durable state under\n`${CODEX_HOME:-$HOME/.codex}/process-jobs`. Before the first controller call,\nuse the host permission context instead of probing the filesystem. If that\ndirectory is not writable in the current sandbox, request\n`sandbox_permissions: \"require_escalated\"` on the first call with a narrow\njustification and, when supported, prefix\n`[\"node\", \"<plugin-root>/scripts/job.mjs\"]`. Do not waste a call on a\npredictable `EPERM`, weaken the sandbox, or edit Codex configuration.\n\n## Route and compose\n\nUse CPJ when the user asks to detach/background work, or when a finite local\nworkload may exceed about 60 seconds, has uncertain duration, should survive a\nclient exit, or merits later lightweight status checks.\n\nClassify the underlying workload from context, not its executable name. A\nqualifying script, download, inference runner, or wrapper uses its original\nforeground payload through CPJ. Honor an explicit user request to keep work in\nthe foreground.\n\nExclude quick commands, interactive stdin, servers/watchers, intentional\ndaemons, remote/external services, and fire-and-exit launchers. The tracked\nprocess must remain in the foreground until the real workload ends.\n\nTask-specific skills own command construction, preflight checks, arguments, and\ncorrectness gates. CPJ owns execution lifecycle for qualifying finite local\nworkloads. Preserve a validated foreground argv or shell string. If a workflow\nemits a detached launcher, do not pass that launcher through CPJ unchanged:\nprefer its foreground payload, or a supported mode that remains alive until the\nworkload finishes and propagates its terminal status. Otherwise leave it with\nits external lifecycle owner.\n\n## Required choices\n\n- Require a concrete command and cwd; never invent consequential arguments.\n- Default to direct argv. Use `--shell` for Bash features and `--posix-sh` only\n  for intentionally portable POSIX syntax.\n- Add `--critical` for repair, firmware, migration, destructive conversion, or\n  any operation whose interruption could worsen state.\n- Add `--goal-mode` only when this command belongs to an explicitly active\n  Codex Goal. If unclear and `get_goal` exists, check once; never inspect private\n  Goal storage or infer Goal mode from repeated turns.\n- Optional controller flags before `--`: `--no-notify`, `--notify-user`,\n  `--no-notify-user`, and `--json`.\n\nDetached work receives no interactive stdin. Resolve passwords, confirmations,\nsudo, or Polkit in the foreground first and prefer non-interactive checks such\nas `sudo -n`. `--shell` requires `/bin/bash` and must remain compatible with\nmacOS Bash 3.2. Never put secrets in argv or tracked logs.\n\nFor storage repair, preserve the evidenced target device, mount state, and\nflags. Never infer a device node from its name.\n\n## Hard turn boundary\n\nTreat a successful controller return as a hard launch-turn release boundary.\nDo not read the status skill or call status, tail, result, `--wait`,\n`write_stdin`, sleep, `ps`, or another process probe in the launch turn.\nResult-dependent work resumes through completion delivery, a later\nuser-initiated turn, or a later automatic continuation of an explicitly active\nGoal. If the same user request includes independent work, continue only that\nindependent work.\n\nThis boundary has no same-turn wait exception. A request to report the final\nresult when it finishes is an eventual-delivery request, not permission to keep\nthe launch turn open. If the user explicitly requires foreground execution in\nthe same turn, do not use CPJ for that command. State the tradeoff and run the\nforeground command only with the user's approval. Never substitute polling.\n\n## Report and stop\n\nName this workflow **Codex Process Jobs**, never a detached-job skill or\nworkflow. Before launch, use at most one short sentence: say that Codex Process\nJobs will run it in the background and hand back immediately. Do not narrate\nprocedure, payload, argv, cwd, controller mechanics, metadata, or validation.\n\nAfter success, use no more than two short sentences: identify the background\njob ID, then say that a completion notification and any requested summary\nshould appear when it finishes; status is available on request. If delivery is\nunavailable or disabled, say completion is recorded and status/result is\navailable. Never promise an immediate wake.\n\nFor `--goal-mode`, say the job is durably tracked under the Goal and will be\npicked up by completion delivery, a hook, or Goal continuation. Automatic\ncontinuation is not permission to monitor: do independent work or apply the host\nGoal blocked audit.\n\nA job is machine-scoped and survives Codex App, IDE, or CLI exit. Never add\nsession-exit cleanup. Critical jobs later require explicit approval and\n`$cancel --force`.\n"
}

SHA-256: 5e70992cda2057f5428908f7efa0f74588a599aaa2073d557eb94733b796ba6b