Oompa's production Codex transport currently launches the pinned JavaScript wrapper through Bun. That wrapper launches the actual native Codex process. Root-process exit therefore does not by itself establish provider process collection, especially after forced termination.
Introduce a narrow Rust process component behind the existing production transport. Keep the pinned provider launcher, credential-store configuration, environment allowlist, provider protocol, session program, account authority and durable store owned by their existing layers.
The process contract must separate root exit, child-pipe write acceptance, stdout/stderr EOF, and final native custody settlement. The actual session close/release path must consume the new settlement evidence. Unsupported or uncertain containment remains explicit; a process group does not prove the absence of descendants that escaped it. Lost acknowledgements never authorize replay.
The native byte-process interface should support a second provider-runtime consumer without requiring common provider policy or a shared account database. Keep initial source product-local until both real integrations establish the shared contract; distribute admitted immutable binaries without an end-user compiler prerequisite.
Acceptance includes the actual production constructor with credential-free executables covering launcher/native-child topology, backpressure, partial/unknown writes, stale account barriers, output bounds, TERM refusal, forced stop, inherited pipes, owner/helper disappearance and retained recovery. Preserve all required source, package, install, Mac/Linux native, and provider qualification gates. Windows needs its own qualified handle/Job Object implementation before activation. Preserve the existing Linux authority supervisor.
This issue records the approved implementation boundary. Each increment will have an active repository plan, independent adversarial review, focused evidence and the applicable current-head delivery gates. A transport prototype alone is not completion of the native integration or cross-platform product support.
Oompa's production Codex transport currently launches the pinned JavaScript wrapper through Bun. That wrapper launches the actual native Codex process. Root-process exit therefore does not by itself establish provider process collection, especially after forced termination.
Introduce a narrow Rust process component behind the existing production transport. Keep the pinned provider launcher, credential-store configuration, environment allowlist, provider protocol, session program, account authority and durable store owned by their existing layers.
The process contract must separate root exit, child-pipe write acceptance, stdout/stderr EOF, and final native custody settlement. The actual session close/release path must consume the new settlement evidence. Unsupported or uncertain containment remains explicit; a process group does not prove the absence of descendants that escaped it. Lost acknowledgements never authorize replay.
The native byte-process interface should support a second provider-runtime consumer without requiring common provider policy or a shared account database. Keep initial source product-local until both real integrations establish the shared contract; distribute admitted immutable binaries without an end-user compiler prerequisite.
Acceptance includes the actual production constructor with credential-free executables covering launcher/native-child topology, backpressure, partial/unknown writes, stale account barriers, output bounds, TERM refusal, forced stop, inherited pipes, owner/helper disappearance and retained recovery. Preserve all required source, package, install, Mac/Linux native, and provider qualification gates. Windows needs its own qualified handle/Job Object implementation before activation. Preserve the existing Linux authority supervisor.
This issue records the approved implementation boundary. Each increment will have an active repository plan, independent adversarial review, focused evidence and the applicable current-head delivery gates. A transport prototype alone is not completion of the native integration or cross-platform product support.