feat(turn): report the managed executor and fail closed when it cannot launch - #4416
Closed
huangruiteng wants to merge 4 commits into
Closed
huangruiteng wants to merge 4 commits into
huangruiteng wants to merge 4 commits into
Conversation
huangruiteng
force-pushed
the
codex/default-turn-host-binding-20260915
branch
from
September 15, 2026 04:34
dd78fed to
ca4f3cd
Compare
huangruiteng
force-pushed
the
codex/managed-executor-readback-20260915
branch
from
September 15, 2026 04:34
1933637 to
3eed1a4
Compare
This was referenced Sep 15, 2026
…t launch `loopx turn plan` and `loopx turn run-once` now carry a typed `managed_executor` block naming the planned executor, whether it is bound to an operator credential or to an individual CLI host, and whether LoopX can prove it launches here. A `run-once --execute` whose planned host reports `available: false` fails closed with status `unavailable`: it invokes no host, writes no journal, and spends no quota slot, so a Turn never moves onto another executor on its own. The credential-resolved default also has to pair its host with a schedulable execution mode: a managed default now plans `isolated-headless` instead of a visible interactive mode that the `outer_controller` scheduler context rejects, so the shipped default is usable end to end. Coverage: a readback matrix for the binding, executor coverage for the refusal and preview paths, CLI default-mode coverage, and a hermetic smoke that runs both the readback and the fail-closed refusal through the CLI. Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Describe the shipped `managed_executor` block, what `executor_kind` means, when `available` is false versus null, and the fail-closed contract of an explicitly executing Turn whose planned host cannot launch. Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
huangruiteng
force-pushed
the
codex/default-turn-host-binding-20260915
branch
from
September 15, 2026 05:13
ca4f3cd to
bcade15
Compare
huangruiteng
force-pushed
the
codex/managed-executor-readback-20260915
branch
from
September 15, 2026 05:13
3eed1a4 to
5740c4f
Compare
…wner Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Collaborator
Author
|
Superseded by #4443 ( The value here is kept: #4443 is main-based and carries the CLI output allowance this PR also needed, so the two no longer have to be reviewed as two layers. Closing to compress the delivery chain. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A planned managed Turn now reports which executor it would run on and fails
closed when that executor provably cannot launch here. Stacked on the
credential-resolved default Turn host change.
Changes
managed_executor_bindingprojects the executor, its kind (managed,individual,generic), the credential env var name (never its value), alaunchability verdict, and a typed reason when unavailable.
loopx turn planandloopx turn run-onceattachmanaged_executorto theirpayload.
unlaunchable: status
unavailable, typed reason, no journal write, no quotaspend.
turn plandefault execution mode follows the resolved host, so a manageddefault plans
isolated-headlessinstead of an execution mode the outercontroller rejects.
Validation
tests/test_turn_managed_executor_binding.py, executor fail-closed andplan-preview tests,
tests/test_turn_default_host_binding.pyCLI default-modetest; 93 focused tests then 290 across the turn driver/executor suites, green.
examples/loopx-turn-managed-executor-binding-smoke.pyproves the four-stepCLI behavior, including an import-blocked dsh runtime.
codex-cli/individual; credential ->dsh/managed/available: true; blockedruntime ->
dsh/available: false/dsh_runtime_unavailable.Boundaries
Review notes
loopx turn plangains the semantic fieldmanaged_executor, attributed asmanaged_executor_binding_v0. Theagent-facing CLI base/head differential grants one bounded, one-time growth
allowance (512 chars / 512 bytes / 12 lines / 448 compact chars) bound to the
declared none-to-v0 binding transition on
loopx_turn_plan,loopx_turn_plan_transaction_detailandloopx_turn_run_once_previewonly.Quota, status and every other agent-facing surface keep their ordinary budget,
and a v0-to-v0 change receives no allowance.
host_binding.py, the binding owner, so the already-largeturn_driver/executor.pydoes not grow (1507 -> 1496 lines; limit 1500).tests/canary/test_maintainability_ratchet.py8 passed;tests/control_plane/test_cli_output_differential.py59 passed;examples/control_plane/cli-output-base-head-differential-smoke.pyok(base=102 candidate=102 review_required=0); 81 focused Turn tests passed.