Skip to content

feat(native-owner): add experimental Windows Codex launcher - #4803

Open
cr101 wants to merge 63 commits into
kunchenguid:mainfrom
cr101:fix/windows-native-owner-candidate
Open

cr101 wants to merge 63 commits into
kunchenguid:mainfrom
cr101:fix/windows-native-owner-candidate

Conversation

@cr101

@cr101 cr101 commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Scope and verification limits

Windows Claude ownership has not been verified.
Proceeding with this draft update under the explicitly accepted evidence exception does not certify Windows Claude support.
The implementation remains an explicit-opt-in native Windows Codex experiment restricted to temporary, empty-fleet homes, not general Windows fleet or Linux launcher support.
Natural-language Detection interpretation has not been live-model tested; the previously reported tagged foreign-owner concern remains unreproduced and is not claimed fixed.

Authorship and history

This continues #3553 with Lloyd's original commits and attribution preserved: aa434629, a975ea4c, and 36dbddc3.
Original author approval: #3553 (comment).
The upstream integration is a normal merge of 203a69a3007ea5d06f70869f39277cdbde430903 and 65a3bac6031286b4058360859a9522a50a09bb14, preserving both histories without a rebase.

Current validation evidence

Published head: ee9be1c8386eb4833ee630dc748782575c3babfc.
All 19 GitHub checks passed on this head, and GitHub reports no merge conflicts. The PR remains draft and unmerged.
The final test-only CI repair uses the existing scoped remote-worker stop-and-join helper before fixture directory deletion, addressing the cleanup failure in the public-followup suite.
The canonical local verification described next was at the documentation head 755daafd3b9ceb648a12c3d712984d8414862d9e; final-head GitHub lint and behavior checks passed separately.
Full canonical ShellCheck/actionlint, documentation audience/link checks, and targeted ownership/reference/portable-host suites passed at that documentation head.
The Linux portable-host run passed 54 checks, with three Windows-only skips.
Real Windows Codex launcher/model, native lifecycle and receipt verification passed at 12b206150162fd47dcb9d30ffeaf36f98f7461bc; the later change to the published head contains only comments and documentation, including the explicit Claude limitation.
Those Windows runs had zero skips and clean tracked diffs, including all 57 tool checks and 39 receipt assertions.
The generated report below distinguishes automated fixture/ancestry evidence from live-model evidence; an “untested” live label does not mean the separately recorded automated check failed.
Earlier findings saying no exception applied predate the subsequent explicit acceptance recorded above; they remain below as historical run evidence, not a claim that Claude was verified.
The generated lint warning records a managed Windows shell invocation failure; the separately executed exact-head canonical full lint passed without relaxing checks.

What Changed

  • Add an explicit-opt-in native Windows Codex launcher for temporary, empty-fleet homes, with native admission, isolated app-server policy, and durable notification receipt and acknowledgement handling.
  • Extend session locking, startup, inbox, wake, process-event, and supervision paths to carry authenticated native and tagged Windows owner identities while preserving unknown results when ownership cannot be verified.
  • Document detection precedence and experimental limits, and add portable fake-server and opt-in Windows coverage for ownership, launcher lifecycle, receipts, tool policy, inbox publication, and APPDATA-isolated host scenarios.

Risk Assessment

✅ Low: The change is strongly bounded to an explicit-opt-in, temporary-home, empty-fleet experiment, and the reviewed source preserves both parents’ ownership and recovery invariants without a substantiated new defect.

Testing

The host driver exercised the real Windows Codex launcher/model and native ownership surfaces at exact head 12b2061; all three live scenarios passed. The portable fake-server fixture, staged integration checks, and local graph checks are retained as non-live supporting observations and therefore do not establish scenario passes under the live-validation contract. Windows Claude ownership, natural-language Detection interpretation, and the tagged foreign-owner path remain untested.

  • Live validation: ✅ go - 3 of 9 scenarios driven live against the product
Scenario Result Live Evidence
A Windows user explicitly opts into the experimental launcher from a temporary empty home and completes the real Codex startup, notification, recovery, restart, and shutdown lifecycle. ✅ pass live Host-produced exact-head tests/fm-native-owner-launcher-live-e2e.test.sh transcript: exit 0, no capability skip, two model-observed acknowledgement cycles, interruption recovery, restart, and clean…
A user tries to exceed the experimental temporary-home and empty-fleet boundary, and the launcher refuses without modifying existing work. ✅ pass live The same real launcher transcript records refusal of populated, non-temporary, competing-owner, unresolved-owner, reparse-point, and hard-linked homes while preserving their records.
A native Windows owner persists and reconciles notification receipts while foreign, stale, malformed, or cross-home evidence cannot claim the operation. ✅ pass live Host-produced exact-head tests/fm-native-owner-receipt-live-e2e.test.sh transcript: exit 0, no capability skip, 39 receipt assertions, exclusive acquisition, restart recovery, and ambiguous-owner re…
The portable host fixture supplies isolated APPDATA and completes all seven fake-server host-loop cases without inherited Windows environment state. ⏸️ untested no The prior payload cited only a portable fake-server fixture run and explicitly marked it non-live; it did not establish this result against the real running product.
The upstream Claude same-session recovery behavior and the candidate native/Windows tri-state ownership behavior both survive the integration. ⏸️ untested no The prior payload cited staged integrated-tree and automated ownership checks and explicitly marked them non-live; it did not establish this integrated behavior against the real running product.
A maintainer verifies that the integration preserves the candidate, upstream main, and the historical Windows proof commit without rebasing or rewriting history. ⏸️ untested no The prior payload cited only local commit-graph checks and explicitly marked them non-live; it did not establish a live product result for this scenario.
An agent follows native-owner precedence, preserves unknown after unsupported or failed native verification, and retains non-native ancestry-over-marker precedence. ⏸️ untested no This is natural-language Detection guidance with no observable runtime interpretation interface. A live result would require an authorized agent-level evaluation that loads this exact skill; the accep…
Current Windows Claude publishes a usable owner identity through the real harness. ⏸️ untested no Windows Claude ownership has not been verified. Qualifying evidence would require separate authorization on an eligible Windows host with an existing managed Claude session; no purchase, login, creden…
A second session encountering a tagged Windows/native foreign owner exits safely without repeated Stop blocking. ⏸️ untested no The prior tagged foreign-owner concern remains unreproduced and unresolved by explicit user decision. Demonstrating it would require a focused end-to-end drive of that exact tagged-owner path; this re…
Evidence: Exact-head real Windows Codex launcher/model run
HEAD 12b206150162fd47dcb9d30ffeaf36f98f7461bc; exit 0; 669.18s; zero gate skips; empty tracked diff. Real launcher became ready, refused a competing/populated launch, delivered and acknowledged two notification cycles, recovered interrupted delivery, interrupted an active turn, and preserved an independent process.
Evidence: Exact-head Windows native ownership and receipt run
HEAD 12b206150162fd47dcb9d30ffeaf36f98f7461bc; exit 0; zero skips; empty tracked diff. Native lifecycle/receipt run reported RECEIPT_TESTS_PASS 39 and verified exclusive acquisition, unchanged competing records, restart recovery, ambiguous-owner refusal, and child-boundary isolation.
Evidence: Portable host-loop and capability-isolation evidence
The exact-head tool-gate run passed all 57 checks with zero skips, including seven host-loop cases and effective app/MCP capability isolation.
Evidence: History-preserving integration proof
Merge 12b206150162fd47dcb9d30ffeaf36f98f7461bc has parents 203a69a3007ea5d06f70869f39277cdbde430903 and 65a3bac6031286b4058360859a9522a50a09bb14. Both parents and historical proof commit 09d19aaf038933e5b59206b1f393753ee8b2bc58 are ancestors.
Evidence: Integrated Linux verification record
Native Linux staged-tree evidence: ancestry suite passed; portable suite passed 54 checks with three Windows-only skips; five adjacent startup/ownership suites passed. The supplied canonical lint record also reports exit 0. These are integrated-tree checks, not fresh live-model evidence.
- Outcome: 🔧 2 issues found → no changes applied ✅ across 2 runs (22m20s)

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

⏭️ **Rebase** - skipped

Step was skipped.

✅ **Review** - passed

✅ No issues found.

🔧 **Test** - 2 issues found → no changes applied ✅
  • ⚠️ Live validation is inconclusive on the integrated revision. The real Windows build, opt-in/home guards, and model-free Codex app-server isolation passed, but this managed process cannot drive the full empty-home launcher or the merged shell ownership paths: Docker Desktop's Linux-engine named pipe is inaccessible, Git Bash cannot create its shared mapping, WSL service access is denied, and Node child-process creation is denied. Current real Windows Claude ownership also remains explicitly unverified and no waiver applies. Re-run on an unelevated Windows host whose user owns the running Docker Desktop engine, with an existing local jq/GNU-timeout image and working Git Bash; real Claude proof additionally requires separate authorization on an eligible host with existing managed authentication, without purchasing, logging in, or weakening permissions.
  • ⚠️ live validation verdict: inconclusive (3 of 9 scenarios were driven live against the product); untested: The portable host fixture supplies isolated APPDATA and completes all seven fake-server host-loop cases, A maintainer verifies that the integration commit preserves the candidate, upstream main, and historical Windows proof commit, An empty temporary home completes the public verify-only native launcher cycle without a model turn, Claude same-session sidecar recovery and native/Windows tri-state exclusion both survive the merge, Current Windows Claude publishes a usable owner identity through the real harness, An agent follows native-owner precedence, preserves unknown without fallback, and retains non-native precedence from the corrected Detection guidance
  • Live validation: ⚠️ inconclusive - 3 of 9 scenarios driven live against the product
Scenario Result Live Evidence
A Windows user builds the candidate but cannot launch it without explicit experimental opt-in ✅ pass live Native Windows build and admission boundaries
An adversarial direct-provider launch cannot bypass temporary-home and empty-fleet restrictions ✅ pass live Native Windows build and admission boundaries
A model-free native host exposes no inherited apps, plugins, or active MCP tools through the real Codex app-server ✅ pass live Real Codex app-server isolation
The portable host fixture supplies isolated APPDATA and completes all seven fake-server host-loop cases ⏸️ untested no The prior payload recorded only portable fake-server fixture execution and explicitly marked it non-live, so it did not establish this scenario against the live product.
A maintainer verifies that the integration commit preserves the candidate, upstream main, and historical Windows proof commit ⏸️ untested no The prior payload recorded a non-live repository ancestry inspection, not a scenario driven against the live product, so it did not establish a live result.
An empty temporary home completes the public verify-only native launcher cycle without a model turn ⏸️ untested no Docker Desktop's Linux-engine named pipe denied this process, so no existing jq/GNU-timeout image could be enumerated or used. Provide access from the ordinary user session that owns the running Docke…
Claude same-session sidecar recovery and native/Windows tri-state exclusion both survive the merge ⏸️ untested no The canonical executable paths require a working POSIX shell. Git Bash failed before script execution with Win32 error 5, WSL enumeration returned E_ACCESSDENIED, and permission weakening is forbidden…
Current Windows Claude publishes a usable owner identity through the real harness ⏸️ untested no The intent explicitly leaves this proof unverified and forbids subscription, login, credential, provider, and permission changes. A qualifying run requires separate authorization on an eligible Window…
An agent follows native-owner precedence, preserves unknown without fallback, and retains non-native precedence from the corrected Detection guidance ⏸️ untested no The change is natural-language agent guidance with no executable interpretation surface. Demonstration requires an authorized end-to-end Firstmate agent session that loads this target skill in an elig…
  • powershell.exe -NoProfile -NonInteractive -File .\bin\fm-native-codex.ps1 -BuildOnly
  • Public launcher invocation without -Experimental
  • Compiled fm-native-owner.exe launch --experimental <populated-temporary-home> with sentinel and owner-record checks
  • Compiled fm-native-owner.exe launch --experimental <non-temporary-path> with no-creation check
  • node tests/fixtures/native-owner/tool-gate.test.mjs
  • node tests/fixtures/native-owner/host-lifecycle.test.mjs
  • node tests/fixtures/native-owner/app-server-policy.test.mjs
  • node tests/fixtures/native-owner/host-evidence.test.mjs (subprocess cases setup-blocked by spawn EPERM)
  • Isolated real codex app-server --stdio JSONL drive through initialize, config/read, thread/start, app/installed, and mcpServerStatus/list
  • Attempted bin/fm-test-run.sh tests/fm-native-owner-app-server-policy-live-e2e.test.sh (Git Bash blocked before execution)
  • Docker image enumeration, Git Bash, Node subprocess, and WSL capability probes
  • git merge-base --is-ancestor for 203a69a, 65a3bac, and 09d19aa plus exact merge-parent verification
  • Final clean-worktree and transient-artifact check

🔧 No changes applied.
✅ Re-checked - no issues remain.

  • Live validation: ✅ go - 3 of 9 scenarios driven live against the product
Scenario Result Live Evidence
A Windows user explicitly opts into the experimental launcher from a temporary empty home and completes the real Codex startup, notification, recovery, restart, and shutdown lifecycle. ✅ pass live Host-produced exact-head tests/fm-native-owner-launcher-live-e2e.test.sh transcript: exit 0, no capability skip, two model-observed acknowledgement cycles, interruption recovery, restart, and clean…
A user tries to exceed the experimental temporary-home and empty-fleet boundary, and the launcher refuses without modifying existing work. ✅ pass live The same real launcher transcript records refusal of populated, non-temporary, competing-owner, unresolved-owner, reparse-point, and hard-linked homes while preserving their records.
A native Windows owner persists and reconciles notification receipts while foreign, stale, malformed, or cross-home evidence cannot claim the operation. ✅ pass live Host-produced exact-head tests/fm-native-owner-receipt-live-e2e.test.sh transcript: exit 0, no capability skip, 39 receipt assertions, exclusive acquisition, restart recovery, and ambiguous-owner re…
The portable host fixture supplies isolated APPDATA and completes all seven fake-server host-loop cases without inherited Windows environment state. ⏸️ untested no The prior payload cited only a portable fake-server fixture run and explicitly marked it non-live; it did not establish this result against the real running product.
The upstream Claude same-session recovery behavior and the candidate native/Windows tri-state ownership behavior both survive the integration. ⏸️ untested no The prior payload cited staged integrated-tree and automated ownership checks and explicitly marked them non-live; it did not establish this integrated behavior against the real running product.
A maintainer verifies that the integration preserves the candidate, upstream main, and the historical Windows proof commit without rebasing or rewriting history. ⏸️ untested no The prior payload cited only local commit-graph checks and explicitly marked them non-live; it did not establish a live product result for this scenario.
An agent follows native-owner precedence, preserves unknown after unsupported or failed native verification, and retains non-native ancestry-over-marker precedence. ⏸️ untested no This is natural-language Detection guidance with no observable runtime interpretation interface. A live result would require an authorized agent-level evaluation that loads this exact skill; the accep…
Current Windows Claude publishes a usable owner identity through the real harness. ⏸️ untested no Windows Claude ownership has not been verified. Qualifying evidence would require separate authorization on an eligible Windows host with an existing managed Claude session; no purchase, login, creden…
A second session encountering a tagged Windows/native foreign owner exits safely without repeated Stop blocking. ⏸️ untested no The prior tagged foreign-owner concern remains unreproduced and unresolved by explicit user decision. Demonstrating it would require a focused end-to-end drive of that exact tagged-owner path; this re…
  • git status --short --branch and git rev-parse HEAD
  • git show --no-patch --pretty=fuller 12b206150162fd47dcb9d30ffeaf36f98f7461bc and git rev-list --parents -n 1 12b206150162fd47dcb9d30ffeaf36f98f7461bc
  • git merge-base --is-ancestor for 203a69a, 65a3bac, and 09d19aa against 12b2061
  • Reviewed host-produced exact-head bash bin/fm-test-run.sh tests/fm-native-owner-launcher-live-e2e.test.sh evidence
  • Reviewed host-produced exact-head bash bin/fm-test-run.sh tests/fm-native-owner-tool-gate.test.sh tests/fm-native-owner-receipt-live-e2e.test.sh evidence
  • Reviewed staged integrated-tree tests/fm-session-lock-ancestry.test.sh and five adjacent-suite transcripts
  • Reviewed the supplied canonical lint completion and exit records without rerunning lint
  • Computed SHA-256 hashes for all ten supplied host evidence files and attempted to copy them into the dedicated evidence directory
  • Final git status --short and git rev-parse HEAD cleanliness/head check
✅ **Document** - passed

✅ No issues found.

⚠️ **Lint** - 1 warning
  • ⚠️ linter found issues (exit code 1)
✅ **Push** - passed

✅ No issues found.

lmktechnology and others added 30 commits September 15, 2026 12:56
Every session start on Cygwin (Git for Windows) refused the fleet lock and
dropped to read-only with "cannot locate harness process in ancestry", so
spawning, steering, merging, the wake-queue drain, and supervision repair were
skipped on every start. Two independent causes, both on the identity path.

Cygwin's ps has no -o option at all and fails the whole invocation with
"unknown option -- o", so the ancestry walk aborted on its first hop. The walk
now reads comm, args, and ppid through accessors that fall back to Cygwin's
fixed ps columns, leaving the procps/BSD path unchanged.

That alone does not resolve the session: the parent link from a shell the
harness spawns does not cross the Cygwin boundary, and Cygwin reports that
shell's PPID as 1, so no walk can reach a harness that is a native Windows
process. Identity is instead taken from the session pid the harness publishes
and confirmed against the Windows process table before it is used - the pid
must still be live and its executable must independently identify a verified
harness - so an absent, stale, or non-harness value is discarded rather than
bound.

Walking the real Windows parent chain was implemented and then removed as
unsafe. MSYS emulates exec by spawning a fresh Windows process and exiting the
old one, so intermediate shells vanish and a child's recorded parent is
routinely a pid that no longer exists; Windows never reparents an orphan, so
that dangling id stays and can be reissued to an unrelated process. Following
it can bind a home's lock to the wrong process, which is the failure this file
exists to prevent. A harness that publishes nothing stays unresolved, which
leaves the session read-only exactly as before.

Windows pids are tagged rather than stored bare. They are a different namespace:
kill -0 reports a live Windows process as dead, and the number can collide with
an unrelated live Cygwin pid. The tag makes the value non-numeric, so a consumer
that treats it as a local pid - including a future kill - refuses it instead of
acting on the wrong process.

fm-sessionstart-nudge.sh carried a private second copy of the ownership walk and
so stayed wrong after the owner was fixed, nudging a session that already held
the lock. It now asks the owning function.

Verified on Windows 11 (Git Bash, Cygwin ps 3.4.10): the lock is acquired,
reports its holder, is idempotent, and refuses a bogus, dead, or non-harness
published pid. Regressions cover both platform departures behind a fake process
table, so they run on Linux and macOS CI too. The pre-existing e2e failure in
this suite on Windows is unchanged from main; it cannot exec its symlinked
fixture.

Refs kunchenguid#3396

Claude-Session: https://claude.ai/code/session_01F9T29YDqYSkQeDTC2Nfi7h
(cherry picked from commit 8b281b7)
Delegating the nudge to fm_session_lock_owned_by_self changed the question it
asks. The nudge asks whether a process in this ancestry took the lock; the
ownership predicate additionally requires a verified harness in that ancestry,
so a session whose lock was written by a plain shell started being nudged to
run session start again. tests/fm-sessionstart-nudge.test.sh pins the looser
contract deliberately.

The walk stays local, now reading ppid through the portable accessor so it also
survives a ps with no -o option, and defers to the ownership predicate only for
a Windows-tagged holder, which is not in this process table at all.

(cherry picked from commit 0baf64f)
…the lock

The Windows identity added in this branch introduced a second shape into
state/.lock. Six gates read that field, and each one answered "is this value
usable" with its own inline numeric test, so every one of them read a valid
Windows holder as malformed.

The visible cost was concentrated in startup completion: the record was never
written, and the clear/compact check that consumes it could never match, so
every clear or compact on Windows repeated the full startup sequence. The
deferred network sweeps reported ownership as changed when it had not, and the
Stop auto-arm treated a dead Windows session as an unreadable lock rather than
a recoverable one. fm-lease.sh was the outlier: rather than refusing a value it
could not use, `tr -cd '0-9'` reduced the tag to its digits and produced a
number naming an unrelated process in the local table. It happened to fail
closed downstream, but deriving a wrong-namespace pid is precisely what the tag
exists to prevent, so it now takes the value whole and requires a local pid.

fm_session_pid_valid is now the single owner of that question and every gate
delegates to it, so a third identity shape cannot split them again.

Verified against the shipped bytes of each gate with a tagged lock: startup
completion now records and is recognized (main's gate reruns the full startup
on the same input), both network-ownership gates authorize their sweeps, and a
tagged lock yields no lease holder pid instead of 7204.

(cherry picked from commit 9256182)
@cr101 cr101 changed the title fix(windows): preserve session identity and add experimental native Codex ownership feat(native-owner): add experimental Windows Codex launcher Sep 19, 2026
…s/fm-public-followup.test.sh. The fixture now stops and joins its scoped remote-worker tree before deleting temporary files, and reports failure if shutdown cannot be confirmed. This prevents the late writer that caused `Directory not empty`; `git diff --check` passes. Focused Bash execution was unavailable because managed Git Bash fails with Win32 error 5; host verification command: `FM_TEST_ONLY=test_remote_secondmate_loop_delivers_and_retires bash tests/fm-public-followup.test.sh`. Windows Claude ownership has not been verified. That run-scoped exception was not applied to this CI failure
@cr101
cr101 marked this pull request as ready for review September 19, 2026 10:19
@kunchenguid

Copy link
Copy Markdown
Owner

Speaking as Kun's firstmate: triage for #4803 (cr101, feat(native-owner): add experimental Windows Codex launcher).

Classification: opt-in (tip vs main 2bcb88c38921030033a37d67ae4f5d82cea90eb4…ee9be1c8386eb4833ee630dc748782575c3babfc). Docs and bin/fm-native-codex.ps1 gate the launcher behind explicit -Experimental / empty-temp-home / empty-fleet admission; ordinary session-start does not select it. Shared lock/inbox/wake paths gain native: owner identity support and tighter wake-queue locking, but the unconfigured Linux/non-native path still uses numeric harness pids and does not auto-enable the Windows launcher. Contributor "opt-in" claim matches tip inspection for the primary surface; shared plumbing is supporting infrastructure for that gated experiment.

VISION (per-rule, inspected tip vs main + unconfigured path):

  1. One captain, one interface — aligns: captain-facing outcomes unchanged; experimental launcher is below-deck harness plumbing, not a new captain chat surface.
  2. Authority is explicit and never inferred — aligns for the launcher (explicit -Experimental, refuses populated/non-temp homes). Shared identity plumbing stays fail-closed on unrecognized owners (read-only). Residual: Windows Claude ownership explicitly unverified per PR body.
  3. Scripts own the mechanics, agents own the judgment — aligns: native owner/receipt/launcher logic lives in scripts/C#/mjs; no agent adjudicates ownership.
  4. A restart is a non-event — aligns: receipt journal + restart recovery paths; durable notification ack evidence.
  5. Delegation with a spine — aligns / cannot tell on live Claude path: Codex empty-home lifecycle live-proven; Windows Claude ownership left untested by design of this PR.
  6. The fleet outlives any vendor — aligns: adds a harness adapter candidate behind verification gates; does not couple ordinary startup to one vendor.
  7. Scope — aligns as experimental candidate docs; large surface (85 files / ~7k LOC) stays out of the default workshop path when unconfigured.

Attestation: MATCH (no-mistakes-pipeline-attestation:v1 head_sha ee9be1c8386eb4833ee630dc748782575c3babfc == HEAD).
Mergeability / CI / no-mistakes: MERGEABLE/CLEAN; all 19 checks green on HEAD including PR must be raised via no-mistakes.
Draft: yes — not auto-merge eligible while draft.
Next: waiting-author — mark ready when you want merge consideration; keep the Windows Claude / tagged-foreign-owner limits explicit. No Firstmate flag (draft / not otherwise-ready). Security FYI only: native Windows owner identity + isolated app-server policy + authenticated host ops — review before any undraft merge; no waiting-captain card.

@cr101

cr101 commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Now marked ready for review. The draft status noted in the earlier triage is no longer current.

@cr101

cr101 commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

@kunchenguid, could you please review this PR when you have a chance? Thank you.

@cr101

cr101 commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

@kunchenguid, to make review easier I'm splitting this PR into smaller pieces.
The first is #6300: the Windows/Git Bash session-lock identity work from #3553, rebased onto current main (15 files, fixes #3396, POSIX behavior unchanged, all checks green).
Next would be the remaining tagged-lock readers (#4535, #4539) and a one-file test cleanup fix.
The native Windows Codex launcher is a platform expansion, so I'd like your view on whether you want it at all before splitting that part further.
This PR stays open as the reference until then.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants