pub const CODEX: CliBackend;Expand description
codex, measured at 0.154.0 by running it (#1339).
Disabled, and for a reason no probe can close. Its shell is core — there
is no flag that removes it, and -s read-only restricts the filesystem
rather than establishing action safety — so a spawned codex can execute
commands that never pass MUR’s handler, entitlements or HITL gate. The
design admits it only behind a verified process sandbox inherited by
child processes, and no such sandbox exists yet.
It has a row rather than being absent because absence says nothing. A
user who has codex installed should see it listed with this reason, not
silently missing — the same lesson as the subscription rail in #1334.
stream_flags is --json, not --output-format stream-json: measured,
and it carries completed items only, so a codex-backed turn cannot stream
partial output even once the sandbox exists.