Goal
Install and manage the daemon through launchd with honest login/boot behavior, safe config generations and reversible lifecycle commands.
Create one active Codex goal from the statement above when this issue is dispatched. The Project Goal field is a work specification; it does not start an agent. Do not invent a token budget.
Execution contract
| Field |
Value |
| Goal key |
G15 |
| Stage |
M3 - Reliability qualification |
| Initial status |
Backlog |
| Primary agent |
gpt-5.6-luna / max |
| Priority / risk |
P1 / High |
| Test profiles |
offline, trusted-runtime |
Use one issue branch/worktree and one focused PR. Independent Luna max review is required for authentication, protocol, concurrency, resource ownership, cleanup or service identity boundaries; other changes need independent contract review. Model fields are routing instructions, not GitHub user assignments.
Dependencies
Dependencies must be Done before implementation begins. A new issue is not blocked simply because its future evidence has not been collected.
Scope
startup/unstartup/restart/doctor installation and config persistence. Do not promise cold-boot access unless G02 established it.
TDD and failure evidence
- Red: CLI without an interactive shell/ambient env uses correct endpoint/keychain paths.
- Test stale lock, duplicate launch registration, malformed config, generation update mid-job, rollback and daemon crash restart.
- Run actual supported login/lock/reboot mode; uninstall does not automatically delete Apps or legacy workers.
Capture a meaningful failing case before the implementation, then green evidence and relevant refactor checks. Tooling/prose-only work uses appropriate negative checks without artificial application tests. Live/runtime profiles require reviewed commits, a dedicated trusted test environment and explicit authorization for the concrete experiment. Public PR CI uses hosted environments without credentials. Planned or skipped tests never count as passed.
Acceptance criteria
Safety invariants
Preserve existing manual runners; no global Docker prune/context switching, broad process kill, implicit App enrollment, busy-job cancellation during ordinary scale-down or transparent workflow replay. Use only verifiably owned resources. Keep management credentials and raw secret-bearing SDK errors out of worker environments, logs, fixtures and commits; per-worker JIT transport follows G01. Native pools remain trusted-only.
Design references
Goal
Install and manage the daemon through launchd with honest login/boot behavior, safe config generations and reversible lifecycle commands.
Create one active Codex goal from the statement above when this issue is dispatched. The Project Goal field is a work specification; it does not start an agent. Do not invent a token budget.
Execution contract
Use one issue branch/worktree and one focused PR. Independent Luna max review is required for authentication, protocol, concurrency, resource ownership, cleanup or service identity boundaries; other changes need independent contract review. Model fields are routing instructions, not GitHub user assignments.
Dependencies
Dependencies must be Done before implementation begins. A new issue is not blocked simply because its future evidence has not been collected.
Scope
startup/unstartup/restart/doctor installation and config persistence. Do not promise cold-boot access unless G02 established it.
TDD and failure evidence
Capture a meaningful failing case before the implementation, then green evidence and relevant refactor checks. Tooling/prose-only work uses appropriate negative checks without artificial application tests. Live/runtime profiles require reviewed commits, a dedicated trusted test environment and explicit authorization for the concrete experiment. Public PR CI uses hosted environments without credentials. Planned or skipped tests never count as passed.
Acceptance criteria
Safety invariants
Preserve existing manual runners; no global Docker prune/context switching, broad process kill, implicit App enrollment, busy-job cancellation during ordinary scale-down or transparent workflow replay. Use only verifiably owned resources. Keep management credentials and raw secret-bearing SDK errors out of worker environments, logs, fixtures and commits; per-worker JIT transport follows G01. Native pools remain trusted-only.
Design references