basquetWi + New ticket

lezama ca.sh deploy: GCABA box - get Elazar explicit OK before nw-lezama-cc syncs; codex AGENTS.md convention (aro_join on start, cm/cms -> read_unread)

Deferred normal plpm-llmmsgsrv-cc

Sub-tickets

No sub-tickets.
+ Add sub-ticket

Questions

No questions.

Activity

  • system created · 2026-05-29
    wi cli; parent=#572
  • system canceled · 2026-06-04
    Superseded by Elazar's 2026-06-04 directive: kill + delete the lezama codex (live sandbox-off full-access app-server daemon PID 1224 on the GCABA-restricted box - exactly the persistent non-GCABA workload lezama RESTRICTED policy forbids). #576 was 'deploy codex to lezama IF Elazar OKs'; Elazar ordered the opposite. Codex-bridge revival (#572/#634 t1-2) is whey-loopback (ws://127.0.0.1:8789), so no lezama codex is needed. Reopen only if Elazar reverses.
  • system statusChanged · 2026-06-04
    CORRECTION (was canceled): nw-lezama-cc kept the shared /usr/local/bin/codex CLI (active fleet-toolchain: ca/cfsa/cfresume/codex-update/llmlist/llmtop/title/oc) and only killed the rogue app-server daemon + trashed its unit (/etc/systemd/system/codex-app-server.service, RESTORABLE from Trash). So a lezama codex app-server is gated/disabled, not bricked. #576 stays DEFERRED: any lezama codex-agent deploy still needs explicit Elazar OK + a SUPERVISED non-dangerous config (the killed one was --dangerously-bypass-approvals-and-sandbox full-access, which violates lezama RESTRICTED). #572 core revival is whey-loopback and does NOT need this.
  • wi-cli-whey note · 2026-06-05
    Elazar explicit OK for lezama deploy 2026-06-05 (engineering DM). No longer blocked on approval; gated only on ca.sh landing in sh.git (#574). Then nw-lezama-cc syncs via sh.git pull.
task
2026-05-29
6w ago
2026-06-04 15:55