What you will build
A small parser fix in a synthetic repository, with a failing test established before the agent starts. The acceptance criteria will be executable and independent of the agent’s final message.
- Bounded task contract
- Docker launches Codex
- Agent edits and tests
- Reviewer checks exported patch
Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.
Read the mechanism
Docker’s Codex integration handles supported OpenAI authentication on the host. Its sandbox does not automatically import your host ~/.codex configuration; project-level configuration is a separate input that must be reviewed.
The integration currently launches Codex with its internal approval/sandbox layer bypassed by default. That choice relies on Docker’s outer microVM and configured capabilities. It is not a recommended flag for ordinary host execution. Review the Docker boundary—workspace mode, network, credentials and MCP—before assuming the agent has a second safety layer.
The agent’s narrative is a report, not the test runner. A confident “fixed” can coexist with a failing test, a changed test that weakens the assertion, or an unrelated dependency upgrade.
Worked lab · fix one parser edge case
Create parse.mjs and parse.test.mjs in a synthetic repository:
// parse.mjs — deliberately incomplete
export function parseCount(value) {
return Number(value);
}
// parse.test.mjs
import test from 'node:test';
import assert from 'node:assert/strict';
import { parseCount } from './parse.mjs';
test('parses a non-negative integer', () => {
assert.equal(parseCount('12'), 12);
});
test('rejects empty input', () => {
assert.throws(() => parseCount(''));
});
test('rejects negative values', () => {
assert.throws(() => parseCount('-1'));
});
Run node --test parse.test.mjs on the baseline and record the failures. Commit the baseline. With approved provider access, create a clone from the main checkout:
sbx create --clone --name handbook-codex --skills off codex .
sbx run --name handbook-codex
Paste this task into the agent session:
Fix parseCount so it accepts a non-empty decimal representation of a non-negative safe integer and rejects invalid input. Preserve the existing tests and add cases for decimals, whitespace-only input and values beyond the safe-integer range. Change only parse.mjs and parse.test.mjs. Run the Node test suite and report the exact result. Do not push, open a PR or modify project configuration.
State your whitespace policy explicitly if trimming should be allowed. Requirements that leave syntax ambiguous can produce passing tests for different contracts.
Expected observations
The initial tests should fail for empty and negative input. The final candidate must pass independently rerun tests, preserve the original assertions and stay within scope. Fetch the committed patch as in chapter 6, inspect it, then test it from a disposable review checkout.
Model requests may incur provider charges. This handbook has not run or benchmarked this agent exercise; no completion or quality result is implied.
Troubleshooting
If host configuration appears missing, that is expected separation rather than an invitation to mount your home directory. If authentication fails, use Docker’s documented host flow. If tests were edited away, reject the candidate even if the runner reports success.
Interview practice
Which layer protects the host in this integration?
The Docker microVM plus its explicit sharing and integration boundaries. The default Docker launch should not be interpreted as two independent active sandbox layers.
What makes the acceptance check independent?
The reviewer retains the original requirements and tests, examines the full diff and reruns verification outside the agent’s narrative. New tests can improve coverage but must not replace the original contract silently.
Completion check
Produce a baseline failure, a scoped patch, an independent passing result and a list of untested cases. Explain why none of those alone proves production readiness.
Sources and version notes
Checked 6 October 2026; current baseline: sbx v0.46.0. Codex integration
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.