Before following this workflow, read the Codex runtime contract. It defines plugin paths, model configuration, delegation, and persistence.
Boundary Discipline
Place validation, type narrowing, and error handling at system boundaries. Trust internal code unconditionally. Business logic lives in pure functions. The shell is thin and mechanical.
Why: Scattered validation is noisy, redundant, and gives a false sense of safety. Keep logic out of framework wiring so it can be tested without the framework.
The pattern:
- At boundaries (CLI args, config files, external APIs, network protocols): validate, return errors, handle defensively.
- Inside the system: typed data, error propagation, no re-validation. Trust the types.
- Across the boundary. Expose domain concepts, not the boundary's private representation. Keep general-purpose mechanism inside and special-purpose policy at the edge.
Applications:
Validation and error handling:
- Validate config at parse time (the boundary), not inside business logic
- Parse raw data into domain types at the boundary
- Do not re-export transport, storage, framework, or wire types through the public surface
- No redundant nil checks deep in call chains if the boundary already validated
Code organization:
- Business logic in pure functions with no framework dependencies
- Parse functions: pure transforms from raw bytes to typed state
- Prompt construction: structured state in, string out
- Scoring and assessment: pure transforms from state to results
The tests:
- "Is this data crossing a system boundary right now?" If not, validation is redundant.
- "Can this be a pure function that the shell just calls?" If yes, extract it.
1---2name: principle-boundary-discipline3description: Apply when wiring validation, error handling, or framework adapters. Concentrate guards at system boundaries (CLI, config, network, external APIs); trust internal types and keep business logic in pure functions.4---56Before following this workflow, read [the Codex runtime contract](../../CODEX.md). It defines plugin paths, model configuration, delegation, and persistence.78# Boundary Discipline910Place validation, type narrowing, and error handling at system boundaries. Trust internal code unconditionally. Business logic lives in pure functions. The shell is thin and mechanical.1112**Why:** Scattered validation is noisy, redundant, and gives a false sense of safety. Keep logic out of framework wiring so it can be tested without the framework.1314**The pattern:**15- **At boundaries** (CLI args, config files, external APIs, network protocols): validate, return errors, handle defensively.16- **Inside the system:** typed data, error propagation, no re-validation. Trust the types.17- **Across the boundary.** Expose domain concepts, not the boundary's private representation. Keep general-purpose mechanism inside and special-purpose policy at the edge.1819**Applications:**2021Validation and error handling:22- Validate config at parse time (the boundary), not inside business logic23- Parse raw data into domain types at the boundary24- Do not re-export transport, storage, framework, or wire types through the public surface25- No redundant nil checks deep in call chains if the boundary already validated2627Code organization:28- Business logic in pure functions with no framework dependencies29- Parse functions: pure transforms from raw bytes to typed state30- Prompt construction: structured state in, string out31- Scoring and assessment: pure transforms from state to results3233**The tests:**34- "Is this data crossing a system boundary right now?" If not, validation is redundant.35- "Can this be a pure function that the shell just calls?" If yes, extract it.