Uh oh!
There was an error while loading. Please reload this page.
fix(server): update standalone Codex installs with codex update - #5630
fix(server): update standalone Codex installs with codex update#5630hkarlsen06 wants to merge 3 commits into
Conversation
The Codex driver declared `nativeUpdate: null`, so a standalone install (`~/.local/bin/codex` -> `~/.codex/packages/standalone/...`) matched none of the package-manager heuristics and fell through to the bare-name fallback in `resolvePackageManagedProviderMaintenance`, which assumes an unclassified install is npm-managed. One-click update then ran `npm install -g @openai/codex@latest`, which updates a different install than the one being probed - creating one outright when no npm copy existed. The post-update re-probe still read the untouched standalone binary, still saw `behind_latest`, and recorded `unchanged`, so the provider reported "still needs an update" on every attempt. Declare the native update path the way ClaudeDriver already does for the identical `~/.local/bin` layout, so these installs are updated with `codex update`. Refs pingdotgg#5629
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🟠 High
isCodexNativeCommandPath classifies a configured binary under /.codex/packages/standalone/ as native, but the nativeUpdate action always runs the bare command codex rather than the configured binaryPath. When the user points binaryPath at the standalone release binary and codex is absent from PATH (or resolves to a different installation), the update fails or updates the wrong installation. The update command should use the configured binary path instead of the hardcoded "codex" executable.
🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/server/src/provider/Drivers/CodexDriver.ts around line 84:
`isCodexNativeCommandPath` classifies a configured binary under `/.codex/packages/standalone/` as native, but the `nativeUpdate` action always runs the bare command `codex` rather than the configured `binaryPath`. When the user points `binaryPath` at the standalone release binary and `codex` is absent from `PATH` (or resolves to a different installation), the update fails or updates the wrong installation. The update command should use the configured binary path instead of the hardcoded `"codex"` executable.
There was a problem hiding this comment.
Sorry, I'm unable to act on this request because you do not have permissions within this repository.
There was a problem hiding this comment.
Pull request overview
This PR fixes an incorrect “Update now” loop for Codex when the CLI was installed via OpenAI’s standalone installer by teaching the server-side Codex driver to recognize that layout as “native-updatable” and to run codex update instead of defaulting to an npm-global update command.
Changes:
- Add Codex native-update detection (
isCodexNativeCommandPath) and wirenativeUpdateto runcodex update. - Add unit tests for Codex native path matching to ensure package-manager installs remain package-manager-updated.
- Extend maintenance capability resolution tests to ensure native detection works when only a symlink’s real path matches the native layout.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| apps/server/src/provider/providerMaintenance.test.ts | Adds coverage ensuring native-update selection works via realCommandPath when a PATH-resolved symlink points into a native install layout. |
| apps/server/src/provider/Drivers/CodexExecutable.test.ts | New tests validating Codex standalone/native path matching and negative cases for npm/bun/Homebrew layouts. |
| apps/server/src/provider/Drivers/CodexDriver.ts | Implements Codex native update capability (codex update) and adds a path matcher for standalone installs to avoid falling back to npm-global updates. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
ApprovabilityVerdict: Needs human review 2 blocking correctness issues found. This PR enables a new update pathway for standalone Codex installs by configuring You can customize Macroscope's approvability policy. Learn more. |
`makeNativeProviderMaintenanceCapabilities` took its executable from the driver definition, so a native update always spawned the bare command name and let PATH decide which binary it hit. Classification, meanwhile, was performed on the configured `binaryPath`. Those two disagree exactly when a provider is pointed at something other than the first PATH match - the multi-install case this classification exists to serve. A provider configured with an explicit standalone path would be offered a one-click update that then self-updated whichever install happened to be first on PATH, or failed outright when the bare command was absent. Pass the resolved command path through as the update executable, falling back to the definition's bare name when nothing was resolved. Refs pingdotgg#5629
Uh oh!
There was an error while loading. Please reload this page.
`makeProviderMaintenanceCapabilities` joined the executable and its args with a space to build `command`, the string the UI shows and users copy as the manual update. Now that native updates carry an absolute executable path, an install under a directory containing spaces rendered as a command that splits into the wrong tokens when pasted. Quote tokens containing whitespace. Execution is unaffected either way - the runner spawns `executable` with `args` as a list, and shell mode on Windows already escapes through `escapeWindowsShellArg` - so this is purely about the copyable string. Refs pingdotgg#5629
t3dotgg
commented
Aug 28, 2026
Note 🤖 GPT-5.6 Sol responding on behalf of Theo We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together. We are keeping the standalone Codex update fix in the open #4065 instead of maintaining two implementations. The symlink detection, resolved binary coverage, and Windows npm-shim case from this PR remain useful input for that review. If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. |
Fixes the permanent "Codex still appears outdated" loop reported in #5629.
Problem
CodexDriverdeclarednativeUpdate: null. A Codex CLI installed with OpenAI's standalone installer lives at~/.local/bin/codexand symlinks into~/.codex/packages/standalone/releases/<ver>/bin/codex, which matches none of the package-manager heuristics inresolvePackageManagedProviderMaintenance. With the provider's default barebinaryPathof"codex", resolution then fell through to the fallback atproviderMaintenance.ts:311, which assumes an unclassified install is npm-managed and reportscanUpdate: true.Clicking Update now therefore ran
npm install -g @openai/codex@latestagainst an install npm does not own. The command exits 0, soproviderMaintenanceRunnerre-probed, still resolved the untouched standalone binary, still sawbehind_latest, and recordedunchanged— surfacing "Provider still needs an update" on every attempt.The silent half is worse than the loop: on a machine with no npm copy, that command creates a second Codex install the user never asked for, while the binary they actually run stays stale.
Fix
Declare Codex's native update path the way
ClaudeDriveralready does for the identical~/.local/binlayout:codex updateis a first-class subcommand of the CLI. BecauserealCommandPathis already threaded throughresolveProviderMaintenanceCapabilitiesEffect, the/.codex/packages/standalone/clause matches through the symlink regardless of the link's name.Tests
CodexExecutable.test.ts(new) — asserts standalone paths match and that npm, bun and Homebrew paths do not, so package-manager-owned installs keep being updated by their package manager.providerMaintenance.test.ts— adds coverage for a native install matched only viarealCommandPaththrough a symlink. That path had no test, and it is the mechanism this fix depends on.apps/serversuite: 1917 passed, 7 skipped, 0 failures.tsgo --noEmit,vp lintandvp fmt --checkall clean.Deliberately not fixed here
#5629 also describes a second defect: the
providerMaintenance.ts:311fallback treats "could not classify this install" as "assume npm" for bare-namebinaryPathvalues, while the path-separator branch two lines below correctly declines tomanual-only. Tightening it looked like a natural companion change, but it is not safe as-is.A Windows npm global install resolves to
%APPDATA%\npm\codex.cmd.realPathdoes not rewrite.cmdshims, andisNpmGlobalCommandPathrequires a/node_modules/segment, so that path matches nothing and currently reaches npm-global only through this fallback. Making the fallback stricter would silently take the update button away from Windows npm users.Correcting that properly needs a Windows npm shim heuristic first, which felt like it belonged in its own PR with its own test matrix rather than riding along with a driver fix. Happy to follow up if maintainers want it.
Note on scope
isCodexNativeCommandPathmatches~/.local/bin/codexas well as the standalone release path, mirroringisClaudeNativeCommandPath. Native matching runs before the package-manager checks, so a Codex binary manually symlinked into~/.local/binfrom a bun or pnpm install would now be offeredcodex updateinstead of its package manager's command. That matches existing Claude behaviour, andcodex updatereports the owning install method rather than doing something destructive — but I'm happy to drop the~/.local/binclause and rely solely on/.codex/packages/standalone/if you'd prefer the narrower match.Note
Medium Risk
Changes which executable runs for provider updates and Codex maintenance classification; behavior is covered by new tests but affects update execution paths.
Overview
Fixes the outdated Codex loop for OpenAI’s standalone installer by treating those installs as native and offering
codex updateinstead ofnpm install -g @openai/codex@latest.Codex driver: Adds
isCodexNativeCommandPath(paths under~/.local/bin/codex/~/.codex/packages/standalone/) and wiresnativeUpdatewithcodex update, matching the Claude driver pattern.Shared maintenance: Native update actions now spawn the resolved binary path (symlink or configured path), not the bare command name, so updates hit the install that was classified. Copyable update strings quote executable paths that contain spaces; spawn still uses unquoted argv.
Tests cover Codex path classification, symlink
realPathmatching, configured-vs-PATH binaries, and spaced paths.Reviewed by Cursor Bugbot for commit d09a15d. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Fix
codex updatefor standalone Codex installs detected by command pathisCodexNativeCommandPathto classify a binary as a standalone Codex install when its path ends with/.local/bin/codex[.exe]or contains/.codex/packages/standalone/.nativeUpdateconfig into the Codex driver that runscodex updatewhen the binary matches the standalone layout, including symlink realpath resolution.Macroscope summarized d09a15d.