-
Notifications
You must be signed in to change notification settings - Fork 1.3k
docs(cli): explain shim-free Codex token injection boundaries (#2713) #3208
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
35 changes: 35 additions & 0 deletions
35
devlog/_plan/260902_nonbug_adoption_backlog/070_wp7_shim_free_token.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,35 @@ | ||
| # wp7 — #2713 shim-free Codex token injection | ||
|
|
||
| State at entry: the narrow `ocx doctor` diagnostic requested by the issue ("env_key set + variable | ||
| absent + shim missing → actionable repair line") landed on `dev` in PR #2844 (`5734a1caf`, | ||
| `collectCodexEnvKeyReadiness` in `src/cli/doctor.ts`, tests in | ||
| `tests/doctor-codex-envkey-readiness.test.ts`). The maintainer review (score 58) and the reviewer | ||
| follow-up (2026-08-29) both settled the remaining design questions: | ||
|
|
||
| - A `systemd --user` drop-in is rejected as the default: it does not fit a root-owned server and | ||
| only reaches services launched by the user manager, not interactive shells, cron, or Desktop. | ||
| - `EnvironmentFile=` on `opencodex-proxy.service` lands only in the proxy process; it cannot | ||
| inject `OPENCODEX_API_AUTH_TOKEN` into an independently launched `codex exec`. Validated by the | ||
| reporter on a root VPS. | ||
| - Codex has no credential-file directive for `env_key`; the value must exist in the Codex process | ||
| environment. Do not invent one. | ||
| - No new token file; the existing `service-api-token` is the source. Do not add another launcher | ||
| interception at the Codex binary path (that is the hole the issue reports). | ||
| - Verdict: no `ocx codex-env` command yet; a narrow documentation update is what remains. | ||
|
|
||
| ## Scope (docs only) | ||
|
|
||
| `docs-site/src/content/docs/reference/cli/lifecycle.md`, in the `ocx codex-shim` section: a | ||
| subsection "Token injection without the shim" that states the process boundary, lists what does and | ||
| does not carry `OPENCODEX_API_AUTH_TOKEN` to Codex (shim; exporting the variable in the launching | ||
| process — shell profile, cron line, service unit that launches Codex itself; `EnvironmentFile=` on | ||
| the proxy unit does not), points to `ocx doctor`'s "Codex env_key launch readiness" line, and | ||
| reminds that the token value is never printed and must not be copied into `config.toml`. | ||
|
|
||
| ## Acceptance | ||
|
|
||
| - Section present; no new commands or config keys claimed (`skill:surface:check` unaffected). | ||
| - `bun run privacy:scan` clean. | ||
| - PR to dev; close #2713 with English rationale: doctor slice landed (#2844), documentation landed, | ||
| first-class `ocx codex-env` declined for now with the reasons above; reopen path stated. | ||
|
|
9 changes: 9 additions & 0 deletions
9
devlog/_plan/260902_nonbug_adoption_backlog/071_wp7_audit_r1_synthesis.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| # wp7 audit r1 — synthesis | ||
|
|
||
| Audit input is the issue's own review chain: maintainer review (grok-bot, score 58) and the reviewer | ||
| follow-up confirming both referenced landings on `dev` (`5734a1ca` doctor, `bb3321ca` framing) and | ||
| the process-boundary conclusion. Verified in this tree: `collectCodexEnvKeyReadiness` | ||
| (`src/cli/doctor.ts:473`) and its action line; `src/codex/shim.ts:726` is the only reader that | ||
| exports the token into a Codex process; `src/cli/index.ts:241` exports it for `ocx` itself. | ||
| Verdict: pass for a docs-only closure; nothing in the plan changes runtime behavior. | ||
|
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
For the documented systemd-unit path, this wording directs users to set
EnvironmentFile=$OPENCODEX_HOME/service-api-token, butwriteServiceApiTokenFile()writes only the raw token plus a newline (src/lib/service-secrets.ts:52-65), while systemd'sEnvironmentFile=format requires newline-separated variable assignments. Consequently the Codex unit receives noOPENCODEX_API_AUTH_TOKENand still fails with the missing-variable error. Document anExecStartwrapper that reads and exports the raw file, or require a separate protectedOPENCODEX_API_AUTH_TOKEN=...environment file instead.AGENTS.md reference: docs-site/AGENTS.md:L7-L10
Useful? React with 👍 / 👎.