Fix Codex startup approvals and companion upgrades
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
---
|
||||
name: codex-app-server-upgrade
|
||||
description: Safely check, update, or self-upgrade the host Codex app-server and Codex CLI binary for this project. Use when asked to upgrade Codex, run app-server update checks, restart Codex after an update, or let Codex invoke its own app-server upgrade through the project script.
|
||||
description: Safely check, update, or self-upgrade the host Codex app-server, Codex CLI binary, and its code-mode host for this project. Use when asked to upgrade Codex, repair or update its code-mode host, run app-server update checks, restart Codex after an update, or let Codex invoke its own app-server upgrade through the project script.
|
||||
---
|
||||
|
||||
# Codex App Server Upgrade
|
||||
@@ -19,6 +19,14 @@ If the current directory is not the project root, find the nearest repository co
|
||||
|
||||
## Commands
|
||||
|
||||
Start with automatic approval review when needed:
|
||||
|
||||
```bash
|
||||
scripts/start-codex-app-server start --approve-for-me
|
||||
```
|
||||
|
||||
For a durable setting across restarts and upgrades, set `CODEX_APPROVE_FOR_ME=1` in `.env`.
|
||||
|
||||
Check status:
|
||||
|
||||
```bash
|
||||
@@ -41,7 +49,9 @@ scripts/start-codex-app-server check-updates -y
|
||||
|
||||
## Self-Upgrade Behavior
|
||||
|
||||
When the app-server is running, `check-updates -y` downloads and validates the new Codex binary first, then starts a detached worker to stop the app-server process group, replace the binary, and start the app-server again. This is the correct path even when Codex itself initiated the command.
|
||||
When the app-server is running, `check-updates -y` downloads and validates matching Codex, code-mode host, and Linux `bwrap` binaries from the same release first. It then starts a detached worker to stop the app-server process group, replace all downloaded components, and start the app-server again. Release archives may contain target-suffixed executable names; the installer normalizes them to their stable installed paths.
|
||||
|
||||
If Codex is already current but its sibling `codex-code-mode-host` binary is missing, `check-updates` downloads and installs the checked companion binary. On Linux it also repairs the bundled `bwrap` helper when needed.
|
||||
|
||||
Expect the current Codex connection or tool call to be interrupted after the handoff. After a short delay, verify the outcome with:
|
||||
|
||||
@@ -57,7 +67,7 @@ sed -n '1,160p' run/codex-app-server-upgrade.log
|
||||
|
||||
## Safety Rules
|
||||
|
||||
- Do not manually `kill`, `mv`, or overwrite the Codex binary for this workflow.
|
||||
- Do not manually `kill`, `mv`, or overwrite the Codex or code-mode host binaries for this workflow.
|
||||
- Do not assume `/usr/local/bin/codex`, a specific home directory, or any machine-specific path.
|
||||
- Use `CODEX_BIN=/absolute/path/to/codex` only when the user or environment explicitly requires a non-default binary.
|
||||
- If the script reports that it cannot replace the binary without write permission, stop and report that non-interactive privileges or a writable `CODEX_BIN` are required.
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
interface:
|
||||
display_name: "Codex App Server Upgrade"
|
||||
short_description: "Safely self-upgrade Codex app-server."
|
||||
default_prompt: "Safely check for and apply a Codex app-server upgrade using the project script."
|
||||
short_description: "Safely upgrade Codex and its code-mode host."
|
||||
default_prompt: "Use $codex-app-server-upgrade to safely update Codex and its code-mode host."
|
||||
|
||||
Reference in New Issue
Block a user