rdmpw3265m-changelog-20260830-2229-codex-upgrade-auth-blocker
rdmpw3265m changelog — Codex upgrade and authentication blocker
Codex was upgraded safely from 0.150.1 to 0.151.0 while four live proxy connections were preserved; tool execution remains blocked until the correct account is signed in locally on rdmpw3265m.
Scope
- Host:
rdmpw3265monly. - Source/coordination task:
01a05576-551e-7502-af54-bd854b1e56aaonrdmsm4x. - No application repository, project source, credential store, task database, security policy, signing state, or deployment was changed.
Files and state touched
- Homebrew cask:
codexupgraded from0.150.1to0.151.0. - New binary:
/usr/local/Caskroom/codex/0.151.0/bin/codex. - New helper:
/usr/local/Caskroom/codex/0.151.0/bin/codex-code-mode-host. - Evidence backup:
/Users/richh/.agent-coordination/remote-helper-repair/20260830/rdmpw3265m/app-server.pre-upgrade.log. - Evidence backup:
/Users/richh/.agent-coordination/remote-helper-repair/20260830/rdmpw3265m/processes.pre-upgrade.txt. - Helper probe output:
/Users/richh/.agent-coordination/remote-helper-repair/20260830/rdmpw3265m/helper-help-initial.txt. - This changelog's canonical copy:
/Users/richh/dev/LLM/Claude/changelogs/rdmpw3265m-changelog-20260830-2229-codex-upgrade-auth-blocker.mdonrdmsm4x; a secondary matching copy is placed at the same path onrdmpw3265m.
Commands and actions
- Verified the host identity and pinned SSH Ed25519 fingerprint before mutation.
- Inspected process ancestry, working directories, Unix sockets, proxy connections, cask version, helper signature/hash, app-server log, and values-free authentication presence/status.
- Sent immutable owner/context request
20260830-222533-0EEF8A97to the host-local Claude, Codex, and monitoring identities. - Ran
/usr/local/bin/brew upgrade --cask codex. - Ran
codex --version,shasum -a 256,codesign --verify --deep --strict, and a bounded real helper--helplaunch probe. - Did not stop or restart the standalone app-server or any proxy.
Verification evidence
- Homebrew reports Codex
0.151.0. - Helper SHA-256:
e9003e97938340f9f53c6f869b764e4dfe895340e9a7e8ba40f4fff029372934. - Helper signature is valid on disk and satisfies its designated requirement; signer is OpenAI OpCo, LLC.
- Helper
--helpreturned exit0and printed the expected usage text. - Existing PIDs
45356,5284,25809,62027, and78670remained alive after the cask upgrade. - The pre-upgrade app-server log showed repeated
401 Unauthorizedresponses withtoken_invalidated. /usr/local/Caskroom/codex/0.150.1/bin/codex login statusreturnedNot logged in;/Users/richh/.codex/auth.jsonwas absent. No secret value was read or recorded.
Backup and undo
- The pre-upgrade app-server log and process inventory are preserved
under
/Users/richh/.agent-coordination/remote-helper-repair/20260830/rdmpw3265m/. - Homebrew's normal rollback path is to reinstall an available older cask version if OpenAI/Homebrew republishes it; no manual binary rollback was manufactured.
- Do not restore authentication by copying another host's
auth.json, cookies, credentials, approvals, or native task database.
Outstanding owner action
- Rich or the authorized GUI-session owner must sign into the correct
Codex/ChatGPT account locally on
rdmpw3265m. - After successful sign-in creates valid local authentication,
boundedly restart only standalone SSH app-server PID
45356and verify that its four proxies reconnect on Codex0.151.0and that a real code-mode task probe succeeds. - The per-host Apple Notes entry titled
rdmpw3265m-changelog-20260830-2229-codex-upgrade-auth-blockeris pending because this repair ran over SSH outside the host's Aqua GUI session. The Markdown archive exists and must not be described as a saved Note until a GUI-side agent creates it.