rdmpw3275m-changelog-20260830-2213-codex-remote-helper-repair
rdmpw3275m-changelog-20260830-2213-codex-remote-helper-repair
Repaired the Codex remote SSH code-mode helper without changing project data, restoring the existing ScanRoo task's ability to negotiate the helper and create a shell.
Scope
- Host:
rdmpw3275m. - Source coordination task:
01a05576-551e-7502-af54-bd854b1e56aaonrdmsm4x. - Affected task: ScanRoo task
01a01124-965f-73b2-86ea-8b080cd19e2c. - No repository, task database, auth store, credential, cookie, approval, enrollment, GUI app-server, or unrelated process was changed.
Exact state changed
- Restarted the standalone SSH Codex app-server from stale PID
6148, which was executing/usr/local/Caskroom/codex/0.150.1.upgrading/bin/codex, to PID48585executing/usr/local/Caskroom/codex/0.151.0/bin/codex. - Atomically refreshed the inode of
/usr/local/Caskroom/codex/0.151.0/bin/codex-code-mode-hostwhile preserving identical executable bytes, signature, mode, and quarantine metadata. - Recreated
/Users/richh/Documents/Codex/2026-08-16/zias the task's exact empty recorded working-directory container. It is not a project root and no repository was initialized. - Added rollback evidence under
/Users/richh/.agent-coordination/remote-helper-repair/20260830/rdmpw3275m/.
Commands and diagnostics
- Verified host identity with
scutil,arch, and the host Ed25519 fingerprint; expected fingerprint prefixKT0oBLNDmatched. - Verified Homebrew prefix
/usr/local, Codex0.151.0, helper path, file type, SHA-256, Developer ID signature, dynamic dependencies, extended attributes, current PIDs, children, executable mappings, and app-server logs. - Used
sampleon a bounded test process and temporary same-directory copies to isolate the stall to the original helper inode. All temporary diagnostic files were removed. - Preserved the old log, sent
TERMonly to the verified idle standalone app-server and MCP child, removed only its stale control socket, and relaunched explicit Homebrew Codex0.151.0. - Used an atomic verified copy/move sequence for the helper inode refresh; the exact original inode was retained for rollback evidence.
Verification
- Helper SHA-256 before and after:
e9003e97938340f9f53c6f869b764e4dfe895340e9a7e8ba40f4fff029372934. codesign --verify --strictpassed before and after; signer remainedDeveloper ID Application: OpenAI OpCo, LLC (2DC432GLL2).- Quarantine metadata was restored/preserved exactly after the rejected diagnostic hypothesis.
- Original helper path now returns its
--helpoutput successfully. - Final probe through the original ScanRoo task reported: helper
negotiation succeeded, shell creation succeeded, exit code
0,codex-cli 0.151.0, Homebrew prefix/usr/local, helper path/usr/local/Caskroom/codex/0.151.0/bin/codex-code-mode-host, and the restored task directory empty. - The original ScanRoo task is active again, performing canonical-root and one-writer discovery before any project edit.
Backup and undo
- Pre-restart log:
/Users/richh/.agent-coordination/remote-helper-repair/20260830/rdmpw3275m/app-server-before-restart.log. - Original helper inode:
/Users/richh/.agent-coordination/remote-helper-repair/20260830/rdmpw3275m/codex-code-mode-host.original-inode. - Original quarantine value:
/Users/richh/.agent-coordination/remote-helper-repair/20260830/rdmpw3275m/codex-code-mode-host.quarantine.hex. - A clean future Homebrew Codex reinstall/upgrade should supersede the preserved original inode. Moving the original inode back would also restore the observed loader stall and is only a last-resort forensic rollback.
- The empty task container may be removed only after the task is relocated or archived and no longer records that path; it contains no project data at verification time.
Outstanding owner actions
- ScanRoo's owner must resolve the canonical
rdmsm4xroot, active writer, commit, and dirty state before accepting or integrating any work. - Recheck the helper after the next Codex cask upgrade; if the in-place upgrade recreates the loader stall, prefer a clean Homebrew reinstall and retain this evidence.
- Apple Notes entry is pending: the SSH session could not enter the
logged-in Aqua audit session (
Operation not permitted). This Markdown file is present both in the canonicalrdmsm4xarchive and the host's secondary archive; a GUI-side helper must add the exact title to Notes folderrdmpw3275m.