Skip to content

fix(codex): stop recursive dynamic-launcher shims - #1441

Closed
comfuture wants to merge 17 commits into
lidge-jun:devfrom
comfuture:fix/1439-mise-shim-recursion
Closed

comfuture wants to merge 17 commits into
lidge-jun:devfrom
comfuture:fix/1439-mise-shim-recursion

Conversation

@comfuture

@comfuture comfuture commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Stop generated Unix Codex autostart shims from spinning forever when a saved dynamic launcher resolves codex back to the wrapper, as observed with mise exec -- codex.
  • Validate fresh installs, direct refreshes, and guarded auto-restores with a bypassed, bounded --version probe before committing state. Unsafe results and unexpected probe exceptions roll back the new launcher, prior owned backup, wrapper, and state transaction.
  • Isolate launcher validation in a detached process group without relying on shell job control. Timeout, background descendants, and cleanup failure are classified before rollback; terminated groups are verified with exact ESRCH handling.
  • Detect recursive redispatch even when a descendant escapes into a new session or process group by observing a probe-only private sentinel for the full five-second validation window. An inherited descendant lease provides earlier liveness evidence but is not trusted as the sole completion signal.
  • Drain launcher diagnostics with a bounded fallback, store probe metadata in a private temporary directory, and preserve user launchers across partial writes and concurrent replacements.
  • Revalidate generated wrappers after probing and use recorded fingerprints during rollback, so an updater replacement is neither committed as an owned shim nor unlinked.
  • Revision and transactionally regenerate obsolete installed Unix shims. Safe saved launchers upgrade in place; unsafe recursive backups remove the obsolete shim and restore the original launcher.
  • Keep same-PID and bounded-depth runtime guards as backstops. Exec recursion fails immediately; one legitimate new-PID nested Codex invocation remains allowed, while repeated child-process shim redispatch exits 126 with the supported ocx codex-shim uninstall recovery command.
  • Add regression coverage for same-PID, child-process, delayed detached-session redispatch, obsolete-shim migration, dash compatibility and seam activation, immediate diagnostics, descendant cleanup, timeout and exception rollback, partial writes, concurrent replacement in every install and repair path, existing-backup preservation, and valid child invocation.
  • Document launcher validation and remediation in the canonical lifecycle page and all translated lifecycle pages.
  • Record the bounded behavioral-probe choice, process-group containment boundary, five-second window, and rollback invariants in the runtime Decision Log.
  • Rebased onto upstream/dev at 316f6758be0bd47c5f8d183bbc797a6dcf2d4c9e, including the CLI root, command-registry, and normalized dispatch-exit integration; the shim patch rebased without conflict.

Closes #1439

Verification

  • Exact current head: 67bb96628b375fe202ab2ea4b975a502adefe30f.
  • bun run typecheck passed on the exact current head.
  • bun test tests/codex-shim.test.ts tests/codex-shim-readiness.test.ts tests/codex-shim-autorestore.test.ts passed on the exact current head: 80 passed, 0 failed.
  • bun run privacy:scan passed on the exact current head.
  • cd docs-site && bun run build passed on the exact current head and built 265 pages.
  • OCX_TEST_NO_QUEUE=1 bun run prepush on the pre-rebase shim-equivalent head ran 10,978 tests: 10,969 passed, 8 skipped, and one static SQLite fixture collided with the pre-existing concurrent test runner. That exact failed case passed immediately in isolation: 1 passed, 0 failed. The typecheck phase passed; privacy passed separately after the test phase.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
    • The canonical English lifecycle page and Korean, Russian, Japanese, and Simplified Chinese translations document validation refusal and remediation.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.
    • Probes bypass service startup, are bounded, retain only bounded temporary diagnostics inside a private directory, observe process-independent re-entry for the full five-second window, use an inherited lease as supplemental liveness evidence, terminate the original isolated process group, and roll back before state commit. Probe metadata contains no secrets.

Review readiness checklist

This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:

  • All CI tests are green on my local testing.

  • I pushed my PR to the latest dev commit.

  • I resolved all correct Codex and CodeRabbit findings.

  • My PR is ready for review.

Summary by CodeRabbit

  • Bug Fixes

    • Prevented Unix command shims from recursively invoking themselves.
    • Installations, repairs, and upgrades now validate launchers before applying changes.
    • Unsafe, failed, timed-out, or incomplete checks are rejected and rolled back safely.
    • Improved process cleanup, diagnostics, backup protection, and restoration of original launchers.
    • Preserved valid nested command execution without affecting expected output.
  • Documentation

    • Updated lifecycle guidance in multiple languages with launcher validation and recovery details.
  • Tests

    • Expanded coverage for recursion, timeouts, cleanup, concurrency, rollback, and successful child invocation.

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working review-ready

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants