Files
codex/scripts/codex_package/README.md
Michael Bolin eefd6490d6 package: include zsh fork in Codex package
Summary:
- add a checked-in codex-zsh DotSlash manifest for supported Unix targets
- fetch the matching zsh fork artifact during package builds and install it at codex-resources/zsh/bin/zsh when available
- expose the bundled zsh fork through install-context and have Config use it as the runtime zsh path for packaged installs
- remove the user/profile zsh_path config override now that the fork is package-managed
- update app-server zsh-fork integration tests to spawn from a temporary package layout instead of configuring zsh_path directly
- use copyfile for package executable staging so local package smoke tests do not preserve platform-specific source metadata

Test Plan:
- just fmt
- just write-config-schema
- just bazel-lock-update
- just bazel-lock-check
- just fix -p codex-config -p codex-core -p codex-exec
- just fix -p codex-app-server
- just fix -p codex-core -p codex-app-server -p codex-cli -p codex-exec -p codex-mcp-server -p codex-tui
- python3 -m py_compile scripts/codex_package/cli.py scripts/codex_package/layout.py scripts/codex_package/zsh.py
- python3 -m unittest discover scripts/codex_package
- cargo test -p codex-core default_zsh_path_sets_runtime_zsh_path
- cargo test -p codex-core session_new_fails_when_zsh_fork_enabled_without_packaged_zsh
- cargo test -p codex-core restricted_read_implicitly_allows_helper_executables
- cargo test -p codex-config
- cargo test -p codex-app-server turn_start_shell_zsh_fork_executes_command_v2
- cargo test -p codex-app-server turn_start_shell_zsh_fork
- cargo check -p codex-cli -p codex-exec -p codex-mcp-server
2026-05-22 17:30:19 -07:00

3.6 KiB

Codex package builder

This package contains the implementation behind scripts/build_codex_package.py. The top-level script is the stable executable entry point; these modules keep the package-building logic split by responsibility.

The builder creates a canonical Codex package directory:

.
├── codex-package.json
├── bin
│   └── <entrypoint>[.exe]
├── codex-resources
│   ├── bwrap                             # Linux only
│   ├── zsh/bin/zsh                       # supported Unix targets only
│   ├── codex-command-runner.exe          # Windows only
│   └── codex-windows-sandbox-setup.exe   # Windows only
└── codex-path
    └── rg[.exe]

The package directory is the primary artifact. Archive formats such as .tar.gz, .tar.zst, and .zip are serializations of that directory.

If --target is omitted, the builder uses the release target for the current host platform. On Linux, that default is a musl target to match Codex release artifacts; pass a GNU Linux target explicitly for native glibc local builds. If --package-dir is omitted, the builder creates a new temporary directory and prints its path after the package is built.

The --variant flag selects the package entrypoint. Supported variants are codex and codex-app-server. The version field in codex-package.json is read from [workspace.package].version in codex-rs/Cargo.toml.

Source-built artifacts

Artifacts built from this repository are built by the package builder in one grouped cargo build command per package when they are needed and no prebuilt override was provided:

  • all targets: the selected entrypoint, unless --entrypoint-bin is provided
  • Linux targets: bwrap, unless --bwrap-bin is provided
  • Windows targets: codex-command-runner and codex-windows-sandbox-setup, unless the corresponding prebuilt helper flags are provided

The default cargo profile is dev-small because local iteration should favor fast, small builds. Release jobs should pass --cargo-profile release and an explicit target. Release jobs that already built and signed/notarized the entrypoint should pass --entrypoint-bin so the package contains that exact binary instead of rebuilding it.

Release jobs that already built package resource binaries should also pass the corresponding resource flags: --bwrap-bin for Linux packages, and --codex-command-runner-bin plus --codex-windows-sandbox-setup-bin for Windows packages. This keeps package archive creation as a pure staging step after signing instead of rebuilding resources.

When the builder source-builds an entrypoint for a Darwin or Linux target, it downloads and verifies the matching Codex-built V8 release pair before invoking Cargo and sets RUSTY_V8_ARCHIVE plus RUSTY_V8_SRC_BINDING_PATH for that build. Windows targets keep Cargo's release-build MSVC artifact path. Explicit overrides remain authoritative when both variables are already set. Set V8_FROM_SOURCE=1 to leave the build with the v8 crate source-build path.

rg is not built from this repository, so the builder fetches it from the DotSlash manifest at scripts/codex_package/rg. Downloaded archives are cached under $TMPDIR/codex-package/<target>-rg and are reused only after the recorded size and SHA-256 digest have been verified. Pass --rg-bin to use a local ripgrep executable instead.

The patched zsh fork used by shell_zsh_fork is fetched from the DotSlash manifest at scripts/codex_package/codex-zsh when the selected target has a matching prebuilt artifact. Downloaded archives are cached under $TMPDIR/codex-package/<target>-zsh and installed at codex-resources/zsh/bin/zsh.