Skip to content

bug: Gator Codex harness fails on Codex ≥0.156.0 because the sandbox account ID is a credential placeholder #4214

Description

@purp

User Story

I use OpenShell's Gator agent to supervise PR reviews on a local Docker-driver gateway. I directly encountered Gator watchers that never post to their PRs because every Codex cycle exits within seconds, so I need the Gator image to run a current Codex CLI with ChatGPT-account auth.

Problem Statement

Gator's Codex harness fails on every cycle when the Gator image contains Codex CLI 0.156.0 or later. Codex exits with selected workspace missing from routing discovery, prints no OPENSHELL_AGENT_RESULT, and the supervisor records transient_failure / missing_agent_result indefinitely.

Codex 0.156.0 added client-side workspace routing (codex-rs/app-server/src/request_processors/account_processor/workspace_routing.rs). On each run, it calls GET /backend-api/wham/accounts/check and keeps only the returned workspace whose id equals the local auth.json tokens.account_id (line 332 at rust-v0.156.0 and rust-v0.160.0). Inside a Gator sandbox, CODEX_AUTH_ACCOUNT_ID is an OpenShell credential placeholder (openshell:reso…), not the real account ID. The gateway substitutes the real value only in outbound requests, so the server returns the real workspace ID, the local comparison never matches, and Codex aborts. The same account and Codex version work on the host, where auth.json holds the real ID.

scripts/agents/gator/Dockerfile installs @openai/codex@${CODEX_VERSION} with ARG CODEX_VERSION=latest. Docker caches that layer, so each machine keeps whatever version it first built. Machines with a pre-0.156.0 cache keep working, and any uncached build gets the broken version. Because of this, the failure shows up at different times on different machines instead of in a reviewed change.

#4065 compounds the problem. It changed the manifest default model to gpt-6.1-sol. Codex 0.155.1 rejects that model with The 'gpt-6.1-sol' model is not supported when using Codex with a ChatGPT account (plus Model metadata for 'gpt-6.1-sol' not found), and the versions that accept it fail the workspace check. As a result, Gator currently can't run its default model with ChatGPT auth at any Codex version.

Impact / Why This Matters

  • New or rebuilt Gator images are broken for ChatGPT-auth users, whatever model they use.
  • Failing watchers look healthy: the sandboxes are Ready, status.json shows only missing OPENSHELL_AGENT_RESULT after harness exit 1, and the harness output is deleted after each cycle. Diagnosing it took a manual probe inside the sandbox.
  • Current workaround: build with a temporary --from context pinned to CODEX_VERSION=0.155.1 and launch with CODEX_MODEL=gpt-6-sol. That freezes Gator on an old CLI and abandons the manifest default.

Acceptance Criteria

  • An uncached Gator image build with the pinned Codex version completes a watch cycle (emits OPENSHELL_AGENT_RESULT) using ChatGPT-account auth and the manifest default model.
  • The Gator Dockerfile pins an explicit Codex CLI version, so Codex upgrades happen through reviewed changes.
  • Codex workspace routing succeeds inside the sandbox without exposing a bearer credential to the workload.

Reproduction Steps

Prerequisites: a Docker-driver OpenShell gateway, host gh auth, and host Codex logged in with a ChatGPT account (~/.codex/auth.json, auth_mode: chatgpt). Run from the repository root.

  1. Create a Gator build context pinned to a current Codex release:

    ctx="$(mktemp -d)"
    cp -R scripts/agents/gator/. "$ctx"/
    sed -i.bak 's/^ARG CODEX_VERSION=latest$/ARG CODEX_VERSION=0.160.0/' "$ctx/Dockerfile"
  2. Launch a watcher on any open PR:

    ./scripts/agents/run.sh --agent gator --gateway <gateway> --name gator-repro \
      --from "$ctx" --watch "Review and monitor PR #<n> through the gator-gate workflow. Scope this invocation only to PR #<n>."
  3. Within about 30 seconds, the cycle fails:

    openshell --gateway <gateway> sandbox exec --name gator-repro -- cat /sandbox/.openshell-agent/status.json
    # "status":"transient_failure","reason":"missing_agent_result","notes":"missing OPENSHELL_AGENT_RESULT after harness exit 1; upstream transport failure detected"
  4. Run a trivial prompt through the harness adapter to see the actual error:

    openshell --gateway <gateway> sandbox exec --name gator-repro -- bash -c 'printf "Reply with the single word OK. Do not run any tools.\n" > /tmp/probe.txt && CODEX_MODEL=gpt-6.1-sol CODEX_REASONING=medium bash /etc/openshell/agent-payload/runtime/harnesses/codex/exec.sh /tmp/probe.txt'
    # ERROR: selected workspace missing from routing discovery

    The result is the same with CODEX_MODEL=gpt-6-sol.

  5. Confirm the credential shape inside the sandbox (prints prefixes only):

    openshell --gateway <gateway> sandbox exec --name gator-repro -- bash -c 'echo "${CODEX_AUTH_ACCOUNT_ID:0:14}"'
    # openshell:reso
  6. Control: on the host, with the same account and host Codex 0.160.0 (codex --version), the same prompt succeeds:

    printf 'Reply with the single word OK. Do not run any tools.\n' | codex exec --skip-git-repo-check --ephemeral -c 'model="gpt-6.1-sol"' -
    # OK
  7. Contrast: repeat steps 1–4 with CODEX_VERSION=0.155.1. gpt-6.1-sol fails with not supported when using Codex with a ChatGPT account, and gpt-6-sol succeeds.

Environment

  • OpenShell CLI: 0.1.3-dev.89+g3592a482c
  • Gateway: 0.1.3-dev.34+g07a486d75 (Docker compute driver, local mTLS)
  • Host: macOS (Darwin 25.6.0) arm64; Docker Engine 29.8.1 linux/arm64
  • Gator payload_version: 9, harness codex, manifest model gpt-6.1-sol
  • Codex auth: ChatGPT account (Business plan)
  • Codex versions tested: 0.155.1 (in sandbox and on host), 0.160.0 (in sandbox and on host). 0.156.0–0.159.x were checked in source only, not run.

Suggested UX (if applicable)

Pinning would make the CLI version an explicit, reviewed value that's bumped together with model defaults:

ARG CODEX_VERSION=<tested version>

How Codex should get a usable account ID inside the sandbox is an open design question. Options include:

  • Delivering the account ID as a non-secret provider value instead of a placeholder. It identifies a workspace and isn't a bearer credential, but this needs a security decision.
  • Having the gateway answer or rewrite accounts/check so it's consistent with the placeholder.
  • Configuring Codex to skip client-side workspace routing, if it supports that.

Logs

OpenAI Codex v0.160.0
model: gpt-6.1-sol
ERROR: Reconnecting... 5/5
warning: Falling back from WebSockets to HTTPS transport. selected workspace missing from routing discovery
ERROR: selected workspace missing from routing discovery
OpenAI Codex v0.155.1
model: gpt-6.1-sol
warning: Model metadata for `gpt-6.1-sol` not found. Defaulting to fallback metadata; this can degrade performance and cause issues.
ERROR: {"type":"error","status":400,"error":{"type":"invalid_request_error","message":"The 'gpt-6.1-sol' model is not supported when using Codex with a ChatGPT account."}}

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions