Linux desktop docs only advertise a mutable latest/ .deb; checksum-pinned packagers break on overwrite
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 68/100
- Tipo di issue
- Documentazione
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- debian, linux
- Ambito
- documentation, release
Direzione di ricerca
Inizia dalla pagina Desktop app (Linux) collegata nell’issue e confronta i suoi link latest/ mutabili con gli URL versionati del pool e l’indice APT Packages fornito. Documenta il percorso versionato stabile e la fonte del checksum accanto ai link di praticità, mantenendo il contratto sul nome del file indicato. Il lavoro è completato quando i manutentori dei pacchetti downstream possono trovare le informazioni sulla versione e su SHA256 senza dover dipendere da un blob latest/ sovrascritto.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
What is the type of issue?
- Documentation is missing
- Documentation is confusing
What is the issue?
The Linux desktop install docs point packagers and users at a mutable blob:
https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_amd64.debhttps://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_arm64.deb
That path is overwritten in place. On 2026-08-13 20:11 UTC, latest/chatgpt_amd64.deb changed from 26.803.81509 (sha256 a9bf91a3…) to 26.810.41047 (sha256 78715fa3…, 391786694 bytes). Any PKGBUILD / Nix FOD / Guix origin that pins sha256 against latest/ fails with FAILED on the next makepkg.
The durable contract already exists and works. It is just not documented on the Linux install page:
| What | URL |
|---|---|
APT Packages (includes Version + SHA256) |
https://persistent.oaistatic.com/codex-app-prod/linux/deb/dists/stable/main/binary-amd64/Packages |
Versioned pool .deb |
https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_26.810.41047_amd64.deb |
Verified today against that Packages file:
Package: chatgpt
Version: 26.810.41047
Filename: pool/main/c/chatgpt/chatgpt_26.810.41047_amd64.deb
Size: 391786694
SHA256: 78715fa3cd136ff67070daa76819adaecc5b42e99851559659645dce1fbf2af3
This is not a request for an official Arch/Nix package. Downstream packagers can pin the official signed .deb if the versioned pool path and per-arch SHA256 stay published.
Suggested docs/packaging contract (small, already almost there):
- Document the versioned pool URL and the
Packagesindex on Desktop app (Linux), next to the conveniencelatest/links. - Keep
pool/main/c/chatgpt/chatgpt_${version}_${arch}.debstable across releases (a rename breaks every pin at once). - Optional but useful: publish a
SHA256SUMS(or a small versions JSON) next tolatest/, so packagers do not have to scrapePackages.
Where did you find it?
- Docs: https://learn.chatgpt.com/docs/codex/linux/linux-app
- Same
latest/URLs are what AURopenai-codex-desktopcurrently vendors: https://aur.archlinux.org/packages/openai-codex-desktop - Checksum failure already reported there on 2026-08-13 (comment by hbarcelos) after
latest/was overwritten - Related ask on the closed Linux-app request, not filed as its own issue: https://github.com/openai/codex/issues/11023#issuecomment-5284456387
Downstream workaround (AUR)
Pin the versioned pool URL instead of latest/. Tested on Arch x86_64: openai-codex-desktop 26.810.41047-1 builds and the bundled binary reports 26.810.41047.
-pkgver=26.803.81509
-pkgrel=8
+pkgver=26.810.41047
+pkgrel=1
source_x86_64=(
- "${_deb_x86_64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_amd64.deb"
+ "${_deb_x86_64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_amd64.deb"
)
source_aarch64=(
- "${_deb_aarch64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_arm64.deb"
+ "${_deb_aarch64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_arm64.deb"
)
-sha256sums_x86_64=('a9bf91a368f9f7c4eea38082a9fb8fb46b8d005b719a6d7715d2e5a1982c38eb')
-sha256sums_aarch64=('f38fcc194eca9ab0327dc10c92340681eae77c5d75164df700384ce2adaccbc1')
+sha256sums_x86_64=('78715fa3cd136ff67070daa76819adaecc5b42e99851559659645dce1fbf2af3')
+sha256sums_aarch64=('996f793ca0397676fcb9cd002114c97755cc3741907c400f7f5ddcf6c70c0a4e')
SHA256 values taken from the official Packages index (amd64 + arm64), not from hashing latest/.
- Lingua principale
- Rust
- Stelle
- 127k
- Fork
- 19.9k
- Merge medio
- 1m
- PR unite (30g)
- 994
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di openai/codex
-
app bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
openai/codex#51001 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug tool-calls
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
app bug dots mcp windows-os
Difficoltà 2/5 Meno di un'ora Idoneità per principianti 75/100
openai/codex#50982 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
app-server bug CLI remote windows-os
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
app bug sandbox windows-os
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
openai/codex#50915 · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di openai/codex
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
pnpm/pnpm#16635 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug llm translation
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno
-
skillfs: one malformed chat-log line aborts the entire skill-usage analysis (skill_usage_from_chat_logs.py)Forse già presa @zjncs l’ha presa oggi. Apertacomponent:skillfs
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
agentic-os-org/ANOLISA#6116 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
indygreg/cryptography-rs#99 ·