Linux desktop docs only advertise a mutable latest/ .deb; checksum-pinned packagers break on overwrite
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 68/100
- issue の種類
- ドキュメント
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- debian, linux
- 領域
- documentation, release
調査の方向性
Issue にリンクされている Desktop app (Linux) ページから始め、そこにある変更され得る latest/ リンクを、バージョン付きの pool URL および提供されている APT Packages インデックスと比較します。指定されたファイル名の契約を維持しながら、利便性のためのリンクの隣に、安定したバージョン付きパスとチェックサムのソースを記載します。下流のパッケージメンテナーが、上書きされた latest/ blob に依存せずにバージョンと SHA256 の情報を見つけられれば完了です。
索引モデルが issue の本文から書いたものです。
説明
What is the type of issue?
- Documentation is missing
- Documentation is confusing
What is the issue?
The Linux desktop install docs point packagers and users at a mutable blob:
https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_amd64.debhttps://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_arm64.deb
That path is overwritten in place. On 2026-08-13 20:11 UTC, latest/chatgpt_amd64.deb changed from 26.803.81509 (sha256 a9bf91a3…) to 26.810.41047 (sha256 78715fa3…, 391786694 bytes). Any PKGBUILD / Nix FOD / Guix origin that pins sha256 against latest/ fails with FAILED on the next makepkg.
The durable contract already exists and works. It is just not documented on the Linux install page:
| What | URL |
|---|---|
APT Packages (includes Version + SHA256) |
https://persistent.oaistatic.com/codex-app-prod/linux/deb/dists/stable/main/binary-amd64/Packages |
Versioned pool .deb |
https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_26.810.41047_amd64.deb |
Verified today against that Packages file:
Package: chatgpt
Version: 26.810.41047
Filename: pool/main/c/chatgpt/chatgpt_26.810.41047_amd64.deb
Size: 391786694
SHA256: 78715fa3cd136ff67070daa76819adaecc5b42e99851559659645dce1fbf2af3
This is not a request for an official Arch/Nix package. Downstream packagers can pin the official signed .deb if the versioned pool path and per-arch SHA256 stay published.
Suggested docs/packaging contract (small, already almost there):
- Document the versioned pool URL and the
Packagesindex on Desktop app (Linux), next to the conveniencelatest/links. - Keep
pool/main/c/chatgpt/chatgpt_${version}_${arch}.debstable across releases (a rename breaks every pin at once). - Optional but useful: publish a
SHA256SUMS(or a small versions JSON) next tolatest/, so packagers do not have to scrapePackages.
Where did you find it?
- Docs: https://learn.chatgpt.com/docs/codex/linux/linux-app
- Same
latest/URLs are what AURopenai-codex-desktopcurrently vendors: https://aur.archlinux.org/packages/openai-codex-desktop - Checksum failure already reported there on 2026-08-13 (comment by hbarcelos) after
latest/was overwritten - Related ask on the closed Linux-app request, not filed as its own issue: https://github.com/openai/codex/issues/11023#issuecomment-5284456387
Downstream workaround (AUR)
Pin the versioned pool URL instead of latest/. Tested on Arch x86_64: openai-codex-desktop 26.810.41047-1 builds and the bundled binary reports 26.810.41047.
-pkgver=26.803.81509
-pkgrel=8
+pkgver=26.810.41047
+pkgrel=1
source_x86_64=(
- "${_deb_x86_64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_amd64.deb"
+ "${_deb_x86_64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_amd64.deb"
)
source_aarch64=(
- "${_deb_aarch64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/latest/chatgpt_arm64.deb"
+ "${_deb_aarch64}::https://persistent.oaistatic.com/codex-app-prod/linux/deb/pool/main/c/chatgpt/chatgpt_${pkgver}_arm64.deb"
)
-sha256sums_x86_64=('a9bf91a368f9f7c4eea38082a9fb8fb46b8d005b719a6d7715d2e5a1982c38eb')
-sha256sums_aarch64=('f38fcc194eca9ab0327dc10c92340681eae77c5d75164df700384ce2adaccbc1')
+sha256sums_x86_64=('78715fa3cd136ff67070daa76819adaecc5b42e99851559659645dce1fbf2af3')
+sha256sums_aarch64=('996f793ca0397676fcb9cd002114c97755cc3741907c400f7f5ddcf6c70c0a4e')
SHA256 values taken from the official Packages index (amd64 + arm64), not from hashing latest/.
- 主要言語
- Rust
- スター
- 128k
- フォーク
- 20.1k
- 平均マージ
- 1分
- マージ済み PR(30日)
- 994
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
openai/codex のほかの issue
-
app enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
メンテナーはふだん 1 日以内に返信
-
app bug config windows-os
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
openai/codex#51926 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
app bug model-behavior windows-os
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
openai/codex#51912 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
app bug dots remote
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
メンテナーはふだん 1 日以内に返信
-
app bug performance
難易度 2/5 1〜3時間 初心者へのやさしさ 80/100
openai/codex#51818 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 80/100
elodin-sys/elodin#890 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
guidance-ai/llguidance#391 ·
-
documentation
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
Verifiedz/Shimmer#144 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信