github / github/spec-kit

[Bug] Windows Codex PATH can crash HTTPS updates with OPENSSL_Applink

Đang mở
#4,433 4 bình luận 0 reaction 0 người được giao Xem trên GitHub
author-awaiting author-needs-info author-needs-proof bug-assess severity-medium triage-can-wait
Ngôn ngữ chính
Python
Star
137k
Fork
12.3k
Merge trung bình
2 ngày 12 giờ
Pull request đã merge (30 ngày)
159

Mô tả

### Spec Kit version

`specify 1.0.4`, installed as a uv tool on Windows.

### Environment

- Codex Desktop local task on Windows
- The task PATH prepends Codex-owned native dependency directories, including Poppler and Git directories that contain their own `libssl-3-x64.dll` and `libcrypto-3-x64.dll`.
- `specify.exe` is the uv-installed launcher under `%USERPROFILE%\.local\bin`.

### Reproduction

From an initialized consumer with registered HTTPS catalogs, run either:

```powershell
specify workflow update program-kit-bootstrap
specify bundle update program-kit --integration codex
```

Both commands reproducibly exit 1 before completing the remote update with:

```text
OPENSSL_Uplink(...): no OPENSSL_Applink
```

The failure occurs specifically in the Codex Desktop process environment. A local/offline component installation can proceed because it does not enter the failing HTTPS path.

### Expected behavior

Spec Kit HTTPS/catalog operations should use the OpenSSL runtime packaged with its Python environment and must not load an ABI-incompatible DLL merely because another application prepended native tools to PATH. If the launcher cannot isolate its DLL search path, it should fail with an actionable dependency diagnostic rather than the OpenSSL applink abort.

### Impact

Documented `workflow update` and `bundle update` commands cannot run from Codex Desktop on affected Windows hosts. This blocks unattended governed upgrades and encourages consumers to use incomplete local recovery sequences.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Reproduce `specify workflow update program-kit-bootstrap` and `specify bundle update program-kit --integration codex` in the Codex Desktop Windows environment. Inspect how the uv-installed `specify.exe` launcher and its Python HTTPS path resolve OpenSSL DLLs when Codex prepends native directories to PATH. Done means both HTTPS updates complete successfully, or an actionable dependency diagnostic replaces the OpenSSL applink abort.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
cli, devtools, operating-systems
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
48/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.