openai / openai/codex

Build-provenance documentation for Codex 0.154.0 and its ARM64-musl V8 artifact

Open
#45,272 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

documentation
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What is the type of issue?

Documentation is missing.

What is the issue?

We are documenting the native build provenance of the official Codex 0.154.0 ARM64-musl artifacts embedded in an Android launcher. This is a request for retained build evidence or a pinned reproduction recipe, not a security-vulnerability report or an allegation that the release is incorrect.

We have verified the release payloads and original signatures, recovered the matching GNU-debuglink symbol files and Cargo timing artifacts, and traced the separately produced V8 archive and exact ICU data. The remaining gap is the final contributing native objects/sections, rather than another conservative dependency or license list.

Could you share any retained evidence for these exact outputs, or point us to an existing public location?

  1. Codex final links: linker maps or equivalent post-LTO/garbage-collection/ICF contribution reports; final link commands/response files and toolchain versions; or a linker reproducer containing the matching inputs. For generated/static native objects not already covered by pinned Cargo inputs, a source-to-object manifest with source revisions, patches and compile commands would help.
  2. The reused V8 archive: a retained Bazel action/compilation graph or equivalent mapping its objects to source revisions, compile flags, toolchain and generated inputs, plus the archive assembly command. Please distinguish repeated member names by ordinal or hash. This producer-side mapping is separate from what the later Codex link retained.

If original records have expired, identifying which are unavailable and providing a pinned build recipe/toolchain definition would still be useful. We would label a separate source replay as a new build, not as the original producer's link map. No credentials, signing material or private runner data are requested; paths can be normalized while preserving source/input identities.

Where did you find it?

Codex: release rust-v0.154.0, source commit 6b9826e3aa83b1a5947db50f4332cb9c65f1b340.
Both specific producing jobs below succeeded; the overall workflow run contains other failed work and is not being described as wholly successful.

Producing job Distributed ELF SHA-256
app-server / 102657284351 codex-app-server 0c2495cedd0e01fd6ba1e9d949b637f55ac283e6019b998024c010788da8c508
primary / 102657284476 codex-code-mode-host f31e1c5ffbbca7884aff2f0f8795d3da197f4aafb114033a399dfc17a5119031

V8: producer commit 12b3e88028b983051913fb6bb95d7a11218bdceb, ARM64-musl sandbox job 90418416602, original artifact ID 8705113138 (rusty-v8-150.4.0-ptrcomp-sandbox-aarch64-unknown-linux-musl). Its original job artifact matches the published archive/bindings/checksum files, and the consumer checksum pin agrees.

  • librusty_v8_ptrcomp_sandbox_release_aarch64-unknown-linux-musl.a.gz SHA-256: d258efd9c17b67077013f110302ff148fd11428cc4804fcb5c9ad05e3e634cb4.
  • Decompressed archive SHA-256: ee804b4b7f326ecdf4bcc5c93c94b84374d7e435759af934df372b9e5640ff26.

We inventoried all 2,100 archive objects and found positive complete, non-relocated instruction matches from 501 objects in the actual host. We are not treating the remaining objects as absent or this witness set as an exhaustive link map.

Thank you; even a pointer to the appropriate existing provenance artifacts would help.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked Codex producing jobs 102657284351 and 102657284476, then the V8 sandbox job 90418416602 and its cited artifacts. Done means locating retained link or compilation provenance for the specified outputs, or documenting which records are unavailable and providing a pinned reproduction recipe without presenting a new build as the original.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, rust
Domain
build-system, documentation, release
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.