Skip to content

[Bug]: Automatic Codex detection fails for npm-installed Codex on Windows #5

Description

@causercode

/status version

1.0.0

Windows version and architecture

Windows 11

What happened?

/status reports that Codex is not installed when Codex CLI was installed through npm on Windows.

The Codex command works normally from PowerShell, but npm places codex.ps1 and codex.cmd on PATH, not the underlying native codex.exe.

The current resolver:

  1. Checks the configured executable path.
  2. Checks %LOCALAPPDATA%\Programs\OpenAI\Codex\bin\codex.exe.
  3. Searches each PATH directory specifically for codex.exe.

It deliberately rejects .cmd, .ps1, and .bat shims. Consequently, it cannot automatically detect a normal npm-based Codex installation, even though the native executable is present inside the npm package.

Environment

  • Windows 11
  • Codex CLI installed through npm
  • Codex CLI version: 0.155.1
  • CODEX_HOME: default %USERPROFILE%\.codex
  • /status diagnostic code: codex_not_installed

Get-Command codex -All returns entries similar to:

C:\Users\<user>\Tools\node-v24.11.1-win-x64\codex.ps1
C:\Users\<user>\Tools\node-v24.11.1-win-x64\codex.cmd
C:\Users\<user>\Tools\node-v24.11.1-win-x64\codex

The actual native executable is located at:

C:\Users\<user>\Tools\node-v24.11.1-win-x64\node_modules\@openai\codex\node_modules\@openai\codex-win32-x64\vendor\x86_64-pc-windows-msvc\bin\codex.exe

Selecting that executable manually in /status Settings works.

Reproduction steps

  1. Install Node.js on Windows.

  2. Install Codex globally through npm:

    npm install -g @openai/codex
  3. Confirm that Codex works:

    codex --version
  4. Start /status with the Codex executable setting left blank.

  5. Refresh the Codex provider.

Actual result

/status shows Codex as unavailable, and its log contains:

code=codex_account:codex_not_installed
code=codex_rate_limits:codex_not_installed
code=codex_token_usage:codex_not_installed

Expected result

/status should automatically locate and use the native codex.exe bundled with an npm-installed Codex CLI.

Suggested fix

Continue refusing to execute shell shims directly, but use detected npm shims as safe discovery anchors.

When ordinary codex.exe resolution fails:

  1. Search PATH for codex.cmd or codex.ps1.
  2. Take the shim’s parent directory as the npm global binary directory.
  3. Check bounded, architecture-specific native executable candidates beneath its node_modules directory.
  4. Validate that the candidate is a fully qualified, existing .exe before launching it.

Potential candidates include:

<shim-directory>\node_modules\@openai\codex\
  node_modules\@openai\codex-win32-x64\
  vendor\x86_64-pc-windows-msvc\bin\codex.exe
<shim-directory>\node_modules\@openai\codex-win32-x64\
  vendor\x86_64-pc-windows-msvc\bin\codex.exe

Equivalent ARM64 package and target names should also be checked:

@openai\codex-win32-arm64
aarch64-pc-windows-msvc

This preserves the existing protection against launching .cmd or PowerShell scripts while supporting the standard npm installation layout.

Suggested tests

  • Resolves nested npm x64 installation.
  • Resolves hoisted npm x64 installation.
  • Resolves nested and hoisted ARM64 installations.
  • Prefers explicitly configured and standalone installations over npm fallback.
  • Does not execute or return the shim itself.
  • Ignores missing or malformed npm package layouts.
  • Ignores native executables outside the expected bounded package paths.
  • Reports npm-specific provenance, such as npm installation.

Relevant implementation: [ExecutableResolver.cs](https://github.com/causercode/slash-status/blob/main/src/TokenStatus.Infrastructure/Cli/ExecutableResolver.cs).

Redacted diagnostics


Activity

  1. changed the title [-][Bug]: Automatic Codex detection fails for npm-installed Codex on Windows ##[/-] [+][Bug]: Automatic Codex detection fails for npm-installed Codex on Windows[/+] on Sep 21, 2026
  2. causercode commented on Sep 22, 2026

    @causercode
    OwnerAuthor

    Implemented in #6 and targeted for v1.0.1. The PR preserves the native-executable security boundary while adding bounded npm package discovery for Windows x64 and ARM64. This issue will close automatically when the PR merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions