Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions bin/ocx.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -447,6 +447,9 @@ function runPackageManagerSelfUpdate(manager) {
}
const env = mutationChildEnvironment();
delete env.OCX_SERVICE;
// The restarted proxy is an ordinary owner; only a sibling's own replacement carries this.
delete env.OCX_SIBLING_OF_PORT;
delete env.OCX_SIBLING_HANDOFF_NONCE;
console.log(`Attempting to restart the proxy on port ${bakePort}.`);
const child = spawn(process.execPath, [postUpdateLauncher, "start", "--port", String(bakePort)], {
detached: true,
Expand Down
15 changes: 7 additions & 8 deletions docs-site/src/content/docs/fr/guides/remote-link.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,20 +9,19 @@ Une liaison entre machines connecte un ordinateur OpenCodex **Home** à un ordin

- Home peut se connecter à Child avec une clé OpenSSH.
- Pour une liaison initiée par Child, Child peut se connecter à Home avec une clé OpenSSH (la connexion par mot de passe n’est pas prise en charge).
- OpenCodex est installé sur Child.
- OpenCodex 2.66.0 ou ultérieur est installé sur Child (et sur Home pour une liaison initiée par Child).
- Les deux ordinateurs utilisent macOS ou Linux.
- Le tableau de bord Home dispose d’une session appairée complète.
- La liaison se lance depuis Home : son tableau de bord est ouvert sur l’ordinateur Home lui-même (navigateur ou application de bureau, installation autonome) ou via une session Hub appairée.

SSH par mot de passe et Windows restent hors du flux actuel. Pour démarrer une liaison depuis Child, ouvrez le tableau de bord du Child autonome, choisissez **Enfant** → **Trouver le Home**, sélectionnez l’hôte SSH de Home, vérifiez puis confirmez l’empreinte de la clé hôte, et choisissez **Connecter comme Enfant**. Child doit pouvoir se connecter à Home avec une clé SSH (les mots de passe ne sont pas pris en charge), et `ocx` doit être en cours d’exécution sur Home. Le port du tunnel client est `1024` ou supérieur. Après la jonction, Child redémarre et se connecte via Home. Cette option est disponible uniquement en mode autonome.
SSH par mot de passe et Windows restent hors du flux actuel. Connecter un ordinateur comme Child depuis le tableau de bord (liaison initiée par Child) n’est pas disponible dans cette version : la jonction redémarre OpenCodex sur cet ordinateur, ce qui couperait les connexions Codex déjà ouvertes ; le tableau de bord affiche donc le rôle **Enfant** comme indisponible. La liaison initiée par Home est la voie prise en charge : sur l’ordinateur qui doit servir de Home, choisissez **Home** et ajoutez l’autre ordinateur comme Child, comme décrit ci-dessous.

## Ajouter un Child depuis `#remote`

1. Ouvrez le tableau de bord sur `#remote` et activez Remote Link.
2. Choisissez **Home**.
3. Sélectionnez **Add child**.
4. Choisissez un hôte parmi les candidats SSH, ou saisissez un alias de configuration SSH.
5. Lancez le test de connexion et comparez l’empreinte proposée avec celle de l’ordinateur visé. Cette comparaison aide à détecter un mauvais hôte ou une clé d’hôte modifiée avant que SSH ne lui fasse confiance.
6. Confirmez l’empreinte, puis connectez Child.
2. Choisissez **Home**, puis **Continue**. La liste des hôtes SSH s’ouvre.
3. Choisissez un hôte parmi les candidats SSH, ou saisissez un alias de configuration SSH.
4. Lancez le test de connexion et comparez l’empreinte proposée avec celle de l’ordinateur visé. Cette comparaison aide à détecter un mauvais hôte ou une clé d’hôte modifiée avant que SSH ne lui fasse confiance.
5. Confirmez l’empreinte, puis connectez Child.

Le tableau de bord ne demande pas de saisir un jeton. Il sonde d’abord l’hôte et ne peut appliquer la liaison qu’après votre confirmation explicite de l’empreinte.

Expand Down
2 changes: 1 addition & 1 deletion docs-site/src/content/docs/fr/reference/cli/lifecycle.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ Assistant de configuration interactif (`setup` est un alias de `init`). Il deman

### `ocx start [--port <port>] [--socks5 [host:port] | --socks5-off]`

Démarre le serveur proxy, de préférence sur le port `10100`. La commande écrit l’état du PID et du port d’exécution, et refuse de démarrer une deuxième instance active. Lorsque le port préféré est occupé, `start` interroge le processus qui l’occupe puis s’arrête dans tous les cas : elle refuse de démarrer si un processus opencodex y répond et signale sinon que le processus est inconnu. Elle ne déplace jamais l’écouteur vers un autre port d’elle-même, car cela laisserait le premier proxy en cours d’exécution et redirigerait Codex vers le second. Un autre `--port` explicite est également refusé avec le même `OPENCODEX_HOME`, car les modes d’observation et de plafond écrivent tous deux dans le même journal de dépenses. Utilisez un `OPENCODEX_HOME` distinct pour une instance sœur indépendante ; `port: 0` ne sépare que l’attribution du port, pas l’état. Au démarrage, elle synchronise dans le catalogue Codex les modèles de chaque fournisseur. À l’arrêt, elle rétablit le fonctionnement natif de Codex, sauf si le proxy a été lancé comme service géré (`OCX_SERVICE=1`).
Démarre le serveur proxy, de préférence sur le port `10100`. La commande écrit l’état du PID et du port d’exécution, et refuse de démarrer une deuxième instance active. Lorsque le port préféré est occupé, `start` interroge le processus qui l’occupe puis s’arrête dans tous les cas : elle refuse de démarrer si un processus opencodex y répond et signale sinon que le processus est inconnu. Elle ne déplace jamais l’écouteur vers un autre port d’elle-même, car cela laisserait le premier proxy en cours d’exécution et redirigerait Codex vers le second. Un autre `--port` explicite est également refusé avec le même `OPENCODEX_HOME`, car les modes d’observation et de plafond écrivent tous deux dans le même journal de dépenses. Utilisez un `OPENCODEX_HOME` distinct pour une instance sœur indépendante ; `port: 0` ne sépare que l’attribution du port, pas l’état. Au démarrage, elle synchronise dans le catalogue Codex les modèles de chaque fournisseur. À l’arrêt, elle rétablit le fonctionnement natif de Codex, sauf si le proxy a été lancé comme service géré (`OCX_SERVICE=1`). Une instance sœur démarrée à côté d’un proxy déjà actif ne fait ni l’un ni l’autre, même lorsqu’elle est arrêtée avec `ocx stop` ou par un signal : elle ne sert que les requêtes directes sur son propre port, et Codex, Grok et Claude restent dirigés vers le proxy qui tournait déjà.

`--socks5` (par défaut `127.0.0.1:10808`) enregistre l’URL SOCKS5 dans `config.proxy` et achemine
les requêtes HTTP(S) sortantes dans un véritable tunnel SOCKS5. `--socks5-off` supprime uniquement
Expand Down
11 changes: 8 additions & 3 deletions docs-site/src/content/docs/guides/providers.md
Original file line number Diff line number Diff line change
Expand Up @@ -284,8 +284,10 @@ desktop and the wrong one in two common cases: you need a different browser prof
identity, a second account), or the dashboard is open against a proxy running somewhere else.

Every login surface shows the authorization URL with a copy button, the device code when the
provider issues one, and a field to paste the redirect URL or authorization code back. So you can
always finish a login by hand.
provider issues one, and the current instructions. Browser callback flows also show a field to
paste the redirect URL or authorization code back. During device approval that field is hidden:
enter the displayed code on the provider's verification page instead. If the provider switches
to manual input, the dashboard replaces the old code and instructions on its next status poll.

To stop the proxy from opening a browser at all, tick **Don't open a browser on the proxy machine**
beside the login button, or set it permanently:
Expand All @@ -302,7 +304,7 @@ Two cases behave differently, and it is worth knowing which you are in:

- **A different browser profile on the same machine** works with the copied link alone. The
loopback callback on `127.0.0.1` still completes the flow.
- **A browser on a different machine** also needs the paste fallback, because the redirect URI is
- **A browser callback flow on a different machine** also needs the paste fallback, because the redirect URI is
still `http://127.0.0.1:<port>/callback` on the proxy's host. Finish the login there, then paste
the redirect URL (or just the code) back into the dashboard or `ocx account code`.

Expand Down Expand Up @@ -774,6 +776,9 @@ including add-account and reauthentication. A raw admin token or forged GUI head
`403 oauth_consent_required` before a credential is read or a grant starts. This gate uses
the server-resolved session principal, not a separately recorded warning-checkbox receipt.
Direct `ocx login meta-muse` and other OAuth providers keep their existing login policies.
The management OAuth provider list therefore omits Meta Muse for raw-admin-token dashboards;
open a session-authenticated dashboard to use that login flow. This changes discovery only,
not the admission checks on login start or manual continuation.

Both seeded `meta-muse` models expose `minimal`/`low`/`medium`/`high`/`xhigh`/`max` to
routed clients, including Grok's effort picker. Requests use
Expand Down
24 changes: 16 additions & 8 deletions docs-site/src/content/docs/guides/remote-link.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,20 +9,19 @@ A machine link connects an OpenCodex **Home** computer to a **Child** computer o

- The Home computer can log in to the Child with an OpenSSH key.
- For a Child-initiated link, the Child can log in to Home with an OpenSSH key (password login is not supported).
- OpenCodex is installed on the Child computer.
- OpenCodex 2.66.0 or later is installed on the Child computer, and on Home for a Child-initiated link.
- Both computers run macOS or Linux.
- The Home dashboard has a full paired session.
- Links are started from the Home: its dashboard is opened on the Home computer itself (browser or desktop app, standalone install) or through a paired Hub session.

Password SSH and Windows are outside the current flow. For a Child-initiated link, open the standalone Child dashboard, choose **Child** → **Find Home**, select the SSH host for Home, check and confirm the host-key fingerprint, then choose **Connect as Child**. The Child must be able to log in to Home with an SSH key (password login is not supported), and `ocx` must be running on Home. The client tunnel port is `1024` or higher. After joining, the Child restarts and connects through Home. This option is available only on a standalone runtime.
Password SSH and Windows are outside the current flow. Connecting a computer as a Child from the dashboard (a Child-initiated link) is not available in this release: joining restarts OpenCodex on that computer, which would drop the Codex connections already running there, so the dashboard shows the **Child** role as unavailable. Home-initiated linking is the supported path: on the computer that should be Home, choose **Home** and add the other computer as a Child, as described below.

## Add a Child from `#remote`

1. Open the dashboard at `#remote` and switch Remote Link on.
2. Choose **Home**.
3. Select **Add child**.
4. Choose a host from the SSH candidates, or enter an SSH config alias.
5. Run the connection test and compare the offered host fingerprint with the fingerprint for the machine you intend to use. Comparing it helps detect a wrong host or a changed host key before SSH trusts the host.
6. Confirm the fingerprint, then connect the Child.
2. Choose **Home**, then **Continue**. The SSH host list opens.
3. Choose a host from the SSH candidates, or enter an SSH config alias.
4. Run the connection test and compare the offered host fingerprint with the fingerprint for the machine you intend to use. Comparing it helps detect a wrong host or a changed host key before SSH trusts the host.
5. Confirm the fingerprint, then connect the Child.

The dashboard does not ask you to enter a token. It probes the host first, and it cannot apply the link until you explicitly confirm the fingerprint.

Expand All @@ -46,6 +45,15 @@ ocx disconnect

To disconnect a Child-initiated link, run `ocx disconnect` on the Child. It disconnects the client tunnel and revokes the link on Home over SSH. If Home revocation fails, it prints: `Home revoke failed; run ocx link revoke --link-id <linkId> on the home.`

## Troubleshooting

When a step fails, the dashboard shows the reason and, when SSH reported one, the last line of its error output under the message.

- **Could not connect to the SSH host**: the host must accept your SSH key without a password prompt; `ssh -o BatchMode=yes <alias> true` must succeed from a terminal. A `ProxyCommand` helper such as `cloudflared` must be installed in `/opt/homebrew/bin`, `/usr/local/bin`, `~/.bun/bin`, `~/.local/bin` or another directory on the PATH OpenCodex runs with.
- **ocx was not found on the remote computer**: OpenCodex looks for `ocx` on the PATH of a non-interactive SSH session first, then in `~/.bun/bin`, `~/.local/bin`, `/opt/homebrew/bin` and `/usr/local/bin`. If it is installed elsewhere, add that directory to PATH in a file the remote shell reads for non-interactive sessions, such as `~/.zshenv` for zsh.
- **OpenCodex on the remote computer is too old**: run `ocx update` on that computer. Remote Link needs 2.66.0 or later.
- **The remote computer did not report an OpenCodex version**: `ocx --version` on that computer printed something else, for example the usage text of an unsupported Windows install.

## Security

The Child uses the Home computer's providers and provider credentials through the link. The Home creates a separate link key for each Child; removing the link revokes that key. Compare the host fingerprint before confirmation so a wrong machine or changed host key is not accepted by mistake. Dashboard sessions issued from a Tailscale identity cannot manage machine links.
Expand Down
15 changes: 7 additions & 8 deletions docs-site/src/content/docs/ja/guides/remote-link.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,20 +9,19 @@ description: SSH で OpenCodex の Home コンピューターと Child コンピ

- Home から Child に OpenSSH キーでログインできること。
- Child から開始するリンクでは、Child から Home に OpenSSH キーでログインできる必要があります(パスワードログインには対応していません)。
- Child に OpenCodex がインストールされていること。
- Child に OpenCodex 2.66.0 以降がインストールされていること(Child から開始するリンクでは Home にも)。
- 両方のコンピューターが macOS または Linux であること。
- Home のダッシュボードに完全なペアリング済みセッションがあること。
- リンクは Home 側から開始すること。使うダッシュボードは、Home のコンピューター上で直接開いたもの(スタンドアロン環境のブラウザーまたはデスクトップアプリ)か、ペアリング済みの Hub セッションです。

パスワード SSH と Windows は現在のフローに含まれません。Child からリンクを開始するには、スタンドアロンの Child ダッシュボードで **子** → **Home を探す** を選び、Home の SSH ホストを選択し、ホストキーのフィンガープリントを確認してから **子として接続** を選びます。Child から Home へ SSH キーでログインできる必要があり(パスワードログインには対応していません)、Home では `ocx` が実行中である必要があります。クライアントトンネルのポートは `1024` 以上です。参加後、Child は再起動して Home に接続します。この項目はスタンドアロンランタイムでのみ使用できます。
パスワード SSH と Windows は現在のフローに含まれません。このリリースでは、ダッシュボードからコンピューターを Child として接続すること(Child から開始するリンク)はできません。参加するとそのコンピューターの OpenCodex が再起動し、すでに動いている Codex 接続が切断されるため、ダッシュボードでは **子** の役割を選択できません。サポートされているのは Home から開始するリンクです。Home にするコンピューターで **Home** を選び、下記の手順でもう一方のコンピューターを Child として追加してください。

## `#remote` から Child を追加する

1. ダッシュボードで `#remote` を開き、Remote Link をオンにします。
2. **Home** を選びます。
3. **Add child** を選びます。
4. SSH の候補からホストを選ぶか、SSH 設定のエイリアスを入力します。
5. 接続テストを実行し、表示されたホストフィンガープリントを接続先コンピューターのものと比較します。比較すると、SSH がホストを信頼する前に、別のコンピューターや変更されたホストキーを検出できます。
6. フィンガープリントを確認して Child を接続します。
2. **Home** を選び、**Continue** を押します。SSH ホストの一覧が開きます。
3. SSH の候補からホストを選ぶか、SSH 設定のエイリアスを入力します。
4. 接続テストを実行し、表示されたホストフィンガープリントを接続先コンピューターのものと比較します。比較すると、SSH がホストを信頼する前に、別のコンピューターや変更されたホストキーを検出できます。
5. フィンガープリントを確認して Child を接続します。

ダッシュボードはトークンの入力を求めません。先にホストをプローブし、フィンガープリントを明示的に確認するまでリンクを適用しません。

Expand Down
Loading
Loading