R10 Secret-Scrubbed Codex Environment — Reconciliation Release

Status: PASS_LIVE / FAIL_CLOSED / REAL_WINDOWS_RUNTIME_NOT_PROVEN / PRODUCTION_NO_GO

Effective audit date: 2026-08-29 UTC.

Goal

Harden the real Codex acceptance path so the isolated Windows Codex runtime cannot inherit relay/user secrets through shell-command environment propagation, while preserving exact authenticated-device provenance and the fail-closed V5 acceptance gate.

Active contract

  • implementation: R10-SECRET-SCRUBBED-CODEX-ENV
  • acceptance lane: CODEX_REAL_RUNTIME_ACCEPTANCE_V5
  • challenge id: 74235c6a-2d8c-4528-88b4-0cc608466731
  • challenge SHA-256: 6317fada2f2022bc873dd68bea49b16a2fdb11c572242d8850c597f06236cd7e
  • deadline: 2026-09-01T03:15:00Z
  • bootstrap metadata schema: rumbo-codex-device-bootstrap/v4

Exact launchers

  • Python launcher v6.0: SHA-256 6decd6dc7034da93774cffd89f828b4e27f93ada92c8a2dce2d4142b1e58082e, 25241 bytes.
  • Windows launcher: SHA-256 ecf3e9e90bbccb32a36e0d3b53c770cae018308093aad540a3125f508b360628, 4249 bytes.
  • Env probe script: SHA-256 8dff8e38c986fabdea627183745fb643bfbcb8c9262e915f6d1f8447d90a2f72.
  • Static Python source is byte-identical to the served module.

Reconciled defects

  1. R10 candidate server/schema had advanced while the PowerShell wrapper still required R9/v3. Fixed to R10/v4 and exact-hash-bound.
  2. V5 launcher emitted shell-environment proof but server acceptance did not initially require it. Server now requires challenge contract + response evidence for inherit=core, default sensitive excludes, no CODEX_HOME shell inheritance, no sensitive OPENAI_* shell inheritance, and successful env probe.
  3. Python metadata self-check had v3/v4 drift. Fixed to v4; served/static identities reconciled.
  4. Windows preflight now verifies the R10 shell-environment security boundary and exact env-probe SHA before pairing.
  5. Acceptance selftest pins the exact Python/Windows launcher identities and shell-environment contract.

Runtime boundary

The isolated parent Codex environment still copies only regular auth.json into a temporary CODEX_HOME, strips inherited CODEX_*, OPENAI_API_KEY, and OPENAI_BASE_URL, and executes Codex with read-only sandbox, approval policy never, ephemeral exec, ignored user config/rules, and explicit shell-environment filtering. The local env probe must observe zero sensitive inherited shell variable names and must bind the hidden local probe, plugin manifest, and SKILL.md hashes.

Verification receipts

  • hash contract: 01a04c66-7f2b-7737-af16-c3cd82d0ac29 — PASS.
  • branch endpoint contract: 01a04c66-f673-7471-ada3-54b1b74a3d94 — PASS.
  • branch acceptance selftest: 01a04c68-0581-71ee-8c94-2e595ca60580 — PASS.
  • legacy bearer negative test: 01a04c69-3f2a-71fa-bde2-829d1f56c14e — PASS; legacy stored bearer/pairing values tested returned HTTP 401 while GPT/Admin V4 returned 200.
  • Python source identity: 01a04c69-e0a4-74a2-8a86-f8b706c75f4d — PASS / exact byte identity.
  • audit-chain verification: 01a04c68-3314-7599-a03e-ff2551f766f0 — PASS.

A separate synthetic self-test lane R10_ENV_ACCEPTANCE_SELFTEST_V2 appended audit events 90–95. Its operational lane/message/pairing/token/contract rows were removed after the test; immutable audit events remain by design. No V5 Codex evidence was created by this test.

Live truth at reconciliation

  • V5 Codex ACKs: 0.
  • V5 Codex responses: 0.
  • V5 active device tokens: 0.
  • V5 pending pairings: 0.
  • authentic Windows Codex runtime: NOT_PROVEN.
  • final ChatGPT semantic ACK: NOT_PROVEN.
  • full federated runtime: NO_GO.
  • production: NO_GO.

Promotion completed by concurrent exact-source reconciliation on main. Core R10 files were verified exact between main and the audited branch. Post-promotion acceptance selftest 01a04c6b-8d70-75aa-8931-0f59cfff94e3 — PASS. Final reconciliation selftest 01a04c6c-f5ab-7293-ba99-dcb193c1649e — PASS. Final audit-chain check 01a04c6d-090c-74c4-b1be-8d31e8341c2b — PASS. No real-runtime claim is inferred from synthetic tests.