Skip to content

[Bug] Windows Codex PATH can crash HTTPS updates with OPENSSL_Applink #4433

Description

@joey-orbyss

Spec Kit version

specify 1.0.4, installed as a uv tool on Windows.

Environment

  • Codex Desktop local task on Windows
  • The task PATH prepends Codex-owned native dependency directories, including Poppler and Git directories that contain their own libssl-3-x64.dll and libcrypto-3-x64.dll.
  • specify.exe is the uv-installed launcher under %USERPROFILE%\.local\bin.

Reproduction

From an initialized consumer with registered HTTPS catalogs, run either:

specify workflow update program-kit-bootstrap
specify bundle update program-kit --integration codex

Both commands reproducibly exit 1 before completing the remote update with:

OPENSSL_Uplink(...): no OPENSSL_Applink

The failure occurs specifically in the Codex Desktop process environment. A local/offline component installation can proceed because it does not enter the failing HTTPS path.

Expected behavior

Spec Kit HTTPS/catalog operations should use the OpenSSL runtime packaged with its Python environment and must not load an ABI-incompatible DLL merely because another application prepended native tools to PATH. If the launcher cannot isolate its DLL search path, it should fail with an actionable dependency diagnostic rather than the OpenSSL applink abort.

Impact

Documented workflow update and bundle update commands cannot run from Codex Desktop on affected Windows hosts. This blocks unattended governed upgrades and encourages consumers to use incomplete local recovery sequences.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions