Skip to content

[extension] Codex Migrate command protection #2878

Description

@jsegeren

Contribution type

New Extension

Proposed Extension ID

command.codex-migrate

Capability boundary

Protect the Codex Migrate CLI's destination-changing migration operations. The extension owns the codex-migrate executable and reviews the two shell surfaces that can actually change destination state: export --apply and serve --apply. The latter enables staged transfer, finalization, and verified recovery controls in the local browser. Inventory, inspection, recovery inspection, read-only dashboards, version, and help remain non-reviewable. It does not attempt to inspect HTTP actions taken later inside the local browser UI, nor does it weaken filesystem, SSH, or other matching Guard rules.

Command surface

Executable: codex-migrate (Mac beta/CLI 1.x). Supported subcommands: launch, inventory, inspect, export, serve, and recovery. export --apply installs selected repair components; serve --apply enables transfer, finalization, and verified recovery controls. inspect is read-only even if --apply is supplied, while recovery --apply is rejected by the CLI. launch starts the local guided browser UI without itself applying a transfer.

Destructive or sensitive examples

  • codex-migrate export --target user@new-mac.local --target-home /Users/user --component personal-skills --apply
  • codex-migrate serve --target user@new-mac.local --target-home /Users/user --apply

These forms can install selected components or enable staged migration and recovery changes after the tool's own verification gates.

Safe counterparts

  • codex-migrate inventory --json
  • codex-migrate inspect --target user@new-mac.local --target-home /Users/user --json
  • codex-migrate inspect --target user@new-mac.local --target-home /Users/user --apply (still read-only)
  • codex-migrate export --target user@new-mac.local --target-home /Users/user --component personal-skills --json
  • codex-migrate serve --target user@new-mac.local --target-home /Users/user --no-open
  • codex-migrate recovery --target user@new-mac.local --target-home /Users/user --json
  • codex-migrate --help, codex-migrate --version, and subcommand help

Parser and composition edge cases

Tests cover reordered and abbreviated --apply, quoted target/home values, paths with spaces, compound commands, exec and xargs wrappers, help overrides, trailing commands, unresolved expansions in flag position, expansions consumed as known option values, and quoted examples. Unknown or expansion-provided flag arguments must not imply safety.

Risk and authority model

Proposed action class: Codex Migrate destination-changing operation. Risk classes: destructive_shell, execution, and network_egress; severity high; default mode review. Safer alternative: run the same subcommand without --apply, inspect the plan and verified destination backup, then repeat with --apply only when ready. The extension emits evidence only and remains external/opt-in, so required core and overlapping rules retain their floors.

Privacy and performance

The matcher is bounded to the canonical executable and explicit subcommand/flag structure. Evidence stores stable IDs and generic details, not targets, usernames, paths, SSH identity files, workspace names, or command text. Read-only invocations are the benign hot path and should exit after bounded token inspection.

Authoritative references

Readiness

  • I searched the Extension directory and existing issues for overlapping coverage.
  • I removed secrets, credentials, private command history, and local paths from these examples.
  • I can contribute or help validate destructive and safe-counterpart tests.

Activity

  1. kantorcodes commented on Sep 10, 2026

    @kantorcodes
    Member

    Contribution type

    New Extension

    Proposed Extension ID

    command.codex-migrate

    Capability boundary

    Protect the Codex Migrate CLI's destination-changing migration operations. The extension owns the codex-migrate executable and its inspect, export, serve, and recovery --apply forms. Read-only inventory, inspection, recovery inspection, read-only dashboards, version, and help remain non-reviewable. It does not attempt to inspect HTTP actions taken later inside the local browser UI, nor does it weaken filesystem, SSH, or other matching Guard rules.

    Command surface

    Executable: codex-migrate (Mac beta/CLI 1.x). Supported subcommands: launch, inventory, inspect, export, serve, and recovery. Mutating authority is explicit on inspect, export, serve, and recovery through --apply; launch starts the local guided browser UI without itself applying a transfer.

    Destructive or sensitive examples

    • codex-migrate inspect --target user@new-mac.local --target-home /Users/user --apply
    • codex-migrate export --target user@new-mac.local --target-home /Users/user --component personal-skills --apply
    • codex-migrate serve --target user@new-mac.local --target-home /Users/user --apply
    • codex-migrate recovery --target user@new-mac.local --target-home /Users/user --apply

    These forms can stage, install, replace, or recover selected destination state after the tool's own verification gates.

    Safe counterparts

    • codex-migrate inventory --json
    • codex-migrate inspect --target user@new-mac.local --target-home /Users/user --json
    • codex-migrate export --target user@new-mac.local --target-home /Users/user --component personal-skills --json
    • codex-migrate serve --target user@new-mac.local --target-home /Users/user --no-open
    • codex-migrate recovery --target user@new-mac.local --target-home /Users/user --json
    • codex-migrate --help, codex-migrate --version, and subcommand help

    Parser and composition edge cases

    Tests will cover reordered --apply, quoted target/home values, paths with spaces, compound commands, wrappers, --help, trailing commands, duplicate flags, unresolved expansions, and malformed or unsupported subcommands. Unknown or expansion-provided arguments must not imply safety.

    Risk and authority model

    Proposed action class: Codex Migrate destination-changing operation. Risk classes: destructive_shell, execution, and network_egress; severity high; default mode review. Safer alternative: run the same subcommand without --apply, inspect the plan and verified destination backup, then repeat with --apply only when ready. The extension emits evidence only and remains external/opt-in, so required core and overlapping rules retain their floors.

    Privacy and performance

    The matcher is bounded to the canonical executable and explicit subcommand/flag structure. Evidence stores stable IDs and generic details, not targets, usernames, paths, SSH identity files, workspace names, or command text. Read-only invocations are the benign hot path and should exit after bounded token inspection.

    Authoritative references

    Readiness

    • I searched the Extension directory and existing issues for overlapping coverage.
    • I removed secrets, credentials, private command history, and local paths from these examples.
    • I can contribute or help validate destructive and safe-counterpart tests.

    This seems like a great candidate. Looking forward to the PR!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions