Pull requests / #1398

#1398 docs: keeping Codex CLI off the network with Strata

open · @fioruccione · 0 评论 · 在 GitHub 查看

Setup & installServer & APIDocumentationLinux

描述

Adds a short paragraph to the Codex CLI section of `docs/DETAILS.md`: how to keep Codex itself off the network when the model is Strata. Docs only.

**Why:** with the existing recipe, prompts and answers go only to `127.0.0.1:8080`, but Codex still contacts OpenAI. Measured on Linux with Codex CLI 0.160.1, tracing every `connect()`:

| Codex setup | Connections outside 127.0.0.1 during one `codex exec` |
| --- | ---: |
| `~/.codex` logged in to ChatGPT, default settings (the documented recipe) | 4 HTTPS to `chatgpt.com` / `ab.chatgpt.com` |
| same, with analytics, feedback and the update check off | 1 |
| a separate `CODEX_HOME` with no ChatGPT login, plus the settings below | **0** |

The paragraph gives that home's `config.toml`. It also says what the interactive TUI still does: it fetches the start-up tip from `raw.githubusercontent.com` (nothing of the user's is sent), and its app-server daemon logs a remote-control websocket loop to `chatgpt.com`, which did not connect without a login. It ends with a `strace` one-liner to check again after a Codex update. The one-liner covers IPv4 and IPv6, and I checked that it catches the logged-in case (it lists the `chatgpt.com` addresses) and prints nothing for the documented config.

The content of the 4 connections was not inspected (TLS), and the docs say so. Codex changes quickly, which is why the docs give the check rather than a promise.

Measured on my machine, with an AI coding assistant helping on the tracing and the write-up.

站内延伸阅读

链到安装、模型与版本说明,便于 SEO/GEO,非官方 issue 正文。