Bundled Browser/Chrome/Computer Use plugins disappear after Windows app updates due to stale bundled marketplace path
Environment
- Codex Desktop version:
<paste current app version>
- Windows version / build:
<paste Windows version and OS build>
- Install type: Microsoft Store / WindowsApps packaged app
- Affected bundled plugins/skills:
- Browser
- Chrome
- Computer Use
Summary
After some Codex Desktop updates on Windows, bundled plugins/skills become unavailable until local repair. This has happened repeatedly across multiple app updates.
The recurring pattern is that Codex updates into a new versioned WindowsApps directory, but the local Codex config continues to point the bundled marketplace source at an older versioned app directory. After that, the bundled marketplace temp/cache state becomes incomplete, commonly leaving only the chrome plugin available while browser and computer-use disappear.
This appears to be an app update / marketplace registration regression, not a confirmed security issue.
Expected Behavior
After Codex Desktop updates, bundled plugins should remain registered and available.
Specifically:
[marketplaces.openai-bundled].source should point to the current app version's bundled marketplace source.
- The bundled marketplace temp/cache should be refreshed from the current app source.
- Bundled plugins
browser, chrome, and computer-use should remain available after restart/update.
Actual Behavior
After an update:
- Bundled plugins/skills disappear or become unavailable.
- Local config may still reference an older versioned
WindowsApps app path.
- The bundled marketplace temp/cache can become incomplete.
- In observed cases,
.tmp/bundled-marketplaces/openai-bundled/plugins commonly contained only chrome.
- The current app's bundled source manifests still existed and parsed correctly for
browser, chrome, and computer-use.
- Repairing the marketplace source path and rebuilding/restoring temp/cache from the current bundled source restored all three plugins.
Reproduction Pattern
This is intermittent but has recurred after multiple Windows app updates.
- Install / run Codex Desktop on Windows.
- Confirm bundled plugins are available.
- Let Codex Desktop update to a newer packaged app version.
- Restart Codex.
- Check bundled plugin availability.
- Inspect local bundled marketplace config/state:
%USERPROFILE%\.codex\config.toml
%USERPROFILE%\.codex\.tmp\bundled-marketplaces\openai-bundled\plugins
- Codex cache directories, if relevant
- Observe whether
[marketplaces.openai-bundled].source still points to an older OpenAI.Codex_<version> directory instead of the currently running app directory.
Evidence / Diagnostics
Most recent observed instance:
- Running app package:
OpenAI.Codex_26.623.4041.0
- Stale configured bundled source before repair:
OpenAI.Codex_26.616.10790.0
- Current bundled source plugin manifest versions:
26.623.31921
- Initial temp bundled marketplace plugins directory contained only:
- Current bundled source under the active app root still contained valid manifests for:
browser
chrome
computer-use
- After correcting the bundled marketplace source and restoring/rebuilding temp/cache from the current app source, all three plugins validated and became available again.
Prior local occurrences involved these app package versions:
OpenAI.Codex_26.616.6631.0
OpenAI.Codex_26.616.9593.0
OpenAI.Codex_26.616.10790.0
OpenAI.Codex_26.623.4041.0
Suggested diagnostics to attach:
# Redacted excerpt from %USERPROFILE%\.codex\config.toml
[marketplaces.openai-bundled]
source = "<redacted path showing old OpenAI.Codex_<version> vs current OpenAI.Codex_<version>>"
# Redacted directory listing
%USERPROFILE%\.codex\.tmp\bundled-marketplaces\openai-bundled\plugins
<show which plugin folders are present>
# Current app bundled source listing
<redacted WindowsApps path>\OpenAI.Codex_<current version>\...
<show browser/chrome/computer-use manifests exist and parse>
Workaround
A local repair restores functionality:
- Update
[marketplaces.openai-bundled].source in %USERPROFILE%\.codex\config.toml to point at the current OpenAI.Codex_<version> bundled marketplace source.
- Restore/rebuild the bundled marketplace temp/cache from the current app source.
- Restart Codex.
- Validate that
browser, chrome, and computer-use are available again.
Requested Fix
Please make Codex Desktop resilient to Windows packaged app updates by ensuring the bundled marketplace registration is refreshed when the app version/path changes.
Possible fixes:
- Avoid persisting an absolute versioned
WindowsApps path for the bundled marketplace source.
- On startup, detect when
[marketplaces.openai-bundled].source points to an older/non-current app package path.
- Re-register or migrate the bundled marketplace source to the current app root automatically.
- Rebuild bundled marketplace temp/cache atomically when the bundled source version changes.
- Validate that all expected bundled plugins are present after update and repair automatically if not.
Privacy / Security Note
This report intentionally excludes private documents, credentials, full local state dumps, and old conversation text. Based on current evidence, this appears to be an update/registration regression affecting bundled plugin availability, not a confirmed security vulnerability.
Bundled Browser/Chrome/Computer Use plugins disappear after Windows app updates due to stale bundled marketplace path
Environment
<paste current app version><paste Windows version and OS build>Summary
After some Codex Desktop updates on Windows, bundled plugins/skills become unavailable until local repair. This has happened repeatedly across multiple app updates.
The recurring pattern is that Codex updates into a new versioned
WindowsAppsdirectory, but the local Codex config continues to point the bundled marketplace source at an older versioned app directory. After that, the bundled marketplace temp/cache state becomes incomplete, commonly leaving only thechromeplugin available whilebrowserandcomputer-usedisappear.This appears to be an app update / marketplace registration regression, not a confirmed security issue.
Expected Behavior
After Codex Desktop updates, bundled plugins should remain registered and available.
Specifically:
[marketplaces.openai-bundled].sourceshould point to the current app version's bundled marketplace source.browser,chrome, andcomputer-useshould remain available after restart/update.Actual Behavior
After an update:
WindowsAppsapp path..tmp/bundled-marketplaces/openai-bundled/pluginscommonly contained onlychrome.browser,chrome, andcomputer-use.Reproduction Pattern
This is intermittent but has recurred after multiple Windows app updates.
%USERPROFILE%\.codex\config.toml%USERPROFILE%\.codex\.tmp\bundled-marketplaces\openai-bundled\plugins[marketplaces.openai-bundled].sourcestill points to an olderOpenAI.Codex_<version>directory instead of the currently running app directory.Evidence / Diagnostics
Most recent observed instance:
OpenAI.Codex_26.623.4041.0OpenAI.Codex_26.616.10790.026.623.31921chromebrowserchromecomputer-usePrior local occurrences involved these app package versions:
OpenAI.Codex_26.616.6631.0OpenAI.Codex_26.616.9593.0OpenAI.Codex_26.616.10790.0OpenAI.Codex_26.623.4041.0Suggested diagnostics to attach:
Workaround
A local repair restores functionality:
[marketplaces.openai-bundled].sourcein%USERPROFILE%\.codex\config.tomlto point at the currentOpenAI.Codex_<version>bundled marketplace source.browser,chrome, andcomputer-useare available again.Requested Fix
Please make Codex Desktop resilient to Windows packaged app updates by ensuring the bundled marketplace registration is refreshed when the app version/path changes.
Possible fixes:
WindowsAppspath for the bundled marketplace source.[marketplaces.openai-bundled].sourcepoints to an older/non-current app package path.Privacy / Security Note
This report intentionally excludes private documents, credentials, full local state dumps, and old conversation text. Based on current evidence, this appears to be an update/registration regression affecting bundled plugin availability, not a confirmed security vulnerability.