-
Notifications
You must be signed in to change notification settings - Fork 2k
Codex binary preflight runs an uncached spctl --assess on every lookup (~2.5 s of syspolicyd CPU each; ~55% of a core when refresh cadence rises) #4078
Copy link
Copy link
Open
Labels
P2Normal priority bug or improvement with limited blast radius.Normal priority bug or improvement with limited blast radius.clawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.ClawSweeper marked this issue as needing maintainer review before automation.clawsweeper:needs-security-reviewClawSweeper marked this issue as needing security-sensitive review.ClawSweeper marked this issue as needing security-sensitive review.clawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.ClawSweeper does not recommend queueing a new automated fix PR for this issue.clawsweeper:source-reproClawSweeper found a high-confidence source-level issue reproduction.ClawSweeper found a high-confidence source-level issue reproduction.impact:otherThis issue has meaningful maintainer-visible impact outside the owned taxonomy.This issue has meaningful maintainer-visible impact outside the owned taxonomy.issue-rating: 🦞 diamond lobsterVery strong issue quality with high-confidence source-level or clear reproduction.Very strong issue quality with high-confidence source-level or clear reproduction.
Description
Activity
Metadata
Metadata
Assignees
Labels
P2Normal priority bug or improvement with limited blast radius.Normal priority bug or improvement with limited blast radius.clawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.ClawSweeper marked this issue as needing maintainer review before automation.clawsweeper:needs-security-reviewClawSweeper marked this issue as needing security-sensitive review.ClawSweeper marked this issue as needing security-sensitive review.clawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.ClawSweeper does not recommend queueing a new automated fix PR for this issue.clawsweeper:source-reproClawSweeper found a high-confidence source-level issue reproduction.ClawSweeper found a high-confidence source-level issue reproduction.impact:otherThis issue has meaningful maintainer-visible impact outside the owned taxonomy.This issue has meaningful maintainer-visible impact outside the owned taxonomy.issue-rating: 🦞 diamond lobsterVery strong issue quality with high-confidence source-level or clear reproduction.Very strong issue quality with high-confidence source-level or clear reproduction.
Summary
CodexLaunchPreflight.isLaunchCandidateAllowedspawnsspctl --assess --type execute --verbose=4on the nativecodexbinary every timeBinaryLocator.resolveCodexBinaryruns, and nothing caches the verdict. On this Mac each assessment of the 281 MB x86_64 standalonecodexcosts ~2.5 s ofsyspolicydCPU, and Gatekeeper does not cache arejected (the code is valid but does not seem to be an app)verdict either, so the cost is linear in how often CodexBar lookscodexup.The CPU is billed to
syspolicyd, not to CodexBar, so CodexBar's own CPU column looks idle while the fan runs. That made it hard to attribute.Same class as #3837 (uncached signature validation on every refresh), on a different path.
Environment
spctlAssessment(path:)andisLaunchCandidateAllowed(...)inSources/CodexBarCore/PathEnvironment.swiftare unchanged on v0.68.0 /main.~/.local/bin/codex→~/.codex/packages/standalone/current/bin/codex(Developer ID Application: OpenAI OpCo, LLC (2DC432GLL2), 281 MB, no quarantine xattr)Measurements
Three back-to-back runs of
spctl --assess --type execute --verbose=4 ~/.local/bin/codex, withsyspolicydotherwise idle:syspolicydCPUFrom the unified log (
log show --predicate 'process == "spctl"'), everyspctlparented by CodexBar:syspolicyd, continuously.syspolicydmeasured 16.5 s of CPU per 30 s (~55% of a core). Quitting CodexBar took it to 0.00 s per 30 s. The trigger for the faster cadence was not identified, but whatever raises the lookup rate, every lookup pays the full assessment.Source-level cause
PathEnvironment.swift:resolveBinary→find/ well-known paths →launchCandidateFilter(CodexLaunchPreflight.isLaunchCandidateAllowed) →spctlAssessment(path:), which launches/usr/sbin/spctlon every call. There is no memoization. Callers includeCodexStatusProbe.fetch,resolveCodexExecutableForRPC, the Codex descriptor'sbinaryLocator, andCodexLoginRunner.Expected
Cache the preflight verdict per resolved native binary, keyed on something that changes when the binary does (path + inode + size + mtime, or the code-directory hash), as #3857 did for the Chromium gate. An unchanged binary should not be re-assessed on every refresh.
Workaround
Set
CODEX_CLI_PATHin CodexBar's environment, e.g.open --env CODEX_CLI_PATH=$HOME/.local/bin/codex -a CodexBar.resolveBinaryreturns an existing override before the preflight runs. Verified: 0spctlchildren over a 6-minute window spanning a refresh, and Codex usage still fetched. Caveat: a Sparkle relaunch dropsopen --envvariables, so the workaround has to be re-applied after each update.