Codex CLI 0.160.1 preserves Windows environment variables for remote MCP

Codex CLI 0.160.1 preserves SYSTEMROOT, TEMP, and TMP when Unix hosts spawn remote stdio MCP servers on Windows executors with custom environments.

OpenAI released Codex CLI 0.160.1 on 2026-10-05 to fix environment filtering when running remote Model Context Protocol (MCP) servers on Windows. The release ensures that Unix orchestrators preserve SYSTEMROOT, TEMP, and TMP on the Windows executor when passing explicit remote environment variables. Without these variables, Windows subprocesses fail during runtime initialization, dynamic library resolution, and temporary file allocation.

Key facts

  • OpenAI published Codex CLI 0.160.1 under Git tag rust-v0.160.1 at 18:29 UTC on 2026-10-05.
  • The release preserves SYSTEMROOT, TEMP, and TMP when launching remote stdio MCP servers with explicit remote environment variables.
  • The change fixes setups where a Unix host (macOS or Linux) coordinates with a Windows remote executor.
  • Pull request #51121 backported the fix to the 0.160 maintenance branch from pull request #50129 on main.
  • The patch modifies codex-rs/rmcp-client/src/stdio_server_launcher.rs to append the three Windows variables to the base allowlist.
  • Environment filtering continues to isolate unrequested secrets and undeclared environment variables.
  • A subsequent release, rust-v0.162.0-alpha.16, was tagged later the same evening at 21:37 UTC on 2026-10-05 on the separate alpha development track.

How remote MCP environment filtering works

Codex CLI allows developers to run Model Context Protocol (MCP) servers across process and network boundaries. When an agent configuration defines a remote stdio MCP server, Codex CLI connects to a remote executor and launches the requested server binary over standard input and output streams.

To prevent accidental credential leakage, Codex CLI restricts the environment variables passed to remote server processes. When a developer provides an explicit list of remote variables in the server configuration, Codex CLI creates a restricted allowlist rather than forwarding the entire execution shell.

Prior to Codex CLI 0.160.1, the remote stdio launcher constructed this allowlist from Unix defaults defined in DEFAULT_ENV_VARS. When the orchestrator was a Unix system (such as macOS or Linux) and the executor was a Windows machine, the Unix allowlist stripped out essential Windows platform variables:

  1. SYSTEMROOT (typically C:\Windows), which the Windows kernel and C runtime need to locate system dynamic-link libraries (DLLs) and spawn basic system utilities.
  2. TEMP and TMP (typically C:\Users\<user>\AppData\Local\Temp), which compilers, runtime workers, and language package managers use to create scratch files and standard I/O buffers.

When an explicit remote variable like API_KEY or REMOTE_TOKEN was defined, Codex CLI applied the filter and omitted SYSTEMROOT, TEMP, and TMP. As a result, the remote Windows child process failed to start or crashed on its first disk write.

The stdio server launcher patch

OpenAI initially merged the fix into the main branch via pull request #50129 on 2026-10-02 (commit 7d3e696). On 2026-10-05, Andrew Gu (andrewgu-oai) backported the patch into the 0.160 release line via pull request #51121 (commit 91c0ea5b6c0c2dbb68a8dcbaadccbb3eb8cf149b).

The fix modifies a single launcher method in codex-rs/rmcp-client/src/stdio_server_launcher.rs. When building the effective child environment, the launcher appends SYSTEMROOT, TEMP, and TMP directly to the DEFAULT_ENV_VARS iterator:

// codex-rs/rmcp-client/src/stdio_server_launcher.rs
crate::utils::DEFAULT_ENV_VARS
    .iter()
    .chain(["SYSTEMROOT", "TEMP", "TMP"].iter())
    .map(|name| (*name).to_string())
    .chain(remote_env_vars.iter().cloned())
    .collect()

The accompanying unit test in stdio_server_launcher.rs verifies that Windows system variables pass through while unrequested variables remain stripped:

// Verification test in stdio_server_launcher.rs
let env = shell_environment::create_env_from_vars(
    [
        ("PATH".to_string(), "/remote/bin".to_string()),
        ("SystemRoot".to_string(), r"C:\Windows".to_string()),
        ("TEMP".to_string(), r"C:\Users\test\AppData\Local\Temp".to_string()),
        ("TMP".to_string(), r"C:\Users\test\AppData\Local\Temp".to_string()),
        ("REMOTE_TOKEN".to_string(), "remote-secret".to_string()),
        ("UNREQUESTED_SECRET".to_string(), "unrequested".to_string()),
    ],
    ["REMOTE_TOKEN"],
);

assert_eq!(env.get("PATH").map(String::as_str), Some("/remote/bin"));
assert_eq!(env.get("SystemRoot").map(String::as_str), Some(r"C:\Windows"));
for name in ["TEMP", "TMP"] {
    assert_eq!(env.get(name).map(String::as_str), Some(r"C:\Users\test\AppData\Local\Temp"));
}
assert_eq!(env.get("REMOTE_TOKEN").map(String::as_str), Some("remote-secret"));
assert_eq!(env.get("UNREQUESTED_SECRET"), None);

Because environment variable lookups on Windows are case-insensitive, matching handles both SystemRoot and SYSTEMROOT. Unrequested environment variables, such as UNREQUESTED_SECRET, continue to be rejected by the allowlist.

Upgrading Codex CLI

Developers using Codex CLI across heterogeneous Unix and Windows environments can install Codex CLI 0.160.1 using npm:

npm install -g @openai/codex@0.160.1

Prebuilt release binaries and archive packages for x86_64 and aarch64 architectures across macOS Darwin, Linux musl, and Windows MSVC are also available on GitHub under release tag rust-v0.160.1.

A separate release tagged rust-v0.162.0-alpha.16 was published on GitHub at 21:37 UTC on 2026-10-05. That release belongs to the experimental alpha stream and is separate from the stable 0.160.1 maintenance fix.

Sources

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.