# codex-desktop-linux: a community repackaging of OpenAI's Linux ChatGPT app

> The project rebuilds OpenAI's signed Linux .deb into deb, RPM, pacman, AppImage and Nix outputs, and adds Linux features that are off by default. It is for Linux users who want the official Electron payload without hand-converting packages.

**ilysenko/codex-desktop-linux** — Unofficial ChatGPT desktop app for Linux (formerly the Codex app), built locally from OpenAI’s official macOS app. Includes Chat, Work, and Codex. Packages for Debian/Ubuntu (.deb), Fedora/openSUSE (.rpm), Arch (pacman), Nix/NixOS, and AppImage, with Wayland and X11 support.

- Repository: https://github.com/ilysenko/codex-desktop-linux
- Stars: 3,857 · Forks: 503
- Language: JavaScript
- License: MIT
- Published: 2026-09-14 · Updated: 2026-09-14 · Language: en
- Canonical page: https://hysenlabs.com/projects/ilysenko-codex-desktop-linux

## What codex-desktop-linux actually ships

OpenAI publishes a signed Linux .deb of its ChatGPT desktop application. That is the only upstream source this project accepts. codex-desktop-linux takes that payload, verifies it, and repackages it for Debian and Ubuntu, Fedora, openSUSE, Arch, Nix and NixOS, plus an AppImage for atomic desktops and other distributions. It is unofficial and community-maintained; the README describes it as a distribution of the official Linux application rather than a fork of the app itself.

The identity split is deliberate. The application appears in desktop menus as ChatGPT Community with an icon marked with a blue C, while the package name, command and install prefix stay codex-desktop and /opt/codex-desktop. That makes it distinguishable from OpenAI's own ChatGPT package on the same machine, which matters because both can be installed at once.

Who this is for: Linux users who want the official Electron runtime, native modules, bundled codex and rg binaries, code-mode host, plugins, libraries, locales and Owl metadata, but do not want to convert a .deb by hand or run an unpacked tree. The README states that with no ASAR-changing feature enabled, resources/app.asar stays byte-for-byte identical to the official package. That is the strongest claim in the repository, and it is the reason to trust the repackaging more than a random third-party build.

## How the build turns one .deb into five package formats

The Makefile drives everything. It resolves the current package through OpenAI's signed stable APT metadata for amd64 or arm64, stages it into codex-app/, then produces the native artifact for the detected distribution into dist/. Distribution detection reads /etc/os-release and matches ID and ID_LIKE tokens against arch, manjaro and endeavouros for pacman; fedora, rhel, centos, suse and opensuse for RPM; debian, ubuntu, linuxmint and pop for deb. If os-release gives nothing, it falls back to the presence of dpkg-deb, rpmbuild or makepkg.

The Rust side is a Cargo workspace with four members: computer-use-linux, read-aloud-linux, updater and record-replay-linux. Those are the optional Linux features and the update manager, not the application core. The README says Rust is used for the updater and for enabled native feature helpers, so a build without those features does not need the same toolchain depth.

You can bypass repository discovery by pointing the build at a local package you already trust. The README notes the local file is still checked for package name, architecture, control metadata, payload completeness and SHA-256 recording, but because signed repository discovery is skipped, the caller is responsible for its origin. Old .dmg, DMG= and CODEX_DMG_* inputs are intentionally unsupported, which is a leftover from the project's earlier macOS-derived approach.

## Installing the Codex desktop app on Linux with make bootstrap-native

The README's recommended path is a clone followed by one make target. Clone first, because the native package and AppImage builds run from the checkout:

```bash
git clone https://github.com/ilysenko/codex-desktop-linux.git
cd codex-desktop-linux
```

Then run the bootstrap target. According to the README it installs build dependencies, resolves the current package through OpenAI's signed stable APT metadata, builds codex-app/, creates the native package for the detected distribution, and installs the newest artifact from dist/:

```bash
make bootstrap-native
```

If the dependencies are already present, the shorter target skips the dependency step:

```bash
make install-native
```

To pick optional features before installing, run setup first. The README is explicit that this only writes the local feature selection and does not build or install anything, so it must be followed by install-native:

```bash
make setup-native
make install-native
```

On NixOS or another Nix system the README gives a flake command instead of the Makefile path:

```bash
nix run github:ilysenko/codex-desktop-linux
```

For atomic desktops or an unsupported distribution, build an AppImage without the native updater:

```bash
make build-app && make appimage
```

If repository resolution is not what you want, supply a local package. The README warns that signed repository discovery is skipped in this mode, so you own the provenance question:

```bash
UPSTREAM_DEB=/path/to/chatgpt_<version>_<arch>.deb make build-app
```

What you should see: a package in dist/ matching the detected format (codex-desktop_*.deb, codex-desktop-*.rpm or codex-desktop-[0-9]*.pkg.tar.*), and, after install, a ChatGPT Community entry in your desktop menu that launches codex-desktop from /opt/codex-desktop.

## The anonymous launch counter, and how to switch it off

The launcher sends at most one anonymous usage event per UTC day to a public GoatCounter dashboard. The README says the event contains only the fixed path /app-launch, that GoatCounter derives an aggregate country from the network request, and that no application activity, account or machine identifier, version, architecture, package format, language, screen size or referrer is sent. Every installation sends the same fixed, non-identifying User-Agent so GoatCounter does not discard the request as a bot.

This is telemetry in a desktop app, and it is worth saying plainly rather than burying. The payload is minimal and the stated purpose is to help the community decide whether maintaining the distribution is useful, but a network request on every launch is still a network request. The request runs in the background; a missing curl, a blocked request or any other error never delays the application and produces no output, which means you cannot detect it by watching startup time.

Disabling it takes one environment variable, documented in the README:

```bash
CODEX_LINUX_DISABLE_USAGE_REPORTING=1 codex-desktop
```

If you want that permanent, you would set it in the desktop entry or a wrapper, and the README does not document that step. That is a gap: the variable is documented, the persistent configuration is not.

## Where codex-desktop-linux breaks down

The single-instance lock is the sharpest limitation. The README states that the official chatgpt package and the custom codex-desktop package may coexist, but both intentionally use the upstream Codex user profile, and you must not run them at the same time because the upstream single-instance lock may route the second launch into the process that is already running. So coexistence is a packaging property, not a usage property. If you planned to keep both installed and compare them side by side, the upstream lock decides which one you actually get.

Only the latest signed stable OpenAI Linux package is supported, on amd64 and arm64. There is no channel for pinning an older upstream version, and no documented rollback if a new upstream build regresses. The README does not document rollback. If you need to hold a specific version, this project does not give you a supported way to do it.

AppImage is the other weak spot. The README says AppImage never adds --no-sandbox automatically, and that if your distribution disables unprivileged user namespaces you should use the native package or follow the sandbox guidance in docs/troubleshooting.md. On hardened kernels where unprivileged user namespaces are off, the AppImage is the wrong tool and the native package is the answer.

Finally, there is no hosted download. Every path starts with a clone or a flake reference, and the build needs Node.js 20 or newer, npm, Python 3, curl, gpgv, dpkg-deb, tar, make and a C/C++ toolchain, with Rust for the updater and native feature helpers. On a machine where you cannot install those, this project has nothing to offer.

## How it differs from building the official .deb yourself

The obvious alternative is downloading OpenAI's signed Linux .deb and installing it directly with apt or dpkg. That approach is simpler and has no third party in the chain at all. The difference is scope: the official .deb targets Debian-derived systems, so on Fedora, openSUSE, Arch or NixOS you either convert it, unpack it by hand, or run it outside the package manager. codex-desktop-linux exists to close that gap, and it does so by reusing the official payload rather than rebuilding the application.

The trade is provenance. Installing the official .deb means trusting one vendor. Installing this project means trusting the maintainer's verification and repackaging steps in addition to OpenAI, and accepting that upstream changes can break the build until the maintainer catches up. The README's byte-for-byte claim about resources/app.asar when no ASAR-changing feature is enabled is the project's own answer to that concern, and it is checkable by anyone who wants to diff the staged tree against the upstream package.

A second alternative is a distribution-maintained package. Those tend to lag upstream releases and often ship a different feature set. This project tracks the latest signed stable upstream package by design, which is both its selling point and the reason it has no version-pinning story.

## Maintenance, licensing and what removal involves

The repository is not archived and the last push was on 2026-09-14, three days before this writing, so the project is being worked on right now. The README points contributors at CONTRIBUTING.md and AGENTS.md, and there is a CI workflow plus a separate upstream-build-app workflow, which suggests upstream changes are pulled in on a schedule rather than only on demand. The release history is not retrievable from the repository listing, so there is no way to judge cadence from releases alone.

Upgrade cost is mostly the rebuild. Because the build resolves the current package from the signed stable index each time, staying current means re-running the build and reinstalling the artifact. The native package installs a user update service, and removal disables it. If a service from an older or manual installation lingers, the README gives explicit cleanup:

```bash
systemctl --user disable --now codex-update-manager.service
systemctl --user daemon-reload
```

Uninstalling uses the package manager that installed it: apt remove codex-desktop, dnf remove codex-desktop, zypper remove codex-desktop or pacman -R codex-desktop. For an AppImage you delete the file you built. The README says to close both ChatGPT Community and the official ChatGPT application before removing.

The project is MIT licensed, and the README does not describe any additional terms on the repackaged payload. That is worth checking yourself: the licence here covers this repository's build tooling, while the upstream application carries its own terms, and nothing in the README resolves how those interact for redistribution. That is a question for your own review, not a settled point.

## Conclusion

Adopt it if you want the official signed payload in a native package on Debian, Fedora, openSUSE, Arch or Nix, and you are willing to build from a clone. Skip it if you need a hosted download, an aarch64 AppImage, or you want to run it alongside the official ChatGPT package, since both share the upstream Codex profile and the single-instance lock. Verify first that Node.js 20 or newer, npm, Python 3, curl, gpgv, dpkg-deb, tar, make and a C/C++ toolchain are present, and decide whether the anonymous daily launch event is acceptable or you will set CODEX_LINUX_DISABLE_USAGE_REPORTING=1.

## FAQ

### What does the Codex desktop app do?

This project distributes OpenAI's official Linux ChatGPT desktop application, which the README describes as including Chat, Work and Codex, along with the bundled codex and rg binaries, code-mode host, plugins, libraries and locales. codex-desktop-linux repackages that signed payload rather than reimplementing it.

### Can Codex access my computer?

The README does not describe the application's permissions or what the Codex features can reach on your machine. What it does document is a launcher that sends at most one anonymous launch event per UTC day to a public GoatCounter dashboard, carrying only the fixed path /app-launch, and an environment variable to disable it.

### What do people use codex for?

The README does not describe typical usage. It documents the packaging: the official Electron runtime, native modules, bundled codex and rg, code-mode host, plugins, libraries, locales and Owl metadata are reused directly from OpenAI's signed Linux package.

### How to remove codex from Linux?

Close both ChatGPT Community and the official ChatGPT application first, then remove the package with the manager that installed it: apt remove codex-desktop, dnf remove codex-desktop, zypper remove codex-desktop or pacman -R codex-desktop. If a leftover update service remains, the README gives systemctl --user disable --now codex-update-manager.service followed by systemctl --user daemon-reload.

## Sources

- [ilysenko/codex-desktop-linux on GitHub](https://github.com/ilysenko/codex-desktop-linux)
- [Issues](https://github.com/ilysenko/codex-desktop-linux/issues)
- [License: MIT](https://github.com/ilysenko/codex-desktop-linux/blob/main/LICENSE)
- [README](https://github.com/ilysenko/codex-desktop-linux/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ilysenko-codex-desktop-linux
