WINDOWS EVIDENCE-GATED WORKFLOW

Enhanced Theme Guide for Windows

Prepare, use only the pinned Engine source, verify the exact runtime tuple, and complete Restore without inventing missing instructions.

Windows task boundary

This page defines the Windows evidence and decision flow for the independent local Engine. It does not invent a PowerShell command, executable path, package name, service, firewall instruction, or permission prompt that is not present in the pinned Engine documentation. Confirm that the source instructions match Runtime SHA a1c48b3a84cc64532196e624fdf33ee1277cb018 before acting.

Prepare the Windows machine

Save work, note the Windows version and architecture, record the Codex build, and close or back up important sessions. Keep one validated theme JSON and one referenced image in a named local directory. Review rights and hashes. Stop for FAIL, a mismatch, scripts or executables inside a theme package, nested archives, traversal paths, unexpected files, or blocked redistribution.

Confirm the pinned Engine instructions

Open the independent Engine source and license linked by the approved record. Use only its verified Windows procedure for the pinned Runtime SHA. Design must reserve a clear block for a verified command or launcher instruction when upstream evidence exists; it must not synthesize a command from common Windows conventions.

Apply on a trusted local machine

The Engine launches or connects to Codex through a loopback Chrome DevTools Protocol endpoint and injects CSS or DOM into the local renderer. The debug endpoint does not provide user-level authentication. Keep it local to the trusted machine, do not open the port to a network, and use only the documented theme directory and Apply action.

Verify the Windows session

Record Windows version, architecture, Codex build, Engine version, Runtime SHA, theme and artifact hashes, date, evidence hash, and observed result. A screenshot or visual impression alone is not formal evidence. Browser preview and Structural PASS remain separate. Missing exact evidence means NOT_VERIFIED; changed builds or artifacts mean REVERIFY_REQUIRED.

Restore on Windows

Follow the pinned Restore action. Confirm that injected content was removed, the themed CDP session and loopback port were closed, and stock Codex reopened without debug flags. Keep recovery evidence with the same exact tuple. If process, port, or stock reopen cannot be checked, show CANNOT_VERIFY and avoid a completed recovery claim.

Troubleshooting boundaries

If the Engine cannot start, Windows blocks the documented action, the endpoint is unavailable, the theme cannot be read, or stock Codex does not reopen cleanly, stop. Recheck the verified Engine source, permissions described there, exact versions, file pair, hashes, and any remaining themed process. Do not invent a firewall or administrator workaround.

Status and independence

VERIFIED_BY_US requires a complete exact Windows evidence record. REFERENCE_ONLY material is not formal verification and does not authorize redistribution. CodexSkin Tools is an independent project and is not affiliated with, endorsed by, or sponsored by OpenAI.

Record the Windows result without overclaiming

Keep each result attached to the exact Windows evidence tuple instead of converting it into a broad platform label. Record the completed check, any unavailable input, and whether Restore was observed with the same machine, build, Engine, Runtime SHA, and artifact. If the pinned Engine source does not specify a command, executable path, permission elevation, or firewall action, leave that instruction absent rather than substituting a common Windows procedure.

States

preflight
Windows preflight: versions, files, rights, hashes, validation, and Restore path must be reviewed.
instruction_pending
Exact Windows command or launcher evidence is not frozen here; use only the verified pinned Engine instruction.
runtime_default
Windows Runtime status: NOT_VERIFIED.
reverify
Windows Runtime status: REVERIFY_REQUIRED because the build, Engine, Runtime SHA, or artifact changed.

Errors

engine_start
The local Engine did not start as documented. Stop and verify the pinned Windows instructions and versions.
endpoint
The loopback endpoint could not be confirmed. Do not expose another port or claim a themed session.
restore
The Windows recovery checks are incomplete. Runtime recovery remains CANNOT_VERIFY.

Frequently asked questions

Where are the exact Windows commands?

They must come from the verified pinned Engine instructions for the stated Runtime SHA. This contract does not invent commands, executable paths, or administrator steps.

What evidence is needed for a Windows runtime result?

Record Windows version and architecture, Codex build, Engine version, Runtime SHA, artifact hashes, date, evidence hash, observed result, and completed Restore evidence.

Should I open the loopback debug port through a firewall?

No general firewall instruction is frozen here. Keep the endpoint on the trusted local machine and follow only the verified pinned Engine guidance.