macOS Codex 通过 SSH 连接 Windows 失败
问题
macOS Codex 通过 SSH 连接 Windows,界面显示“SSH 连接失败”,日志包含:
** WARNING: connection is not using a post-quantum key exchange algorithm. ** This sessionmay be vulnerable to "store now, decrypt later"attacks. ** The server may need to be upgraded.See https://openssh.com/pq.html Authenticatedto 162.105.88.199 ([162.105.88.199]:22) using"publickey".入00:1:301+ec "$SHELL" -i-c '"set loginsh=1; if (-retc/csh.login ) source00010000💯343+…-/etc/csh.login ) source /etc/csh.login; if ( -r~/.login)source …
Categorylnfo : ParserError: (😃 [,ParentContainsErrorRecordException +FullyQualifiedErrorld : MissingStatementBlockTransferred: sent 3856, received 3208 bytes, in0.3 seconds Bytes per second: sent 14316.1,received 11910.3
出错命令包含$SHELL、/etc/csh.login等 Unix shell 内容。
SSH 认证已成功,失败发生在远程环境启动阶段。
成因:Codex SSH 启动脚本依赖 Unix shell,却被 Windows PowerShell 解析。
解决思路
两种方式:
- 使用 Codex“控制其他设备”功能,访问原生 Windows。
- 通过 SSH 连接 Windows 内的 WSL Ubuntu。
本文采用第二种方式,保留 Windows SSH 默认 shell:
Mac → Windows SSH → wsl.exe → WSL SSH → Bash → Linux Codex配置 WSL SSH
在 Ubuntu 中安装 OpenSSH Server 和 netcat,并启用 systemd。
创建独立 SSH 配置:
# /etc/ssh/sshd_config_codex Port 2222 ListenAddress 127.0.0.1 HostKey /etc/ssh/ssh_host_ed25519_key PubkeyAuthentication yes AuthorizedKeysFile .ssh/authorized_keys PasswordAuthentication no KbdInteractiveAuthentication no PermitRootLogin no AllowUsers <WSL用户名> UsePAM yes Subsystem sftp internal-sftp将 Mac 公钥加入 WSL 用户的~/.ssh/authorized_keys,目录权限设为700,文件权限设为600。
创建专用服务:
# /etc/systemd/system/codex-wsl-ssh.service [Unit] Description=SSH listener for Codex WSL After=network.target [Service] Type=simple ExecStartPre=/usr/bin/install -d -m 0755 /run/sshd ExecStartPre=/usr/sbin/sshd -t -f /etc/ssh/sshd_config_codex ExecStart=/usr/sbin/sshd -D -e -f /etc/ssh/sshd_config_codex Restart=on-failure RestartSec=3 [Install] WantedBy=multi-user.target启用服务:
sudo systemctl daemon-reload sudo systemctl enable --now codex-wsl-ssh.service配置 Mac SSH
在~/.ssh/config中添加:
Host labwin-pub HostName <Windows地址> User <Windows用户名> Host labwin-wsl HostName 127.0.0.1 Port 2222 User <WSL用户名> HostKeyAlias labwin-wsl IdentityFile ~/.ssh/id_ed25519 IdentitiesOnly yes ProxyCommand ssh -T -o BatchMode=yes labwin-pub wsl.exe -d Ubuntu -- nc 127.0.0.1 2222需要两层密钥登录都正常:Mac 到 Windows、Mac 到 WSL。首次连接应核对 WSL 主机指纹。
验证:
ssh labwin-wsl uname -s结果应为Linux。
配置 WSL 代理
Windows Codex 正常、WSL 却超时或提示unsupported_country_region_territory时,应检查 WSL 是否实际使用了 Windows 的网络配置。
本例 Windows 代理环境变量指向http://127.0.0.1:7897。为了让 WSL 使用同一地址,在 Windows 用户目录的.wslconfig中合并:
[wsl2] networkingMode=mirrored autoProxy=false dnsTunneling=true保存工作后执行wsl --shutdown,再启动 Ubuntu。
这里采用 Windows 环境变量作为代理来源。autoProxy跟随的是 Windows 系统代理设置,不能代替环境变量同步。
从 Windows 启动 WSL
将以下条目合并到 Windows 的WSLENV环境变量中,保留已有条目:
HTTP_PROXY/u:HTTPS_PROXY/u:NO_PROXY/u:ALL_PROXY/u在 WSL 中同步大小写变量:
export http_proxy="$HTTP_PROXY" export https_proxy="$HTTPS_PROXY" export no_proxy="$NO_PROXY" export all_proxy="$ALL_PROXY"WSLENV 传递的是启动 WSL 的 Windows 进程所持有的变量。修改持久化变量后,需要重新打开 Windows Terminal、IDE 等启动应用。
通过 SSH 启动 WSL Codex
仅设置 WSLENV 不足以覆盖 SSH 和后台服务的启动环境。
在实际启动 Codex 的入口读取 Windows 保存的代理变量,再传给 Codex,而不是只依赖 WSLENV。
安装并登录 Linux Codex
在 Ubuntu 中准备 Linux 版 Node.js/npm,再执行:
npm install -g @openai/codex command -v codex codex --version codex login按输出链接完成登录。
在 Codex 应用内添加连接
写入 SSH 配置不等于已经添加到应用的连接列表。
在 Mac Codex 中打开:
设置 → 连接 → SSH → 添加 → labwin-wsl启用连接,选择/mnt/c/...或/mnt/e/...下的项目目录,字母对应 Windows 盘符。