Environment
- Surface: Codex Windows desktop app
- Codex version:
26.1002.52244 - OS: Windows 10
- Model: Sol 6.1, High reasoning
- Authentication/plan: ChatGPT Pro
- Windows sandbox setting:
elevated - The app’s update checker reported
up_to_date.
Bug
The elevated Windows sandbox repeatedly fails before commands start. Even a read-only Get-Location command fails, and the patch editor cannot create or edit repository files. Codex then requests approval to run commands outside the sandbox.
Expected behavior: ordinary reads and writes within the configured writable workspace should succeed using the normal sandbox.
The logs identify a runtime permission-validation failure: sandbox setup cannot open node_repl.exe for an ACL update because Windows reports that another process is using it.
Reproduction
-
Configure:
[windows] sandbox = "elevated" -
Fully exit and reopen the desktop app.
-
Open a local project configured as trusted and writable.
-
Ask Codex to run
Get-Location. -
Ask Codex to create a temporary file, then edit an existing temporary file.
On this machine, the shell fails before launch, file creation fails, and editing reports a reparse-point error.
Diagnostics
Shell error:
Failed to create unified exec process:
helper_unknown_error: setup refresh had errors
Relevant sandbox log excerpt, with the local path anonymized:
runtime read/execute validation failed:
validate runtime read/execute access on
%LOCALAPPDATA%\OpenAI\Codex\runtimes\cua_node\<runtime-id>\bin\node_repl.exe:
open ACL target for root-only update:
The process cannot access the file because it is being used by another process.
(os error 32)
Editing an existing file also reports:
Failed to read file to update <temporary-file-path>:
path contains a reparse point
None of the inspected parent directories was a reparse point or link.
| Test | Elevated sandbox |
|---|---|
| Normal shell/read command | Failed before launch |
| Patch editor: create file | Failed |
| Patch editor: edit existing file | Failed |
| Outside sandbox: create, read, edit, rename, delete | All passed |
Additional checks:
- The project was trusted and granted modify access to
CodexSandboxUsers. deny_read_acl_state.jsoncontained valid JSON: 22 bytes, zero NUL bytes.- Fully restarting the app did not resolve the issue.
- Rebooting Windows did not resolve it.
- After reboot, the failure recurred with only two newly started
node_repl.exeprocesses. - All temporary test files were removed; application files were unchanged.
Confirmed workaround
Changing the existing setting to:
[windows]
sandbox = "unelevated"
and restarting the app restored normal operation. Shell creation, reading, editing, renaming and deletion all passed. The normal patch editor also successfully created, edited and deleted files, without escalation or temporary command overrides.
Timing and frequency
The first matching error in the inspected October logs occurred at approximately 11:37 am on 8 October 2026, Australia/Sydney (UTC+11). Every elevated-mode attempt in our diagnostic tests failed, including after the app restart and Windows reboot.
Related support message
OpenAI_Support stated on 16 September that the related issue was resolved in subsequent Windows app updates. This report documents continued failures on the version above; I cannot confirm whether this is the same underlying defect, an unaddressed case, or a regression.