Windows 11: “setup refresh had errors” blocks commands and browser tasks

Environment

  • Surface: App; local Windows tasks and browser controls
  • Codex version: 26.1002.52244
  • OS: Windows 11, 64-bit; reproduced on a physical workstation and a Windows 11 VirtualBox VM
  • Model: Not recorded
  • Plan/authentication: Pro plan ($125), signed in through the app

Bug

The app shows the computer as connected and authorized, and accepts new task turns, but commands fail before execution. Even a read-only PowerShell Get-Location command cannot start. A separate browser task also reports the same startup error.

Expected: connected, authorized local tasks should be able to execute basic commands and use browser controls.

The VM worked earlier in the day, then developed the same error after a restart. I have not retrieved its underlying log, so I cannot confirm whether both machines have the same root cause.

Reproduction

  1. Open the Windows app and enable computer access
  2. Start or resume a local task
  3. Ask it to run only Get-Location
  4. The execution helper fails before starting the command

The failure persists after updating the app, closing and reopening it, restarting Windows, and revoking/re-enabling computer access. Windows App Repair on the physical workstation also did not resolve it.

Diagnostics

Exact error:

exec-server rejected request (-32603): helper_unknown_error: setup refresh had errors

On the physical workstation, the sandbox log reports Windows error 32: a file is being used by another process. This occurs during runtime access validation involving VCRUNTIME140_1.dll in the Codex cua_node runtime’s @oai/sky/bin/windows/swift/x64 directory. Earlier failures referenced node_repl.exe.

Using tasklist and Get-Process, I confirmed that codex-computer-use-swift had loaded that exact runtime DLL. The helper exits when I close the app. Reopening creates a new process, and command execution still fails.

When/how often: October 7, 2026, repeatedly throughout the afternoon and evening, America/New_York (EDT, UTC−04:00). Once affected, every attempted basic execution check failed, including after App Repair that evening.

I have not reset or reinstalled the app, deleted runtime folders, or changed ownership/permissions. Local project details, usernames, machine names and full paths are omitted.

Is there a supported recovery procedure that preserves local task state and sandbox security? Which additional redacted diagnostics would help?

So it seems

Edit:

%USERPROFILE%\.codex\config.tom

switch

sandbox = "elevated"

to

sandbox = "unelevated"

Seems to have gotten codex to start working again. Need to do more testing. I’m not sure if that was originally set one way and was changed along the way or if something else cause it to stop working as elevated when it was originally.

It seems to had resolved my issue as well. Not sure how it work though.

Besides, the file is named as config.toml, which misses an L from PS-Lbs’s reply. So you should look for

%USERPROFILE%\.codex\config.toml Instead.