Critical: Unexpected deletion/rename activity in personal folder (D:\Content) during Codex session, suggesting fail-closed path guardrails
Critical: Unexpected deletion/rename activity in personal folder (D:\Content) during Codex session, need fail-closed path
guardrails
Description
On February 17, 2026 (Swedish local time), approximately 10:53-11:00, I experienced unexpected mass deletion/rename activity under
D:\Content during a Codex-assisted session. This path contains critical personal known-folder data (Desktop/Downloads/
Documents targets) and had been stable for years. I recovered files via Shadow Copies and DMDE, but this caused high-risk
data-loss impact and significant downtime.
Suggesting product-level safeguards:
- User-defined protected-path deny list (hard block on write/rename/delete/move/ACL changes), fail-closed.
- Explicit per-command confirmation for destructive operations, with exact target paths shown before execution.
- Strict fail-closed behavior when sandbox/permission state is uncertain.
- Immutable command provenance log (timestamps, command, cwd, resolved target paths) for incident auditing.
- Preflight dry-run for write operations showing planned file changes and risk level before execution.
- Safer Windows defaults, including enforceable workspace-only write mode.
This incident reduced trust in default filesystem safety behavior. I can provide timeline details and forensic evidence if
needed.
This issue has 4 comments on GitHub. Read the full discussion on GitHub ↗