sandbox profile bug

Open 💬 0 comments Opened May 15, 2026 by roothider

What version of the Codex App are you using (From “About Codex” dialog)?

26.513.20950 (2816)

What subscription do you have?

plus

What platform is your computer?

macos apple silicon

What issue are you seeing?

The Codex app does not apply the custom sandbox rules from config.toml, whether you choose [Default Permissions] or [Custom config.toml] in the UI...

What steps can reproduce the bug?

Codex App 0.131.0-alpha.9
~/.codex/config.toml:
default_permissions = "custom"
[permissions.custom.filesystem]
":root" = "read"
"/Applications/" = "none"

CLI:
codex sandbox macos --permissions-profile custom -- ls -l /Applications/
=> Operation not permitted

Codex App new thread:
execute ls -l /Applications/
=> succeeds

state_5.sqlite threads.sandbox_policy shows {"type":"read-only"} instead of custom PermissionProfile.

What is the expected behavior?

Codex apps should respect config.toml

Additional information

_No response_

View original on GitHub ↗