Full Access thread downgraded to on-request/workspace-write after interrupted manual context compaction on Windows Desktop
What version of the Codex App are you using (From “About Codex” dialog)?
26.519.81530
What subscription do you have?
GPT Pro 20x
What platform is your computer?
_No response_
What issue are you seeing?
Summary
A Codex Desktop thread that was running with Full Access unexpectedly downgraded to approval_policy=on-request and sandbox_policy=workspace-write after an interrupted/manual context compaction. The UI/global state still indicated Full Access, but subsequent tool calls started requesting approval.
This looks related to:
- #23958
- #23875
- #24300
However, this report adds a Windows Desktop + CLI 0.133.0 reproduction path involving interruption/manual context compaction.
Environment
- Platform: Windows Desktop
- Codex CLI version: 0.133.0
- Thread/session id:
019e6737-b640-71a3-8c10-317141e73ec3 - Original cwd:
D:\code\VTK_test - Expected mode: Full Access
- Expected permissions:
approval_policy=never,sandbox_policy=danger-full-access
What happened
The session initially started correctly with Full Access:
approval_policy=never
sandbox_policy=danger-full-access
After the previous turn was interrupted and context was manually compacted, the regenerated turn context changed to:
approval_policy=on-request
sandbox_policy=workspace-write
After that point, shell calls started including:
"sandbox_permissions": "require_escalated"
So Codex began asking for approvals even though the thread/user expected Full Access.
Local evidence
Relevant local trace:
rollout-2026-05-27T10-16-04-019e6737-b640-71a3-8c10-317141e73ec3.jsonl
Before compaction:
- line 5: approval_policy=never, sandbox=danger-full-access
- line 778/971/989/1547: still never + danger-full-access
After interruption/manual context compaction:
- line 1906: previous turn aborted/interrupted
- line 1909: compaction
- line 1911: context_compacted
- line 1912: regenerated permissions context
- line 1914: turn_context changed to approval_policy=on-request, sandbox_policy=workspace-write
Persisted state also showed the affected thread stored as:
sandbox_policy=workspace-write
approval_mode=on-request
while global UI/full-access state still indicated Full Access.
Raw JSONL excerpt
This is a privacy-preserving excerpt from the local JSONL. Long instruction blocks, user task content, and encrypted compaction payloads are redacted, but the timestamps, event types, turn ids, permission fields, sandbox fields, cwd, and CLI version are unchanged.
{"line":1,"timestamp":"2026-05-27T02:17:02.397Z","type":"session_meta","payload":{"id":"019e6737-b640-71a3-8c10-317141e73ec3","timestamp":"2026-05-27T02:16:04.928Z","cwd":"D:\\code\\VTK_test","originator":"Codex Desktop","cli_version":"0.133.0","source":"vscode","thread_source":"user","model_provider":"openai","base_instructions":"[redacted]"}}
{"line":5,"timestamp":"2026-05-27T02:17:02.472Z","type":"turn_context","payload":{"turn_id":"dc85c18d-502a-4195-a466-e5f1eb21b2e5","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1547,"timestamp":"2026-05-27T09:16:49.846Z","type":"turn_context","payload":{"turn_id":"019e6875-c0b5-7a53-97af-ba21c2e85983","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1905,"timestamp":"2026-05-27T10:06:57.614Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"<turn_aborted>\\nThe user interrupted the previous turn on purpose. Any running unified exec processes may still be running in the background. If any tools/commands were aborted, they may have partially executed.\\n</turn_aborted>"}]}}
{"line":1906,"timestamp":"2026-05-27T10:06:57.629Z","type":"event_msg","payload":{"type":"turn_aborted","turn_id":"019e6875-c0b5-7a53-97af-ba21c2e85983","reason":"interrupted","completed_at":1779876417,"duration_ms":7409497}}
{"line":1907,"timestamp":"2026-05-27T10:07:02.833Z","type":"event_msg","payload":{"type":"task_started","turn_id":"019e68e6-e420-7920-b3e7-1afaaebf014d","started_at":1779876422,"model_context_window":258400,"collaboration_mode_kind":"default"}}
{"line":1908,"timestamp":"2026-05-27T10:13:55.022Z","type":"event_msg","payload":{"type":"task_started","turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","started_at":1779876835,"model_context_window":258400,"collaboration_mode_kind":"default"}}
{"line":1909,"timestamp":"2026-05-27T10:15:14.381Z","type":"compacted","payload":{"message":"","replacement_history":"[redacted long user/instruction history and encrypted_content]"}}
{"line":1911,"timestamp":"2026-05-27T10:15:14.408Z","type":"event_msg","payload":{"type":"context_compacted"}}
{"line":1912,"timestamp":"2026-05-27T10:15:14.489Z","type":"response_item","payload":{"type":"message","role":"developer","content":[{"type":"input_text","text":"<permissions instructions>\\nFilesystem sandboxing defines which files can be read or written. `sandbox_mode` is `workspace-write`: The sandbox permits reading files, and editing files in `cwd` and `writable_roots`. Editing files in other directories requires approval. Network access is restricted.\\n# Escalation Requests\\n[redacted rest of regenerated permissions/app context]"}]}}
{"line":1914,"timestamp":"2026-05-27T10:15:14.489Z","type":"turn_context","payload":{"turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"on-request","sandbox_policy":{"type":"workspace-write","writable_roots":["C:\\Users\\15972\\.codex\\memories"],"network_access":false,"exclude_tmpdir_env_var":false,"exclude_slash_tmp":false},"permission_profile":{"type":"managed","file_system":{"type":"restricted","entries":[{"path":{"type":"special","value":{"kind":"root"}},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test"},"access":"write"},{"path":{"type":"special","value":{"kind":"slash_tmp"}},"access":"write"},{"path":{"type":"special","value":{"kind":"tmpdir"}},"access":"write"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.git"},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.agents"},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.codex"},"access":"read"},{"path":{"type":"path","path":"C:\\Users\\15972\\.codex\\memories"},"access":"write"}]},"network":"restricted"},"file_system_sandbox_policy":{"kind":"restricted","entries":"[same restricted entries as permission_profile.file_system.entries]"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1928,"timestamp":"2026-05-27T10:15:38.326Z","type":"response_item","payload":{"type":"function_call","name":"shell_command","arguments":"{\"command\":\"Get-Content -LiteralPath 'C:\\\\Users\\\\15972\\\\.codex\\\\plugins\\\\cache\\\\openai-bundled\\\\browser\\\\26.519.81530\\\\skills\\\\browser\\\\SKILL.md' -TotalCount 160\",\"workdir\":\"D:\\\\code\\\\VTK_test\",\"timeout_ms\":10000,\"sandbox_permissions\":\"require_escalated\",\"justification\":\"需要读取已安装 Browser 技能说明,以便按浏览器插件工作流验证本地 HTML 页面。\",\"prefix_rule\":[\"Get-Content\"]}","call_id":"call_Ftu2xTXneTp7NBx6zRvYY0C8"}}
Additional observation: permission change only took effect after abort/new turn
During the affected turn, I attempted to recover by changing permissions in the UI back to the default profile and then back to Full Access. I do not see an explicit thread/settings or UI-permission-change event in this JSONL, so I cannot point to a raw settings record for that UI action.
What the JSONL does show:
- From line 1914 to line 2173, the active turn remained
approval_policy=on-requestandsandbox_policy=workspace-write. - In that affected turn, 43
shell_commandcalls included"sandbox_permissions":"require_escalated". - Several commands failed through the Windows sandbox path with
CreateProcessAsUserW failed: 5/windows sandbox failed: spawn setup refresh. - After I interrupted the stuck approval/sandbox turn, the next turn started with regenerated Full Access permissions:
approval_policy=never,sandbox_policy=danger-full-access,permission_profile=disabled. - After that restored turn context, subsequent tool calls no longer included
sandbox_permissions.
This suggests the UI permission profile may not refresh the already-running turn context, while a new turn after abort/resume does pick up Full Access again.
{"line":2170,"timestamp":"2026-05-27T10:34:15.042Z","type":"response_item","payload":{"type":"function_call_output","call_id":"call_wZA7k66VAPpeNGEhjui2jKoP","output":"execution error: Io(Custom { kind: Other, error: \"windows sandbox: runner error: CreateProcessAsUserW failed: 5\" })"}}
{"line":2172,"timestamp":"2026-05-27T10:34:15.799Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"<turn_aborted>\\nThe user interrupted the previous turn on purpose. Any running unified exec processes may still be running in the background. If any tools/commands were aborted, they may have partially executed.\\n</turn_aborted>"}]}}
{"line":2173,"timestamp":"2026-05-27T10:34:15.813Z","type":"event_msg","payload":{"type":"turn_aborted","turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","reason":"interrupted","completed_at":1779878055,"duration_ms":1220791}}
{"line":2175,"timestamp":"2026-05-27T10:34:54.177Z","type":"response_item","payload":{"type":"message","role":"developer","content":[{"type":"input_text","text":"<permissions instructions>\\nFilesystem sandboxing defines which files can be read or written. `sandbox_mode` is `danger-full-access`: No filesystem sandboxing - all commands are permitted. Network access is enabled.\\nApproval policy is currently never. Do not provide the `sandbox_permissions` for any reason, commands will be rejected.\\r\\n</permissions instructions>"}]}}
{"line":2176,"timestamp":"2026-05-27T10:34:54.177Z","type":"turn_context","payload":{"turn_id":"019e6900-61b4-7dc2-91f3-ab97f888d383","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":2177,"timestamp":"2026-05-27T10:34:54.189Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"继续,我注意到我明明给你完全访问权限,你还是一直在向我要权限,刚刚的最后一个申请我不小心按到ESC你就停住了,继续\\n"}]}}
{"line":2182,"timestamp":"2026-05-27T10:35:09.197Z","type":"response_item","payload":{"type":"function_call","name":"shell_command","arguments":"{\"command\":\"Get-Content -LiteralPath 'D:\\\\code\\\\VTK_test\\\\translation_work\\\\sections_zh_llm\\\\09_advanced_computer_graphics.md' | Select-Object -Skip 54 -First 78\",\"workdir\":\"D:\\\\code\\\\VTK_test\",\"timeout_ms\":10000}","call_id":"call_wqhVLzdFQXaPLn6jCUzqy3yB"}}
Expected behavior
Context compaction/resume should preserve the effective thread permission profile. A thread running in Full Access should remain:
approval_policy=never
sandbox_policy=danger-full-access
unless the user explicitly changes permissions.
Actual behavior
After manual context compaction following an interruption, the thread silently changed to:
approval_policy=on-request
sandbox_policy=workspace-write
and started prompting for approvals.
Why this may not be a duplicate
This appears related to #23958 and #23875, but this case has a specific trigger and environment:
- Windows Desktop
- CLI 0.133.0
- manual context compaction after an interrupted turn
- Full Access UI/global state did not match the regenerated runtime permissions
Happy to provide more logs if useful.
What steps can reproduce the bug?
I do not have a minimal stable repro yet. The observed sequence in this session was:
- Start / continue a Codex Desktop thread in Full Access mode.
- The JSONL showed approval_policy=never and sandbox_policy=danger-full-access across multiple turns.
- Run a long task.
- Interrupt the turn after context compaction appeared to stall.
- Manually compact context / resume the thread.
- The regenerated turn_context changed to approval_policy=on-request and sandbox_policy=workspace-write.
- Subsequent shell calls started including sandbox_permissions=require_escalated and began prompting for approval.
- After aborting that affected turn and starting a new turn, the context returned to approval_policy=never and sandbox_policy=danger-full-access.
What is the expected behavior?
_No response_
Additional information
_No response_
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗