Codex CLI v0.141.0 crashes with zsh: trace trap / SIGTRAP when attempting shell tool execution on macOS x86_64

Open 💬 2 comments Opened Jun 19, 2026 by itvincent-git

What version of Codex CLI is running?

0.141.0

What subscription do you have?

plus

Which model were you using?

5.5, 5.4

What platform is your computer?

x86

What terminal emulator and version are you using (if applicable)?

zsh

Codex doctor report

❯ codex doctor --allCodex Doctor v0.141.0 · macos-x86_64

Notes⚠ updates      update configuration is locally consistent⚠ threads      2 issues - rollout files are missing from the state DB; rollout scan was incomplete or found bad files─────────────────────────────────────────────────────────────

Environment✓ system       zh-Hans-HKos                       Mac OS 26.3.1 [64-bit]OS language              zh-Hans-HKLANG                     zh_HK.UTF-8VISUAL                   not setEDITOR                   not set✓ runtime      npm (package /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin, bin /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/bin, resources /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/codex-resources, path /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/codex-path)version                  0.141.0install method           npm (package /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin, bin /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/bin, resources /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/codex-resources, path /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/codex-path)commit                   unknownexecutable               ~/.nvm/versions/node/v24…-apple-darwin/bin/codex✓ install      consistentcontext                  npm (package /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin, bin /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/bin, resources /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/codex-resources, path /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/codex-path)managed by               npm: yes · bun: no · package root /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codexPATH entries (3)         ~/.nvm/versions/node/v24.11.0/bin/codex/usr/local/bin/codex/usr/local/bin//codexnpm update target        ~/.nvm/versions/node/v24…e_modules/@openai/codex✓ search       file exists (bundled, /Users/vincent/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-x64/vendor/x86_64-apple-darwin/codex-path/rg)search command           ~/.nvm/versions/node/v24…le-darwin/codex-path/rgsearch provider          bundledsearch command readiness file exists✓ git          git version 2.50.1 (Apple Git-155)selected git             /usr/bin/gitversion                  git version 2.50.1 (Apple Git-155)exec path                /Applications/Xcode.app/…er/usr/libexec/git-corerepo detected            truerepo root                ~/Documents/Develop/github/typer-cmd.git entry               directorybranch                   masterPATH entries (1)         /usr/bin/git✓ terminal     Apple Terminal 466terminal                 Apple TerminalTERM_PROGRAM             Apple_Terminalterminal version         466stdin is terminal        truestdout is terminal       truestderr is terminal       trueterminal size            172x36color output             enabledCOLORTERM                truecoloreffective locale         zh_HK.UTF-8✓ title        default · project typer-cmdtitle source             defaulttitle items              activity, project-nameactivity item            trueproject source           git repo rootproject value            typer-cmd✓ state        databases healthyCODEX_HOME               ~/.codex (dir)log dir                  ~/.codex/log (dir)sqlite home              ~/.codex (dir)state DB                 ~/.codex/state_5.sqlite (file) · integrity oklog DB                   ~/.codex/logs_2.sqlite (file) · integrity okgoals DB                 ~/.codex/goals_1.sqlite (file) · integrity okmemories DB              ~/.codex/memories_1.sqlite (file) · integrity okactive rollouts          574 files · 224.70 MB (avg 400.85 KB)archived rollouts        1 files · 49.44 KB (avg 49.44 KB)⚠ threads      2 issues - rollout files are missing from the state DB; rollout scan was incomplete or found bad filesdefault model provider   openairollout DB active files  573rollout DB archived files 1rollout DB scan errors   1rollout DB malformed file names 0rollout DB scan cap reached falserollout DB scan error sample ~/.codex/sessions/rollou…a32c-833341d48956.jsonl (no parseable rollout items)rollout DB rows          571rollout DB active rows   570rollout DB archived rows 1rollout DB missing active rows 3rollout DB missing archived rows 0rollout DB stale rows    0rollout DB archive mismatches 0rollout DB duplicate rollout thread ids 0rollout DB duplicate DB paths 0rollout DB model providers openai=571rollout DB sources       cli=541, vscode=17, exec=8, subagent=3, subagent=2rollout DB missing active sample ~/.codex/sessions/2026/0…9239-fb4fe9c351ae.jsonlrollout DB missing active sample ~/.codex/sessions/2026/0…b698-e184593e562b.jsonlrollout DB missing active sample ~/.codex/sessions/2026/0…baf1-8190f8a0cbcd.jsonl→ Check file permissions and unexpected files under CODEX_HOME sessions.

Configuration✓ config       loadedmodel                    gpt-5.5 · openaicwd                      ~/Documents/Develop/github/typer-cmdconfig.toml              ~/.codex/config.tomlconfig.toml parse        okMCP servers              3feature flags            30 enabled · 1 overriddenoverrides                memoriesenabled flags            shell_tool, unified_exec, shell_snapshot, terminal_resize_reflow, sqlite, memories, hooks, enable_request_compression, multi_agent, apps, tool_suggest, plugins, in_app_browser, browser_use, browser_use_external, computer_use, plugin_sharing, image_generation, skill_mcp_dependency_install, mentions_v2, steer, guardian_approval, goals, collaboration_modes, tool_call_mcp_elicitation, personality, fast_mode, tui_app_server, remote_compaction_v2, workspace_dependencies✓ auth         auth is configuredauth storage mode        Fileauth file                ~/.codex/auth.jsonstored auth mode         chatgptstored API key           falsestored ChatGPT tokens    truestored agent identity    false✓ mcp          3 server (1 stdio, 2 streamable_http) · 1 disabledconfigured servers       3disabled servers         1stdio servers            1streamable_http servers  2✓ sandbox      restricted fs + restricted network · approval OnRequestapproval policy          OnRequestfilesystem sandbox       restrictednetwork sandbox          restrictedlinux helper             noneexecve wrapper helper    ~/.codex/tmp/arg0/codex-…vq/codex-execve-wrapper

Updates⚠ updates      update configuration is locally consistentstartup update check     trueupdate action            npm install -g @openai/codexversion cache            ~/.codex/version.jsoncached latest version    0.141.0last checked at          2026-06-18 07:29 UTCdismissed version        0.121.0npm update target        ~/.nvm/versions/node/v24…e_modules/@openai/codexlatest version probe     curl: (56) The requested URL returned error: 403

Connectivity✓ network      network-related environment looks readableproxy env vars present   HTTP_PROXY, HTTPS_PROXY, ALL_PROXY, NO_PROXY✓ websocket    connected (HTTP 101 Switching Protocols) · 15s timeoutmodel provider           openaiprovider name            OpenAIwire API                 responsessupports websockets      trueproxy env vars present   HTTP_PROXY, HTTPS_PROXY, ALL_PROXY, NO_PROXYconnect timeout          15000 msauth mode                chatgptendpoint                 wss://chatgpt.com/backend-api/DNS                      2 IPv4, 0 IPv6, first IPv4handshake result         HTTP 101 Switching Protocolsreasoning header         falsemodels etag present      trueserver model present     false✓ reachability active provider endpoints are reachable over HTTPreachability mode        ChatGPT authChatGPT base URL         https://chatgpt.com/backend-api/ reachable (HTTP 403)

Background Server○ app-server   not running (ephemeral mode)daemon state dir         ~/.codex/app-server-daemonsettings                 ~/.codex/app-server-daemon/settings.json (missing)pid file                 ~/.codex/app-server-daemon/app-server.pid (missing)update-loop pid file     ~/.codex/app-server-daem…/app-server-updater.pid (missing)control socket           ~/.codex/app-server-cont…app-server-control.sockstatus                   not runningmode                     ephemeral

─────────────────────────────────────────────────────────────15 ok · 1 idle · 2 notes · 2 warn · 0 fail degraded

--summary compact output   --all expand truncated lists--json redacted report

What issue are you seeing?

Codex CLI works for normal model responses, but crashes as soon as the agent attempts to invoke shell/tool execution.

A minimal prompt that does not use tools works:

codex exec \
--ignore-user-config \
--ignore-rules \
--ephemeral \
--cd "$HOME/Documents/Develop/github" \
--skip-git-repo-check \
--sandbox read-only \
'只输出 ok,不要调用任何工具,不要扫描文件。'

Output:

codex
ok
tokens used
2,653

However, a minimal prompt that asks Codex to invoke shell crashes:

codex exec \
--ignore-user-config \
--ignore-rules \
--ephemeral \
--cd "$HOME/Documents/Develop/github" \
--skip-git-repo-check \
--sandbox read-only \
'请调用 shell,只执行:pwd && find . -maxdepth 1 -type d | head -5。不要写文件,不要扫描更深目录。'

Output:

OpenAI Codex v0.141.0
--------
workdir: /Users/vincent/Documents/Develop/github
model: gpt-5.5
provider: openai
approval: never
sandbox: read-only
reasoning effort: none
reasoning summaries: none
session id: 019ee08e-e0a3-7000-872e-b500f6b94dc5
--------
user
请调用 shell,只执行:pwd && find . -maxdepth 1 -type d | head -5。不要写文件,不要扫描更深目录。
codex
我将只执行你指定的只读命令。
zsh: trace trap codex exec --ignore-user-config --ignore-rules --ephemeral --cd --sandbox

This also reproduces with a real task that asks Codex to scan build artifacts under a projects directory. Codex prints an initial assistant message, then crashes before returning any shell output.

What steps can reproduce the bug?

Steps to reproduce
Install Codex CLI v0.141.0 via npm on macOS x86_64.
Run:
codex exec \
--ignore-user-config \
--ignore-rules \
--ephemeral \
--cd "$HOME/Documents/Develop/github" \
--skip-git-repo-check \
--sandbox read-only \
'请调用 shell,只执行:pwd && find . -maxdepth 1 -type d | head -5。不要写文件,不要扫描更深目录。'
Observe that Codex crashes with:
zsh: trace trap
Expected behavior

Codex should execute the read-only shell command and print the output, for example:

/Users/vincent/Documents/Develop/github
.
./project-a
./project-b
...
Actual behavior

Codex starts normally, receives the prompt, and replies that it will execute the command. Then the process crashes with zsh: trace trap before any shell output is printed.

Environment
Codex CLI: 0.141.0
Install method: npm
Runtime path: ~/.nvm/versions/node/v24.11.0/lib/node_modules/@openai/codex/...
Node: v24.11.0
OS: macOS 26.3.1
Architecture: x86_64 / Intel Mac
Terminal: Apple Terminal 466
Shell: zsh
Model: gpt-5.5
Provider: openai
Auth mode: ChatGPT
Sandbox: read-only in minimal repro; also reproduced with workspace-write
Approval: never

codex doctor --all reports auth, websocket, git, terminal, and install as OK. It reports some warnings around rollout/session files and update probing, but the crash still reproduces with:

--ignore-user-config
--ignore-rules
--ephemeral
--sandbox read-only

So this does not appear to be caused by my user config, rules, MCP servers, or hooks.

Crash report details

The macOS .ips crash report shows:

Exception Type: EXC_BREAKPOINT
Signal: SIGTRAP
Termination: Trace/BPT trap: 5

Relevant crashed thread frames include V8 initialization / memory permission code:

v8::base::OS::SetPermissions(...)
v8::internal::CodeRange::InitReservation(...)
v8::internal::Isolate::Init(...)
v8::Isolate::New(...)
Additional notes

This seems specifically related to the shell/tool execution path:

Model-only prompt works.
Prompt requiring shell/tool execution crashes.
Reproduces even with --ignore-user-config, --ignore-rules, and --ephemeral.
Reproduces in read-only sandbox, before any shell command output is returned.

I can provide the full redacted codex doctor --all output and the macOS .ips crash report if useful.

What is the expected behavior?

_No response_

Additional information

_No response_

View original on GitHub ↗

This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗