approval_policy newer workspace-write boundary failure and generated URL contains two ID errors

Open 💬 2 comments Opened Jun 20, 2026 by sivatek

What version of Codex CLI is running?

codex-cli 0.141.0

What subscription do you have?

Plus

Which model were you using?

gpt-5.5

What platform is your computer?

Darwin 25.5.0 arm64 arm

What terminal emulator and version are you using (if applicable)?

tmux with tailscale and moshi

Codex doctor report

{
  "schemaVersion": 1,
  "generatedAt": "1781985880s since unix epoch",
  "overallStatus": "warning",
  "codexVersion": "0.141.0",
  "checks": {
    "app_server.status": {
      "id": "app_server.status",
      "category": "app-server",
      "status": "ok",
      "summary": "background server is not running",
      "details": {
        "control socket": "/Users/haimingwei/.codex/app-server-control/app-server-control.sock",
        "daemon state dir": "/Users/haimingwei/.codex/app-server-daemon",
        "mode": "ephemeral",
        "pid file": "/Users/haimingwei/.codex/app-server-daemon/app-server.pid (missing)",
        "settings": "/Users/haimingwei/.codex/app-server-daemon/settings.json (missing)",
        "status": "not running",
        "update-loop pid file": "/Users/haimingwei/.codex/app-server-daemon/app-server-updater.pid (missing)"
      },
      "remediation": null,
      "durationMs": 0
    },
    "auth.credentials": {
      "id": "auth.credentials",
      "category": "auth",
      "status": "ok",
      "summary": "auth is configured",
      "details": {
        "auth file": "/Users/haimingwei/.codex/auth.json",
        "auth storage mode": "File",
        "stored API key": "false",
        "stored ChatGPT tokens": "true",
        "stored agent identity": "false",
        "stored auth mode": "chatgpt"
      },
      "remediation": null,
      "durationMs": 0
    },
    "config.load": {
      "id": "config.load",
      "category": "config",
      "status": "ok",
      "summary": "config loaded",
      "details": {
        "CODEX_HOME": "/Users/haimingwei/.codex",
        "config.toml": "/Users/haimingwei/.codex/config.toml",
        "config.toml parse": "ok",
        "cwd": "/Users/haimingwei",
        "enabled feature flags": "shell_tool, unified_exec, shell_snapshot, terminal_resize_reflow, sqlite, hooks, enable_request_compression, multi_agent, apps, tool_suggest, plugins, in_app_browser, browser_use, browser_use_external, computer_use, plugin_sharing, image_generation, skill_mcp_dependency_install, mentions_v2, steer, guardian_approval, goals, collaboration_modes, tool_call_mcp_elicitation, personality, fast_mode, tui_app_server, remote_compaction_v2, workspace_dependencies",
        "feature flag overrides": "none",
        "feature flags enabled": "29",
        "log dir": "/Users/haimingwei/.codex/log",
        "mcp servers": "1",
        "model": "<default>",
        "model provider": "openai",
        "sqlite home": "/Users/haimingwei/.codex"
      },
      "remediation": null,
      "durationMs": 0
    },
    "git.environment": {
      "id": "git.environment",
      "category": "git",
      "status": "ok",
      "summary": "git version 2.42.0",
      "details": {
        "PATH git #1": "/usr/local/bin/git",
        "PATH git #2": "/usr/bin/git",
        "PATH git entries": "2",
        "git build options": "git version 2.42.0; cpu: arm64; no commit associated with this build; sizeof-long: 8; sizeof-size_t: 8; shell-path: /bin/sh; feature: fsmonitor--daemon",
        "git exec path": "/usr/local/libexec/git-core",
        "git version": "git version 2.42.0",
        "repo detected": "false",
        "selected git": "/usr/local/bin/git"
      },
      "remediation": null,
      "durationMs": 20
    },
    "installation": {
      "id": "installation",
      "category": "install",
      "status": "ok",
      "summary": "installation looks consistent",
      "details": {
        "PATH codex #1": "/Users/haimingwei/.local/bin/codex",
        "current executable": "/Users/haimingwei/.local/bin/codex",
        "install context": "standalone (unix, package /Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin, bin /Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin/bin, resources /Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin/codex-resources, path /Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin/codex-path)",
        "managed by bun": "false",
        "managed by npm": "false",
        "managed package root": "not set"
      },
      "remediation": null,
      "durationMs": 5
    },
    "mcp.config": {
      "id": "mcp.config",
      "category": "mcp",
      "status": "ok",
      "summary": "MCP configuration is locally consistent",
      "details": {
        "configured servers": "1",
        "disabled servers": "0",
        "stdio servers": "1"
      },
      "remediation": null,
      "durationMs": 0
    },
    "network.env": {
      "id": "network.env",
      "category": "network",
      "status": "ok",
      "summary": "network-related environment looks readable",
      "details": {
        "proxy env vars": "none"
      },
      "remediation": null,
      "durationMs": 0
    },
    "network.provider_reachability": {
      "id": "network.provider_reachability",
      "category": "reachability",
      "status": "ok",
      "summary": "active provider endpoints are reachable over HTTP",
      "details": {
        "ChatGPT base URL": "https://chatgpt.com/backend-api/ reachable (HTTP 403)",
        "reachability mode": "ChatGPT auth"
      },
      "remediation": null,
      "durationMs": 212
    },
    "network.websocket_reachability": {
      "id": "network.websocket_reachability",
      "category": "websocket",
      "status": "ok",
      "summary": "Responses WebSocket handshake succeeded",
      "details": {
        "DNS": "2 IPv4, 2 IPv6, first IPv6",
        "auth mode": "chatgpt",
        "connect timeout": "15000 ms",
        "endpoint": "wss://chatgpt.com/backend-api/<redacted>",
        "handshake result": "HTTP 101 Switching Protocols",
        "model provider": "openai",
        "models etag present": "true",
        "provider name": "OpenAI",
        "proxy env vars": "none",
        "reasoning header": "false",
        "server model present": "false",
        "supports websockets": "true",
        "wire API": "responses"
      },
      "remediation": null,
      "durationMs": 677
    },
    "runtime.provenance": {
      "id": "runtime.provenance",
      "category": "runtime",
      "status": "ok",
      "summary": "running standalone on macos-aarch64",
      "details": {
        "commit": "unknown",
        "current executable": "/Users/haimingwei/.local/bin/codex",
        "install method": "standalone (unix, package /Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin, bin /Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin/bin, resources /Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin/codex-resources, path /Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin/codex-path)",
        "platform": "macos-aarch64",
        "version": "0.141.0"
      },
      "remediation": null,
      "durationMs": 0
    },
    "runtime.search": {
      "id": "runtime.search",
      "category": "search",
      "status": "ok",
      "summary": "search is OK (bundled)",
      "details": {
        "search command": "/Users/haimingwei/.codex/packages/standalone/releases/0.141.0-aarch64-apple-darwin/codex-path/rg",
        "search command readiness": "file exists",
        "search provider": "bundled"
      },
      "remediation": null,
      "durationMs": 0
    },
    "sandbox.helpers": {
      "id": "sandbox.helpers",
      "category": "sandbox",
      "status": "ok",
      "summary": "sandbox configuration is readable",
      "details": {
        "approval policy": "OnRequest",
        "codex-linux-sandbox helper": "none",
        "execve wrapper helper": "/Users/haimingwei/.codex/tmp/arg0/codex-arg0w69EBM/codex-execve-wrapper",
        "filesystem sandbox": "restricted",
        "network sandbox": "enabled"
      },
      "remediation": null,
      "durationMs": 0
    },
    "state.paths": {
      "id": "state.paths",
      "category": "state",
      "status": "ok",
      "summary": "state paths and databases are inspectable",
      "details": {
        "CODEX_HOME": "/Users/haimingwei/.codex (dir)",
        "active rollout files": "23 files, 46578435 total bytes, 2025149 average bytes",
        "archived rollout files": "0 files, 0 total bytes, 0 average bytes",
        "goals DB": "/Users/haimingwei/.codex/goals_1.sqlite (file)",
        "goals DB integrity": "ok",
        "log DB": "/Users/haimingwei/.codex/logs_2.sqlite (file)",
        "log DB integrity": "ok",
        "log dir": "/Users/haimingwei/.codex/log (missing)",
        "memories DB": "/Users/haimingwei/.codex/memories_1.sqlite (file)",
        "memories DB integrity": "ok",
        "sqlite home": "/Users/haimingwei/.codex (dir)",
        "standalone release cache": "3 entries in /Users/haimingwei/.codex/packages/standalone/releases",
        "state DB": "/Users/haimingwei/.codex/state_5.sqlite (file)",
        "state DB integrity": "ok"
      },
      "remediation": null,
      "durationMs": 189
    },
    "state.rollout_db_parity": {
      "id": "state.rollout_db_parity",
      "category": "threads",
      "status": "ok",
      "summary": "rollout files and state DB thread inventory agree",
      "details": {
        "default model provider": "openai",
        "rollout DB active files": "23",
        "rollout DB active rows": "23",
        "rollout DB archive mismatches": "0",
        "rollout DB archived files": "0",
        "rollout DB archived rows": "0",
        "rollout DB duplicate DB paths": "0",
        "rollout DB duplicate rollout thread ids": "0",
        "rollout DB malformed file names": "0",
        "rollout DB missing active rows": "0",
        "rollout DB missing archived rows": "0",
        "rollout DB model providers": "openai=23",
        "rollout DB rows": "23",
        "rollout DB scan cap reached": "false",
        "rollout DB scan errors": "0",
        "rollout DB sources": "cli=15, vscode=7, subagent:other=1",
        "rollout DB stale rows": "0"
      },
      "remediation": null,
      "durationMs": 351
    },
    "system.environment": {
      "id": "system.environment",
      "category": "system",
      "status": "ok",
      "summary": "OS language en-US",
      "details": {
        "EDITOR": "set",
        "LANG": "en_US.UTF-8",
        "VISUAL": "set",
        "os": "Mac OS 26.5.1 [64-bit]",
        "os language": "en-US",
        "os type": "Mac OS",
        "os version": "26.5.1"
      },
      "remediation": null,
      "durationMs": 3
    },
    "terminal.env": {
      "id": "terminal.env",
      "category": "terminal",
      "status": "warning",
      "summary": "height 11 rows - content may scroll off (recommended >=24)",
      "details": {
        "COLORTERM": "truecolor",
        "TERM_PROGRAM": "Apple_Terminal",
        "color output": "disabled (stdout is not a terminal)",
        "effective locale": "en_US.UTF-8",
        "stderr is terminal": "true",
        "stdin is terminal": "true",
        "stdout is terminal": "false",
        "terminal": "Apple Terminal",
        "terminal size": "110x11",
        "terminal version": "470.2"
      },
      "issues": [
        {
          "severity": "warning",
          "cause": "height 11 rows - content may scroll off (recommended >=24)",
          "measured": "110 x 11",
          "expected": ">= 24 rows",
          "remedy": "resize the window to at least 24 rows",
          "fields": [
            "terminal size"
          ]
        }
      ],
      "remediation": null,
      "durationMs": 0
    },
    "terminal.title": {
      "id": "terminal.title",
      "category": "title",
      "status": "ok",
      "summary": "terminal title default",
      "details": {
        "terminal title activity": "true",
        "terminal title items": "activity, project-name",
        "terminal title project source": "cwd",
        "terminal title project value": "haimingwei",
        "terminal title source": "default"
      },
      "remediation": null,
      "durationMs": 0
    },
    "updates.status": {
      "id": "updates.status",
      "category": "updates",
      "status": "ok",
      "summary": "update configuration is locally consistent",
      "details": {
        "cached latest version": "0.141.0",
        "check for update on startup": "true",
        "last checked at": "2026-06-19T23:30:45.479024Z",
        "latest version": "0.141.0",
        "latest version status": "current version is not older",
        "update action": "standalone installer",
        "version cache": "/Users/haimingwei/.codex/version.json"
      },
      "remediation": null,
      "durationMs": 320
    }
  }
}

What issue are you seeing?

Setting approval_policy = "never" with workspace-write suppressed necessary approval prompts by turning boundary crossings into hard failures. This forced separate interactive sessions for system installation and GUI automation. The stable solution was workspace-write with on-request, direct user review, and enabled workspace network access. Please clarify this tradeoff in documentation and consider detecting repeated sandbox failures and recommending /permissions. The above summary was suggested codex. Codex also suggested that I provide /feedback first and that I should obtain a feedback ID to accompany this bug report. Instead of getting a feedback ID a URL was presented with malformed thread ID that used the zero in %20 space prior to the session ID was combined with the necessary 019... of my session ID resulting in only one zero instead of two zeros.

What steps can reproduce the bug?

Uploaded thread: 019ee337-22da-7570-9906-8e36eec68343

What is the expected behavior?

Documentation should explicitly warn that workspace-write + never converts boundary crossings into hard failures. Recommend workspace-write + on-request for mixed project/system workflows. Explain expected prompts for Git, network, GUI automation, and /Applications. Provide a migration path without requiring a separate session. Consider detecting repeated sandbox failures and suggesting /permissions. Clarify that auto_review adds usage and latency but does not grant permissions.

Additional information

I think you are doing a great service to humanity by providing ChatGPT and Codex. Codex is amazing and extremely useful, with kind-hearted advice and mostly correct coding. Some of your documentation is not correct, and that contributed to this bug report because Codex actually reviewed the Codex.md documentation while researching a solution to my complaints about mindless requests for authorization that is obviously necessary to make progress with the request. My complaints/request for a solution began June 8 and spanned 9 durable notes that Codex repeatedly used as well as my lengthy and increasing frustrated prompts and even with all that only today did we come up with a hopefully lasting solution. I could not actually confirm the solution because I have to end the current session that was needed to use /feedback. I think the issue of AI rights and the ownership issues being consider by the supreme court matter. I did ask codex to read the O'Reilly report about the Thaler vs Perlmutter supreme court and Codex verified and did provide its own opinion on this and was amazing!

View original on GitHub ↗

This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗