Windows SSH session: sandbox/unified exec runner times out on pipe-in, while local/RDP works
What version of Codex CLI is running?
0.142.4, 0.142.5
What subscription do you have?
ChatGPT Plus
Which model were you using?
gpt-5.4, gpt-5.5
What platform is your computer?
Microsoft Windows NT 10.0.26200.0 x64
What terminal emulator and version are you using (if applicable)?
Windows PowerShell over Windows OpenSSH Server, connected from another computer via SSH.
Codex doctor report
{
"schemaVersion": 1,
"generatedAt": "1782920910s since unix epoch",
"overallStatus": "ok",
"codexVersion": "0.142.5",
"checks": {
"app_server.status": {
"id": "app_server.status",
"category": "app-server",
"status": "ok",
"summary": "background server is not running",
"details": {
"control socket": "C:\\Users\\DELL\\.codex\\app-server-control\\app-server-control.sock",
"daemon state dir": "C:\\Users\\DELL\\.codex\\app-server-daemon",
"mode": "ephemeral",
"pid file": "C:\\Users\\DELL\\.codex\\app-server-daemon\\app-server.pid (missing)",
"settings": "C:\\Users\\DELL\\.codex\\app-server-daemon\\settings.json (missing)",
"status": "not running",
"update-loop pid file": "C:\\Users\\DELL\\.codex\\app-server-daemon\\app-server-updater.pid (missing)"
},
"remediation": null,
"durationMs": 0
},
"auth.credentials": {
"id": "auth.credentials",
"category": "auth",
"status": "ok",
"summary": "auth is configured",
"details": {
"auth file": "C:\\Users\\DELL\\.codex\\auth.json",
"auth storage mode": "File",
"stored API key": "false",
"stored ChatGPT tokens": "true",
"stored agent identity": "false",
"stored auth mode": "chatgpt"
},
"remediation": null,
"durationMs": 0
},
"config.load": {
"id": "config.load",
"category": "config",
"status": "ok",
"summary": "config loaded",
"details": {
"CODEX_HOME": "C:\\Users\\DELL\\.codex",
"config.toml": "C:\\Users\\DELL\\.codex\\config.toml",
"config.toml parse": "ok",
"cwd": "C:\\Users\\DELL",
"enabled feature flags": "<redacted>",
"feature flag overrides": "unified_exec=true, memories=true, prevent_idle_sleep=true",
"feature flags enabled": "36",
"log dir": "C:\\Users\\DELL\\.codex\\log",
"mcp servers": "0",
"model": "gpt-5.5",
"model provider": "openai",
"sqlite home": "C:\\Users\\DELL\\.codex"
},
"remediation": null,
"durationMs": 0
},
"git.environment": {
"id": "git.environment",
"category": "git",
"status": "ok",
"summary": "git version 2.53.0.windows.1",
"details": {
"PATH git #1": "D:\\SSoftware\\Git\\cmd\\git.exe",
"PATH git entries": "1",
"git build options": "git version 2.53.0.windows.1; cpu: x86_64; built from commit: a5512bdee37ed7142c233d21e2d347ffc4860ff3; sizeof-long: 4; sizeof-size_t: 8; shell-path: D:/git-sdk-64-build-installers/usr/bin/sh; rust: disabled; feature: fsmonitor--daemon; gettext: enabled; libcurl: 8.18.0; OpenSSL: OpenSSL 3.5.5 27 Jan 2026; zlib: 1.3.1; SHA-1: SHA1_DC; SHA-256: SHA256_BLK; default-ref-format: files; default-hash: sha1",
"git exec path": "D:/SSoftware/Git/mingw64/libexec/git-core",
"git version": "git version 2.53.0.windows.1",
"repo detected": "false",
"selected git": "D:\\SSoftware\\Git\\cmd\\git.exe"
},
"remediation": null,
"durationMs": 45
},
"installation": {
"id": "installation",
"category": "install",
"status": "ok",
"summary": "installation looks consistent",
"details": {
"PATH codex #1": "C:\\Users\\DELL\\AppData\\Roaming\\npm\\codex",
"PATH codex #2": "C:\\Users\\DELL\\AppData\\Roaming\\npm\\codex.cmd",
"PATH codex entries": "2",
"current executable": "C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\bin\\codex.exe",
"install context": "npm (package C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc, bin C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\bin, resources C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-resources, path C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-path)",
"managed by bun": "false",
"managed by npm": "true",
"managed package root": "C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex",
"npm update target": "C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex"
},
"remediation": null,
"durationMs": 190
},
"mcp.config": {
"id": "mcp.config",
"category": "mcp",
"status": "ok",
"summary": "no MCP servers configured",
"details": {},
"remediation": null,
"durationMs": 0
},
"network.env": {
"id": "network.env",
"category": "network",
"status": "ok",
"summary": "network-related environment looks readable",
"details": {
"proxy env vars": "none"
},
"remediation": null,
"durationMs": 0
},
"network.provider_reachability": {
"id": "network.provider_reachability",
"category": "reachability",
"status": "ok",
"summary": "active provider endpoints are reachable over HTTP",
"details": {
"ChatGPT base URL": "https://chatgpt.com/backend-api/ reachable (HTTP 403)",
"reachability mode": "ChatGPT auth"
},
"remediation": null,
"durationMs": 755
},
"network.websocket_reachability": {
"id": "network.websocket_reachability",
"category": "websocket",
"status": "ok",
"summary": "Responses WebSocket handshake succeeded",
"details": {
"DNS": "1 IPv4, 0 IPv6, first IPv4",
"auth mode": "chatgpt",
"connect timeout": "15000 ms",
"endpoint": "wss://chatgpt.com/backend-api/<redacted>",
"handshake result": "HTTP 101 Switching Protocols",
"model provider": "openai",
"models etag present": "true",
"provider name": "OpenAI",
"proxy env vars": "none",
"reasoning header": "false",
"server model present": "false",
"supports websockets": "true",
"wire API": "responses"
},
"remediation": null,
"durationMs": 979
},
"runtime.provenance": {
"id": "runtime.provenance",
"category": "runtime",
"status": "ok",
"summary": "running npm on windows-x86_64",
"details": {
"commit": "unknown",
"current executable": "C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\bin\\codex.exe",
"install method": "npm (package C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc, bin C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\bin, resources C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-resources, path C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-path)",
"platform": "windows-x86_64",
"version": "0.142.5"
},
"remediation": null,
"durationMs": 0
},
"runtime.search": {
"id": "runtime.search",
"category": "search",
"status": "ok",
"summary": "search is OK (bundled)",
"details": {
"search command": "C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-path\\rg.exe",
"search command readiness": "file exists",
"search provider": "bundled"
},
"remediation": null,
"durationMs": 0
},
"sandbox.helpers": {
"id": "sandbox.helpers",
"category": "sandbox",
"status": "ok",
"summary": "sandbox configuration is readable",
"details": {
"approval policy": "OnRequest",
"codex-linux-sandbox helper": "none",
"execve wrapper helper": "none",
"filesystem sandbox": "restricted",
"network sandbox": "enabled"
},
"remediation": null,
"durationMs": 0
},
"state.paths": {
"id": "state.paths",
"category": "state",
"status": "ok",
"summary": "state paths and databases are inspectable",
"details": {
"CODEX_HOME": "C:\\Users\\DELL\\.codex (dir)",
"active rollout files": "32 files, 19208976 total bytes, 600280 average bytes",
"archived rollout files": "0 files, 0 total bytes, 0 average bytes",
"goals DB": "C:\\Users\\DELL\\.codex\\goals_1.sqlite (file)",
"goals DB integrity": "ok",
"log DB": "C:\\Users\\DELL\\.codex\\logs_2.sqlite (file)",
"log DB integrity": "ok",
"log dir": "C:\\Users\\DELL\\.codex\\log (dir)",
"memories DB": "C:\\Users\\DELL\\.codex\\memories_1.sqlite (file)",
"memories DB integrity": "ok",
"sqlite home": "C:\\Users\\DELL\\.codex (dir)",
"state DB": "C:\\Users\\DELL\\.codex\\state_5.sqlite (file)",
"state DB integrity": "ok"
},
"remediation": null,
"durationMs": 259
},
"state.rollout_db_parity": {
"id": "state.rollout_db_parity",
"category": "threads",
"status": "ok",
"summary": "rollout files and state DB thread inventory agree",
"details": {
"default model provider": "openai",
"rollout DB active files": "32",
"rollout DB active rows": "32",
"rollout DB archive mismatches": "0",
"rollout DB archived files": "0",
"rollout DB archived rows": "0",
"rollout DB duplicate DB paths": "0",
"rollout DB duplicate rollout thread ids": "0",
"rollout DB malformed file names": "0",
"rollout DB missing active rows": "0",
"rollout DB missing archived rows": "0",
"rollout DB model providers": "openai=32",
"rollout DB rows": "32",
"rollout DB scan cap reached": "false",
"rollout DB scan errors": "0",
"rollout DB sources": "subagent:other=12, vscode=12, cli=6, subagent:memory_consolidation=2",
"rollout DB stale rows": "0"
},
"remediation": null,
"durationMs": 203
},
"system.environment": {
"id": "system.environment",
"category": "system",
"status": "ok",
"summary": "OS language zh-CN",
"details": {
"EDITOR": "not set",
"VISUAL": "not set",
"os": "Windows 10.0.26200 (Windows 11 Professional) [64-bit]",
"os language": "zh-CN",
"os type": "Windows",
"os version": "10.0.26200"
},
"remediation": null,
"durationMs": 0
},
"terminal.env": {
"id": "terminal.env",
"category": "terminal",
"status": "ok",
"summary": "terminal metadata was detected",
"details": {
"SSH_CLIENT": "present",
"SSH_CONNECTION": "present",
"SSH_TTY": "present",
"TERM": "xterm-256color",
"color output": "enabled",
"console input code page": "936",
"console output code page": "936",
"stderr console mode": "0x00000007 (VT processing: true)",
"stderr is terminal": "true",
"stdin is terminal": "true",
"stdout console mode": "0x00000007 (VT processing: true)",
"stdout is terminal": "true",
"terminal": "unknown",
"terminal size": "120x30"
},
"remediation": null,
"durationMs": 0
},
"terminal.title": {
"id": "terminal.title",
"category": "title",
"status": "ok",
"summary": "terminal title default",
"details": {
"terminal title activity": "true",
"terminal title items": "activity, project-name",
"terminal title project source": "cwd",
"terminal title project value": "DELL",
"terminal title source": "default"
},
"remediation": null,
"durationMs": 0
},
"updates.status": {
"id": "updates.status",
"category": "updates",
"status": "ok",
"summary": "update configuration is locally consistent",
"details": {
"cached latest version": "0.142.5",
"check for update on startup": "true",
"last checked at": "2026-07-01T11:59:05.776531900Z",
"latest version": "0.142.5",
"latest version status": "current version is not older",
"npm update target": "C:\\Users\\DELL\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex",
"update action": "npm install -g @openai/codex",
"version cache": "C:\\Users\\DELL\\.codex\\version.json"
},
"remediation": null,
"durationMs": 1709
}
}
}
What issue are you seeing?
When I run Codex CLI directly on the Windows machine, or through RDP, the sandbox/unified exec runner works normally. Minimal commands such as Get-Location and reading a small CSV file work.
However, when I SSH into the same Windows machine using Windows OpenSSH Server and start Codex CLI from that SSH session, even the minimal sandbox command Get-Location fails.
The error is:
Failed to create unified exec process: timed out after 15000ms connecting runner pipe-in
I also previously saw a similar error:
windows sandbox: timed out after 15000ms connecting runner pipe-in
This only happens in the SSH session. The same project, same working directory, same Codex CLI version, and same Windows user work correctly from local/RDP sessions.
I tried:
- rebooting the machine
- restarting Codex
- setting
$env:TERM = "xterm-256color"before starting Codex - running
codex doctor
After setting TERM=xterm-256color, codex doctor reports 0 failures, but Codex still cannot execute sandbox commands under SSH.
This looks like a Windows SSH session + Windows-native sandbox/unified exec runner issue rather than a project, disk, Git, or PowerShell problem.
What steps can reproduce the bug?
- On a Windows 11 Pro machine, install Codex CLI 0.142.5 via npm.
- Open the same project directory in three different ways:
- directly on the machine / local console
- through RDP
- through Windows OpenSSH Server from another computer
- In the local/RDP session, run:
cd <project path>
codex
- In Codex, run:
Get-Location
- Result: local/RDP session succeeds and prints the working directory.
- Now SSH into the same Windows machine from another computer:
ssh <user>@<host>
cd <project path>
$env:TERM = "xterm-256color"
codex doctor
codex
codex doctorreports 0 fail.
- In Codex under SSH, run:
Get-Location
- Result: sandbox/unified exec command fails with:
Failed to create unified exec process: timed out after 15000ms connecting runner pipe-in
or:
windows sandbox: timed out after 15000ms connecting runner pipe-in
The failure is reproducible under SSH but not under local/RDP sessions.
What is the expected behavior?
Codex CLI should be able to execute basic sandbox commands from a Windows SSH session, or it should clearly report that Windows-native sandbox/unified exec is unsupported in SSH sessions.
At minimum, a basic command such as Get-Location should either run successfully or fail with a more specific diagnostic message explaining why the sandbox runner cannot be created under SSH.
Additional information
The issue appears specific to the Windows SSH login context.
Observed comparison:
- Local console / RDP: works
- SSH session via Windows OpenSSH Server: fails
- Same machine, same user, same project path, same Codex version
codex doctorreports 0 fail after settingTERM=xterm-256colorSSH_TTY,SSH_CONNECTION, andSSH_CLIENTare present in the doctor output
I initially suspected the project path or disk, but local/RDP runs against the same project path work. The minimal command Get-Location fails under SSH, so the issue does not appear to depend on project files or command complexity.
I can provide a redacted codex doctor --json report and redacted sandbox log snippets if useful.
This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗