Windows shell timeout/cancellation can orphan descendants; timeout appeared sensitive to a wall-clock step
What version of Codex CLI is running?
codex-cli 0.144.6
What subscription do you have?
Pro
Which model were you using?
gpt-5.6-sol ultra
What platform is your computer?
Microsoft Windows NT 10.0.26200.0 x64
What terminal emulator and version are you using (if applicable)?
Windows Terminal using PowerShell
Codex doctor report
{
"schemaVersion": 1,
"generatedAt": "1785013875s since unix epoch",
"overallStatus": "ok",
"codexVersion": "0.144.6",
"checks": {
"app_server.status": {
"id": "app_server.status",
"category": "app-server",
"status": "ok",
"summary": "background server is not running",
"details": {
"control socket": "C:\\Users\\Cuthiell\\.codex\\app-server-control\\app-server-control.sock",
"daemon state dir": "C:\\Users\\Cuthiell\\.codex\\app-server-daemon",
"mode": "ephemeral",
"pid file": "C:\\Users\\Cuthiell\\.codex\\app-server-daemon\\app-server.pid (missing)",
"settings": "C:\\Users\\Cuthiell\\.codex\\app-server-daemon\\settings.json (missing)",
"status": "not running",
"update-loop pid file": "C:\\Users\\Cuthiell\\.codex\\app-server-daemon\\app-server-updater.pid (missing)"
},
"remediation": null,
"durationMs": 0
},
"auth.credentials": {
"id": "auth.credentials",
"category": "auth",
"status": "ok",
"summary": "auth is configured",
"details": {
"auth file": "C:\\Users\\Cuthiell\\.codex\\auth.json",
"auth storage mode": "File",
"stored API key": "false",
"stored ChatGPT tokens": "true",
"stored agent identity": "false",
"stored auth mode": "chatgpt"
},
"remediation": null,
"durationMs": 0
},
"config.load": {
"id": "config.load",
"category": "config",
"status": "ok",
"summary": "config loaded",
"details": {
"CODEX_HOME": "C:\\Users\\Cuthiell\\.codex",
"config.toml": "C:\\Users\\Cuthiell\\.codex\\config.toml",
"config.toml parse": "ok",
"cwd": "C:\\Users\\Cuthiell",
"enabled feature flags": "<redacted>",
"feature flag overrides": "memories=true",
"feature flags enabled": "36",
"log dir": "C:\\Users\\Cuthiell\\.codex\\log",
"mcp servers": "1",
"model": "gpt-5.6-sol",
"model provider": "openai",
"sqlite home": "C:\\Users\\Cuthiell\\.codex"
},
"remediation": null,
"durationMs": 0
},
"git.environment": {
"id": "git.environment",
"category": "git",
"status": "ok",
"summary": "git version 2.54.0.windows.1",
"details": {
"PATH git #1": "C:\\Program Files\\Git\\bin\\git.exe",
"PATH git #2": "C:\\Program Files\\Git\\cmd\\git.exe",
"PATH git entries": "2",
"git build options": "git version 2.54.0.windows.1; cpu: x86_64; built from commit: 2b8a3ab140826ac423c2845ef81d4c6ac4f7bf3c; sizeof-long: 4; sizeof-size_t: 8; shell-path: D:/git-sdk-64-build-installers/usr/bin/sh; rust: disabled; feature: fsmonitor--daemon; gettext: enabled; libcurl: 8.19.0; OpenSSL: OpenSSL 3.5.6 7 Apr 2026; zlib: 1.3.2; SHA-1: SHA1_DC; SHA-256: SHA256_BLK; default-ref-format: files; default-hash: sha1",
"git exec path": "C:/Program Files/Git/mingw64/libexec/git-core",
"git version": "git version 2.54.0.windows.1",
"repo detected": "false",
"selected git": "C:\\Program Files\\Git\\bin\\git.exe"
},
"remediation": null,
"durationMs": 78
},
"installation": {
"id": "installation",
"category": "install",
"status": "ok",
"summary": "installation looks consistent",
"details": {
"PATH codex #1": "C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\codex",
"PATH codex #2": "C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\codex.cmd",
"PATH codex entries": "2",
"current executable": "C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\bin\\codex.exe",
"install context": "npm (package C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc, bin C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\bin, resources C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-resources, path C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-path)",
"managed by bun": "false",
"managed by npm": "true",
"managed by pnpm": "false",
"managed package root": "C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex",
"npm update target": "C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex"
},
"remediation": null,
"durationMs": 467
},
"mcp.config": {
"id": "mcp.config",
"category": "mcp",
"status": "ok",
"summary": "MCP configuration is locally consistent",
"details": {
"configured servers": "1",
"disabled servers": "0",
"streamable_http servers": "1"
},
"remediation": null,
"durationMs": 4058
},
"network.env": {
"id": "network.env",
"category": "network",
"status": "ok",
"summary": "network-related environment looks readable",
"details": {
"proxy env vars": "none"
},
"remediation": null,
"durationMs": 0
},
"network.provider_reachability": {
"id": "network.provider_reachability",
"category": "reachability",
"status": "ok",
"summary": "active provider endpoints are reachable over HTTP",
"details": {
"ChatGPT base URL": "https://chatgpt.com/backend-api/ reachable (HTTP 403)",
"reachability mode": "ChatGPT auth"
},
"remediation": null,
"durationMs": 1096
},
"network.websocket_reachability": {
"id": "network.websocket_reachability",
"category": "websocket",
"status": "ok",
"summary": "Responses WebSocket handshake succeeded",
"details": {
"DNS": "2 IPv4, 2 IPv6, first IPv6",
"auth mode": "chatgpt",
"connect timeout": "15000 ms",
"endpoint": "wss://chatgpt.com/backend-api/<redacted>",
"handshake result": "HTTP 101 Switching Protocols",
"model provider": "openai",
"models etag present": "true",
"provider name": "OpenAI",
"proxy env vars": "none",
"reasoning header": "false",
"server model present": "false",
"supports websockets": "true",
"wire API": "responses"
},
"remediation": null,
"durationMs": 1512
},
"runtime.provenance": {
"id": "runtime.provenance",
"category": "runtime",
"status": "ok",
"summary": "running npm on windows-x86_64",
"details": {
"commit": "unknown",
"current executable": "C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\bin\\codex.exe",
"install method": "npm (package C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc, bin C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\bin, resources C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-resources, path C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-path)",
"platform": "windows-x86_64",
"version": "0.144.6"
},
"remediation": null,
"durationMs": 0
},
"runtime.search": {
"id": "runtime.search",
"category": "search",
"status": "ok",
"summary": "search is OK (bundled)",
"details": {
"search command": "C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex\\node_modules\\@openai\\codex-win32-x64\\vendor\\x86_64-pc-windows-msvc\\codex-path\\rg.exe",
"search command readiness": "file exists",
"search provider": "bundled"
},
"remediation": null,
"durationMs": 0
},
"sandbox.helpers": {
"id": "sandbox.helpers",
"category": "sandbox",
"status": "ok",
"summary": "sandbox configuration is readable",
"details": {
"approval policy": "Never",
"codex-linux-sandbox helper": "none",
"execve wrapper helper": "none",
"filesystem sandbox": "unrestricted",
"network sandbox": "enabled"
},
"remediation": null,
"durationMs": 0
},
"state.paths": {
"id": "state.paths",
"category": "state",
"status": "ok",
"summary": "state paths and databases are inspectable",
"details": {
"CODEX_HOME": "C:\\Users\\Cuthiell\\.codex (dir)",
"active rollout files": "262 files, 1435912904 total bytes, 5480583 average bytes",
"archived rollout files": "0 files, 0 total bytes, 0 average bytes",
"goals DB": "C:\\Users\\Cuthiell\\.codex\\goals_1.sqlite (file)",
"goals DB integrity": "ok",
"log DB": "C:\\Users\\Cuthiell\\.codex\\logs_2.sqlite (file)",
"log DB integrity": "ok",
"log dir": "C:\\Users\\Cuthiell\\.codex\\log (dir)",
"memories DB": "C:\\Users\\Cuthiell\\.codex\\memories_1.sqlite (file)",
"memories DB integrity": "ok",
"sqlite home": "C:\\Users\\Cuthiell\\.codex (dir)",
"state DB": "C:\\Users\\Cuthiell\\.codex\\state_5.sqlite (file)",
"state DB integrity": "ok"
},
"remediation": null,
"durationMs": 1305
},
"state.rollout_db_parity": {
"id": "state.rollout_db_parity",
"category": "threads",
"status": "ok",
"summary": "rollout files and state DB thread inventory agree",
"details": {
"default model provider": "openai",
"rollout DB active files": "262",
"rollout DB active rows": "262",
"rollout DB archive mismatches": "0",
"rollout DB archived files": "0",
"rollout DB archived rows": "0",
"rollout DB duplicate DB paths": "0",
"rollout DB duplicate rollout thread ids": "0",
"rollout DB malformed file names": "0",
"rollout DB missing active rows": "0",
"rollout DB missing archived rows": "0",
"rollout DB model providers": "openai=262",
"rollout DB rows": "262",
"rollout DB scan cap reached": "false",
"rollout DB scan errors": "0",
"rollout DB sources": "subagent:thread_spawn=247, cli=15",
"rollout DB stale rows": "0"
},
"remediation": null,
"durationMs": 31084
},
"system.environment": {
"id": "system.environment",
"category": "system",
"status": "ok",
"summary": "OS language en-US",
"details": {
"EDITOR": "not set",
"VISUAL": "not set",
"os": "Windows 10.0.26200 (Windows 11 Professional) [64-bit]",
"os language": "en-US",
"os type": "Windows",
"os version": "10.0.26200"
},
"remediation": null,
"durationMs": 0
},
"terminal.env": {
"id": "terminal.env",
"category": "terminal",
"status": "ok",
"summary": "terminal metadata was detected",
"details": {
"WT_SESSION": "present",
"color output": "enabled",
"console input code page": "437",
"console output code page": "437",
"stderr console mode": "0x00000007 (VT processing: true)",
"stderr is terminal": "true",
"stdin is terminal": "true",
"stdout console mode": "0x00000007 (VT processing: true)",
"stdout is terminal": "true",
"terminal": "Windows Terminal",
"terminal size": "120x30"
},
"remediation": null,
"durationMs": 1
},
"terminal.title": {
"id": "terminal.title",
"category": "title",
"status": "ok",
"summary": "terminal title default",
"details": {
"terminal title activity": "true",
"terminal title items": "activity, project-name",
"terminal title project source": "cwd",
"terminal title project value": "Cuthiell",
"terminal title source": "default"
},
"remediation": null,
"durationMs": 0
},
"updates.status": {
"id": "updates.status",
"category": "updates",
"status": "ok",
"summary": "update configuration is locally consistent",
"details": {
"cached latest version": "0.144.6",
"check for update on startup": "true",
"last checked at": "2026-07-19T22:12:26.447037500Z",
"latest version": "0.145.0",
"latest version status": "newer version is available",
"npm update target": "C:\\Users\\Cuthiell\\AppData\\Roaming\\npm\\node_modules\\@openai\\codex",
"update action": "npm install -g @openai/codex",
"version cache": "C:\\Users\\Cuthiell\\.codex\\version.json"
},
"remediation": null,
"durationMs": 2418
}
}
}
What issue are you seeing?
Windows shell timeout/cancellation can orphan descendants; timeout appeared sensitive to a wall-clock step
Environment:
- Codex app shell path:
functions.exec->tools.shell_command - Windows NT
10.0.26200.0 - PowerShell
7.6.3 - Current installed CLI reports
codex-cli 0.144.6; please use the attached session logs as the authoritative build identity for the July 24-25 executions.
Observed behavior:
- On 2026-07-24, Windows time synchronization stepped the workstation clock forward by approximately 9h50m while a long-running test command was active. The shell tool returned exit 124 before the requested monotonic elapsed duration had passed. This appears consistent with wall-clock deadline accounting rather than a monotonic timeout.
- Independently, on 2026-07-25, stopping a running exec cell terminated its PowerShell wrapper but not its descendants.
TestWorkspace.CliPID 72412 and its guardian PID 58588 remained alive; the run continued and held build outputs. Stopping only PID 72412 later allowed the guardian to drain its owned Job.
Minimal cancellation repro:
$pidPath = Join-Path $env:TEMP 'codex-orphan-child.pid'
Remove-Item -LiteralPath $pidPath -ErrorAction SilentlyContinue
$child = Start-Process pwsh -PassThru -ArgumentList @(
'-NoProfile',
'-Command',
'Start-Sleep -Seconds 300'
)
$child.Id | Set-Content -LiteralPath $pidPath
$child.WaitForExit()
Run that through the shell tool with a long timeout, then stop the Codex tool call after the PID file appears. Check afterward:
$childPid = [int](Get-Content -LiteralPath (
Join-Path $env:TEMP 'codex-orphan-child.pid'))
Get-Process -Id $childPid
Expected: timeout, cancellation, or caller loss terminates the entire owned process tree and the tool returns only after bounded quiescence and output drain. Timeout duration should use a monotonic elapsed-time source.
Actual: the wrapper can terminate and return while descendants continue running. The clock-step incident also produced a premature timeout.
Requested behavior:
- Use a monotonic deadline for timeout accounting.
- Assign the command to a platform process group/Windows Job before its first instruction.
- On timeout, cancellation, or caller loss, terminate the entire owned tree and boundedly wait for zero remaining processes and drained pipes.
- Distinguish confirmed cleanup from unconfirmed cleanup in the terminal result; do not report an ordinary timeout if descendant cleanup is uncertain.
- If detached execution is intentional, expose it explicitly with a durable receipt and reattachment/termination contract rather than silently orphaning the process.
Local mitigation, not a Codex fix:
Our repository now routes authoritative long-running commands through a C# process run wrapper. On Windows it creates the target suspended inside an unnamed kill-on-close Job, gives an independent guardian exact Job/controller/caller-ancestry handles before resuming it, uses a relative timer and Stopwatch timestamps, and waits for Job quiescence on timeout, cancellation, controller death, or outer-caller loss. It reports 124/130 only after confirmed cleanup and 125 when cleanup cannot be confirmed. This protects only commands explicitly routed through this repository-specific wrapper; ordinary Codex shell calls remain exposed.
What steps can reproduce the bug?
Uploaded thread: 019f6d87-f13a-7492-9cd5-fcdc218ee012
What is the expected behavior?
See above
Additional information
_No response_
3 Comments
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action
I reviewed #35193 and #35070, as well as the earlier #33913 they reference. The surviving-descendant/process-tree portion of this report substantially overlaps #33913/#35193.
The separate observation here—a timeout firing early immediately after the Windows wall clock advanced by approximately 9h50m—does not appear to be covered there and points to deadline accounting that should use a monotonic elapsed-time source. I’m leaving this issue open for that distinct aspect; I’m happy to split the clock-step report into its own issue if maintainers prefer.
Independent Windows 10 reproduction with a severe system-wide consequence.
Environment
26.727.40816-win32-x64codex-command-runner-0.146.0-alpha.9.2.exeWhat happened
Several generic
node --test .../npm testcommands timed out or were interrupted during an IDE Codex session. Their parent command processes exited, but child Node test workers survived and were reparented. The workers continued running for roughly an hour until Windows exhausted system commit.Windows Resource-Exhaustion-Detector Event 2004 listed three orphaned
node.exeworkers at approximately 30.39 GB, 29.82 GB, and 29.68 GB of virtual size while commit was exhausted. Follow-on failures included:fatal: Out of memory, malloc failedVirtualAlloc ... errno=1455, then fatal OOM0xC000012Doom, code-536870904dwm.execrashes followed by a LiveKernelEvent 193 watchdog eventAfter reboot, the orphaned workers were gone and memory returned to normal.
The child workload did contain a runaway Windows filesystem-watch event loop, but that should have remained contained to the timed-out command. The Codex lifecycle failure was that descendants survived after the command parent and continued consuming resources outside the command/session boundary.
Expected containment
On timeout, cancellation, session termination, or command-runner exit, Codex should terminate the complete descendant process tree. A Windows Job Object with kill-on-close semantics would provide a hard lifecycle boundary even when the child workload is faulty.
No session transcript, repository identity, local paths, prompts, or source code are included in this report.