[Windows][Desktop 26.803.10989.0] cert-parent-death sentinel opens visible Terminal error 0x800700E8
Summary
On Windows, Codex Desktop local tool activity can launch an internal PowerShell parent-lifetime sentinel in a visible terminal window. The window reports:
error 2147942632 (0x800700E8)
The command shown by the window, sanitized to remove its random identifier, is:
powershell.exe -NoLogo -NoProfile -NonInteractive -Command <title-assignment>='cert-parent-death-<redacted-random-id>'; Start-Sleep -Seconds 300
The popup is intrusive and can accumulate across local tool activity.
Environment
- Windows
- Codex Desktop package version:
26.803.10989.0 - Windows-native local agent
- No user-specific paths, logs, network information, or identifiers are included in this report
Reproduction
- Fully exit Codex Desktop and ensure all Codex/ChatGPT processes have ended.
- Start Codex Desktop again.
- Run one harmless ordinary non-elevated, read-only shell canary:
``powershell``
Write-Output 'sandbox-canary-ok'
- Confirm the canary completes normally with exit code 0.
- Observe that a visible terminal window nevertheless appears with the
cert-parent-death-<random-id>/Start-Sleep -Seconds 300command and error0x800700E8.
Isolation evidence
- The issue reproduced after a genuinely clean process termination and restart.
- The ordinary sandbox canary completed successfully, so normal shell execution was healthy.
- The visible sentinel failure is therefore separable from shell-command success and from the Windows workspace-write
SetTokenInformation(TokenDefaultDacl) failed: 1344defect. - Switching the default Codex sandbox policy to stricter
read-onlyavoids the separate 1344 execution failure but does not prevent this sentinel popup. - No scheduled task, monitoring service, or unrelated local process was needed to reproduce it.
- No Windows security control was disabled.
Expected behavior
Internal parent-lifetime sentinels should be launched without a user-visible console or terminal window. Their parent/pipe lifecycle should not produce an interactive Windows Terminal error page.
The Windows launcher should use an appropriate hidden/no-console creation path, or replace the PowerShell sentinel with a non-console/native mechanism.
Actual behavior
The sentinel is handed to the interactive terminal infrastructure. Its pipe closes with ERROR_NO_DATA / 0x800700E8, leaving a visible error window containing the internal command.
Related issues
- #26613 — visible PowerShell/console windows during Codex Desktop background polling; also reports that changing Windows Terminal delegation did not solve the flashes.
- #35827 — traces
ChatGPT.exe -> powershell.exe -> conhost.exeduring local tool activity.
This report appears to be a more specific variant involving the internal cert-parent-death sentinel and a five-minute sleep.
1 Comment
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action