Skip to content

Windows sandbox regression in Codex CLI 0.138.0: setup refresh fails with os error 740 / CreateProcessAsUserW failed: 2; 0.132.0 works #26158

Description

@BaseBlank

What version of Codex CLI is running?

Failing version: codex-cli 0.136.0 Working rollback version: codex-cli 0.132.0 I am currently staying on 0.132.0 because it restores Windows sandbox execution.

What subscription do you have?

ChatGPT PRO

Which model were you using?

gpt-5.5

What platform is your computer?

Windows 11 x64. Approximate environment: Windows 11 x64, version 25H2 / build 26200.x

What terminal emulator and version are you using (if applicable)?

PowerShell 7.6.2 No tmux/screen/zellij. Codex installed through npm global install.

Codex doctor report

Codex Doctor v0.136.0 · windows-x86_64

Environment:
  system: en
  runtime: npm
  install: consistent
  search: bundled rg.exe found
  git: git version 2.54.0.windows.1
  terminal: Windows Terminal
  state: databases healthy

Configuration:
  config: loaded
  auth: configured
  mcp: 1 server configured
  sandbox: restricted fs + restricted network · approval OnRequest

Updates:
  update configuration is locally consistent

Connectivity:
  network-related environment looks readable
  websocket: connected
  active provider endpoints are reachable over HTTP

Background Server:
  app-server not running (ephemeral mode)

Summary:
  16 ok · 1 idle · 1 notes · 1 warn · 0 fail · degraded

The only warning was:

threads: rollout scan was incomplete or found bad files

The doctor report did not show a failed installation, auth, network, or sandbox helper check.

I am not pasting the full raw JSON here because it contains local filesystem paths. I can provide a redacted JSON report if needed.

What issue are you seeing?

After upgrading Codex CLI to 0.136.0 on Windows, sandboxed command execution started failing before the requested command actually ran.

The original user-facing failure inside Codex TUI was:

execution error: Io(Custom { kind: Other, error: "windows sandbox: spawn setup refresh" })

This happened even for simple read-only commands, for example:

Get-Location
Get-Content -Raw -LiteralPath .gitignore
Get-Content -Raw -LiteralPath README.md
Get-ChildItem -Force | Select-Object Name
cmd /c type .gitignore

Codex was not able to read .gitignore or README.md. This was not a .gitignore or project-file issue, because even Get-Location failed before PowerShell started.

The sandbox log showed repeated setup-refresh failures like this, with local paths redacted:

[REDACTED_TIME codex.exe] setup refresh: spawning %APPDATA%\npm\node_modules@openai\codex\node_modules@openai\codex-win32-x64\vendor\x86_64-pc-windows-msvc\codex-resources\codex-windows-sandbox-setup.exe (cwd=<PROJECT_DIR>, payload_len=5296)

[REDACTED_TIME codex.exe] setup refresh: failed to spawn %APPDATA%\npm\node_modules@openai\codex\node_modules@openai\codex-win32-x64\vendor\x86_64-pc-windows-msvc\codex-resources\codex-windows-sandbox-setup.exe: The requested operation requires elevation. (os error 740)

On my localized Windows system, the message was:

(os error 740)

I then tested the sandbox directly outside the TUI.

With codex-cli 0.136.0:

$cmd = "$env:WINDIR\System32\cmd.exe"

codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK

Observed:

windows sandbox failed: runner error: CreateProcessAsUserW failed: 2

Then:

codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK

Observed:

windows sandbox failed: CreateProcessAsUserW failed: 2

So after some troubleshooting, both elevated and unelevated modes failed on 0.136.0.

Important: codex doctor --summary reported 0 fails, so the install/config/network/auth state appeared healthy from doctor’s perspective.

Rollback fixed it:

npm install -g @openai/[email protected]
codex --version

Output:

codex-cli 0.132.0

Then:

$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ROLLBACK_TEST_OK

Output:

CODEX_ROLLBACK_TEST_OK

This strongly suggests a Windows sandbox regression after 0.132.0, visible on my system with 0.136.0.

What steps can reproduce the bug?

On Windows 11 x64:

Install Codex CLI 0.136.0 globally through npm:
npm install -g @openai/[email protected]
codex --version

Expected version output:

codex-cli 0.136.0
Use this relevant config:
approval_policy = "on-request"
sandbox_mode = "workspace-write"
approvals_reviewer = "user"

[sandbox_workspace_write]
network_access = false

[windows]
sandbox = "elevated"
Start Codex normally:
codex --sandbox workspace-write --ask-for-approval untrusted
Ask Codex to read simple local files:
Read .gitignore and README.md. Do not modify files. Report whether both reads succeeded.

Observed inside Codex:

execution error: Io(Custom { kind: Other, error: "windows sandbox: spawn setup refresh" })
Reproduce outside the TUI with a minimal command:
$cmd = "$env:WINDIR\System32\cmd.exe"

codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK
codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK

Observed on 0.136.0 after troubleshooting:

windows sandbox failed: runner error: CreateProcessAsUserW failed: 2
windows sandbox failed: CreateProcessAsUserW failed: 2

Earlier sandbox log entries also showed:

setup refresh: failed to spawn ...\codex-resources\codex-windows-sandbox-setup.exe: The requested operation requires elevation. (os error 740)
Roll back to 0.132.0:
npm install -g @openai/[email protected]
codex --version
Retest elevated sandbox:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ROLLBACK_TEST_OK

Observed:

CODEX_ROLLBACK_TEST_OK

What is the expected behavior?

Codex CLI 0.136.0 should be able to run basic sandboxed commands on Windows in the elevated sandbox, especially commands such as:

cmd /c echo CODEX_ELEVATED_OK
Get-Location
Get-Content -Raw -LiteralPath .gitignore
Get-Content -Raw -LiteralPath README.md

At minimum, if sandbox setup cannot proceed, Codex should report a clear actionable diagnostic explaining which Windows setup step, helper executable, permission, AppCompat/UAC setting, or sandbox runner path failed.

The expected output for this test should be:

CODEX_ELEVATED_OK

Additional information

Troubleshooting already attempted:

Restarted the computer completely.
shutdown /r /f /t 0

Result: did not fix the issue.

Confirmed codex doctor --summary did not show installation/config/auth/network failures.

Result: doctor summary had 0 fail, but sandbox execution still failed.

Tested direct sandbox command execution outside the TUI.
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK
codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK

Result on 0.136.0: failed.

Ran the official elevated sandbox setup command:
codex sandbox setup --elevated --current-user

A UAC prompt appeared for:

codex-windows-sandbox-setup.exe
Verified publisher: OpenAI OpCo, LLC

The command completed:

Windows elevated sandbox setup completed for at %USERPROFILE%.codex.

Result: did not fix sandbox execution on 0.136.0.

Tried the narrow AppCompat RUNASINVOKER workaround for codex-windows-sandbox-setup.exe.

Result: this appeared to move the failure past the original os error 740, but sandbox execution still failed later with:

runner error: CreateProcessAsUserW failed: 2

So RUNASINVOKER was not a complete fix.

Tested without the -- separator in the sandbox command.

Result: still failed.

Tested both sandbox modes.

Result:

elevated -> CreateProcessAsUserW failed: 2
unelevated -> CreateProcessAsUserW failed: 2
Tested:
windows.sandbox_private_desktop = false

via command-line config:

codex -c 'windows.sandbox="elevated"' -c 'windows.sandbox_private_desktop=false'
sandbox windows $cmd /c echo CODEX_ELEVATED_NO_PRIVATE_DESKTOP_OK

Result: still failed with CreateProcessAsUserW failed: 2.

Refreshed the runner cache by renaming:
%USERPROFILE%.codex.sandbox-bin

Result: still failed on 0.136.0.

Rolled back to 0.132.0.
npm install -g @openai/[email protected]

Result: fixed the elevated Windows sandbox test:

CODEX_ROLLBACK_TEST_OK

Related existing issues that look similar:

#24391
#24050
#24098
#22428

What seems new/useful in this report:

The failure is confirmed on codex-cli 0.136.0.
codex doctor --summary reported no major failures.
codex sandbox setup --elevated --current-user completed successfully but did not fix it.
RUNASINVOKER only changed the failure mode; it did not restore execution.
windows.sandbox_private_desktop=false did not fix it.
Refreshing .sandbox-bin did not fix it.
Downgrading to codex-cli 0.132.0 restored elevated sandbox execution immediately.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    CLIIssues related to the Codex CLIbugSomething isn't workingsandboxIssues related to permissions or sandboxingwindows-osIssues related to Codex on Windows systems

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions