What version of Codex CLI is running?
Failing version: codex-cli 0.136.0 Working rollback version: codex-cli 0.132.0 I am currently staying on 0.132.0 because it restores Windows sandbox execution.
What subscription do you have?
ChatGPT PRO
Which model were you using?
gpt-5.5
What platform is your computer?
Windows 11 x64. Approximate environment: Windows 11 x64, version 25H2 / build 26200.x
What terminal emulator and version are you using (if applicable)?
PowerShell 7.6.2 No tmux/screen/zellij. Codex installed through npm global install.
Codex doctor report
Codex Doctor v0.136.0 · windows-x86_64
Environment:
system: en
runtime: npm
install: consistent
search: bundled rg.exe found
git: git version 2.54.0.windows.1
terminal: Windows Terminal
state: databases healthy
Configuration:
config: loaded
auth: configured
mcp: 1 server configured
sandbox: restricted fs + restricted network · approval OnRequest
Updates:
update configuration is locally consistent
Connectivity:
network-related environment looks readable
websocket: connected
active provider endpoints are reachable over HTTP
Background Server:
app-server not running (ephemeral mode)
Summary:
16 ok · 1 idle · 1 notes · 1 warn · 0 fail · degraded
The only warning was:
threads: rollout scan was incomplete or found bad files
The doctor report did not show a failed installation, auth, network, or sandbox helper check.
I am not pasting the full raw JSON here because it contains local filesystem paths. I can provide a redacted JSON report if needed.
What issue are you seeing?
After upgrading Codex CLI to 0.136.0 on Windows, sandboxed command execution started failing before the requested command actually ran.
The original user-facing failure inside Codex TUI was:
execution error: Io(Custom { kind: Other, error: "windows sandbox: spawn setup refresh" })
This happened even for simple read-only commands, for example:
Get-Location
Get-Content -Raw -LiteralPath .gitignore
Get-Content -Raw -LiteralPath README.md
Get-ChildItem -Force | Select-Object Name
cmd /c type .gitignore
Codex was not able to read .gitignore or README.md. This was not a .gitignore or project-file issue, because even Get-Location failed before PowerShell started.
The sandbox log showed repeated setup-refresh failures like this, with local paths redacted:
[REDACTED_TIME codex.exe] setup refresh: spawning %APPDATA%\npm\node_modules@openai\codex\node_modules@openai\codex-win32-x64\vendor\x86_64-pc-windows-msvc\codex-resources\codex-windows-sandbox-setup.exe (cwd=<PROJECT_DIR>, payload_len=5296)
[REDACTED_TIME codex.exe] setup refresh: failed to spawn %APPDATA%\npm\node_modules@openai\codex\node_modules@openai\codex-win32-x64\vendor\x86_64-pc-windows-msvc\codex-resources\codex-windows-sandbox-setup.exe: The requested operation requires elevation. (os error 740)
On my localized Windows system, the message was:
(os error 740)
I then tested the sandbox directly outside the TUI.
With codex-cli 0.136.0:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK
Observed:
windows sandbox failed: runner error: CreateProcessAsUserW failed: 2
Then:
codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK
Observed:
windows sandbox failed: CreateProcessAsUserW failed: 2
So after some troubleshooting, both elevated and unelevated modes failed on 0.136.0.
Important: codex doctor --summary reported 0 fails, so the install/config/network/auth state appeared healthy from doctor’s perspective.
Rollback fixed it:
npm install -g @openai/[email protected]
codex --version
Output:
codex-cli 0.132.0
Then:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ROLLBACK_TEST_OK
Output:
CODEX_ROLLBACK_TEST_OK
This strongly suggests a Windows sandbox regression after 0.132.0, visible on my system with 0.136.0.
What steps can reproduce the bug?
On Windows 11 x64:
Install Codex CLI 0.136.0 globally through npm:
npm install -g @openai/[email protected]
codex --version
Expected version output:
codex-cli 0.136.0
Use this relevant config:
approval_policy = "on-request"
sandbox_mode = "workspace-write"
approvals_reviewer = "user"
[sandbox_workspace_write]
network_access = false
[windows]
sandbox = "elevated"
Start Codex normally:
codex --sandbox workspace-write --ask-for-approval untrusted
Ask Codex to read simple local files:
Read .gitignore and README.md. Do not modify files. Report whether both reads succeeded.
Observed inside Codex:
execution error: Io(Custom { kind: Other, error: "windows sandbox: spawn setup refresh" })
Reproduce outside the TUI with a minimal command:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK
codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK
Observed on 0.136.0 after troubleshooting:
windows sandbox failed: runner error: CreateProcessAsUserW failed: 2
windows sandbox failed: CreateProcessAsUserW failed: 2
Earlier sandbox log entries also showed:
setup refresh: failed to spawn ...\codex-resources\codex-windows-sandbox-setup.exe: The requested operation requires elevation. (os error 740)
Roll back to 0.132.0:
npm install -g @openai/[email protected]
codex --version
Retest elevated sandbox:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ROLLBACK_TEST_OK
Observed:
CODEX_ROLLBACK_TEST_OK
What is the expected behavior?
Codex CLI 0.136.0 should be able to run basic sandboxed commands on Windows in the elevated sandbox, especially commands such as:
cmd /c echo CODEX_ELEVATED_OK
Get-Location
Get-Content -Raw -LiteralPath .gitignore
Get-Content -Raw -LiteralPath README.md
At minimum, if sandbox setup cannot proceed, Codex should report a clear actionable diagnostic explaining which Windows setup step, helper executable, permission, AppCompat/UAC setting, or sandbox runner path failed.
The expected output for this test should be:
CODEX_ELEVATED_OK
Additional information
Troubleshooting already attempted:
Restarted the computer completely.
shutdown /r /f /t 0
Result: did not fix the issue.
Confirmed codex doctor --summary did not show installation/config/auth/network failures.
Result: doctor summary had 0 fail, but sandbox execution still failed.
Tested direct sandbox command execution outside the TUI.
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK
codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK
Result on 0.136.0: failed.
Ran the official elevated sandbox setup command:
codex sandbox setup --elevated --current-user
A UAC prompt appeared for:
codex-windows-sandbox-setup.exe
Verified publisher: OpenAI OpCo, LLC
The command completed:
Windows elevated sandbox setup completed for at %USERPROFILE%.codex.
Result: did not fix sandbox execution on 0.136.0.
Tried the narrow AppCompat RUNASINVOKER workaround for codex-windows-sandbox-setup.exe.
Result: this appeared to move the failure past the original os error 740, but sandbox execution still failed later with:
runner error: CreateProcessAsUserW failed: 2
So RUNASINVOKER was not a complete fix.
Tested without the -- separator in the sandbox command.
Result: still failed.
Tested both sandbox modes.
Result:
elevated -> CreateProcessAsUserW failed: 2
unelevated -> CreateProcessAsUserW failed: 2
Tested:
windows.sandbox_private_desktop = false
via command-line config:
codex -c 'windows.sandbox="elevated"' -c 'windows.sandbox_private_desktop=false'
sandbox windows $cmd /c echo CODEX_ELEVATED_NO_PRIVATE_DESKTOP_OK
Result: still failed with CreateProcessAsUserW failed: 2.
Refreshed the runner cache by renaming:
%USERPROFILE%.codex.sandbox-bin
Result: still failed on 0.136.0.
Rolled back to 0.132.0.
npm install -g @openai/[email protected]
Result: fixed the elevated Windows sandbox test:
CODEX_ROLLBACK_TEST_OK
Related existing issues that look similar:
#24391
#24050
#24098
#22428
What seems new/useful in this report:
The failure is confirmed on codex-cli 0.136.0.
codex doctor --summary reported no major failures.
codex sandbox setup --elevated --current-user completed successfully but did not fix it.
RUNASINVOKER only changed the failure mode; it did not restore execution.
windows.sandbox_private_desktop=false did not fix it.
Refreshing .sandbox-bin did not fix it.
Downgrading to codex-cli 0.132.0 restored elevated sandbox execution immediately.
What version of Codex CLI is running?
Failing version: codex-cli 0.136.0 Working rollback version: codex-cli 0.132.0 I am currently staying on 0.132.0 because it restores Windows sandbox execution.
What subscription do you have?
ChatGPT PRO
Which model were you using?
gpt-5.5
What platform is your computer?
Windows 11 x64. Approximate environment: Windows 11 x64, version 25H2 / build 26200.x
What terminal emulator and version are you using (if applicable)?
PowerShell 7.6.2 No tmux/screen/zellij. Codex installed through npm global install.
Codex doctor report
What issue are you seeing?
After upgrading Codex CLI to 0.136.0 on Windows, sandboxed command execution started failing before the requested command actually ran.
The original user-facing failure inside Codex TUI was:
execution error: Io(Custom { kind: Other, error: "windows sandbox: spawn setup refresh" })
This happened even for simple read-only commands, for example:
Get-Location
Get-Content -Raw -LiteralPath .gitignore
Get-Content -Raw -LiteralPath README.md
Get-ChildItem -Force | Select-Object Name
cmd /c type .gitignore
Codex was not able to read .gitignore or README.md. This was not a .gitignore or project-file issue, because even Get-Location failed before PowerShell started.
The sandbox log showed repeated setup-refresh failures like this, with local paths redacted:
[REDACTED_TIME codex.exe] setup refresh: spawning %APPDATA%\npm\node_modules@openai\codex\node_modules@openai\codex-win32-x64\vendor\x86_64-pc-windows-msvc\codex-resources\codex-windows-sandbox-setup.exe (cwd=<PROJECT_DIR>, payload_len=5296)
[REDACTED_TIME codex.exe] setup refresh: failed to spawn %APPDATA%\npm\node_modules@openai\codex\node_modules@openai\codex-win32-x64\vendor\x86_64-pc-windows-msvc\codex-resources\codex-windows-sandbox-setup.exe: The requested operation requires elevation. (os error 740)
On my localized Windows system, the message was:
(os error 740)
I then tested the sandbox directly outside the TUI.
With codex-cli 0.136.0:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK
Observed:
windows sandbox failed: runner error: CreateProcessAsUserW failed: 2
Then:
codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK
Observed:
windows sandbox failed: CreateProcessAsUserW failed: 2
So after some troubleshooting, both elevated and unelevated modes failed on 0.136.0.
Important: codex doctor --summary reported 0 fails, so the install/config/network/auth state appeared healthy from doctor’s perspective.
Rollback fixed it:
npm install -g @openai/[email protected]
codex --version
Output:
codex-cli 0.132.0
Then:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ROLLBACK_TEST_OK
Output:
CODEX_ROLLBACK_TEST_OK
This strongly suggests a Windows sandbox regression after 0.132.0, visible on my system with 0.136.0.
What steps can reproduce the bug?
On Windows 11 x64:
Install Codex CLI 0.136.0 globally through npm:
npm install -g @openai/[email protected]
codex --version
Expected version output:
codex-cli 0.136.0
Use this relevant config:
approval_policy = "on-request"
sandbox_mode = "workspace-write"
approvals_reviewer = "user"
[sandbox_workspace_write]
network_access = false
[windows]
sandbox = "elevated"
Start Codex normally:
codex --sandbox workspace-write --ask-for-approval untrusted
Ask Codex to read simple local files:
Read .gitignore and README.md. Do not modify files. Report whether both reads succeeded.
Observed inside Codex:
execution error: Io(Custom { kind: Other, error: "windows sandbox: spawn setup refresh" })
Reproduce outside the TUI with a minimal command:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK
codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK
Observed on 0.136.0 after troubleshooting:
windows sandbox failed: runner error: CreateProcessAsUserW failed: 2
windows sandbox failed: CreateProcessAsUserW failed: 2
Earlier sandbox log entries also showed:
setup refresh: failed to spawn ...\codex-resources\codex-windows-sandbox-setup.exe: The requested operation requires elevation. (os error 740)
Roll back to 0.132.0:
npm install -g @openai/[email protected]
codex --version
Retest elevated sandbox:
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ROLLBACK_TEST_OK
Observed:
CODEX_ROLLBACK_TEST_OK
What is the expected behavior?
Codex CLI 0.136.0 should be able to run basic sandboxed commands on Windows in the elevated sandbox, especially commands such as:
cmd /c echo CODEX_ELEVATED_OK
Get-Location
Get-Content -Raw -LiteralPath .gitignore
Get-Content -Raw -LiteralPath README.md
At minimum, if sandbox setup cannot proceed, Codex should report a clear actionable diagnostic explaining which Windows setup step, helper executable, permission, AppCompat/UAC setting, or sandbox runner path failed.
The expected output for this test should be:
CODEX_ELEVATED_OK
Additional information
Troubleshooting already attempted:
Restarted the computer completely.
shutdown /r /f /t 0
Result: did not fix the issue.
Confirmed codex doctor --summary did not show installation/config/auth/network failures.
Result: doctor summary had 0 fail, but sandbox execution still failed.
Tested direct sandbox command execution outside the TUI.
$cmd = "$env:WINDIR\System32\cmd.exe"
codex -c 'windows.sandbox="elevated"' sandbox windows $cmd /c echo CODEX_ELEVATED_OK
codex -c 'windows.sandbox="unelevated"' sandbox windows $cmd /c echo CODEX_UNELEVATED_OK
Result on 0.136.0: failed.
Ran the official elevated sandbox setup command:
codex sandbox setup --elevated --current-user
A UAC prompt appeared for:
codex-windows-sandbox-setup.exe
Verified publisher: OpenAI OpCo, LLC
The command completed:
Windows elevated sandbox setup completed for at %USERPROFILE%.codex.
Result: did not fix sandbox execution on 0.136.0.
Tried the narrow AppCompat RUNASINVOKER workaround for codex-windows-sandbox-setup.exe.
Result: this appeared to move the failure past the original os error 740, but sandbox execution still failed later with:
runner error: CreateProcessAsUserW failed: 2
So RUNASINVOKER was not a complete fix.
Tested without the -- separator in the sandbox command.
Result: still failed.
Tested both sandbox modes.
Result:
elevated -> CreateProcessAsUserW failed: 2
unelevated -> CreateProcessAsUserW failed: 2
Tested:
windows.sandbox_private_desktop = false
via command-line config:
codex -c 'windows.sandbox="elevated"'
-c 'windows.sandbox_private_desktop=false'sandbox windows $cmd /c echo CODEX_ELEVATED_NO_PRIVATE_DESKTOP_OK
Result: still failed with CreateProcessAsUserW failed: 2.
Refreshed the runner cache by renaming:
%USERPROFILE%.codex.sandbox-bin
Result: still failed on 0.136.0.
Rolled back to 0.132.0.
npm install -g @openai/[email protected]
Result: fixed the elevated Windows sandbox test:
CODEX_ROLLBACK_TEST_OK
Related existing issues that look similar:
#24391
#24050
#24098
#22428
What seems new/useful in this report:
The failure is confirmed on codex-cli 0.136.0.
codex doctor --summary reported no major failures.
codex sandbox setup --elevated --current-user completed successfully but did not fix it.
RUNASINVOKER only changed the failure mode; it did not restore execution.
windows.sandbox_private_desktop=false did not fix it.
Refreshing .sandbox-bin did not fix it.
Downgrading to codex-cli 0.132.0 restored elevated sandbox execution immediately.