What version of the Codex App are you using (From “About Codex” dialog)?
OpenAI.Codex 26.803.5235.0 (Computer Use plugin 26.803.41515; bundled Codex CLI 0.147.0-alpha.6.5; @oai/sky 0.6.2)
What subscription do you have?
Unknown / not displayed in the Codex App
What platform is your computer?
Windows 11 Pro 25H2, build 26200.8973, x64; Codex installed as AppX/MSIX
What issue are you seeing?
The bundled Computer Use plugin cannot perform its first read-only operation on Windows. Importing @oai/sky succeeds, but await sky.list_windows() fails immediately with:
Error: spawn EPERM
at ChildProcess.spawn (node:internal/child_process:421:11)
at spawn (node:child_process:796:9)
at ...\@oai\sky\...\windows\internal\helper_transport.js
The helper path (PII redacted) is:
C:\Users\<user>\AppData\Local\OpenAI\Codex\runtimes\cua_node\f1bf3cd3a5929acd\bin\node_modules\@oai\sky\bin\windows\codex-computer-use.exe
Every Computer Use operation fails before connecting to the signed bundled helper because sandboxed Node child-process creation returns EPERM. Updating system Node.js does not affect this because Computer Use uses its bundled runtime.
What steps can reproduce the bug?
- Install/enable
computer-use@openai-bundled in the Windows Codex desktop app.
- Start a fresh task.
- Initialize the documented runtime:
if (!globalThis.sky) {
const { sky } = await import("@oai/sky");
globalThis.sky = sky;
}
- Run the first read-only operation:
await sky.list_windows();
- Observe
Error: spawn EPERM.
Reproduces after a full Windows restart, clean app reinstall, Computer Use plugin/runtime refresh, and Node kernel reset.
What is the expected behavior?
sky.list_windows() should launch or connect to the bundled signed helper and return the available Windows application windows. Computer Use should work using the permission settings exposed by the desktop app.
Additional information
Control tests:
- Bundled
cua_node is Node.js v24.14.0 and is signed by OpenAI.
- Outside the Codex sandbox, that exact bundled Node executable successfully spawns
cmd.exe and prints child-ok.
- Inside the Computer Use/Node sandbox, spawning
cmd.exe, Node itself, or codex-computer-use.exe returns EPERM.
- Updating system Node.js to v24.18.0 had no effect.
- No matching Microsoft Defender, AppLocker, or current Code Integrity block was found. Runtime executables have valid signatures and readable/executable ACLs.
The alternative elevated Windows sandbox also cannot initialize. The app displays “Windows setup didn't finish”. Setup creates sandbox users and WFP filters, then fails while adding a read ACE to the protected WindowsApps package directory:
grant read ACE failed ... for sandbox_group: SetNamedSecurityInfoW failed: 5
read ACL run completed with errors
setup error: read ACL run had errors
Returning to unelevated mode removes the setup banner but Computer Use still fails with spawn EPERM.
Related reports:
Please investigate the Windows sandbox child-process launch policy and the elevated sandbox setup's handling of protected WindowsApps ACLs.
What version of the Codex App are you using (From “About Codex” dialog)?
OpenAI.Codex 26.803.5235.0 (Computer Use plugin 26.803.41515; bundled Codex CLI 0.147.0-alpha.6.5; @oai/sky 0.6.2)
What subscription do you have?
Unknown / not displayed in the Codex App
What platform is your computer?
Windows 11 Pro 25H2, build 26200.8973, x64; Codex installed as AppX/MSIX
What issue are you seeing?
The bundled Computer Use plugin cannot perform its first read-only operation on Windows. Importing
@oai/skysucceeds, butawait sky.list_windows()fails immediately with:The helper path (PII redacted) is:
C:\Users\<user>\AppData\Local\OpenAI\Codex\runtimes\cua_node\f1bf3cd3a5929acd\bin\node_modules\@oai\sky\bin\windows\codex-computer-use.exeEvery Computer Use operation fails before connecting to the signed bundled helper because sandboxed Node child-process creation returns
EPERM. Updating system Node.js does not affect this because Computer Use uses its bundled runtime.What steps can reproduce the bug?
computer-use@openai-bundledin the Windows Codex desktop app.Error: spawn EPERM.Reproduces after a full Windows restart, clean app reinstall, Computer Use plugin/runtime refresh, and Node kernel reset.
What is the expected behavior?
sky.list_windows()should launch or connect to the bundled signed helper and return the available Windows application windows. Computer Use should work using the permission settings exposed by the desktop app.Additional information
Control tests:
cua_nodeis Node.js v24.14.0 and is signed by OpenAI.cmd.exeand printschild-ok.cmd.exe, Node itself, orcodex-computer-use.exereturnsEPERM.The alternative elevated Windows sandbox also cannot initialize. The app displays “Windows setup didn't finish”. Setup creates sandbox users and WFP filters, then fails while adding a read ACE to the protected WindowsApps package directory:
Returning to unelevated mode removes the setup banner but Computer Use still fails with
spawn EPERM.Related reports:
Please investigate the Windows sandbox child-process launch policy and the elevated sandbox setup's handling of protected WindowsApps ACLs.