Environment
- Windows desktop app, local PowerShell execution.
- Installed app version: 26.1002.52244, build 13536, release channel prod.
- The configured updater reports
up_to_date.
- Task sandbox: workspace-write with auto_review.
- Observed on 2026-10-08. Windows edition/build and subscription are not included because they have not been collected for this report.
Failure
Both ordinary sandbox commands and supported browser control fail before the requested action starts:
Failed to create unified exec process:
helper_unknown_error: setup refresh had errors
trusted Node process exited unexpectedly; kernel reset
Even a trivial Get-Date -Format o fails before execution. Approved, narrowly scoped escalated filesystem diagnostics can still run. This is a tool-startup failure, not an approval-review rejection or a website login failure.
Reproduction on the affected installation
- Open the Windows desktop app and an existing local chat.
- Request a trivial sandboxed PowerShell command.
- Observe
helper_unknown_error: setup refresh had errors.
- Initialize the supported browser tool with
await cua.getState();.
- The tool exits without returning browser inventory.
- Run the supported JavaScript kernel reset and retry once; the same startup failure persists.
- Inspect the dated sandbox log.
A Windows reboot was verified at 13:42 KST. The failing helpers were created afterward, at 13:47 KST, so the reproduced failure is not simply a process left running before reboot.
Sanitized diagnostic evidence
The 2026-10-08 sandbox log reports runtime read/execute validation failing while opening runtime files for an ACL update, with Windows sharing violation os error 32.
Observed targets within
%LOCALAPPDATA%\OpenAI\Codex\runtimes\cua_node\3dd31cfff853001c\bin\:
node_repl.exe
node_modules\@oai\sky\bin\windows\swift\x64\VCRUNTIME140_1.dll
- subsequently
node.exe
Representative log times (UTC):
- 04:47:55:
node_repl.exe ACL validation sharing violation.
- 04:53:52:
VCRUNTIME140_1.dll ACL validation sharing violation.
- 04:59:07:
node.exe ACL validation sharing violation.
Read-only exact-path module enumeration identified codex-computer-use-swift.exe, parented by the desktop app's ChatGPT.exe, as loading the exact private DLL.
Recovery attempts and results
- App restart and full Windows reboot: not recovered.
- Supported browser-tool JavaScript reset: not recovered.
- Two failed current-chat
node_repl.exe helpers were matched by exact executable path, creation time, and ancestry to the same Codex parent as the current shell execution, then stopped. The next sandbox failure targeted the private DLL.
- With explicit user authorization, the identity-checked shared
codex-computer-use-swift.exe helper was stopped. The main app, open browsers, and unrelated worker processes were preserved.
- Newly created, failed current-chat helpers were also cleaned up. Browser initialization and the trivial sandbox command still failed.
- No ACLs, sandbox configuration, security settings, runtime binaries, or credentials were manually changed.
- The underlying vendor-level trigger and whether the update caused this are not established.
Expected behavior / impact
Sandbox setup and browser initialization should work while the application's own runtime helpers are present, or recover through a supported reset. Current behavior blocks browser-based work and normal shell execution even after reboot.
Please identify the first supported Windows desktop release with a fix, or provide a supported repair that preserves existing work and browser sessions.
Related reports
This appears to be an additional reproduction of #51906 and #51932, rather than a confirmed separate root cause. Happy for this report to be consolidated.
Only sanitized diagnostic excerpts are included; no full session transcript, business content, user-profile name, credentials, or secret files are attached.
Environment
up_to_date.Failure
Both ordinary sandbox commands and supported browser control fail before the requested action starts:
Even a trivial
Get-Date -Format ofails before execution. Approved, narrowly scoped escalated filesystem diagnostics can still run. This is a tool-startup failure, not an approval-review rejection or a website login failure.Reproduction on the affected installation
helper_unknown_error: setup refresh had errors.await cua.getState();.A Windows reboot was verified at 13:42 KST. The failing helpers were created afterward, at 13:47 KST, so the reproduced failure is not simply a process left running before reboot.
Sanitized diagnostic evidence
The 2026-10-08 sandbox log reports runtime read/execute validation failing while opening runtime files for an ACL update, with Windows sharing violation
os error 32.Observed targets within
%LOCALAPPDATA%\OpenAI\Codex\runtimes\cua_node\3dd31cfff853001c\bin\:node_repl.exenode_modules\@oai\sky\bin\windows\swift\x64\VCRUNTIME140_1.dllnode.exeRepresentative log times (UTC):
node_repl.exeACL validation sharing violation.VCRUNTIME140_1.dllACL validation sharing violation.node.exeACL validation sharing violation.Read-only exact-path module enumeration identified
codex-computer-use-swift.exe, parented by the desktop app'sChatGPT.exe, as loading the exact private DLL.Recovery attempts and results
node_repl.exehelpers were matched by exact executable path, creation time, and ancestry to the same Codex parent as the current shell execution, then stopped. The next sandbox failure targeted the private DLL.codex-computer-use-swift.exehelper was stopped. The main app, open browsers, and unrelated worker processes were preserved.Expected behavior / impact
Sandbox setup and browser initialization should work while the application's own runtime helpers are present, or recover through a supported reset. Current behavior blocks browser-based work and normal shell execution even after reboot.
Please identify the first supported Windows desktop release with a fix, or provide a supported repair that preserves existing work and browser sessions.
Related reports
This appears to be an additional reproduction of #51906 and #51932, rather than a confirmed separate root cause. Happy for this report to be consolidated.
Only sanitized diagnostic excerpts are included; no full session transcript, business content, user-profile name, credentials, or secret files are attached.