codex - 💡(How to fix) Fix Full Access thread downgraded to on-request/workspace-write after interrupted manual context compaction on Windows Desktop

Official PRs (…)
ON THIS PAGE

Recommended Tools

×6

Utilities matched from this issue’s tags and category — try them while you read without losing context.

GitHub issue graph ai analysis

Paste a GitHub issue URL. We fetch that issue, discover linked issues from bodies/comments/timeline, collect linked pull requests, and produce a structured English report.

The report is written in English Markdown for sharing and archival.

Helpful · Quick feedback

Loading…

A Codex Desktop thread that was running with Full Access unexpectedly downgraded to approval_policy=on-request and sandbox_policy=workspace-write after an interrupted/manual context compaction. The UI/global state still indicated Full Access, but subsequent tool calls started requesting approval.

This looks related to:

  • #23958
  • #23875
  • #24300

However, this report adds a Windows Desktop + CLI 0.133.0 reproduction path involving interruption/manual context compaction.

Error Message

{"line":2170,"timestamp":"2026-05-27T10:34:15.042Z","type":"response_item","payload":{"type":"function_call_output","call_id":"call_wZA7k66VAPpeNGEhjui2jKoP","output":"execution error: Io(Custom { kind: Other, error: "windows sandbox: runner error: CreateProcessAsUserW failed: 5" })"}} {"line":2172,"timestamp":"2026-05-27T10:34:15.799Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"<turn_aborted>\nThe user interrupted the previous turn on purpose. Any running unified exec processes may still be running in the background. If any tools/commands were aborted, they may have partially executed.\n</turn_aborted>"}]}} {"line":2173,"timestamp":"2026-05-27T10:34:15.813Z","type":"event_msg","payload":{"type":"turn_aborted","turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","reason":"interrupted","completed_at":1779878055,"duration_ms":1220791}} {"line":2175,"timestamp":"2026-05-27T10:34:54.177Z","type":"response_item","payload":{"type":"message","role":"developer","content":[{"type":"input_text","text":"<permissions instructions>\nFilesystem sandboxing defines which files can be read or written. sandbox_mode is danger-full-access: No filesystem sandboxing - all commands are permitted. Network access is enabled.\nApproval policy is currently never. Do not provide the sandbox_permissions for any reason, commands will be rejected.\r\n</permissions instructions>"}]}} {"line":2176,"timestamp":"2026-05-27T10:34:54.177Z","type":"turn_context","payload":{"turn_id":"019e6900-61b4-7dc2-91f3-ab97f888d383","cwd":"D:\code\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}} {"line":2177,"timestamp":"2026-05-27T10:34:54.189Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"继续,我注意到我明明给你完全访问权限,你还是一直在向我要权限,刚刚的最后一个申请我不小心按到ESC你就停住了,继续\n"}]}} {"line":2182,"timestamp":"2026-05-27T10:35:09.197Z","type":"response_item","payload":{"type":"function_call","name":"shell_command","arguments":"{"command":"Get-Content -LiteralPath 'D:\\code\\VTK_test\\translation_work\\sections_zh_llm\\09_advanced_computer_graphics.md' | Select-Object -Skip 54 -First 78","workdir":"D:\\code\\VTK_test","timeout_ms":10000}","call_id":"call_wqhVLzdFQXaPLn6jCUzqy3yB"}}

Root Cause

A Codex Desktop thread that was running with Full Access unexpectedly downgraded to approval_policy=on-request and sandbox_policy=workspace-write after an interrupted/manual context compaction. The UI/global state still indicated Full Access, but subsequent tool calls started requesting approval.

This looks related to:

  • #23958
  • #23875
  • #24300

However, this report adds a Windows Desktop + CLI 0.133.0 reproduction path involving interruption/manual context compaction.

Code Example

approval_policy=never
sandbox_policy=danger-full-access

---

approval_policy=on-request
sandbox_policy=workspace-write

---

"sandbox_permissions": "require_escalated"

---

rollout-2026-05-27T10-16-04-019e6737-b640-71a3-8c10-317141e73ec3.jsonl

Before compaction:
- line 5: approval_policy=never, sandbox=danger-full-access
- line 778/971/989/1547: still never + danger-full-access

After interruption/manual context compaction:
- line 1906: previous turn aborted/interrupted
- line 1909: compaction
- line 1911: context_compacted
- line 1912: regenerated permissions context
- line 1914: turn_context changed to approval_policy=on-request, sandbox_policy=workspace-write

---

sandbox_policy=workspace-write
approval_mode=on-request

---

{"line":1,"timestamp":"2026-05-27T02:17:02.397Z","type":"session_meta","payload":{"id":"019e6737-b640-71a3-8c10-317141e73ec3","timestamp":"2026-05-27T02:16:04.928Z","cwd":"D:\\code\\VTK_test","originator":"Codex Desktop","cli_version":"0.133.0","source":"vscode","thread_source":"user","model_provider":"openai","base_instructions":"[redacted]"}}
{"line":5,"timestamp":"2026-05-27T02:17:02.472Z","type":"turn_context","payload":{"turn_id":"dc85c18d-502a-4195-a466-e5f1eb21b2e5","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1547,"timestamp":"2026-05-27T09:16:49.846Z","type":"turn_context","payload":{"turn_id":"019e6875-c0b5-7a53-97af-ba21c2e85983","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1905,"timestamp":"2026-05-27T10:06:57.614Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"<turn_aborted>\\nThe user interrupted the previous turn on purpose. Any running unified exec processes may still be running in the background. If any tools/commands were aborted, they may have partially executed.\\n</turn_aborted>"}]}}
{"line":1906,"timestamp":"2026-05-27T10:06:57.629Z","type":"event_msg","payload":{"type":"turn_aborted","turn_id":"019e6875-c0b5-7a53-97af-ba21c2e85983","reason":"interrupted","completed_at":1779876417,"duration_ms":7409497}}
{"line":1907,"timestamp":"2026-05-27T10:07:02.833Z","type":"event_msg","payload":{"type":"task_started","turn_id":"019e68e6-e420-7920-b3e7-1afaaebf014d","started_at":1779876422,"model_context_window":258400,"collaboration_mode_kind":"default"}}
{"line":1908,"timestamp":"2026-05-27T10:13:55.022Z","type":"event_msg","payload":{"type":"task_started","turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","started_at":1779876835,"model_context_window":258400,"collaboration_mode_kind":"default"}}
{"line":1909,"timestamp":"2026-05-27T10:15:14.381Z","type":"compacted","payload":{"message":"","replacement_history":"[redacted long user/instruction history and encrypted_content]"}}
{"line":1911,"timestamp":"2026-05-27T10:15:14.408Z","type":"event_msg","payload":{"type":"context_compacted"}}
{"line":1912,"timestamp":"2026-05-27T10:15:14.489Z","type":"response_item","payload":{"type":"message","role":"developer","content":[{"type":"input_text","text":"<permissions instructions>\\nFilesystem sandboxing defines which files can be read or written. `sandbox_mode` is `workspace-write`: The sandbox permits reading files, and editing files in `cwd` and `writable_roots`. Editing files in other directories requires approval. Network access is restricted.\\n# Escalation Requests\\n[redacted rest of regenerated permissions/app context]"}]}}
{"line":1914,"timestamp":"2026-05-27T10:15:14.489Z","type":"turn_context","payload":{"turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"on-request","sandbox_policy":{"type":"workspace-write","writable_roots":["C:\\Users\\15972\\.codex\\memories"],"network_access":false,"exclude_tmpdir_env_var":false,"exclude_slash_tmp":false},"permission_profile":{"type":"managed","file_system":{"type":"restricted","entries":[{"path":{"type":"special","value":{"kind":"root"}},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test"},"access":"write"},{"path":{"type":"special","value":{"kind":"slash_tmp"}},"access":"write"},{"path":{"type":"special","value":{"kind":"tmpdir"}},"access":"write"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.git"},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.agents"},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.codex"},"access":"read"},{"path":{"type":"path","path":"C:\\Users\\15972\\.codex\\memories"},"access":"write"}]},"network":"restricted"},"file_system_sandbox_policy":{"kind":"restricted","entries":"[same restricted entries as permission_profile.file_system.entries]"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1928,"timestamp":"2026-05-27T10:15:38.326Z","type":"response_item","payload":{"type":"function_call","name":"shell_command","arguments":"{\"command\":\"Get-Content -LiteralPath 'C:\\\\Users\\\\15972\\\\.codex\\\\plugins\\\\cache\\\\openai-bundled\\\\browser\\\\26.519.81530\\\\skills\\\\browser\\\\SKILL.md' -TotalCount 160\",\"workdir\":\"D:\\\\code\\\\VTK_test\",\"timeout_ms\":10000,\"sandbox_permissions\":\"require_escalated\",\"justification\":\"需要读取已安装 Browser 技能说明,以便按浏览器插件工作流验证本地 HTML 页面。\",\"prefix_rule\":[\"Get-Content\"]}","call_id":"call_Ftu2xTXneTp7NBx6zRvYY0C8"}}

---

{"line":2170,"timestamp":"2026-05-27T10:34:15.042Z","type":"response_item","payload":{"type":"function_call_output","call_id":"call_wZA7k66VAPpeNGEhjui2jKoP","output":"execution error: Io(Custom { kind: Other, error: \"windows sandbox: runner error: CreateProcessAsUserW failed: 5\" })"}}
{"line":2172,"timestamp":"2026-05-27T10:34:15.799Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"<turn_aborted>\\nThe user interrupted the previous turn on purpose. Any running unified exec processes may still be running in the background. If any tools/commands were aborted, they may have partially executed.\\n</turn_aborted>"}]}}
{"line":2173,"timestamp":"2026-05-27T10:34:15.813Z","type":"event_msg","payload":{"type":"turn_aborted","turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","reason":"interrupted","completed_at":1779878055,"duration_ms":1220791}}
{"line":2175,"timestamp":"2026-05-27T10:34:54.177Z","type":"response_item","payload":{"type":"message","role":"developer","content":[{"type":"input_text","text":"<permissions instructions>\\nFilesystem sandboxing defines which files can be read or written. `sandbox_mode` is `danger-full-access`: No filesystem sandboxing - all commands are permitted. Network access is enabled.\\nApproval policy is currently never. Do not provide the `sandbox_permissions` for any reason, commands will be rejected.\\r\\n</permissions instructions>"}]}}
{"line":2176,"timestamp":"2026-05-27T10:34:54.177Z","type":"turn_context","payload":{"turn_id":"019e6900-61b4-7dc2-91f3-ab97f888d383","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":2177,"timestamp":"2026-05-27T10:34:54.189Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"继续,我注意到我明明给你完全访问权限,你还是一直在向我要权限,刚刚的最后一个申请我不小心按到ESC你就停住了,继续\\n"}]}}
{"line":2182,"timestamp":"2026-05-27T10:35:09.197Z","type":"response_item","payload":{"type":"function_call","name":"shell_command","arguments":"{\"command\":\"Get-Content -LiteralPath 'D:\\\\code\\\\VTK_test\\\\translation_work\\\\sections_zh_llm\\\\09_advanced_computer_graphics.md' | Select-Object -Skip 54 -First 78\",\"workdir\":\"D:\\\\code\\\\VTK_test\",\"timeout_ms\":10000}","call_id":"call_wqhVLzdFQXaPLn6jCUzqy3yB"}}

---

approval_policy=never
sandbox_policy=danger-full-access

---

approval_policy=on-request
sandbox_policy=workspace-write
RAW_BUFFERClick to expand / collapse

What version of the Codex App are you using (From “About Codex” dialog)?

26.519.81530

What subscription do you have?

GPT Pro 20x

What platform is your computer?

No response

What issue are you seeing?

Summary

A Codex Desktop thread that was running with Full Access unexpectedly downgraded to approval_policy=on-request and sandbox_policy=workspace-write after an interrupted/manual context compaction. The UI/global state still indicated Full Access, but subsequent tool calls started requesting approval.

This looks related to:

  • #23958
  • #23875
  • #24300

However, this report adds a Windows Desktop + CLI 0.133.0 reproduction path involving interruption/manual context compaction.

Environment

  • Platform: Windows Desktop
  • Codex CLI version: 0.133.0
  • Thread/session id: 019e6737-b640-71a3-8c10-317141e73ec3
  • Original cwd: D:\code\VTK_test
  • Expected mode: Full Access
  • Expected permissions: approval_policy=never, sandbox_policy=danger-full-access

What happened

The session initially started correctly with Full Access:

approval_policy=never
sandbox_policy=danger-full-access

After the previous turn was interrupted and context was manually compacted, the regenerated turn context changed to:

approval_policy=on-request
sandbox_policy=workspace-write

After that point, shell calls started including:

"sandbox_permissions": "require_escalated"

So Codex began asking for approvals even though the thread/user expected Full Access.

Local evidence

Relevant local trace:

rollout-2026-05-27T10-16-04-019e6737-b640-71a3-8c10-317141e73ec3.jsonl

Before compaction:
- line 5: approval_policy=never, sandbox=danger-full-access
- line 778/971/989/1547: still never + danger-full-access

After interruption/manual context compaction:
- line 1906: previous turn aborted/interrupted
- line 1909: compaction
- line 1911: context_compacted
- line 1912: regenerated permissions context
- line 1914: turn_context changed to approval_policy=on-request, sandbox_policy=workspace-write

Persisted state also showed the affected thread stored as:

sandbox_policy=workspace-write
approval_mode=on-request

while global UI/full-access state still indicated Full Access.

Raw JSONL excerpt

This is a privacy-preserving excerpt from the local JSONL. Long instruction blocks, user task content, and encrypted compaction payloads are redacted, but the timestamps, event types, turn ids, permission fields, sandbox fields, cwd, and CLI version are unchanged.

{"line":1,"timestamp":"2026-05-27T02:17:02.397Z","type":"session_meta","payload":{"id":"019e6737-b640-71a3-8c10-317141e73ec3","timestamp":"2026-05-27T02:16:04.928Z","cwd":"D:\\code\\VTK_test","originator":"Codex Desktop","cli_version":"0.133.0","source":"vscode","thread_source":"user","model_provider":"openai","base_instructions":"[redacted]"}}
{"line":5,"timestamp":"2026-05-27T02:17:02.472Z","type":"turn_context","payload":{"turn_id":"dc85c18d-502a-4195-a466-e5f1eb21b2e5","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1547,"timestamp":"2026-05-27T09:16:49.846Z","type":"turn_context","payload":{"turn_id":"019e6875-c0b5-7a53-97af-ba21c2e85983","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1905,"timestamp":"2026-05-27T10:06:57.614Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"<turn_aborted>\\nThe user interrupted the previous turn on purpose. Any running unified exec processes may still be running in the background. If any tools/commands were aborted, they may have partially executed.\\n</turn_aborted>"}]}}
{"line":1906,"timestamp":"2026-05-27T10:06:57.629Z","type":"event_msg","payload":{"type":"turn_aborted","turn_id":"019e6875-c0b5-7a53-97af-ba21c2e85983","reason":"interrupted","completed_at":1779876417,"duration_ms":7409497}}
{"line":1907,"timestamp":"2026-05-27T10:07:02.833Z","type":"event_msg","payload":{"type":"task_started","turn_id":"019e68e6-e420-7920-b3e7-1afaaebf014d","started_at":1779876422,"model_context_window":258400,"collaboration_mode_kind":"default"}}
{"line":1908,"timestamp":"2026-05-27T10:13:55.022Z","type":"event_msg","payload":{"type":"task_started","turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","started_at":1779876835,"model_context_window":258400,"collaboration_mode_kind":"default"}}
{"line":1909,"timestamp":"2026-05-27T10:15:14.381Z","type":"compacted","payload":{"message":"","replacement_history":"[redacted long user/instruction history and encrypted_content]"}}
{"line":1911,"timestamp":"2026-05-27T10:15:14.408Z","type":"event_msg","payload":{"type":"context_compacted"}}
{"line":1912,"timestamp":"2026-05-27T10:15:14.489Z","type":"response_item","payload":{"type":"message","role":"developer","content":[{"type":"input_text","text":"<permissions instructions>\\nFilesystem sandboxing defines which files can be read or written. `sandbox_mode` is `workspace-write`: The sandbox permits reading files, and editing files in `cwd` and `writable_roots`. Editing files in other directories requires approval. Network access is restricted.\\n# Escalation Requests\\n[redacted rest of regenerated permissions/app context]"}]}}
{"line":1914,"timestamp":"2026-05-27T10:15:14.489Z","type":"turn_context","payload":{"turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"on-request","sandbox_policy":{"type":"workspace-write","writable_roots":["C:\\Users\\15972\\.codex\\memories"],"network_access":false,"exclude_tmpdir_env_var":false,"exclude_slash_tmp":false},"permission_profile":{"type":"managed","file_system":{"type":"restricted","entries":[{"path":{"type":"special","value":{"kind":"root"}},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test"},"access":"write"},{"path":{"type":"special","value":{"kind":"slash_tmp"}},"access":"write"},{"path":{"type":"special","value":{"kind":"tmpdir"}},"access":"write"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.git"},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.agents"},"access":"read"},{"path":{"type":"path","path":"D:\\code\\VTK_test\\.codex"},"access":"read"},{"path":{"type":"path","path":"C:\\Users\\15972\\.codex\\memories"},"access":"write"}]},"network":"restricted"},"file_system_sandbox_policy":{"kind":"restricted","entries":"[same restricted entries as permission_profile.file_system.entries]"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":1928,"timestamp":"2026-05-27T10:15:38.326Z","type":"response_item","payload":{"type":"function_call","name":"shell_command","arguments":"{\"command\":\"Get-Content -LiteralPath 'C:\\\\Users\\\\15972\\\\.codex\\\\plugins\\\\cache\\\\openai-bundled\\\\browser\\\\26.519.81530\\\\skills\\\\browser\\\\SKILL.md' -TotalCount 160\",\"workdir\":\"D:\\\\code\\\\VTK_test\",\"timeout_ms\":10000,\"sandbox_permissions\":\"require_escalated\",\"justification\":\"需要读取已安装 Browser 技能说明,以便按浏览器插件工作流验证本地 HTML 页面。\",\"prefix_rule\":[\"Get-Content\"]}","call_id":"call_Ftu2xTXneTp7NBx6zRvYY0C8"}}

Additional observation: permission change only took effect after abort/new turn

During the affected turn, I attempted to recover by changing permissions in the UI back to the default profile and then back to Full Access. I do not see an explicit thread/settings or UI-permission-change event in this JSONL, so I cannot point to a raw settings record for that UI action.

What the JSONL does show:

  • From line 1914 to line 2173, the active turn remained approval_policy=on-request and sandbox_policy=workspace-write.
  • In that affected turn, 43 shell_command calls included "sandbox_permissions":"require_escalated".
  • Several commands failed through the Windows sandbox path with CreateProcessAsUserW failed: 5 / windows sandbox failed: spawn setup refresh.
  • After I interrupted the stuck approval/sandbox turn, the next turn started with regenerated Full Access permissions: approval_policy=never, sandbox_policy=danger-full-access, permission_profile=disabled.
  • After that restored turn context, subsequent tool calls no longer included sandbox_permissions.

This suggests the UI permission profile may not refresh the already-running turn context, while a new turn after abort/resume does pick up Full Access again.

{"line":2170,"timestamp":"2026-05-27T10:34:15.042Z","type":"response_item","payload":{"type":"function_call_output","call_id":"call_wZA7k66VAPpeNGEhjui2jKoP","output":"execution error: Io(Custom { kind: Other, error: \"windows sandbox: runner error: CreateProcessAsUserW failed: 5\" })"}}
{"line":2172,"timestamp":"2026-05-27T10:34:15.799Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"<turn_aborted>\\nThe user interrupted the previous turn on purpose. Any running unified exec processes may still be running in the background. If any tools/commands were aborted, they may have partially executed.\\n</turn_aborted>"}]}}
{"line":2173,"timestamp":"2026-05-27T10:34:15.813Z","type":"event_msg","payload":{"type":"turn_aborted","turn_id":"019e68ed-2ec2-79b0-9d91-5580fbd4b93f","reason":"interrupted","completed_at":1779878055,"duration_ms":1220791}}
{"line":2175,"timestamp":"2026-05-27T10:34:54.177Z","type":"response_item","payload":{"type":"message","role":"developer","content":[{"type":"input_text","text":"<permissions instructions>\\nFilesystem sandboxing defines which files can be read or written. `sandbox_mode` is `danger-full-access`: No filesystem sandboxing - all commands are permitted. Network access is enabled.\\nApproval policy is currently never. Do not provide the `sandbox_permissions` for any reason, commands will be rejected.\\r\\n</permissions instructions>"}]}}
{"line":2176,"timestamp":"2026-05-27T10:34:54.177Z","type":"turn_context","payload":{"turn_id":"019e6900-61b4-7dc2-91f3-ab97f888d383","cwd":"D:\\code\\VTK_test","current_date":"2026-05-27","timezone":"Asia/Shanghai","approval_policy":"never","sandbox_policy":{"type":"danger-full-access"},"permission_profile":{"type":"disabled"},"model":"gpt-5.5","personality":"friendly","collaboration_mode":"[redacted]","realtime_active":false,"effort":"xhigh","summary":"auto"}}
{"line":2177,"timestamp":"2026-05-27T10:34:54.189Z","type":"response_item","payload":{"type":"message","role":"user","content":[{"type":"input_text","text":"继续,我注意到我明明给你完全访问权限,你还是一直在向我要权限,刚刚的最后一个申请我不小心按到ESC你就停住了,继续\\n"}]}}
{"line":2182,"timestamp":"2026-05-27T10:35:09.197Z","type":"response_item","payload":{"type":"function_call","name":"shell_command","arguments":"{\"command\":\"Get-Content -LiteralPath 'D:\\\\code\\\\VTK_test\\\\translation_work\\\\sections_zh_llm\\\\09_advanced_computer_graphics.md' | Select-Object -Skip 54 -First 78\",\"workdir\":\"D:\\\\code\\\\VTK_test\",\"timeout_ms\":10000}","call_id":"call_wqhVLzdFQXaPLn6jCUzqy3yB"}}

Expected behavior

Context compaction/resume should preserve the effective thread permission profile. A thread running in Full Access should remain:

approval_policy=never
sandbox_policy=danger-full-access

unless the user explicitly changes permissions.

Actual behavior

After manual context compaction following an interruption, the thread silently changed to:

approval_policy=on-request
sandbox_policy=workspace-write

and started prompting for approvals.

Why this may not be a duplicate

This appears related to #23958 and #23875, but this case has a specific trigger and environment:

  • Windows Desktop
  • CLI 0.133.0
  • manual context compaction after an interrupted turn
  • Full Access UI/global state did not match the regenerated runtime permissions

Happy to provide more logs if useful.

What steps can reproduce the bug?

I do not have a minimal stable repro yet. The observed sequence in this session was:

  1. Start / continue a Codex Desktop thread in Full Access mode.
  2. The JSONL showed approval_policy=never and sandbox_policy=danger-full-access across multiple turns.
  3. Run a long task.
  4. Interrupt the turn after context compaction appeared to stall.
  5. Manually compact context / resume the thread.
  6. The regenerated turn_context changed to approval_policy=on-request and sandbox_policy=workspace-write.
  7. Subsequent shell calls started including sandbox_permissions=require_escalated and began prompting for approval.
  8. After aborting that affected turn and starting a new turn, the context returned to approval_policy=never and sandbox_policy=danger-full-access.

What is the expected behavior?

No response

Additional information

No response

Vote matrix · Quick signals

Works
Did the solution work? Tap to confirm.
Easy Fix
Was it a quick fix?
Time Saver
Did it save you time?
Blocking
Was it severely blocking?
Common Issue
Are others likely hitting this too?
Flaky / Intermittent
Is it intermittent?
Verified / Reproducible
Can you reproduce it reliably?
Loading…

FAQ

Expected behavior

Context compaction/resume should preserve the effective thread permission profile. A thread running in Full Access should remain:

approval_policy=never
sandbox_policy=danger-full-access

unless the user explicitly changes permissions.

Still need to ship something?

×6

Another batch ranked right after the header list — different links, same matching logic.

Back to top recommendations

TRENDING

codex - 💡(How to fix) Fix Full Access thread downgraded to on-request/workspace-write after interrupted manual context compaction on Windows Desktop