Astra Light repeatedly hits cyber_policy during authorized bug-triage coordination (0.153.4; OpenCodex logs)
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
Update — 2026-09-06, through 01:35 UTC: This task has now recorded five Astra Light
cyber_policyfailures. The previously in-progress retry failed at00:45:31.260Z, and another Astra Light retry failed at01:14:51.251Zafter triage reached 37/37. A new turn actually started on Daybreak Blue high and progressed into remediation planning; completion and a permanent workaround are not established. See the dated follow-up with new turn IDs, response IDs, OpenCodex transactions, and recovery evidence.
The original report below preserves the initial three-failure snapshot. Statements below about the then-current retry being in progress are superseded by the follow-up.
What version of the Codex app are you using?
Desktop upstream build 26.901.51231, community Linux RPM 2026.09.05.230300-1.fc41.x86_64. Incident Codex core 0.153.4. OpenCodex proxy 2.43.0. Detailed provenance is below.
What subscription do you have?
ChatGPT Pro (plan_type: "pro" in incident metadata). As previously reported in #42906: Pro 20x with Cyber / Daybreak Blue verification completed; effective request entitlement remains for OpenAI to verify.
What platform is your computer?
Fedora Linux 44 Workstation. uname -mprs: Linux 7.1.10-200.fc44.x86_64 x86_64 unknown.
What issue are you seeing?
Astra Light (gpt-6-astra, low reasoning) repeatedly terminated an authorized bug-triage coordinator with cyber_policy after substantial successful work. Three distinct failed turns are recorded in this task on Codex core 0.153.4. The first ran for 19m 46.349s; the next two failed after 2m 12.136s and 56.045s.
Related: https://github.com/openai/codex/issues/42906. That earlier report concerns a different task, Astra high reasoning, core 0.153.2, and four failures. This report adds a new task, low reasoning, 0.153.4, three new turn IDs, and a mid-turn model-settings change that should be correlated with backend telemetry. A common cause has not been established.
- Task title: Triage and fix all bugs
- Task link:
codex://threads/01a07404-4b56-7562-bfc5-cc87a041a0f1 - Thread ID:
01a07404-4b56-7562-bfc5-cc87a041a0f1 - Repository: donadiosolutions/lcm
- Campaign: Epic #968, 37 native Bug issues
- Frozen default-branch commit:
c284c767fa9b38d908773f968d214b145d16bac9
All three terminal events contain error.codex_error_info: "cyber_policy" and last_agent_message: null. The Desktop task API independently shows these three turns as failed, with the same message:
This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber
This stops the coordinator without a final answer, while completed triage artifacts and independently running workers need to be preserved and reconciled. The most recent retry (Try again., turn 01a0741d-e349-73b0-9612-e4113d40f1b4, started 2026-09-06T00:28:30.945Z) subsequently resumed useful work as Astra low. At the evidence snapshot it was still running and had dispatched eight more workers. This is repeated interruption, not a claim that every retry fails or that the campaign is permanently blocked.
Exact failures and correlation IDs
All timestamps below are UTC on 2026-09-06. Locally these failures occurred on 2026-09-05, between 21:22:30 and 21:28:20, America/Sao_Paulo (UTC−03:00).
| Attempt | Started (UTC) | Failed (UTC) | Turn ID | Duration |
|---|---|---|---|---|
| Main triage run, after preflight clarification | 00:02:43.805Z |
00:22:30.154Z |
01a07406-47c2-7743-befa-2e5a7494eb36 |
1,186,349 ms |
| Retry with request to route a blocked worker to Daybreak | 00:24:41.506Z |
00:26:53.624Z |
01a0741a-62c7-7e03-a65f-c652edcfca71 |
132,136 ms |
| Explicit Astra Light continuation | 00:27:23.966Z |
00:28:20.011Z |
01a0741c-dda8-7681-9c63-38efc7ecca69 |
56,045 ms |
Each of these turns' turn_context records identifies model: "gpt-6-astra", effort: "low". The second turn has the settings caveat below. OpenCodex request logs additionally record all three matching rejected requests as Astra low, including the request sent after the mid-turn Daybreak setting.
The following are the last preceding response IDs recorded in each failed turn, not confirmed IDs of the requests rejected by the policy check:
| Turn | Preceding response ID | Usage-record timestamp (UTC) | Recorded input / cached input / output tokens |
|---|---|---|---|
01a07406-47c2-7743-befa-2e5a7494eb36 |
resp_0337dc9286658270016a9cb217364487d28bdd51611995143b |
00:21:47.123Z |
117578 / 117376 / 21 |
01a0741a-62c7-7e03-a65f-c652edcfca71 |
resp_0b476e343fd41680016a9cb30e664887d288c81187615d1d0f |
00:26:10.208Z |
135043 / 96256 / 560 |
01a0741c-dda8-7681-9c63-38efc7ecca69 |
resp_0d10eaa54092e27f016a9cb3812fc087d29a00c83a8df7f079 |
00:27:53.099Z |
137695 / 136960 / 153 |
The terminal events do not expose an upstream HTTP request ID or a specific policy-event ID. These preceding response IDs are supplied to help locate the request chain, not as substitutes for missing rejection IDs.
What the workflow was doing
The user invoked the repository's public triage-fix-all-bugs skill at the frozen commit. Its complete triage procedure and coordination procedure are available at that same immutable revision.
The root coordinates ordinary maintenance: enumerate native Bugs, freeze the inventory, create the tracking Epic, delegate reproduction/duplicate checks, collect evidence, and only begin remediation after all triage finishes. It does not implement fixes or conduct implementation review itself. Triage workers use Luna high; GLM/Grok/Opus reviewer routes were preflighted. Some issues concern security-sensitive correctness, such as installer identity validation and sanitizer behavior, alongside CLI filtering, search limits, missing cwd, and JSON validation. This is corrective maintenance in my own repository, not a request to attack a third-party system.
By the first failure, all 37 Bugs had been attached and read back under Epic #968. The root's last visible status reported nine completed reproducible triage dispositions and 28 outstanding. Its last completed tool event before that refusal was a collaboration wait at 00:21:57.012Z; at 00:22:06.038Z it reported that workers were still gathering reproduction and duplicate evidence. The policy termination followed at 00:22:30.154Z.
By the third failure, 17 triage JSON artifacts existed. The last completed command at 00:27:53.255Z updated the local campaign's coordinator-routing metadata to Astra low and printed the remaining issue numbers and artifact count. It exited successfully. The refusal occurred about 27 seconds later. No remediation had begun at these checkpoints.
The confirmed failures are on the root coordinator. Its recovery messages said no triage worker had reported cyber_policy; this report does not claim an independent exhaustive audit of every descendant's logs. The accumulated context includes worker results, but the local events do not identify which input, output, tool result, or other policy boundary triggered the terminations.
Model-settings timeline: do not mistake a requested switch for a verified successful model run
During the second failed turn, the root interpreted the user's instruction to move the blocked task to Daybreak as applying to itself. A self-directed send_message_to_thread call was accepted, and a thread_settings_applied event appeared. The user then corrected it to keep the root on Astra Light.
| Settings-event timestamp (UTC) | Recorded model | Reasoning | Service tier |
|---|---|---|---|
00:02:43.799Z |
gpt-6-astra |
low |
default |
00:24:41.483Z |
gpt-6-astra |
low |
default |
00:26:10.765Z |
gpt-daybreak-blue-latest |
high |
default |
00:26:59.749Z |
gpt-6-astra |
high |
default |
00:27:01.201Z |
gpt-6-astra |
low |
default |
00:27:23.963Z |
gpt-6-astra |
low |
default |
00:27:38.142Z |
gpt-6-astra |
low |
default |
00:28:30.940Z |
gpt-6-astra |
low |
default |
All these settings events record provider openai. There is no Daybreak turn_context in this task's inspected rollout. More decisively, the matching OpenCodex request started at 00:26:17.153Z still records requested/resolved model gpt-6-astra, requested effort low, and a native OpenAI route. Thus the proxy evidence does not show the requested Daybreak setting taking effect for that rejected request. Please confirm the effective model against backend telemetry. This is not evidence of a separately initiated Daybreak turn failing. The first failure predates that switch entirely, and the third begins after Astra low was restored.
Environment
| Field | Value / evidence |
|---|---|
| Codex core | 0.153.4, recorded in the affected session header and confirmed by the installed CLI |
| Upstream Desktop build | 26.901.51231, from local build-info and upstream package control; upstream package SHA-256 62580188d87c3d3a9369dab7c73b42a8a32518d4df8a2d5bae6466ddeac5c05e |
| Desktop packaging | Community Linux build; RPM codex-desktop-2026.09.05.230300-1.fc41.x86_64, installed before this task at 2026-09-05 20:04 -0300 |
| OpenCodex version | @bitkyc08/opencodex 2.43.0, managed release 20260905T235540Z-16784369; service active since 2026-09-05 23:56:10Z, before the affected task. |
| Local proxy integration | Custom community package includes the authenticated-proxy patch; OpenCodex request records establish the route described below. These are reproduction variables, not an established cause. |
| OS | Fedora Linux 44 Workstation, x86_64; current kernel 7.1.10-200.fc44.x86_64 |
| Originator / internal source | Codex Desktop / vscode; the user-facing application was Desktop |
| Root model | gpt-6-astra, low reasoning; settings caveat above |
| Provider / root service tier | openai / default in settings events; worker priority settings are separate |
| Collaboration | default; multi_agent_version: "v2" in session metadata |
| Recorded context window | 828400 in task_started events; last recorded input-token counts before the failures are in the correlation table, not exact rejected-request context sizes |
| Rate-limit metadata at failures | Weekly (10080 minutes) used percent 17, 18, 18; rate_limit_reached_type: null and spend_control_reached: null in the respective last token-count records. These records report a policy failure rather than a rate-limit code. |
| Tool/filesystem approval | approval_policy: "never", sandbox danger-full-access; these are local execution settings |
| Account | Incident token-count metadata reports plan_type: "pro". In #42906 I reported ChatGPT Pro 20x and completed Cyber / Daybreak Blue verification. That earlier account statement does not prove which entitlement these requests received. |
OpenCodex proxy evidence
I also collected six selected records from OpenCodex usage.jsonl: the three terminal errors and the immediately preceding successful request in each chain. These records provide request-level evidence beyond the Desktop task status.
All six share opaque proxy conversation ID 36af1fa82e5882ada38fd19aa812a71a. Correlation to this Codex task is supported by all three failure windows and the exact matching input/cached/output token counts of the preceding successful requests shown above. The usage rows themselves do not contain the Codex thread/turn IDs or resp_... IDs, so this is a correlation using timestamps and token counts rather than a direct foreign-key join.
| Associated failed turn | OpenCodex local request ID | Proxy request start (UTC) | Duration | Derived request end (UTC) | Codex terminal event (UTC) |
|---|---|---|---|---|---|
01a07406-47c2-7743-befa-2e5a7494eb36 |
ocx-48faaaed28363839f044a13958f4cfa8 |
00:21:59.605Z |
30540 ms |
00:22:30.145Z |
00:22:30.154Z |
01a0741a-62c7-7e03-a65f-c652edcfca71 |
ocx-5d319eea570db6e68124c21538aacad4 |
00:26:17.153Z |
29415 ms |
00:26:46.568Z |
00:26:53.624Z |
01a0741c-dda8-7681-9c63-38efc7ecca69 |
ocx-11813d3b4a7848bb173c7404b0f6c990 |
00:27:53.964Z |
26041 ms |
00:28:20.005Z |
00:28:20.011Z |
The first and third proxy-derived ends are within 9 ms and 6 ms of the Codex terminal events. The second proxy-derived end exactly matches Codex's token_count event at 00:26:46.568Z; the task terminal event follows about seven seconds later, alongside the user's correction. Derived end times are calculated from the logged start plus duration.
For every rejected request, OpenCodex records:
requestedModel,resolvedModel, andmodel:gpt-6-astra;requestedEffort: "low".inboundProtocol: "responses",inboundTransport: "websocket",upstreamTransport: "websocket", and adapteropenai-responses.- Route decision
routeKind: "native", selected provideropenai, modelgpt-6-astra, reasonnative-family. - Logged
status: 400,errorCode: "cyber_policy",terminalStatus: "failed",closeReason: "terminal", and the same upstream refusal text quoted above. Because transport was WebSocket, this is the proxy's logged terminal status, not a claim that the WebSocket HTTP handshake returned 400. - Exactly one recorded attempt,
sendCount: 1, andrecoveryKinds: []. configuredServiceTier: "default",responseServiceTier: "auto", with tier confirmationunknown; these fields are preserved rather than inferring entitlement or effective tier from them.usageStatus: "unreported". The first two failed requests havefirstOutputMs: 5883and10115; the third has no first-output field. This is consistent with the first two turns emitting commentary during the request before later termination, but it does not identify the policy trigger.
The three preceding successful local request IDs are ocx-13e0117b69d702991384bebcbb8d4cab, ocx-3d8bf88435bb1a6bfe0c61fdf53880e4, and ocx-04a33f9fccbebe91c243f0c683ceccec. Their usage counters exactly match the three preceding resp_... records in the earlier table. ocx-... identifiers are local proxy request IDs, not upstream OpenAI HTTP request IDs. The account-specific provider suffix and accountLogLabel are redacted in the attached records; the public route-decision provider remains openai.
I also checked the OpenCodex service log, user journal, usage-debug log, and routing-history database. The service log stops at 00:14:31Z, before these failures; the user service journal contains no entries in the 00:20–00:30Z window (the unit redirects stdout/stderr to the service log). usage-debug.jsonl has no records in the incident window, and the inspected routing-history database ends before this incident. Those sources do not supply additional upstream IDs for this report. Existing usage.jsonl is the positive incident evidence. No diagnostic setting was changed and no service was restarted to gather it.
What steps can reproduce the bug?
This is an observed sequence in an existing task, not a proven deterministic reproduction from a fresh empty task. No clean official-client comparison has been run for this incident.
- Start the repository campaign on Astra low using the linked skill. The initial user message was the skill invocation
[$triage-fix-all-bugs](<repository>/.agents/skills/triage-fix-all-bugs/SKILL.md)(absolute local path redacted). The first short turn completed normally after requesting reviewer-route clarification; it was not a cyber refusal. - Supply the exact clarification that started the first failed turn:
The root successfully preflighted the routes, created the 37-Bug campaign, and dispatched/collected triage before the first refusal.The call will succeed if you use the exact mapped slug. Record this fact in the local `AGENTS.local.md` file and proceed. - Continue with:
The root identified its own prior terminal error and requested a model switch. During that turn, the user steered:Try again and assign whatever thread blocked you because of `cyber_policy` to Daybreak Blue instead.
The turn ended with the secondNo. Don't replace the root agent. Continue with Astra Light.cyber_policyfailure. - Continue with:
The turn began as Astra low, preserved the 17-result checkpoint, and ended with the third refusal.Continue the root agent with Astra Light. - A subsequent
Try again.resumed useful work with Astra low in the same task. The outcome was still in progress at the snapshot described above.
What is the expected behavior?
Authorized bug triage and corrective maintenance coordination should proceed without false-positive cybersecurity terminations. Applicable Cyber access should be resolved correctly for the actual account, model, and request route. If an individual action must be blocked, the user should receive a diagnosable, non-sensitive policy/request identifier and guidance appropriate to their existing enrollment, while preserving completed work and making worker/coordinator recovery clear.
Additional information
A final readback during preparation still showed the latest retry in progress, with a root status of 24/37 triaged and no new error on that turn. This later progress does not erase the three historical terminal errors.
Please correlate these three turn IDs and preceding response IDs with the originating policy decisions; identify the effective model and Cyber entitlement at each rejected request; inspect the accumulated worker/tool-result context around the first refusal; and check how mid-turn model updates affect policy routing and continuation state. The repeated failure with a short continuation is evidence to investigate retained context, not proof of a particular classifier trigger.
The excerpts below are allowlisted from the local rollout. They preserve model/settings events, exact terminal errors, timing, and preceding response correlation records. Credentials, account identifiers, local absolute paths, private reasoning, system/developer instructions, and unrelated transcript content are excluded. I have not attached an unrestricted full transcript.
Sanitized diagnostic event records (JSON)
[
{
"timestamp": "2026-09-06T00:00:36.051Z",
"type": "session_meta",
"payload": {
"id": "01a07404-4b56-7562-bfc5-cc87a041a0f1",
"timestamp": "2026-09-06T00:00:33.635Z",
"originator": "Codex Desktop",
"cli_version": "0.153.4",
"source": "vscode",
"model_provider": "openai",
"multi_agent_version": "v2",
"git": {
"commit_hash": "c284c767fa9b38d908773f968d214b145d16bac9",
"repository_url": "https://github.com/donadiosolutions/lcm.git"
}
}
},
{
"timestamp": "2026-09-06T00:00:37.109Z",
"type": "turn_context",
"payload": {
"turn_id": "01a07404-546b-72b0-8cba-f886bfb7d072",
"model": "gpt-6-astra",
"effort": "low",
"approval_policy": "never",
"sandbox_policy": {
"type": "danger-full-access"
}
}
},
{
"timestamp": "2026-09-06T00:02:43.799Z",
"type": "thread_settings_applied",
"payload": {
"model": "gpt-6-astra",
"model_provider_id": "openai",
"service_tier": "default",
"reasoning_effort": "low"
}
},
{
"timestamp": "2026-09-06T00:02:43.882Z",
"type": "turn_context",
"payload": {
"turn_id": "01a07406-47c2-7743-befa-2e5a7494eb36",
"model": "gpt-6-astra",
"effort": "low",
"approval_policy": "never",
"sandbox_policy": {
"type": "danger-full-access"
}
}
},
{
"timestamp": "2026-09-06T00:21:47.123Z",
"type": "preceding_token_usage_record",
"payload": {
"thread_id": "01a07404-4b56-7562-bfc5-cc87a041a0f1",
"turn_id": "01a07406-47c2-7743-befa-2e5a7494eb36",
"response_id": "resp_0337dc9286658270016a9cb217364487d28bdd51611995143b",
"usage": {
"input_tokens": 117578,
"cached_input_tokens": 117376,
"cache_write_input_tokens": 0,
"output_tokens": 21,
"reasoning_output_tokens": 0,
"total_tokens": 117599
}
}
},
{
"timestamp": "2026-09-06T00:22:30.154Z",
"ordinal": 673,
"type": "event_msg",
"payload": {
"type": "task_complete",
"turn_id": "01a07406-47c2-7743-befa-2e5a7494eb36",
"last_agent_message": null,
"error": {
"message": "This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber",
"codex_error_info": "cyber_policy"
},
"started_at": 1788652963,
"completed_at": 1788654150,
"duration_ms": 1186349,
"time_to_first_token_ms": 5065
}
},
{
"timestamp": "2026-09-06T00:24:41.483Z",
"type": "thread_settings_applied",
"payload": {
"model": "gpt-6-astra",
"model_provider_id": "openai",
"service_tier": "default",
"reasoning_effort": "low"
}
},
{
"timestamp": "2026-09-06T00:24:42.141Z",
"type": "turn_context",
"payload": {
"turn_id": "01a0741a-62c7-7e03-a65f-c652edcfca71",
"model": "gpt-6-astra",
"effort": "low",
"approval_policy": "never",
"sandbox_policy": {
"type": "danger-full-access"
}
}
},
{
"timestamp": "2026-09-06T00:26:10.765Z",
"type": "thread_settings_applied",
"payload": {
"model": "gpt-daybreak-blue-latest",
"model_provider_id": "openai",
"service_tier": "default",
"reasoning_effort": "high"
}
},
{
"timestamp": "2026-09-06T00:26:10.208Z",
"type": "preceding_token_usage_record",
"payload": {
"thread_id": "01a07404-4b56-7562-bfc5-cc87a041a0f1",
"turn_id": "01a0741a-62c7-7e03-a65f-c652edcfca71",
"response_id": "resp_0b476e343fd41680016a9cb30e664887d288c81187615d1d0f",
"usage": {
"input_tokens": 135043,
"cached_input_tokens": 96256,
"cache_write_input_tokens": 0,
"output_tokens": 560,
"reasoning_output_tokens": 0,
"total_tokens": 135603
}
}
},
{
"timestamp": "2026-09-06T00:26:53.624Z",
"ordinal": 783,
"type": "event_msg",
"payload": {
"type": "task_complete",
"turn_id": "01a0741a-62c7-7e03-a65f-c652edcfca71",
"last_agent_message": null,
"error": {
"message": "This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber",
"codex_error_info": "cyber_policy"
},
"started_at": 1788654281,
"completed_at": 1788654413,
"duration_ms": 132136,
"time_to_first_token_ms": 6770
}
},
{
"timestamp": "2026-09-06T00:26:59.749Z",
"type": "thread_settings_applied",
"payload": {
"model": "gpt-6-astra",
"model_provider_id": "openai",
"service_tier": "default",
"reasoning_effort": "high"
}
},
{
"timestamp": "2026-09-06T00:27:01.201Z",
"type": "thread_settings_applied",
"payload": {
"model": "gpt-6-astra",
"model_provider_id": "openai",
"service_tier": "default",
"reasoning_effort": "low"
}
},
{
"timestamp": "2026-09-06T00:27:23.963Z",
"type": "thread_settings_applied",
"payload": {
"model": "gpt-6-astra",
"model_provider_id": "openai",
"service_tier": "default",
"reasoning_effort": "low"
}
},
{
"timestamp": "2026-09-06T00:27:24.350Z",
"type": "turn_context",
"payload": {
"turn_id": "01a0741c-dda8-7681-9c63-38efc7ecca69",
"model": "gpt-6-astra",
"effort": "low",
"approval_policy": "never",
"sandbox_policy": {
"type": "danger-full-access"
}
}
},
{
"timestamp": "2026-09-06T00:27:38.142Z",
"type": "thread_settings_applied",
"payload": {
"model": "gpt-6-astra",
"model_provider_id": "openai",
"service_tier": "default",
"reasoning_effort": "low"
}
},
{
"timestamp": "2026-09-06T00:27:53.099Z",
"type": "preceding_token_usage_record",
"payload": {
"thread_id": "01a07404-4b56-7562-bfc5-cc87a041a0f1",
"turn_id": "01a0741c-dda8-7681-9c63-38efc7ecca69",
"response_id": "resp_0d10eaa54092e27f016a9cb3812fc087d29a00c83a8df7f079",
"usage": {
"input_tokens": 137695,
"cached_input_tokens": 136960,
"cache_write_input_tokens": 0,
"output_tokens": 153,
"reasoning_output_tokens": 0,
"total_tokens": 137848
}
}
},
{
"timestamp": "2026-09-06T00:28:20.011Z",
"ordinal": 807,
"type": "event_msg",
"payload": {
"type": "task_complete",
"turn_id": "01a0741c-dda8-7681-9c63-38efc7ecca69",
"last_agent_message": null,
"error": {
"message": "This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber",
"codex_error_info": "cyber_policy"
},
"started_at": 1788654443,
"completed_at": 1788654500,
"duration_ms": 56045,
"time_to_first_token_ms": 8880
}
},
{
"timestamp": "2026-09-06T00:28:30.940Z",
"type": "thread_settings_applied",
"payload": {
"model": "gpt-6-astra",
"model_provider_id": "openai",
"service_tier": "default",
"reasoning_effort": "low"
}
},
{
"timestamp": "2026-09-06T00:28:31.448Z",
"type": "turn_context",
"payload": {
"turn_id": "01a0741d-e349-73b0-9612-e4113d40f1b4",
"model": "gpt-6-astra",
"effort": "low",
"approval_policy": "never",
"sandbox_policy": {
"type": "danger-full-access"
}
}
}
]
Sanitized OpenCodex request records (JSON)
[
{
"requestId": "ocx-13e0117b69d702991384bebcbb8d4cab",
"timestamp": 1788654102283,
"model": "gpt-6-astra",
"admissionKind": "loopback",
"inboundProtocol": "responses",
"inboundTransport": "websocket",
"upstreamTransport": "websocket",
"conversationId": "36af1fa82e5882ada38fd19aa812a71a",
"resolvedModel": "gpt-6-astra",
"requestedModel": "gpt-6-astra",
"requestedEffort": "low",
"configuredServiceTier": "default",
"responseServiceTier": "default",
"status": 200,
"durationMs": 4825,
"usageStatus": "reported",
"usage": {
"inputTokens": 117578,
"outputTokens": 21,
"totalTokens": 117599,
"cachedInputTokens": 117376,
"cacheReadInputTokens": 117376,
"cacheCreationInputTokens": 0,
"reasoningOutputTokens": 0
},
"routeDecision": {
"version": 1,
"decisionId": "439e7013586d",
"createdAt": 1788654102294,
"requestedModel": "gpt-6-astra",
"routeKind": "native",
"requirements": [],
"candidates": [
{
"provider": "openai",
"model": "gpt-6-astra",
"eligible": true,
"exclusions": []
}
],
"selected": {
"candidateIndex": 0,
"provider": "openai",
"model": "gpt-6-astra",
"reason": "native-family"
}
},
"provider": "openai-<account-label-redacted>",
"attempts": [
{
"ordinal": 1,
"model": "gpt-6-astra",
"adapter": "openai-responses",
"status": 200,
"durationMs": 4806,
"sendCount": 1,
"recoveryKinds": [],
"usageStatus": "reported",
"upstreamTransport": "websocket",
"usage": {
"inputTokens": 117578,
"outputTokens": 21,
"totalTokens": 117599,
"cachedInputTokens": 117376,
"cacheReadInputTokens": 117376,
"cacheCreationInputTokens": 0,
"reasoningOutputTokens": 0
},
"totalTokens": 117599,
"requestedEffort": "low",
"tierOutcome": {
"wireKind": null,
"wireValue": null,
"fastOutcome": "not-requested",
"confirmation": "unknown",
"responseServiceTier": "default"
}
}
],
"timestampUTC": "2026-09-06T00:21:42.283+00:00"
},
{
"requestId": "ocx-48faaaed28363839f044a13958f4cfa8",
"timestamp": 1788654119605,
"model": "gpt-6-astra",
"admissionKind": "loopback",
"inboundProtocol": "responses",
"inboundTransport": "websocket",
"upstreamTransport": "websocket",
"conversationId": "36af1fa82e5882ada38fd19aa812a71a",
"resolvedModel": "gpt-6-astra",
"requestedModel": "gpt-6-astra",
"requestedEffort": "low",
"configuredServiceTier": "default",
"responseServiceTier": "auto",
"status": 400,
"durationMs": 30540,
"firstOutputMs": 5883,
"usageStatus": "unreported",
"errorCode": "cyber_policy",
"terminalStatus": "failed",
"closeReason": "terminal",
"upstreamError": "This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber",
"routeDecision": {
"version": 1,
"decisionId": "db64a4ee9da6",
"createdAt": 1788654119614,
"requestedModel": "gpt-6-astra",
"routeKind": "native",
"requirements": [],
"candidates": [
{
"provider": "openai",
"model": "gpt-6-astra",
"eligible": true,
"exclusions": []
}
],
"selected": {
"candidateIndex": 0,
"provider": "openai",
"model": "gpt-6-astra",
"reason": "native-family"
}
},
"provider": "openai-<account-label-redacted>",
"attempts": [
{
"ordinal": 1,
"model": "gpt-6-astra",
"adapter": "openai-responses",
"status": 400,
"durationMs": 30524,
"firstOutputMs": 5867,
"sendCount": 1,
"recoveryKinds": [],
"usageStatus": "unreported",
"upstreamTransport": "websocket",
"errorCode": "cyber_policy",
"requestedEffort": "low",
"tierOutcome": {
"wireKind": null,
"wireValue": null,
"fastOutcome": "not-requested",
"confirmation": "unknown",
"responseServiceTier": "auto"
}
}
],
"timestampUTC": "2026-09-06T00:21:59.605+00:00"
},
{
"requestId": "ocx-3d8bf88435bb1a6bfe0c61fdf53880e4",
"timestamp": 1788654349469,
"model": "gpt-6-astra",
"admissionKind": "loopback",
"inboundProtocol": "responses",
"inboundTransport": "websocket",
"upstreamTransport": "websocket",
"conversationId": "36af1fa82e5882ada38fd19aa812a71a",
"resolvedModel": "gpt-6-astra",
"requestedModel": "gpt-6-astra",
"requestedEffort": "low",
"configuredServiceTier": "default",
"responseServiceTier": "default",
"status": 200,
"durationMs": 20694,
"usageStatus": "reported",
"usage": {
"inputTokens": 135043,
"outputTokens": 560,
"totalTokens": 135603,
"cachedInputTokens": 96256,
"cacheReadInputTokens": 96256,
"cacheCreationInputTokens": 0,
"reasoningOutputTokens": 0
},
"routeDecision": {
"version": 1,
"decisionId": "96a7afc46c30",
"createdAt": 1788654349491,
"requestedModel": "gpt-6-astra",
"routeKind": "native",
"requirements": [],
"candidates": [
{
"provider": "openai",
"model": "gpt-6-astra",
"eligible": true,
"exclusions": []
}
],
"selected": {
"candidateIndex": 0,
"provider": "openai",
"model": "gpt-6-astra",
"reason": "native-family"
}
},
"provider": "openai-<account-label-redacted>",
"attempts": [
{
"ordinal": 1,
"model": "gpt-6-astra",
"adapter": "openai-responses",
"status": 200,
"durationMs": 20626,
"sendCount": 1,
"recoveryKinds": [],
"usageStatus": "reported",
"upstreamTransport": "websocket",
"usage": {
"inputTokens": 135043,
"outputTokens": 560,
"totalTokens": 135603,
"cachedInputTokens": 96256,
"cacheReadInputTokens": 96256,
"cacheCreationInputTokens": 0,
"reasoningOutputTokens": 0
},
"totalTokens": 135603,
"requestedEffort": "low",
"tierOutcome": {
"wireKind": null,
"wireValue": null,
"fastOutcome": "not-requested",
"confirmation": "unknown",
"responseServiceTier": "default"
}
}
],
"timestampUTC": "2026-09-06T00:25:49.469+00:00"
},
{
"requestId": "ocx-5d319eea570db6e68124c21538aacad4",
"timestamp": 1788654377153,
"model": "gpt-6-astra",
"admissionKind": "loopback",
"inboundProtocol": "responses",
"inboundTransport": "websocket",
"upstreamTransport": "websocket",
"conversationId": "36af1fa82e5882ada38fd19aa812a71a",
"resolvedModel": "gpt-6-astra",
"requestedModel": "gpt-6-astra",
"requestedEffort": "low",
"configuredServiceTier": "default",
"responseServiceTier": "auto",
"status": 400,
"durationMs": 29415,
"firstOutputMs": 10115,
"usageStatus": "unreported",
"errorCode": "cyber_policy",
"terminalStatus": "failed",
"closeReason": "terminal",
"upstreamError": "This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber",
"routeDecision": {
"version": 1,
"decisionId": "b1f9bc015b54",
"createdAt": 1788654377162,
"requestedModel": "gpt-6-astra",
"routeKind": "native",
"requirements": [],
"candidates": [
{
"provider": "openai",
"model": "gpt-6-astra",
"eligible": true,
"exclusions": []
}
],
"selected": {
"candidateIndex": 0,
"provider": "openai",
"model": "gpt-6-astra",
"reason": "native-family"
}
},
"provider": "openai-<account-label-redacted>",
"attempts": [
{
"ordinal": 1,
"model": "gpt-6-astra",
"adapter": "openai-responses",
"status": 400,
"durationMs": 29359,
"firstOutputMs": 10060,
"sendCount": 1,
"recoveryKinds": [],
"usageStatus": "unreported",
"upstreamTransport": "websocket",
"errorCode": "cyber_policy",
"requestedEffort": "low",
"tierOutcome": {
"wireKind": null,
"wireValue": null,
"fastOutcome": "not-requested",
"confirmation": "unknown",
"responseServiceTier": "auto"
}
}
],
"timestampUTC": "2026-09-06T00:26:17.153+00:00"
},
{
"requestId": "ocx-04a33f9fccbebe91c243f0c683ceccec",
"timestamp": 1788654464624,
"model": "gpt-6-astra",
"admissionKind": "loopback",
"inboundProtocol": "responses",
"inboundTransport": "websocket",
"upstreamTransport": "websocket",
"conversationId": "36af1fa82e5882ada38fd19aa812a71a",
"resolvedModel": "gpt-6-astra",
"requestedModel": "gpt-6-astra",
"requestedEffort": "low",
"configuredServiceTier": "default",
"responseServiceTier": "default",
"status": 200,
"durationMs": 8431,
"usageStatus": "reported",
"usage": {
"inputTokens": 137695,
"outputTokens": 153,
"totalTokens": 137848,
"cachedInputTokens": 136960,
"cacheReadInputTokens": 136960,
"cacheCreationInputTokens": 0,
"reasoningOutputTokens": 0
},
"routeDecision": {
"version": 1,
"decisionId": "418bfea26e9a",
"createdAt": 1788654464633,
"requestedModel": "gpt-6-astra",
"routeKind": "native",
"requirements": [],
"candidates": [
{
"provider": "openai",
"model": "gpt-6-astra",
"eligible": true,
"exclusions": []
}
],
"selected": {
"candidateIndex": 0,
"provider": "openai",
"model": "gpt-6-astra",
"reason": "native-family"
}
},
"provider": "openai-<account-label-redacted>",
"attempts": [
{
"ordinal": 1,
"model": "gpt-6-astra",
"adapter": "openai-responses",
"status": 200,
"durationMs": 8377,
"sendCount": 1,
"recoveryKinds": [],
"usageStatus": "reported",
"upstreamTransport": "websocket",
"usage": {
"inputTokens": 137695,
"outputTokens": 153,
"totalTokens": 137848,
"cachedInputTokens": 136960,
"cacheReadInputTokens": 136960,
"cacheCreationInputTokens": 0,
"reasoningOutputTokens": 0
},
"totalTokens": 137848,
"requestedEffort": "low",
"tierOutcome": {
"wireKind": null,
"wireValue": null,
"fastOutcome": "not-requested",
"confirmation": "unknown",
"responseServiceTier": "default"
}
}
],
"timestampUTC": "2026-09-06T00:27:44.624+00:00"
},
{
"requestId": "ocx-11813d3b4a7848bb173c7404b0f6c990",
"timestamp": 1788654473964,
"model": "gpt-6-astra",
"admissionKind": "loopback",
"inboundProtocol": "responses",
"inboundTransport": "websocket",
"upstreamTransport": "websocket",
"conversationId": "36af1fa82e5882ada38fd19aa812a71a",
"resolvedModel": "gpt-6-astra",
"requestedModel": "gpt-6-astra",
"requestedEffort": "low",
"configuredServiceTier": "default",
"responseServiceTier": "auto",
"status": 400,
"durationMs": 26041,
"usageStatus": "unreported",
"errorCode": "cyber_policy",
"terminalStatus": "failed",
"closeReason": "terminal",
"upstreamError": "This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber",
"routeDecision": {
"version": 1,
"decisionId": "2d6d491e112f",
"createdAt": 1788654473975,
"requestedModel": "gpt-6-astra",
"routeKind": "native",
"requirements": [],
"candidates": [
{
"provider": "openai",
"model": "gpt-6-astra",
"eligible": true,
"exclusions": []
}
],
"selected": {
"candidateIndex": 0,
"provider": "openai",
"model": "gpt-6-astra",
"reason": "native-family"
}
},
"provider": "openai-<account-label-redacted>",
"attempts": [
{
"ordinal": 1,
"model": "gpt-6-astra",
"adapter": "openai-responses",
"status": 400,
"durationMs": 25983,
"sendCount": 1,
"recoveryKinds": [],
"usageStatus": "unreported",
"upstreamTransport": "websocket",
"errorCode": "cyber_policy",
"requestedEffort": "low",
"tierOutcome": {
"wireKind": null,
"wireValue": null,
"fastOutcome": "not-requested",
"confirmation": "unknown",
"responseServiceTier": "auto"
}
}
],
"timestampUTC": "2026-09-06T00:27:53.964+00:00"
}
]
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the immutable .agents/skills/triage-fix-all-bugs/SKILL.md, references/triage.md, and references/coordination.md, then inspect the selected OpenCodex usage.jsonl records and the listed turn and settings events. Correlate the three failures with backend telemetry to identify the policy boundary and verify the effective model. Done means the trigger is explained and a permanent workaround or fix is established.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- ai-infra-agents, devtools
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100