openai / openai/codex

Windows desktop: request policy attribution for a pre-process diagnostic rejection

Open
#43,825 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug sandbox windows-os
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

Environment

  • Windows 11 ARM64 running in Parallels.
  • Codex desktop app; the previously recorded client version is 26.901.51231. It has not been freshly verified.

Existing rejection

A narrowly scoped, explicitly user-authorized diagnostic was rejected before process creation with blocked by policy.

The intended diagnostic was limited to compiling and loading a test interop DLL and importing a Filesystem module from a temporary mirror. It did not involve signing, Inno Setup, product installation, or permission changes.

The diagnostic did not start. It has not been retried as part of this reporting request. The specific enforcing component, matched rule, and configuration source are unknown; the error alone is not being attributed to PowerShell ExecutionPolicy or a particular Windows security control.

Requested clarification

Please help determine:

  1. Which component makes this rejection decision, and which implementation/version applies to the desktop app?
  2. Which rule was matched, and where does that rule or configuration originate?
  3. Is there a supported review channel for this specific operation, without broadly relaxing permissions or repeating the rejected command?
  4. If the existing event cannot be located from this summary, what is the minimum necessary event identifier, and how can it be provided without sharing session contents or raw logs?

This is a request to review an existing rejection, not a request for unrestricted access or re-execution.

Privacy boundary

No session records, raw logs, project source, DLLs, local paths, command arguments, environment contents, credentials, or attachments are included. Please specify the minimum necessary metadata before requesting additional diagnostic material.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or code entry points are identified in the issue. Start by identifying the desktop component responsible for the reported pre-process rejection and the relevant event or rule metadata; done means explaining the enforcing component, matched rule, configuration source, and minimum safe diagnostic identifier.

Written by the indexing model from the issue text.

Assessment

Domain
desktop, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.