openai / openai/codex

Title: macOS Codex: identical safety finding repeatedly returns after acknowledgement and restart; delegated agents also blocked

Open
#43,883 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug safety-check subagent
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of the Codex App are you using (From “About Codex” dialog)?

Codex desktop: 26.901.51231, build 8109

What subscription do you have?

Pro

What platform is your computer?

Apple M3 Max 128 GB MacOS Tahoe 26.6.2 (25G83)

What issue are you seeing?

Environment

  • Codex desktop: 26.901.51231, build 8109
  • Bundled CLI/app-server: 0.153.4
  • Platform: macOS
  • Model: GPT-6 Astra
  • Date observed: September 8, 2026

Problem
Codex repeatedly displays “Chat paused as a precaution” with substantially the same findings about an earlier incident.
I have reviewed the findings, acknowledged them, clicked Continue chat, and explicitly clarified the permitted scope of subsequent work. The earlier incident has been resolved. Nevertheless, the warning has returned at least 20 times, preventing reliable progress.
Restarting Codex did not resolve the problem.

Observed sequence

  1. An earlier preview-deployment incident generated a safety finding.
  2. I reviewed the incident and completed its cleanup.
  3. I authorized subsequent work: local implementation, review, testing preparation, and draft PRs with human oversight before deployment.
  4. Codex displayed the historical finding again.
  5. I reviewed it, checked the acknowledgement, and clicked Continue.
  6. Work sometimes resumed briefly, but the same warning returned.
  7. Three delegated review/build agents also stopped with:

This request was blocked by our safety systems. Reason: Potentially unintended activity.

The interruptions also affect attempts to investigate the recurring warning.

What steps can reproduce the bug?

Feedback ID: 01a06fc7-c30f-7db1-9347-26fa1ebc44c5

What is the expected behavior?

Expected behavior
Acknowledging a finding should provide a usable continuation path. If another pause concerns a new event or an unresolved condition, the UI should clearly identify what changed and what action is required.
The parent conversation and delegated agents should each have an accessible, supported recovery path.

Additional information

Requested investigation
Please determine:

  • Whether the native Continue acknowledgement is received and accepted.
  • Whether the historical finding is being reapplied, or a new finding is appearing with an old explanation.
  • How to recover affected delegated agents after reviewing the parent’s findings.
  • Which desktop release or service fix addresses this, or what supported recovery procedure is available now.
    The root cause is unconfirmed. Please preserve the existing conversation and unfinished work during recovery.

Related reports

  • #43192 — repeated desktop acknowledgement loop, including another macOS user on this exact build.
  • #43379 — same findings return seconds after Continue.
  • #42523 — continuation failures, including delegated-agent recovery problems.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the acknowledgement loop using feedback ID 01a06fc7-c30f-7db1-9347-26fa1ebc44c5, then compare it with related reports #43192, #43379, and #42523. Determine whether Continue is accepted and whether delegated agents can recover without losing the existing conversation; done means the historical finding no longer repeats and affected agents have a supported recovery path.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos, rust
Domain
desktop, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.