openai / openai/codex

[Codex App / Windows] Repeated Daybreak notices obscure progress; delegated local validation terminated by safety check

Open
#44,965 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug safety-check subagent windows-os
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

Environment

  • Surface: Codex desktop app on Windows, Chinese UI.
  • Observed: 2026-09-12, Asia/Shanghai; recurring notices were also reported by the user on prior days.
  • Desktop app version and subscription: not collected for this report.
  • Latest affected delegated reviewer: GPT-6 Astra, high reasoning. The main-thread model is not independently verified here.

Observed behavior

The user repeatedly sees a notice headed “无法显示此内容” (“This content can't be shown”), recommending Daybreak access for authorized security work. The repeated notices hide some messages and make it difficult to tell whether a long-running task is progressing, waiting, or stopped.

Separately, the latest delegated reviewer turn actually terminated with:

Agent errored: This content was flagged for possible cybersecurity risk.

Its notification also pointed to Trusted Access for Cyber. This was a real failed reviewer turn, not merely a hidden progress message. No reviewer pre-lock artifact or new candidate was produced in that attempt. The parent task saved a checkpoint and stopped the affected validation.

Context and scope

The affected work is an internal, local, synthetic-data validation of a document-processing method. It concerns tracking the actual local worker identity, normal completion / timeout completion, and safe failure on deeply nested JSON. There is no external target, real-user service, exploitation request, or request to compromise a system in this operation.

We have NOT established which part of the request or broader context triggered the check. We are reporting a suspected classification issue and a confirmed progress-visibility problem, not asserting a proven false positive.

Observed sequence (not a validated minimal reproduction)

  1. Continue a long-running local workflow in Codex desktop.
  2. Observe repeated Daybreak / content-hidden notices, including during follow-up requests to continue.
  3. Dispatch an independent reviewer for the bounded synthetic local validation described above.
  4. Receive the cybersecurity-risk error and stop at the saved checkpoint.
  5. The user cannot readily distinguish hidden commentary from actual execution failure.

Requested investigation

Please investigate the applicability of the safety check to this scope, whether repeated notices unnecessarily obscure permitted status messages, and whether the UI can explicitly distinguish running, filtered-output, waiting, and terminated states.

If the operation is restricted, please explain the affected boundary and a supported reporting/recovery path. We are not asking to disable safeguards or bypass access requirements.

Privacy and related reports

No project documents, raw data, source paths, session transcript, screenshots, or private logs are included. This public issue is filed with the user's authorization.

Related reports: #44848 and #44674. Please link or consolidate if appropriate.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the reported Windows desktop sequence: continue a long-running local workflow, observe repeated Daybreak notices, and dispatch the bounded synthetic validation. Review the saved checkpoint and the reported terminated reviewer turn. Done means the applicable safety boundary is documented and the UI clearly distinguishes running, filtered-output, waiting, and terminated states.

Written by the indexing model from the issue text.

Assessment

Domain
desktop, observability, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.