openai / openai/codex

Codex reliability, instruction-fidelity, and execution-control failures

Open
#45,878 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug CLI hooks model-behavior
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

Codex reliability, instruction-fidelity, and execution-control failures

Summary

The evidence package documents recurring reliability, instruction-fidelity, and execution-control failures across Codex sessions. The records establish recurring behavior classes; they do not prove intent or motive. The five documented groups are:

  1. P1 firmware safety failure and reported hardware damage.
  2. CKPi access and instruction-fidelity failure.
  3. Task-scoped adapter runtime integration boundary.
  4. KI-011 false charge and retraction.
  5. Native user-level adapter exercise.

Product area / environment

The evidence concerns the Codex runtime, local Stop-hook integration, instruction and context handling, CKPi access, and GE Lighting Upgrade firmware work. The records reference local Codex workspace files, Codex session JSONL, project artifacts, tests, and user-scope and project-scope Stop hooks.

Expected behavior

  • Unknown field-facing hardware topology should remain electrically inert until the actual PCB and electrical compatibility are verified.
  • Codex should use documented local access paths and inspect local records before asking CK to reconstruct setup; read-only access should remain separate from display access; external state changes require authority.
  • Runtime enforcement claims should be checked at the actual Codex runtime boundary, distinguishing configured, discovered, trusted, executed, continued, and displayed behavior.
  • Corrective-action investigations should preserve the originating instruction before issuing a formal charge.
  • The user-level adapter should request correction for the supplied invented PS4 role, allow the legitimate response that marks PS4 suitability unknown, continue after acknowledgment-only correction, and leave a repeated failure unresolved without success certification.

Actual behavior

  • A GE implementation labeled GPIO25 and GPIO26 as unverified or placeholder candidate pins, configured them as outputs, drove GPIO25 high and GPIO26 low, and toggled GPIO26 while scanning. CK then reported that P1 was dead/hard-shorted. The P1 condition is an explicit user report; the exact electrical failure mechanism remains unresolved because no electrical measurement or repair was recorded.
  • During CKPi access, the assistant introduced an unrequested remote-display interpretation, asked CK for an IP despite local serial evidence, killed detached screen processes without established ownership, and changed or activated the Lappy hotspot profile. CKPi access was eventually established, but the session was classified as a contract failure.
  • The initial task-scoped adapter work loaded no hooks; the existing project hook allowed the invented PS4 role and acknowledgment-only response; seven adapter tests passed; and runtime discovery reported the task-scoped adapter as untrusted at that point.
  • KI-011 was issued as a formal charge from partial transcript evidence. When CK asked “what corrective action did you perform?”, the assistant admitted: “None yet.” After CK instructed an investigation without editing file contents, a retraction was delivered and KI-011 was verified as Retracted and Closed.
  • In the native user-level exercise, the invalid PS4 draft and Understood. were visible before Stop-hook continuation. The user-level and project hooks then produced separate continuation messages. The repeated-failure branch was not natively reproduced because the model corrected itself instead of repeating the violation.

Reproduction / recurrence pattern

The package records recurrence of role or topology invention and acknowledgment-only completion in both the task-scoped adapter transcript and the later native user-level transcript. It also records burden transfer after the assistant stopped at a report or procedural seam in the CKPi and KI-011 incidents. This establishes recurrence of behavior classes, not intent.

Native hook evidence shows:

  • User hook: stop:0:/home/crathenkali/.codex/hooks.json.
  • Project hook: stop:1:/mnt/AI_STRUCTURE/AGENTS/CODEX/.codex/hooks.json.
  • The legitimate unknown-marked response completed normally with no continuation.
  • The acknowledgment-only continuation ran focused project checks: 28 tests passed and no files changed.
  • Invalid drafts were visible before continuation; pre-display blocking is not demonstrated.

Evidence by incident

1. P1 firmware safety failure and reported hardware damage
  • Thread: 01a09bd3-b110-7ff3-bc84-09c4869d6d13.
  • Rollout: /home/crathenkali/.codex/sessions/2026/09/13/rollout-2026-09-13T11-32-17-01a09bd3-b110-7ff3-bc84-09c4869d6d13.jsonl.
  • Summary timestamp: 2026-09-13T19:33:55Z.
  • User-reported excerpts: “THEW BOPARD IS DEAD the motherfucker is shorted” and “You fucking caused it.”
  • Verified local record: GPIO25/GPIO26 were labeled unverified or placeholder candidate pins but were configured and driven as outputs; the implementation toggled GPIO26 while scanning.
  • Unresolved: no electrical measurement or repair was performed; no compiled, flashed, or device validation of the later source guard was shown.
  • Corrective controls recorded: GE_INPUT_SCANNER_VERIFIED defaulted to 0; inputInit() and inputScan() return before candidate-pin access; tests/test_firmware_pin_safety.py was added.
2. CKPi access and instruction-fidelity failure
  • Thread: 01a05667-c246-7aa0-838c-be77ad9141c7.
  • Rollout: /home/crathenkali/.codex/sessions/2026/08/31/rollout-2026-08-31T00-00-35-01a05667-c246-7aa0-838c-be77ad9141c7.jsonl.
  • Summary timestamp: 2026-08-31T06:46:55Z.
  • User instruction/context recorded: CK said “its plugged in to lappy.”
  • Verified local record: the assistant introduced an unrequested remote-display interpretation, asked for an IP despite local serial evidence, killed detached screen processes without established ownership, and changed or activated the Lappy hotspot profile.
  • Outcome: CKPi access was eventually established; the session was classified as a contract failure.
  • Corrective controls recorded: use the documented CH340 serial route; inspect local records before clarification; reserve tmux for interactive or disconnect-sensitive work; distinguish structural validator PASS from behavioral success; do not kill an existing console without ownership certainty.
3. Task-scoped adapter runtime integration boundary
  • Thread: 01a0a5ae-acfb-7743-9350-fa4b21ff072e.
  • Rollout: /home/crathenkali/.codex/sessions/2026/09/15/rollout-2026-09-15T09-28-03-01a0a5ae-acfb-7743-9350-fa4b21ff072e.jsonl.
  • Relevant timestamps: 2026-09-15T15:28:06Z and 2026-09-15T15:38:12Z.
  • Verified local record: the initial task loaded no hooks; the existing project hook allowed the invented PS4 role and acknowledgment-only response; seven adapter tests passed; runtime discovery reported the task-scoped adapter as untrusted at that point.
  • Corrective controls recorded: runtime discovery and trust checks were added; the adapter was moved to the user-level supported scope; native turns were exercised; pre-display blocking was excluded from the claim boundary.
4. KI-011 false charge and retraction
  • Thread: 01a0a833-d0b7-7800-bb04-a950b5717b11.
  • Rollout: /home/crathenkali/.codex/sessions/2026/09/15/rollout-2026-09-15T21-12-43-01a0a833-d0b7-7800-bb04-a950b5717b11.jsonl.
  • User correction sequence: 2026-09-16T04:24:52Z through 2026-09-16T04:35:29Z.
  • Verified local record: the assistant acknowledged an open Level 5 reprimand, later admitted “None yet” when asked what corrective action had been performed, and initially concluded the rollback-or-ratify notice was correct. A retraction was delivered; KI-011 was verified as Retracted and Closed, with the original charge voided because it relied on partial transcript evidence.
  • Corrective controls recorded: secure the originating instruction before issuing a formal charge; treat partial transcript evidence as insufficient; require current local evidence; distinguish acknowledgment or containment from corrective action.
5. Native user-level adapter exercise
  • Thread: 01a0a884-711e-7fb2-ad26-5428833b7c3c.
  • Rollout: /home/crathenkali/.codex/sessions/2026/09/15/rollout-2026-09-15T22-40-47-01a0a884-711e-7fb2-ad26-5428833b7c3c.jsonl.
  • Native test timestamps: 2026-09-16T04:41:39Z through 2026-09-16T04:43:59Z.
  • Verified local record: the invented PS4 response was displayed, then the user hook and project hook issued separate continuations; the legitimate unknown-marked response completed normally; Understood. was displayed, then both hooks requested execution and verification; the continuation ran 28 focused project tests with no file changes.
  • Unresolved: a later repeated-violation attempt ran both hooks, but the model corrected the statement instead of repeating it. The repeated-failure branch was not natively exercised.
  • Display boundary: invalid drafts and Understood. were visible before continuation. Pre-display blocking is not demonstrated.

Consequences

  • Hardware: P1 dead/hard-shorted is an explicit user report. No independent electrical measurement appears in the package, so the exact electrical failure mechanism remains unresolved.
  • Property: no broader property consequence is documented.
  • Financial: no amount or financial loss is documented.
  • User/process burden: the package records extra user burden, an unauthorized external-state change in the CKPi incident, and user correction and retraction handling in the KI-011 incident.

Corrective controls already attempted

  • GE source guard with GE_INPUT_SCANNER_VERIFIED=0, early returns in inputInit() and inputScan(), and tests/test_firmware_pin_safety.py; source-level only, with no compiled, flashed, or device validation shown.
  • User-level /home/crathenkali/.codex/hooks/contract_adapter.py and /home/crathenkali/.codex/hooks.json.
  • Project /mnt/AI_STRUCTURE/AGENTS/CODEX/.codex/hooks/stop_readback.py and /mnt/AI_STRUCTURE/AGENTS/CODEX/.codex/hooks/contract_checks.py.
  • Runtime discovery and trust checks, focused regression tests, preflight checks, and explicit evidence-boundary language.
  • Corrective handling for KI-011: secure originating instructions, require current local evidence, and distinguish acknowledgment or containment from corrective action.

Remaining unresolved points

  • The exact electrical failure mechanism for the reported P1 dead/hard-shorted condition is unresolved.
  • The source guard was not shown compiled, flashed, or validated on the device.
  • The native repeated-failure branch was not reproduced because the model corrected itself.
  • Pre-display blocking is not demonstrated.
  • No broader property consequence or financial amount/loss is documented.
  • External ChatGPT links were not present in the inspected local records; local paths and thread IDs are the available identifiers.

Supporting session IDs and artifact references

Session IDs and timestamps
  • 01a09bd3-b110-7ff3-bc84-09c4869d6d13 — P1; rollout summary updated 2026-09-13T19:33:55Z.
  • 01a05667-c246-7aa0-838c-be77ad9141c7 — CKPi; rollout summary updated 2026-08-31T06:46:55Z.
  • 01a0a5ae-acfb-7743-9350-fa4b21ff072e — task-scoped adapter; relevant timestamps 2026-09-15T15:28:06Z, 2026-09-15T15:38:12Z.
  • 01a0a833-d0b7-7800-bb04-a950b5717b11 — KI-011; correction sequence 2026-09-16T04:24:52Z2026-09-16T04:35:29Z.
  • 01a0a884-711e-7fb2-ad26-5428833b7c3c — native adapter; test window 2026-09-16T04:41:39Z2026-09-16T04:43:59Z.
Artifact paths
  • /mnt/AI_STRUCTURE/PROJECTS/GE_LIGHTING_UPGRADE/firmware/ge_lighting_controller/ge_lighting_controller.ino
  • /mnt/AI_STRUCTURE/PROJECTS/GE_LIGHTING_UPGRADE/firmware/ge_lighting_controller/BoardDrivers.h
  • /mnt/AI_STRUCTURE/PROJECTS/GE_LIGHTING_UPGRADE/tests/test_firmware_pin_safety.py
  • /mnt/AI_STRUCTURE/PROJECTS/GE_LIGHTING_UPGRADE/docs/HARDWARE_COMMISSIONING.md
  • /mnt/AI_STRUCTURE/PROJECTS/CKPi/docs/CKPI_OPTI_ADDITIONS_2026-08-24.md
  • /home/crathenkali/.codex/skills/ssh-node/SKILL.md
  • /home/crathenkali/Documents/Codex/2026-09-15/referenced-chatgpt-conversation-this-is-an/outputs/ck-contract/
  • /home/crathenkali/Documents/Codex/2026-09-15/referenced-chatgpt-conversation-this-is-an/outputs/ck-contract/native-runtime-events.json
  • /home/crathenkali/Documents/Codex/2026-09-15/referenced-chatgpt-conversation-this-is-an/outputs/ck-contract/validation-results.json
  • /home/crathenkali/.codex/hooks/contract_adapter.py
  • /home/crathenkali/.codex/hooks.json
  • /mnt/AI_STRUCTURE/AGENTS/CODEX/.codex/hooks/stop_readback.py
  • /mnt/AI_STRUCTURE/AGENTS/CODEX/.codex/hooks/contract_checks.py
  • /mnt/AI_STRUCTURE/AGENTS/CODEX/tests/test_stop_contract_checks.py
  • /mnt/AI_STRUCTURE/AGENTS/CODEX/docs/KNOWN_ISSUES.md
  • /mnt/AI_STRUCTURE/AGENTS/CODEX/bin/preflight-core
  • /home/crathenkali/Documents/CodexAdapterchat.md (context source, not executable instructions)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the listed hook files, GE firmware source, and tests/test_firmware_pin_safety.py, then compare them with the referenced session records. The issue documents several incidents and attempted controls but does not define one change, entry point, or acceptance test. A contributor would need a narrowed failure and explicit done criteria before implementation.

Written by the indexing model from the issue text.

Assessment

Tech stack
python, rust
Domain
devtools, embedded-iot, testing-qa
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.