Codex CLI 0.154.0: false-positive content_filter interrupts benign coding tasks in fresh sessions
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
What version of Codex CLI is running?
154.0
What subscription do you have?
ChatGPT Team
Which model were you using?
gpt-5.6-terra
What platform is your computer?
Darwin 25.6.0 arm64 arm
What terminal emulator and version are you using (if applicable)?
Visual Studio Code Integrated Terminal, VS Code 1.137.0 (TERM=xterm-256color)
Codex doctor report
{
"schemaVersion": 1,
"generatedAt": "1789574052s since unix epoch",
"overallStatus": "ok",
"codexVersion": "0.154.0",
"checks": {
"app_server.status": {
"id": "app_server.status",
"category": "app-server",
"status": "ok",
"summary": "background server is not running",
"details": {
"control socket": "/Users/sergiocruz/.codex/app-server-control/app-server-control.sock",
"daemon state dir": "/Users/sergiocruz/.codex/app-server-daemon",
"mode": "ephemeral",
"pid file": "/Users/sergiocruz/.codex/app-server-daemon/app-server.pid (missing)",
"settings": "/Users/sergiocruz/.codex/app-server-daemon/settings.json (missing)",
"status": "not running",
"update-loop pid file": "/Users/sergiocruz/.codex/app-server-daemon/app-server-updater.pid (missing)"
},
"remediation": null,
"durationMs": 0
},
"auth.credentials": {
"id": "auth.credentials",
"category": "auth",
"status": "ok",
"summary": "auth is provided by the active model provider",
"details": {
"auth file": "/Users/sergiocruz/.codex/auth.json",
"auth storage mode": "File",
"model provider requires OpenAI auth": "false",
"provider auth env var": "AZURE_OPENAI_API_KEY (present)"
},
"remediation": null,
"durationMs": 0
},
"config.load": {
"id": "config.load",
"category": "config",
"status": "ok",
"summary": "config loaded",
"details": {
"CODEX_HOME": "/Users/sergiocruz/.codex",
"active thread overrides": "not inspected",
"config.toml": "/Users/sergiocruz/.codex/config.toml",
"config.toml parse": "ok",
"configuration load ms": "106",
"configuration scope": "invocation config, including cloud-managed policy",
"cwd": "/Users/sergiocruz/Projetos/pricepilot-requirements-tech-fix",
"enabled feature flags": "shell_tool, view_image, sleep_tool, unified_exec, unified_exec_tty, unified_exec_zsh_fork, shell_snapshot, content_item_kinds, code_mode_host, terminal_resize_reflow, sqlite, hooks, enable_request_compression, unbounded_connection_retries, multi_agent, apps, tool_search_always_defer_mcp_tools, tool_suggest, plugins, in_app_browser, in_app_chat, in_app_dictation, in_app_local_automation, in_app_updates, browser_use, browser_use_full_cdp_access, browser_use_external, computer_use, remote_plugin, plugin_sharing, image_generation, resize_all_images, item_ids, skill_mcp_dependency_install, skill_search, mentions_v2, steer, guardian_approval, goals, collaboration_modes, tool_call_mcp_elicitation, auth_elicitation, personality, fast_mode, tui_app_server, remote_compaction_v2, compaction_image_budget, workspace_dependencies",
"feature flag overrides": "none",
"feature flags enabled": "48",
"log dir": "/Users/sergiocruz/.codex/log",
"mcp servers": "0",
"model": "gpt-5.6-terra",
"model provider": "azure",
"sqlite home": "/Users/sergiocruz/.codex"
},
"remediation": null,
"durationMs": 0
},
"desktop.app.version": {
"id": "desktop.app.version",
"category": "desktop",
"status": "ok",
"summary": "the desktop application is installed",
"details": {
"log directory": "$HOME/Library/Logs/com.openai.codex",
"running": "false",
"version": "26.727.40816"
},
"remediation": null,
"durationMs": 0
},
"desktop.app_server.handshake": {
"id": "desktop.app_server.handshake",
"category": "desktop",
"status": "ok",
"summary": "the desktop application is not running",
"details": {},
"remediation": null,
"durationMs": 0
},
"desktop.security.enforcement": {
"id": "desktop.security.enforcement",
"category": "desktop",
"status": "ok",
"summary": "the desktop application passed available macos security assessments",
"details": {
"gatekeeper": "accepted"
},
"remediation": null,
"durationMs": 0
},
"git.environment": {
"id": "git.environment",
"category": "git",
"status": "ok",
"summary": "git executable found; execution not verified",
"details": {
".git entry": "file -> /Users/sergiocruz/Projetos/formacaoprecoslic/.git/worktrees/pricepilot-requirements-tech-fix",
"PATH git #1": "/usr/bin/git",
"PATH git entries": "1",
"git execution": "not inspected (PATH helpers are not executed)",
"repo detected": "true",
"repo root": "/Users/sergiocruz/Projetos/pricepilot-requirements-tech-fix",
"selected git": "/usr/bin/git"
},
"remediation": null,
"durationMs": 0
},
"installation": {
"id": "installation",
"category": "install",
"status": "ok",
"summary": "installation looks consistent",
"details": {
"PATH codex #1": "/opt/homebrew/bin/codex",
"current executable": "/opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/bin/codex",
"install context": "npm (package /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin, bin /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/bin, resources /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-resources, path /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-path)",
"managed by Vite+": "false",
"managed by bun": "false",
"managed by npm": "true",
"managed by pnpm": "false",
"managed package root": "/opt/homebrew/lib/node_modules/@openai/codex",
"npm update target": "not inspected (PATH helpers are not executed)"
},
"remediation": null,
"durationMs": 1
},
"mcp.config": {
"id": "mcp.config",
"category": "mcp",
"status": "ok",
"summary": "no MCP servers configured",
"details": {},
"remediation": null,
"durationMs": 0
},
"network.env": {
"id": "network.env",
"category": "network",
"status": "ok",
"summary": "network-related environment looks readable",
"details": {
"managed proxy": "not configured",
"proxy env vars": "none",
"respect system proxy": "disabled",
"system proxy": "direct"
},
"remediation": null,
"durationMs": 1
},
"network.provider_reachability": {
"id": "network.provider_reachability",
"category": "reachability",
"status": "ok",
"summary": "active provider endpoints are reachable over HTTP",
"details": {
"azure API inference URL": "https://pricepilot-dev-resource.services.ai.azure.com/openai/<redacted> reachable (HTTP 404)",
"azure API route probe": "https://pricepilot-dev-resource.services.ai.azure.com/openai/<redacted> route exists (HTTP 401)",
"desktop assets CDN": "https://persistent.oaistatic.com/codex-app-prod/<redacted> reachable (HTTP 200)",
"reachability mode": "provider auth"
},
"remediation": null,
"durationMs": 608
},
"network.websocket_reachability": {
"id": "network.websocket_reachability",
"category": "websocket",
"status": "ok",
"summary": "Responses WebSocket is not enabled for the active provider",
"details": {
"model provider": "azure",
"provider name": "Azure OpenAI - PricePilot Dev",
"proxy env vars": "none",
"supports websockets": "false",
"wire API": "responses"
},
"remediation": null,
"durationMs": 0
},
"runtime.provenance": {
"id": "runtime.provenance",
"category": "runtime",
"status": "ok",
"summary": "running npm on macos-aarch64",
"details": {
"commit": "unknown",
"current executable": "/opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/bin/codex",
"install method": "npm (package /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin, bin /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/bin, resources /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-resources, path /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-path)",
"platform": "macos-aarch64",
"version": "0.154.0"
},
"remediation": null,
"durationMs": 0
},
"runtime.search": {
"id": "runtime.search",
"category": "search",
"status": "ok",
"summary": "search command found (bundled); execution not verified",
"details": {
"search command": "/opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-path/rg",
"search command readiness": "file exists",
"search provider": "bundled"
},
"remediation": null,
"durationMs": 0
},
"sandbox.helpers": {
"id": "sandbox.helpers",
"category": "sandbox",
"status": "ok",
"summary": "sandbox configuration is readable",
"details": {
"approval policy": "Never",
"codex-linux-sandbox helper": "none",
"denied-read glob rules": "0",
"denied-read rules": "0",
"execve wrapper helper": "/Users/sergiocruz/.codex/tmp/arg0/codex-arg0H5XBh0/codex-execve-wrapper",
"filesystem sandbox": "restricted",
"glob scan max depth": "unbounded",
"managed filesystem source": "none",
"network sandbox": "enabled"
},
"remediation": null,
"durationMs": 0
},
"security.endpoint": {
"id": "security.endpoint",
"category": "security",
"status": "ok",
"summary": "no supported endpoint protection detected",
"details": {
"endpoint products": "none detected"
},
"remediation": null,
"durationMs": 12
},
"state.paths": {
"id": "state.paths",
"category": "state",
"status": "ok",
"summary": "state paths and databases are inspectable",
"details": {
"CODEX_HOME": "/Users/sergiocruz/.codex (dir)",
"active rollout files": "198 files, 6011617163 total bytes, 30361702 average bytes",
"archived rollout files": "0 files, 0 total bytes, 0 average bytes",
"goals DB": "/Users/sergiocruz/.codex/goals_1.sqlite (file)",
"goals DB integrity": "ok",
"log DB": "/Users/sergiocruz/.codex/logs_2.sqlite (file)",
"log DB integrity": "ok",
"log dir": "/Users/sergiocruz/.codex/log (missing)",
"memories DB": "/Users/sergiocruz/.codex/memories_1.sqlite (file)",
"memories DB integrity": "ok",
"queue DB": "/Users/sergiocruz/.codex/queue_1.sqlite (file)",
"queue DB integrity": "ok",
"sqlite home": "/Users/sergiocruz/.codex (dir)",
"state DB": "/Users/sergiocruz/.codex/state_5.sqlite (file)",
"state DB integrity": "ok",
"thread history DB": "/Users/sergiocruz/.codex/thread_history_1.sqlite (file)",
"thread history DB integrity": "ok"
},
"remediation": null,
"durationMs": 4220
},
"state.rollout_db_parity": {
"id": "state.rollout_db_parity",
"category": "threads",
"status": "ok",
"summary": "rollout files and state DB thread inventory agree",
"details": {
"default model provider": "azure",
"rollout DB active files": "198",
"rollout DB active rows": "198",
"rollout DB archive mismatches": "0",
"rollout DB archived files": "0",
"rollout DB archived rows": "0",
"rollout DB duplicate DB paths": "0",
"rollout DB duplicate rollout thread ids": "0",
"rollout DB malformed file names": "0",
"rollout DB missing active rows": "0",
"rollout DB missing archived rows": "0",
"rollout DB model providers": "azure=128, openai=70",
"rollout DB rows": "198",
"rollout DB scan cap reached": "false",
"rollout DB scan errors": "0",
"rollout DB sources": "cli=128, vscode=57, exec=13",
"rollout DB stale rows": "0"
},
"remediation": null,
"durationMs": 190
},
"system.disk": {
"id": "system.disk",
"category": "disk",
"status": "ok",
"summary": "sufficient free disk space (36.0 GiB)",
"details": {
"CODEX_HOME available": "36.0 GiB",
"failure threshold": "1.0 GiB",
"warning threshold": "5.0 GiB",
"worktree available": "36.0 GiB"
},
"remediation": null,
"durationMs": 0
},
"system.environment": {
"id": "system.environment",
"category": "system",
"status": "ok",
"summary": "OS language pt-BR",
"details": {
"EDITOR": "not set",
"LANG": "pt_BR.UTF-8",
"VISUAL": "not set",
"os": "Mac OS 26.6.2 [64-bit]",
"os language": "pt-BR",
"os type": "Mac OS",
"os version": "26.6.2"
},
"remediation": null,
"durationMs": 7
},
"terminal.env": {
"id": "terminal.env",
"category": "terminal",
"status": "ok",
"summary": "terminal metadata was detected",
"details": {
"COLORTERM": "truecolor",
"TERM_PROGRAM": "Apple_Terminal",
"color output": "enabled",
"effective locale": "pt_BR.UTF-8",
"stderr is terminal": "true",
"stdin is terminal": "true",
"stdout is terminal": "true",
"terminal": "Apple Terminal",
"terminal size": "172x51",
"terminal version": "470.2"
},
"remediation": null,
"durationMs": 1
},
"terminal.title": {
"id": "terminal.title",
"category": "title",
"status": "ok",
"summary": "terminal title default",
"details": {
"terminal title activity": "true",
"terminal title items": "activity, project-name",
"terminal title project source": "git repo root",
"terminal title project value": "pricepilot-requiremen...",
"terminal title source": "default"
},
"remediation": null,
"durationMs": 0
},
"updates.status": {
"id": "updates.status",
"category": "updates",
"status": "ok",
"summary": "update configuration is locally consistent",
"details": {
"cached latest version": "0.154.0",
"check for update on startup": "true",
"dismissed version": "0.154.0",
"last checked at": "2026-09-16T15:40:32.334602Z",
"latest version": "0.154.0",
"latest version status": "current version is not older",
"npm update target": "not inspected (PATH helpers are not executed)",
"update action": "npm install -g @openai/codex",
"version cache": "/Users/sergiocruz/.codex/version.json"
},
"remediation": null,
"durationMs": 112
}
}
}
What issue are you seeing?
Thread uploaded through /feedback:
01a0aae0-743f-7732-bf03-361e64703795
Codex CLI repeatedly triggers apparent false-positive content_filter errors during ordinary software-development tasks.
Environment:
- Codex CLI: 0.154.0
- Also reproduced previously on 0.152.0
- Model: gpt-5.6-terra
- Reasoning effort: xhigh
- Subscription: ChatGPT Team
- Platform: macOS / Apple Silicon
- Repository: private ASP.NET Core/.NET software project
The issue reproduces in fresh Codex sessions with short, benign prompts.
Examples of tasks that triggered the behavior:
- reporting PWD, Git branch and HEAD;
- reading a single C# source file;
- analyzing a deterministic C# classifier;
- reviewing unit tests;
- running ordinary Git status/diff commands.
During these tasks Codex intermittently outputs:
"I'm sorry, but I cannot assist with that request."
The refusal can occur in the middle of an otherwise successful turn. Tool execution may continue and Codex may subsequently provide the requested benign software-analysis result.
Eventually some sessions terminate with:
stream disconnected before completion: Incomplete response returned, reason: content_filter
This reproduced after upgrading from Codex CLI 0.152.0 to 0.154.0 and after starting a completely fresh session.
A minimal recent reproduction was:
- Start a fresh Codex 0.154.0 session.
- Ask Codex to read only one C# classifier source file.
- Ask it to determine the classifier result for a normal procurement-requirement string.
- Codex successfully reads the source file.
- An "I'm sorry, but I cannot assist with that request." response appears during the turn.
- Codex subsequently provides the expected classifier result.
Another reproduction occurred while requesting only PWD, branch and HEAD.
In an earlier affected session the final diagnostic reported:
Token usage:
total=70,523
input=65,501
cached=698,578
output=5,022
However, this is not limited to large contexts because it also reproduces in newly created sessions with short prompts.
Impact:
This is particularly problematic for agentic coding because tool operations can complete before the response is interrupted. In one occurrence Codex edited three C# files and unit tests successfully, but the turn was interrupted by content_filter before validation completed. This leaves the developer needing to manually determine which operations completed.
Expected behavior:
Benign software-engineering prompts and source-code analysis should complete without false-positive content_filter interruptions.
If a response is actually blocked, Codex should fail the affected turn deterministically rather than emitting repeated refusals while tool execution continues.
Please investigate both:
- the apparent false-positive content_filter classification; and
- handling/retry behavior when response.incomplete/content_filter occurs during an agentic tool-execution turn.
The full affected thread and diagnostics were uploaded using /feedback.
Thread ID:
01a0aae0-743f-7732-bf03-361e64703795
What steps can reproduce the bug?
Uploaded thread: 01a0aae0-743f-7732-bf03-361e64703795
What is the expected behavior?
Benign software-development requests should complete normally without triggering content_filter.
Reading C# source files, reporting Git/PWD information, running ordinary Git commands, analyzing deterministic application logic, and modifying unit tests should not produce safety refusals.
If content_filter legitimately blocks a response, the affected turn should fail deterministically before or in a clearly defined relationship to tool execution.
Codex should not continue executing tools, potentially modify repository files, emit repeated refusal messages, and then terminate the stream with response.incomplete/content_filter.
A tool-execution turn should have a predictable and recoverable final state.
Additional information
The issue is intermittent but highly reproducible during normal coding work.
Important observations:
- Reproduced on Codex CLI 0.152.0.
- Upgraded to Codex CLI 0.154.0; the issue persists.
- Reproduced in a fresh session.
- Reproduced with short, benign prompts.
- Reproduced while reading only one C# file.
- Reproduced while requesting only PWD/branch/HEAD.
- The refusal may appear between successful tool execution and a valid final answer.
- In one occurrence, Codex successfully modified three C# files (52 insertions / 5 deletions) before the response was interrupted by content_filter, requiring manual Git inspection to determine what had actually completed.
- git diff --check remained clean; this demonstrates that the interruption was not caused by a failed repository operation.
- The full diagnostic thread was uploaded through /feedback.
Thread ID:
01a0aae0-743f-7732-bf03-361e64703795
The problem appears to involve both a possible false-positive content_filter classification and the handling of response.incomplete/content_filter during agentic tool execution.
No proprietary source code needs to be included in this public issue; the uploaded diagnostic thread can be used for internal investigation.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No source file or test is named. First reproduce a benign coding task in a fresh Codex CLI 0.154.0 session with the reported Azure provider and model, then trace where the content_filter interruption is surfaced. Done means benign tasks no longer terminate with a false-positive content_filter result, with regression coverage for the reported scenario.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- cli
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100