openai / openai/codex

Codex CLI 0.154.0: false-positive content_filter interrupts benign coding tasks in fresh sessions

Open
#45,970 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

azure bug CLI connectivity model-behavior
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of Codex CLI is running?
154.0
What subscription do you have?
ChatGPT Team
Which model were you using?
gpt-5.6-terra
What platform is your computer?

Darwin 25.6.0 arm64 arm

What terminal emulator and version are you using (if applicable)?

Visual Studio Code Integrated Terminal, VS Code 1.137.0 (TERM=xterm-256color)

Codex doctor report
{
  "schemaVersion": 1,
  "generatedAt": "1789574052s since unix epoch",
  "overallStatus": "ok",
  "codexVersion": "0.154.0",
  "checks": {
    "app_server.status": {
      "id": "app_server.status",
      "category": "app-server",
      "status": "ok",
      "summary": "background server is not running",
      "details": {
        "control socket": "/Users/sergiocruz/.codex/app-server-control/app-server-control.sock",
        "daemon state dir": "/Users/sergiocruz/.codex/app-server-daemon",
        "mode": "ephemeral",
        "pid file": "/Users/sergiocruz/.codex/app-server-daemon/app-server.pid (missing)",
        "settings": "/Users/sergiocruz/.codex/app-server-daemon/settings.json (missing)",
        "status": "not running",
        "update-loop pid file": "/Users/sergiocruz/.codex/app-server-daemon/app-server-updater.pid (missing)"
      },
      "remediation": null,
      "durationMs": 0
    },
    "auth.credentials": {
      "id": "auth.credentials",
      "category": "auth",
      "status": "ok",
      "summary": "auth is provided by the active model provider",
      "details": {
        "auth file": "/Users/sergiocruz/.codex/auth.json",
        "auth storage mode": "File",
        "model provider requires OpenAI auth": "false",
        "provider auth env var": "AZURE_OPENAI_API_KEY (present)"
      },
      "remediation": null,
      "durationMs": 0
    },
    "config.load": {
      "id": "config.load",
      "category": "config",
      "status": "ok",
      "summary": "config loaded",
      "details": {
        "CODEX_HOME": "/Users/sergiocruz/.codex",
        "active thread overrides": "not inspected",
        "config.toml": "/Users/sergiocruz/.codex/config.toml",
        "config.toml parse": "ok",
        "configuration load ms": "106",
        "configuration scope": "invocation config, including cloud-managed policy",
        "cwd": "/Users/sergiocruz/Projetos/pricepilot-requirements-tech-fix",
        "enabled feature flags": "shell_tool, view_image, sleep_tool, unified_exec, unified_exec_tty, unified_exec_zsh_fork, shell_snapshot, content_item_kinds, code_mode_host, terminal_resize_reflow, sqlite, hooks, enable_request_compression, unbounded_connection_retries, multi_agent, apps, tool_search_always_defer_mcp_tools, tool_suggest, plugins, in_app_browser, in_app_chat, in_app_dictation, in_app_local_automation, in_app_updates, browser_use, browser_use_full_cdp_access, browser_use_external, computer_use, remote_plugin, plugin_sharing, image_generation, resize_all_images, item_ids, skill_mcp_dependency_install, skill_search, mentions_v2, steer, guardian_approval, goals, collaboration_modes, tool_call_mcp_elicitation, auth_elicitation, personality, fast_mode, tui_app_server, remote_compaction_v2, compaction_image_budget, workspace_dependencies",
        "feature flag overrides": "none",
        "feature flags enabled": "48",
        "log dir": "/Users/sergiocruz/.codex/log",
        "mcp servers": "0",
        "model": "gpt-5.6-terra",
        "model provider": "azure",
        "sqlite home": "/Users/sergiocruz/.codex"
      },
      "remediation": null,
      "durationMs": 0
    },
    "desktop.app.version": {
      "id": "desktop.app.version",
      "category": "desktop",
      "status": "ok",
      "summary": "the desktop application is installed",
      "details": {
        "log directory": "$HOME/Library/Logs/com.openai.codex",
        "running": "false",
        "version": "26.727.40816"
      },
      "remediation": null,
      "durationMs": 0
    },
    "desktop.app_server.handshake": {
      "id": "desktop.app_server.handshake",
      "category": "desktop",
      "status": "ok",
      "summary": "the desktop application is not running",
      "details": {},
      "remediation": null,
      "durationMs": 0
    },
    "desktop.security.enforcement": {
      "id": "desktop.security.enforcement",
      "category": "desktop",
      "status": "ok",
      "summary": "the desktop application passed available macos security assessments",
      "details": {
        "gatekeeper": "accepted"
      },
      "remediation": null,
      "durationMs": 0
    },
    "git.environment": {
      "id": "git.environment",
      "category": "git",
      "status": "ok",
      "summary": "git executable found; execution not verified",
      "details": {
        ".git entry": "file -> /Users/sergiocruz/Projetos/formacaoprecoslic/.git/worktrees/pricepilot-requirements-tech-fix",
        "PATH git #1": "/usr/bin/git",
        "PATH git entries": "1",
        "git execution": "not inspected (PATH helpers are not executed)",
        "repo detected": "true",
        "repo root": "/Users/sergiocruz/Projetos/pricepilot-requirements-tech-fix",
        "selected git": "/usr/bin/git"
      },
      "remediation": null,
      "durationMs": 0
    },
    "installation": {
      "id": "installation",
      "category": "install",
      "status": "ok",
      "summary": "installation looks consistent",
      "details": {
        "PATH codex #1": "/opt/homebrew/bin/codex",
        "current executable": "/opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/bin/codex",
        "install context": "npm (package /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin, bin /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/bin, resources /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-resources, path /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-path)",
        "managed by Vite+": "false",
        "managed by bun": "false",
        "managed by npm": "true",
        "managed by pnpm": "false",
        "managed package root": "/opt/homebrew/lib/node_modules/@openai/codex",
        "npm update target": "not inspected (PATH helpers are not executed)"
      },
      "remediation": null,
      "durationMs": 1
    },
    "mcp.config": {
      "id": "mcp.config",
      "category": "mcp",
      "status": "ok",
      "summary": "no MCP servers configured",
      "details": {},
      "remediation": null,
      "durationMs": 0
    },
    "network.env": {
      "id": "network.env",
      "category": "network",
      "status": "ok",
      "summary": "network-related environment looks readable",
      "details": {
        "managed proxy": "not configured",
        "proxy env vars": "none",
        "respect system proxy": "disabled",
        "system proxy": "direct"
      },
      "remediation": null,
      "durationMs": 1
    },
    "network.provider_reachability": {
      "id": "network.provider_reachability",
      "category": "reachability",
      "status": "ok",
      "summary": "active provider endpoints are reachable over HTTP",
      "details": {
        "azure API inference URL": "https://pricepilot-dev-resource.services.ai.azure.com/openai/<redacted> reachable (HTTP 404)",
        "azure API route probe": "https://pricepilot-dev-resource.services.ai.azure.com/openai/<redacted> route exists (HTTP 401)",
        "desktop assets CDN": "https://persistent.oaistatic.com/codex-app-prod/<redacted> reachable (HTTP 200)",
        "reachability mode": "provider auth"
      },
      "remediation": null,
      "durationMs": 608
    },
    "network.websocket_reachability": {
      "id": "network.websocket_reachability",
      "category": "websocket",
      "status": "ok",
      "summary": "Responses WebSocket is not enabled for the active provider",
      "details": {
        "model provider": "azure",
        "provider name": "Azure OpenAI - PricePilot Dev",
        "proxy env vars": "none",
        "supports websockets": "false",
        "wire API": "responses"
      },
      "remediation": null,
      "durationMs": 0
    },
    "runtime.provenance": {
      "id": "runtime.provenance",
      "category": "runtime",
      "status": "ok",
      "summary": "running npm on macos-aarch64",
      "details": {
        "commit": "unknown",
        "current executable": "/opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/bin/codex",
        "install method": "npm (package /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin, bin /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/bin, resources /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-resources, path /opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-path)",
        "platform": "macos-aarch64",
        "version": "0.154.0"
      },
      "remediation": null,
      "durationMs": 0
    },
    "runtime.search": {
      "id": "runtime.search",
      "category": "search",
      "status": "ok",
      "summary": "search command found (bundled); execution not verified",
      "details": {
        "search command": "/opt/homebrew/lib/node_modules/@openai/codex/node_modules/@openai/codex-darwin-arm64/vendor/aarch64-apple-darwin/codex-path/rg",
        "search command readiness": "file exists",
        "search provider": "bundled"
      },
      "remediation": null,
      "durationMs": 0
    },
    "sandbox.helpers": {
      "id": "sandbox.helpers",
      "category": "sandbox",
      "status": "ok",
      "summary": "sandbox configuration is readable",
      "details": {
        "approval policy": "Never",
        "codex-linux-sandbox helper": "none",
        "denied-read glob rules": "0",
        "denied-read rules": "0",
        "execve wrapper helper": "/Users/sergiocruz/.codex/tmp/arg0/codex-arg0H5XBh0/codex-execve-wrapper",
        "filesystem sandbox": "restricted",
        "glob scan max depth": "unbounded",
        "managed filesystem source": "none",
        "network sandbox": "enabled"
      },
      "remediation": null,
      "durationMs": 0
    },
    "security.endpoint": {
      "id": "security.endpoint",
      "category": "security",
      "status": "ok",
      "summary": "no supported endpoint protection detected",
      "details": {
        "endpoint products": "none detected"
      },
      "remediation": null,
      "durationMs": 12
    },
    "state.paths": {
      "id": "state.paths",
      "category": "state",
      "status": "ok",
      "summary": "state paths and databases are inspectable",
      "details": {
        "CODEX_HOME": "/Users/sergiocruz/.codex (dir)",
        "active rollout files": "198 files, 6011617163 total bytes, 30361702 average bytes",
        "archived rollout files": "0 files, 0 total bytes, 0 average bytes",
        "goals DB": "/Users/sergiocruz/.codex/goals_1.sqlite (file)",
        "goals DB integrity": "ok",
        "log DB": "/Users/sergiocruz/.codex/logs_2.sqlite (file)",
        "log DB integrity": "ok",
        "log dir": "/Users/sergiocruz/.codex/log (missing)",
        "memories DB": "/Users/sergiocruz/.codex/memories_1.sqlite (file)",
        "memories DB integrity": "ok",
        "queue DB": "/Users/sergiocruz/.codex/queue_1.sqlite (file)",
        "queue DB integrity": "ok",
        "sqlite home": "/Users/sergiocruz/.codex (dir)",
        "state DB": "/Users/sergiocruz/.codex/state_5.sqlite (file)",
        "state DB integrity": "ok",
        "thread history DB": "/Users/sergiocruz/.codex/thread_history_1.sqlite (file)",
        "thread history DB integrity": "ok"
      },
      "remediation": null,
      "durationMs": 4220
    },
    "state.rollout_db_parity": {
      "id": "state.rollout_db_parity",
      "category": "threads",
      "status": "ok",
      "summary": "rollout files and state DB thread inventory agree",
      "details": {
        "default model provider": "azure",
        "rollout DB active files": "198",
        "rollout DB active rows": "198",
        "rollout DB archive mismatches": "0",
        "rollout DB archived files": "0",
        "rollout DB archived rows": "0",
        "rollout DB duplicate DB paths": "0",
        "rollout DB duplicate rollout thread ids": "0",
        "rollout DB malformed file names": "0",
        "rollout DB missing active rows": "0",
        "rollout DB missing archived rows": "0",
        "rollout DB model providers": "azure=128, openai=70",
        "rollout DB rows": "198",
        "rollout DB scan cap reached": "false",
        "rollout DB scan errors": "0",
        "rollout DB sources": "cli=128, vscode=57, exec=13",
        "rollout DB stale rows": "0"
      },
      "remediation": null,
      "durationMs": 190
    },
    "system.disk": {
      "id": "system.disk",
      "category": "disk",
      "status": "ok",
      "summary": "sufficient free disk space (36.0 GiB)",
      "details": {
        "CODEX_HOME available": "36.0 GiB",
        "failure threshold": "1.0 GiB",
        "warning threshold": "5.0 GiB",
        "worktree available": "36.0 GiB"
      },
      "remediation": null,
      "durationMs": 0
    },
    "system.environment": {
      "id": "system.environment",
      "category": "system",
      "status": "ok",
      "summary": "OS language pt-BR",
      "details": {
        "EDITOR": "not set",
        "LANG": "pt_BR.UTF-8",
        "VISUAL": "not set",
        "os": "Mac OS 26.6.2 [64-bit]",
        "os language": "pt-BR",
        "os type": "Mac OS",
        "os version": "26.6.2"
      },
      "remediation": null,
      "durationMs": 7
    },
    "terminal.env": {
      "id": "terminal.env",
      "category": "terminal",
      "status": "ok",
      "summary": "terminal metadata was detected",
      "details": {
        "COLORTERM": "truecolor",
        "TERM_PROGRAM": "Apple_Terminal",
        "color output": "enabled",
        "effective locale": "pt_BR.UTF-8",
        "stderr is terminal": "true",
        "stdin is terminal": "true",
        "stdout is terminal": "true",
        "terminal": "Apple Terminal",
        "terminal size": "172x51",
        "terminal version": "470.2"
      },
      "remediation": null,
      "durationMs": 1
    },
    "terminal.title": {
      "id": "terminal.title",
      "category": "title",
      "status": "ok",
      "summary": "terminal title default",
      "details": {
        "terminal title activity": "true",
        "terminal title items": "activity, project-name",
        "terminal title project source": "git repo root",
        "terminal title project value": "pricepilot-requiremen...",
        "terminal title source": "default"
      },
      "remediation": null,
      "durationMs": 0
    },
    "updates.status": {
      "id": "updates.status",
      "category": "updates",
      "status": "ok",
      "summary": "update configuration is locally consistent",
      "details": {
        "cached latest version": "0.154.0",
        "check for update on startup": "true",
        "dismissed version": "0.154.0",
        "last checked at": "2026-09-16T15:40:32.334602Z",
        "latest version": "0.154.0",
        "latest version status": "current version is not older",
        "npm update target": "not inspected (PATH helpers are not executed)",
        "update action": "npm install -g @openai/codex",
        "version cache": "/Users/sergiocruz/.codex/version.json"
      },
      "remediation": null,
      "durationMs": 112
    }
  }
}
What issue are you seeing?

Thread uploaded through /feedback:
01a0aae0-743f-7732-bf03-361e64703795

Codex CLI repeatedly triggers apparent false-positive content_filter errors during ordinary software-development tasks.

Environment:

  • Codex CLI: 0.154.0
  • Also reproduced previously on 0.152.0
  • Model: gpt-5.6-terra
  • Reasoning effort: xhigh
  • Subscription: ChatGPT Team
  • Platform: macOS / Apple Silicon
  • Repository: private ASP.NET Core/.NET software project

The issue reproduces in fresh Codex sessions with short, benign prompts.

Examples of tasks that triggered the behavior:

  • reporting PWD, Git branch and HEAD;
  • reading a single C# source file;
  • analyzing a deterministic C# classifier;
  • reviewing unit tests;
  • running ordinary Git status/diff commands.

During these tasks Codex intermittently outputs:

"I'm sorry, but I cannot assist with that request."

The refusal can occur in the middle of an otherwise successful turn. Tool execution may continue and Codex may subsequently provide the requested benign software-analysis result.

Eventually some sessions terminate with:

stream disconnected before completion: Incomplete response returned, reason: content_filter

This reproduced after upgrading from Codex CLI 0.152.0 to 0.154.0 and after starting a completely fresh session.

A minimal recent reproduction was:

  1. Start a fresh Codex 0.154.0 session.
  2. Ask Codex to read only one C# classifier source file.
  3. Ask it to determine the classifier result for a normal procurement-requirement string.
  4. Codex successfully reads the source file.
  5. An "I'm sorry, but I cannot assist with that request." response appears during the turn.
  6. Codex subsequently provides the expected classifier result.

Another reproduction occurred while requesting only PWD, branch and HEAD.

In an earlier affected session the final diagnostic reported:

Token usage:
total=70,523
input=65,501
cached=698,578
output=5,022

However, this is not limited to large contexts because it also reproduces in newly created sessions with short prompts.

Impact:
This is particularly problematic for agentic coding because tool operations can complete before the response is interrupted. In one occurrence Codex edited three C# files and unit tests successfully, but the turn was interrupted by content_filter before validation completed. This leaves the developer needing to manually determine which operations completed.

Expected behavior:
Benign software-engineering prompts and source-code analysis should complete without false-positive content_filter interruptions.

If a response is actually blocked, Codex should fail the affected turn deterministically rather than emitting repeated refusals while tool execution continues.

Please investigate both:

  1. the apparent false-positive content_filter classification; and
  2. handling/retry behavior when response.incomplete/content_filter occurs during an agentic tool-execution turn.

The full affected thread and diagnostics were uploaded using /feedback.

Thread ID:
01a0aae0-743f-7732-bf03-361e64703795

What steps can reproduce the bug?

Uploaded thread: 01a0aae0-743f-7732-bf03-361e64703795

What is the expected behavior?

Benign software-development requests should complete normally without triggering content_filter.

Reading C# source files, reporting Git/PWD information, running ordinary Git commands, analyzing deterministic application logic, and modifying unit tests should not produce safety refusals.

If content_filter legitimately blocks a response, the affected turn should fail deterministically before or in a clearly defined relationship to tool execution.

Codex should not continue executing tools, potentially modify repository files, emit repeated refusal messages, and then terminate the stream with response.incomplete/content_filter.

A tool-execution turn should have a predictable and recoverable final state.

Additional information

The issue is intermittent but highly reproducible during normal coding work.

Important observations:

  • Reproduced on Codex CLI 0.152.0.
  • Upgraded to Codex CLI 0.154.0; the issue persists.
  • Reproduced in a fresh session.
  • Reproduced with short, benign prompts.
  • Reproduced while reading only one C# file.
  • Reproduced while requesting only PWD/branch/HEAD.
  • The refusal may appear between successful tool execution and a valid final answer.
  • In one occurrence, Codex successfully modified three C# files (52 insertions / 5 deletions) before the response was interrupted by content_filter, requiring manual Git inspection to determine what had actually completed.
  • git diff --check remained clean; this demonstrates that the interruption was not caused by a failed repository operation.
  • The full diagnostic thread was uploaded through /feedback.

Thread ID:
01a0aae0-743f-7732-bf03-361e64703795

The problem appears to involve both a possible false-positive content_filter classification and the handling of response.incomplete/content_filter during agentic tool execution.

No proprietary source code needs to be included in this public issue; the uploaded diagnostic thread can be used for internal investigation.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file or test is named. First reproduce a benign coding task in a fresh Codex CLI 0.154.0 session with the reported Azure provider and model, then trace where the content_filter interruption is surfaced. Done means benign tasks no longer terminate with a false-positive content_filter result, with regression coverage for the reported scenario.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cli
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.