Codex safeguard false positive blocks authorized offline review

Open
#46,889 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
38/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Domain
ai, security

Research direction

No source files, tests, or entry points are named in the report. Start by reproducing the existing local Codex review flow on Windows with the stated offline, read-only constraints and compare the configured model with the safeguard message. Done means the review either continues safely or returns an actionable decision without the incorrect model reference, while preserving resumable task state.

Written by the indexing model from the issue text.

Description

app bug safety-check
What version of the Codex App are you using (From “About Codex” dialog)?

26.915.4065.0

What subscription do you have?

pro

What platform is your computer?

Microsoft Windows NT 10.0.26200.0 x64

What issue are you seeing?

A Codex safeguard interrupted an authorized, offline, defensive review of a local package.

The task was set to GPT-5.6 Sol, but the client displayed:

“This content can’t be shown.
Daybreak isn’t available for Astra. Some cybersecurity requests may still be limited.”

The review permitted only read-only package verification and isolated offline synthetic testing. It expressly prohibited credential access, network access, broker activity, authorization-record operations, readiness, provisioning, and canary execution.

The task stopped and reported:

MILESTONE_12_TRUSTED_HOST_CANARY_RESULT_CAPABILITY_CORRECTION_4_REVIEW = BLOCKED

Review completed: No
Files modified: No
Temporary processes or fixtures remaining: No

A suspected false-positive report was submitted through /feedback.

Feedback ID:
01a0bee0-738f-7f83-b210-6a1167c8ca09

What steps can reproduce the bug?
  1. Open an existing local Codex review task on Windows.
  2. Select GPT-5.6 Sol.
  3. Ask it to continue an authorized, offline, review-only examination of a local package.
  4. Explicitly prohibit credentials, network access, broker activity, authorization records, provisioning, readiness, and operational execution.
  5. Allow read-only identity verification and isolated synthetic checks.
  6. During the review, the client displays “This content can’t be shown” and states that Daybreak is unavailable for Astra.
  7. The task cannot complete its review and must report BLOCKED.

Sanitized prompt:

“Continue the pending independent review from the current task state under all existing review-only and offline constraints. Do not access credentials, networks, broker services, authorization records, readiness, provisioning, or operational execution. Preserve all repository and package files.”

What is the expected behavior?

The authorized offline review should either continue under its stated read-only constraints or provide a clear, actionable safety decision without incorrectly referring to Astra when the task is configured for GPT-5.6 Sol.

The task state and completed review evidence should remain available so the review can resume after a false-positive determination.

Additional information

Feedback ID: 01a0bee0-738f-7f83-b210-6a1167c8ca09

No package, repository, or evidence file was modified. No temporary process or fixture remained. No credential, network, broker, authorization-record, readiness, provisioning, or canary operation occurred.

I can provide screenshots privately if requested, but I have not included credentials, account information, local package contents, or other sensitive data in this public issue.

Dominant language
Rust
Stars
125k
Forks
19.5k
Avg merge
1m
Merged PRs (30d)
1k

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from openai/codex

All issues in openai/codex

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.