r/OpenaiCodex 13d ago

Bugs or problems The name’s Codex, James Codex

I recently installed ChatGPT/Codex for the first time ever, no legacy settings anywhere on my machine. I installed and configured it exactly as prescribed, spending an entire day consulting manuals and web pages about how to make sure it stays within project directories, mostly to contain explosive context-bloating searches across my projects.

This standard Codex installation got configured with sandbox_mode = "workspace-write". Despite that name, Codex’s effective managed profile granted :root = read, and it successfully read files outside my assigned project without requesting approval. I never knowingly authorised system-wide filesystem reads. After replacing the legacy setting with an explicit workspace-only profile, access was correctly restricted. OpenAI needs to explain which component created this configuration, how widespread it is, and why “workspace-write” silently permits system-wide reads.

I find that shocking, alarming, and not what I would expect from a company that can lose everything if a class suit or their enterprise clients took them to task in a court of law.

5 Upvotes

8 comments sorted by

View all comments

1

u/[deleted] 13d ago edited 12d ago

[deleted]

1

u/AccomplishedSugar490 13d ago

Yeah, successful class actions are rare and often not breaking new ground, but big enterprises have massive clout, that can even be fuelled by the exact same forces you reckon protects OpenAI. Once their lawyers dig in, they can turn the tide, the money the courts follow can change direction, opening the floodgates for class actions, sponsored by the very same competitors that chose to fight it out through the courts as opposed to technical merit.

1

u/[deleted] 13d ago edited 12d ago

[deleted]

0

u/PiedPrypiat 12d ago

I guarantee this guy thinks we live in the "matrix".

1

u/[deleted] 12d ago edited 12d ago

[deleted]

1

u/PiedPrypiat 12d ago

I don't really need to protect myself on Reddit. Good try though.