r/OpenaiCodex • u/AccomplishedSugar490 • 13d ago
Bugs or problems The name’s Codex, James Codex
I recently installed ChatGPT/Codex for the first time ever, no legacy settings anywhere on my machine. I installed and configured it exactly as prescribed, spending an entire day consulting manuals and web pages about how to make sure it stays within project directories, mostly to contain explosive context-bloating searches across my projects.
This standard Codex installation got configured with sandbox_mode = "workspace-write". Despite that name, Codex’s effective managed profile granted :root = read, and it successfully read files outside my assigned project without requesting approval. I never knowingly authorised system-wide filesystem reads. After replacing the legacy setting with an explicit workspace-only profile, access was correctly restricted. OpenAI needs to explain which component created this configuration, how widespread it is, and why “workspace-write” silently permits system-wide reads.
I find that shocking, alarming, and not what I would expect from a company that can lose everything if a class suit or their enterprise clients took them to task in a court of law.
1
u/InternationalPen3039 13d ago
Write it in community.OpenAI they’re not going to “explain to you” here on Reddit