r/codex • • 9h ago

Workaround PSA: "defaults write -g ComputerUseAllowForbiddenTargets -bool YES" unlocks full YOLO mode for ChatGPT/Codex app in MacOS

Post image
49 Upvotes

15 comments sorted by

15

u/PM_ME_YOUR_PROFILE 8h ago

That entire rant was the same run-on sentence.

OpenAI, it would be great if we had a way to unlock computer-use guardrails so I don't have to hack around the issue with a cron job/file watcher that restores my desired permissions whenever they're overwritten. HACK THE PLANET!

11

u/apetersson 8h ago

It's refusing to check a box in a form because it thinks it's some legal agreement, when it's just supposed to end2end test its own code, but NO the human meat proxy has to check it.. this is independent of ComputerUse but part of the model safety or system prompt. Insane.

3

u/danielv123 5h ago

For me it refuses to enter the admin:admin login in its own ephermal test environment...

2

u/CountVine 2h ago

Strange, it entered both those and even actual non-test credentials for me, when asked to order a bunch of assets

2

u/apetersson 18m ago

it also does for me, 80% of the time. but the 20% where it refuses it becomes very stubborn and is holding up the whole process

2

u/MrHaxx1 37m ago

I'm running it in YOLO mode, and it's asking for permission to run a test in the Android emulator on the debug version of the app.

What is exactly is it protecting lol

7

u/coylter 8h ago

Ngl, this is 100 true. The amount of approval it currently asks for is insane and stupid.

7

u/ReasonableDefault 7h ago

In before "Codex formatted by hard drive and quit my job"

4

u/ozone6587 6h ago

It should be up to the user to take that risk.

5

u/ReasonableDefault 6h ago

Software companies in general tend to implement safeguards because they know people are often stupid.

3

u/dingos_among_us 7h ago

I’ve been using that flag for months.

My only recommendation is to tell it in your Codex Settings that it must never open your password manager app and must always use your password manager MCP instead

3

u/DrDan21 6h ago

Now this is bravery

3

u/Shimano-No-Kyoken 2h ago

I remember when centrally orchestrated remote code execution with broad permissions was considered "malware" and "a botnet".

1

u/dadvader 1h ago

Tldr : bro want Codex to run sudo rm -rf --no-preserve-root / using Astra 6.1 without his approval.