Summary
On Windows, Codex Desktop local tool activity can launch an internal PowerShell parent-lifetime sentinel in a visible terminal window. The window reports:
error 2147942632 (0x800700E8)
The command shown by the window, sanitized to remove its random identifier, is:
powershell.exe -NoLogo -NoProfile -NonInteractive -Command <title-assignment>='cert-parent-death-<redacted-random-id>'; Start-Sleep -Seconds 300
The popup is intrusive and can accumulate across local tool activity.
Environment
- Windows
- Codex Desktop package version:
26.803.10989.0
- Windows-native local agent
- No user-specific paths, logs, network information, or identifiers are included in this report
Reproduction
- Fully exit Codex Desktop and ensure all Codex/ChatGPT processes have ended.
- Start Codex Desktop again.
- Run one harmless ordinary non-elevated, read-only shell canary:
Write-Output 'sandbox-canary-ok'
- Confirm the canary completes normally with exit code 0.
- Observe that a visible terminal window nevertheless appears with the
cert-parent-death-<random-id> / Start-Sleep -Seconds 300 command and error 0x800700E8.
Isolation evidence
- The issue reproduced after a genuinely clean process termination and restart.
- The ordinary sandbox canary completed successfully, so normal shell execution was healthy.
- The visible sentinel failure is therefore separable from shell-command success and from the Windows workspace-write
SetTokenInformation(TokenDefaultDacl) failed: 1344 defect.
- Switching the default Codex sandbox policy to stricter
read-only avoids the separate 1344 execution failure but does not prevent this sentinel popup.
- No scheduled task, monitoring service, or unrelated local process was needed to reproduce it.
- No Windows security control was disabled.
Expected behavior
Internal parent-lifetime sentinels should be launched without a user-visible console or terminal window. Their parent/pipe lifecycle should not produce an interactive Windows Terminal error page.
The Windows launcher should use an appropriate hidden/no-console creation path, or replace the PowerShell sentinel with a non-console/native mechanism.
Actual behavior
The sentinel is handed to the interactive terminal infrastructure. Its pipe closes with ERROR_NO_DATA / 0x800700E8, leaving a visible error window containing the internal command.
Related issues
This report appears to be a more specific variant involving the internal cert-parent-death sentinel and a five-minute sleep.
Summary
On Windows, Codex Desktop local tool activity can launch an internal PowerShell parent-lifetime sentinel in a visible terminal window. The window reports:
error 2147942632 (0x800700E8)The command shown by the window, sanitized to remove its random identifier, is:
The popup is intrusive and can accumulate across local tool activity.
Environment
26.803.10989.0Reproduction
cert-parent-death-<random-id>/Start-Sleep -Seconds 300command and error0x800700E8.Isolation evidence
SetTokenInformation(TokenDefaultDacl) failed: 1344defect.read-onlyavoids the separate 1344 execution failure but does not prevent this sentinel popup.Expected behavior
Internal parent-lifetime sentinels should be launched without a user-visible console or terminal window. Their parent/pipe lifecycle should not produce an interactive Windows Terminal error page.
The Windows launcher should use an appropriate hidden/no-console creation path, or replace the PowerShell sentinel with a non-console/native mechanism.
Actual behavior
The sentinel is handed to the interactive terminal infrastructure. Its pipe closes with
ERROR_NO_DATA/0x800700E8, leaving a visible error window containing the internal command.Related issues
ChatGPT.exe -> powershell.exe -> conhost.exeduring local tool activity.This report appears to be a more specific variant involving the internal
cert-parent-deathsentinel and a five-minute sleep.