| Unsupported platform: ${platform} (${arch}) | exception | error | rust, network-proxy, mitm-hooks, query-string, config-validation, toml |
| Unsupported target triple: ${targetTriple} | exception | error | rust, network-proxy, mitm-hooks, query-string, config-validation |
| Missing optional dependency ${platformPackage}. Reinstall Co | exception | error | rust, network-proxy, mitm-hooks, query-string, config-validation, toml |
| invalid agent graph store request: {message} | error_code | error | rust, network-proxy, mitm-hooks, secrets, env-vars, config-validation |
| agent graph store internal error: {message} | error_code | error | rust, network-proxy, mitm-hooks, secrets, config-validation |
| Agent Identity only supports production and staging ChatGPT | validation | error | rust, network-proxy, http-headers, mitm-hooks, config-validation |
| invalid agent identity JWT format | exception | error | rust, network-proxy, mitm-hooks, secrets, file-path, config-validation |
| failed to decrypt encrypted task id | exception | error | rust, network-proxy, hostname, policy, validation |
| `bypass_hook_trust` override must be a boolean | validation | error | rust, network-proxy, wildcard, glob, policy, config-validation |
| {message} | exception | error | telemetry, otel, opentelemetry, env-vars, startup, rust |
| {context}: {source} | exception | error | auth, workload-identity, mcp-server, startup, rust |
| approval_policy = "untrusted" is no longer supported; remove | validation | error | memories, consolidation, filesystem, validation, rust |
| timed out waiting for a client to subscribe to the thread af | exception | error | memories, consolidation, file-format, version-marker, rust |
| current-time request failed: code={} message={} | exception | error | file-lock, concurrency, history, wouldblock, rust |
| current-time request was canceled: {err} | exception | error | file-lock, concurrency, history, wouldblock, rust |
| current-time request timed out after {}s | exception | error | bedrock, aws, auth, model-provider, rust |
| current-time response is outside the supported range | exception | error | |
| expected exactly one client subscribed to the thread, found | exception | error | |
| auth refresh returned invalid credentials | exception | error | |
InvalidInput error parsing -c overrides: {e} | exception | error | |
InvalidData error loading default config after config error: {e} | exception | error | |
| failed to initialize sqlite state runtime after moving damag | exception | error | |
| failed to move damaged sqlite state database files into a ba | exception | error | |
| host-owned MCP server '{CODEX_APPS_MCP_SERVER_NAME}' is not | exception | error | |
| hosted connector refresh completed without publishing a snap | exception | error | |
| failed to refresh tools for MCP server '{CODEX_APPS_MCP_SERV | exception | error | |
| pid-managed app-server startup is unsupported on this platfo | exception | error | |
| timed out waiting for pid-managed app server {pid} to stop | exception | error | |
| timed out waiting for pid reservation in {} to finish initia | exception | error | |
| timed out waiting for pid lock {} | exception | error | |
| pid-managed app-server shutdown is unsupported on this platf | exception | error | rust, codex, daemon, platform-support, windows, shutdown |
| pid-managed updater shutdown is unsupported on this platform | exception | error | rust, codex, daemon, platform-support, windows, process-group, updater |
| failed to read start time for pid-managed app server {pid} | exception | error | rust, codex, daemon, unix, subprocess, ps, startup-failure |
| pid-managed app server {pid} has no recorded start time | exception | error | rust, codex, daemon, unix, ps, procfs |
| app-server closed the control socket | exception | error | rust, codex, daemon, websocket, json-rpc, unix-socket, connection-reset |
| app-server user-agent omitted version separator | exception | error | rust, codex, daemon, user-agent, json-rpc, version-mismatch |
| app-server user-agent omitted version | exception | error | rust, codex, daemon, user-agent, version-mismatch |
| codex app-server daemon lifecycle is only supported on Unix | exception | error | rust, codex, daemon, platform-support, windows |
| app server is running but is not managed by codex app-server | exception | error | |
| managed standalone Codex install not found at {managed_codex | exception | error | |
| timed out waiting for daemon operation lock {} | exception | error | |
| managed Codex binary {} exited with status {} | exception | error | |
| managed Codex version output was malformed | exception | error | |
| remoteControl/pairing/start rejected manual pairing paramete | exception | error | |
| {method} rejected legacy params | exception | error | remote-control, json-rpc, invalid-params, version-mismatch, app-server-daemon |
| {method} failed: {} | exception | error | remote-control, json-rpc, error-response, websocket, app-server-daemon |
| pid-managed updater loop is unsupported on this platform | exception | error | platform-support, windows, updater, daemon, cfg-gating |
| standalone Codex updater exited with status {status} | exception | error | updater, subprocess, installer, shell, exit-status |
| standalone Codex updater request failed with status {status} | exception | error | http, installer, status-code, network, updater |
| TypeScript header worker panicked | exception | error | codegen, typescript, thread-panic, export, concurrency |
| Prettier failed with status {status} | exception | error | prettier, typescript, codegen, formatting, export |
| expected bundle root to be an object | exception | error | json-schema, codegen, invariant, export, schema-bundle |
| expected bundle definitions map | exception | error | json-schema, codegen, invariant, export, schema-bundle |
| expected v2 namespace in bundle definitions | exception | error | json-schema, codegen, v2-namespace, export, schema-bundle |
| {label} schema still references namespaced definitions; foun | exception | error | |
| expected definitions map in {label} schema | exception | error | |
| {label} schema missing definitions: {} | exception | error | |
| expected namespace {namespace} to be an object | exception | error | |
| schema definition collision in {location}: {name} (existing | exception | error | |
| expected ServerNotification schema to be an object | exception | error | |
| Numbered definition naming collision detected: schema={schem | panic | error | |
| Variant title naming collision detected: {collision_key} (ge | panic | error | |
InvalidInput path `{path}` is not absolute | validation | error | |
| `--ws-shared-secret-file`, `--ws-issuer`, `--ws-audience`, a | validation | error | |
| `--ws-token-file` and `--ws-token-sha256` are mutually exclu | validation | error | |
| `--ws-token-file` and `--ws-token-sha256` require `--ws-auth | validation | error | |
| `--ws-token-file` or `--ws-token-sha256` is required when `- | validation | error | |
| websocket auth flags require `--ws-auth capability-token` or | validation | error | |
| websocket auth clock skew must fit in a signed 64-bit intege | validation | error | |
| signed websocket bearer secret {} must be at least {MIN_SIGN | validation | error | |
| failed to read websocket auth secret {}: {err} | exception | error | |
| websocket auth secret {} must not be empty | validation | error | |
| {flag_name} must be a 64-character hex SHA-256 digest | validation | error | |
| {message} | exception | error | app-server, protocol, turn, error-payload, rust |
| invalid remote control account id header: {err} | exception | error | http-headers, authentication, remote-control, rust, invalid-input |
| remote control requires ChatGPT authentication | exception | error | authentication, chatgpt, remote-control, login, permission-denied |
| remote control requires ChatGPT authentication; API key auth | exception | error | authentication, api-key, chatgpt, remote-control, permission-denied |
| remote control enrollment is waiting for a ChatGPT account i | exception | warning | authentication, account-id, remote-control, enrollment, would-block |
| remote control client list requires environmentId | validation | error | validation, remote-control, api-params, invalid-input |
| remote control client list limit must be between 1 and 100 | validation | error | validation, pagination, remote-control, invalid-input |
| remote control client revoke requires environmentId | validation | error | validation, remote-control, revocation, api-params, invalid-input |
| remote control client revoke requires clientId | validation | error | validation, remote-control, revocation, api-params, invalid-input |
| remote control URL cannot be a base | validation | error | url, config, remote-control, invalid-input, rust |
| remote control {response_kind} failed at `{url}`: HTTP {stat | http | error | |
io::ErrorKind::InvalidInput remote control URL cannot be a base | validation | error | |
io::ErrorKind::InvalidData failed to parse remote control client last_seen_at `{last_seen_at}`: {err} | exception | error | |
io::ErrorKind::NotFound remote control cannot be enabled because sqlite state db is unavailable | exception | error | |
io::ErrorKind::PermissionDenied remote control is disabled by managed requirements | exception | error | |
io::ErrorKind::Interrupted remote control account changed during enrollment | exception | error | |
| remote control pairing failed at `{}`: HTTP {status}, {}, bo | http | error | |
io::ErrorKind::InvalidData failed to parse remote control pairing response from `{}`: HTTP {status}, {}, bo | exception | error | |
| remote control pairing status failed at `{}`: HTTP {status}, | http | error | |
io::ErrorKind::NotFound remote control enrollment cache unavailable because sqlite state db is disabled: | exception | error | |
| remote control is disabled by managed requirements | exception | error | |
| remote control cannot be enabled because sqlite state db is | exception | error | |
| remote control pairing requires remote control to be enabled | exception | error | |
| remote control pairing status accepts either pairingCode or | validation | error | |
| remote control pairing status requires pairingCode or manual | validation | error | |
| remote control pairing is unavailable until enrollment compl | exception | error | |
| invalid remote control URL `{remote_control_url}`: {err} | validation | error | |
| invalid remote control URL `{remote_control_url}` | validation | error | |
| invalid remote control URL `{remote_control_url}`; expected | validation | error | |
| remote control {response_kind} failed at `{url}`: HTTP {stat | http | error | |
| remote control server token refresh deferred until {next_ref | exception | error | |
| timed out connecting to remote control websocket at `{}` aft | exception | error | |
| remote control requires sqlite state db | exception | error | |
| remote control disabled after account changed | exception | error | |
| remote control account changed while resolving persisted pre | exception | error | |
| remote control disabled before enrollment | exception | error | |
| remote control disabled during enrollment | exception | error | |
| processor unavailable | exception | error | |
| app-server control socket is already in use at {} | exception | error | |
| app-server control socket path exists and is not a socket: { | exception | error | |
| refusing to start non-loopback websocket listener {bind_addr | validation | error | |
| {0} | exception | error | |
| patch detected without explicit call to apply_patch. Rerun a | exception | error | |
| {context}: {source} | exception | error | |
| {error} | exception | error | rust, apply-patch, partial-failure, rollback |
| No files were modified. | exception | warning | rust, apply-patch, empty-input, no-op |
InvalidInput path is a directory | exception | error | rust, apply-patch, filesystem, invalid-input |
| invalid patch: {0} | exception | error | rust, apply-patch, parser, validation |
| invalid hunk at line {line_number}, {message} | exception | error | rust, apply-patch, parser, syntax |
InvalidInput Refusing to create helper binaries under temporary dir {temp_root:?} (codex_home | exception | error | rust, codex, configuration, environment, startup |
| AWS service name must not be empty | exception | error | rust, aws, sigv4, configuration |
| AWS profile must be configured | exception | error | rust, aws, configuration, profile |
| AWS SDK config did not resolve a credentials provider | exception | error | rust, aws, credentials, authentication |
| AWS SDK config did not resolve a region | exception | error | rust, aws, configuration, region, sigv4 |
| failed to load AWS profiles: {0} | exception | error | |
| failed to load AWS credentials: {0} | exception | error | |
| request URL is not a valid URI: {0} | exception | error | |
| failed to construct HTTP request for signing: {0} | exception | error | |
| request contains a non-UTF8 header value: {0} | exception | error | |
| failed to build signable request: {0} | exception | error | |
| failed to build SigV4 signing params: {0} | exception | error | |
| SigV4 signing failed: {0} | exception | error | |
| thread usage response did not contain requested thread {thre | exception | error | |
| {method} {url} failed: {status}; content-type={ct}; body={bo | http | error | |
| Decode error for {url}: {e}; content-type={ct}; body={body} | exception | error | |
| POST {url} succeeded but no task id found; content-type={ct} | http | error | |
| failed to compile bubblewrap for Linux target: {err} | panic | error | |
| failed to convert argv to CString: {err} | panic | error | |
| bubblewrap is not available in this build.
Notes:
- ensure t | panic | error | |
| bwrap is only supported on Linux | panic | error | |
| No diff turn found | exception | error | |
| No PR output item found | exception | error | |
| Git apply failed (applied={}, skipped={}, conflicts={})\nstd | exception | error | |
| ChatGPT auth not available | exception | error | |
| ChatGPT backend requests require Codex backend auth | exception | error | |
| ChatGPT account ID not available, please re-run `codex login | exception | error | |
| Request failed with status {status}: {body} | exception | error | |
| ChatGPT account ID not available, please re-run codex login | exception | error | |
| ChatGPT auth not available | exception | error | |
| ChatGPT connectors require Codex backend auth | exception | error | |
| ChatGPT backend requests require Codex backend auth | exception | error | |
| ChatGPT account ID not available, please re-run codex login | exception | error | |
| Seatbelt sandbox is only available on macOS | exception | error | |
| invalid --sandbox-state-json value: {err} | exception | error | |
| --sandbox-state-disable-network cannot be applied to a disab | exception | error | |
| Windows sandbox is only available on Windows | exception | error | |
| failed to start managed network proxy: {err} | exception | error | |
| codex-linux-sandbox executable not found | panic | error | |
| `open -a {app_path} {url}` exited with {status} | exception | error | |
| Desktop app at {} failed OpenAI signature verification (team | exception | error | |
| failed to install Codex.app to any applications directory | exception | error | |
| curl download failed with {status} | exception | error | |
| `hdiutil attach` failed with {status}: {stderr} | exception | error | |
| hdiutil detach failed with {status} | exception | error | |
| no .app bundle found at {mount_point} | exception | error | |
| ditto copy failed with {status} | exception | error | |
| failed to open {url} with {status} | exception | error | |
| `{cmd_str}` failed with status {status} | exception | error | |
| `codex update` is not available in debug builds. Install a r | exception | error | |
| Could not detect the Codex installation method. Please updat | exception | error | |
| {err} | exception | error | |
| --force requires a session UUID; names must be confirmed int | validation | error | |
| Unknown feature flag: {feature} | validation | error | |
| `codex agents` received conflicting remote server endpoints | validation | error | |
| `codex agents` does not accept an initial prompt or images | validation | error | |
| `codex agents` cannot apply local provider or additional-dir | validation | error | |
| `codex agents` is unavailable while workload identity is act | validation | error | |
| `codex agents` requires `--remote` on this platform | validation | error | |
| `codex sandbox` is not supported on this operating system | exception | error | |
| --profile only applies to runtime commands and `codex mcp`: | validation | error | |
| Codex executable path is not configured | exception | error | |
| --environment-id is required when --remote is set | validation | error | |
| CODEX_ACCESS_TOKEN is required when --use-agent-identity-aut | validation | error | |
| Agent Identity authentication is unavailable | exception | error | |
| CODEX_ACCESS_TOKEN did not provide permitted Agent Identity | exception | error | |
| remote exec-server registration requires ChatGPT authenticat | exception | error | |
| invalid remote exec-server registration URL: {err} | exception | error | |
| remote exec-server registration URL must include a host | exception | error | |
| remote exec-server API-key authentication is restricted to H | exception | error | |
| remote exec-server registration requires ChatGPT authenticat | exception | error | |
| `--remote {remote}` is only supported for interactive TUI co | exception | error | |
| `--remote-auth-token-env` is only supported for interactive | exception | error | cli, codex, flag-validation, remote, tui |
| `--strict-config` is not supported for `codex {subcommand}` | exception | error | cli, codex, flag-validation, strict-config |
| environment variable `{env_var_name}` is not set | exception | error | cli, codex, environment-variable, auth-token, remote |
| environment variable `{env_var_name}` is empty | exception | error | cli, codex, environment-variable, auth-token, remote |
| failed to load marketplace(s):
{issue_lines} | exception | error | cli, codex, marketplace, plugins, yaml |
| {} upgrade failure(s) occurred. | exception | error | cli, codex, marketplace, upgrade, json, git |
| command is required | validation | error | cli, codex, mcp, stdio, argument-validation |
| exactly one of --command or --url must be provided | validation | error | cli, codex, mcp, argument-validation |
| No MCP server named '{name}' found. | validation | error | cli, codex, mcp, oauth, not-found |
| OAuth login is only supported for streamable HTTP servers. | validation | error | |
| No MCP server named '{name}' found in configuration. | validation | error | |
| OAuth logout is only supported for streamable_http transport | validation | error | |
| failed to delete OAuth credentials: {err} | exception | error | |
| invalid server name '{name}' (use letters, numbers, '-', '_' | validation | error | |
| one or more rollout migrations failed | exception | error | |
| plugin id `{}` belongs to marketplace `{}`, but --marketplac | validation | error | |
| plugin requires --marketplace unless passed as <plugin>@<mar | validation | error | |
| plugin `{plugin_name}` was not found in marketplace `{market | validation | error | |
| plugin `{plugin_name}` in marketplace `{marketplace_name}` m | validation | error | |
| failed to load configured marketplace snapshot(s):
{issue_li | exception | error | |
| `codex queue` does not support image attachments | validation | error | |
| {error:#} | exception | error | |
| foreground app-server exited before remote control became re | exception | error | |
| foreground app-server task failed before remote control beca | exception | error | |
| Remote control is enabled on {} but the connection is errore | exception | error | |
| Remote control is disabled on {}. | exception | error | |
| `codex sandbox setup` currently requires --elevated | validation | error | |
| sandbox provisioning succeeded, but failed to persist elevat | exception | error | |
| failed to determine current user from environment: {err} | exception | error | |
| --user or --current-user is required | validation | error | |
| --codex-home is required with --user | validation | error | |
| code-mode host bulk websocket pairing was abandoned | exception | error | |
| timed out pairing code-mode host bulk websocket | exception | error | |
| code-mode client sent a message on the wrong websocket lane | exception | error | |
| received a second code-mode client hello | exception | error | |
| duplicate code-mode request ID {request_id:?} | exception | error | |
| code-mode websocket messages must be binary framed messages | exception | error | |
| unsupported --listen URL `{listen_url}`; expected `ws://IP:P | validation | error | |
| code-mode IPC frame length {length} exceeds {MAX_FRAME_BYTES | exception | error | |
| code-mode IPC frame declares {length} payload bytes but cont | exception | error | |
| failed to decode code-mode IPC frame: {err} | exception | error | |
| code-mode IPC frame length exceeds u32 | exception | error | |
| request auth build error: {0} | exception | error | |
| transient auth error: {0} | exception | error | |
| api error {status}: {message} | exception | error | |
| stream error: {0} | exception | error | |
| context window exceeded | exception | error | |
| quota exceeded | exception | error | |
| usage not included | exception | error | |
| retryable error: {message} | exception | error | |
| rate limit: {0} | exception | error | |
| invalid request: {message} | exception | error | |
| cyber policy: {message} | exception | error | |
| misalignment policy violation: {message} | exception | error | |
| server overloaded | exception | error | |
| file `{file_name}` is too large: {size_bytes} bytes exceeds | validation | error | |
| failed to send OpenAI file request to {url}: {source} | exception | error | |
| OpenAI file blob upload to {host} failed after {elapsed_ms} | exception | error | |
| OpenAI file blob upload to {host} failed with status {status | http | error | |
| OpenAI file request to {url} failed with status {status}: {b | http | error | |
| failed to parse OpenAI file response from {url}: {source} | exception | error | |
| OpenAI file upload for `{file_id}` is not ready yet | exception | error | |
| OpenAI file upload for `{file_id}` failed: {message} | exception | error | |
| tool call rejected because the catalog changed after `{}/{to | exception | error | |
| MCP server '{server}' was not ready for this step | exception | error | |
| required MCP servers failed to initialize: {details} | exception | error | |
| unknown MCP server '{name}' | exception | error | |
| unknown MCP server '{CODEX_APPS_MCP_SERVER_NAME}' | exception | error | |
| unknown MCP server '{server}' | exception | error | |
| MCP server `{server}` is running in environment `{}`, expect | exception | error | |
| tool '{tool}' is disabled for MCP server '{server}' | exception | error | |
| MCP server '{server}' is not connected | exception | error | |
| elicitation request router unavailable | exception | error | |
| elicitation request not found | exception | error | |
| failed to send elicitation response: {e:?} | exception | error | |
| {method} exceeded the pagination limit of {MAX_MCP_CATALOG_P | exception | error | |
| {method} exceeded the catalog limit of {max_items} items | exception | error | |
| {method} returned a pagination cursor exceeding {MAX_MCP_PAG | exception | error | |
| {method} returned a repeated pagination cursor | exception | error | |
| {method} pagination timed out after {timeout:?} | exception | error | |
| hosted MCP event server was removed | exception | error | |
| events/list returned an unexpected MCP result | exception | error | |
| originating MCP tool call does not match the requested resou | exception | error | |
| originating MCP tool call has ambiguous account selection | exception | error | |
| originating MCP tool connector does not match its app contex | exception | error | |
| originating MCP tool link does not match its app context | exception | error | |
| originating MCP tool requires an explicit account link | exception | error | |
| originating MCP tool is disabled by app configuration | exception | error | |
| MCP client startup timed out after {startup_timeout:?} | exception | error | |
| MCP startup cancelled | exception | error | |
| MCP startup failed: {error} | exception | error | |
| Environment variable {env_var} for MCP server '{server_name} | validation | error | mcp, codex, environment-variable, bearer-token, authentication, streamable-http, config |
| Environment variable {env_var} for MCP server '{server_name} | validation | error | mcp, codex, environment-variable, bearer-token, authentication, missing-secret |
| Environment variable {env_var} for MCP server '{server_name} | validation | error | mcp, codex, environment-variable, unicode, bearer-token, encoding |
| Invalid MCP server name '{server_name}': must match pattern | validation | error | mcp, codex, server-name, validation, config, regex |
| executor-owned MCP server `{server_name}` cannot use hosted | validation | error | mcp, codex, authentication, chatgpt-auth, executor, remote-environment, config |
| non-local HTTP MCP server `{server_name}` did not resolve an | exception | error | mcp, codex, execution-environment, executor, bearer-token, startup, remote-environment |
| codex_apps MCP server is unavailable | exception | error | mcp, codex, codex-apps, resource-read, widget, connection-unavailable |
| MCP server '{server}' is not registered by the hosted runtim | exception | error | mcp, codex, codex-apps, reserved-name, event-stream, registration, config |
| {message} | exception | error | config, codex, cloud-config, enterprise-managed, http, authentication, timeout |
| failed to parse cloud config fragment {fragment}: {message} | validation | error | config, codex, toml, parse-error, enterprise-managed, cloud-config |
| invalid cloud config fragment {fragment}: {message} | validation | error | config, cloud-config, enterprise, toml, path-resolution, rust |
InvalidInput `ollama-chat` is no longer supported.
How to fix: replace `ollama-chat` with `ol | validation | error | config, provider, ollama, deprecation, migration, rust |
| invalid value for `{field_name}`: `{candidate}` is not in th | validation | error | config, constraints, policy, enterprise, validation, rust |
| To use model `{model}`, you need to use auto review. | validation | error | config, model-selection, auto-review, policy, constraints, rust |
| field `{field_name}` cannot be empty | validation | error | config, validation, empty-string, constraints, rust |
| invalid rules in requirements (set by {requirement_source}): | validation | error | config, exec-policy, sandbox-rules, requirements, toml, rust |
| invalid requirement for MCP server `{server_name}` (set by { | validation | error | config, mcp, requirements, validation, toml, rust |
| Config file {} has no parent directory | exception | error | config, loader, filesystem, path, rust |
| Managed config file {} has no parent directory | exception | error | config, managed-config, enterprise, filesystem, path, rust |
| requirements layer {source} has no base directory | exception | error | |
| managed config root must be a table | validation | error | |
| packaged defaults config file {} not found | exception | error | |
| packaged defaults config file {} has no parent directory | exception | error | |
| invalid embedded packaged defaults; this is a Codex build er | validation | error | |
| --profile `{active_user_profile}` cannot be used while {} co | validation | error | |
| Managed config file {} has no parent directory | exception | error | |
| Config file {} has no parent directory | exception | error | |
| Failed to read config file {}: {e} | exception | error | |
| unknown configuration field `{ignored_path}` in -c/--config | validation | error | |
InvalidData Requirements file {} has no parent directory | exception | error | |
| Failed to read requirements file {}: {e} | exception | error | |
| Failed to read project config file {config_file_display}: {e | exception | error | |
| Failed to read project hooks config file {}: {err} | exception | error | |
InvalidData Managed config file {} has no parent directory | exception | error | config, managed-config, path, rust, filesystem |
InvalidData {} | exception | error | toml, config, marketplace, parse-error, rust |
InvalidData {} | exception | error | toml, mcp, config, parse-error, rust |
| default_permissions refers to undefined profile `{profile_na | validation | error | permissions, config, profile, reference, rust |
| permissions profile `{profile_name}` extends undefined profi | validation | error | permissions, config, profile, inheritance, rust |
| permissions profile `{profile_name}` cannot extend unsupport | validation | error | permissions, config, profile, builtin, namespace, rust |
| permissions profile inheritance cycle detected: {} | validation | error | permissions, config, profile, inheritance, cycle, rust |
| failed to serialize permissions profile while resolving inhe | validation | error | |
| failed to deserialize merged permissions profile while resol | validation | error | |
| project_root_markers must be an array of strings | validation | error | |
| rules prefix_rules cannot be empty | validation | error | |
| rules prefix_rule at index {rule_index} has an empty pattern | validation | error | |
| rules prefix_rule at index {rule_index} has an invalid patte | validation | error | |
| rules prefix_rule at index {rule_index} has an empty justifi | validation | error | |
| rules prefix_rule at index {rule_index} is missing a decisio | validation | error | |
| rules prefix_rule at index {rule_index} has decision 'allow' | validation | error | |
| failed to parse requirements layer {layer_source}: {message} | validation | error | |
| failed to parse merged requirements: {message} | validation | error | |
| failed to compose requirements field `{field}` between {exis | validation | error | |
| invalid shell environment policy in {}: {error} | validation | error | |
| project layers are not ordered from root to cwd | exception | error | |
| {message} | exception | error | |
| No corresponding config content | exception | error | |
| failed to load AGENTS.md instructions for environment `{}`: | exception | error | |
| MCP event request _meta must be a JSON object, got {other} | validation | error | |
| duplicate agent role name `{role_name}` declared in the same | validation | error | |
| duplicate agent role name `{role_name}` declared in config | validation | error | |
| failed to parse agent role file at {}: {err} | validation | error | |
| failed to deserialize agent role file at {}: {err} | validation | error | |
| agent role file at {} must define a non-empty `name` | validation | error | |
| agent role file at {} must contain a TOML table | validation | error | |
| {field_label} cannot be blank | validation | error | |
| agent role `{role_name}` must define a description | validation | error | |
| agent role file at {}.developer_instructions cannot be blank | validation | error | |
| agent role file at {} must define `developer_instructions` | validation | error | |
| agents.{role_name}.config_file must point to an existing fil | validation | error | |
| agents.{role_name}.config_file must point to a file: {} | validation | error | |
| {field_label} must contain at least one name | validation | error | |
| {field_label} cannot contain blank names | validation | error | |
| {field_label} cannot contain duplicates | validation | error | |
| {field_label} may only contain ASCII letters, digits, spaces | validation | error | |
| duplicate agent role name `{role_name}` discovered in {} | validation | error | |
| invalid value for `{field_name}`: `{candidate}` is not in th | validation | error | |
| approval_policy = "untrusted" is no longer supported; remove | exception | error | |
| failed to build managed network proxy from {source}: {err} | validation | error | |
| features.token_budget.reminder_threshold_tokens must be posi | validation | error | |
| features.token_budget.reminder_message_template must not be | validation | error | |
| features.token_budget.reminder_message_template must not exc | validation | error | |
| features.token_budget.guidance_message must not exceed {TOKE | validation | error | |
| features.token_budget.auto_compact_fallback_prompt must not | validation | error | |
| features.token_budget.auto_compact_fallback_buffer_tokens is | validation | error | |
| features.token_budget.auto_compact_fallback_buffer_tokens mu | validation | error | |
| failed to serialize default config: {e} | exception | error | |
| failed to parse model_catalog_json path `{}` as JSON: {err} | validation | error | |
| model_catalog_json path `{}` must contain at least one model | validation | error | |
| configured value for `{field_name}` is disallowed by require | validation | error | |
| mcp_servers.{server_name} uses unsupported `bearer_token`; s | validation | error | |
| features.rollout_budget.limit_tokens is required when rollou | validation | error | |
| features.rollout_budget.limit_tokens must be positive | validation | error | |
| features.rollout_budget.reminder_at_remaining_tokens is requ | validation | error | |
| features.rollout_budget.reminder_at_remaining_tokens must co | validation | error | |
| features.rollout_budget.{field} must be finite and non-negat | validation | error | |
| {label} must be at least {HARD_MIN_MULTI_AGENT_V2_TIMEOUT_MS | validation | error | |
| {label} must be at most {HARD_MAX_MULTI_AGENT_V2_TIMEOUT_MS} | validation | error | |
| {LABEL} must not be empty | validation | error | |
| {LABEL} must not have leading or trailing whitespace | validation | error | |
| {LABEL} must match ^[a-zA-Z0-9_-]+$ | validation | error | |
| {LABEL} must be at most {MAX_LEN} characters | validation | error | |
| {LABEL} uses a reserved namespace: {namespace} | validation | error | |
| `experimental_thread_store_endpoint` is no longer supported; | validation | error | |
| `sandbox_mode` and `permission_profile` overrides cannot bot | validation | error | |
| `sandbox_mode` and `default_permissions` overrides cannot bo | validation | error | |
| `permission_profile` and `default_permissions` overrides can | validation | error | |
| legacy `profile = "{profile}"` config is no longer supported | validation | error | codex, config, toml, migration, profile |
| config defines `[permissions]` profiles but does not set `de | validation | error | codex, permissions, config, toml, validation |
| Model provider `{model_provider_id}` not found | validation | error | codex, model-provider, config, ollama, not-found |
| features.multi_agent_v2.max_concurrent_threads_per_session m | validation | error | codex, config, multi-agent, validation |
| features.multi_agent_v2.min_wait_timeout_ms must be at most | validation | error | codex, config, multi-agent, timeouts |
| features.multi_agent_v2.default_wait_timeout_ms must be at l | validation | error | codex, config, multi-agent, timeouts |
| features.multi_agent_v2.default_wait_timeout_ms must be at m | validation | error | codex, config, multi-agent, timeouts |
| agents.max_concurrent_threads_per_session must be at least 1 | validation | error | codex, config, agents, validation |
| `approval_policy = "never"` cannot be used because requireme | validation | error | codex, approval-policy, sandbox, permissions, requirements |
| goals.max_goal_token_budget exceeds the maximum supported to | validation | error | |
| failed to read {context} {}: {e} | exception | error | |
| {context} is empty: {} | validation | error | |
| failed to read effective config for selected permission prof | validation | error | |
| requirements.toml permissions profile `{profile_id}` conflic | validation | error | |
| requirements.toml default_permissions must be set unless all | validation | error | |
| requirements.toml default_permissions requires allowed_permi | validation | error | |
| requirements.toml allowed_permission_profiles refers to unde | validation | error | |
| requirements.toml default_permissions `{default_permissions} | validation | error | |
| network proxy constraints are invalid: {err} | validation | error | |
| environment network policy requires managed network enforcem | validation | error | |
| environment network policy cannot override a disabled contro | validation | error | |
| environment network policy violates managed requirements: {e | validation | error | |
| permissions profile `{profile_name}` uses a reserved built-i | validation | error | |
| default_permissions requires a `[permissions]` table | validation | error | |
| default_permissions refers to unknown built-in profile `{pro | validation | error | |
| filesystem path `{path}` does not support nested entries | validation | error | |
| filesystem glob subpath `{subpath}` only supports `deny` acc | validation | error | |
| filesystem glob path `{path}` only supports `deny` access; u | validation | error | |
| glob_scan_max_depth must be at least 1 | validation | error | |
| filesystem path `{path}` must be absolute, use `~/...`, or s | validation | error | |
| filesystem subpath `{}` must be a descendant path without `. | validation | error | |
| `additional_developer_instructions` from {} exceeds the mode | validation | error | |
| features.current_time_reminder.clock_source is external, but | exception | error | |
| command args are empty | exception | error | |
| failed to read rules files from {dir}: {source} | exception | error | |
| failed to read rules file {path}: {source} | exception | error | |
| failed to parse rules file {path}: {source} | exception | error | |
| failed to update rules file {path}: {source} | exception | error | |
| failed to join blocking rules update task: {source} | exception | error | |
| failed to update in-memory rules: {source} | exception | error | |
| guardian review completed without an assessment payload | exception | error | |
| guardian assessment was not valid JSON | exception | error | |
| guardian review session could not preserve REPL developer po | exception | error | |
| guardian review completed without an assessment payload | exception | error | |
| guardian review session was not available after spawn | exception | error | |
| guardian review input was not started: {submission:?} | exception | error | |
| guardian review session could not set permission profile: {e | exception | error | |
| guardian review session could not clear MCP servers: {err} | exception | error | |
| guardian review session could not disable `features.{}`: {er | exception | error | |
| MCP tool returned an error: {text} | exception | error | |
| MCP runtime refresh semaphore closed | exception | error | |
| unknown MCP server '{CODEX_APPS_MCP_SERVER_NAME}' | exception | error | |
| failed to send elicitation response: {e:?} | exception | error | |
| failed to start managed network proxy: {err} | exception | error | |
| Session persistence is disabled; cannot {operation}. | exception | error | |
| managed network proxy refresh semaphore closed | exception | error | |
| failed to update runtime allowlist: {err} | exception | error | |
| failed to update runtime denylist: {err} | exception | error | |
| failed to persist network policy amendment to execpolicy: {e | exception | error | |
| network policy amendment host '{}' does not match approved h | exception | error | |
| reserved thread ID cannot be used when resuming a thread | validation | error | |
| zsh fork feature enabled, but no packaged zsh fork is availa | exception | error | |
| zsh fork feature enabled, but packaged zsh fork `{}` is not | exception | error | rust, codex, shell, zsh, feature-flag, session-startup |
| unknown environment shell `{name}` | validation | error | rust, codex, shell, unsupported-value, environment-validation |
| Shell snapshot not supported yet for {shell_type:?} | exception | warning | rust, codex, shell-snapshot, powershell, cmd, unsupported-platform-feature |
| Shell snapshotting is not yet supported for {shell_type:?} | exception | warning | rust, codex, shell-snapshot, cmd, feature-gap |
| Snapshot output missing marker {marker} | exception | warning | rust, codex, shell-snapshot, rcfile, output-parsing |
| Snapshot command timed out for {shell_name} | exception | warning | rust, codex, shell-snapshot, timeout, slow-startup |
| Snapshot command exited with status {status}: {stderr} | exception | warning | rust, codex, shell-snapshot, nonzero-exit, dotfiles |
| local cwd URI `{cwd_display}` is not a host-native path | validation | error | rust, codex, approvals, cwd, file-uri, path-validation |
| local cwd URI `{cwd_display}` is not absolute: {err} | validation | error | rust, codex, approvals, cwd, relative-path, path-validation |
| plugin cache root should be absolute: {err} | panic | critical | rust, codex, plugins, panic, absolute-path, config-validation |
| {context}: {source} | exception | error | |
| {0} | exception | error | |
| No default OSS provider configured. Use --local-provider=pro | exception | error | |
| OSS provider not set but oss flag was used | exception | error | |
| OSS setup failed: {e} | exception | error | |
| Forking with images requires a prompt | exception | error | |
| Forking with output options requires a prompt | exception | error | |
| Ephemeral forks require a prompt | exception | error | |
| failed to initialize in-process app-server client: {err} | exception | error | |
| Session not found: {} | exception | error | |
| in-process app-server shutdown failed: {err} | exception | error | |
| Review prompt cannot be empty | exception | error | |
| Specify --uncommitted, --base, --commit, or provide custom r | exception | error | |
| capability root discovery accepts at most {MAX_ROOTS_PER_REQ | exception | error | |
| failed to spawn exec-server: {0} | exception | error | |
| timed out connecting to exec-server websocket `{url}` after | exception | error | |
| failed to connect to exec-server websocket `{url}`: {source} | exception | error | |
| failed to configure exec-server websocket: {0} | exception | error | |
| timed out waiting for exec-server initialize handshake after | exception | error | |
| exec-server transport closed | exception | error | |
| {0} | exception | error | |
| failed to serialize or deserialize exec-server JSON: {0} | exception | error | |
| HTTP request failed: {0} | exception | error | |
| exec-server protocol error: {0} | exception | error | |
| environment `{environment_id}` is already registered with a | exception | error | |
| exec-server rejected request ({code}): {message} | exception | error | |
| environment registry request failed ({status}{code_suffix}): | exception | error | |
| environment registry configuration error: {0} | exception | error | |
| environment registry authentication error: {0} | exception | error | |
| environment registry request failed: {0} | exception | error | |
| exec-server connection attempt failed: {0} | exception | error | |
-32602 {0} | validation | error | |
-32603 {0} | exception | error | |
| file read handle `{handle_id}` already exists | exception | error | |
| at most {MAX_OPEN_FILE_READS} file reads may be open per con | exception | error | |
| file read offset overflowed | exception | error | |
| file read block length must be between 1 and {FILE_READ_CHUN | exception | error | |
| unknown file read handle `{handle_id}` | exception | error | |
| file is too large to read: limit is {MAX_READ_FILE_BYTES} by | exception | error | |
InvalidInput sandboxed filesystem operations require configured runtime paths | exception | error | |
Interrupted filesystem walk cancelled | exception | error | |
| no-follow filesystem operations require an absolute path | validation | error | |
| no-follow filesystem operations require a normalized path | validation | error | |
| path must name an entry | validation | error | |
| path is not a regular file | validation | error | |
| path contains a symbolic link | validation | error | |
| directory already exists | exception | error | |
| recursive no-follow removal is unsupported | exception | error | |
| no-follow filesystem operations require an absolute path | validation | error | |
| no-follow filesystem operations require a local disk or UNC | validation | error | |
| no-follow filesystem operations require an absolute Windows | validation | error | |
| filesystem path is too long | validation | error | |
| path contains a reparse point | validation | error | |
| path `{}` is not a file | validation | error | |
| recursive no-follow removal is unsupported | exception | error | |
| Noise channel key generation failed: {0} | exception | error | |
| invalid Noise channel public key: {0} | exception | error | |
| invalid Noise channel message: {0} | exception | error | |
| Noise channel handshake failed: {0} | exception | error | |
| Noise channel transport failed: {0} | exception | error | |
| path `{}` is not a file | validation | error | |
| path `{}` is not a regular file | validation | error | |
InvalidData {FS_READ_BLOCK_METHOD} returned {} bytes, maximum is {} | exception | error | |
InvalidData remote fs/readFile returned invalid base64 dataBase64: {err} | exception | error | |
BrokenPipe exec-server transport closed | exception | error | |
| Codex executable path is not configured | validation | error | |
| fs/readFile returned invalid base64 dataBase64: {err} | validation | error | |
| sandboxed filesystem operations require ReadOnly or Workspac | validation | error | |
| prefix rule requires at least one token | exception | error | |
| invalid network rule: {0} | exception | error | |
| policy path has no parent: {path} | exception | error | |
| failed to create policy directory {dir}: {source} | exception | error | |
| failed to format prefix tokens: {source} | exception | error | |
| failed to serialize network rule field: {source} | exception | error | |
| failed to open policy file {path}: {source} | exception | error | |
| failed to write to policy file {path}: {source} | exception | error | |
| failed to lock policy file {path}: {source} | exception | error | |
| failed to seek policy file {path}: {source} | exception | error | |
| failed to read policy file {path}: {source} | exception | error | |
| failed to read metadata for policy file {path}: {source} | exception | error | |
| invalid decision: {0} | exception | error | |
| invalid pattern element: {0} | exception | error | |
| invalid example: {0} | exception | error | |
| invalid rule: {0} | exception | error | |
| expected every example to match at least one rule. rules: {r | exception | error | |
| expected example to not match rule `{rule}`: {example} | exception | error | |
| starlark error: {0} | exception | error | |
| failed to read app config for selected plugin `{plugin_id}` | exception | error | rust, plugin, config, io, codex |
| failed to parse app config for selected plugin `{plugin_id}` | exception | error | rust, plugin, json, serde, codex |
| could not resolve the Luna model provider: {0} | exception | error | rust, auth, model-provider, guardian, codex |
| Luna Responses WebSocket failed: {0} | exception | error | rust, websocket, api, guardian, codex |
| Luna Responses WebSocket connection timed out | exception | error | rust, websocket, timeout, network, guardian |
| Luna response did not contain assistant output | exception | warning | rust, model-response, guardian, codex |
| Luna response exceeded the output limit | exception | warning | rust, output-limit, guardian, codex |
| generated image exceeds the executor file size limit | exception | warning | rust, image-generation, size-limit, executor, codex |
| generated image directory is not a real directory | exception | warning | rust, image-generation, symlink, security, executor |
| generated image destination already exists | exception | warning | rust, image-generation, file-exists, executor, codex |
| failed to read MCP config for selected plugin `{plugin_id}` | exception | error | rust, mcp, plugin, config, io, codex |
| failed to resolve MCP config path `{relative_path}` below se | exception | error | rust, mcp, plugin, path, codex |
| failed to parse MCP config for selected plugin `{plugin_id}` | exception | error | rust, mcp, plugin, json, serde, codex |
| filename '{filename}' {reason} | validation | error | rust, memories, validation, filename, codex |
| ad-hoc note must not be empty | validation | error | rust, memories, validation, codex |
| ad-hoc note '{filename}' already exists | validation | error | rust, memories, duplicate, codex |
| path '{path}' {reason} | validation | error | rust, memories, validation, path, codex |
| cursor '{cursor}' {reason} | validation | error | rust, memories, pagination, cursor, codex |
| path '{path}' was not found | validation | error | rust, memories, not-found, codex |
| line_offset must be a 1-indexed line number | validation | error | rust, codex, memories, validation, off-by-one, line-offset |
| max_lines must be a positive integer | validation | error | rust, codex, memories, validation, pagination, option-semantics |
| line_offset exceeds file length | validation | warning | rust, codex, memories, pagination, eof, stale-state |
| path '{path}' is not a file | validation | error | rust, codex, memories, filesystem, validation, eisdir |
| queries must not be empty or contain empty strings | validation | error | rust, codex, memories, search, validation, empty-input |
| all_within_lines.line_count must be a positive integer | validation | error | rust, codex, memories, search, validation, enum-payload |
| I/O error while reading memories: {0} | exception | error | rust, codex, memories, filesystem, io, utf-8, permissions |
| queue storage failed: {0} | exception | error | rust, codex, queue, storage, sqlite, thread-store |
| queued submission payload is invalid: {0} | validation | error | rust, codex, queue, serde, json, version-skew, schema-drift |
| local queued attachment is invalid: {0} | validation | error | rust, codex, queue, attachment, io, file-not-found |
| Core failed to submit queued user message: {0} | exception | error | queue, codex-core, turn-submission, rust |
| only user input can be added to the user-message queue | validation | error | queue, input-validation, turn-input, rust |
| queued user input exceeds the maximum length of {MAX_USER_IN | validation | error | queue, input-validation, length-limit, rust |
| generated input schema for {name} should parse: {err} | panic | critical | skills, json-schema, schemars, panic, tool-registration, rust |
| generated skill tool schema should serialize: {err} | panic | critical | skills, json-schema, serde, panic, build-corruption, rust |
| root tool schema must be an object | panic | critical | skills, json-schema, schemars, panic, unreachable, rust |
| memory import requires at least one selected memory | validation | error | migration, memory-import, input-validation, rust |
| memory import requires the Codex state database | exception | error | migration, memory-import, state-db, rust |
| invalid external agent session import ledger: {err} | exception | error | migration, session-import, json, corruption, rust |
| mutex poisoned | panic | critical | feedback, concurrency, mutex, panic, rust |
| invalid DSN: {error} | exception | error | |
| Sentry rejected feedback upload with HTTP status {response_s | exception | error | |
| at least one search directory is required | validation | error | |
| git command `{command}` failed with status {status}: {stderr | exception | error | |
| git command `{command}` produced non-UTF-8 output | exception | error | |
| {path:?} is not a git repository | exception | error | |
| path {path:?} must be relative to the repository root | exception | error | |
| path {path:?} escapes the repository root | exception | error | |
| failed to process path inside worktree | exception | error | |
| failed to load required managed hooks: {} | exception | error | |
| Failed to read CA certificate file {} selected by {}: {sourc | exception | error | |
| Failed to load CA certificates from {} selected by {}: {deta | exception | error | |
| Failed to parse certificate #{certificate_index} from {} sel | exception | error | |
| Failed to build HTTP client while using CA bundle from {} ({ | exception | error | |
| Failed to build HTTP client while using system root certific | exception | error | |
| Failed to register certificate #{certificate_index} from {} | exception | error | |
| http {status}: {body:?} | http | error | |
| retry limit reached | exception | error | |
| timeout | exception | error | network, timeout, http, rust |
| connection failed: {0} | exception | error | network, connection, dns, tls, rust |
| network error: {0} | exception | error | network, http, reqwest, rust |
| request build error: {0} | exception | error | request, encoding, compression, rust |
| stream failed: {0} | exception | error | network, streaming, sse, rust |
| Failed to configure outbound proxy selected for {route_class | exception | error | proxy, configuration, env-vars, rust |
| failed to resolve the outbound proxy route: {0} | exception | error | proxy, async, tokio, rust |
| failed to build route-aware request: {0} | exception | error | request, http-headers, validation, rust |
| redirect target uses unsupported URL scheme: {0} | exception | error | http, redirect, url, rust |
| too many redirects | exception | error | http, redirects, network, rust |
| route-aware request timed out | exception | error | http, timeout, network, rust |
| failed to open bundled bubblewrap {}: {err} | panic | critical | rust, linux, sandbox, bubblewrap, panic, filesystem |
| invalid bundled bubblewrap fd path: {err} | panic | critical | rust, linux, sandbox, c-string, panic, unreachable |
| failed to exec bundled bubblewrap {} via {fd_path}: {err} | panic | critical | rust, linux, sandbox, bubblewrap, exec, permissions, panic |
| failed to normalize bundled bubblewrap path {}: {err} | panic | critical | rust, linux, path-resolution, sandbox, panic |
| invalid CODEX_BWRAP_SHA256 value: {err} | panic | critical | rust, build-config, env-var, sha256, sandbox, panic |
| failed to convert argv to CString: {err} | panic | critical | rust, c-string, argv, input-validation, panic |
| failed to read fd flags for preserved bubblewrap file descri | panic | critical | rust, linux, file-descriptor, fcntl, sandbox, panic |
| failed to clear CLOEXEC for preserved bubblewrap file descri | panic | critical | rust, linux, file-descriptor, fcntl, cloexec, race-condition, panic |
InvalidInput descriptor-backed mount must contain FD:DEST: {mount} | validation | error | linux-sandbox, bubblewrap, argument-validation, rust |
PermissionDenied descriptor-backed mount does not match its destination: {} | exception | error | linux-sandbox, file-descriptors, security, bubblewrap, rust |
| unsupported architecture for seccomp filter | panic | critical | seccomp, architecture, linux-sandbox, panic, rust |
| invalid legacy bubblewrap fd mount: {error} | panic | error | bubblewrap, linux-sandbox, argv, panic, rust |
| bubblewrap is unavailable: no system bwrap was found on PATH | panic | critical | bubblewrap, linux-sandbox, missing-dependency, panic, rust |
| failed to normalize system bubblewrap path {}: {err} | panic | error | bubblewrap, path, environment, linux-sandbox, panic |
| invalid system bubblewrap path: {err} | panic | error | |
| failed to exec system bubblewrap {program_path}: {err} | panic | error | |
| codex-linux-sandbox is only supported on Linux | panic | error | |
| No command specified to execute. | panic | error | |
| --verify-fd-mount is only supported in the inner sandbox sta | panic | error | |
| {err} | panic | error | |
| failed to verify descriptor-backed bubblewrap mount: {err} | panic | error | |
| failed to verify Linux sandbox capabilities: {} | panic | error | |
| Linux sandbox retained effective or permitted capabilities | panic | error | |
| managed proxy mode requires --proxy-route-spec | panic | error | |
| error activating Linux proxy routing bridge: {err} | panic | error | |
| error applying Linux sandbox restrictions: {e:?} | panic | error | |
| failed to fork sandboxed command: {err} | panic | error | |
| failed to reap sandboxed child: {err} | panic | error | |
| failed to prepare host proxy routing bridge: {err} | panic | error | |
| error applying legacy Linux sandbox restrictions: {e:?} | panic | error | |
| --apply-seccomp-then-exec is incompatible with --use-legacy- | panic | error | |
| permission profiles requiring direct runtime enforcement are | panic | error | |
| failed to fork for bubblewrap: {err} | panic | error | |
| failed to place bubblewrap child in its own process group: { | panic | critical | sandbox, bubblewrap, setpgid, process-group, seccomp, fork, linux |
| failed to create bubblewrap exec start pipe: {err} | panic | error | sandbox, bubblewrap, pipe, file-descriptor, emfile, resource-exhaustion |
| waitpid failed for bubblewrap child: {err} | panic | error | sandbox, waitpid, sigchld, child-process, double-reap, linux |
| failed to create synthetic bubblewrap mount marker directory | panic | error | sandbox, registry, tmpdir, permissions, filesystem, enospc, bubblewrap |
| failed to register synthetic bubblewrap mount target {}: {er | panic | error | sandbox, registry, marker-file, enospc, tmpfs, write-failure, bubblewrap |
| failed to create protected create marker directory {}: {err} | panic | error | sandbox, protected-create, registry, tmpdir, permissions, enospc |
| failed to register protected create target {}: {err} | panic | error | sandbox, protected-create, marker-file, enospc, tmpfs, write-failure |
| failed to read synthetic bubblewrap mount marker {}: {err} | panic | error | sandbox, registry, marker-file, permissions, read-failure, eio |
| failed to read synthetic bubblewrap mount marker directory { | panic | error | sandbox, registry, read-dir, enotdir, permissions, bubblewrap |
| failed to read synthetic bubblewrap mount marker in {}: {err | panic | error | sandbox, registry, read-dir, io-error, race, bubblewrap |
| failed to remove stale synthetic bubblewrap mount marker {}: | panic | error | |
| failed to unregister synthetic bubblewrap mount target {}: { | panic | error | |
| failed to remove synthetic bubblewrap mount marker directory | panic | error | |
| failed to unregister protected create target {}: {err} | panic | error | |
| failed to remove protected create marker directory {}: {err} | panic | error | |
| failed to remove protected create target {}: {err} | panic | error | |
| failed to inspect synthetic bubblewrap mount target {}: {err | panic | error | |
| failed to remove synthetic bubblewrap mount target {}: {err} | panic | error | |
| failed to create synthetic bubblewrap mount registry {}: {er | panic | error | |
| failed to open synthetic bubblewrap mount registry lock {}: | panic | error | |
| failed to lock synthetic bubblewrap mount registry {}: {err} | panic | error | |
| failed to unlock synthetic bubblewrap mount registry {}: {er | panic | error | |
| failed to resolve synthetic mount registry temp directory {} | panic | error | |
| failed to create stderr pipe for bubblewrap: {err} | panic | error | |
| failed to redirect stderr for bubblewrap: {err} | panic | error | |
| failed to read bubblewrap stderr: {err} | panic | error | |
| {context}: {err} | panic | error | |
| failed to resolve current executable path: {err} | panic | error | |
| Failed to convert arg to CString | panic | error | |
| Failed to execvp {}: {err} | panic | error | |
InvalidInput managed proxy mode requires parseable loopback proxy endpoints | exception | error | |
NotFound missing proxy env key {} | exception | error | |
AlreadyExists failed to allocate proxy routing temp dir under {} | exception | error | |
NotFound Built-in provider {LMSTUDIO_OSS_PROVIDER_ID} not found | exception | error | |
InvalidData oss provider must have a base_url | exception | error | |
| agent identity bootstrap unavailable after {attempts} attemp | exception | error | |
PermissionDenied Login is restricted to workspace id(s) {}. | exception | error | |
| a different workload identity configuration is already activ | exception | error | |
| the workload identity process-session registry is unavailabl | exception | error | |
| {0} | exception | error | |
NotFound device code login is not enabled for this Codex server. Use the browser login or | exception | error | |
| login error page template must parse: {err} | panic | error | |
AddrInUse Unable to determine the server port | exception | error | |
Interrupted Login cancelled | exception | error | |
| login error page template must render: {err} | panic | error | |
InvalidFormat invalid ID token format | exception | error | |
| either threadId or conversationId must be provided | validation | error | |
| error parsing -c overrides: {e} | validation | error | |
| error loading config: {e} | exception | error | |
| error loading otel config: {e} | exception | error | |
| workload identity is not supported by `codex mcp-server` | validation | error | |
| refusing to clear symlinked memory root {} | exception | error | |
| memory root cannot be a symbolic link: {} | validation | error | |
| removed {removed_symlinks} symbolic links from consolidated | validation | error | |
| consolidated memory artifact is not a file: {} | validation | error | |
| memory summary artifact does not start with v1: {} | validation | error | |
WouldBlock could not acquire shared history lock after multiple attempts | error_code | error | |
WouldBlock could not acquire exclusive lock on history file after multiple attempts | exception | error | |
| AWS auth refresh command must be `aws` | validation | error | |
| collaboration mode default template must parse: {err} | panic | critical | rust, codex, template, panic, lazy-init |
| collaboration mode default template must render: {err} | panic | critical | rust, codex, template, render, panic |
| unknown network proxy attribution token | exception | error | rust, codex, network-proxy, attribution, permission-denied |
| network proxy attribution environment mismatch | exception | error | rust, codex, network-proxy, attribution, environment, permission-denied |
| empty proxy connection | exception | warning | rust, codex, network-proxy, eof, connection, probe |
| invalid network proxy attribution frame | exception | error | rust, codex, network-proxy, protocol, magic-bytes, invalid-data |
| invalid network proxy attribution token length | exception | error | rust, codex, network-proxy, framing, length-prefix, invalid-data |
| network proxy attribution token is not UTF-8 | exception | error | rust, codex, network-proxy, utf-8, token, invalid-data |
| network proxy attribution frame timed out | exception | error | rust, codex, network-proxy, timeout, handshake, frame |
| network proxy attribution token is too long | exception | error | |
| failed to create cert params: {err} | exception | error | |
| failed to generate host key pair: {err} | exception | error | |
| failed to sign host cert: {err} | exception | error | |
| startup CA bundle contained no certificates: {} | exception | error | |
| startup CA bundle contained an invalid trusted certificate: | exception | error | |
| managed MITM CA cert path is missing a parent | exception | error | |
| managed MITM CA certificate path is missing a file name | exception | error | |
| refusing to use symlink lock file {} | exception | error | |
| failed to generate CA key pair: {err} | exception | error | |
| failed to generate CA cert: {err} | exception | error | |
| missing parent directory | exception | error | |
| refusing to overwrite existing file {} | exception | error | |
| refusing to reuse symlink {} | exception | error | |
| refusing to reuse existing mismatched file {} | exception | error | |
| expected an absolute path, got {socket_path:?} | validation | error | |
| network.proxy_url must use a fixed non-zero port for managed | validation | error | |
| network.socks_url must use a fixed non-zero port for managed | validation | error | |
| missing host in network proxy address: {url} | validation | error | |
| missing host in network proxy address: {input} | validation | error | |
| network target rejected by policy | exception | error | |
| unix sockets not supported | exception | error | |
| network.mitm_hooks requires network.mitm = true | validation | error | |
| network.mitm_hooks[{hook_index}].match.methods must not be e | validation | error | |
| network.mitm_hooks[{hook_index}].match.path_prefixes must no | validation | error | |
| network.mitm_hooks[{hook_index}].match.body is reserved for | validation | error | network, mitm, codex, config-validation, unsupported-feature |
| network.mitm_hooks[{hook_index}].host must not be empty | validation | error | network, mitm, codex, config-validation, required-field |
| missing required environment variable {env_var} | validation | error | network, mitm, codex, secrets, environment-variables, startup |
| expected exactly one of secret_env_var or secret_file | validation | error | network, mitm, codex, secrets, config-validation |
| path_prefixes must not contain empty entries | validation | error | network, mitm, codex, config-validation, path-matching |
| glob pattern must not be empty | validation | error | network, mitm, codex, config-validation, glob, path-matching |
| invalid glob pattern {pattern:?}: {err} | validation | error | network, mitm, codex, config-validation, glob, globset, path-matching |
| host must not be empty | validation | error | network, mitm, codex, config-validation, required-field, hostname |
| MITM hook hosts must be exact hosts and cannot contain wildc | validation | error | network, mitm, codex, config-validation, hostname, wildcard |
| methods must not contain empty entries | validation | error | network, mitm, codex, config-validation, http-methods |
| query keys must not be empty | validation | error | |
| query key {name:?} must list at least one allowed value | validation | error | |
| secret_env_var must not be empty | validation | error | |
| invalid header name {name:?}: {err} | validation | error | |
| secret_file must not be empty | validation | error | |
| secret_file must be an absolute path: {path:?} | validation | error | |
| host is empty | validation | error | |
| unsupported global wildcard domain pattern "*"; use exact ho | validation | error | |
| environment network policy requires an enabled executor prox | validation | error | |
| cannot update network.enabled on a running proxy | validation | error | |
| cannot update network.proxy_url on a running proxy | validation | error | |
| cannot update network.socks_url on a running proxy | validation | error | |
| cannot update network.enable_socks5 on a running proxy | validation | error | |
| cannot update network.enable_socks5_udp on a running proxy | validation | error | |
| execution-scoped network proxy is already running | exception | error | |
| shared managed Windows proxy route is already running | exception | error | |
| remote exec-server network proxy does not support MITM, cred | validation | error | |
| static config state cannot be reloaded | exception | error | |
| executor-local network proxy launch requires an enabled prox | exception | error | |
| invalid host | exception | error | |
| Request blocked by network policy. | exception | error | |
| network.credential_broker requires network.mitm = true | validation | error | |
| invalid value for {field_name}: {candidate} (allowed {allowe | validation | error | |
| network proxy route does not enable SOCKS5 | exception | error | |
| shared managed Windows SOCKS5 ingress stopped | exception | error | |
| proxy client token has no registered network proxy route SID | exception | error | |
| proxy client token has multiple registered network proxy rou | exception | error | |
Unsupported Windows proxy connection attribution currently supports IPv4 only | exception | error | |
InvalidData invalid IPv4 TCP owner table length | exception | error | |
NotFound accepted connection is absent from the IPv4 TCP owner table | exception | error | |
| {operation}: {error} | exception | error | |
NotFound Built-in provider {OLLAMA_OSS_PROVIDER_ID} not found | exception | error | |
| oss provider must have a base_url | panic | error | |
| configured span attribute key must not be empty | validation | error | |
| failed to read {}: {error} | exception | error | |
| failed to build OTLP metrics exporter | exception | error | |
| invalid OTLP metrics configuration: {message} | validation | error | |
| telemetry shutdown worker stopped before initializing | exception | error | |
InvalidInput invalid configured tracestate: {err} | validation | error | |
| {0} | validation | error | |
| plugin resource path `{path}` is outside package root `{root | validation | error | |
| Review prompt cannot be empty | validation | error | |
| {message} | exception | error | |
| provider auth cwd must resolve: {err} | panic | error | |
| sandbox denied exec error, exit code: {}, stdout: {}, stderr | exception | error | |
| seccomp setup error | exception | error | |
| seccomp backend error | exception | error | |
| command timed out | exception | error | |
| command was killed by a signal | exception | error | |
| Landlock was not able to fully enforce all sandbox rules | exception | error | |
| turn aborted. Something went wrong? Hit `/feedback` to repor | exception | error | |
| shared rollout token budget exhausted | exception | error | |
| stream disconnected before completion: {0} | exception | error | |
| Codex ran out of room in the model's context window. Start a | exception | error | |
| no thread with id: {0} | exception | error | |
| agent thread limit reached | exception | error | |
| session configured event was not the first event in the stre | exception | error | |
| timeout waiting for child process to exit | exception | error | |
| request timed out | exception | error | |
| spawn failed: child stdout/stderr not captured | exception | error | |
| interrupted (Ctrl-C). Something went wrong? Hit `/feedback` | exception | error | |
| {0} | exception | error | |
| duplicate tool: {0} | exception | error | |
| Image poisoning | exception | error | |
| Selected model is at capacity. Please try a different model. | exception | error | |
| {message} | exception | error | |
| Quota exceeded. Check your plan and billing details. | exception | error | |
| To use Codex with your ChatGPT plan, upgrade to Plus: https: | exception | error | |
| We're currently experiencing high demand, which may cause te | exception | error | |
| internal error; agent loop died unexpectedly | exception | error | |
| sandbox error: {0} | exception | error | |
| codex-linux-sandbox was required but not provided | exception | error | |
| unsupported operation: {0} | exception | error | rust, codex, protocol, bad-request, unsupported-feature |
| Fatal error: {0} | exception | critical | rust, codex, internal, unrecoverable, session |
| unsupported audio format | validation | error | rust, codex, audio, mime-type, validation, user-input |
| {kind} input exceeds {max_bytes} bytes | validation | error | rust, codex, file-size, limit, image, audio, user-input |
| externally enforced filesystem permissions cannot be interse | exception | error | rust, codex, sandbox, permissions, security, external |
| platform-default filesystem permissions cannot be intersecte | exception | error | rust, codex, sandbox, permissions, platform-defaults |
| unsupported permission path: {0} | exception | error | rust, codex, sandbox, permissions, path, canonicalization |
InvalidInput permissions profile requests filesystem writes outside the workspace root, which | exception | error | rust, sandbox, permissions, config-validation |
| Unsupported platform: ${process.platform} (${process.arch}) | exception | error | node, npm, platform-support, native-binary |
| upstream URL must include a host | exception | error | rust, url-validation, proxy, cli-args |
| creating HTTP server: {err} | exception | error | rust, http-server, startup, networking |
| server stopped unexpectedly | exception | error | rust, http-server, runtime-failure, networking |
| API key is too large to fit in the {BUFFER_SIZE}-byte buffer | validation | error | rust, stdin, api-key, input-validation |
| API key must be provided via stdin (e.g. printenv OPENAI_API | validation | error | rust, stdin, api-key, missing-credentials |
| API key may only contain ASCII letters, numbers, '-' or '_' | validation | error | rust, api-key, validation, charset |
BrokenPipe unknown process | exception | error | rust, mcp, transport, process-management |
WouldBlock process is starting | exception | warning | rust, mcp, stdio-transport, wouldblock, retry, process-startup |
InvalidData remote MCP server output stream lost process events: expected sequence {expected | exception | error | rust, mcp, stdio-transport, sequence-gap, broadcast-channel, data-loss |
| streamable HTTP session expired with 404 Not Found | exception | error | rust, mcp, streamable-http, http-404, session-expired |
| invalid HTTP header: {0} | validation | error | rust, mcp, http-headers, header-value, invalid-characters |
| MCP response body exceeds {maximum_bytes} bytes | exception | error | rust, mcp, streamable-http, response-size, memory-limit |
InvalidData oversized MCP SSE event was already rejected | exception | error | rust, mcp, sse, size-limit, sticky-error |
| MCP HTTP headers helper containment failed: {error} | exception | error | rust, mcp, windows, job-object, containment, headers-helper |
| MCP HTTP headers helper failed to start: {error} | exception | error | rust, mcp, windows, process-spawn, headers-helper, cmd, env-clear |
| MCP HTTP headers helper process id was unavailable | exception | error | rust, mcp, unix, process-exit, race, headers-helper |
| MCP HTTP headers helper stdout was unavailable | exception | error | rust, mcp, internal-invariant, stdout, headers-helper |
| MCP HTTP headers helper exited with status {status} | exception | error | rust, mcp, headers-helper, exit-status, credentials |
| MCP HTTP headers helper wrote non-UTF-8 data | exception | error | rust, mcp, headers-helper, utf-8, encoding |
| MCP HTTP headers helper must output a JSON object of strings | exception | error | rust, mcp, headers-helper, json, shape-validation |
| MCP HTTP headers helper returned duplicate header names | exception | error | rust, mcp, headers-helper, duplicate-keys, http-headers |
| MCP HTTP headers helper returned an invalid header name | exception | error | rust, mcp, headers-helper, header-name, invalid-token |
| MCP HTTP headers helper returned a reserved header | exception | error | rust, mcp, headers-helper, reserved-headers, http-headers, authorization |
| MCP HTTP headers helper returned an invalid header value | exception | error | |
| MCP stdin closed | exception | error | |
| OAuth issuer-bound callbacks require an authorization server | exception | error | |
| OAuth authorization endpoint origin does not match the autho | exception | error | |
| OAuth token endpoint origin does not match the authorization | exception | error | |
| timed out after {acquire_timeout:?} waiting for OAuth refres | exception | error | |
| timed out after {refresh_request_timeout:?} refreshing OAuth | exception | error | |
| failed to resolve CODEX_HOME for MCP OAuth {store} aggregate | exception | error | |
| failed to create MCP OAuth {store} aggregate-store lock dire | exception | error | |
| failed to open MCP OAuth {store} aggregate-store lock {} | exception | error | |
| timed out after {acquire_timeout:?} waiting for MCP OAuth {s | exception | error | |
| failed to lock MCP OAuth {store} aggregate-store lock {} | exception | error | |
| failed to write OAuth tokens to keyring: {} | exception | error | |
| executor OAuth credential key conflicts with a host-owned cr | exception | error | |
| credentials path is not a regular file | exception | error | |
| MCP authorization server does not advertise CIMD with token | exception | error | |
| MCP OAuth CIMD requires an ephemeral loopback callback at `/ | exception | error | |
| unsupported OAuth HTTP redirect policy | exception | error | |
| OAuth HTTP request timed out | exception | error | |
| OAuth HTTP request exceeded {MAX_OAUTH_HTTP_REDIRECTS} redir | exception | error | |
| OAuth HTTP response body exceeds {maximum_bytes} bytes | exception | error | |
| OAuth authorization server issuer does not match authorizati | exception | error | |
| OAuth login task was cancelled: {err} | exception | error | |
| invalid MCP OAuth callback port `{config_port}`: port must b | validation | error | |
| unable to determine callback address | exception | error | |
| MCP server URL `{server_url}` must include a host | validation | error | |
| OAuth provider did not return credentials | exception | error | |
| unsupported CODEX_MCP_PROTOCOL_VERSION `{}` for stdio MCP se | validation | error | |
| timed out awaiting {label} after {duration:.0?} | exception | error | |
| client already initializing | exception | error | |
| client already initialized | exception | error | |
| MCP client is shut down | exception | error | |
| handshake succeeded but server info was missing | exception | error | |
| MCP tool arguments must be a JSON object, got {other} | validation | error | |
| MCP tool request _meta must be a JSON object, got {other} | validation | error | |
| MCP client not initialized | exception | error | |
| OAuth credential store pinned concurrently for MCP server `{ | exception | error | |
| OAuth credential loading task failed: {error} | exception | error | |
| timed out handshaking with MCP server after {duration:?} | exception | error | |
| MCP client recovery semaphore closed | exception | error | |
| MCP client cannot recover before initialize succeeds | exception | error | |
| recovered handshake succeeded but server info was missing | exception | error | |
| {label} must be valid Unicode for remote MCP stdio | validation | error | |
| timed out handshaking with MCP server after {duration:?} | exception | error | |
| handshaking with MCP server failed: {source} | exception | error | |
| env_vars entry `{}` uses source `remote`, which requires rem | validation | error | |
| empty session file: {} | exception | error | |
| rollout missing metadata builder: {} | exception | error | |
| failed to read backfill state at {}: {err} | exception | error | |
| failed to read backfill state at {} after startup backfill: | exception | error | |
| timed out waiting for state db backfill at {} after {:?} (st | exception | error | |
| duplicate code cell start for {code_cell_id} | exception | error | |
| duplicate code cell start for {} | exception | error | |
| code cell start {} did not include a Codex turn id | exception | error | |
| code cell initial response referenced unknown cell {code_cel | exception | error | |
| code cell end referenced unknown cell {code_cell_id} | exception | error | |
| wait tool request payload {} did not contain function argume | exception | error | |
| wait tool request payload {} did not contain cell_id | exception | error | |
| {event_name} {runtime_cell_id} did not include a thread id | exception | error | |
| runtime code cell {runtime_cell_id} in thread {thread_id} ma | exception | error | |
| code cell start referenced unknown thread {thread_id} | exception | error | |
| code cell start referenced unknown Codex turn {codex_turn_id | exception | error | |
| code cell start used thread {thread_id}, but Codex turn {cod | exception | error | |
| code cell {code_cell_id} disappeared during output linking | exception | error | |
| conversation item {item_id} disappeared during code-cell out | exception | error | |
| duplicate compaction request start for {} | exception | error | |
| compaction request {} referenced unknown codex turn {} | exception | error | |
| compaction request {} used thread {}, but codex turn {} belo | exception | error | |
| compaction request completion referenced unknown request {co | exception | error | |
| compaction request {compaction_request_id} completion used c | exception | error | |
| duplicate compaction install for {compaction_id} | exception | error | |
| compaction install {compaction_id} referenced unknown codex | exception | error | |
| compaction install {compaction_id} used thread {thread_id}, | exception | error | |
| model item in payload {} did not contain a string type | exception | error | |
| unsupported model item type {item_type} in payload {} | exception | error | |
| message item in payload {} did not contain a string role | exception | error | |
| unsupported message role {role} in payload {} | exception | error | |
| item in payload {raw_payload_id} was not an agent_message | exception | error | |
| agent_message item in payload {raw_payload_id} contained no | exception | error | |
| reasoning item in payload {} had non-string encrypted_conten | exception | error | |
| reasoning item in payload {} contained no content, summary, | exception | error | |
| reasoning item in payload {} had non-array {key} | exception | error | |
| reasoning item in payload {} had {key} entry without string | exception | error | |
| reasoning item in payload {} had unsupported content type {i | exception | error | |
| reasoning item in payload {} had unsupported summary type {i | exception | error | |
| reasoning item in payload {} had {expected_type} entry witho | exception | error | |
| compaction item in payload {} did not contain string encrypt | exception | error | |
| inference request payload {} did not contain input | exception | error | |
| inference request payload {} had non-array input | exception | error | |
| incremental inference request {inference_call_id} referenced | exception | error | |
| inference response payload {} did not contain output_items | exception | error | |
| inference response referenced unknown call {inference_call_i | exception | error | |
| model conversation mismatch while reducing turn {codex_turn_ | exception | error | |
| conversation item {item_id} was referenced before it was cre | exception | error | |
| model-visible call id {call_id} was reused with different co | exception | error | |
| reasoning item merge attempted with different encrypted_cont | exception | error | |
| duplicate inference start for {} | exception | error | |
| inference start {inference_call_id} referenced unknown codex | exception | error | |
| inference start {inference_call_id} used thread {thread_id}, | exception | error | |
| inference completion referenced unknown call {inference_call | exception | error | |
| compaction installed event {compaction_id} did not include a | exception | error | |
| compaction installed event {compaction_id} did not include a | exception | error | |
| raw trace event has no reducer implementation | exception | error | |
| duplicate thread start for {thread_id} | exception | error | |
| duplicate codex turn start for {codex_turn_id} | exception | error | |
| codex turn end for {codex_turn_id} used thread {event_thread | exception | error | |
| codex turn end referenced unknown turn {codex_turn_id} | exception | error | |
| sub-agent activity {:?} does not match tool call kind {tool_ | exception | error | |
| pending interaction edge {} was observed with conflicting de | exception | error | |
| non-spawn interaction edge {} carried a spawn fallback targe | exception | error | |
| interaction edge {} was observed with conflicting endpoints | exception | error | |
| terminal end referenced unknown operation {operation_id} | exception | error | |
| terminal operation {operation_id} changed process id from {e | exception | error | |
| terminal session {terminal_id} disappeared during reduction | exception | error | |
| terminal session {terminal_id} belongs to thread {}, not {th | exception | error | |
| tool call {tool_call_id} disappeared during terminal observa | exception | error | |
| terminal operation {operation_id} disappeared during observa | exception | error | |
| dispatch terminal request is for {}, not write_stdin | exception | error | |
| write_stdin dispatch payload used unsupported {} payload | exception | error | |
| duplicate tool call start for {tool_call_id} | exception | error | |
| MCP correlation referenced unknown tool call {tool_call_id} | exception | error | |
| duplicate MCP correlation for tool call {tool_call_id} | exception | error | |
| tool call end referenced unknown call {tool_call_id} | exception | error | |
| tool runtime start referenced unknown call {tool_call_id} | exception | error | |
| tool runtime start would create a second terminal operation | exception | error | |
| tool call {tool_call_id} disappeared during runtime start re | exception | error | |
| tool runtime end referenced unknown call {tool_call_id} | exception | error | |
| tool call start did not include thread or Codex turn context | exception | error | |
| tool call start referenced unknown thread {thread_id} | exception | error | |
| tool call start referenced unknown Codex turn {codex_turn_id | exception | error | |
| tool call start used thread {thread_id}, but Codex turn {cod | exception | error | |
| duplicate tool call for model-visible call id {model_visible | exception | error | |
| multiple tool calls matched model-visible call id {model_vis | exception | error | |
| tool call {tool_call_id} disappeared during conversation lin | exception | error | |
| tool call {tool_call_id} disappeared during output linking | exception | error | |
| conversation item {item_id} disappeared during output linkin | exception | error | |
| failed to serialize permission profile: {err} | panic | error | |
| cwd must be valid UTF-8 | panic | error | |
| command cwd must be valid UTF-8 | panic | error | |
| Windows sandbox process spawn is unavailable on this platfor | exception | error | |
| secret name must not be empty | validation | error | |
| secret name must contain only A-Z, 0-9, or _ | validation | error | |
| environment id must not be empty | validation | error | |
| secret value must not be empty | validation | error | |
| secrets file version {} is newer than supported version {} | validation | error | |
| failed to load secrets key from keyring for {account} | exception | error | |
| failed to persist secrets key in keyring | exception | error | |
| {ESCALATE_SOCKET_ENV_VAR} is not a valid file descriptor: {c | exception | error | |
| mismatched number of fds in SuperExecMessage: {} in the mess | exception | error | |
| prepared escalated command must not be empty | exception | error | |
| socket closed while receiving frame header | exception | error | |
| socket closed while receiving frame payload | exception | error | |
| short datagram write: wrote {written} bytes out of {} | exception | error | |
| message too large: {len} | exception | error | |
| too many fds: {} | exception | error | |
| socket closed while sending frame payload | exception | error | |
| io error while {action}: {source} | exception | error | |
| missing YAML frontmatter delimited by --- | exception | error | |
| invalid YAML: {0} | exception | error | |
| missing field `{0}` | exception | error | |
| invalid {field}: {reason} | exception | error | |
| invalid backfill status: {value} | exception | error | |
| invalid unix timestamp: {secs} | exception | error | |
| rollout migration state has incomplete last checked thread | exception | error | |
| unknown thread goal status `{other}` | exception | error | |
| thread references an unknown section: {id} | exception | error | |
| thread has a section name without a section id: {name} | exception | error | |
| invalid unix timestamp millis: {value} | exception | error | |
| invalid unix timestamp seconds: {value} | exception | error | |
| project not found: {project_id} | validation | error | |
| idempotency key refers to deleted project: {idempotency_key} | validation | error | |
| thread not found: {thread_id} | validation | error | |
| project {project_id} cannot be moved before itself | validation | error | |
| before project not found: {before_project_id} | validation | error | |
| invalid project cursor: {cursor} | validation | error | |
InvalidInput queue reorder must include every queued submission exactly once | validation | error | |
| invalid unix timestamp millis: {millis} | exception | error | |
| before thread cannot be specified without a section | validation | error | |
| section {section} does not exist | validation | error | |
| thread {thread_id} cannot be moved before itself | validation | error | |
| before thread {before_thread_id} is not in section {section} | validation | error | |
| section {section} has no remaining thread positions | exception | error | |
| built-in pinned thread section cannot be renamed | validation | error | |
| built-in pinned thread section cannot be deleted | validation | error | |
| multiple agents found for canonical path `{agent_path}` | exception | error | |
| thread {thread_id} not found | exception | error | |
| invalid thread-store request: {message} | exception | error | |
| thread-store conflict: {message} | exception | error | |
| thread-store unsupported operation: {operation} | exception | error | |
| thread-store internal error: {message} | exception | error | |
| {0} | exception | error | |
| Fatal error: {0} | exception | error | |
| tool input schema must not be a singleton null type | validation | error | |
| {err:#} | exception | error | |
| this app server does not support confirmed permission change | exception | error | |
| Cannot safely retry a turn whose input exceeds the bounded h | exception | error | |
| pet frame dimensions and grid counts must be non-zero | validation | error | |
| pet frame grid must cover spritesheet exactly: expected {spr | validation | error | |
| pet frame count {frame_count} exceeds maximum {MAX_PET_FRAME | validation | error | |
| animation {name} must include at least one frame | validation | error | |
| animation {name} references sprite index {sprite_index}, but | validation | error | |
| animation {name} fps must be finite and between 0 and {MAX_A | validation | error | |
| animation {name} references sprite index {}, but pet has {fr | validation | error | |
| animation {name} fallback {} does not exist | validation | error | |
| failed to determine the working directory recorded for the s | exception | error | |
| terminal input stream closed during startup | exception | error | |
| failed to initialize sqlite local db at {}: {detail} | exception | error | |
| status history rate-limit state poisoned | panic | error | |
| status history agents summary state poisoned | panic | error | |
| status history thread-usage state poisoned | panic | error | |
TimedOut timed out discarding buffered terminal input | exception | error | |
Unsupported keyboard enhancement reset is not implemented for the legacy Windows API | exception | error | |
| terminal stderr suppression is already active | exception | error | |
| path must be absolute: {} | validation | error | |
| path does not exist: {} | validation | error | |
| path must be a directory: {} | validation | error | |
AlreadyExists socket directory path exists and is not a directory: {} | exception | error | |
InvalidInput path is not absolute: {} | validation | error | |
| CODEX_HOME points to {val:?}, but that path does not exist | exception | error | |
| failed to read CODEX_HOME {val:?}: {err} | exception | error | |
| CODEX_HOME points to {val:?}, but that path is not a directo | exception | error | |
| failed to canonicalize CODEX_HOME {val:?}: {err} | exception | error | |
| Could not find home directory | exception | error | |
| failed to read image at {path}: {source} | exception | error | |
| failed to decode image at {path}: {source} | exception | error | |
| failed to encode image as {format:?}: {source} | exception | error | |
| unsupported image `{mime}` | validation | error | |
| invalid image data URL: {reason} | validation | error | |
| image {representation} is too large ({size} bytes; max {max} | validation | error | |
| opaque fallback path URI `{path}` cannot be recovered as a n | exception | error | |
| path URI `{path}` cannot be rendered using {convention} path | exception | error | |
| path `{path}` is not absolute{convention} | exception | error | |
| '{path}' is invalid on '{os}' | validation | error | |
| invalid URI: {0} | exception | error | |
| unsupported path URI scheme `{0}` | exception | error | |
| credentials are not allowed in path URIs | exception | error | |
| ports are not allowed in path URIs | exception | error | |
| query parameters are not allowed in path URIs | exception | error | |
| fragments are not allowed in path URIs | exception | error | |
| path `{0}` must be relative when joining a path URI | exception | error | |
| path {} has no parent directory | exception | error | |
| missing program for pipe spawn | validation | error | |
| process interrupt is not supported by this process backend | exception | error | |
| process is not attached to a PTY | exception | error | |
| missing program for PTY spawn | exception | error | |
| failed to openpty: {:?} | exception | error | |
| writer already taken | exception | error | |
| InitializeProcThreadAttributeList failed: {} | exception | error | |
| UpdateProcThreadAttribute failed: {} | exception | error | |
| failed to create psuedo console: HRESULT {result} | exception | error | |
| failed to resize console to {}x{}: HRESULT: {} | exception | error | |
| CreateProcessW `{:?}` in cwd `{:?}` failed: {} | exception | error | |
| missing program name | exception | error | |
| invalid encoding for command line argument {arg:?} | validation | error | |
TokenLockFailed Failed to acquire readiness token lock | exception | error | |
FlagAlreadyReady Flag is already ready. Impossible to subscribe | exception | error | |
| could not resolve to any address | exception | error | |
| {operation} failed for {}: {code} | exception | error | |
| CreateFileW failed for {} | exception | error | |
| GetSecurityInfo failed for {}: {} | exception | error | |
| SetNamedSecurityInfoW failed: {code3} | exception | error | |
| SetEntriesInAclW failed: {code2} | exception | error | |
| GetNamedSecurityInfoW failed: {code} | exception | error | |
| GetNamedSecurityInfoW failed for {}: {code} | exception | error | |
| errors.join("; ") | exception | error | |
| CreateFileW failed for pipe {name}: {err} | exception | error | |
| runner: pipe closed before spawn_request | exception | error | |
| runner: unsupported protocol version {} | exception | error | |
| runner: expected spawn_request, got {other:?} | exception | error | |
| OpenMutexW failed: {err} | exception | error | |
| runner: empty capability SID list | exception | error | |
| runner: no pipe-in provided | validation | error | |
| runner: no pipe-out provided | validation | error | |
| runner spawn_ready write failed: pipe_write lock poisoned | exception | error | |
HelperFirewallComInitFailed CoInitializeEx failed: {hr:?} | error_code | error | |
HelperFirewallPolicyAccessFailed CoCreateInstance NetFwPolicy2 failed: {err:?} | error_code | error | |
HelperFirewallRuleCreateOrAddFailed Rules::Remove failed for {internal_name}: {err:?} | error_code | error | |
HelperFirewallPolicyIneffective local firewall policy modifications do not apply to every current profile: Local | error_code | error | |
HelperFirewallRuleVerifyFailed LocalUserAuthorizedList (read-back) failed: {err:?} | error_code | error | |
| sandbox ACL path must be absolute: {} | validation | error | |
| sandbox ACL path must have a local disk prefix: {} | validation | error | |
| sandbox ACL path contains a reparse point: {} | validation | error | |
| NtCreateFile returned an invalid sandbox ACL directory handl | exception | error | |
| OpenMutexW failed: {err} | exception | error | |
| CreateMutexW failed: {} | exception | error | |
HelperUserCreateOrUpdateFailed failed to create/update user {name}, code {status}/{upd} | error_code | error | |
HelperUsersGroupCreateFailed failed to create local group {name}, code {status} | error_code | error | |
| LookupAccountNameW failed for {name}: {err} | exception | error | |
| ConvertStringSidToSidW failed for {sid_str}: {} | exception | error | |
| GetLengthSid failed for {sid_str} | exception | error | |
| CopySid failed for {sid_str} | exception | error | |
| LookupAccountSidW preflight failed for {sid_str}: {err} | exception | error | |
| LookupAccountSidW failed for {sid_str}: {} | exception | error | |
| ConvertStringSidToSidW failed: {} | exception | error | |
HelperUsersFileWriteFailed failed to create secrets dir {}: {err} | error_code | error | |
HelperDpapiProtectFailed dpapi protect failed for offline user: {err} | error_code | error | |
HelperSetupMarkerWriteFailed remove setup marker file {} failed: {err} | error_code | error | |
HelperLogFailed failed to write setup log line: {err} | error_code | error | |
| ConvertStringSidToSidW failed: {} | exception | error | |
| SetEntriesInAclW sandbox dir failed: {set} | exception | error | |
| {api} sandbox dir failed: {res} | exception | error | |
HelperRequestArgsFailed expected payload argument | error_code | error | |
HelperSandboxDirCreateFailed failed to create sandbox dir {}: {err} | error_code | error | |
| read ACL run had errors | exception | error | |
HelperUserProvisionFailed provision sandbox users failed: {err} | error_code | error | |
HelperFirewallRuleCreateOrAddFailed ensure offline proxy allowlist failed: {err} | error_code | error | |
HelperSandboxLockFailed lock sandbox dir {} failed: {err} | error_code | error | |
HelperSidResolveFailed resolve SID for offline user {} failed: {err} | error_code | error | |
HelperReadAclHelperSpawnFailed spawn read ACL helper failed: {err} | error_code | error | |
| convert write root capability SID failed | exception | error | |
| convert SID failed | exception | error | |
| convert deny capability SID failed | exception | error | |
| setup refresh had errors | exception | error | |
| CreateDesktopW failed: {err} | exception | error | |
| SetEntriesInAclW failed for private desktop: {set_entries_co | exception | error | |
| SetSecurityInfo failed for private desktop: {set_security_co | exception | error | |
| CryptProtectData failed: {} | exception | error | |
| CryptUnprotectData failed: {} | exception | error | |
| frame too large: {} | exception | error | |
| frame too large: {len} | exception | error | |
| runner pipe closed before spawn_ready | exception | error | |
| expected spawn_ready from runner, got {other:?} | exception | error | |
| runner {pipe_label} connect thread exited before reporting i | exception | error | |
| DuplicateHandle failed for runner {pipe_label_for_thread} co | exception | error | |
| runner {pipe_label} connect thread exited before publishing | exception | error | |
| CancelSynchronousIo failed for runner {pipe_label} connect t | exception | error | |
| timed out after {}ms connecting runner {pipe_label} | exception | error | |
| PeekNamedPipe failed while waiting for spawn_ready: {err} | exception | error | |
| runner frame length overflow | exception | error | |
| timed out after {}ms waiting for runner spawn_ready | exception | error | |
PermissionDenied LookupAccountNameW failed for {name}: {err} | exception | error | |
| workspace-write sandbox has no writable root capability SIDs | exception | error | |
| runner pipe closed before exit | exception | error | |
| runner error: {} | exception | error | |
| unexpected runner message during capture: {other:?} | exception | error | |
| Windows sandbox is only available on Windows | exception | error | |
| no home dir | exception | error | |
| helper not found next to current executable or under {RESOUR | exception | error | |
| helper destination has no parent: {} | exception | error | |
| RegCreateKeyExW failed: {status} ({error}) | exception | error | |
| GetFileAttributesW failed for {}: {err} ({error}) | exception | error | |
| SetFileAttributesW failed for {}: {err} ({error}) | exception | error | |
| Windows sandbox setup is missing or out of date; rerun the s | exception | error | |
| Restricted read-only access requires the elevated Windows sa | exception | error | |
| deny-read overrides require the elevated Windows sandbox bac | exception | error | |
| Windows sandbox is only available on Windows | exception | error | |
| GetStdHandle failed: {} | exception | error | |
| SetHandleInformation failed: {} | exception | error | |
| SetHandleInformation failed for stdio handle: {} | exception | error | |
| CreatePipe stdin failed: {} | exception | error | |
| CreatePipe stdout failed: {} | exception | error | |
| CreatePipe stderr failed: {} | exception | error | |
| permission profile requests full-disk filesystem writes, whi | exception | error | |
| only managed permission profiles can be enforced by the Wind | exception | error | |
| only restricted managed filesystem permissions can be enforc | exception | error | |
| unsupported filesystem permissions for Windows sandbox setup | validation | error | |
| AllocateAndInitializeSid failed: {} | exception | error | |
| CheckTokenMembership failed: {} | exception | error | |
| workspace-write sandbox has no writable root capability SIDs | exception | error | |
| readonly capability SID string missing | exception | error | |
| SetEntriesInAclW failed: {res} | exception | error | |
| SetTokenInformation(TokenDefaultDacl) failed: {err} | exception | error | |
| CreateWellKnownSid failed: {} | exception | error | |
| invalid SID string: {sid} | exception | error | |
| OpenProcessToken failed: {} | exception | error | |
| Logon SID not present on token | exception | error | |
| TokenUser size query returned 0 | exception | error | |
| GetTokenInformation(TokenUser) failed: {} | exception | error | |
| GetLengthSid(TokenUser) failed: {} | exception | error | |
| CopySid(TokenUser) failed: {} | exception | error | |
| LookupPrivilegeValueW failed: {} | exception | error | |
| AdjustTokenPrivileges failed: {} | exception | error | |
| AdjustTokenPrivileges error {err} | exception | error | |
| no capability SIDs provided | exception | error | |
| CreateRestrictedToken failed: {} | exception | error | |
| runner handshake task failed: {err} | exception | error | |
| spawned ConPTY is missing its process job | exception | error | |
| separate stderr handle should be present | exception | error | |
| separate stderr channel should be present | exception | error | |
| WriteFile failed: {err} | exception | error | |
| WriteFile returned success but wrote 0 bytes | exception | error | |
| failed to lock ConPTY handle | exception | error | |
| process is not attached to a PTY | exception | error | |
| failed to resize console: HRESULT {result} | exception | error | |
| Restricted read-only access requires the elevated Windows sa | exception | error | |
| deny-read overrides require the elevated Windows sandbox bac | exception | error | |
| runner resize pipe closed | exception | error | |
| managed networking requires the elevated Windows sandbox bac | exception | error | |
| network proxy restricting SID requires the elevated Windows | exception | error | |
| {operation} failed: {} | exception | error | |
| failed to initialize WFP setup metrics provider: {err} | exception | error | |
| LookupAccountNameW failed for {name}: {err} | exception | error | |
| ConvertStringSidToSidW failed for {sid_str}: {} | exception | error | |
| GetLengthSid failed for {sid_str} | exception | error | |
| CopySid failed for {sid_str} | exception | error | |
| missing sandboxed command in windows sandbox wrapper request | validation | error | |
| unexpected windows sandbox wrapper argument: {arg} | validation | error | |
| missing required {CODEX_HOME_FLAG} | validation | error | |
| {CODEX_HOME_FLAG} must be absolute: {} | validation | error | |
| missing required {COMMAND_CWD_FLAG} | validation | error | |
| missing required {ENV_JSON_FLAG} | validation | error | |
| missing required {PERMISSION_PROFILE_FLAG} | validation | error | |
| missing required {SANDBOX_LEVEL_FLAG} | validation | error | |
| missing sandboxed command separator -- | validation | error | |
| missing value for {flag} | validation | error | |
| invalid windows sandbox level: {value} | validation | error | |
| the workload identity federation rule ID must not be empty | exception | error | |
| the workload identity assertion file path must be absolute | exception | error | |
| the workload identity assertion is invalid | exception | error | |
| the workload identity assertion exceeds 16 KiB | exception | error | |
| could not read workload identity assertion file {path} | exception | error | |
| could not configure the workload identity HTTP client | exception | error | |
| the workload identity token URL must use HTTPS or loopback H | exception | error | |
| the workload identity token exchange is unavailable | exception | error | |
| the workload identity token exchange was rejected with HTTP | exception | error | |
| the workload identity token exchange returned an invalid res | exception | error | |
| approval_mode must be one of: {supported} | exception | error | |
| the connected Codex runtime did not activate goal mode for t | exception | error | |
| initialize response missing required metadata (user_agent={u | exception | error | |
| unsupported input item: {type(item)!r} | exception | error | |
| unexpected ChatGPT login response: {response_root!r} | exception | error | |
| unexpected device-code login response: {response_root!r} | exception | error | |
| login {login_id!r} is not registered for waiting | exception | error | |
| turn {turn_id!r} is not registered for streaming | exception | error | |
| thread {state.thread_id!r} already has an active goal operat | exception | error | |
| turn.error.message | exception | error | |
| turn failed with status {turn.status.value} | exception | error | |
| turn completed event not received | exception | error | |
| sandbox must be one of: {options} | exception | error | |
| AsyncCodex is not initialized yet. Prefer `async with AsyncC | exception | error | |
| Expected generated params model or dict, got {type(params)._ | exception | error | |
| Unable to locate the pinned Codex runtime. Install the publi | exception | error | |
| Codex binary not found at {codex_bin}. Set CodexConfig.codex | exception | error | |
| {method} response must be a JSON object | exception | error | |
-32600 thread must be idle before starting a goal: {thread_id} | exception | error | |
| timed out waiting for goal turn to start after {int(_GOAL_ST | exception | error | |
| Codex process is not running | exception | error | |
| Codex process closed stdout. stderr_tail={self._stderr_tail( | exception | error | |
| Invalid JSON-RPC line: {line!r} | exception | error | |
| Invalid JSON-RPC payload: {message!r} | exception | error | |
| max_attempts must be >= 1 | validation | error | |
| {PACKAGE_NAME} is installed but missing its package metadata | exception | error | |
| {PACKAGE_NAME} is installed but missing its packaged codex b | exception | error | |
| Child process has no stdin | exception | error | |
| Child process has no stdout | exception | error | |
| Codex Exec exited with ${detail}: ${stderrBuffer.toString("u | exception | error | |
| Codex config overrides must be a plain object | validation | error | |
| Codex config override keys must be non-empty strings | validation | error | |
| Codex config override at ${path} must be a finite number | validation | error | |
| Codex config override at ${path} cannot be null | validation | error | |
| Unsupported Codex config override value at ${path}: ${typeNa | validation | error | |
| Unsupported platform: ${platform} (${arch}) | exception | error | |
| Unsupported target triple: ${targetTriple} | exception | error | |
| Unable to locate Codex CLI binaries. Ensure ${CODEX_NPM_NAME | exception | error | |
| Unable to locate Codex CLI binaries for ${targetTriple}. Ens | exception | error | |
| outputSchema must be a plain JSON object | validation | error | |
| Failed to parse item: ${item} | exception | error | |
| ${turnFailure.message} | exception | error | |