openai/codex · error · anyhow::Error
permission profile requests full-disk filesystem writes, whi
Error message
permission profile requests full-disk filesystem writes, which cannot be enforced by the Windows sandbox
What it means
Error "permission profile requests full-disk filesystem writes, which cannot be enforced by the Windows sandbox" thrown in openai/codex.
Source
Thrown at codex-rs/windows-sandbox-rs/src/resolved_permissions.rs:50
pub enum WindowsSandboxTokenMode {
ReadOnlyCapability,
WritableRootsCapability,
}
/// Chooses the restricted-token family needed for a managed permission profile.
pub fn token_mode_for_permission_profile(
permission_profile: &PermissionProfile,
workspace_roots: &[AbsolutePathBuf],
cwd: &Path,
env_map: &HashMap<String, String>,
) -> Result<WindowsSandboxTokenMode> {
let permissions =
ResolvedWindowsSandboxPermissions::try_from_permission_profile_for_workspace_roots(
permission_profile,
workspace_roots,
)?;
if permissions.file_system.has_full_disk_write_access() {
anyhow::bail!(
"permission profile requests full-disk filesystem writes, which cannot be enforced by the Windows sandbox"
);
}
if permissions.writable_roots_for_cwd(cwd, env_map).is_empty() {
Ok(WindowsSandboxTokenMode::ReadOnlyCapability)
} else {
Ok(WindowsSandboxTokenMode::WritableRootsCapability)
}
}
impl ResolvedWindowsSandboxPermissions {
pub fn try_from_permission_profile(permission_profile: &PermissionProfile) -> Result<Self> {
if !matches!(permission_profile, PermissionProfile::Managed { .. }) {
anyhow::bail!(
"only managed permission profiles can be enforced by the Windows sandbox"
);
}
let (file_system, network) = permission_profile.to_runtime_permissions();View on GitHub (pinned to 339751715c)
When it happens
Trigger: Thrown at codex-rs/windows-sandbox-rs/src/resolved_permissions.rs:50 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of openai/codex@339751715c (2026-08-25).
Data as JSON: /api/errors/1d1b9b16581359f8.
Report an issue: GitHub.