A Locked-Down Codex Profile Can Refuse AGENTS.md and Call the Session Corrupt
Codex fails thread start when the sandbox cannot read AGENTS.md, and the error text can blame the sessions directory.
Direct answer
Since Codex rust-v0.149.0, a permission profile that cannot read the working directory fails session start when AGENTS.md is present, and the wrapper can report the sessions directory as corrupt.
Codex treats AGENTS.md as project instructions, and since rust-v0.149.0 it reads that file under the sandbox of the selected environment. If the permission profile cannot read the working directory, a folder that contains AGENTS.md fails before the first turn.
GitHub issue 40937 says the failure is real and the message is not. The wrapper in session startup reports the sessions directory as corrupt or unreadable, even though the read that failed was AGENTS.md. The behavior comes from pull request 39653, merged on 20 August 2026. That change applies each environment's filesystem sandbox while discovering and reading instruction files, and it fails thread or turn setup when sandboxing blocks a discovered file. A restricted project with no instruction file is still allowed to start. Cached instructions are cleared on refresh so a tighter profile cannot keep serving an older copy.
What the report asks Codex to do
The issue argues for a skip, not a hard stop: start the session, warn that the profile denied the read, and name the profile and the path. The alternative it accepts is a fail-closed error that says the profile blocked AGENTS.md, not that session data is corrupt. One workaround named in the report is to set project_doc_max_bytes to 0 so instructions are not loaded.
For a harness, the instruction file is now inside the permission boundary. A profile that cannot see the repo cannot silently load the repo's rules, and today it may also refuse to start.
Source: Codex issue 40937.
FAQ
- Which change introduced the failure?
- Pull request 39653, merged 20 August 2026, applies the environment sandbox while discovering AGENTS.md and fails setup when that read is blocked.
- What does the issue ask for instead?
- Start the session, skip the file, and say which profile denied the read, rather than claiming session data is corrupt.