Remote Control fails on Windows with socket directory is not private to the current user
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 75/100
Research direction
Search the Rust codebase for the code that creates the app-server-control socket directory under the user's .codex folder on Windows, or the error message stating the socket directory is not private to the current user. Update the Windows-specific directory creation logic to set permissions that restrict access to the current user only. Test the Remote Control feature on Windows to confirm the permission error is resolved.
Written by the indexing model from the issue text.
Description
What version of Codex CLI is running?
codex-cli 0.160.0
What subscription do you have?
Plus
Which model were you using?
No response
What platform is your computer?
Microsoft Windows NT 10.0.26300.0 x64
What terminal emulator and version are you using (if applicable)?
Windows Terminal
Codex doctor report
{
"schemaVersion": 1,
"generatedAt": "1791148554s since unix epoch",
"overallStatus": "warning",
"codexVersion": "0.160.0",
"checks": {
"app_server.status": {
"id": "app_server.status",
"category": "app-server",
"status": "ok",
"summary": "background server is not running",
"details": {
"control socket": "C:\\Users\\Stef\\.codex\\app-server-control\\app-server-control.sock",
"daemon state dir": "C:\\Users\\Stef\\.codex\\app-server-daemon",
"dedicated pid file": "C:\\Users\\Stef\\.codex\\app-server-daemon\\daemon.pid (missing)",
"dedicated update-loop pid file": "C:\\Users\\Stef\\.codex\\app-server-daemon\\daemon-updater.pid (file)",
"mode": "persistent",
"pid file": "C:\\Users\\Stef\\.codex\\app-server-daemon\\app-server.pid (missing)",
"settings": "C:\\Users\\Stef\\.codex\\app-server-daemon\\settings.json (file)",
"status": "not running",
"update-loop pid file": "C:\\Users\\Stef\\.codex\\app-server-daemon\\app-server-updater.pid (missing)"
},
"remediation": null,
"durationMs": 0
},
"auth.credentials": {
"id": "auth.credentials",
"category": "auth",
"status": "ok",
"summary": "auth is configured",
"details": {
"auth file": "C:\\Users\\Stef\\.codex\\auth.json",
"auth storage mode": "File",
"stored API key": "false",
"stored ChatGPT tokens": "true",
"stored agent identity": "false",
"stored auth mode": "chatgpt"
},
"remediation": null,
"durationMs": 0
},
"config.load": {
"id": "config.load",
"category": "config",
"status": "ok",
"summary": "config loaded",
"details": {
"CODEX_HOME": "C:\\Users\\Stef\\.codex",
"active thread overrides": "not inspected",
"config.toml": "C:\\Users\\Stef\\.codex\\config.toml",
"config.toml parse": "ok",
"configuration load ms": "16",
"configuration scope": "invocation config, including cloud-managed policy",
"cwd": "C:\\Users\\Stef",
"enabled feature flags": "<redacted>",
"feature flag overrides": "memories=true",
"feature flags enabled": "54",
"log dir": "C:\\Users\\Stef\\.codex\\log",
"mcp servers": "1",
"model": "gpt-6-astra",
"model provider": "openai",
"sqlite home": "C:\\Users\\Stef\\.codex"
},
"remediation": null,
"durationMs": 0
},
"desktop.app.version": {
"id": "desktop.app.version",
"category": "desktop",
"status": "ok",
"summary": "the desktop application is installed",
"details": {
"log directory": "$HOME\\AppData\\Local\\Codex/Logs",
"running": "false",
"version": "26.930.3930.0"
},
"remediation": null,
"durationMs": 0
},
"desktop.app_server.handshake": {
"id": "desktop.app_server.handshake",
"category": "desktop",
"status": "ok",
"summary": "the desktop application is not running",
"details": {},
"remediation": null,
"durationMs": 0
},
"desktop.security.enforcement": {
"id": "desktop.security.enforcement",
"category": "desktop",
"status": "ok",
"summary": "no locally visible recent Codex security enforcement was found",
"details": {},
"remediation": null,
"durationMs": 0
},
"git.environment": {
"id": "git.environment",
"category": "git",
"status": "ok",
"summary": "git executable not found",
"details": {
"PATH git entries": "0",
"git execution": "not inspected (PATH helpers are not executed)",
"repo detected": "false",
"selected git": "not found"
},
"remediation": null,
"durationMs": 6
},
"git.worktree.dev_drive": {
"id": "git.worktree.dev_drive",
"category": "git",
"status": "ok",
"summary": "no Git worktree is active",
"details": {},
"remediation": null,
"durationMs": 0
},
"installation": {
"id": "installation",
"category": "install",
"status": "ok",
"summary": "installation looks consistent",
"details": {
"PATH codex #1": "C:\\Users\\Stef\\AppData\\Local\\Programs\\OpenAI\\Codex\\bin\\codex.exe",
"PATH codex #2": "C:\\Users\\Stef\\AppData\\Local\\Microsoft\\WinGet\\Links\\codex.exe",
"PATH codex entries": "2",
"current executable": "C:\\Users\\Stef\\AppData\\Local\\Programs\\OpenAI\\Codex\\bin\\codex.exe",
"install context": "standalone (windows, package C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc, bin C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc\\bin, resources C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc\\codex-resources, path C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc\\codex-path)",
"managed by Vite+": "false",
"managed by bun": "false",
"managed by npm": "false",
"managed by pnpm": "false",
"managed package root": "not set"
},
"remediation": null,
"durationMs": 5
},
"mcp.config": {
"id": "mcp.config",
"category": "mcp",
"status": "warning",
"summary": "MCP configuration has optional issues",
"details": {
"configured servers": "1",
"disabled servers": "0",
"node_repl": "env var CODEX_WINDOWS_REGISTERED_CORE is not set",
"stdio servers": "1"
},
"remediation": "Set the missing MCP env vars or disable the affected server.",
"durationMs": 0
},
"network.env": {
"id": "network.env",
"category": "network",
"status": "ok",
"summary": "network-related environment looks readable",
"details": {
"managed proxy": "not configured",
"proxy env vars": "none",
"respect system proxy": "disabled"
},
"remediation": null,
"durationMs": 0
},
"network.provider_reachability": {
"id": "network.provider_reachability",
"category": "reachability",
"status": "ok",
"summary": "active provider endpoints are reachable over HTTP",
"details": {
"ChatGPT inference URL": "https://chatgpt.com/backend-api/<redacted> reachable (HTTP 405)",
"desktop assets CDN": "https://persistent.oaistatic.com/codex-app-prod/<redacted> reachable (HTTP 200)",
"reachability mode": "ChatGPT auth"
},
"remediation": null,
"durationMs": 170
},
"network.websocket_reachability": {
"id": "network.websocket_reachability",
"category": "websocket",
"status": "ok",
"summary": "Responses WebSocket handshake succeeded",
"details": {
"DNS": "2 IPv4, 2 IPv6, first IPv6",
"auth mode": "chatgpt",
"connect timeout": "15000 ms",
"endpoint": "wss://chatgpt.com/backend-api/<redacted>",
"handshake result": "HTTP 101 Switching Protocols",
"model provider": "openai",
"provider name": "OpenAI",
"proxy env vars": "none",
"reasoning header": "false",
"server model present": "false",
"supports websockets": "true",
"wire API": "responses"
},
"remediation": null,
"durationMs": 807
},
"runtime.provenance": {
"id": "runtime.provenance",
"category": "runtime",
"status": "ok",
"summary": "running standalone on windows-x86_64",
"details": {
"commit": "unknown",
"current executable": "C:\\Users\\Stef\\AppData\\Local\\Programs\\OpenAI\\Codex\\bin\\codex.exe",
"install method": "standalone (windows, package C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc, bin C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc\\bin, resources C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc\\codex-resources, path C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc\\codex-path)",
"platform": "windows-x86_64",
"version": "0.160.0"
},
"remediation": null,
"durationMs": 0
},
"runtime.search": {
"id": "runtime.search",
"category": "search",
"status": "ok",
"summary": "search command found (bundled); execution not verified",
"details": {
"search command": "C:\\Users\\Stef\\.codex\\packages\\standalone\\releases\\0.160.0-x86_64-pc-windows-msvc\\codex-path\\rg.exe",
"search command readiness": "file exists",
"search provider": "bundled"
},
"remediation": null,
"durationMs": 0
},
"sandbox.filesystem_paths": {
"id": "sandbox.filesystem_paths",
"category": "sandbox",
"status": "ok",
"summary": "no explicit filesystem paths to probe",
"details": {},
"remediation": null,
"durationMs": 0
},
"sandbox.helpers": {
"id": "sandbox.helpers",
"category": "sandbox",
"status": "ok",
"summary": "sandbox configuration is readable",
"details": {
"approval policy": "OnRequest",
"codex-linux-sandbox helper": "none",
"denied-read glob rules": "0",
"denied-read restrictions": "false",
"denied-read rules": "0",
"execve wrapper helper": "none",
"filesystem sandbox": "restricted",
"glob scan max depth": "unbounded",
"managed filesystem source": "none",
"network sandbox": "restricted",
"sandbox backend": "elevated",
"sandbox provisioning": "complete"
},
"remediation": null,
"durationMs": 3
},
"security.endpoint": {
"id": "security.endpoint",
"category": "security",
"status": "warning",
"summary": "endpoint protection detected; Codex exclusions are unverified",
"details": {
"Codex exclusions": "not verified",
"endpoint products": "Microsoft Defender",
"exclusion targets": "signed Codex app; codex.exe; codex-windows-sandbox-setup.exe; codex-command-runner.exe; codex-code-mode-host.exe"
},
"issues": [
{
"severity": "warning",
"cause": "Microsoft Defender can interfere with Codex. Verify Codex exclusions.",
"measured": "not verified",
"expected": "Codex application and helper exclusions",
"remedy": "Microsoft Defender: Add a certificate or executable-path exclusion for Codex and its helpers. If Attack Surface Reduction blocks Codex, add a rule exclusion. If Controlled Folder Access blocks Codex, allow the app.",
"fields": [
"Codex exclusions"
]
}
],
"remediation": "ask your security administrator to verify Codex exclusions and required helper allowances",
"durationMs": 24
},
"state.paths": {
"id": "state.paths",
"category": "state",
"status": "ok",
"summary": "state paths and databases are inspectable",
"details": {
"CODEX_HOME": "C:\\Users\\Stef\\.codex (dir)",
"active rollout files": "12 files, 68577624 total bytes, 5714802 average bytes",
"archived rollout files": "0 files, 0 total bytes, 0 average bytes",
"goals DB": "C:\\Users\\Stef\\.codex\\goals_1.sqlite (file)",
"goals DB integrity": "ok",
"log DB": "C:\\Users\\Stef\\.codex\\logs_2.sqlite (file)",
"log DB integrity": "ok",
"log dir": "C:\\Users\\Stef\\.codex\\log (missing)",
"memories DB": "C:\\Users\\Stef\\.codex\\memories_1.sqlite (file)",
"memories DB integrity": "ok",
"memories v2 DB": "C:\\Users\\Stef\\.codex\\memories_v2_1.sqlite (missing)",
"memories v2 DB integrity": "skipped (missing)",
"queue DB": "C:\\Users\\Stef\\.codex\\queue_1.sqlite (file)",
"queue DB integrity": "ok",
"sqlite home": "C:\\Users\\Stef\\.codex (dir)",
"standalone release cache": "1 entries in C:\\Users\\Stef\\.codex\\packages\\standalone\\releases",
"state DB": "C:\\Users\\Stef\\.codex\\state_5.sqlite (file)",
"state DB integrity": "ok",
"thread history DB": "C:\\Users\\Stef\\.codex\\thread_history_1.sqlite (file)",
"thread history DB integrity": "ok"
},
"remediation": null,
"durationMs": 143
},
"state.rollout_db_parity": {
"id": "state.rollout_db_parity",
"category": "threads",
"status": "ok",
"summary": "rollout files and state DB thread inventory agree",
"details": {
"default model provider": "openai",
"rollout DB active files": "12",
"rollout DB active rows": "12",
"rollout DB archive mismatches": "0",
"rollout DB archived files": "0",
"rollout DB archived rows": "0",
"rollout DB duplicate DB paths": "0",
"rollout DB duplicate rollout thread ids": "0",
"rollout DB malformed file names": "0",
"rollout DB missing active rows": "0",
"rollout DB missing archived rows": "0",
"rollout DB model providers": "openai=12",
"rollout DB rows": "12",
"rollout DB scan cap reached": "false",
"rollout DB scan errors": "0",
"rollout DB sources": "vscode=10, subagent:other=1, subagent:thread_spawn=1",
"rollout DB stale rows": "0"
},
"remediation": null,
"durationMs": 86
},
"system.disk": {
"id": "system.disk",
"category": "disk",
"status": "ok",
"summary": "sufficient free disk space (141.9 GiB)",
"details": {
"CODEX_HOME available": "141.9 GiB",
"failure threshold": "1.0 GiB",
"warning threshold": "5.0 GiB",
"worktree available": "141.9 GiB"
},
"remediation": null,
"durationMs": 0
},
"system.environment": {
"id": "system.environment",
"category": "system",
"status": "ok",
"summary": "OS language en-GB",
"details": {
"EDITOR": "not set",
"VISUAL": "not set",
"os": "Windows 10.0.26300 (Windows 11 Professional) [64-bit]",
"os language": "en-GB",
"os type": "Windows",
"os version": "10.0.26300"
},
"remediation": null,
"durationMs": 1
},
"terminal.env": {
"id": "terminal.env",
"category": "terminal",
"status": "ok",
"summary": "terminal metadata was detected",
"details": {
"WT_SESSION": "present",
"color output": "enabled",
"console input code page": "850",
"console output code page": "850",
"stderr console mode": "0x00000007 (VT processing: true)",
"stderr is terminal": "true",
"stdin is terminal": "true",
"stdout console mode": "0x00000007 (VT processing: true)",
"stdout is terminal": "true",
"terminal": "Windows Terminal",
"terminal size": "120x30"
},
"remediation": null,
"durationMs": 1
},
"terminal.title": {
"id": "terminal.title",
"category": "title",
"status": "ok",
"summary": "terminal title default",
"details": {
"terminal title activity": "true",
"terminal title items": "activity, project-name",
"terminal title project source": "cwd",
"terminal title project value": "Stef",
"terminal title source": "default"
},
"remediation": null,
"durationMs": 0
},
"updates.status": {
"id": "updates.status",
"category": "updates",
"status": "ok",
"summary": "update configuration is locally consistent",
"details": {
"cached latest version": "0.160.0",
"check for update on startup": "true",
"desktop application": "OpenAI.Codex",
"desktop latest build": "26.930.4958.0",
"desktop update status": "available",
"last checked at": "2026-10-04T19:54:14.213877600Z",
"latest version": "0.160.0",
"latest version status": "current version is not older",
"update action": "standalone installer",
"version cache": "C:\\Users\\Stef\\.codex\\version.json"
},
"remediation": null,
"durationMs": 402
}
}
}
What issue are you seeing?
Environment
- Windows 11 Professional x64
- Codex CLI 0.160.0
- ChatGPT desktop app reports itself up to date
- Running under normal/non-elevated Windows account
Problem
I’m trying to pair the ChatGPT mobile app with my Windows PC for Codex Remote Control.
Pairing is initiated correctly from:
ChatGPT desktop app → Settings → Connections → Control this PC → Add
Both QR pairing and manual-code pairing complete authentication, briefly show Pairing..., and then return to the authorization screen.
The desktop app can also show:
Couldn't update remote control availability
Running:
codex remote-control
fails with:
foreground app-server exited before remote control became ready
Caused by:
socket directory is not private to the current user
ACL verification
Directory:
C:\Users\Stef.codex\app-server-control
ACL: - Owner: Stefan\Stef
- AreAccessRulesProtected: True
- Access rule count: 1
- Identity: Stefan\Stef
- Rights: FullControl
- Type: Allow
- IsInherited: False
I also renamed the existing app-server-control directory and let Codex recreate it, but the same error occurs.
Other troubleshooting - Updated Codex CLI
- Verified desktop app says it is up to date
- Restarted Windows
- Tried QR and manual pairing
- Enabled MFA
- Restarted Remote Control
- Checked Microsoft Defender Protection History
- Added narrow Codex Defender exclusions
- Verified PowerShell is not elevated (IsInRole(Administrator) returns False)
- CODEX_HOME is not set
- Tried RUST_LOG=debug with a custom log_dir, but no logs were produced before the failure
It appears the Windows socket privacy check is rejecting a directory whose ACL is already private to the current user.
What steps can reproduce the bug?
- Open the ChatGPT desktop app on Windows 11.
- Go to Settings → Connections → Control this PC.
- Enable "Allow connections".
- Click "Add" and attempt to pair the ChatGPT mobile app.
- Complete the authorization flow on the phone.
- Pairing briefly shows "Pairing..." and then returns to the authorization screen without completing.
The desktop app can also show:
"Couldn't update remote control availability"
To reproduce the lower-level failure from PowerShell:
codex remote-control
Result:
Starting app-server with remote control enabled...
Error: foreground app-server exited before remote control became ready
Caused by:
socket directory is not private to the current user
The same occurs with:
codex remote-control --json
I also verified the ACL of:
C:\Users\Stef.codex\app-server-control
The directory is owned by my Windows user, has protected access rules, one access rule only, FullControl for my user, and no inherited permissions.
Relevant ACL checks:
$dir = "$env:USERPROFILE.codex\app-server-control"
$acl = Get-Acl $dir
$acl | Format-List Owner,AreAccessRulesProtected,Sddl
$acl.Access.Count
$acl.Access | Format-List IdentityReference,FileSystemRights,AccessControlType,InheritanceFlags,PropagationFlags,IsInherited
What is the expected behavior?
Remote Control should start successfully on the Windows host, the Allow connections setting should remain enabled, and pairing from the ChatGPT mobile app should complete after authorization.
codex remote-control should start the app-server without exiting with a socket privacy error.
Additional information
I confirmed PowerShell is not running as Administrator, CODEX_HOME is not set, and the affected directory ACL is already private to my Windows user (Stefan\Stef) with protected access rules, one FullControl rule, and no inherited permissions.
I also renamed the existing app-server-control directory and allowed Codex to recreate it, but the same error persisted.
QR pairing and manual-code pairing both fail in the same way.
Microsoft Defender Protection History is clean, and the ChatGPT desktop app reports itself up to date.
- Dominant language
- Rust
- Stars
- 127k
- Forks
- 19.9k
- Avg merge
- 1m
- Merged PRs (30d)
- 994
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from openai/codex
-
[macOS Desktop] New sidebar hover navigation accidentally switches sections while reaching a chatOpenapp bug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day
-
bug skills
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
bug CLI config
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Shell installer: updating PATH replaces symlinked profiles and changes existing file permissionsOpenbug CLI
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Git Bash on Windows: terminal enlarge/shrink breaks chat input and previous conversation scrollingOpenbug CLI TUI windows-os
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
wardian-app/Wardian#1603 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 2 days
-
bug
Difficulty 1/5 1-3 hours Newbie friendliness 72/100
peteonrails/voxtype#844 ·
Maintainers usually reply within 1 day
-
feature
Difficulty 1/5 Under an hour Newbie friendliness 85/100
uwuclxdy/clauth#107 · 1 comment ·
Maintainers usually reply within 4 days