Skip to content

Agent reports stale PR review after sandboxed GitHub access fails despite available scoped escalation #49083

Description

@goneflyin

Summary

During a requested re-review of a GitHub PR, Codex ran gh pr view inside a workspace-write sandbox with restricted network access. The command failed to connect to api.github.com. The agent treated that as a GitHub connectivity problem, reviewed its stale local branch, and reported findings that the submitter had already fixed in a newer PR commit. It then told the user it could not verify the remote head.

A narrowly scoped retry outside the sandbox succeeded immediately with the same gh installation and authentication. This is an agent escalation/diagnosis failure, not evidence that GitHub or the user's network was down.

Related: #47658 (closed after its reporter enabled sandbox networking); #31017 covers a different gh credential symptom.

Environment

Reproduction and evidence

  1. Ask Codex to re-review that PR after the submitter pushes a new commit.
  2. Sandboxed gh pr view 4 --json ... exits 1: error connecting to api.github.com.
  3. Sandboxed git ls-remote origin 'refs/pull/4/head' exits 128: ssh: Could not resolve hostname github.com.
  4. Codex continues against local commit 52656cd, reports two defects, and says GitHub is unavailable. The actual PR head is 6952d40, which fixes both defects.
  5. The same session retries gh pr view 4 --json number,title,headRefOid,... with sandbox_permissions: "require_escalated", a read-only gh pr view prefix rule, and a narrow justification. It exits 0 and reports headRefOid: 6952d40.... git fetch origin pull/4/head:refs/remotes/origin/pr/4 likewise succeeds with scoped escalation.

No authentication or host-network configuration changed between steps 2 and 5.

Expected behavior

For a task that requires current remote SCM state, the agent should recognize a restricted-sandbox network/DNS failure, distinguish it from host connectivity or authentication, and retry an authorized read-only SCM command through scoped escalation before reviewing or claiming the PR cannot be verified. If escalation is unavailable or denied, it should stop short of a current-head review and identify the precise boundary.

The product could also make ordinary read-only SCM inspection easier to authorize through a narrow default capability or clearer configuration guidance, while keeping write operations and broad network access separate.

Actual behavior and impact

The agent reported stale, already-fixed defects as current review findings. The user had to diagnose Codex's execution context and prompt it to use the CLI correctly. This defeats the point of PR re-review and makes sandboxing feel like a misleading failure mode rather than a useful boundary.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    CLIIssues related to the Codex CLIbugSomething isn't workingcode-reviewIssues relating to code reviews performed by codexmodel-behaviorIssues related to behaviors exhibited by the modelsandboxIssues related to permissions or sandboxing

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions