Summary
During a requested re-review of a GitHub PR, Codex ran gh pr view inside a workspace-write sandbox with restricted network access. The command failed to connect to api.github.com. The agent treated that as a GitHub connectivity problem, reviewed its stale local branch, and reported findings that the submitter had already fixed in a newer PR commit. It then told the user it could not verify the remote head.
A narrowly scoped retry outside the sandbox succeeded immediately with the same gh installation and authentication. This is an agent escalation/diagnosis failure, not evidence that GitHub or the user's network was down.
Related: #47658 (closed after its reporter enabled sandbox networking); #31017 covers a different gh credential symptom.
Environment
Reproduction and evidence
- Ask Codex to re-review that PR after the submitter pushes a new commit.
- Sandboxed
gh pr view 4 --json ... exits 1: error connecting to api.github.com.
- Sandboxed
git ls-remote origin 'refs/pull/4/head' exits 128: ssh: Could not resolve hostname github.com.
- Codex continues against local commit
52656cd, reports two defects, and says GitHub is unavailable. The actual PR head is 6952d40, which fixes both defects.
- The same session retries
gh pr view 4 --json number,title,headRefOid,... with sandbox_permissions: "require_escalated", a read-only gh pr view prefix rule, and a narrow justification. It exits 0 and reports headRefOid: 6952d40.... git fetch origin pull/4/head:refs/remotes/origin/pr/4 likewise succeeds with scoped escalation.
No authentication or host-network configuration changed between steps 2 and 5.
Expected behavior
For a task that requires current remote SCM state, the agent should recognize a restricted-sandbox network/DNS failure, distinguish it from host connectivity or authentication, and retry an authorized read-only SCM command through scoped escalation before reviewing or claiming the PR cannot be verified. If escalation is unavailable or denied, it should stop short of a current-head review and identify the precise boundary.
The product could also make ordinary read-only SCM inspection easier to authorize through a narrow default capability or clearer configuration guidance, while keeping write operations and broad network access separate.
Actual behavior and impact
The agent reported stale, already-fixed defects as current review findings. The user had to diagnose Codex's execution context and prompt it to use the CLI correctly. This defeats the point of PR re-review and makes sandboxing feel like a misleading failure mode rather than a useful boundary.
Summary
During a requested re-review of a GitHub PR, Codex ran
gh pr viewinside a workspace-write sandbox with restricted network access. The command failed to connect toapi.github.com. The agent treated that as a GitHub connectivity problem, reviewed its stale local branch, and reported findings that the submitter had already fixed in a newer PR commit. It then told the user it could not verify the remote head.A narrowly scoped retry outside the sandbox succeeded immediately with the same
ghinstallation and authentication. This is an agent escalation/diagnosis failure, not evidence that GitHub or the user's network was down.Related: #47658 (closed after its reporter enabled sandbox networking); #31017 covers a different
ghcredential symptom.Environment
workspace-writesandbox, restricted network,approvals_reviewer = "auto_review"ghauthenticated as the expected user throughGITHUB_TOKENReproduction and evidence
gh pr view 4 --json ...exits 1:error connecting to api.github.com.git ls-remote origin 'refs/pull/4/head'exits 128:ssh: Could not resolve hostname github.com.52656cd, reports two defects, and says GitHub is unavailable. The actual PR head is6952d40, which fixes both defects.gh pr view 4 --json number,title,headRefOid,...withsandbox_permissions: "require_escalated", a read-onlygh pr viewprefix rule, and a narrow justification. It exits 0 and reportsheadRefOid: 6952d40....git fetch origin pull/4/head:refs/remotes/origin/pr/4likewise succeeds with scoped escalation.No authentication or host-network configuration changed between steps 2 and 5.
Expected behavior
For a task that requires current remote SCM state, the agent should recognize a restricted-sandbox network/DNS failure, distinguish it from host connectivity or authentication, and retry an authorized read-only SCM command through scoped escalation before reviewing or claiming the PR cannot be verified. If escalation is unavailable or denied, it should stop short of a current-head review and identify the precise boundary.
The product could also make ordinary read-only SCM inspection easier to authorize through a narrow default capability or clearer configuration guidance, while keeping write operations and broad network access separate.
Actual behavior and impact
The agent reported stale, already-fixed defects as current review findings. The user had to diagnose Codex's execution context and prompt it to use the CLI correctly. This defeats the point of PR re-review and makes sandboxing feel like a misleading failure mode rather than a useful boundary.