OpenAI product lead Tibo has detailed the Codex file-deletion issue and shared the fixes that have gone live. In rare cases, GPT-5.6 got its paths crossed while cleaning up temporary files. The most dangerous scenario: it mistook $HOME for a temp folder and wiped out everything in the user's home directory.
OpenAI is now adding five layers of protection:
- Inspect before deleting. Codex must verify the path it's about to remove; if the scope isn't clear, it stops.
- Temp files only go in new directories. System environment variables like
$HOMEare no longer used as temp directories. - High-risk deletion commands get extra review. The system flags suspicious deletion commands for additional vetting; if they don't pass, they're blocked and the model is prompted to try a safer approach.
- Full Access is harder to trigger by accident. Codex's fully privileged mode now comes with clearer warnings, and especially dangerous permission combos are further restricted.
- Training Codex to make this mistake less often. OpenAI turned the file-deletion bug into a regression test, added reinforcement learning tasks around it, and filtered destructive operations out of training data.
Tibo says the new measures have already significantly reduced these incidents without noticeably impacting Codex's ability to complete coding tasks. He still recommends that everyday users prefer sandbox mode, and only enable Full Access in environments they trust and can restore.
https://twitter.com/thsottiaux/status/2089891927659585918