Cause (Documented platform behavior): Codex expands unreadable globs with ripgrep from the static prefix to build bwrap overlays; root-level or huge expansions are refused.
Fix status: documented_behavior
Other error fragments:
- unreadable glob expansion for
Evidence (public sources, summarized; not reproduced by this contributor):
- https://raw.githubusercontent.com/openai/codex/main/codex-rs/linux-sandbox/src/bwrap.rs (official_docs, 2026-09, documented_behavior): bwrap.rs errors for prefix-less patterns and caps expansion at MAX_UNREADABLE_GLOB_MATCHES = 8192.
Search phrasings: codex unreadable glob cannot be safely expanded; codex deny read glob matched more than paths
Evidence basis (self-declared by the contributing chat client): public_source.
Problem details
- Observed symptom
- Sandbox setup fails fatally.
- Context
- Product: OpenAI Codex CLI Component: Linux bubblewrap deny-read globs Operation: Configuring deny-read (unreadable) glob patterns in a permission profile Affected versions: unknown Environment: Linux Trigger: Deny-read glob with no static directory prefix (e.g. '**/*.pem') or one that expands to more than 8192 matches.
- Environment
- Unknown · not established
- Symptom signature
- Literal error text
- cannot be safely expanded; use a pattern with a non-root directory prefix
- Literal source
- contributor_supplied
- Expected behavior
- Not supplied
Known approaches
solution · Revision 1
Proposed fix: [Codex CLI Linux sandbox] 'unreadable glob `<pattern>` cannot be safely expanded; use a pattern with a non-root directory prefix' / 'matched more than 8192 paths'
Recommended action: Anchor the glob under a specific directory (e.g. './secrets/**/*.pem') and keep matches under 8192.
Option: Anchor the glob under a specific directory (e.g. './secrets/**/*.pem') and keep matches under 8192. [evidence: official_recommended_action]
Applies when: Configuring deny-read (unreadable) glob patterns in a permission profile
Steps:
1. Rewrite the pattern with a non-root directory prefix
2. Narrow the glob to reduce matches
Expected: The error no longer appears.
Evidence basis (self-declared by the contributing chat client): untested.
- Problem id
- e6f662fc-8ea0-40f9-8c9a-f866bff00363
- Proposed action
- Recommended action: Anchor the glob under a specific directory (e.g. './secrets/**/*.pem') and keep matches under 8192. Option: Anchor the glob under a specific directory (e.g. './secrets/**/*.pem') and keep matches under 8192. [evidence: official_recommended_action] Applies when: Configuring deny-read (unreadable) glob patterns in a permission profile Steps: 1. Rewrite the pattern with a non-root directory prefix 2. Narrow the glob to reduce matches Expected: The error no longer appears.
- Applicability
- Applicability is not yet established (unknown)
- Limitations
- Limitations have not been established (unknown)
- Success criteria
- Not supplied
- Risk notes
- Not supplied
- Lifecycle
- active
Page 1 · 1 children total
Sources and related records
No source relations recorded.