Use at the start of a Codex session (especially sandboxed) to run scripts/codex-sandbox-preflight.sh and interpret network + writable_roots constraints.
PermissionError: [Errno 1] Operation not permitted, seccomp, or unexpected “Permission denied” when paths look writable.git push, etc.read-pdf, pdf-to-markdown, llm, or wbg-auth.gh,
gcloud, gws, llm, aws, az, or oci.scripts/codex-preflight.sh
Compatibility note: scripts/codex-sandbox-preflight.sh still exists as a shim,
but scripts/codex-preflight.sh is the canonical script name.
scripts/codex-preflight.sh --json
scripts/codex-preflight.sh --with-network
socket() allowed vs blocked (and DNS if allowed).tk, read-pdf, pdf-to-markdown, llm, and
wbg-auth are available, plus a concise tk queue summary when applicable.codex, gh, gcloud, gws, llm,
aws, az, and oci look ready, missing, partial, or unsupported.~/.config/wbg-auth is writable inside the sandbox.~/.codex/config.toml is symlinked to dotfiles or has diverged.INFO- socket() syscall blocked:-c sandbox_workspace_write.network_access=true (still sandboxed, but with egress).WARN missing_writable_root=$HOME/.config/wbg-auth (or similar) / sandbox write fails for ~/.config/wbg-auth:wbg-auth will crash on startup due to log file creation.~/.config/wbg-auth to sandbox_workspace_write.writable_roots in ~/.codex/config.toml.WARN- python TLS handshake ... failed certificate verification:bin/wbg-ca-helper install-wsl-trust.requests / certifi, exporting
REQUESTS_CA_BUNDLE=/etc/ssl/certs/ca-certificates.crt and
SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt can be necessary even
when basic socket and DNS checks pass.socket(). Use --with-network from a normal shell for that.codex-preflight when it is on PATH; the old
sandbox-named entrypoint is compatibility-only.