Skip to content

[Bug] Windows PowerShell -WindowStyle Hidden causes EACLIDENTITY under Bun #1589

Description

@Zbyy0311

Client or integration

OpenCodex dashboard / Codex configuration sync

Area

Windows compatibility / identity lookup / configuration writes

Summary

This report supersedes #1588, which was automatically closed before the required version and operating-system fields were present.

On Windows 11 x64, OpenCodex cannot resolve the effective Windows account when it launches PowerShell through Bun with the CLI arguments -WindowStyle Hidden.

This causes configuration writes and model synchronization to fail with:

CodexUserIdentityRefusal: Windows effective-account lookup failed.

The same behavior was observed in OpenCodex 2.12.0 and remains reproducible in 2.14.0, so this appears to be a cross-version compatibility issue rather than a regression introduced only by 2.14.0.

Version

  • OpenCodex: 2.14.0
  • Bundled Bun: 1.3.14

Operating system

  • Windows 11 Pro 23H2
  • OS build: 22631
  • Architecture: x64

Reproduction

Windows PowerShell executable:

C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

The following Bun invocation fails with exit code 255 and empty stdout/stderr:

Bun.spawnSync(
  [
    powershell,
    "-NoLogo",
    "-NoProfile",
    "-NonInteractive",
    "-WindowStyle",
    "Hidden",
    "-Command",
    "[System.Security.Principal.WindowsIdentity]::GetCurrent().User.Value",
  ],
  {
    stdin: "ignore",
    stdout: "pipe",
    stderr: "pipe",
    timeout: 8000,
    windowsHide: true,
  },
);

The same invocation succeeds and returns the account SID when the PowerShell CLI pair "-WindowStyle", "Hidden" is removed.

Directly running the PowerShell command also succeeds. Start-Process -WindowStyle Hidden from inside PowerShell works as well; the failure appears specific to passing -WindowStyle Hidden as a PowerShell CLI argument to a Bun-spawned process.

Actual impact

The failure affects code paths that need effective-account identity, including:

  • configuration writes and synchronization
  • ACL hardening
  • Codex coordinator/configuration path resolution

The user-facing result is an identity/configuration error even though the Windows account and filesystem are otherwise usable.

Suggested fix

For direct PowerShell child-process argument arrays, remove the CLI arguments:

"-WindowStyle",
"Hidden",

and retain Bun's:

windowsHide: true

This preserves hidden process creation without passing the failing PowerShell CLI option. The Start-Process -WindowStyle Hidden usages inside PowerShell scripts should be evaluated separately because they work in the affected environment.

Relevant call sites include src/codex/user-identity.ts, src/lib/windows-user-principal.ts, src/config.ts, src/codex/app-server-processes.ts, src/tray/windows.ts, and src/update/job.ts.

Expected behaviour

Effective-account lookup should succeed on Windows when PowerShell is launched through Bun, or the error should identify the incompatible process argument explicitly rather than surfacing as a generic EACLIDENTITY / identity refusal.

No credentials or personal account identifiers are included in this report.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingplatformOS/service/tray/ACL (Windows-heavy, not Windows-only)

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions