Skip to content

Resolve filesystem denials with explicit path context - #44669

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/fa0da0d149407958e39897a39fe7b87edd6f1644
Sep 10, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/fa0da0d149407958e39897a39fe7b87edd6f1644

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Resolve filesystem denials with explicit path context

Why

Filesystem denial paths need to use the owning environment's path syntax, base directory, and home directory. Host-native resolution cannot supply those facts for another platform, and invalid denials must not be silently skipped when building the sandbox policy.

What changed

  • Add ConfigPathContext to requirements layers so permissions.filesystem.deny_read can resolve using explicit POSIX or Windows path facts, with native defaults when no context is supplied.
  • Share URI-based resolution and validation for literal paths and glob prefixes. Reject ambiguous or lossy paths, including NUL bytes, Windows stream syntax, and unsupported UNC spellings.
  • Move denial conversion into FilesystemConstraints::apply_to_policy, preserving glob patterns and deduplicating entries. Validate all denials before modifying the policy and propagate failures through configuration loading.

Testing

Add tests for per-layer base and home resolution, Windows drives and globs, nested context restoration, missing home directories, and policy conversion without partial mutation. Add a configuration-loading regression test for a required denial glob containing a NUL byte.

## Why

Filesystem denial paths need to use the owning environment's path syntax, base directory, and home directory. Host-native resolution cannot supply those facts for another platform, and invalid denials must not be silently skipped when building the sandbox policy.

## What changed

- Add `ConfigPathContext` to requirements layers so `permissions.filesystem.deny_read` can resolve using explicit POSIX or Windows path facts, with native defaults when no context is supplied.
- Share URI-based resolution and validation for literal paths and glob prefixes. Reject ambiguous or lossy paths, including NUL bytes, Windows stream syntax, and unsupported UNC spellings.
- Move denial conversion into `FilesystemConstraints::apply_to_policy`, preserving glob patterns and deduplicating entries. Validate all denials before modifying the policy and propagate failures through configuration loading.

## Testing

Add tests for per-layer base and home resolution, Windows drives and globs, nested context restoration, missing home directories, and policy conversion without partial mutation. Add a configuration-loading regression test for a required denial glob containing a NUL byte.

GitOrigin-RevId: fa0da0d149407958e39897a39fe7b87edd6f1644
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/fa0da0d149407958e39897a39fe7b87edd6f1644 branch from 8440faf to cc05ecf Compare September 10, 2026 23:08
@copyberry
copyberry Bot merged commit cc05ecf into main Sep 10, 2026
1 check failed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/fa0da0d149407958e39897a39fe7b87edd6f1644 branch September 10, 2026 23:08
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@github-actions github-actions Bot locked and limited conversation to collaborators Sep 10, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant