Repository navigation
Resolve permission profiles with explicit execution-host path context - #44676
Merged
copyberry[bot] merged 1 commit intoSep 11, 2026
Conversation
…#44676) ## Why Permission paths need to follow the execution host's path conventions and home directory. Literal directory names containing glob syntax must not change the meaning of deny patterns, and profile availability checks need to account for configured workspace roots. ## What changed - Use `ConfigPathContext` to compile built-in and custom profiles, returning the resolved profile and deduplicated `PathUri` workspace roots. Materialize configured roots while retaining runtime workspace symbols. - Use the same compiler for configuration loading, persisted profile validation, and profile catalogs. Resolve roots against the requested `cwd` when listing profiles. - Resolve home-relative scoped rules using the supplied home directory and reject unsafe directory prefixes when constructing globs. - Share workspace-root materialization across native paths and URIs. Deny the affected root when a workspace glob cannot be safely resolved, and clear grants for legacy home-relative workspace denials whose target is unknown. ## Testing Add coverage for POSIX, Windows, and UNC path resolution, inherited workspace roots, scoped home denials, missing home context, and conservative denial behavior for unsafe globs. Add an app-server test verifying that profile availability reflects the requested `cwd`. GitOrigin-RevId: ca259434742365c16d0b72629cabfbab41513a80
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/ca259434742365c16d0b72629cabfbab41513a80
branch
from
September 11, 2026 00:03
9aa7df7 to
9e22e74
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/ca259434742365c16d0b72629cabfbab41513a80
branch
September 11, 2026 00:03
Contributor
|
I have read the CLA Document and I hereby sign the CLA You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolve permission profiles with explicit execution-host path context
Why
Permission paths need to follow the execution host's path conventions and home directory. Literal directory names containing glob syntax must not change the meaning of deny patterns, and profile availability checks need to account for configured workspace roots.
What changed
ConfigPathContextto compile built-in and custom profiles, returning the resolved profile and deduplicatedPathUriworkspace roots. Materialize configured roots while retaining runtime workspace symbols.cwdwhen listing profiles.Testing
Add coverage for POSIX, Windows, and UNC path resolution, inherited workspace roots, scoped home denials, missing home context, and conservative denial behavior for unsafe globs. Add an app-server test verifying that profile availability reflects the requested
cwd.