Skip to content

Resolve permission profiles with explicit execution-host path context - #44676

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/ca259434742365c16d0b72629cabfbab41513a80
Sep 11, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/ca259434742365c16d0b72629cabfbab41513a80

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Resolve permission profiles with explicit execution-host path context

Why

Permission paths need to follow the execution host's path conventions and home directory. Literal directory names containing glob syntax must not change the meaning of deny patterns, and profile availability checks need to account for configured workspace roots.

What changed

  • Use ConfigPathContext to compile built-in and custom profiles, returning the resolved profile and deduplicated PathUri workspace roots. Materialize configured roots while retaining runtime workspace symbols.
  • Use the same compiler for configuration loading, persisted profile validation, and profile catalogs. Resolve roots against the requested cwd when listing profiles.
  • Resolve home-relative scoped rules using the supplied home directory and reject unsafe directory prefixes when constructing globs.
  • Share workspace-root materialization across native paths and URIs. Deny the affected root when a workspace glob cannot be safely resolved, and clear grants for legacy home-relative workspace denials whose target is unknown.

Testing

Add coverage for POSIX, Windows, and UNC path resolution, inherited workspace roots, scoped home denials, missing home context, and conservative denial behavior for unsafe globs. Add an app-server test verifying that profile availability reflects the requested cwd.

…#44676)

## Why

Permission paths need to follow the execution host's path conventions and home directory. Literal directory names containing glob syntax must not change the meaning of deny patterns, and profile availability checks need to account for configured workspace roots.

## What changed

- Use `ConfigPathContext` to compile built-in and custom profiles, returning the resolved profile and deduplicated `PathUri` workspace roots. Materialize configured roots while retaining runtime workspace symbols.
- Use the same compiler for configuration loading, persisted profile validation, and profile catalogs. Resolve roots against the requested `cwd` when listing profiles.
- Resolve home-relative scoped rules using the supplied home directory and reject unsafe directory prefixes when constructing globs.
- Share workspace-root materialization across native paths and URIs. Deny the affected root when a workspace glob cannot be safely resolved, and clear grants for legacy home-relative workspace denials whose target is unknown.

## Testing

Add coverage for POSIX, Windows, and UNC path resolution, inherited workspace roots, scoped home denials, missing home context, and conservative denial behavior for unsafe globs. Add an app-server test verifying that profile availability reflects the requested `cwd`.

GitOrigin-RevId: ca259434742365c16d0b72629cabfbab41513a80
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/ca259434742365c16d0b72629cabfbab41513a80 branch from 9aa7df7 to 9e22e74 Compare September 11, 2026 00:03
@copyberry
copyberry Bot merged commit 9e22e74 into main Sep 11, 2026
1 check failed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/ca259434742365c16d0b72629cabfbab41513a80 branch September 11, 2026 00:03
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@github-actions github-actions Bot locked and limited conversation to collaborators Sep 11, 2026
@m1l3ms
m1l3ms deployed to issue-triage September 11, 2026 00:05 — with GitHub Actions Active
@m1l3ms
m1l3ms deployed to issue-triage September 11, 2026 00:05 — with GitHub Actions Active
@m1l3ms
m1l3ms deployed to issue-triage September 11, 2026 00:05 — with GitHub Actions Active
@nkpryor
nkpryor deployed to issue-triage September 11, 2026 00:08 — with GitHub Actions Active
@nkpryor
nkpryor deployed to issue-triage September 11, 2026 00:08 — with GitHub Actions Active
@nkpryor
nkpryor deployed to issue-triage September 11, 2026 00:08 — with GitHub Actions Active
@nkpryor
nkpryor deployed to issue-triage September 11, 2026 00:09 — with GitHub Actions Active
@digitdash
digitdash deployed to issue-triage September 11, 2026 00:10 — with GitHub Actions Active
@digitdash
digitdash deployed to issue-triage September 11, 2026 00:10 — with GitHub Actions Active
@digitdash
digitdash deployed to issue-triage September 11, 2026 00:10 — with GitHub Actions Active
@junaga
junaga deployed to issue-triage September 11, 2026 00:12 — with GitHub Actions Active
@junaga
junaga deployed to issue-triage September 11, 2026 00:12 — with GitHub Actions Active
@junaga
junaga deployed to issue-triage September 11, 2026 00:12 — with GitHub Actions Active
@junaga
junaga deployed to issue-triage September 11, 2026 00:13 — with GitHub Actions Active
@RohinJ444
RohinJ444 deployed to issue-triage September 11, 2026 00:14 — with GitHub Actions Active
@RohinJ444
RohinJ444 deployed to issue-triage September 11, 2026 00:14 — with GitHub Actions Active
@RohinJ444
RohinJ444 deployed to issue-triage September 11, 2026 00:14 — with GitHub Actions Active
@RohinJ444
RohinJ444 deployed to issue-triage September 11, 2026 00:14 — with GitHub Actions Active
@p-poppe
p-poppe deployed to issue-triage September 11, 2026 00:30 — with GitHub Actions Active
@p-poppe
p-poppe deployed to issue-triage September 11, 2026 00:30 — with GitHub Actions Active
@p-poppe
p-poppe deployed to issue-triage September 11, 2026 00:30 — with GitHub Actions Active
@achose369
achose369 deployed to issue-triage September 11, 2026 00:41 — with GitHub Actions Active
@achose369
achose369 deployed to issue-triage September 11, 2026 00:41 — with GitHub Actions Active
@achose369
achose369 deployed to issue-triage September 11, 2026 00:41 — with GitHub Actions Active
@Co5mos
Co5mos deployed to issue-triage September 11, 2026 00:42 — with GitHub Actions Active
@Co5mos
Co5mos deployed to issue-triage September 11, 2026 00:42 — with GitHub Actions Active
@Co5mos
Co5mos deployed to issue-triage September 11, 2026 00:42 — with GitHub Actions Active
@achose369
achose369 deployed to issue-triage September 11, 2026 00:43 — with GitHub Actions Active
@Co5mos
Co5mos deployed to issue-triage September 11, 2026 00:43 — with GitHub Actions Active
@iamh2o
iamh2o deployed to issue-triage September 11, 2026 00:51 — with GitHub Actions Active
@iamh2o
iamh2o deployed to issue-triage September 11, 2026 00:51 — with GitHub Actions Active
@iamh2o
iamh2o deployed to issue-triage September 11, 2026 00:51 — with GitHub Actions Active
@ryanreh99
ryanreh99 deployed to issue-triage September 11, 2026 00:55 — with GitHub Actions Active
@ryanreh99
ryanreh99 deployed to issue-triage September 11, 2026 00:55 — with GitHub Actions Active
@ryanreh99
ryanreh99 deployed to issue-triage September 11, 2026 00:55 — with GitHub Actions Active
@ryanreh99
ryanreh99 deployed to issue-triage September 11, 2026 00:56 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.