Skip to content

Centralize Guardian policy resolution in config and protocol - #45957

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/6fed1c3a831964ad28ea7de5cb19e74e323c1204
Sep 16, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/6fed1c3a831964ad28ea7de5cb19e74e323c1204

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Centralize Guardian policy resolution in config and protocol

What changed

  • Extend GuardianModelPolicy with controls for uncategorized tools, unscored actions, the initial computer-use call allowance, and sandboxed command coverage.
  • Add GuardianPolicyLoader in codex-config to translate legacy settings, preserve catalog policy precedence, and enforce reviewer requirements. Apply live model review requirements through ConfigRequirements::constrain_guardian_policy.
  • Use the shared model policy for Guardian scoring and approval, replacing the extension-local policy wrapper while retaining legacy defaults.

Testing

Add configuration tests for catalog precedence, legacy scope fallback, required-model constraints, and legacy computer-use opt-in and feature gating. Adapt existing extension tests to consume the shared policy.

## What changed

- Extend `GuardianModelPolicy` with controls for uncategorized tools, unscored actions, the initial computer-use call allowance, and sandboxed command coverage.
- Add `GuardianPolicyLoader` in `codex-config` to translate legacy settings, preserve catalog policy precedence, and enforce reviewer requirements. Apply live model review requirements through `ConfigRequirements::constrain_guardian_policy`.
- Use the shared model policy for Guardian scoring and approval, replacing the extension-local policy wrapper while retaining legacy defaults.

## Testing

Add configuration tests for catalog precedence, legacy scope fallback, required-model constraints, and legacy computer-use opt-in and feature gating. Adapt existing extension tests to consume the shared policy.

GitOrigin-RevId: 6fed1c3a831964ad28ea7de5cb19e74e323c1204
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/6fed1c3a831964ad28ea7de5cb19e74e323c1204 branch from 911acbb to 7275afc Compare September 16, 2026 14:56
@copyberry
copyberry Bot merged commit 7275afc into main Sep 16, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/6fed1c3a831964ad28ea7de5cb19e74e323c1204 branch September 16, 2026 14:57
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 16, 2026
@reitojike
reitojike deployed to issue-triage September 16, 2026 15:04 — with GitHub Actions Active
@reitojike
reitojike deployed to issue-triage September 16, 2026 15:04 — with GitHub Actions Active
@reitojike
reitojike deployed to issue-triage September 16, 2026 15:04 — with GitHub Actions Active
@reitojike
reitojike deployed to issue-triage September 16, 2026 15:05 — with GitHub Actions Active
@klinki
klinki deployed to issue-triage September 16, 2026 15:14 — with GitHub Actions Active
@klinki
klinki deployed to issue-triage September 16, 2026 15:14 — with GitHub Actions Active
@klinki
klinki deployed to issue-triage September 16, 2026 15:14 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — 7275afc5 Deployed Sep 16, 2026 by klinki via Identify potential duplicates (all issues) #46029
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants