Skip to content

Preserve attachment Unix socket grants when controller policy is omitted - #46004

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/98a88d01cbb91aea1faaa03b3c414ef3be7af398
Sep 16, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/98a88d01cbb91aea1faaa03b3c414ef3be7af398

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Preserve attachment Unix socket grants when controller policy is omitted

Why

An omitted controller socket policy was treated as an explicit denial, preventing execution environments from supplying their own Unix socket grants.

What changed

  • Preserve omission of dangerously_allow_all_unix_sockets separately from false, and retain explicitly empty unix_sockets maps.
  • Defer to attachment socket permissions when the controller supplies neither setting. Continue enforcing explicit restrictions, socket denials, and managed requirements.
  • Resolve omitted values to false for ordinary execution and remote configuration, preserving the default for commands without attachment grants.
  • Add debug logging for effective environment and remote execution network policies.

Testing

Add regression coverage for omitted, explicit, finite, empty, and managed socket policies through remote launch configuration, including live policy replacement and serialization round trips. Adjust remote environment tests to tolerate child-completion ordering and box large cold-resume test futures to reduce Windows stack usage.

…ted (#46004)

## Why

An omitted controller socket policy was treated as an explicit denial, preventing execution environments from supplying their own Unix socket grants.

## What changed

- Preserve omission of `dangerously_allow_all_unix_sockets` separately from `false`, and retain explicitly empty `unix_sockets` maps.
- Defer to attachment socket permissions when the controller supplies neither setting. Continue enforcing explicit restrictions, socket denials, and managed requirements.
- Resolve omitted values to `false` for ordinary execution and remote configuration, preserving the default for commands without attachment grants.
- Add debug logging for effective environment and remote execution network policies.

## Testing

Add regression coverage for omitted, explicit, finite, empty, and managed socket policies through remote launch configuration, including live policy replacement and serialization round trips. Adjust remote environment tests to tolerate child-completion ordering and box large cold-resume test futures to reduce Windows stack usage.

GitOrigin-RevId: 98a88d01cbb91aea1faaa03b3c414ef3be7af398
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/98a88d01cbb91aea1faaa03b3c414ef3be7af398 branch from e3e8c82 to 43354d0 Compare September 16, 2026 18:21
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot merged commit 43354d0 into main Sep 16, 2026
1 check failed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/98a88d01cbb91aea1faaa03b3c414ef3be7af398 branch September 16, 2026 18:21
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 16, 2026

This branch was successfully deployed

1 active deployment
issue-triage — 43354d0f Deployed Sep 16, 2026 by yossy216-cmyk via Translate non-English issue #13619
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants