Skip to content

Prefer the provisioning service for automatic Windows sandbox setup - #46239

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/1041ae76e9b0893ad60f30a5cdc506748be52552
Sep 17, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/1041ae76e9b0893ad60f30a5cdc506748be52552

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Prefer the provisioning service for automatic Windows sandbox setup

What changed

  • Use the installed provisioning service regardless of the onboarding feature gate. Fall back to the elevated helper only when the service is unavailable; propagate service errors.
  • Pass the effective proxy settings and filter listener ports to match them, including when preserving saved settings.
  • Remove stale credentials before repairing missing, disabled, or password-expired sandbox accounts so older services cannot mistake them for completed setup.
  • Select helper fallback when workload-identity environment variables are present, since service requests do not carry that environment. Continue rejecting helper fallback for registered Core.

Testing

Extend account-repair tests to cover stale credential removal, missing and disabled accounts, and repeated setup checks. Add subprocess tests for workload-identity routing with and without registered Core.

…46239)

## What changed

- Use the installed provisioning service regardless of the onboarding feature gate. Fall back to the elevated helper only when the service is unavailable; propagate service errors.
- Pass the effective proxy settings and filter listener ports to match them, including when preserving saved settings.
- Remove stale credentials before repairing missing, disabled, or password-expired sandbox accounts so older services cannot mistake them for completed setup.
- Select helper fallback when workload-identity environment variables are present, since service requests do not carry that environment. Continue rejecting helper fallback for registered Core.

## Testing

Extend account-repair tests to cover stale credential removal, missing and disabled accounts, and repeated setup checks. Add subprocess tests for workload-identity routing with and without registered Core.

GitOrigin-RevId: 1041ae76e9b0893ad60f30a5cdc506748be52552
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/1041ae76e9b0893ad60f30a5cdc506748be52552 branch from 9fedd66 to 32b54cf Compare September 17, 2026 15:35
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot merged commit 32b54cf into main Sep 17, 2026
1 check failed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/1041ae76e9b0893ad60f30a5cdc506748be52552 branch September 17, 2026 15:35
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 17, 2026
@stozo04
stozo04 deployed to issue-triage September 17, 2026 15:44 — with GitHub Actions Active
@stozo04
stozo04 deployed to issue-triage September 17, 2026 15:44 — with GitHub Actions Active
@stozo04
stozo04 deployed to issue-triage September 17, 2026 15:44 — with GitHub Actions Active
@stozo04
stozo04 deployed to issue-triage September 17, 2026 15:45 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — 32b54cff Deployed Sep 17, 2026 by stozo04 via Identify potential duplicates (open issues fallback) #46338
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants