Skip to content

Support caller-provided MITM CAs in the network proxy - #47132

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/cb209295c19fbe53a9fa0194f11ff06acccabef6
Sep 21, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/cb209295c19fbe53a9fa0194f11ff06acccabef6

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Support caller-provided MITM CAs in the network proxy

What changed

  • Add optional network.mitm_ca configuration with certificate_file and
    private_key_file for trusted proxy configuration. Require MITM to be enabled
    and retain the generated CA when no external CA is configured.
  • Validate absolute paths, regular files, file sizes, certificate/key matching,
    and Unix private-key permissions. Reject symlinks on Unix, private keys embedded
    in certificate files, and external private keys on non-Unix platforms.
  • Store derived external-CA trust bundles in the proxy artifact directory,
    include only certificates, and skip inherited generated bundles to avoid
    retaining stale roots.
  • Preserve MITM for external CAs when disabling credential brokerage. Reject
    external CA configuration for remote execution, even when the proxy is disabled,
    and reject unknown fields in NetworkProxyConfig.
  • Default the upstream request version adapter to HTTP/1.1 and remove the request
    URI from upstream request failure context.

Testing

Add regression coverage for external CA configuration, mismatched keys, embedded
private keys, non-Unix rejection, trust-bundle placement and contents, stale-root
exclusion, credential-broker toggling, and remote configuration rejection.

## What changed

- Add optional `network.mitm_ca` configuration with `certificate_file` and
  `private_key_file` for trusted proxy configuration. Require MITM to be enabled
  and retain the generated CA when no external CA is configured.
- Validate absolute paths, regular files, file sizes, certificate/key matching,
  and Unix private-key permissions. Reject symlinks on Unix, private keys embedded
  in certificate files, and external private keys on non-Unix platforms.
- Store derived external-CA trust bundles in the proxy artifact directory,
  include only certificates, and skip inherited generated bundles to avoid
  retaining stale roots.
- Preserve MITM for external CAs when disabling credential brokerage. Reject
  external CA configuration for remote execution, even when the proxy is disabled,
  and reject unknown fields in `NetworkProxyConfig`.
- Default the upstream request version adapter to HTTP/1.1 and remove the request
  URI from upstream request failure context.

## Testing

Add regression coverage for external CA configuration, mismatched keys, embedded
private keys, non-Unix rejection, trust-bundle placement and contents, stale-root
exclusion, credential-broker toggling, and remote configuration rejection.

GitOrigin-RevId: cb209295c19fbe53a9fa0194f11ff06acccabef6
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/cb209295c19fbe53a9fa0194f11ff06acccabef6 branch from 648e6a8 to e4dba90 Compare September 21, 2026 23:44
@copyberry
copyberry Bot merged commit e4dba90 into main Sep 21, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/cb209295c19fbe53a9fa0194f11ff06acccabef6 branch September 21, 2026 23:44
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 21, 2026
@efratgez
efratgez deployed to issue-triage September 21, 2026 23:54 — with GitHub Actions Active
@efratgez
efratgez deployed to issue-triage September 21, 2026 23:54 — with GitHub Actions Active
@efratgez
efratgez deployed to issue-triage September 21, 2026 23:54 — with GitHub Actions Active
@bpgould
bpgould deployed to issue-triage September 22, 2026 00:10 — with GitHub Actions Active
@bpgould
bpgould deployed to issue-triage September 22, 2026 00:10 — with GitHub Actions Active
@bpgould
bpgould deployed to issue-triage September 22, 2026 00:10 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants