Skip to content

Preserve filesystem denials when preparing approved commands - #48155

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/40584473da98a15e606bb1a8934308f69528850f
Sep 25, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/40584473da98a15e606bb1a8934308f69528850f

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Preserve filesystem denials when preparing approved commands

Why

Approved commands need broader write access while retaining explicit read denials. On Linux, binding the filesystem root writable can shadow standard devices, and additional root-metadata mounts can reopen denied symlink targets.

What changed

  • Add FileSystemSandboxPolicy::for_approved_command to grant root and root-metadata writes while retaining path and glob denials. Keep the original policy when denials cannot be resolved or deny the root.
  • Restore standard devices after Linux writable root binds, then apply explicit deny masks. Avoid redundant root-alias binds and inherit root-metadata writes from the root mount so denied targets stay masked.
  • Preserve literal deny paths alongside resolved targets so Linux can reject denials that cross writable symlinks.
  • Advertise Linux device and approved-root restriction support through two opt-in exec-server capabilities, omitted from serialization when false.

Testing

Add regression coverage for approval policy materialization across Unix, Windows drive, and UNC paths; Windows volume expansion; Linux device access and metadata symlink restrictions; and capability serialization compatibility.

## Why

Approved commands need broader write access while retaining explicit read denials. On Linux, binding the filesystem root writable can shadow standard devices, and additional root-metadata mounts can reopen denied symlink targets.

## What changed

- Add `FileSystemSandboxPolicy::for_approved_command` to grant root and root-metadata writes while retaining path and glob denials. Keep the original policy when denials cannot be resolved or deny the root.
- Restore standard devices after Linux writable root binds, then apply explicit deny masks. Avoid redundant root-alias binds and inherit root-metadata writes from the root mount so denied targets stay masked.
- Preserve literal deny paths alongside resolved targets so Linux can reject denials that cross writable symlinks.
- Advertise Linux device and approved-root restriction support through two opt-in exec-server capabilities, omitted from serialization when false.

## Testing

Add regression coverage for approval policy materialization across Unix, Windows drive, and UNC paths; Windows volume expansion; Linux device access and metadata symlink restrictions; and capability serialization compatibility.

GitOrigin-RevId: 40584473da98a15e606bb1a8934308f69528850f
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/40584473da98a15e606bb1a8934308f69528850f branch from ae0cf99 to 645b683 Compare September 25, 2026 18:07
@copyberry
copyberry Bot merged commit 645b683 into main Sep 25, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/40584473da98a15e606bb1a8934308f69528850f branch September 25, 2026 18:07
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 25, 2026

This branch was successfully deployed

1 active deployment
issue-triage — 645b683a Deployed Sep 25, 2026 by chaoRookie via Translate non-English issue #15132
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants