Skip to content

Fix Windows sandbox ACL repair for long runtime paths - #49058

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/325c17085fa4379eebe982d49175dd2151b0681e
Sep 28, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/325c17085fa4379eebe982d49175dd2151b0681e

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Fix Windows sandbox ACL repair for long runtime paths

Why

Runtime ACL repair needs to handle nested files and directories beyond the legacy Windows path limit.

What changed

Use Rust's OpenOptions for ACL reads and handle-based SetSecurityInfo for updates to support extended-length paths. Request ACL-write access only when grants need updating, and share allocation cleanup across success and error paths.

Testing

Add a regression test covering long directory and file paths alongside a short-path control. Verify repeated repairs grant read/execute access without granting write, delete, or ACL-management rights, and that already-correct grants remain no-ops.

## Why

Runtime ACL repair needs to handle nested files and directories beyond the legacy Windows path limit.

## What changed

Use Rust's `OpenOptions` for ACL reads and handle-based `SetSecurityInfo` for updates to support extended-length paths. Request ACL-write access only when grants need updating, and share allocation cleanup across success and error paths.

## Testing

Add a regression test covering long directory and file paths alongside a short-path control. Verify repeated repairs grant read/execute access without granting write, delete, or ACL-management rights, and that already-correct grants remain no-ops.

GitOrigin-RevId: 325c17085fa4379eebe982d49175dd2151b0681e
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/325c17085fa4379eebe982d49175dd2151b0681e branch from 3a64ae5 to df3e439 Compare September 28, 2026 19:01
@github-actions

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot merged commit df3e439 into main Sep 28, 2026
4 of 8 checks passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/325c17085fa4379eebe982d49175dd2151b0681e branch September 28, 2026 19:01
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 28, 2026

This branch was successfully deployed

1 active deployment
issue-triage — df3e439c Deployed Sep 28, 2026 by zengpenghui123-tech via Translate non-English issue #15928
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants