Enforce configured network proxy in codex sandbox (#27035)

## Why

`codex sandbox` can start a network proxy from a configured permission
profile. Previously, sandbox-level containment was tied to managed
network requirements rather than whether a proxy was actually active.
This meant config-driven proxy policies were not consistently enforced
as the sandbox's only network path.

## What changed

- Enable proxy-only network containment whenever `codex sandbox` starts
a network proxy.
- Apply the same active-proxy check to the macOS and Linux sandbox
paths.
- Add a Linux regression test that verifies a sandboxed command cannot
establish a direct connection while the configured proxy is active.

## Test plan

- `just test -p codex-cli debug_sandbox::tests`
- `sandbox_with_network_proxy_blocks_direct_loopback_access` runs on
Linux to cover the config-driven proxy path end to end.
This commit is contained in:
viyatb-oai
2026-06-08 14:03:37 -07:00
committed by GitHub
parent e0ee491df3
commit 85fd52f7e4
7 changed files with 98 additions and 8 deletions
+4 -2
View File
@@ -47,7 +47,8 @@ pub fn create_linux_sandbox_command_args_for_permission_profile(
"--permission-profile".to_string(),
permission_profile_json,
];
if use_legacy_landlock {
// Proxy-only networking requires bubblewrap's isolated network namespace.
if use_legacy_landlock && !allow_network_for_proxy {
linux_cmd.push("--use-legacy-landlock".to_string());
}
if allow_network_for_proxy {
@@ -83,7 +84,8 @@ fn create_linux_sandbox_command_args(
"--command-cwd".to_string(),
command_cwd,
];
if use_legacy_landlock {
// Proxy-only networking requires bubblewrap's isolated network namespace.
if use_legacy_landlock && !allow_network_for_proxy {
linux_cmd.push("--use-legacy-landlock".to_string());
}
if allow_network_for_proxy {
+5 -2
View File
@@ -33,14 +33,16 @@ fn legacy_landlock_flag_is_included_when_requested() {
}
#[test]
fn proxy_flag_is_included_when_requested() {
fn proxy_flag_takes_precedence_over_legacy_landlock() {
let command = vec!["/bin/true".to_string()];
let command_cwd = Path::new("/tmp/link");
let cwd = Path::new("/tmp");
let permission_profile = PermissionProfile::read_only();
let args = create_linux_sandbox_command_args(
let args = create_linux_sandbox_command_args_for_permission_profile(
command,
command_cwd,
&permission_profile,
cwd,
/*use_legacy_landlock*/ true,
/*allow_network_for_proxy*/ true,
@@ -49,6 +51,7 @@ fn proxy_flag_is_included_when_requested() {
args.contains(&"--allow-network-for-proxy".to_string()),
true
);
assert_eq!(args.contains(&"--use-legacy-landlock".to_string()), false);
}
#[test]
+2 -2
View File
@@ -338,8 +338,8 @@ fn ensure_linux_bubblewrap_is_supported(
allow_network_for_proxy: bool,
is_wsl1: bool,
) -> Result<(), SandboxTransformError> {
let requires_bubblewrap = !use_legacy_landlock
&& (!file_system_sandbox_policy.has_full_disk_write_access() || allow_network_for_proxy);
let requires_bubblewrap = allow_network_for_proxy
|| (!use_legacy_landlock && !file_system_sandbox_policy.has_full_disk_write_access());
if is_wsl1 && requires_bubblewrap {
return Err(SandboxTransformError::Wsl1UnsupportedForBubblewrap);
}
+9
View File
@@ -342,6 +342,15 @@ fn wsl1_rejects_linux_bubblewrap_path() {
),
Err(super::SandboxTransformError::Wsl1UnsupportedForBubblewrap)
));
assert!(matches!(
super::ensure_linux_bubblewrap_is_supported(
&FileSystemSandboxPolicy::unrestricted(),
/*use_legacy_landlock*/ true,
/*allow_network_for_proxy*/ true,
/*is_wsl1*/ true,
),
Err(super::SandboxTransformError::Wsl1UnsupportedForBubblewrap)
));
}
#[cfg(target_os = "linux")]