mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
windows-sandbox: pass workspace roots to runner (#24108)
## Why #23813 switches the Windows sandbox runner path to `PermissionProfile`, but it still left one runtime anchor for resolving symbolic `:workspace_roots` entries. That is not enough once a turn has multiple effective workspace roots: exact entries and deny globs under `:workspace_roots` need to be materialized for every runtime root before the command runner chooses token mode or builds ACL plans. ## What Changed - Replaces the Windows runner/setup `permission_profile_cwd` plumbing with `workspace_roots: Vec<AbsolutePathBuf>`. - Resolves Windows-local `PermissionProfile` data with `materialize_project_roots_with_workspace_roots(...)` instead of the single-cwd helper. - Threads `Config::effective_workspace_roots()` through core execution, unified exec, TUI setup/read-grant flows, app-server setup, app-server `command/exec`, and `debug sandbox` on Windows. - Preserves those workspace roots through the zsh-fork escalation executor instead of rebuilding them from `sandbox_policy_cwd`. - Makes `ExecRequest::new(...)` and the remaining `build_exec_request(...)` helper path take `windows_sandbox_workspace_roots` explicitly so new call sites cannot silently fall back to `vec![cwd]`. - Clarifies the `debug sandbox` non-Windows comment: remaining cwd-dependent resolution still uses `sandbox_policy_cwd`, while `:workspace_roots` entries are already materialized from config roots. - Updates elevated runner IPC `SpawnRequest` to send `workspace_roots` and bumps the framed IPC protocol version to `3` for the payload shape change. - Adds Windows-local resolver coverage for expanding exact and glob `:workspace_roots` entries across multiple roots, plus core helper coverage proving explicit roots are preserved. ## Verification - `cargo check -p codex-windows-sandbox -p codex-core -p codex-tui -p codex-cli -p codex-app-server` - `cargo test -p codex-windows-sandbox` - `cargo test -p codex-core windows_sandbox` - `cargo test -p codex-core unix_escalation` - `cargo test -p codex-app-server windows_sandbox` - `cargo test -p codex-tui windows_sandbox` - `cargo test -p codex-cli debug_sandbox` - `just test -p codex-core unified_exec` - `just test -p codex-core build_exec_request_preserves_windows_workspace_roots` - `env -u CODEX_NETWORK_PROXY_ACTIVE -u CODEX_NETWORK_ALLOW_LOCAL_BINDING just test -p codex-app-server --lib command_exec` - `just test -p codex-windows-sandbox` - `just test -p codex-exec sandbox` - `just fix -p codex-core -p codex-app-server -p codex-windows-sandbox` A local macOS cross-check with `cargo check --target x86_64-pc-windows-msvc ...` did not reach crate Rust code because native dependencies require Windows SDK headers (`windows.h` / `assert.h`) in this environment; Windows CI remains the real target validation. Two local targeted filters compile but do not run assertions on macOS: `env -u CODEX_NETWORK_PROXY_ACTIVE -u CODEX_NETWORK_ALLOW_LOCAL_BINDING just test -p codex-app-server --lib command_exec_processor` matched zero tests, and `just test -p codex-linux-sandbox landlock` matched zero tests because the landlock suite is Linux-only.
This commit is contained in:
@@ -208,10 +208,12 @@ async fn run_command_under_sandbox(
|
||||
// In practice, this should be `std::env::current_dir()` because this CLI
|
||||
// does not support `--cwd`, but let's use the config value for consistency.
|
||||
let cwd = config.cwd.clone();
|
||||
// For now, we always use the same cwd for both the command and the
|
||||
// permission profile. In the future, we could add a CLI option to set them
|
||||
// separately.
|
||||
let permission_profile_cwd = cwd.clone();
|
||||
// Non-Windows sandbox launchers still use `sandbox_policy_cwd` for any
|
||||
// remaining cwd-dependent policy resolution. `:workspace_roots` entries in
|
||||
// the effective profile have already been materialized from config roots.
|
||||
let sandbox_policy_cwd = cwd.clone();
|
||||
#[cfg(target_os = "windows")]
|
||||
let workspace_roots = config.effective_workspace_roots();
|
||||
|
||||
let env = create_env(
|
||||
&config.permissions.shell_environment_policy,
|
||||
@@ -222,8 +224,7 @@ async fn run_command_under_sandbox(
|
||||
if let SandboxType::Windows = sandbox_type {
|
||||
#[cfg(target_os = "windows")]
|
||||
{
|
||||
run_command_under_windows_session(&config, command, cwd, permission_profile_cwd, env)
|
||||
.await;
|
||||
run_command_under_windows_session(&config, command, cwd, workspace_roots, env).await;
|
||||
}
|
||||
#[cfg(not(target_os = "windows"))]
|
||||
{
|
||||
@@ -266,7 +267,7 @@ async fn run_command_under_sandbox(
|
||||
command,
|
||||
file_system_sandbox_policy: &file_system_sandbox_policy,
|
||||
network_sandbox_policy,
|
||||
sandbox_policy_cwd: permission_profile_cwd.as_path(),
|
||||
sandbox_policy_cwd: sandbox_policy_cwd.as_path(),
|
||||
enforce_managed_network: false,
|
||||
network: network.as_ref(),
|
||||
extra_allow_unix_sockets: allow_unix_sockets,
|
||||
@@ -298,7 +299,7 @@ async fn run_command_under_sandbox(
|
||||
command,
|
||||
cwd.as_path(),
|
||||
&config.permissions.effective_permission_profile(),
|
||||
permission_profile_cwd.as_path(),
|
||||
sandbox_policy_cwd.as_path(),
|
||||
use_legacy_landlock,
|
||||
allow_network_for_proxy(managed_network_requirements_enabled),
|
||||
);
|
||||
@@ -350,7 +351,7 @@ async fn run_command_under_windows_session(
|
||||
config: &Config,
|
||||
command: Vec<String>,
|
||||
cwd: AbsolutePathBuf,
|
||||
permission_profile_cwd: AbsolutePathBuf,
|
||||
workspace_roots: Vec<AbsolutePathBuf>,
|
||||
env: std::collections::HashMap<String, String>,
|
||||
) -> ! {
|
||||
use codex_core::windows_sandbox::WindowsSandboxLevelExt;
|
||||
@@ -368,7 +369,7 @@ async fn run_command_under_windows_session(
|
||||
let spawned = if use_elevated {
|
||||
spawn_windows_sandbox_session_elevated_for_permission_profile(
|
||||
&permission_profile,
|
||||
permission_profile_cwd.as_path(),
|
||||
workspace_roots.as_slice(),
|
||||
config.codex_home.as_path(),
|
||||
command,
|
||||
cwd.as_path(),
|
||||
@@ -387,7 +388,7 @@ async fn run_command_under_windows_session(
|
||||
} else {
|
||||
spawn_windows_sandbox_session_legacy(
|
||||
&permission_profile,
|
||||
permission_profile_cwd.as_path(),
|
||||
workspace_roots.as_slice(),
|
||||
config.codex_home.as_path(),
|
||||
command,
|
||||
cwd.as_path(),
|
||||
@@ -1125,7 +1126,7 @@ mod tests {
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn debug_sandbox_uses_explicit_profile_cwd() -> anyhow::Result<()> {
|
||||
async fn debug_sandbox_uses_explicit_cwd() -> anyhow::Result<()> {
|
||||
let codex_home = TempDir::new()?;
|
||||
let cwd = TempDir::new()?;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user