mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
## Why This supersedes #19391. During stack repair, GitHub marked #19391 as merged into a temporary stack branch rather than into `main`, so the runtime-config change needed a fresh PR. `PermissionProfile` is now the canonical permissions shape after #19231 because it can distinguish `Managed`, `Disabled`, and `External` enforcement while also carrying filesystem rules that legacy `SandboxPolicy` cannot represent cleanly. Core config and session state still needed to accept profile-backed permissions without forcing every profile through the strict legacy bridge, which rejected valid runtime profiles such as direct write roots. The unrelated CI/test hardening that previously rode along with this PR has been split into #19683 so this PR stays focused on the permissions model migration. ## What Changed - Adds `Permissions.permission_profile` and `SessionConfiguration.permission_profile` as constrained runtime state, while keeping `sandbox_policy` as a legacy compatibility projection. - Introduces profile setters that keep `PermissionProfile`, split filesystem/network policies, and legacy `SandboxPolicy` projections synchronized. - Uses a compatibility projection for requirement checks and legacy consumers instead of rejecting profiles that cannot round-trip through `SandboxPolicy` exactly. - Updates config loading, config overrides, session updates, turn context plumbing, prompt permission text, sandbox tags, and exec request construction to carry profile-backed runtime permissions. - Preserves configured deny-read entries and `glob_scan_max_depth` when command/session profiles are narrowed. - Adds `PermissionProfile::read_only()` and `PermissionProfile::workspace_write()` presets that match legacy defaults. ## Verification - `cargo test -p codex-core direct_write_roots` - `cargo test -p codex-core runtime_roots_to_legacy_projection` - `cargo test -p codex-app-server requested_permissions_trust_project_uses_permission_profile_intent` --- [//]: # (BEGIN SAPLING FOOTER) Stack created with [Sapling](https://sapling-scm.com). Best reviewed with [ReviewStack](https://reviewstack.dev/openai/codex/pull/19606). * #19395 * #19394 * #19393 * #19392 * __->__ #19606
49 lines
1.5 KiB
Rust
49 lines
1.5 KiB
Rust
#[cfg(target_os = "linux")]
|
|
mod bwrap;
|
|
pub mod landlock;
|
|
mod manager;
|
|
pub mod policy_transforms;
|
|
#[cfg(target_os = "macos")]
|
|
pub mod seatbelt;
|
|
|
|
#[cfg(target_os = "linux")]
|
|
pub use bwrap::find_system_bwrap_in_path;
|
|
#[cfg(target_os = "linux")]
|
|
pub use bwrap::system_bwrap_warning;
|
|
pub use manager::SandboxCommand;
|
|
pub use manager::SandboxExecRequest;
|
|
pub use manager::SandboxManager;
|
|
pub use manager::SandboxTransformError;
|
|
pub use manager::SandboxTransformRequest;
|
|
pub use manager::SandboxType;
|
|
pub use manager::SandboxablePreference;
|
|
pub use manager::compatibility_sandbox_policy_for_permission_profile;
|
|
pub use manager::get_platform_sandbox;
|
|
|
|
use codex_protocol::error::CodexErr;
|
|
|
|
#[cfg(not(target_os = "linux"))]
|
|
pub fn system_bwrap_warning(
|
|
_sandbox_policy: &codex_protocol::protocol::SandboxPolicy,
|
|
) -> Option<String> {
|
|
None
|
|
}
|
|
|
|
impl From<SandboxTransformError> for CodexErr {
|
|
fn from(err: SandboxTransformError) -> Self {
|
|
match err {
|
|
SandboxTransformError::MissingLinuxSandboxExecutable => {
|
|
CodexErr::LandlockSandboxExecutableNotProvided
|
|
}
|
|
#[cfg(target_os = "linux")]
|
|
SandboxTransformError::Wsl1UnsupportedForBubblewrap => {
|
|
CodexErr::UnsupportedOperation(crate::bwrap::WSL1_BWRAP_WARNING.to_string())
|
|
}
|
|
#[cfg(not(target_os = "macos"))]
|
|
SandboxTransformError::SeatbeltUnavailable => CodexErr::UnsupportedOperation(
|
|
"seatbelt sandbox is only available on macOS".to_string(),
|
|
),
|
|
}
|
|
}
|
|
}
|