mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
cb870a169a
## Summary - detect WSL1 before Codex probes or invokes the Linux bubblewrap sandbox - fail early with a clear unsupported-operation message when a command would require bubblewrap on WSL1 - document that WSL2 follows the normal Linux bubblewrap path while WSL1 is unsupported ## Why Codex 0.115.0 made bubblewrap the default Linux sandbox. WSL1 cannot create the user namespaces that bubblewrap needs, so shell commands currently fail later with a raw bwrap namespace error. This makes the unsupported environment explicit and keeps non-bubblewrap paths unchanged. The WSL detection reads /proc/version, lets an explicit WSL<version> marker decide WSL1 vs WSL2+, and only treats a bare Microsoft marker as WSL1 when no explicit WSL version is present. addresses https://github.com/openai/codex/issues/16076 --------- Co-authored-by: Codex <noreply@openai.com>
48 lines
1.5 KiB
Rust
48 lines
1.5 KiB
Rust
#[cfg(target_os = "linux")]
|
|
mod bwrap;
|
|
pub mod landlock;
|
|
mod manager;
|
|
pub mod policy_transforms;
|
|
#[cfg(target_os = "macos")]
|
|
pub mod seatbelt;
|
|
|
|
#[cfg(target_os = "linux")]
|
|
pub use bwrap::find_system_bwrap_in_path;
|
|
#[cfg(target_os = "linux")]
|
|
pub use bwrap::system_bwrap_warning;
|
|
pub use manager::SandboxCommand;
|
|
pub use manager::SandboxExecRequest;
|
|
pub use manager::SandboxManager;
|
|
pub use manager::SandboxTransformError;
|
|
pub use manager::SandboxTransformRequest;
|
|
pub use manager::SandboxType;
|
|
pub use manager::SandboxablePreference;
|
|
pub use manager::get_platform_sandbox;
|
|
|
|
use codex_protocol::error::CodexErr;
|
|
|
|
#[cfg(not(target_os = "linux"))]
|
|
pub fn system_bwrap_warning(
|
|
_sandbox_policy: &codex_protocol::protocol::SandboxPolicy,
|
|
) -> Option<String> {
|
|
None
|
|
}
|
|
|
|
impl From<SandboxTransformError> for CodexErr {
|
|
fn from(err: SandboxTransformError) -> Self {
|
|
match err {
|
|
SandboxTransformError::MissingLinuxSandboxExecutable => {
|
|
CodexErr::LandlockSandboxExecutableNotProvided
|
|
}
|
|
#[cfg(target_os = "linux")]
|
|
SandboxTransformError::Wsl1UnsupportedForBubblewrap => {
|
|
CodexErr::UnsupportedOperation(crate::bwrap::WSL1_BWRAP_WARNING.to_string())
|
|
}
|
|
#[cfg(not(target_os = "macos"))]
|
|
SandboxTransformError::SeatbeltUnavailable => CodexErr::UnsupportedOperation(
|
|
"seatbelt sandbox is only available on macOS".to_string(),
|
|
),
|
|
}
|
|
}
|
|
}
|