1 Commits
Author SHA1 Message Date
open-matt aa380897f6 Add startup-only PID namespace inheritance to exec-server (#47989)
## Why

When a container denies fresh `/proc` mounts, the existing sandbox fallback retains the caller's `/proc` while creating a new PID namespace. Process IDs inside the sandbox can then differ from those exposed by `/proc`, breaking process lookups.

## What changed

- Add `codex exec-server --linux-sandbox-pid-namespace=inherit` to reuse the caller's PID namespace and `/proc` for both process and filesystem helpers. Repository config and command environment variables cannot enable it.
- Keep `isolate` as the default, preserving the existing mount fallback and compatibility with older helpers. Inheritance requires an updated helper and omits `--unshare-pid` and `--as-pid-1`.
- Preserve other sandbox restrictions. With `:minimal`, bind the inherited `/proc` read-only with its container masks and apply explicit filesystem denials afterward.

Inheritance is intended for dedicated environments: it allows sandboxed commands to signal other same-UID processes, including the executor.

## Testing

Add unit and integration coverage for namespace flags, denied proc mounts, consistent process IDs, retained sandbox restrictions, and startup-only selection across process and filesystem helpers.

GitOrigin-RevId: dd13f2b9286d7edcf366b3a42a455f4d78daaf27
2026-09-25 03:12:10 +00:00