mirror of
https://github.com/openai/codex.git
synced 2026-09-28 16:53:06 +08:00
## Why Approved commands need broader write access while retaining explicit read denials. On Linux, binding the filesystem root writable can shadow standard devices, and additional root-metadata mounts can reopen denied symlink targets. ## What changed - Add `FileSystemSandboxPolicy::for_approved_command` to grant root and root-metadata writes while retaining path and glob denials. Keep the original policy when denials cannot be resolved or deny the root. - Restore standard devices after Linux writable root binds, then apply explicit deny masks. Avoid redundant root-alias binds and inherit root-metadata writes from the root mount so denied targets stay masked. - Preserve literal deny paths alongside resolved targets so Linux can reject denials that cross writable symlinks. - Advertise Linux device and approved-root restriction support through two opt-in exec-server capabilities, omitted from serialization when false. ## Testing Add regression coverage for approval policy materialization across Unix, Windows drive, and UNC paths; Windows volume expansion; Linux device access and metadata symlink restrictions; and capability serialization compatibility. GitOrigin-RevId: 40584473da98a15e606bb1a8934308f69528850f