mirror of
https://github.com/openai/codex.git
synced 2026-09-29 01:03:01 +08:00
## Why Private IP destinations always bypassed inherited upstream proxies, preventing their use for private networks reachable through an upstream VPN proxy. ## What changed - Add `codex exec-server --proxy-private-ips-via-upstream`, also configurable with `CODEX_EXEC_SERVER_PROXY_PRIVATE_IPS_VIA_UPSTREAM=true`. The setting defaults to disabled. - Allow permitted RFC 1918, carrier-grade NAT, and IPv6 unique-local destinations to use an applicable upstream proxy. Loopback and link-local destinations retain direct routing, and destination access policy still applies. - Keep connections direct when no valid upstream proxy applies or `allow_upstream_proxy=false`. Errors after selecting an upstream proxy do not trigger a direct retry. - Rename `ExecServerRuntimePaths` to `ExecServerRuntimeOptions` and carry the routing setting from executor startup into the managed network proxy. ## Testing Add routing coverage for private address ranges, special-use addresses, and public targets with the option enabled and disabled. Verify that HTTP and CONNECT requests still enforce destination allowlists and denylists, and update the CLI help snapshot. GitOrigin-RevId: b7c9cc7da0e0f545694a6521b74c9b36b7b92769
41 lines
1.6 KiB
Rust
41 lines
1.6 KiB
Rust
//! Minimal exec-server fixture for Bazel-only integration tests.
|
|
//!
|
|
//! Linking only exec-server avoids depending on the full Codex CLI binary
|
|
//! when a test only needs a WebSocket executor endpoint. It handles the arg0
|
|
//! helper mode because sandboxed process requests re-exec this binary.
|
|
|
|
use codex_exec_server::ExecServerRuntimeOptions;
|
|
use codex_http_client::HttpClientFactory;
|
|
use codex_http_client::OutboundProxyPolicy;
|
|
use std::ffi::OsStr;
|
|
|
|
const CODEX_LINUX_SANDBOX_EXE_ENV_VAR: &str = "CODEX_TEST_LINUX_SANDBOX_EXE";
|
|
|
|
fn main() -> Result<(), Box<dyn std::error::Error + Send + Sync>> {
|
|
#[cfg(target_os = "linux")]
|
|
codex_utils_pty::init_spawn_helper(std::env::args_os());
|
|
let mut args = std::env::args_os();
|
|
let _ = args.next();
|
|
let argv1 = args.next();
|
|
#[cfg(unix)]
|
|
if argv1.as_deref() == Some(OsStr::new(codex_exec_server::CODEX_ARG0_EXEC_HELPER_ARG1)) {
|
|
codex_exec_server::run_arg0_exec_helper_main();
|
|
}
|
|
if argv1.as_deref() == Some(OsStr::new(codex_exec_server::CODEX_FS_HELPER_ARG1)) {
|
|
codex_exec_server::run_fs_helper_main();
|
|
}
|
|
|
|
let current_exe = std::env::current_exe()?;
|
|
let codex_linux_sandbox_exe =
|
|
std::env::var_os(CODEX_LINUX_SANDBOX_EXE_ENV_VAR).map(std::path::PathBuf::from);
|
|
let runtime_paths = ExecServerRuntimeOptions::new(current_exe, codex_linux_sandbox_exe)?;
|
|
tokio::runtime::Builder::new_multi_thread()
|
|
.enable_all()
|
|
.build()?
|
|
.block_on(codex_exec_server::run_main(
|
|
"ws://127.0.0.1:0",
|
|
runtime_paths,
|
|
HttpClientFactory::new(OutboundProxyPolicy::ReqwestDefault),
|
|
))
|
|
}
|