mirror of
https://github.com/openai/codex.git
synced 2026-09-28 16:53:06 +08:00
## Why Asynchronous Guardian scoring omitted the target environment's denied-read restrictions, and cached score authorization did not include that permission context. A score from one environment could therefore be reused for an action in another environment with different restrictions. ## What changed - Share permission resolution between synchronous review and asynchronous scoring, including resolving `write_stdin` targets from the owning terminal session. - Include environment identity and denied-read paths/globs in async scoring context and cached score authorization. - Fall back to synchronous review when permission evidence cannot be resolved or exceeds the async limit of 3,000 bytes, rather than omitting restrictions. ## Testing Add regression coverage for rejecting cached scores with different environments or denied paths, passing the target environment's restrictions to the classifier, and rejecting oversized async permission evidence. GitOrigin-RevId: 14b6f3454bbea458be037560eb1da47d22874df1