Files
codex/codex-rs/exec-server-protocol
viyatb-oai 645b683a9e Preserve filesystem denials when preparing approved commands (#48155)
## Why

Approved commands need broader write access while retaining explicit read denials. On Linux, binding the filesystem root writable can shadow standard devices, and additional root-metadata mounts can reopen denied symlink targets.

## What changed

- Add `FileSystemSandboxPolicy::for_approved_command` to grant root and root-metadata writes while retaining path and glob denials. Keep the original policy when denials cannot be resolved or deny the root.
- Restore standard devices after Linux writable root binds, then apply explicit deny masks. Avoid redundant root-alias binds and inherit root-metadata writes from the root mount so denied targets stay masked.
- Preserve literal deny paths alongside resolved targets so Linux can reject denials that cross writable symlinks.
- Advertise Linux device and approved-root restriction support through two opt-in exec-server capabilities, omitted from serialization when false.

## Testing

Add regression coverage for approval policy materialization across Unix, Windows drive, and UNC paths; Windows volume expansion; Linux device access and metadata symlink restrictions; and capability serialization compatibility.

GitOrigin-RevId: 40584473da98a15e606bb1a8934308f69528850f
2026-09-25 18:06:57 +00:00
..