Skip to content

fix(cli): use numeric TIOCSTI in macOS sandbox policy - #1

Open
bibryam wants to merge 1 commit into
mainfrom
codex/fix-macos-tiocsti-constant
Open

bibryam wants to merge 1 commit into
mainfrom
codex/fix-macos-tiocsti-constant

Conversation

@bibryam

@bibryam bibryam commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

Use the platform's numeric libc::TIOCSTI value in the generated Seatbelt policy instead of the bare TIOCSTI symbol.

On macOS 14.2, the existing symbolic rule causes sandbox-exec to fail while compiling the policy, before it starts the requested program:

sandbox-exec: unbound variable: TIOCSTI at <input string>, line 132, column 33

This reproduces even for /usr/bin/true, independently of a terminal, browser, model, or user project. The affected rule was introduced in openai#42590.

The fix preserves the terminal-input-injection denial and its position after the generated policy. It does not remove a security rule or change permissions. Using libc::TIOCSTI avoids depending on a Seatbelt symbol that older macOS versions do not expose.

Regression coverage

  • Add a public codex sandbox startup test with redirected standard streams.
  • Retain the disposable-PTY test that first proves input injection works outside the sandbox, then verifies the sandbox rejects it with EPERM and leaves no injected input queued.
  • Share the existing nested-Seatbelt availability check between the two tests.

Validation

Tested on the affected host: macOS 14.2 (23C64), Apple Silicon, Rust 1.95.0.

  • just fmt — passed.
  • git diff --check — passed.
  • just test -p codex-cli --test sandbox_tty — 2 passed, 0 skipped.
  • just test -p codex-cli --success-output immediate — 451 passed, 0 skipped.
  • target/debug/codex sandbox -P :read-only -- /usr/bin/true — exit 0.

The Rust test runs used CARGO_PROFILE_DEV_DEBUG=0 CARGO_PROFILE_TEST_DEBUG=0 CARGO_BUILD_JOBS=4 to bound build disk/memory usage. The real Seatbelt checks ran outside a parent Seatbelt sandbox; they did not take the nested-sandbox skip path.

Both current upstream and the installed desktop build use sandbox -- COMMAND; macos is not a subcommand in these versions. The installed binary also reproduces the same TIOCSTI failure with the canonical command shown above. No installed app binaries or security settings were modified for this PR.

Review location

This is a review PR in the reporter's fork, not an upstream PR. OpenAI's current contribution policy accepts bug reports and root-cause analysis rather than external code contributions. Upstream report: openai#45119

Copy link
Copy Markdown

Thanks for investigating this and providing a fix. I am experiencing the same browser / Computer Use startup failure on macOS 13.5.

Environment (verified locally):

  • macOS 13.5, build 22G74
  • Desktop app version 26.930.21537, build 12776
  • The app updater reports up_to_date.

Both connecting to a browser and calling await cua.getState() fail before any browser state is returned. The error is:

node_repl kernel exited unexpectedly
kernel_status: exited(code=65)
sandbox-exec: <input string>:148:33: unbound variable: | \tTIOCSTI
reason: stdout_eof

Some attempts first return trusted Node process exited unexpectedly; kernel reset, rerun your request. Explicitly resetting the tool runtime and retrying still produces the same error.

The following minimal test independently reproduces the parser failure on my machine:

/usr/bin/sandbox-exec -p '(version 1)(deny default)(deny file-ioctl (ioctl-command TIOCSTI))' /usr/bin/true

It exits with code 65 and unbound variable: TIOCSTI. Read-only inspection also found the symbolic (deny file-ioctl (ioctl-command TIOCSTI)) rule in the desktop app's bundled Codex executable.

I have not applied or tested your patch, and no application binaries or sandbox protections have been modified. Do you have guidance for applying a compatible backport to this desktop version while preserving the existing sandbox protections, or know of an official desktop release that includes the fix?

Happy to provide additional non-sensitive diagnostic details if useful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants