Repository navigation
Conversation
|
Thanks for investigating this and providing a fix. I am experiencing the same browser / Computer Use startup failure on macOS 13.5. Environment (verified locally):
Both connecting to a browser and calling Some attempts first return The following minimal test independently reproduces the parser failure on my machine: /usr/bin/sandbox-exec -p '(version 1)(deny default)(deny file-ioctl (ioctl-command TIOCSTI))' /usr/bin/trueIt exits with code 65 and I have not applied or tested your patch, and no application binaries or sandbox protections have been modified. Do you have guidance for applying a compatible backport to this desktop version while preserving the existing sandbox protections, or know of an official desktop release that includes the fix? Happy to provide additional non-sensitive diagnostic details if useful. |
Summary
Use the platform's numeric
libc::TIOCSTIvalue in the generated Seatbelt policy instead of the bareTIOCSTIsymbol.On macOS 14.2, the existing symbolic rule causes
sandbox-execto fail while compiling the policy, before it starts the requested program:This reproduces even for
/usr/bin/true, independently of a terminal, browser, model, or user project. The affected rule was introduced in openai#42590.The fix preserves the terminal-input-injection denial and its position after the generated policy. It does not remove a security rule or change permissions. Using
libc::TIOCSTIavoids depending on a Seatbelt symbol that older macOS versions do not expose.Regression coverage
codex sandboxstartup test with redirected standard streams.EPERMand leaves no injected input queued.Validation
Tested on the affected host: macOS 14.2 (23C64), Apple Silicon, Rust 1.95.0.
just fmt— passed.git diff --check— passed.just test -p codex-cli --test sandbox_tty— 2 passed, 0 skipped.just test -p codex-cli --success-output immediate— 451 passed, 0 skipped.target/debug/codex sandbox -P :read-only -- /usr/bin/true— exit 0.The Rust test runs used
CARGO_PROFILE_DEV_DEBUG=0 CARGO_PROFILE_TEST_DEBUG=0 CARGO_BUILD_JOBS=4to bound build disk/memory usage. The real Seatbelt checks ran outside a parent Seatbelt sandbox; they did not take the nested-sandbox skip path.Both current upstream and the installed desktop build use
sandbox -- COMMAND;macosis not a subcommand in these versions. The installed binary also reproduces the same TIOCSTI failure with the canonical command shown above. No installed app binaries or security settings were modified for this PR.Review location
This is a review PR in the reporter's fork, not an upstream PR. OpenAI's current contribution policy accepts bug reports and root-cause analysis rather than external code contributions. Upstream report: openai#45119