Skip to content

Preserve environment configuration ownership - #38678

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/fe70c4be5f151432b69bf4b141e316faa89036ae
Aug 15, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/fe70c4be5f151432b69bf4b141e316faa89036ae

Conversation

@copyberry

@copyberry copyberry Bot commented Aug 15, 2026 •

Copy link
Copy Markdown

Preserve environment configuration ownership

Why

Environment attachments can either inherit configuration from their thread or
provide their own. Later thread setting updates must refresh inherited
configuration without overwriting attachment-owned permissions and capability
roots.

What changed

  • Resolve each attachment's configuration when it is selected and retain
    whether it came from the thread or the attachment owner.
  • Apply subsequent thread configuration updates only to thread-owned
    attachments, while preserving ownership across snapshots and child threads.
  • Keep the resolved configuration with the environment selection so runtime
    consumers use a single canonical value.

Testing

  • Extend remote-environment coverage to verify that thread-owned permissions
    follow thread updates while owner-provided read-only permissions remain in
    effect.
  • Cover configuration inheritance, attachment replacement, and owner-configured
    capability roots.

## Why

Environment attachments can either inherit configuration from their thread or
provide their own. Later thread setting updates must refresh inherited
configuration without overwriting attachment-owned permissions and capability
roots.

## What changed

- Resolve each attachment's configuration when it is selected and retain
  whether it came from the thread or the attachment owner.
- Apply subsequent thread configuration updates only to thread-owned
  attachments, while preserving ownership across snapshots and child threads.
- Keep the resolved configuration with the environment selection so runtime
  consumers use a single canonical value.

## Testing

- Extend remote-environment coverage to verify that thread-owned permissions
  follow thread updates while owner-provided read-only permissions remain in
  effect.
- Cover configuration inheritance, attachment replacement, and owner-configured
  capability roots.

GitOrigin-RevId: fe70c4be5f151432b69bf4b141e316faa89036ae
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/fe70c4be5f151432b69bf4b141e316faa89036ae branch from 81c4bf6 to 22bf16a Compare August 15, 2026 00:44
@copyberry
copyberry Bot merged commit 22bf16a into main Aug 15, 2026
28 of 32 checks passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/fe70c4be5f151432b69bf4b141e316faa89036ae branch August 15, 2026 00:46
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 15, 2026

This branch was previously deployed

1 inactive deployment
issue-triage — 22bf16a3 Deployed Aug 15, 2026 by PsychOsmosis via Identify potential duplicates (all issues) #37893
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants