Skip to content

Avoid fork when spawning macOS filesystem helpers - #46661

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/d49c00787f30ec0bc196f9e066a0770fc8151152
Sep 19, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/d49c00787f30ec0bc196f9e066a0770fc8151152

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Avoid fork when spawning macOS filesystem helpers

Why

Filesystem helpers use a pre_exec callback to close inherited descriptors on macOS, forcing a fork before execution. Native spawning needs to preserve that isolation and support the socket used for file descriptor transfer.

What changed

  • Launch filesystem helpers through codex_utils_pty::Command, using posix_spawn with POSIX_SPAWN_CLOEXEC_DEFAULT on macOS and returning native launch errors without a fork fallback.
  • Extend the shared command wrapper with explicit descriptor and fallback policies, socket-backed stdin, and custom argv[0] support.
  • Add Child::wait_with_output to drain stdout and stderr concurrently, retain kill-on-drop behavior on cancellation, and keep output pipes open until the child exits.

Testing

Add regression tests for fork-free sandboxed reads, writes, and file descriptor transfers; sandbox denial of outside paths and symlink escapes; descriptor isolation; bidirectional socket stdin; custom argv[0]; executable-format errors; and output-pipe lifetimes.

## Why

Filesystem helpers use a `pre_exec` callback to close inherited descriptors on macOS, forcing a fork before execution. Native spawning needs to preserve that isolation and support the socket used for file descriptor transfer.

## What changed

- Launch filesystem helpers through `codex_utils_pty::Command`, using `posix_spawn` with `POSIX_SPAWN_CLOEXEC_DEFAULT` on macOS and returning native launch errors without a fork fallback.
- Extend the shared command wrapper with explicit descriptor and fallback policies, socket-backed stdin, and custom `argv[0]` support.
- Add `Child::wait_with_output` to drain stdout and stderr concurrently, retain kill-on-drop behavior on cancellation, and keep output pipes open until the child exits.

## Testing

Add regression tests for fork-free sandboxed reads, writes, and file descriptor transfers; sandbox denial of outside paths and symlink escapes; descriptor isolation; bidirectional socket stdin; custom `argv[0]`; executable-format errors; and output-pipe lifetimes.

GitOrigin-RevId: d49c00787f30ec0bc196f9e066a0770fc8151152
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/d49c00787f30ec0bc196f9e066a0770fc8151152 branch from d16a853 to 595cc91 Compare September 19, 2026 15:15
@copyberry
copyberry Bot merged commit 595cc91 into main Sep 19, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/d49c00787f30ec0bc196f9e066a0770fc8151152 branch September 19, 2026 15:15
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 19, 2026
@master5d
master5d deployed to issue-triage September 19, 2026 15:23 — with GitHub Actions Active
@master5d
master5d deployed to issue-triage September 19, 2026 15:23 — with GitHub Actions Active
@master5d
master5d deployed to issue-triage September 19, 2026 15:23 — with GitHub Actions Active
@master5d
master5d deployed to issue-triage September 19, 2026 15:24 — with GitHub Actions Active
@werdbrian
werdbrian deployed to issue-triage September 19, 2026 16:06 — with GitHub Actions Active
@werdbrian
werdbrian deployed to issue-triage September 19, 2026 16:06 — with GitHub Actions Active
@werdbrian
werdbrian deployed to issue-triage September 19, 2026 16:06 — with GitHub Actions Active
@werdbrian
werdbrian deployed to issue-triage September 19, 2026 16:07 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — 595cc91e Deployed Sep 19, 2026 by rtkzoop via Identify potential duplicates (open issues fallback) #46791
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.