Repository navigation
Add a bubblewrap backend for sandbox integrity checks - #51840
Merged
copyberry[bot] merged 1 commit intoOct 7, 2026
Merged
copyberry[bot] merged 1 commit into
copyberry[bot] merged 1 commit into
Conversation
## What changed Add Linux dependency discovery and policy preparation to `exec-server`'s sandbox integrity module. Inventory bundled and system `bwrap` candidates and the deny-glob scanner using the launcher's location and the command's `PATH` and working directory. Resolve `:tmpdir` and tilde-prefixed deny globs using the command's `TMPDIR` and `HOME`, with account home-directory fallback. Reuse Linux sandbox helpers to expand deny globs in the command's explicit environment. ## Testing Add Linux tests covering symlinked launchers, relative and empty `PATH` entries, and empty, relative, and tilde-prefixed `TMPDIR` values alongside home-relative deny globs. GitOrigin-RevId: fe404fa4be77ece677b22d52d77a7234dbf0cffe
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/fe404fa4be77ece677b22d52d77a7234dbf0cffe
branch
from
October 7, 2026 21:50
93e656c to
d9960e1
Compare
Contributor
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/fe404fa4be77ece677b22d52d77a7234dbf0cffe
branch
October 7, 2026 21:51
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add a bubblewrap backend for sandbox integrity checks
What changed
Add Linux dependency discovery and policy preparation to
exec-server's sandbox integrity module. Inventory bundled and systembwrapcandidates and the deny-glob scanner using the launcher's location and the command'sPATHand working directory.Resolve
:tmpdirand tilde-prefixed deny globs using the command'sTMPDIRandHOME, with account home-directory fallback. Reuse Linux sandbox helpers to expand deny globs in the command's explicit environment.Testing
Add Linux tests covering symlinked launchers, relative and empty
PATHentries, and empty, relative, and tilde-prefixedTMPDIRvalues alongside home-relative deny globs.