mirror of
https://github.com/openai/codex.git
synced 2026-08-23 13:09:46 +00:00
## What changed - Add `EnvironmentNetworkPolicy` as a serializable view of portable domain, Unix-socket, upstream-proxy, and local-binding restrictions without exposing controller-owned proxy runtime settings. - Add an optional `network_policy` field to `EnvironmentConfig` and re-export the policy and related permission types through the core APIs. - Reject owner-provided network policies during environment preview and readiness until runtime enforcement is implemented, while preserving the existing controller policy when the field is absent. ## Testing - Cover rejection through both environment preview and readiness, including preservation of the existing environment selection. GitOrigin-RevId: 80ad4cf4d4a45632daa7a823e6cf568eb0e8bb80