mirror of
https://github.com/openai/codex.git
synced 2026-08-27 13:49:27 +00:00
## Why Sandboxed exec-server process requests can use a restricted filesystem profile that does not expose the exec-server binary. On Linux, the outer bubblewrap stage re-enters that binary with the `codex-linux-sandbox` argv0 to install seccomp, so hiding the binary prevents the requested process from starting. ## What changed - add the configured `codex_self_exe` to the process permission profile before constructing the outer platform sandbox - add a Linux exec-server integration test that starts a real remote process with restricted reads and verifies it can read an allowed workspace file ## Test plan - `just test -p codex-exec-server process_sandbox` - `just test -p codex-exec-server --test exec_process remote_process_keeps_sandbox_helper_visible_with_restricted_reads`