mirror of
https://github.com/openai/codex.git
synced 2026-08-23 13:09:46 +00:00
## Why Filesystem denials and managed-network blocks did not share a structured event shape, requiring downstream consumers to rediscover enforcement paths and parse backend-specific output. See https://github.com/openai/codex/pull/17573. ## What changed - Add normalized filesystem and network violation types in `codex-sandboxing` and emit them through a shared tracing seam. - Classify filesystem denials by backend and reason, retaining an optional path and bounded output snippet, and preserve managed-network block context. - Report the sandbox type through exec-server responses so unified exec can classify remote denials without guessing; omitted values remain compatible with older peers. - Record violations from exec, apply-patch, shell-escalation, unified-exec, and managed-network enforcement paths without changing denial behavior. ## Testing - Cover filesystem classification, path extraction, `SIGSYS`, network event conversion, protocol compatibility, and remote sandbox-type propagation. GitOrigin-RevId: d673173b4fa6bdf0a24421194a8a61c81fab9c96