Files
codex/codex-rs/core/src
jif bdda5da56c Preserve executor workspace permissions for apply_patch (#36133)
## What changed

Build the `apply_patch` filesystem sandbox context from the executor's canonical permission profile instead of the execution attempt's materialized profile. Continue merging any additional permissions requested by the patch while keeping workspace roots scoped separately to the attempt.

## Testing

- Update the sandbox-context test to verify that executor `workspace-write` permissions are preserved when attempt workspace roots and additional file permissions are present.

GitOrigin-RevId: 2a9a8c2e1b1945e300283c400d0f1e573225a553
2026-07-30 11:12:21 +00:00
..
2026-07-20 13:45:29 +00:00