mirror of
https://github.com/openai/codex.git
synced 2026-09-03 14:59:03 +00:00
## Why Sandbox wrappers replaced the process launch command and did not carry an `ExecParams.arg0` override through to the inner process. ## What changed - Route sandboxed Unix launches with a custom `arg0` through a helper mode that re-execs the requested program with the override. - Expose the helper executable to the filesystem sandbox and dispatch its mode from Codex and exec-server test binaries. ## Testing Add coverage for the prepared sandbox command and an end-to-end remote process that verifies both the custom `arg0` and filesystem restrictions. GitOrigin-RevId: c9f8eef3906d184e670184c2eeed250d5895a9ca
183 lines
6.9 KiB
Rust
183 lines
6.9 KiB
Rust
mod arg0_exec_helper;
|
|
mod capability_discovery;
|
|
mod capability_discovery_cache;
|
|
mod client;
|
|
mod client_api;
|
|
mod client_transport;
|
|
mod connection;
|
|
mod environment;
|
|
mod environment_provider;
|
|
mod environment_registry;
|
|
mod environment_toml;
|
|
mod file_read;
|
|
mod fs_helper;
|
|
mod fs_helper_main;
|
|
mod fs_sandbox;
|
|
mod local_file_system;
|
|
mod local_process;
|
|
mod noise_channel;
|
|
mod noise_relay;
|
|
mod process;
|
|
mod process_sandbox;
|
|
mod regular_file;
|
|
mod relay;
|
|
mod relay_proto;
|
|
mod remote;
|
|
mod remote_file_system;
|
|
mod remote_process;
|
|
mod resolved_capability;
|
|
mod rpc;
|
|
mod runtime_paths;
|
|
mod sandboxed_file_system;
|
|
mod server;
|
|
mod telemetry;
|
|
mod trace_context;
|
|
mod websocket_pong_watchdog;
|
|
|
|
use codex_exec_server_protocol as protocol;
|
|
|
|
pub use arg0_exec_helper::CODEX_ARG0_EXEC_HELPER_ARG1;
|
|
pub use arg0_exec_helper::main as run_arg0_exec_helper_main;
|
|
pub use capability_discovery::CapabilityDiscoveryError;
|
|
pub use capability_discovery::discover_capability_roots;
|
|
pub use capability_discovery_cache::ExecutorCapabilityDiscoveryCache;
|
|
pub use client::ExecServerClient;
|
|
pub use client::ExecServerError;
|
|
pub use client::http_client::HttpResponseBodyStream;
|
|
pub use client::http_client::ReqwestHttpClient;
|
|
pub use client_api::ExecServerClientConnectOptions;
|
|
pub use client_api::HttpClient;
|
|
pub use client_api::NoiseRendezvousConnectArgs;
|
|
pub use client_api::NoiseRendezvousConnectBundle;
|
|
pub use client_api::NoiseRendezvousConnectProvider;
|
|
pub use client_api::RemoteExecServerConnectArgs;
|
|
pub use codex_exec_server_protocol::ExecutorCapabilityDiscoverySnapshot;
|
|
pub use codex_exec_server_protocol::ProcessId;
|
|
pub use codex_file_system::CopyOptions;
|
|
pub use codex_file_system::CreateDirectoryOptions;
|
|
pub use codex_file_system::ExecutorFileSystem;
|
|
pub use codex_file_system::ExecutorFileSystemFuture;
|
|
pub use codex_file_system::FILE_READ_CHUNK_SIZE;
|
|
pub use codex_file_system::FileMetadata;
|
|
pub use codex_file_system::FileSystemReadStream;
|
|
pub use codex_file_system::FileSystemResult;
|
|
pub use codex_file_system::FileSystemSandboxContext;
|
|
pub use codex_file_system::ReadDirectoryEntry;
|
|
pub use codex_file_system::RemoveOptions;
|
|
pub use codex_file_system::WalkEntry;
|
|
pub use codex_file_system::WalkEntryKind;
|
|
pub use codex_file_system::WalkError;
|
|
pub use codex_file_system::WalkOptions;
|
|
pub use codex_file_system::WalkOutcome;
|
|
pub use environment::CODEX_EXEC_SERVER_NOISE_AUTH_TOKEN_ENV_VAR;
|
|
pub use environment::CODEX_EXEC_SERVER_NOISE_CHATGPT_ACCOUNT_ID_ENV_VAR;
|
|
pub use environment::CODEX_EXEC_SERVER_NOISE_ENVIRONMENT_ID_ENV_VAR;
|
|
pub use environment::CODEX_EXEC_SERVER_NOISE_REGISTRY_URL_ENV_VAR;
|
|
pub use environment::CODEX_EXEC_SERVER_URL_ENV_VAR;
|
|
pub use environment::DeferredEnvironmentRegistration;
|
|
pub use environment::Environment;
|
|
pub use environment::EnvironmentConnectionState;
|
|
pub use environment::EnvironmentManager;
|
|
pub use environment::EnvironmentObservedStatus;
|
|
pub use environment::EnvironmentReadyInfo;
|
|
pub use environment::LOCAL_ENVIRONMENT_ID;
|
|
pub use environment::MAX_SELECTED_CAPABILITY_ROOTS;
|
|
pub use environment::REMOTE_ENVIRONMENT_ID;
|
|
pub use environment_provider::DefaultEnvironmentProvider;
|
|
pub use environment_provider::EnvironmentProvider;
|
|
pub use environment_provider::EnvironmentProviderFuture;
|
|
pub use environment_registry::EnvironmentRegistryConnectRequest;
|
|
pub use environment_registry::EnvironmentRegistryConnectResponse;
|
|
pub use environment_registry::EnvironmentRegistryHarnessKeyValidationRequest;
|
|
pub use environment_registry::EnvironmentRegistryHarnessKeyValidationResponse;
|
|
pub use environment_registry::EnvironmentRegistryRegistrationRequest;
|
|
pub use environment_registry::EnvironmentRegistryRegistrationResponse;
|
|
pub use fs_helper::CODEX_FS_HELPER_ARG1;
|
|
pub use fs_helper_main::main as run_fs_helper_main;
|
|
pub use local_file_system::LOCAL_FS;
|
|
pub use local_file_system::LocalFileSystem;
|
|
pub use noise_channel::NoiseChannelError;
|
|
pub use noise_channel::NoiseChannelIdentity;
|
|
pub use noise_channel::NoiseChannelPublicKey;
|
|
pub use process::ExecBackend;
|
|
pub use process::ExecBackendFuture;
|
|
pub use process::ExecProcess;
|
|
pub use process::ExecProcessEvent;
|
|
pub use process::ExecProcessEventReceiver;
|
|
pub use process::ExecProcessFuture;
|
|
pub use process::StartedExecProcess;
|
|
pub use protocol::ByteChunk;
|
|
pub use protocol::CAPABILITY_ROOTS_DISCOVER_METHOD;
|
|
pub use protocol::CapabilityRootDiscoverRequest;
|
|
pub use protocol::CapabilityRootDiscovery;
|
|
pub use protocol::CapabilityRootsDiscoverParams;
|
|
pub use protocol::CapabilityRootsDiscoverResponse;
|
|
pub use protocol::CapabilityTextFile;
|
|
pub use protocol::DiscoveredPluginFiles;
|
|
pub use protocol::DiscoveredSkillFiles;
|
|
pub use protocol::EnvironmentCapabilities;
|
|
pub use protocol::EnvironmentInfo;
|
|
pub use protocol::EnvironmentStatus;
|
|
pub use protocol::EnvironmentStatusKind;
|
|
pub use protocol::ExecClosedNotification;
|
|
pub use protocol::ExecEnvPolicy;
|
|
pub use protocol::ExecExitedNotification;
|
|
pub use protocol::ExecOutputDeltaNotification;
|
|
pub use protocol::ExecOutputStream;
|
|
pub use protocol::ExecParams;
|
|
pub use protocol::ExecResponse;
|
|
pub use protocol::FsCanonicalizeParams;
|
|
pub use protocol::FsCanonicalizeResponse;
|
|
pub use protocol::FsCloseParams;
|
|
pub use protocol::FsCloseResponse;
|
|
pub use protocol::FsCopyParams;
|
|
pub use protocol::FsCopyResponse;
|
|
pub use protocol::FsCreateDirectoryParams;
|
|
pub use protocol::FsCreateDirectoryResponse;
|
|
pub use protocol::FsGetMetadataParams;
|
|
pub use protocol::FsGetMetadataResponse;
|
|
pub use protocol::FsOpenParams;
|
|
pub use protocol::FsOpenResponse;
|
|
pub use protocol::FsReadBlockParams;
|
|
pub use protocol::FsReadBlockResponse;
|
|
pub use protocol::FsReadDirectoryEntry;
|
|
pub use protocol::FsReadDirectoryParams;
|
|
pub use protocol::FsReadDirectoryResponse;
|
|
pub use protocol::FsReadFileParams;
|
|
pub use protocol::FsReadFileResponse;
|
|
pub use protocol::FsRemoveParams;
|
|
pub use protocol::FsRemoveResponse;
|
|
pub use protocol::FsWalkParams;
|
|
pub use protocol::FsWalkResponse;
|
|
pub use protocol::FsWriteFileParams;
|
|
pub use protocol::FsWriteFileResponse;
|
|
pub use protocol::HttpHeader;
|
|
pub use protocol::HttpRedirectPolicy;
|
|
pub use protocol::HttpRequestBodyDeltaNotification;
|
|
pub use protocol::HttpRequestParams;
|
|
pub use protocol::HttpRequestResponse;
|
|
pub use protocol::InitializeParams;
|
|
pub use protocol::InitializeResponse;
|
|
pub use protocol::ProcessOutputChunk;
|
|
pub use protocol::ProcessSignal;
|
|
pub use protocol::ReadParams;
|
|
pub use protocol::ReadResponse;
|
|
pub use protocol::ShellInfo;
|
|
pub use protocol::SignalParams;
|
|
pub use protocol::SignalResponse;
|
|
pub use protocol::TerminateParams;
|
|
pub use protocol::TerminateResponse;
|
|
pub use protocol::WriteParams;
|
|
pub use protocol::WriteResponse;
|
|
pub use protocol::WriteStatus;
|
|
pub use remote::RemoteEnvironmentConfig;
|
|
pub use remote::run_remote_environment;
|
|
pub use resolved_capability::ResolvedSelectedCapabilityRoot;
|
|
pub use resolved_capability::SelectedCapabilityRootsStatus;
|
|
pub use runtime_paths::ExecServerRuntimePaths;
|
|
pub use server::DEFAULT_LISTEN_URL;
|
|
pub use server::ExecServerListenUrlParseError;
|
|
pub use server::run_main;
|
|
pub use server::run_main_with_telemetry;
|
|
pub use telemetry::ExecServerTelemetry;
|