Files
codex/codex-rs
sayan-oai 530c1aed58 Prevent apply_patch from widening write permissions (#39614)
## Why

Deriving permissions from the parent of an already-writable patch target can
unnecessarily grant write access outside the intended workspace.

## What changed

Skip targets already covered by the active filesystem sandbox policy before
deriving additional parent-directory permissions. Targets outside the writable
area continue to request the required parent access.

## Testing

Added unit and CLI regression coverage for workspace-directory targets,
already-writable parents, and symlink escapes outside the workspace.

GitOrigin-RevId: 187109ff0b56a1a399cb8a9981b7e822977025d5
2026-08-20 06:21:54 +00:00
..