mirror of
https://github.com/openai/codex.git
synced 2026-09-11 20:36:49 +00:00
## Why Runtime permission updates must not weaken managed filesystem `deny_read` requirements. ## What changed - Retain managed deny-read rules separately and merge them into updated permission profiles. - Reject permission profiles and legacy sandbox policies that conflict with a managed denied path. - Apply the same constraint when `command/exec` handles a request-specific sandbox policy. ## Testing - Cover thread permission updates with managed deny-read requirements. - Cover `command/exec` enforcement for managed and user-defined denies, including conflicting policy and profile overrides. GitOrigin-RevId: 5e387b9c1bf1650a21753a74a3338bd33df7d0ce
49 KiB
49 KiB