Files
codex/codex-rs/linux-sandbox
Michael Bolin 506948c80f chore: introduce SandboxPolicy::WorkspaceWrite::use_exact_writable_roots
Without this change, it is challenging to create integration tests to
verify that the folders not included in `writable_roots` in
`SandboxPolicy::WorkspaceWrite` are read-only because, by default,
`get_writable_roots_with_cwd()` includes `TMPDIR`, which is where most integrationt
tests do their work.

This introduces a `use_exact_writable_roots` option to disable the default
includes returned by `get_writable_roots_with_cwd()`.
2025-08-01 11:37:13 -07:00
..
2025-07-30 18:37:00 -07:00

codex-linux-sandbox

This crate is responsible for producing:

  • a codex-linux-sandbox standalone executable for Linux that is bundled with the Node.js version of the Codex CLI
  • a lib crate that exposes the business logic of the executable as run_main() so that
    • the codex-exec CLI can check if its arg0 is codex-linux-sandbox and, if so, execute as if it were codex-linux-sandbox
    • this should also be true of the codex multitool CLI