Skip to content

Give Codex Auto the same network posture on both transports, release 0.4.17 - #32

Merged
pathscale merged 2 commits into
masterfrom
fix/codex-auto-network
Aug 10, 2026
Merged

pathscale merged 2 commits into
masterfrom
fix/codex-auto-network

Conversation

@pathscale

Copy link
Copy Markdown
Owner

Permission::Auto meant two different things depending on which Codex transport a run happened to take.

The app-server path sets networkAccess: true for Auto and false for Edit. The codex exec path set no network configuration at all, so a caller asking for Auto received the Edit posture whenever approvals were off. One posture, two capabilities, selected by an unrelated flag.

codex exec has no network flag, so the fix carries the documented [sandbox_workspace_write] network_access key through -c, which is the same lever the CLI's own help points at. Edit stays gated, which is what keeps its approvals meaningful.

Found while reviewing the Codex integration for agencyzero, where the symptom is a run that can or cannot reach the network depending on a setting nobody associated with the network.

Verification

  • cargo test --lib: 201 passed, including a new test pinning the two transports to the same answer.
  • cargo fmt --check and cargo clippy --all-targets: clean.
  • Not exercised against the live CLI: this changes a config override, and the live suite does not assert network reachability.

meh added 2 commits August 10, 2026 13:35
The app-server path grants networkAccess for Auto and withholds it for
Edit. The exec path set no network configuration, so the same Permission
produced a different capability depending on whether approvals happened
to be enabled for that run.

codex exec has no network flag, so the documented
sandbox_workspace_write.network_access override carries it. Edit stays
gated, which is what keeps its approvals meaningful.
@pathscale
pathscale merged commit 9829fc8 into master Aug 10, 2026
1 check passed
@pathscale
pathscale deleted the fix/codex-auto-network branch August 10, 2026 06:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant