Skip to content

Allow dedicated listeners for managed network proxies - #45463

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/e198891bef1d089f9492d2982505a2d6bb002a74
Sep 14, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/e198891bef1d089f9492d2982505a2d6bb002a74

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Allow dedicated listeners for managed network proxies

Why

Sandboxes that enforce endpoint access directly need dedicated loopback proxy ports instead of shared SID-attributed ingress.

What changed

Expose ManagedProxyRouting through NetworkProxyBuilder::managed_proxy_routing. Selecting DedicatedListeners reserves per-proxy loopback listeners on Windows as well as other platforms. Keep SharedIngress as the default and include the routing mode in proxy equality.

Testing

Add regression coverage for distinct loopback endpoints, sandbox port metadata, and HTTP and SOCKS allow/deny policy enforcement. On Windows, verify that dedicated routing requires no restricting SID and omits the shared-ingress proxy-port environment variable.

## Why

Sandboxes that enforce endpoint access directly need dedicated loopback proxy ports instead of shared SID-attributed ingress.

## What changed

Expose `ManagedProxyRouting` through `NetworkProxyBuilder::managed_proxy_routing`. Selecting `DedicatedListeners` reserves per-proxy loopback listeners on Windows as well as other platforms. Keep `SharedIngress` as the default and include the routing mode in proxy equality.

## Testing

Add regression coverage for distinct loopback endpoints, sandbox port metadata, and HTTP and SOCKS allow/deny policy enforcement. On Windows, verify that dedicated routing requires no restricting SID and omits the shared-ingress proxy-port environment variable.

GitOrigin-RevId: e198891bef1d089f9492d2982505a2d6bb002a74
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/e198891bef1d089f9492d2982505a2d6bb002a74 branch from 5789a63 to 99b3ab2 Compare September 14, 2026 16:52
@copyberry
copyberry Bot merged commit 99b3ab2 into main Sep 14, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/e198891bef1d089f9492d2982505a2d6bb002a74 branch September 14, 2026 16:52
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 14, 2026
@copdips
copdips deployed to issue-triage September 14, 2026 16:53 — with GitHub Actions Active
@copdips
copdips deployed to issue-triage September 14, 2026 16:53 — with GitHub Actions Active
@copdips
copdips deployed to issue-triage September 14, 2026 16:53 — with GitHub Actions Active
@JT-TPE
JT-TPE deployed to issue-triage September 14, 2026 16:55 — with GitHub Actions Active
@JT-TPE
JT-TPE deployed to issue-triage September 14, 2026 16:55 — with GitHub Actions Active
@JT-TPE
JT-TPE deployed to issue-triage September 14, 2026 16:55 — with GitHub Actions Active
@JT-TPE
JT-TPE deployed to issue-triage September 14, 2026 16:56 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — 99b3ab21 Deployed Sep 14, 2026 by carabinshely via Generate label suggestions #45500
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants