Skip to content

Isolate app-server Unix sockets from filesystem-restricted commands - #45984

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/53372c27eea278d964f2cf68aed24323ef3b7082
Sep 16, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/53372c27eea278d964f2cf68aed24323ef3b7082

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Isolate app-server Unix sockets from filesystem-restricted commands

Why

Network access and Unix-socket allowlists must not let commands with filesystem restrictions reach the privileged app-server RPC transport.

What changed

  • Bind Unix control sockets in a fixed, user-owned directory with mode 0700, independent of environment settings, and expose the advertised paths as symlinks. Preserve existing parent permissions, reject unsafe parents, and serialize socket setup and publication.
  • Mask the socket directory in Linux bubblewrap sandboxes after each bind that exposes it. Reject host mount aliases and nested mounts that compromise isolation.
  • Deny access to the directory and outbound connections to its sockets in macOS Seatbelt policies, including when network access or Unix-socket allowlists grant broader access.
  • Require bubblewrap for filesystem-restricted Linux execution. Users with features.use_legacy_landlock enabled must disable it for these policies.

Testing

Add regression coverage for direct and symlink socket access, hardlink attempts, Linux host-process links and bind-mount aliases, and continued use of unrelated and sandbox-local sockets. Add transport coverage for parent permissions, concurrent restart after a stale symlink, and cleanup that preserves a replacement at the advertised path.

…45984)

## Why

Network access and Unix-socket allowlists must not let commands with filesystem restrictions reach the privileged app-server RPC transport.

## What changed

- Bind Unix control sockets in a fixed, user-owned directory with mode `0700`, independent of environment settings, and expose the advertised paths as symlinks. Preserve existing parent permissions, reject unsafe parents, and serialize socket setup and publication.
- Mask the socket directory in Linux bubblewrap sandboxes after each bind that exposes it. Reject host mount aliases and nested mounts that compromise isolation.
- Deny access to the directory and outbound connections to its sockets in macOS Seatbelt policies, including when network access or Unix-socket allowlists grant broader access.
- Require bubblewrap for filesystem-restricted Linux execution. Users with `features.use_legacy_landlock` enabled must disable it for these policies.

## Testing

Add regression coverage for direct and symlink socket access, hardlink attempts, Linux host-process links and bind-mount aliases, and continued use of unrelated and sandbox-local sockets. Add transport coverage for parent permissions, concurrent restart after a stale symlink, and cleanup that preserves a replacement at the advertised path.

GitOrigin-RevId: 53372c27eea278d964f2cf68aed24323ef3b7082
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/53372c27eea278d964f2cf68aed24323ef3b7082 branch from 77c78b3 to 49305d7 Compare September 16, 2026 16:56
@copyberry
copyberry Bot merged commit 49305d7 into main Sep 16, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/53372c27eea278d964f2cf68aed24323ef3b7082 branch September 16, 2026 16:56
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 16, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant