Repository navigation
Add filesystem accessors bound to environment permissions - #46268
Merged
copyberry[bot] merged 1 commit intoSep 17, 2026
Conversation
## What changed Add `EnvironmentAccess` and `FileSystemEnvironmentAccessor` to expose filesystem operations with a captured sandbox configuration, without allowing consumers to extract the filesystem or select another sandbox. Include a text-reading helper and an explicit unrestricted constructor. Provide opaque cache keys that compare filesystem identity and captured permissions without keeping the filesystem alive. Allow opened read streams to outlive the accessor. Export the new APIs through `codex-exec-server` and add `Environment::filesystem_ref()` for borrowing the shared filesystem. ## Testing Add local and remote coverage for text reads through `EnvironmentAccess`, streams surviving accessor disposal, and cache keys distinguishing changed permissions or a replacement filesystem. GitOrigin-RevId: 4f6787ed9ba0fb94adea2f31716c4d3132fed07d
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/4f6787ed9ba0fb94adea2f31716c4d3132fed07d
branch
from
September 17, 2026 17:59
93daed5 to
3d3ae49
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/4f6787ed9ba0fb94adea2f31716c4d3132fed07d
branch
September 17, 2026 17:59
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add filesystem accessors bound to environment permissions
What changed
Add
EnvironmentAccessandFileSystemEnvironmentAccessorto expose filesystem operations with a captured sandbox configuration, without allowing consumers to extract the filesystem or select another sandbox. Include a text-reading helper and an explicit unrestricted constructor.Provide opaque cache keys that compare filesystem identity and captured permissions without keeping the filesystem alive. Allow opened read streams to outlive the accessor. Export the new APIs through
codex-exec-serverand addEnvironment::filesystem_ref()for borrowing the shared filesystem.Testing
Add local and remote coverage for text reads through
EnvironmentAccess, streams surviving accessor disposal, and cache keys distinguishing changed permissions or a replacement filesystem.