Skip to content

Add filesystem accessors bound to environment permissions - #46268

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/4f6787ed9ba0fb94adea2f31716c4d3132fed07d
Sep 17, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/4f6787ed9ba0fb94adea2f31716c4d3132fed07d

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Add filesystem accessors bound to environment permissions

What changed

Add EnvironmentAccess and FileSystemEnvironmentAccessor to expose filesystem operations with a captured sandbox configuration, without allowing consumers to extract the filesystem or select another sandbox. Include a text-reading helper and an explicit unrestricted constructor.

Provide opaque cache keys that compare filesystem identity and captured permissions without keeping the filesystem alive. Allow opened read streams to outlive the accessor. Export the new APIs through codex-exec-server and add Environment::filesystem_ref() for borrowing the shared filesystem.

Testing

Add local and remote coverage for text reads through EnvironmentAccess, streams surviving accessor disposal, and cache keys distinguishing changed permissions or a replacement filesystem.

## What changed

Add `EnvironmentAccess` and `FileSystemEnvironmentAccessor` to expose filesystem operations with a captured sandbox configuration, without allowing consumers to extract the filesystem or select another sandbox. Include a text-reading helper and an explicit unrestricted constructor.

Provide opaque cache keys that compare filesystem identity and captured permissions without keeping the filesystem alive. Allow opened read streams to outlive the accessor. Export the new APIs through `codex-exec-server` and add `Environment::filesystem_ref()` for borrowing the shared filesystem.

## Testing

Add local and remote coverage for text reads through `EnvironmentAccess`, streams surviving accessor disposal, and cache keys distinguishing changed permissions or a replacement filesystem.

GitOrigin-RevId: 4f6787ed9ba0fb94adea2f31716c4d3132fed07d
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/4f6787ed9ba0fb94adea2f31716c4d3132fed07d branch from 93daed5 to 3d3ae49 Compare September 17, 2026 17:59
@copyberry
copyberry Bot merged commit 3d3ae49 into main Sep 17, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/4f6787ed9ba0fb94adea2f31716c4d3132fed07d branch September 17, 2026 17:59
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 17, 2026
@erg
erg deployed to issue-triage September 17, 2026 18:04 — with GitHub Actions Active
@erg
erg deployed to issue-triage September 17, 2026 18:04 — with GitHub Actions Active
@erg
erg deployed to issue-triage September 17, 2026 18:04 — with GitHub Actions Active
@erg
erg deployed to issue-triage September 17, 2026 18:05 — with GitHub Actions Active
@zandaniji
zandaniji deployed to issue-triage September 17, 2026 18:14 — with GitHub Actions Active
@zandaniji
zandaniji deployed to issue-triage September 17, 2026 18:14 — with GitHub Actions Active
@zandaniji
zandaniji deployed to issue-triage September 17, 2026 18:14 — with GitHub Actions Active
@zandaniji
zandaniji deployed to issue-triage September 17, 2026 18:16 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants