Skip to content

Default local binding to true for MXC managed networking - #46523

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/0fa7c1eaec68bebada2b8f7af45688315eea70a9
Sep 19, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/0fa7c1eaec68bebada2b8f7af45688315eea70a9

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Default local binding to true for MXC managed networking

Why

MXC's native host-loopback access is bidirectional, so it cannot enforce allow_local_binding = false. Treating an omitted setting as false prevents managed networking from working with the default configuration.

What changed

  • Preserve an omitted allow_local_binding until the executor's sandbox policy is known. Default to true for Windows MXC and false elsewhere, including remote execution.
  • Reject an effective false for MXC managed networking after applying policy restrictions, without enabling disabled networking.
  • Use the executor's resolved value for remote network approval decisions while preserving explicit controller restrictions.
  • Document that local binding permits local servers and direct host-loopback connections and skips additional private-network destination checks; proxy domain rules still apply.

Testing

Add coverage for per-executor defaults, explicit values, MXC rejection of false, and remote network review cleanup with the resolved policy.

## Why

MXC's native host-loopback access is bidirectional, so it cannot enforce `allow_local_binding = false`. Treating an omitted setting as `false` prevents managed networking from working with the default configuration.

## What changed

- Preserve an omitted `allow_local_binding` until the executor's sandbox policy is known. Default to `true` for Windows MXC and `false` elsewhere, including remote execution.
- Reject an effective `false` for MXC managed networking after applying policy restrictions, without enabling disabled networking.
- Use the executor's resolved value for remote network approval decisions while preserving explicit controller restrictions.
- Document that local binding permits local servers and direct host-loopback connections and skips additional private-network destination checks; proxy domain rules still apply.

## Testing

Add coverage for per-executor defaults, explicit values, MXC rejection of `false`, and remote network review cleanup with the resolved policy.

GitOrigin-RevId: 0fa7c1eaec68bebada2b8f7af45688315eea70a9
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/0fa7c1eaec68bebada2b8f7af45688315eea70a9 branch from f940b2f to 74af249 Compare September 19, 2026 00:00
@copyberry
copyberry Bot merged commit 74af249 into main Sep 19, 2026
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/0fa7c1eaec68bebada2b8f7af45688315eea70a9 branch September 19, 2026 00:00
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 19, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant