Skip to content

Bind unified exec approvals to shell executables - #39311

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/0dd2c7e9a2ac30965ef5fe5de1a8d2968bb5f9d0
Aug 18, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/0dd2c7e9a2ac30965ef5fe5de1a8d2968bb5f9d0

Conversation

@copyberry

@copyberry copyberry Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Bind unified exec approvals to shell executables

Why

An unfamiliar executable can ignore its arguments, so trust in an apparent
inner command must not implicitly trust the executable that runs it.

What changed

  • Evaluate unfamiliar shell executables alongside their parsed commands when
    determining unified exec approval requirements. Inner commands can add
    restrictions, but cannot grant trust to the executable.
  • Include the executable in reusable approval keys so approval for one custom
    shell does not apply to another.
  • Parse literal PowerShell scripts without launching the requested executable,
    preserving command policy checks before approval.

Testing

Add cross-platform coverage for spoofed shell paths, allowed and forbidden
inner commands, explicit custom-shell approval, and session approval isolation.

## Why

An unfamiliar executable can ignore its arguments, so trust in an apparent
inner command must not implicitly trust the executable that runs it.

## What changed

- Evaluate unfamiliar shell executables alongside their parsed commands when
  determining unified exec approval requirements. Inner commands can add
  restrictions, but cannot grant trust to the executable.
- Include the executable in reusable approval keys so approval for one custom
  shell does not apply to another.
- Parse literal PowerShell scripts without launching the requested executable,
  preserving command policy checks before approval.

## Testing

Add cross-platform coverage for spoofed shell paths, allowed and forbidden
inner commands, explicit custom-shell approval, and session approval isolation.

GitOrigin-RevId: 0dd2c7e9a2ac30965ef5fe5de1a8d2968bb5f9d0
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/0dd2c7e9a2ac30965ef5fe5de1a8d2968bb5f9d0 branch from d34d612 to 7d9990f Compare August 18, 2026 23:02
@copyberry
copyberry Bot merged commit 7d9990f into main Aug 18, 2026
28 of 32 checks passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/0dd2c7e9a2ac30965ef5fe5de1a8d2968bb5f9d0 branch August 18, 2026 23:03
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 18, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant