Skip to content

fix: honor workspace network config in turn sandbox policy - #561

Open
davidpp wants to merge 3 commits into
agentclientprotocol:mainfrom
davidpp:codex/workspace-network-config
Open

davidpp wants to merge 3 commits into
agentclientprotocol:mainfrom
davidpp:codex/workspace-network-config

Conversation

@davidpp

@davidpp davidpp commented Sep 28, 2026 •

Copy link
Copy Markdown

Problem

CODEX_CONFIG accepts sandbox_workspace_write.network_access, but sendPrompt sends the mode's hardcoded networkAccess: false in each turn/start. That overrides the session setting, so enabling networking requires selecting full access and widening filesystem permissions too.

Change

Apply an explicit boolean sandbox_workspace_write.network_access from the supplied Codex config to workspace-write turn policies. Preserve writable roots, approval policy/reviewer, defaults, and other sandbox types. Document the existing configuration setting.

Validation

  • npm run typecheck passed.
  • npm run build passed.
  • Full npm test: 1,022 passed, 33 skipped.
  • npm run bundle:all passed for all six targets using Bun 1.3.11, matching CI.
  • After the comment/formatting-only follow-up, typecheck and all five focused network-policy cases passed again; git diff --check is clean.
  • Focused cases cover enabled, disabled, omitted and malformed values, additional write roots, unchanged shared mode objects and full-access policy preservation.
  • Local results above; GitHub workflows currently require maintainer approval. Provider-backed upstream E2E suite was not run.

No generated API types or default permissions are changed.

@auruhm

auruhm commented Sep 29, 2026

Copy link
Copy Markdown

+1 — this is exactly the missing piece, and for us it is the difference between a working and a blind agent.

Driving codex-acp 1.13.1 from Zed on macOS (Apple Silicon) in the default agent mode, a network command fails at DNS:

$ curl -sS -m 8 -o /dev/null -w '%{http_code}\n' https://api.github.com
curl: (6) Could not resolve host: api.github.com        # 000

whereas Codex's own sandbox with the same combination works:

$ codex sandbox -c sandbox_mode=workspace-write -c sandbox_workspace_write.network_access=true -- curl -sS -o /dev/null -w '%{http_code}\n' https://api.github.com
200

So applying the explicit sandbox_workspace_write.network_access from the supplied Codex config to the workspace-write turn policies — while preserving writable roots, approvals and the other sandbox types — is precisely what we need. Happy to test a build against our setup if that helps move it along.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants