Skip to content

fix: replace removed --full-auto with --sandbox workspace-write - #239

Open
zengchang233 wants to merge 1 commit into
PolyArch:devfrom
zengchang233:fix/codex-sandbox-flag
Open

zengchang233 wants to merge 1 commit into
PolyArch:devfrom
zengchang233:fix/codex-sandbox-flag

Conversation

@zengchang233

Copy link
Copy Markdown

Summary

Fixes #237.

This PR fixes the bug reported in #237 and changes the two call sites listed there. It does not use the fix suggested in the issue (probing for --approve-for-me). The reasons are in the next section.

Codex CLI 0.154.0 removed --full-auto. Every codex exec call that scripts/ask-codex.sh or hooks/loop-codex-stop-hook.sh makes now fails immediately:

error: unexpected argument '--full-auto' found

This breaks /humanize:ask-codex, both Codex passes in /humanize:gen-plan, and the summary review in the RLCR stop hook. I hit it on codex-cli 0.155.1.

This PR replaces the default flag in both places with --sandbox=workspace-write.

Why --sandbox workspace-write and not --approve-for-me or a help-text probe

#237 suggests probing codex exec --help for --approve-for-me, falling back to --full-auto. I went with a plain --sandbox workspace-write instead:

  • It matches the old behavior. In codex exec, --full-auto only selected the workspace-write sandbox. The approval policy stayed at the headless default, never. See codex-rs/exec/src/lib.rs at rust-v0.114.0: full_auto maps to SandboxMode::WorkspaceWrite, and the default approval is AskForApproval::Never.
  • --approve-for-me is more permissive. It also sets the approval policy to on-request and sends escalation requests to an automatic reviewer (codex-rs/exec/tests/suite/approval_policy.rs at rust-v0.155.1). A command the reviewer approves could run outside the sandbox. That is more than a review step needs.
  • No probing needed. -s/--sandbox exists on codex exec in rust-v0.114.0 (codex-rs/exec/src/cli.rs), which is the minimum version the Codex install path requires. It is also still present in 0.155.1 (codex exec --help). So the fix does not need to probe for version-specific flags the way the --disable hook-feature probe does.

HUMANIZE_CODEX_BYPASS_SANDBOX=true|1 still replaces the flag with --dangerously-bypass-approvals-and-sandbox, which is unchanged in 0.155.1.

Changes

  • scripts/ask-codex.sh, hooks/loop-codex-stop-hook.sh: the default CODEX_AUTO_FLAG is now --sandbox=workspace-write. It is kept as a single token so the existing array expansion stays the same.
  • docs/usage.md: the HUMANIZE_CODEX_BYPASS_SANDBOX default now describes --sandbox workspace-write.
  • Tests:
    • tests/test-ask-codex.sh: the default run passes --sandbox=workspace-write and not --full-auto. HUMANIZE_CODEX_BYPASS_SANDBOX=1 still replaces the sandbox flag.
    • tests/test-disable-nested-codex-hooks.sh: the implementation-phase stop hook passes --sandbox=workspace-write and not --full-auto.

Deliberately left alone:

  • The mock help text in tests/test-ask-codex.sh (Test B of the --disable probe) mentions --full-auto. It stands in for an older CLI and does not affect the flag under test.
  • tests/test-bitlesson-select-routing.sh already asserts that the BitLesson selector never passes --full-auto, and that still holds.

Testing

  • bash tests/test-ask-codex.sh: 39 passed, 0 failed. This includes the 2 new tests, which fail against dev without the fix.
  • bash tests/test-disable-nested-codex-hooks.sh: 7 passed, 0 failed. This includes 1 new test, which also fails without the fix and shows ... --full-auto -C ... in the captured argv.
  • bash tests/run-all-tests.sh: 2261 passed, 4 failed. The same 4 fail on unmodified dev on my machine, for reasons unrelated to this change:
    • test-unified-codex-config.sh checks the built-in gpt-5.5/high fallback, but my ~/.config/humanize/config.json overrides it. With XDG_CONFIG_HOME pointed at an empty dir, the file passes 69/69 on this branch.
    • test-viz.sh and test-streaming.sh need the Python yaml module, which is not installed locally.
  • Manual check: with the patched ask-codex.sh, a real codex exec call on codex-cli 0.155.1 succeeds (exit_code=0). Before the patch it failed with unexpected argument '--full-auto'.

🤖 Generated with Claude Code

Codex CLI 0.154.0 removed `--full-auto`, so every `codex exec` call from
ask-codex.sh and the RLCR stop hook now fails with
"unexpected argument '--full-auto'" (PolyArch#237).

For `codex exec`, `--full-auto` only selected the workspace-write sandbox
and left the headless approval policy at `never`. `--sandbox workspace-write`
does exactly that and is accepted by every supported CLI (0.114.0 through
0.155.1), so no help-text probing is needed. `--approve-for-me` is not used
because it also switches approvals to on-request with automatic review,
which is more permissive than the old behavior.

HUMANIZE_CODEX_BYPASS_SANDBOX still swaps in
--dangerously-bypass-approvals-and-sandbox.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant