diff --git a/docs/usage.md b/docs/usage.md index 3df6fa0a..dd9ff1ed 100644 --- a/docs/usage.md +++ b/docs/usage.md @@ -476,7 +476,7 @@ on subsequent fetches and SSE reconnects. **WARNING: This is a dangerous option that disables security protections. Use only if you understand the implications.** - **Purpose**: Controls whether Codex runs with sandbox protection -- **Default**: Not set (uses `--full-auto` with sandbox protection) +- **Default**: Not set (uses `--sandbox workspace-write` with sandbox protection) - **Values**: - `true` or `1`: Bypasses Codex sandbox and approvals (uses `--dangerously-bypass-approvals-and-sandbox`) - Any other value or unset: Uses safe mode with sandbox diff --git a/hooks/loop-codex-stop-hook.sh b/hooks/loop-codex-stop-hook.sh index d3051f9c..fed93095 100755 --- a/hooks/loop-codex-stop-hook.sh +++ b/hooks/loop-codex-stop-hook.sh @@ -1208,7 +1208,8 @@ if [[ -n "$CODEX_EXEC_EFFORT" ]]; then CODEX_EXEC_ARGS+=("-c" "model_reasoning_effort=${CODEX_EXEC_EFFORT}") fi -CODEX_AUTO_FLAG="--full-auto" +# Same sandbox the removed --full-auto flag selected (see scripts/ask-codex.sh) +CODEX_AUTO_FLAG="--sandbox=workspace-write" if [[ "${HUMANIZE_CODEX_BYPASS_SANDBOX:-}" == "true" ]] || [[ "${HUMANIZE_CODEX_BYPASS_SANDBOX:-}" == "1" ]]; then CODEX_AUTO_FLAG="--dangerously-bypass-approvals-and-sandbox" fi diff --git a/scripts/ask-codex.sh b/scripts/ask-codex.sh index f16c6656..d12a136a 100755 --- a/scripts/ask-codex.sh +++ b/scripts/ask-codex.sh @@ -277,7 +277,9 @@ if [[ -n "$CODEX_EFFORT" ]]; then fi # Determine automation flag based on environment variable -CODEX_AUTO_FLAG="--full-auto" +# Newer Codex CLIs removed --full-auto. For `codex exec` it only selected the +# workspace-write sandbox, which --sandbox provides on every supported version. +CODEX_AUTO_FLAG="--sandbox=workspace-write" if [[ "${HUMANIZE_CODEX_BYPASS_SANDBOX:-}" == "true" ]] || [[ "${HUMANIZE_CODEX_BYPASS_SANDBOX:-}" == "1" ]]; then CODEX_AUTO_FLAG="--dangerously-bypass-approvals-and-sandbox" fi diff --git a/tests/test-ask-codex.sh b/tests/test-ask-codex.sh index a6c70215..0614eba5 100755 --- a/tests/test-ask-codex.sh +++ b/tests/test-ask-codex.sh @@ -325,6 +325,46 @@ else fi reset_mock +# Test: default run selects the workspace-write sandbox without the removed --full-auto flag +reset_mock +export MOCK_CODEX_STDOUT="sandbox-flag-test" +ASK_CODEX_ARGS_FILE="$TEST_DIR/ask-codex-sandbox-args.txt" +export MOCK_CODEX_ARGS_FILE="$ASK_CODEX_ARGS_FILE" +EXIT_CODE=0 +run_ask_codex "sandbox flag test" > /dev/null 2>&1 || EXIT_CODE=$? +CAPTURED_ARGS="$(cat "$ASK_CODEX_ARGS_FILE" 2>/dev/null || true)" +if [[ $EXIT_CODE -eq 0 ]] \ + && echo "$CAPTURED_ARGS" | grep -qx -- '--sandbox=workspace-write' \ + && ! echo "$CAPTURED_ARGS" | grep -qx -- '--full-auto'; then + pass "default run uses --sandbox=workspace-write instead of --full-auto" +else + fail "default run uses --sandbox=workspace-write instead of --full-auto" \ + "exec args include --sandbox=workspace-write and no --full-auto" \ + "exit=$EXIT_CODE, args=$CAPTURED_ARGS" +fi +reset_mock + +# Test: HUMANIZE_CODEX_BYPASS_SANDBOX still replaces the sandbox flag +reset_mock +export MOCK_CODEX_STDOUT="bypass-flag-test" +ASK_CODEX_ARGS_FILE="$TEST_DIR/ask-codex-bypass-args.txt" +export MOCK_CODEX_ARGS_FILE="$ASK_CODEX_ARGS_FILE" +export HUMANIZE_CODEX_BYPASS_SANDBOX="1" +EXIT_CODE=0 +run_ask_codex "bypass flag test" > /dev/null 2>&1 || EXIT_CODE=$? +unset HUMANIZE_CODEX_BYPASS_SANDBOX +CAPTURED_ARGS="$(cat "$ASK_CODEX_ARGS_FILE" 2>/dev/null || true)" +if [[ $EXIT_CODE -eq 0 ]] \ + && echo "$CAPTURED_ARGS" | grep -qx -- '--dangerously-bypass-approvals-and-sandbox' \ + && ! echo "$CAPTURED_ARGS" | grep -qx -- '--sandbox=workspace-write'; then + pass "HUMANIZE_CODEX_BYPASS_SANDBOX=1 replaces the sandbox flag" +else + fail "HUMANIZE_CODEX_BYPASS_SANDBOX=1 replaces the sandbox flag" \ + "exec args include --dangerously-bypass-approvals-and-sandbox only" \ + "exit=$EXIT_CODE, args=$CAPTURED_ARGS" +fi +reset_mock + # ======================================== # Error Handling Tests # ======================================== diff --git a/tests/test-disable-nested-codex-hooks.sh b/tests/test-disable-nested-codex-hooks.sh index a4f1388a..2b26322b 100755 --- a/tests/test-disable-nested-codex-hooks.sh +++ b/tests/test-disable-nested-codex-hooks.sh @@ -222,6 +222,14 @@ else "exec --disable hooks --disable plugin_hooks --disable codex_hooks" "$(cat "$TEST_DIR/impl.args" 2>/dev/null || echo missing)" fi +if grep -q -- '--sandbox=workspace-write' "$TEST_DIR/impl.args" \ + && ! grep -q -- '--full-auto' "$TEST_DIR/impl.args"; then + pass "implementation-phase stop hook uses --sandbox=workspace-write instead of --full-auto" +else + fail "implementation-phase stop hook uses --sandbox=workspace-write instead of --full-auto" \ + "--sandbox=workspace-write and no --full-auto" "$(cat "$TEST_DIR/impl.args" 2>/dev/null || echo missing)" +fi + REPO_REVIEW="$TEST_DIR/repo-review" setup_repo "$REPO_REVIEW" run_loop_hook "$REPO_REVIEW" "$TEST_DIR/review.args" "true"