Skip to content

feat(agent): support a trusted launcher credential broker - #7944

Open
shellz-n-stuff wants to merge 3 commits into
codex/launcher-tlsfrom
codex/launcher-auth-broker
Open

shellz-n-stuff wants to merge 3 commits into
codex/launcher-tlsfrom
codex/launcher-auth-broker

Conversation

@shellz-n-stuff

@shellz-n-stuff shellz-n-stuff commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Let a confined agent obtain credentials from a trusted launcher's authenticated loopback broker instead of opening the credential cache. The broker fixes the model service and supports bearer refresh.

The launcher delivers the capability in a bounded private stdin frame before ACP starts. Environment variables contain only a nonsecret protocol marker; the former JSON-in-environment protocol is rejected. Catalog and model requests use initialized broker state. Linux disables process dumpability before reading the capability; macOS launchers must enforce the documented process-inspection restrictions.

Authentication failures remain distinct from temporary service failures. The server task preserves its return value for the launcher.

Stack 3/3: base codex/launcher-tls. No sandbox engine or plugin build dependency.

Validation: broker and executable-startup regressions pass, as do agent/plugin lint checks. An independent agent reviewed and exercised the actual local plugin → confined agent → broker → synthetic TLS model → MCP flow. The MCP inspection attempt failed while an unsandboxed environment-read control succeeded. The local plugin also rejects stale engines and handles early worker exit. Linux was not exercised.

The standalone agent suite encountered a cancellation-test timeout also reproduced on unchanged HEAD. All required push checks passed after restacking onto current main, including Rust tests and desktop native checks. The full just ci gate passed on the restacked tree. Hosted checks are tracked on the PR.

Review / merge order: #7942 → #7943 → #7944. Related: #5286. Replaces #7940.

Draft pending human validation of the updated behavior. Companion plugin changes remain in the local plugin folder, which has no Git repository or remote.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T23:42:12.727541Z 34a27c6 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7b62f9268c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/buzz-agent/src/sandbox_runtime.rs Outdated
Comment thread crates/buzz-agent/src/sandbox_runtime.rs Outdated
@shellz-n-stuff
shellz-n-stuff marked this pull request as draft September 28, 2026 15:31
@shellz-n-stuff
shellz-n-stuff marked this pull request as ready for review September 28, 2026 15:43

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 87e4377020

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +19 to +20
/// Launcher-supplied JSON capability for a fixed loopback credential broker.
pub const BROKER_ENV: &str = "BUZZ_SANDBOX_AUTH_BROKER";

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove broker secrets from the agent environment

When an MCP tool runs under the agent's OS user, clearing the child's inherited environment does not keep this capability secret: on Linux, for example, the child can read /proc/$PPID/environ, recover the JSON containing secret and port, and call the loopback /token endpoint to obtain the model bearer. This defeats the stated boundary that MCP tools never receive the credential capability. Consume the capability through a mechanism inaccessible to descendants, or parse and scrub it from the process environment before any MCP process can be spawned (and remove the later environment-presence dependency).

Useful? React with 👍 / 👎.

Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
@shellz-n-stuff
shellz-n-stuff marked this pull request as draft September 28, 2026 23:03
@shellz-n-stuff
shellz-n-stuff force-pushed the codex/launcher-auth-broker branch from 87e4377 to 34a27c6 Compare September 28, 2026 23:14
@shellz-n-stuff
shellz-n-stuff marked this pull request as ready for review September 28, 2026 23:38

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 34a27c6e9c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/buzz-agent/src/sandbox_runtime.rs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant