feat(agent): support a trusted launcher credential broker - #7944
shellz-n-stuff wants to merge 3 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7b62f9268c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 87e4377020
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| /// Launcher-supplied JSON capability for a fixed loopback credential broker. | ||
| pub const BROKER_ENV: &str = "BUZZ_SANDBOX_AUTH_BROKER"; |
There was a problem hiding this comment.
Remove broker secrets from the agent environment
When an MCP tool runs under the agent's OS user, clearing the child's inherited environment does not keep this capability secret: on Linux, for example, the child can read /proc/$PPID/environ, recover the JSON containing secret and port, and call the loopback /token endpoint to obtain the model bearer. This defeats the stated boundary that MCP tools never receive the credential capability. Consume the capability through a mechanism inaccessible to descendants, or parse and scrub it from the process environment before any MCP process can be spawned (and remove the later environment-presence dependency).
Useful? React with 👍 / 👎.
Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
Signed-off-by: Alex Rosenzweig <arosenzweig@squareup.com>
87e4377 to
34a27c6
Compare
b640a33 to
1815161
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 34a27c6e9c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Let a confined agent obtain credentials from a trusted launcher's authenticated loopback broker instead of opening the credential cache. The broker fixes the model service and supports bearer refresh.
The launcher delivers the capability in a bounded private stdin frame before ACP starts. Environment variables contain only a nonsecret protocol marker; the former JSON-in-environment protocol is rejected. Catalog and model requests use initialized broker state. Linux disables process dumpability before reading the capability; macOS launchers must enforce the documented process-inspection restrictions.
Authentication failures remain distinct from temporary service failures. The server task preserves its return value for the launcher.
Stack 3/3: base
codex/launcher-tls. No sandbox engine or plugin build dependency.Validation: broker and executable-startup regressions pass, as do agent/plugin lint checks. An independent agent reviewed and exercised the actual local plugin → confined agent → broker → synthetic TLS model → MCP flow. The MCP inspection attempt failed while an unsandboxed environment-read control succeeded. The local plugin also rejects stale engines and handles early worker exit. Linux was not exercised.
The standalone agent suite encountered a cancellation-test timeout also reproduced on unchanged HEAD. All required push checks passed after restacking onto current main, including Rust tests and desktop native checks. The full
just cigate passed on the restacked tree. Hosted checks are tracked on the PR.Review / merge order: #7942 → #7943 → #7944. Related: #5286. Replaces #7940.
Draft pending human validation of the updated behavior. Companion plugin changes remain in the local plugin folder, which has no Git repository or remote.