Skip to content

[sandbox-hardening] Block Launch Services in the macOS local sandbox - #5335

Merged
dhavalkapil-oai merged 1 commit into
mainfrom
dhavalkapil/macosx-sandbox-hardening
Oct 8, 2026
Merged

dhavalkapil-oai merged 1 commit into
mainfrom
dhavalkapil/macosx-sandbox-hardening

Conversation

@dhavalkapil-oai

@dhavalkapil-oai dhavalkapil-oai commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

This pull request blocks Launch Services from the macOS local sandbox. Launch Services can start an application outside the calling process's sandbox, allowing commands to bypass workspace filesystem restrictions.

  • Add (deny lsopen) to the macOS profile shared by ordinary and PTY execution.
  • Add a portable profile assertion and a native regression test through session.exec(). The native test verifies that the host permits lsopen and the sandbox denies it, without launching a GUI application.

Opening applications, documents, and URLs through Launch Services from sandboxed commands is intentionally denied. Linux behavior and public APIs are unchanged.

Test plan

  • Focused sandbox checks: 10 passed, 2 native tests skipped.

  • Repository formatting, lint, Mypy, and Pyright.

  • Independent security and test reviews; the reviewed patch was replayed unchanged onto current main with no overlap in its recorded dependencies.

  • Run native macOS enforcement tests outside the Codex sandbox:

    env -u VIRTUAL_ENV -u OPENAI_AGENTS_TEST_IN_CODEX_SANDBOX \
      uv run --frozen pytest tests/sandbox/test_runtime.py \
      -k 'unix_local_exec_denies_launch_services or unix_local_exec_confines_commands_to_workspace_root' -v
  • Verified proof of concept is no longer able to launch applications

Checks

  • Added regression tests.
  • Ran .agents/skills/code-change-verification/scripts/run.sh.
  • All verification steps pass.

Launch Services can start applications outside the calling process's
sandbox, allowing sandboxed commands to bypass workspace restrictions.

Deny lsopen in the macOS profile shared by ordinary and PTY execution.
Add portable profile coverage and a native regression test that checks
Launch Services is allowed on the host and denied through session.exec.

Test plan:
- Focused sandbox checks: 10 passed, 2 native tests skipped.
- Formatting, lint, Mypy, and Pyright passed.
- Parallel suite: 12085 passed, 66 skipped, 1 existing failure also
  reproduced on unmodified main; the serial suite was not reached.
- Native macOS enforcement and the app-launch reproduction remain pending.
@dhavalkapil-oai
dhavalkapil-oai marked this pull request as ready for review October 7, 2026 23:03
@dhavalkapil-oai
dhavalkapil-oai requested review from a team, rm-openai and seratch as code owners October 7, 2026 23:03
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T23:04:42.862961Z ba3475f Draft marked ready
🔒 Security Review ✅ Completed 2026-10-07T23:05:26.297270Z ba3475f Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed ba3475ffe37461f06188159633d0e4fba194f2cf. No actionable findings.

The denial belongs in the shared macOS profile used by ordinary and PTY execution. It preserves the existing file grants and leaves Linux execution unchanged. The regression test checks the host policy first, then queries the policy through session.exec().

Hosted CI is green. I inspected the native macOS job: all 31 selected tests passed without skips. This was a source review with hosted-CI evidence; I did not run the GUI-launch PoC locally. The added test verifies the OS policy decision, not an actual GUI launch.

@dhavalkapil-oai
dhavalkapil-oai added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit 125efa0 Oct 8, 2026
25 checks passed
@dhavalkapil-oai
dhavalkapil-oai deleted the dhavalkapil/macosx-sandbox-hardening branch October 8, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants