Repository navigation
[sandbox-hardening] Block Launch Services in the macOS local sandbox - #5335
Conversation
Launch Services can start applications outside the calling process's sandbox, allowing sandboxed commands to bypass workspace restrictions. Deny lsopen in the macOS profile shared by ordinary and PTY execution. Add portable profile coverage and a native regression test that checks Launch Services is allowed on the host and denied through session.exec. Test plan: - Focused sandbox checks: 10 passed, 2 native tests skipped. - Formatting, lint, Mypy, and Pyright passed. - Parallel suite: 12085 passed, 66 skipped, 1 existing failure also reproduced on unmodified main; the serial suite was not reached. - Native macOS enforcement and the app-launch reproduction remain pending.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed ba3475ffe37461f06188159633d0e4fba194f2cf. No actionable findings.
The denial belongs in the shared macOS profile used by ordinary and PTY execution. It preserves the existing file grants and leaves Linux execution unchanged. The regression test checks the host policy first, then queries the policy through session.exec().
Hosted CI is green. I inspected the native macOS job: all 31 selected tests passed without skips. This was a source review with hosted-CI evidence; I did not run the GUI-launch PoC locally. The added test verifies the OS policy decision, not an actual GUI launch.
Summary
This pull request blocks Launch Services from the macOS local sandbox. Launch Services can start an application outside the calling process's sandbox, allowing commands to bypass workspace filesystem restrictions.
(deny lsopen)to the macOS profile shared by ordinary and PTY execution.session.exec(). The native test verifies that the host permitslsopenand the sandbox denies it, without launching a GUI application.Opening applications, documents, and URLs through Launch Services from sandboxed commands is intentionally denied. Linux behavior and public APIs are unchanged.
Test plan
Focused sandbox checks: 10 passed, 2 native tests skipped.
Repository formatting, lint, Mypy, and Pyright.
Independent security and test reviews; the reviewed patch was replayed unchanged onto current
mainwith no overlap in its recorded dependencies.Run native macOS enforcement tests outside the Codex sandbox:
env -u VIRTUAL_ENV -u OPENAI_AGENTS_TEST_IN_CODEX_SANDBOX \ uv run --frozen pytest tests/sandbox/test_runtime.py \ -k 'unix_local_exec_denies_launch_services or unix_local_exec_confines_commands_to_workspace_root' -vVerified proof of concept is no longer able to launch applications
Checks
.agents/skills/code-change-verification/scripts/run.sh.