Skip to content

fix(codex): decline permission escalation with a valid empty grant - #121537

Open
Wenfengcheng wants to merge 1 commit into
NousResearch:mainfrom
Wenfengcheng:fix/codex-permission-response-121297
Open

Wenfengcheng wants to merge 1 commit into
NousResearch:mainfrom
Wenfengcheng:fix/codex-permission-response-121297

Conversation

@Wenfengcheng

@Wenfengcheng Wenfengcheng commented Sep 24, 2026 •

Copy link
Copy Markdown

Problem

Fixes #121297.

Codex app-server permission escalation requests receive {"decision":"decline"}, but PermissionsRequestApprovalResponse requires permissions. The server cannot deserialize the intended denial.

Root cause

The permissions handler reused the command/file-change decision shape. Permission grants have a different wire contract.

Change

Return {"permissions": {}}: grant nothing and preserve Hermes' existing unconditional denial policy. No permission escalation, approval callback, config reads, or new abstraction is added. Command and file-change approval behavior is unchanged.

Add session-level regression coverage and a portable local subprocess round trip through the real JSON-RPC client. Remove the strict xfail for the already-existing POSIX CLI regression so a corrected reply does not become an XPASS failure.

Verification

Base: 3da4a42359c8b50a6ea6563a6c1f989e4dd1fbc4.

  • RED on unmodified product source: 5 assertion failures, including the local stdio peer rejecting the real serialized decision response.
  • scripts/run_tests.sh tests/agent/transports/test_codex_app_server_session.py tests/agent/transports/test_codex_permission_wire.py tests/agent/transports/test_codex_app_server.py tests/e2e/core/providers/test_native_codex_app_server_faults.py -q: 57 passed, 8 skipped on Windows.
  • Empty/nonempty requested permissions and exec/file-change auto-approval both enabled/disabled still yield no grant and never invoke the approval callback.
  • The subprocess fixture replaces only the executable at the spawn boundary; session dispatch, pipes, JSON serialization, response correlation and transcript projection are real. All home directories are temporary; no provider network or real credentials.
  • git diff --check passed.
  • The existing POSIX hermes chat -q E2E suite is skipped on Windows; full repository suite and live Codex service were not exercised.
  • Post-publication exact-head 27361d09c3c3a698b0536bc58303bcd6b4d5e278: scripts/run_tests.sh tests/agent/transports/ -q — 387 passed, 1 skipped across 20 files.

Scope / overlap

#27746 is partial overlap, not this contract: its diff changes which permission escalations are accepted, but still serializes a decision field for both acceptance and denial. This PR only fixes the wire representation of the existing deny policy and deliberately does not implement its permission-granting feature.

#121499 changes the known-bug test gating infrastructure, not the production permission response. The removal here is limited to this fixed issue's strict xfail.

Acceptance: schema-valid denial is delivered here; no remaining item in #121297 is intentionally deferred. Excluded: permission grants/writable-root policy, single-query approval waiting (#121296), process teardown, and failed-turn output.

@alt-glitch alt-glitch added type/bug Something isn't working P2 Medium — degraded but workaround exists comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint provider/openai OpenAI / Codex Responses API labels Sep 24, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint P2 Medium — degraded but workaround exists provider/openai OpenAI / Codex Responses API type/bug Something isn't working

Projects

None yet

2 participants