Repository navigation
Fix Codex app-server permission approval handling - #27746
scottjones08 wants to merge 3 commits into
Conversation
|
Thanks for the focused fix — the premise still reproduces on current main: Problems
Suggested changes
Automated hermes-sweeper review; a human maintainer will make the final call. |
teknium1
left a comment
There was a problem hiding this comment.
Thanks for the focused Codex permission-escalation fix. The current main path still unconditionally declines item/permissions/requestApproval at agent/transports/codex_app_server_session.py:827-832, so the core premise remains valid.
Problems
- PR head
agent/transports/codex_app_server_session.py:128reads writable roots only fromCODEX_HOMEor~/.codex. The session already acceptscodex_homeand forwardsself._codex_hometo its client on current main (agent/transports/codex_app_server_session.py:206-215,247-249), so an explicit override can make the approval check inspect a different config from the app-server. - The new permission-decision path at PR head
agent/transports/codex_app_server_session.py:655-657has no tests. Existing bridge tests cover command and file-change requests attests/agent/transports/test_codex_app_server_session.py:570-713, but notpermissions/requestApproval. - The
approvals.modedashboard option correction is already on main inda6d6164b; it should be omitted during salvage.
Suggested changes
- Thread
self._codex_homeinto writable-root parsing, then fall back toCODEX_HOME/home only when unset. - Add callback, callback-failure, allowed-root, and outside-root tests for permission requests.
Automated hermes-sweeper review; a human maintainer will make the final call.
| malformed config. It lets Hermes safely answer Codex app-server permission | ||
| requests for roots the operator has already marked writable. | ||
| """ | ||
| config_path = Path(os.environ.get("CODEX_HOME", Path.home() / ".codex")) / "config.toml" |
There was a problem hiding this comment.
This bypasses the session's explicit codex_home override. CodexAppServerSession already stores that override and passes it to the app-server client, so parse writable roots from self._codex_home when present and only fall back to CODEX_HOME / ~/.codex otherwise.
Summary\n- route Codex app-server permission escalation requests through Hermes approvals instead of declining them unconditionally\n- safely auto-accept non-interactive permission grants only for configured writable roots/current cwd\n- update config UI schema/docs for the codex_app_server runtime and writable_roots setup\n\n## Verification\n- python3.11 -m py_compile agent/transports/codex_app_server_session.py hermes_cli/web_server.py\n- verified codex app-server can write into configured sibling repo /Users/scottjones/Documents/GitHub/mudanza-azure after restart\n