Skip to content

fix(security): fail closed on invalid Codex ACP mode - #11362

Merged
michaelneale merged 8 commits into
mainfrom
jbg/security-codex-mode-fail-closed
Aug 20, 2026
Merged

michaelneale merged 8 commits into
mainfrom
jbg/security-codex-mode-fail-closed

Conversation

@jbg

@jbg jbg commented Aug 19, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • default Codex ACP to Auto only when GOOSE_MODE is genuinely absent
  • read the permission mode through a strict configuration path that propagates malformed or unreadable layers
  • preserve environment precedence and every supported configured permission mode
  • verify real loader failures prevent the Codex ACP process from starting

Security invariant

Invalid permission configuration must fail before Codex ACP starts with full-access permissions.

Security context

Implements project-loupe/audit-goose#914.

Verification

  • cargo fmt --all
  • cargo test -p goose providers::codex_acp::tests --lib (4 passed)
  • cargo build -p goose
  • cargo clippy -p goose --all-targets -- -D warnings
  • git diff --check

This finding was discovered by Project Loupe

Signed-off-by: Jasper Hugo <jasper@spiral.xyz>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0e4a9b4198

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/goose/src/providers/codex_acp.rs Outdated
@jbg

jbg commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@jbg

jbg commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a975343772

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/goose/src/config/base.rs Outdated
@jbg

jbg commented Aug 19, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: aa1fee96ae

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/goose/src/config/base.rs Outdated
Comment thread crates/goose/src/providers/codex_acp.rs Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9f7b2cb834

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/goose/src/config/base.rs Outdated
@michaelneale
michaelneale enabled auto-merge August 19, 2026 22:11

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a0c0f12e8c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/goose/src/config/base.rs
Comment thread crates/goose/src/providers/codex_acp.rs
@michaelneale
michaelneale added this pull request to the merge queue Aug 19, 2026
@jbg
jbg removed this pull request from the merge queue due to a manual request Aug 19, 2026
@jbg
jbg requested a review from DOsinga August 19, 2026 22:35
@michaelneale
michaelneale added this pull request to the merge queue Aug 20, 2026
Merged via the queue into main with commit 01f5ed7 Aug 20, 2026
25 checks passed
@michaelneale
michaelneale deleted the jbg/security-codex-mode-fail-closed branch August 20, 2026 03:39
jbg added a commit that referenced this pull request Aug 20, 2026
* origin/main: (50 commits)
  chore(deps): bump the ui-minor-and-patch group across 1 directory with 53 updates (#11386)
  fix(security): bound call graph traversal (#11193)
  fix: pin arrayref to known-good commit (#11389)
  feat(providers): add SayGM as declarative OpenAI-compatible provider (#11267)
  feat(providers): custom provider cost fields drive cost tracking (config-declared pricing fallback) (#11220)
  fix(deps): repair dangling syn reference in Cargo.lock (#11385)
  fix(flake): add cudaforge hash for git dependency (#10910)
  feat: auto-focus chat input when user starts typing (#11184)
  fix(security): fail closed on invalid Codex ACP mode (#11362)
  fix(mcp): keep stdio extensions alive across worker exits (#10364)
  feat(ui): collapse scheduled job sessions into accordion in chat history (#11265)
  fix: bound retry command diagnostics (#11365)
  Disable thinking for tool call labels (#11207)
  fix(review): contain REVIEW.md discovery (#11367)
  fix(acp): preserve tool result audience metadata (#11375)
  test(providers): isolate environment-proxy test in its own binary (#11262)
  fix(security): bind Foundry API keys to request origin (#11347)
  fix: canonicalize mangled tool names before permission inspection (follow-up to #10230) (#10285)
  feat(providers): add Lynkr as a declarative OpenAI-compatible provider (#11372)
  fix: sanitize Pi imported output (#10990)
  ...

# Conflicts:
#	crates/goose/src/agents/state_machine/tests/hooks_lifecycle.rs
jbg added a commit that referenced this pull request Aug 20, 2026
* origin/main: (59 commits)
  chore(deps): bump the ui-minor-and-patch group across 1 directory with 53 updates (#11386)
  fix(security): bound call graph traversal (#11193)
  fix: pin arrayref to known-good commit (#11389)
  feat(providers): add SayGM as declarative OpenAI-compatible provider (#11267)
  feat(providers): custom provider cost fields drive cost tracking (config-declared pricing fallback) (#11220)
  fix(deps): repair dangling syn reference in Cargo.lock (#11385)
  fix(flake): add cudaforge hash for git dependency (#10910)
  feat: auto-focus chat input when user starts typing (#11184)
  fix(security): fail closed on invalid Codex ACP mode (#11362)
  fix(mcp): keep stdio extensions alive across worker exits (#10364)
  feat(ui): collapse scheduled job sessions into accordion in chat history (#11265)
  fix: bound retry command diagnostics (#11365)
  Disable thinking for tool call labels (#11207)
  fix(review): contain REVIEW.md discovery (#11367)
  fix(acp): preserve tool result audience metadata (#11375)
  test(providers): isolate environment-proxy test in its own binary (#11262)
  fix(security): bind Foundry API keys to request origin (#11347)
  fix: canonicalize mangled tool names before permission inspection (follow-up to #10230) (#10285)
  feat(providers): add Lynkr as a declarative OpenAI-compatible provider (#11372)
  fix: sanitize Pi imported output (#10990)
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants