fix(security): fail closed on invalid Codex ACP mode - #11362
Conversation
Signed-off-by: Jasper Hugo <jasper@spiral.xyz>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0e4a9b4198
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a975343772
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aa1fee96ae
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9f7b2cb834
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a0c0f12e8c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
* origin/main: (50 commits) chore(deps): bump the ui-minor-and-patch group across 1 directory with 53 updates (#11386) fix(security): bound call graph traversal (#11193) fix: pin arrayref to known-good commit (#11389) feat(providers): add SayGM as declarative OpenAI-compatible provider (#11267) feat(providers): custom provider cost fields drive cost tracking (config-declared pricing fallback) (#11220) fix(deps): repair dangling syn reference in Cargo.lock (#11385) fix(flake): add cudaforge hash for git dependency (#10910) feat: auto-focus chat input when user starts typing (#11184) fix(security): fail closed on invalid Codex ACP mode (#11362) fix(mcp): keep stdio extensions alive across worker exits (#10364) feat(ui): collapse scheduled job sessions into accordion in chat history (#11265) fix: bound retry command diagnostics (#11365) Disable thinking for tool call labels (#11207) fix(review): contain REVIEW.md discovery (#11367) fix(acp): preserve tool result audience metadata (#11375) test(providers): isolate environment-proxy test in its own binary (#11262) fix(security): bind Foundry API keys to request origin (#11347) fix: canonicalize mangled tool names before permission inspection (follow-up to #10230) (#10285) feat(providers): add Lynkr as a declarative OpenAI-compatible provider (#11372) fix: sanitize Pi imported output (#10990) ... # Conflicts: # crates/goose/src/agents/state_machine/tests/hooks_lifecycle.rs
* origin/main: (59 commits) chore(deps): bump the ui-minor-and-patch group across 1 directory with 53 updates (#11386) fix(security): bound call graph traversal (#11193) fix: pin arrayref to known-good commit (#11389) feat(providers): add SayGM as declarative OpenAI-compatible provider (#11267) feat(providers): custom provider cost fields drive cost tracking (config-declared pricing fallback) (#11220) fix(deps): repair dangling syn reference in Cargo.lock (#11385) fix(flake): add cudaforge hash for git dependency (#10910) feat: auto-focus chat input when user starts typing (#11184) fix(security): fail closed on invalid Codex ACP mode (#11362) fix(mcp): keep stdio extensions alive across worker exits (#10364) feat(ui): collapse scheduled job sessions into accordion in chat history (#11265) fix: bound retry command diagnostics (#11365) Disable thinking for tool call labels (#11207) fix(review): contain REVIEW.md discovery (#11367) fix(acp): preserve tool result audience metadata (#11375) test(providers): isolate environment-proxy test in its own binary (#11262) fix(security): bind Foundry API keys to request origin (#11347) fix: canonicalize mangled tool names before permission inspection (follow-up to #10230) (#10285) feat(providers): add Lynkr as a declarative OpenAI-compatible provider (#11372) fix: sanitize Pi imported output (#10990) ...
Summary
GOOSE_MODEis genuinely absentSecurity invariant
Invalid permission configuration must fail before Codex ACP starts with full-access permissions.
Security context
Implements project-loupe/audit-goose#914.
Verification
cargo fmt --allcargo test -p goose providers::codex_acp::tests --lib(4 passed)cargo build -p goosecargo clippy -p goose --all-targets -- -D warningsgit diff --checkThis finding was discovered by Project Loupe