Summary: 2916 instances, 1856 unique

Text	Count
/// via bubblewrap. It is kept for reference and potential fallback use.	1
impl WritableRoot {	1
.needs_direct_runtime_enforcement(NetworkSandboxPolicy::Restricted, cwd.path(),),	1
translate_legacy_bwrap_fd_mounts(&mut argv).expect("fd mount should translate");	1
let mut existing = FileSystemSandboxPolicy::restricted(vec![deny_entry.clone()]);	1
internal_permissions: Option<&AdditionalPermissionProfile>,	1
granted_permissions_by_environment_id: HashMap<String, AdditionalPermissionProfile>,	2
// representable as `SandboxPolicy`. This guard keeps the old safe	1
use crate::seatbelt::CreateSeatbeltCommandArgsParams;	1
) -> Vec<WindowsWritableRoot> {	1
SandboxPolicy::ExternalSandbox {	1
bwrap_network_mode(network_sandbox_policy, allow_network_for_proxy),	1
codex_protocol::models::PermissionProfile::from_runtime_permissions(	1
.map(|policy| PermissionProfile::from_legacy_sandbox_policy_for_cwd(&policy, cwd))	1
close_fd_or_panic(write_fd, "close write end in bubblewrap child");	1
FileSystemPermissionProfileContext::Managed(ManagedFileSystemContext::from(	1
#[path = "seatbelt_tests.rs"]	1
panic!("failed to create stderr pipe for bubblewrap: {err}");	1
impl From<TaggedPermissionProfile> for PermissionProfile {	1
// TODO(anp): Capture these Windows and Landlock settings from	1
include_str!("seatbelt_read_only_platform_defaults.sbpl");	1
let vendor_dir = manifest_dir.join("../vendor/bubblewrap");	2
Self::Disabled => FileSystemSandboxPolicy::unrestricted(),	1
system_bwrap_launcher_for_path_with_probe(fake_bwrap.path(), |_| {	1
pub permissions: &'a codex_protocol::models::PermissionProfile,	1
let fd_path = format!("/proc/self/fd/{}", bwrap_file.as_raw_fd());	1
SandboxPolicy::ReadOnly { network_access, .. } => *network_access,	1
Some(false) => NetworkSandboxPolicy::Restricted,	1
TaggedPermissionProfile::Disabled => Self::Disabled,	1
fn sandbox_policy_mode(permission_profile: &PermissionProfile, cwd: &Path) -> &'static str {	1
CoreRequestPermissionProfile::try_from(params.permissions)	1
use crate::legacy_core::config::PermissionProfileSnapshot;	1
mod bundled_bwrap;	1
PermissionProfile::Disabled => "Disabled",	1
if !permission_profile_supports_windows_restricted_token_sandbox(permission_profile) {	2
impl FromStr for NetworkSandboxPolicy {	1
// bubblewrap, so first confirm it is live before assuming ownership.	1
PermissionProfile::workspace_write(),	7
additional_permissions: Option<&codex_app_server_protocol::AdditionalPermissionProfile>,	1
pub(super) use codex_protocol::models::PermissionProfile;	1
return Ok(PermissionProfile::Disabled);	1
codex_protocol::models::PermissionProfile::Disabled	1
SandboxPolicy::DangerFullAccess	2
permissions: RequestPermissionProfile {	1
bwrap_args	2
use landlock::RulesetCreatedAttr;	1
PermissionProfile::Disabled | PermissionProfile::External { .. }	1
Some(ActivePermissionProfile {	1
root=ReadOnlySandboxPolicy(type="readOnly"),	1
"failed to inspect synthetic bubblewrap mount target {}: {err}",	1
let policy = FileSystemSandboxPolicy::restricted(vec![	39
use codex_app_server_protocol::PermissionProfileListParams;	1
let permission_profile: PermissionProfile = PermissionProfile::Disabled;	3
ExecPermissionProfile::Disabled => Self::Disabled,	1
// `PR_SET_NO_NEW_PRIVS` is required for seccomp, but it also prevents	1
SandboxPolicy::DangerFullAccess,	1
let context = FileSystemSandboxPolicyContext {	1
"failed to read synthetic bubblewrap mount marker {}: {err}",	1
let summary = summarize_sandbox_policy(&SandboxPolicy::ReadOnly {	1
// we avoid this unless we need seccomp or we are explicitly using the	1
impl From<PermissionProfile> for ExecPermissionProfile {	1
response: v2::PermissionProfileListResponse,	1
pub struct PermissionProfileSummary {	1
"failed to normalize system bubblewrap path {}: {err}",	1
NetworkSandboxPolicy::Restricted,	20
pub(crate) struct WindowsWritableRoot {	1
if let Err(err) = CoreRequestPermissionProfile::try_from(params.permissions.clone())	1
SandboxPolicy::ExternalSandbox { network_access } => network_access.is_enabled(),	1
let rebuilt = FileSystemSandboxPolicy::from_legacy_sandbox_policy_preserving_deny_entries(	1
// if lpDesktop is not set when launching with a restricted token.	1
PermissionProfile::External {	3
FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {	2
// paths that still speak `SandboxPolicy`.	1
let mut policy = FileSystemSandboxPolicy::restricted(Vec::new());	1
use_legacy_landlock: bool,	7
) -> Option<codex_app_server_protocol::ActivePermissionProfile> {	1
&PermissionProfile::read_only()	1
// Full disk write normally skips bwrap, but unreadable glob patterns still	1
value: CoreRequestPermissionProfile,	1
use crate::seatbelt::SeatbeltPreparationError;	1
constrained_permission_profile: Constrained<PermissionProfile>,	3
let opaque_policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry::new(	1
}) = system_bwrap_capabilities(system_bwrap_path)	1
fn rejects_duplicate_legacy_bubblewrap_fd_mounts() {	1
permissions: RequestPermissionProfile::default(),	3
fn wait_for_bwrap_child(pid: libc::pid_t) -> libc::c_int {	1
permission_profile: PermissionProfile::read_only(),	2
(BUILT_IN_READ_ONLY_PROFILE, PermissionProfile::read_only()),	1
"read-only" => Ok(SandboxPolicy::new_read_only_policy()),	1
let PermissionProfileSelection {	1
let network_sandbox_policy = NetworkSandboxPolicy::from(&sandbox_policy);	1
fn send_signal_to_bwrap_child(pid: libc::pid_t, signal: libc::c_int) {	1
bwrap_args.args.push("000".to_string());	1
codex_protocol::permissions::FileSystemSandboxPolicy,	2
Ok(WindowsSandboxTokenMode::WritableRootsCapability)	1
fn append_missing_read_only_subpath_args(bwrap_args: &mut BwrapArgs, path: &Path) -> Result<()> {	1
policy: &mut FileSystemSandboxPolicy,	1
pub use permission_profile_catalog::PermissionProfileCatalogEntry;	1
const MACOS_SEATBELT_BASE_POLICY: &str = include_str!("seatbelt_base_policy.sbpl");	1
action.sa_sigaction = forward_signal_to_bwrap_child as *const () as libc::sighandler_t;	1
pub permission_profile: Option<PermissionProfile>,	6
let profile = PermissionProfile::workspace_write_with(	1
FileSystemSandboxPolicy::restricted(vec![unreadable_glob_entry(pattern.clone())]);	1
binaries.append("bwrap")	1
if let Some(path) = bazel_bwrap::candidate() {	1
active_permission_profile: ActivePermissionProfile,	1
let opaque_context = FileSystemSandboxPolicyContext {	1
AppEvent::SelectPermissionProfile(selection) => {	1
.expect("write fake bubblewrap");	1
codex_protocol::permissions::FileSystemSandboxPolicy::unrestricted(),	1
session.permission_profile = PermissionProfile::from_legacy_sandbox_policy_for_cwd(	1
PermissionProfileResolutionError::UndefinedParent {	1
"bwrap".to_string(),	4
use codex_protocol::permissions::FileSystemSandboxPolicyContext;	1
) -> FileSystemSandboxPolicy {	1
enum SandboxPolicyDeserialize {	1
sandbox_policy: Option<SandboxPolicy>,	1
permissions: &RequestPermissionProfile,	2
pub(crate) fn network_sandbox_policy(&self) -> NetworkSandboxPolicy {	1
fn run_bwrap_in_child_capture_stderr(bwrap_args: crate::bwrap::BwrapArgs) -> String {	1
fn denylist_expansion_enabled(permission_profile: &PermissionProfile) -> bool {	1
let error = create_bwrap_command_args(	1
active_permission_profile: Option<&ActivePermissionProfile>,	2
let LandlockCommand {	2
/// Full command args to run under seatbelt.	1
export type { PermissionProfileListParams } from "./PermissionProfileListParams";	1
GrantedPermissionProfile {	2
preferred_bwrap_supports_argv0(),	1
bwrap_args.args.push(path_to_string(mount_root));	2
fn profile_allows_configured_network_proxy(permission_profile: &PermissionProfile) -> bool {	1
let permission_profile = PermissionProfile::from_legacy_sandbox_policy_for_cwd(	1
| ExecPermissionProfile::Disabled	1
/// Assert that `path` is masked due to a bwrap arg sequence like:	1
"use_legacy_landlock" => {	1
fn try_from(value: RequestPermissionProfile) -> Result<Self, Self::Error> {	1
fn seatbelt_regex_for_glob(pattern: &str, glob_match: GlobMatch) -> Option<String> {	1
send_signal_to_bwrap_child(pid, signal);	2
append_existing_empty_directory_args(bwrap_args, subpath, &metadata);	1
fn prefers_system_bwrap_when_help_lists_argv0() {	1
use_legacy_landlock: sandbox_config.use_legacy_landlock,	1
let PermissionProfile::Managed {	1
permission_profile: PermissionProfile::read_only(),	1
&FileSystemSandboxPolicy::restricted(vec![	1
PermissionProfile::External { .. } => return "external",	1
append_unreadable_root_args(&mut bwrap_args, unreadable_root, &allowed_write_paths)?;	1
return Err("bubblewrap argv is missing the inner command after '--'".to_string());	1
should_install_network_seccomp(	2
) -> io::Result<SandboxPolicy> {	1
Ok(SandboxPolicy::WorkspaceWrite {	1
codex_protocol::protocol::SandboxPolicy::WorkspaceWrite {	1
use seccompiler::SeccompCmpOp;	1
PermissionProfile::workspace_write(),	1
codex_app_server_protocol::ActivePermissionProfile::read_only(),	1
codex_sandboxing::system_bwrap_warning(config.permissions.permission_profile())	1
pub enum NetworkSandboxPolicy {	1
..CoreRequestPermissionProfile::default()	3
//! - bubblewrap for filesystem isolation.	1
//! Landlock helpers remain available here as legacy/backup utilities.	1
pub async fn run_command_under_seatbelt(	2
"[features].use_legacy_landlock"	1
CodexErr::LandlockSandboxExecutableNotProvided	1
) -> PermissionProfileToml {	1
panic!("failed to restore bubblewrap forwarded signals: {err}");	1
policy: &FileSystemSandboxPolicy,	1
pub active_permission_profile: Option<ActivePermissionProfile>,	10
.set_permission_profile(PermissionProfile::workspace_write())	1
ClientRequest::PermissionProfileList { params, .. } => {	1
let enabled = SandboxPolicy::ExternalSandbox {	1
std::env::var("CODEX_SANDBOX").as_deref() == Ok("seatbelt")	1
permissions: RequestPermissionProfile {	1
let mut file_system_sandbox_policy = FileSystemSandboxPolicy::restricted(Vec::new());	1
panic!("failed to redirect stderr for bubblewrap: {err}");	1
use crate::landlock::create_linux_sandbox_command_args_for_permission_profile;	1
// Child: redirect stderr to the pipe, then run bubblewrap.	1
use codex_app_server_protocol::AdditionalPermissionProfile as V2AdditionalPermissionProfile;	1
if let Err(err) = try_build_bwrap() {	1
if permission_profile_supports_windows_restricted_token_sandbox(permission_profile)	1
use crate::models::PermissionProfile;	4
pub struct FileSystemSandboxPolicy {	1
pub use crate::permissions::RawFileSystemSandboxPolicy;	1
ensure_legacy_landlock_mode_supports_policy(	1
pub(super) use codex_protocol::models::ActivePermissionProfile;	1
enum NormalizedWritableRoot {	1
pub(super) use_legacy_landlock: bool,	1
}) => PermissionProfile::workspace_write_with(	1
PermissionProfile::from_legacy_sandbox_policy_for_cwd(&policy, cwd);	1
SandboxPolicy::DangerFullAccess => true,	2
use super::AdditionalPermissionProfile;	1
CodexErrorDetails::LandlockRuleset(_) | CodexErrorDetails::LandlockPathFd(_) => false,	1
/// This exists so we can run bubblewrap first (which may rely on setuid)	1
pub(crate) fn sandbox_policy(&self) -> SandboxPolicy {	1
// setuid privilege elevation. Many `bwrap` deployments rely on setuid, so	1
|| config.features.use_legacy_landlock(),	1
match SandboxPolicyDeserialize::deserialize(deserializer)? {	1
SandboxPolicy::DangerFullAccess => SandboxMode::DangerFullAccess,	1
let bwrap_file = File::open(self.program.as_path()).unwrap_or_else(|err| {	1
PermissionProfile::Disabled => {	2
|state| state.use_legacy_landlock,	1
bwrap_args.args.push("--perms".to_string());	2
enum TaggedPermissionProfile {	1
} = bwrap_args;	2
pub fn permission_profile(&self) -> PermissionProfile {	1
use super::SandboxPolicy;	3
// In bubblewrap (`bubblewrap.c`, `SETUP_MOUNT_DEV`), `--dev /dev`	1
WindowsWritableRoot {	1
SandboxPolicy::ReadOnly { .. } => Vec::new(),	1
fn from(value: AdditionalPermissionProfile) -> Self {	1
fn should_warn_about_system_bwrap(permission_profile: &PermissionProfile) -> bool {	1
pub fn find_system_bwrap_in_path() -> Option<PathBuf> {	1
impl From<RequestPermissionProfile> for AdditionalPermissionProfile {	1
SandboxPolicy::ReadOnly { network_access }	1
let src_dir = resolve_bwrap_source_dir(&manifest_dir)?;	1
NetworkSandboxPolicy::Restricted,	6
if !matches!(permission_profile, PermissionProfile::Managed { .. }) {	1
/// bubblewrap pipeline.	1
SandboxType::Landlock => {	1
Self::Seatbelt => "seatbelt",	1
codex_protocol::protocol::SandboxPolicy::ReadOnly { network_access } => {	1
SandboxPolicy::ReadOnly { .. } => false,	1
UseLegacyLandlock,	1
pub use codex_protocol::approvals::ResolvedPermissionProfile;	1
fn from(value: &FileSystemSandboxPolicy) -> Self {	1
fn from(value: ActivePermissionProfile) -> Self {	1
let status = wait_for_bwrap_child(pid);	2
pub enum PermissionProfile {	1
impl<'de> Deserialize<'de> for SandboxPolicy {	1
use_legacy_landlock: self.features.use_legacy_landlock(),	1
ensure_linux_bubblewrap_is_supported(	1
) -> CodexResult<PermissionProfileState> {	1
PermissionProfile::Disabled => return "none",	1
bwrap_args.preserved_files.extend(proxy_controls);	1
SandboxPolicy::ReadOnly {	2
"bubblewrap is unavailable: no system bwrap was found on PATH and no bundled \	1
seatbelt_args.extend(definition_args);	1
tx.send(AppEvent::SelectPermissionProfile(selection.clone()));	1
let policy = SandboxPolicy::WorkspaceWrite {	2
let expected_bwrap = resources_dir.join("bwrap");	1
bwrap_args.args.push(null_fd);	1
.downcast_ref::<UnsupportedLegacyPermissionProfile>()	1
fn from(value: RequestPermissionProfile) -> Self {	1
permission_profile: Some(PermissionProfile::Disabled),	1
/// Enable `PR_SET_NO_NEW_PRIVS` so seccomp can be applied safely.	1
CoreRequestPermissionProfile::default(),	3
.to_legacy_sandbox_policy(NetworkSandboxPolicy::Restricted, cwd)	1
.set_permission_profile(PermissionProfile::read_only())	1
FileSystemSandboxPolicy::restricted(entries)	1
SandboxPolicyDeserialize::ExternalSandbox { network_access } => {	1
| PermissionProfile::Disabled	1
turn_override: RuntimePermissionProfileTurnOverride::LegacySandbox,	1
pub fn file_system_sandbox_policy(&self) -> FileSystemSandboxPolicy {	2
PermissionProfile::Disabled => "full_access",	1
PermissionProfile::External {	1
fn should_apply_network_block(permission_profile: &PermissionProfile) -> bool {	1
network_policy: NetworkSandboxPolicy,	4
// need concrete bwrap masks for the matches expanded below.	1
pub fn to_sandbox_policy(&self) -> FileSystemSandboxPolicy {	1
PermissionProfile::from_runtime_permissions(&policy, NetworkSandboxPolicy::Restricted);	2
"failed to normalize bundled bubblewrap path {}: {err}",	1
use crate::bundled_bwrap::BundledBwrapLauncher;	1
pub(super) permission_profile_state: PermissionProfileState,	1
if matches!(authority, PermissionProfile::Disabled)	1
use codex_protocol::models::AdditionalPermissionProfile;	19
PermissionProfile::from_runtime_permissions(&policy, NetworkSandboxPolicy::Restricted),	1
use crate::permissions::FileSystemSandboxPolicy;	1
let policy = FileSystemSandboxPolicy::workspace_write(	1
impl<'de> Deserialize<'de> for PermissionProfile {	1
let permission_snapshot = PermissionProfileSnapshot::from_session_snapshot(	2
/// Whether to use legacy Landlock behavior in the MCP sandbox state.	1
codex_protocol::protocol::SandboxPolicy::DangerFullAccess => {	1
candidates.push(exe_dir.join("codex-resources").join("bwrap"));	1
let policy = FileSystemSandboxPolicy::restricted(vec![unreadable_path_entry(missing)]);	1
.set_permission_profile(PermissionProfile::workspace_write())?;	1
BUILT_IN_WORKSPACE_PROFILE => FileSystemSandboxPolicy::workspace_write(	1
config.permission_profile = PermissionProfile::default();	1
.expect("make fake bubblewrap executable");	1
assert_eq!(WindowsSandboxTokenMode::WritableRootsCapability, token_mode);	1
permission_profile: PermissionProfileSnapshot,	1
) -> Result<PermissionProfileToml, PermissionProfileResolutionError> {	1
bwrap_args.args.push("--ro-bind".to_string());	1
/// Pre-tagged shape written to rollout files before `PermissionProfile`	1
.and_then(|path| seatbelt_regex_for_glob(path, GlobMatch::Exact))	1
use crate::bundled_bwrap;	1
NetworkSandboxPolicy::Enabled	2
use crate::LandlockCommand;	1
None => PermissionProfileSnapshot::legacy(permission_profile),	1
let mut replacement = FileSystemSandboxPolicy::unrestricted();	1
codex_protocol::protocol::SandboxPolicy::ExternalSandbox {	1
) -> Option<PermissionProfile> {	1
CoreRequestPermissionProfile::default()	2
let mut seatbelt_args: Vec<String> = vec!["-p".to_string(), full_policy];	1
format_additional_permissions_rule(&AdditionalPermissionProfile {	1
SandboxMode::DangerFullAccess => PermissionProfile::Disabled,	1
Ok(bwrap_args)	1
set_no_new_privs()?;	1
pub fn permission_profile_for_server(&self, server_name: &str) -> Option<&PermissionProfile> {	1
writable_root: &WritableRoot,	1
let expected_bwrap = temp_dir.path().join("codex-resources").join("bwrap");	1
use_legacy_landlock: false,	1
| SandboxPolicy::ExternalSandbox { .. }	1
CoreAdditionalPermissionProfile::try_from(response.permissions)	1
PermissionProfile::Managed { .. } => "Managed",	1
let permission_profile: PermissionProfile = PermissionProfile::External {	1
impl From<&FileSystemSandboxPolicy> for FileSystemPermissions {	1
pub fn new(file_system_sandbox_policy: &FileSystemSandboxPolicy, cwd: &Path) -> Option<Self> {	1
let slash_tmp_only_policy = FileSystemSandboxPolicy::restricted(vec![	1
use landlock::Ruleset;	1
codex_protocol::protocol::SandboxPolicy::ExternalSandbox { network_access } => {	1
_permission_profile: &PermissionProfile,	3
SandboxPolicy,	2
let read_only = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {	1
None => PermissionProfileSnapshot::legacy(	1
permission_profile: Option<PermissionProfile>,	1
fn file_system_root(context: &FileSystemSandboxPolicyContext<'_>) -> Option<PathUri> {	1
app.apply_permission_profile_selection(PermissionProfileSelection {	1
/// For now, we take `NetworkSandboxPolicy` as a parameter to spawn_child()	1
// Record both the logical match and any canonical symlink target. The bwrap	1
def _sandbox_policy(sandbox: Sandbox | None) -> SandboxPolicy | None:	1
Ok(create_bwrap_flags_full_filesystem(command, options))	1
assert_eq!(filtered.contains("sandboxPolicy?: SandboxPolicy"), true);	1
use codex_protocol::protocol::SandboxPolicy;	4
raise RuntimeError("--bwrap-bin is only supported for Linux targets.")	1
use codex_protocol::models::PermissionProfile;	82
Some(RuntimePermissionProfileOverride::from_config(&app.config))	2
/// Whether Linux sandbox processes use the legacy Landlock backend.	1
assert!(FileSystemSandboxPolicy::matches_prepared_read_deny(	1
pub use crate::permissions::NetworkSandboxPolicy;	1
fn install_bwrap_signal_forwarders(pid: libc::pid_t) -> ForwardedSignalHandlers {	1
let expected_permission_profile = PermissionProfile::workspace_write();	1
PermissionProfile::Managed { network, .. } | PermissionProfile::External { network } => {	1
active_permission_profile: Option<ActivePermissionProfile>,	3
if !should_warn_about_system_bwrap(permission_profile) {	1
) -> std::io::Result<ResolvedPermissionProfileSelection<'a>> {	1
build_bwrap=spec.is_linux and bwrap_bin is None,	1
pub use crate::permissions::FileSystemSandboxPolicy;	1
panic!("waitpid failed for bubblewrap child: {err}");	1
/// How networking should be configured inside the bubblewrap sandbox.	1
pub struct PermissionProfileSnapshot {	1
"failed to remove synthetic bubblewrap mount marker directory {}: {err}",	1
fn read_only_permission_profile(permission_profile: &PermissionProfile) -> PermissionProfile {	1
sandboxPolicy?: SandboxPolicy | null,	1
codex_protocol::protocol::SandboxPolicy::ExternalSandbox { .. }	1
requested_policy: &FileSystemSandboxPolicy,	1
impl FileSystemPermissionProfileContext {	1
assert!(err.contains("bundled bubblewrap digest mismatch"));	1
snapshot: PermissionProfileSnapshot,	4
let reordered = FileSystemSandboxPolicy::restricted(reordered_entries);	1
PermissionProfile::Disabled => FileSystemPermissionProfileContext::Disabled,	1
mod landlock;	1
let mut intersection = FileSystemSandboxPolicy::restricted(denies);	1
pub(super) use codex_protocol::request_permissions::RequestPermissionProfile;	1
panic!("failed to create bubblewrap exec start pipe: {err}");	1
pub(crate) fn preferred_bwrap_supports_argv0() -> bool {	1
enum RuntimePermissionProfileTurnOverride {	1
SandboxType::Landlock,	1
.unwrap_or_else(|_| PermissionProfile::read_only())	1
} else if self.policy.sandbox.permissions == ExecPermissionProfile::Disabled {	1
let mut bwrap_args = build_bwrap_argv(	1
network_sandbox_policy: NetworkSandboxPolicy::from(sandbox_policy),	1
permission_profile: PermissionProfileSnapshot::active_with_profile_workspace_roots(	3
let permissions = codex_app_server_protocol::RequestPermissionProfile {	1
pub(crate) fn active_permission_profile(&self) -> Option<ActivePermissionProfile> {	2
let permissions = PermissionProfile::Managed {	1
let active_permission_profile = ActivePermissionProfile::new("strict");	1
let mut argv = vec!["bwrap".to_string()];	1
let request = RequestPermissionProfile {	2
let expected_bwrap = target_dir.join("codex-resources").join("bwrap");	1
impl TryFrom<RequestPermissionProfile> for CoreRequestPermissionProfile {	1
let permissions: PermissionProfile = sandbox_context	1
impl WritableRootPathResolution {	1
struct LegacyPermissionProfile {	1
use codex_app_server_protocol::GrantedPermissionProfile;	1
let exit_code = unsafe { bwrap_main(cstrings.len() as libc::c_int, argv_ptrs.as_ptr()) };	1
environment_profiles: impl IntoIterator<Item = (String, PermissionProfile)>,	1
assert_eq!(permission_profile, PermissionProfile::Disabled);	2
fn find_system_bwrap_in_search_paths(	1
root=WorkspaceWriteSandboxPolicy(type="workspaceWrite"),	1
NormalizedWritableRoot::Subpath(root) => (root, SeatbeltPathMatch::Subpath),	1
FileSystemSandboxPolicy::read_only(),	1
LegacySandbox(PermissionProfile),	1
impl fmt::Display for ResolvePermissionProfileError {	1
assert_eq!(AdditionalPermissionProfile::default().is_empty(), true);	1
.unwrap_or_else(|error| panic!("invalid legacy bubblewrap fd mount: {error}"));	1
fn bazel_bwrap_env_key_is_allowed(_key: &str) -> bool {	1
&FileSystemSandboxPolicy::from_legacy_sandbox_policy_preserving_deny_entries(	1
let context = FileSystemSandboxPolicyContext {	6
LandlockRuleset(error: landlock::RulesetError),	1
panic!("failed to restore bubblewrap signal handler for {signal}: {err}");	1
additional_permissions.map(V2AdditionalPermissionProfile::from);	1
PermissionProfile::from_runtime_permissions_with_enforcement(	1
pub fn permission_profile_supports_windows_restricted_token_sandbox(	1
"SandboxPolicy",	1
//!   because Codex itself commonly runs spawned test processes under seatbelt, so this is not just	1
PermissionProfile::External { .. } => "External",	1
ruleset = ruleset.add_rules(landlock::path_beneath_rules(&writable_roots, access_rw))?;	1
|| PermissionProfileResolutionError::UndefinedProfile {	1
pub(crate) permission_profile: Option<PermissionProfile>,	1
impl Default for FileSystemSandboxPolicy {	1
} => FileSystemSandboxPolicy::workspace_write(	1
codex_protocol::protocol::SandboxPolicy::WorkspaceWrite {	1
pub(crate) requested_permissions: RequestPermissionProfile,	1
&& constrained_permission_profile.get() == &PermissionProfile::read_only()	1
pub permission_profile: ConstrainedWithSource<PermissionProfile>,	1
ExecPermissionProfile::Managed {	3
FileSystemSandboxPolicyContext {	2
append_unreadable_root_args(&mut bwrap_args, &unreadable_root, &allowed_write_paths)?;	1
// seccomp, so the outer filesystem sandbox must expose both paths.	1
.to_legacy_sandbox_policy(NetworkSandboxPolicy::from(&expected), cwd.path())	1
pub fn legacy_sandbox_policy(&self) -> SandboxPolicy {	1
const MACOS_SEATBELT_PREFERENCES_POLICY: &str = include_str!("seatbelt_preferences_policy.sbpl");	1
let preflight_argv = build_preflight_bwrap_argv(network_mode)?;	1
file_system_sandbox_policy: FileSystemSandboxPolicy,	1
FileSystemSandboxPolicy::restricted(vec![	6
assert!(should_install_network_seccomp(	2
"failed to read synthetic bubblewrap mount marker directory {}: {err}",	1
!args.synthetic_mount_targets[0].should_remove_after_bwrap(&metadata),	1
exec_system_bwrap(&launcher.program, argv, preserved_files)	1
fn leaves_legacy_restricted_token_backend_alone() {	1
fn build_inner_seccomp_command(args: InnerSeccompCommandArgs<'_>) -> Vec<String> {	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(&policy, relative_cwd);	1
bwrap_args.args.push(path_to_string(path));	3
pub(super) fn permission_profile_from_metadata_value(value: &str, cwd: &Path) -> PermissionProfile {	1
let policy = FileSystemSandboxPolicy::restricted(vec![unreadable_glob_entry(	1
let expected_bwrap = temp_dir.path().join("bwrap");	1
let Some(regex) = seatbelt_regex_for_unreadable_glob(&pattern) else {	1
Self::InvalidSandboxPolicyCwd { cwd, source } => write!(	1
FileSystemSandboxPolicy::workspace_write(	1
"Install bubblewrap with your OS package manager. ",	1
codex_protocol::protocol::SandboxPolicy::ReadOnly {	1
impl PermissionProfileState {	1
legacy_policy: &SandboxPolicy,	1
use_legacy_landlock,	2
seatbelt_args.extend(command);	1
let stderr = run_bwrap_in_child_capture_stderr(preflight_argv);	1
#[error("seccomp backend error")]	1
/// Run a short-lived bubblewrap preflight in a child process and capture stderr.	1
return Err(PermissionProfileResolutionError::Cycle { cycle });	1
candidates.push(package_target_dir.join("codex-resources").join("bwrap"));	1
PermissionProfile::Disabled | PermissionProfile::External { .. }	1
use_legacy_landlock,	3
PermissionProfile::read_only(),	7
let network_seccomp_mode = network_seccomp_mode(	1
raw_overrides: vec!["use_legacy_landlock=true".to_string()],	1
let summary = summarize_sandbox_policy(&SandboxPolicy::WorkspaceWrite {	1
PermissionProfileSnapshot::active_with_profile_workspace_roots(	1
pub use crate::permission_profile_snapshot::PermissionProfileSnapshot;	1
.set_permission_profile_from_session_snapshot(PermissionProfileSnapshot::legacy(	3
system_bwrap_launcher_for_path(Path::new("/definitely/not/a/bwrap")),	1
/// should prefer `activePermissionProfile` for profile provenance.	3
println!("cargo:rustc-cfg=bwrap_available");	1
permission_profile: &PermissionProfile,	26
//! Landlock + seccomp.	1
fn from(value: CoreActivePermissionProfile) -> Self {	1
fn resolve_bwrap_source_dir(manifest_dir: &Path) -> Result<PathBuf, String> {	1
fn sandbox_policy_allows_read(policy: &SandboxPolicy, _path: &Path, _cwd: &Path) -> bool {	1
let signal_forwarders = install_bwrap_signal_forwarders(pid);	2
append_missing_read_only_subpath_args(bwrap_args, &first_missing_component)?;	1
SandboxPolicy::DangerFullAccess	1
bwrap_bin,	1
if matches!(permission_profile, PermissionProfile::Disabled) {	1
permissions: RequestPermissionProfile::default(),	1
let environment_permission_profile = PermissionProfile::from_runtime_permissions(	1
command: LandlockCommand,	1
codex_cli::run_command_under_landlock(	1
file_system_sandbox_policy: &FileSystemSandboxPolicy,	5
.unwrap_or_else(PermissionProfile::read_only),	1
fn finds_adjacent_dev_bwrap() {	1
if key == "use_legacy_landlock" {	1
use codex_app_server_protocol::GrantedPermissionProfile;	1
) -> io::Result<PermissionProfileToml> {	1
bwrap_bin: Path | None,	2
Ok(match PermissionProfileDe::deserialize(deserializer)? {	1
&SandboxPolicy::new_workspace_write_policy()	1
let policy = serde_json::from_value::<SandboxPolicy>(json!({	2
actual: &SandboxPolicy,	1
&FileSystemSandboxPolicy::restricted(Vec::new()),	1
PermissionProfileSnapshot::active(	2
pub(super) fn network_sandbox_policy(&self) -> NetworkSandboxPolicy {	1
use landlock::CompatLevel;	1
PermissionProfile::from_legacy_sandbox_policy_for_cwd(	1
if inputs.bwrap_bin is not None:	1
impl TryFrom<FileSystemSandboxPolicy> for RawFileSystemSandboxPolicy {	1
) -> (SandboxMode, Option<Vec<WritableRoot>>) {	1
additional_permissions: Some(AdditionalPermissionProfile {	2
parent_permission_profile: &PermissionProfile,	1
"max depth should keep deeper matches out of bwrap args: {:#?}",	1
TurnPermissionsOverride::ActiveProfile(ActivePermissionProfile::new(	1
fn append_empty_directory_args(bwrap_args: &mut BwrapArgs, path: &Path) {	1
effective_permission_profile: PermissionProfile,	1
#[cfg_attr(not(windows), allow(unused_variables))] permission_profile: &PermissionProfile,	1
network: NetworkSandboxPolicy::Enabled,	1
use crate::app_event::PermissionProfileSelection;	2
/// wiring, but bubblewrap is now the default filesystem sandbox and Landlock	1
/// Wrap a command with bubblewrap so the filesystem is read-only by default,	1
SandboxPolicy::WorkspaceWrite { network_access, .. } => *network_access,	1
allowed: "must include 'read-only' to allow any PermissionProfile"	1
fn bwrap_main(argc: libc::c_int, argv: *const *const c_char) -> libc::c_int;	1
crate::bwrap::SyntheticMountTarget::missing(target.path())	1
fn permission_profile_id_from_active_profile(active: ActivePermissionProfile) -> String {	2
/// Create a restricted token that includes all provided capability SIDs, the token user SID, and	2
"failed to remove synthetic bubblewrap mount target {}: {err}",	2
.any(|argument| argument == "--apply-seccomp-then-exec")	1
PermissionProfile::read_only(),	1
#[path = "landlock_tests.rs"]	1
/// Full command args to run under Windows restricted token sandbox.	1
SandboxPolicy::ExternalSandbox {	1
BUILT_IN_PERMISSION_PROFILE_WORKSPACE => Some(PermissionProfile::workspace_write()),	1
let SandboxPolicy::WorkspaceWrite {	1
/// Error from linux seccomp backend	1
pub additional_permissions: Option<AdditionalPermissionProfile>,	9
"failed to remove stale synthetic bubblewrap mount marker {}: {err}",	1
PermissionProfile::from_runtime_permissions_with_enforcement(	1
codex_process_hardening::pre_main_hardening();	1
/// - installing the network seccomp filter when network access is disabled.	1
use codex_protocol::protocol::NetworkSandboxPolicy;	2
fn create_seatbelt_command_args_for_legacy_policy(	1
"external filesystem policies are represented by PermissionProfile::External"	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(	1
"failed to register synthetic bubblewrap mount target {}: {err}",	1
pub sandbox_policy: Option<SandboxPolicy>,	6
"permissions profile requests filesystem writes outside the workspace root, which is not supported until the runtime enforces FileSystemSandboxPolicy directly",	1
codex_protocol::protocol::SandboxPolicy::ReadOnly {	1
permissions: RequestPermissionProfile::default(),	2
requested_permissions: CoreRequestPermissionProfile,	2
let granted_permissions: CoreAdditionalPermissionProfile = response.permissions.try_into()?;	1
pub fn effective_permission_profile(&self) -> PermissionProfile {	1
//! - on macOS seatbelt runs, `reqwest::Client::builder().build()` can panic inside	1
pub struct LandlockCommand {	2
| CodexErrorDetails::LandlockSandboxExecutableNotProvided	1
let selection = PermissionProfileSelection {	2
) -> Option<PermissionProfile> {	2
return SandboxPolicy(	3
let Ok(permissions) = PermissionProfile::try_from(self.permissions.clone()) else {	1
pub(crate) sandbox_policy: Option<SandboxPolicy>,	1
enable: vec!["use_linux_sandbox_bwrap".to_string()],	1
"failed to unlock synthetic bubblewrap mount registry {}: {err}",	1
fn from(value: NetworkSandboxPolicy) -> Self {	1
let existing = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {	1
"bundled bubblewrap digest mismatch for {}: expected sha256:{}, got sha256:{}",	1
NetworkSandboxPolicy::Restricted	2
use crate::protocol::WritableRoot;	1
active_permission_profile: Option<ActivePermissionProfile>,	8
/// 1. `CODEX_BWRAP_SOURCE_DIR` points at an existing bubblewrap checkout.	1
if let Some(path) = find_system_bwrap_in_path()	1
matches!(self, NetworkSandboxPolicy::Enabled)	1
SandboxPolicy::DangerFullAccess => {	1
export type { GrantedPermissionProfile } from "./GrantedPermissionProfile";	1
let permission_profile: PermissionProfile = PermissionProfile::Managed {	2
NetworkSandboxPolicy::from(&self.sandbox_policy),	1
NetworkSandboxPolicy::from(sandbox_policy),	1
enum ResolvePermissionProfileError {	1
.can_set(&PermissionProfile::read_only())	2
*network = NetworkSandboxPolicy::Restricted;	1
permissions: Option<&AdditionalPermissionProfile>,	1
permission_profile: PermissionProfile,	12
use codex_app_server_protocol::SandboxPolicy;	2
use_legacy_landlock: self.use_legacy_landlock,	3
sandbox_policy: SandboxPolicy,	4
bwrap_args.args.push("--ro-bind".to_string());	1
bwrap_args.args.push("555".to_string());	1
LandlockPathFd(#[from] landlock::PathFdError),	1
let bwrap_args = create_bwrap_command_args(	1
baseline: &PermissionProfile,	1
use seccompiler::SeccompCondition;	1
"failed to lock synthetic bubblewrap mount registry {}: {err}",	1
writable_roots.push(WritableRoot {	1
let fake_bwrap = NamedTempFile::new().expect("temp file");	3
fallback: impl FnOnce() -> PermissionProfile,	1
PermissionProfile::Managed { .. }	1
fn start(targets: &[crate::bwrap::ProtectedCreateTarget]) -> Option<Self> {	1
use_legacy_landlock: sandbox_config.use_legacy_landlock,	1
pub(crate) struct PermissionProfileSelection {	1
.unwrap_or(PermissionProfile::External {	2
/*apply_landlock_fs*/ true,	1
| codex_protocol::models::PermissionProfile::External { .. } => true,	1
assert_eq!(PermissionProfile::read_only(), payload.permission_profile);	1
permission_profile: PermissionProfileSnapshot::legacy(	1
use crate::bwrap::BwrapOptions;	1
let response = if env::var("CODEX_SANDBOX").as_deref() == Ok("seatbelt") {	1
use seccompiler::SeccompCmpArgLen;	1
"Restricted read-only access is not supported by the legacy Linux Landlock filesystem backend."	1
mut child: PermissionProfileToml,	1
env.insert(CODEX_SANDBOX_ENV_VAR.to_string(), "seatbelt".to_string());	1
.unwrap_or_else(|err| panic!("invalid system bubblewrap path: {err}"));	1
pub fn from_legacy_sandbox_policy_for_cwd(sandbox_policy: &SandboxPolicy, cwd: &Path) -> Self {	2
pub fn policy_context(&self) -> Option<FileSystemSandboxPolicyContext<'_>> {	1
pub(crate) fn permission_profile_state(&self) -> &PermissionProfileState {	1
const BAZEL_BWRAP_ENV_VAR: &str = "CARGO_BIN_EXE_bwrap";	1
.can_set(&PermissionProfile::External {	1
(FileSystemSandboxViolationReason::PolicyDenied, "landlock"),	1
// Example: if `<root>/.codex -> <root>/decoy`, bwrap must still see	1
seatbelt_profile: MacosSeatbeltProfile,	1
Legacy(LegacyPermissionProfile),	1
PermissionProfileSnapshot::legacy(permissions);	1
use codex_app_server_protocol::SandboxPolicy;	1
.map(|(name, _)| (name.clone(), PermissionProfile::default()))	1
RequestPermissionProfile::try_from(permissions.clone()).expect_err("relative path");	1
PermissionProfile::Managed { .. }	1
sandbox_policy: SandboxPolicy::DangerFullAccess,	3
use crate::seatbelt::create_seatbelt_command_args_with_profile;	1
panic!("failed to place bubblewrap child in its own process group: {err}");	1
EscalationExecution::Permissions(EscalationPermissions::ResolvedPermissionProfile(	1
/// Installs Landlock file-system rules on the current thread allowing read	1
let v2_policy = SandboxPolicy::ExternalSandbox {	1
use codex_protocol::models::AdditionalPermissionProfile;	1
fn system_bwrap_launcher_for_path(system_bwrap_path: &Path) -> Option<SystemBwrapLauncher> {	1
requested: AdditionalPermissionProfile,	1
impl From<landlock::RulesetError> for CodexErr {	1
synthetic_mount_targets: bwrap_args.synthetic_mount_targets,	1
apply_landlock_fs: bool,	1
use_legacy_landlock: false,	7
.send(AppEvent::UpdateActivePermissionProfile(	1
assert!(should_apply_network_block(&PermissionProfile::read_only()));	1
TurnPermissionsOverride::LegacySandbox(PermissionProfile::workspace_write()),	1
let output = match Command::new(system_bwrap_path).arg("--help").output() {	1
sandbox_policy: codex_app_server_protocol::SandboxPolicy::ReadOnly {	2
/// and only tighten with seccomp after the filesystem view is established.	1
NetworkSandboxPolicy::Enabled,	2
FileSystemSandboxKind::ExternalSandbox => SandboxPolicy::ExternalSandbox {	1
use crate::app_server_session::UnsupportedLegacyPermissionProfile;	1
pub fn to_core(&self) -> codex_protocol::protocol::SandboxPolicy {	1
pub sandbox_policy: SandboxPolicy,	3
PermissionProfile::Disabled => agent_config	1
use codex_protocol::permissions::FileSystemSandboxPolicyContext;	1
"failed to unregister synthetic bubblewrap mount target {}: {err}",	1
let additional_permissions = AdditionalPermissionProfile {	3
pub(super) active_permission_profile: Option<ActivePermissionProfile>,	1
"landlock",	1
/// 2. Apply in-process restrictions (no_new_privs + seccomp).	1
fn install_network_seccomp_filter_on_current_thread(	1
if network_seccomp_mode.is_some()	1
if let Some(mode) = network_seccomp_mode {	1
.map(|profile| PermissionProfileSummary {	1
parent_permission_profile: &PermissionProfile,	1
use_legacy_landlock: config.features.use_legacy_landlock(),	1
PermissionProfile::from_runtime_permissions_with_enforcement(	2
fn helper_env_preserves_path_for_system_bwrap_discovery_without_leaking_secrets() {	1
- bubblewrap sources expected at codex-rs/vendor/bubblewrap (default)"#	1
ensure_inner_stage_mode_is_valid(apply_seccomp_then_exec, use_legacy_landlock);	1
active_permission_profile: Option<&ActivePermissionProfile>,	1
network: NetworkSandboxPolicy::Restricted,	4
pub mod seatbelt;	1
#[ts(rename = "FileSystemSandboxPolicy")]	1
pub permissions: &'a PermissionProfile,	1
use codex_protocol::models::ActivePermissionProfile as CoreActivePermissionProfile;	1
parent_permission_profile: PermissionProfile,	2
let err = serde_json::from_value::<SandboxPolicy>(json!({	2
/// Unlike [`FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd`], this	1
/// Internal route spec used for managed proxy routing in bwrap mode.	1
/// Build the bubblewrap flags (everything after `argv[0]`).	1
use codex_app_server_protocol::AdditionalPermissionProfile;	3
let glob_policy = FileSystemSandboxPolicy::restricted(	1
const MACOS_SEATBELT_NETWORK_POLICY: &str = include_str!("seatbelt_network_policy.sbpl");	1
codex_protocol::models::PermissionProfile::Managed { .. } => {	1
fn restricted_network_policy_always_installs_seccomp() {	1
append_empty_file_bind_data_args(bwrap_args, unreadable_root)	1
ActivePermissionProfile::read_only(),	3
fn create_bwrap_flags_full_filesystem(command: Vec<String>, options: BwrapOptions) -> BwrapArgs {	1
PermissionProfile::Managed { file_system, .. } => {	1
} else if !matches!(response.sandbox, SandboxPolicy::ReadOnly { .. }) {	1
authority: &PermissionProfile,	1
ActivePermissionProfile::new(":workspace"),	1
"--apply-seccomp-then-exec".to_string(),	1
let mut permission_profile = PermissionProfile::workspace_write();	1
.to_legacy_sandbox_policy(NetworkSandboxPolicy::Restricted, cwd.path())	3
//! analogous to the macOS seatbelt and Linux sandbox wrapper paths. The wrapper	1
network_policy: NetworkSandboxPolicy,	3
pub(super) use codex_app_server_protocol::AdditionalPermissionProfile as AppServerAdditionalPermissionProfile;	1
pub(crate) fn file_system_sandbox_policy(&self) -> FileSystemSandboxPolicy {	1
pub struct ResolvedPermissionProfile {	1
fn bwrap_network_mode(	1
matches!(permission_profile, PermissionProfile::Managed { .. })	1
Constrained::allow_any(PermissionProfile::read_only()),	1
"workspace-write" => Ok(SandboxPolicy::new_workspace_write_policy()),	1
assert!(FileSystemSandboxPolicy::matches_prepared_read_deny(	2
if status.ruleset == landlock::RulesetStatus::NotEnforced {	1
SeccompBackend(#[from] seccompiler::BackendError),	1
if let Err(err) = verify_digest(&bwrap_file, expected_sha256(), self.program.as_path()) {	1
file_system: FileSystemSandboxPolicy,	2
) -> CodexResult<crate::bwrap::BwrapArgs> {	2
program: AbsolutePathBuf::from_absolute_path(fake_bwrap_path).expect("absolute"),	1
fn remove_protected_create_target(target: &crate::bwrap::ProtectedCreateTarget) -> bool {	1
PermissionProfile::External { .. } => SandboxModeRequirement::ExternalSandbox,	1
let permission_profile = PermissionProfile::Managed {	7
close_fd_or_panic(read_fd, "close read end in bubblewrap child");	1
pub profiles: BTreeMap<String, PermissionProfileToml>,	1
| ExecPermissionProfile::External { .. } => false,	1
) -> Result<PermissionProfile, PermissionIntersectionError> {	1
agent_config.set_legacy_sandbox_policy(SandboxPolicy::WorkspaceWrite {	1
pub use permission_profile_selection::ResolvedPermissionProfileSelection;	1
append_mount_target_parent_dir_args(&mut bwrap_args.args, root, masking_root);	1
permissions: RequestPermissionProfile,	4
apply_seccomp_then_exec,	1
active_permission_profile: Option<ActivePermissionProfile>,	1
impl From<AdditionalPermissionProfile> for RequestPermissionProfile {	1
let profile = PermissionProfile::read_only();	2
&PermissionProfile::read_only(),	2
let fake_bwrap_path = temp_dir.path().join("bwrap");	1
Some(RuntimePermissionProfileOverride::from_config(&self.config));	2
PermissionProfile::from_legacy_sandbox_policy_for_cwd(&sandbox.to_core(), cwd)	2
SandboxPolicy::ReadOnly {	3
pub use codex_sandboxing::system_bwrap_warning;	1
permission_profile: PermissionProfileSnapshot::legacy(PermissionProfile::read_only()),	2
network: NetworkSandboxPolicy::Enabled,	2
sandbox_policy: SandboxPolicy::new_read_only_policy(),	1
panic!("failed to clear CLOEXEC for preserved bubblewrap file descriptor {fd}: {err}");	1
fn rejects_malformed_legacy_bubblewrap_fd_mounts() {	1
Self::Disabled => Ok(SandboxPolicy::DangerFullAccess),	1
permissions: codex_app_server_protocol::GrantedPermissionProfile {	1
fn bazel_bwrap_env_key_is_allowed(key: &str) -> bool {	1
use crate::models::PermissionProfileSnapshot;	1
let permission_profile: PermissionProfile = serde_json::from_value(legacy)?;	1
/// callers to construct a legacy [`SandboxPolicy`] first.	1
permission_profile: &'a PermissionProfile,	2
Self::SeatbeltUnavailable => write!(f, "seatbelt sandbox is only available on macOS"),	1
vec!["features.use_linux_sandbox_bwrap=true".to_string(),]	1
TurnPermissionsOverride::LegacySandbox(PermissionProfile::read_only()),	1
LandlockPathFd(error: landlock::PathFdError),	1
impl From<codex_protocol::protocol::SandboxPolicy> for SandboxPolicy {	1
impl From<LegacyPermissionProfile> for PermissionProfile {	1
PermissionProfile::Disabled | PermissionProfile::External { .. } => false,	1
/// Network policy modes for bubblewrap.	1
active_permission_profile: Option<codex_protocol::models::ActivePermissionProfile>,	2
serde_json::from_str::<PermissionProfile>(value)	1
if permission_profile == PermissionProfile::Disabled {	1
ActiveProfile(ActivePermissionProfile),	1
use codex_sandboxing::seatbelt::CreateSeatbeltCommandArgsParams;	1
codex_app_server_protocol::SandboxMode::DangerFullAccess => PermissionProfile::Disabled,	1
SandboxPolicy::ExternalSandbox { .. } => Vec::new(),	1
fn translates_multiple_fd_mounts_for_legacy_system_bubblewrap() {	1
//! - in-process restrictions (`no_new_privs` + seccomp), and	1
PermissionProfile::workspace_write_with(	3
use seatbelt::DenialLogger;	1
panic!("--apply-seccomp-then-exec is incompatible with --use-legacy-landlock");	1
fn from_sandbox_policy(file_system_sandbox_policy: &FileSystemSandboxPolicy) -> Self {	1
fn permission_profile(&self) -> PermissionProfile {	1
use_legacy_landlock,	3
PermissionProfile::Disabled => "danger-full-access",	1
let permissions = (!write_paths.is_empty()).then_some(AdditionalPermissionProfile {	1
PermissionProfile::from_runtime_permissions(&file_system_policy, network_policy);	1
use_legacy_landlock: sandbox_context.use_legacy_landlock,	1
&PermissionProfile::workspace_write()	1
bwrap_args.preserved_files.push(File::open("/dev/null")?);	1
// https://github.com/containers/bubblewrap/releases/tag/v0.9.0	1
if !should_install_network_seccomp(network_sandbox_policy, allow_network_for_proxy) {	1
profile_selection: Option<&PermissionProfileSelection>,	1
use codex_protocol::request_permissions::RequestPermissionProfile;	6
writable_roots: Option<Vec<WritableRoot>>,	2
preserve_deny_reads_from: Option<&FileSystemSandboxPolicy>,	1
prompt_permissions: Option<AdditionalPermissionProfile>,	1
BUILT_IN_READ_ONLY_PROFILE => Some(PermissionProfile::read_only()),	1
assert!(translate_legacy_bwrap_fd_mounts(&mut argv).is_err());	2
| Self::InvalidSandboxPolicyCwd { source, .. } => Some(source),	1
bwrap_bin=bwrap_bin,	1
permissions: AdditionalPermissionProfile,	2
for seatbelt::SandboxDenial { name, capability } in denials {	1
let requested_permissions = CoreRequestPermissionProfile {	4
r#"bubblewrap is not available in this build.	1
NetworkSandboxPolicy::Restricted	2
AdditionalPermissionProfile {	1
panic!("failed to reset bubblewrap signal handler for {signal}: {err}");	1
use codex_protocol::protocol::SandboxPolicy;	13
pub permission_profile: PermissionProfile,	14
if apply_seccomp_then_exec {	1
/// Create a restricted token that includes all provided capability SIDs.	2
output_dir / "bwrap" if spec.is_linux else None,	1
codex-resources/bwrap binary was found next to the Codex executable"	1
PermissionProfile::Managed {	1
pub struct PermissionProfileCatalogEntry {	1
println!("cargo:rustc-check-cfg=cfg(bwrap_available)");	1
Ok(seatbelt_args)	1
pub(crate) additional_permissions: Option<AdditionalPermissionProfile>,	2
/// Installs a seccomp filter for Linux network sandboxing.	1
PermissionProfile::Managed { .. } => {	1
* with bwrap path arguments. Binding the symlink's current target would	1
let policy = FileSystemSandboxPolicy::read_only();	1
PermissionProfile::from_runtime_permissions_with_enforcement(	3
executable_files.append(Path("codex-resources") / "bwrap")	1
bwrap_args.args.push("--ro-bind-data".to_string());	1
active_permission_profile: ActivePermissionProfile,	4
PermissionProfile::Managed { file_system, .. } => {	2
let permission_profile = PermissionProfile::read_only();	5
use seccompiler::TargetArch;	1
let PermissionProfileListParams { cursor, limit, cwd } = params;	1
use codex_protocol::models::ActivePermissionProfile;	18
permissions: RequestPermissionProfile::default(),	2
find_system_bwrap_in_search_paths(std::env::split_paths(&search_path), &cwd)	1
impl From<&SandboxPolicy> for NetworkSandboxPolicy {	1
fn from(value: CoreAdditionalPermissionProfile) -> Self {	1
PermissionProfileSnapshot::legacy(constrained_permission_profile.get().clone());	1
SandboxPolicy::ExternalSandbox { .. } => FileSystemSandboxPolicy::external_sandbox(),	1
use_legacy_landlock: attempt.use_legacy_landlock,	2
pub struct AdditionalPermissionProfile {	2
"features.use_legacy_landlock",	1
fn parse_legacy_sandbox_policy(value: &str) -> serde_json::Result<SandboxPolicy> {	1
let (policy, params) = build_seatbelt_access_policy(	1
GrantedPermissionProfile {	1
ResolvedPermissionProfile {	1
fn preferred_bwrap_launcher() -> BubblewrapLauncher {	1
fn try_from(value: GrantedPermissionProfile) -> Result<Self, Self::Error> {	1
impl PermissionProfileSnapshot {	1
let signal_forwarders = install_bwrap_signal_forwarders(command_pid);	1
fn full_network_without_managed_proxy_skips_network_seccomp_mode() {	1
"bwrap".to_string(),	3
pub(crate) fn create_seatbelt_command_args_with_profile(	1
if apply_landlock_fs && !file_system_sandbox_policy.has_full_disk_write_access() {	1
Some(AbsolutePathBuf::from_absolute_path(&expected_bwrap).expect("absolute"))	4
pub active_permission_profile: ActivePermissionProfile,	1
/*apply_landlock_fs*/ false,	2
/// explicit so bubblewrap can preserve the caller's logical cwd when that	1
pub struct PermissionProfileListParams {	1
SandboxModeRequirement::DangerFullAccess => PermissionProfile::Disabled,	1
let workspace_profile = PermissionProfile::workspace_write();	1
pub struct RawFileSystemSandboxPolicy {	1
#[cfg(all(target_os = "linux", bwrap_available))]	1
fn from(value: CoreRequestPermissionProfile) -> Self {	1
RuntimePermissionProfileTurnOverride::LegacySandbox	1
use crate::landlock::CODEX_LINUX_SANDBOX_ARG0;	1
fn run_or_exec_bwrap(bwrap_args: crate::bwrap::BwrapArgs) -> ! {	1
// System bwrap runs across an exec boundary, so preserved fds must survive exec.	1
self.get_writable_roots_with_cwd_impl(cwd, WritableRootPathResolution::Effective)	1
.map(|(id, permission_profile)| PermissionProfileCatalogEntry {	1
fn sorted_writable_roots(roots: Vec<WritableRoot>) -> Vec<(PathBuf, Vec<PathBuf>)> {	1
Some(RuntimePermissionProfileOverride::from_config(&self.config));	1
PermissionProfile::External { .. } => {	1
NormalizedWritableRoot::Literal(root) => (root, SeatbeltPathMatch::Literal),	1
SandboxPolicy::ExternalSandbox { .. } => {	1
fn system_bwrap_launcher_for_path_with_probe(	1
&& permission_profile == &PermissionProfile::Disabled	1
fn normalize_profile_network_domains(profile: &mut PermissionProfileToml) {	1
pub use debug_sandbox::run_command_under_seatbelt;	1
use codex_protocol::permissions::RawFileSystemSandboxPolicy;	1
if let ExecPermissionProfile::Managed { network, .. } = &mut context.permissions {	1
let mut policy = FileSystemSandboxPolicy::restricted(value.entries.clone());	1
pub enum SandboxPolicy {	2
params: v2::PermissionProfileListParams,	1
if !target.should_remove_after_bwrap(&metadata) {	1
) -> Vec<WritableRoot> {	2
PermissionProfile::Disabled => SandboxModeRequirement::DangerFullAccess,	1
pub entries: BTreeMap<String, PermissionProfileToml>,	1
// Another concurrent bwrap setup can leave an empty mount target at	1
panic!("failed to fork for bubblewrap: {err}");	2
if is_wsl1 && requires_bubblewrap {	1
_permission_profile: &PermissionProfile,	2
fn managed_proxy_routes_use_proxy_routed_seccomp_mode() {	1
SandboxPolicy::DangerFullAccess => FileSystemSandboxPolicy::unrestricted(),	1
FileSystemSandboxPolicy::matches_prepared_read_deny(	1
fn build_bwrap_argv(	1
PermissionProfile::workspace_write_with(	1
build_bwrap: bool,	1
SandboxPolicy::ReadOnly { .. } => SandboxMode::ReadOnly,	1
bwrap_args.args.push("--remount-ro".to_string());	1
) -> Result<PermissionProfileListResponse, JSONRPCErrorError> {	1
assert_eq!(usages[0].feature, Feature::UseLegacyLandlock);	1
let summary = summarize_sandbox_policy(&SandboxPolicy::ExternalSandbox {	2
let candidate = PermissionProfileSnapshot::legacy(permission_profile.clone());	1
append_existing_empty_file_bind_data_args(bwrap_args, subpath, &metadata)?;	1
use codex_core_api::PermissionProfile;	1
#[arg(long = "apply-seccomp-then-exec", hide = true, default_value_t = false)]	1
permission_profile: PermissionProfile,	11
let policy = FileSystemSandboxPolicy::restricted(vec![unreadable_glob_entry(pattern)]);	1
pub fn sandbox_policy(&self) -> SandboxPolicy {	1
impl FromStr for FileSystemSandboxPolicy {	1
managed_deny_read_policy: Option<Arc<FileSystemSandboxPolicy>>,	1
NetworkSandboxPolicy::Restricted	1
fn finds_legacy_standalone_bundled_bwrap_next_to_exe_resources() {	1
let fake_bwrap_path = fake_bwrap.path();	2
install_network_seccomp_filter_on_current_thread(mode)?;	1
) -> std::io::Result<PermissionProfileToml> {	1
pub fn get_writable_roots_with_cwd(&self, cwd: &Path) -> Vec<WritableRoot> {	2
/// Internal: apply seccomp and `no_new_privs` in the already-sandboxed	1
SandboxPolicy::ExternalSandbox {	2
// Request a user namespace explicitly rather than relying on bubblewrap's	1
let policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {	18
PermissionProfileDe::Tagged(tagged) => tagged.into(),	1
bwrap_args.args.push("--remount-ro".to_string());	1
impl SandboxPolicy {	2
crate::bwrap::SyntheticMountTargetKind::EmptyFile => match fs::remove_file(path) {	1
EscalationPermissions::AdditionalPermissionProfile(permission_profile),	1
FileSystemSandboxPolicy::restricted(requested_file_system.entries.clone());	1
/// value is "seatbelt" for macOS, but it may change in the future to	1
export type { AdditionalPermissionProfile } from "./AdditionalPermissionProfile";	1
let v2_policy = SandboxPolicy::ReadOnly {	1
protected_create_targets: bwrap_args.protected_create_targets,	1
FileSystemSandboxPolicy::from(&policy),	1
PermissionProfile::workspace_write_with(	1
.define("main", Some("bwrap_main"));	1
// paths inside bwrap, such as Bazel runfiles helper binaries.	1
SandboxPolicy::DangerFullAccess => Self::Disabled,	1
id: Feature::UseLegacyLandlock,	1
resolve_windows_restricted_token_filesystem_overrides(	1
crate::bwrap::SyntheticMountTargetKind::EmptyFile => {	1
) -> std::io::Result<Vec<PermissionProfileCatalogEntry>> {	2
/// Build the bubblewrap filesystem mounts for a given filesystem policy.	1
use crate::bwrap::create_bwrap_command_args;	1
panic!("bwrap is only supported on Linux");	1
let back_to_v2 = SandboxPolicy::from(core_policy);	3
DangerFullAccessSandboxPolicy,	1
PermissionProfile::from_legacy_sandbox_policy_for_cwd(	2
pub(crate) fn should_remove_after_bwrap(&self, metadata: &Metadata) -> bool {	1
export type { PermissionProfileSummary } from "./PermissionProfileSummary";	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(sandbox_policy, cwd);	1
pub(super) fn emit_system_bwrap_warning(app_event_tx: &AppEventSender, config: &Config) {	1
WritableRoot {	1
/// Enable Windows sandbox (restricted token) on Windows.	1
UpdateActivePermissionProfile(ActivePermissionProfile),	1
let profile: PermissionProfile = PermissionProfile::Managed {	2
Some(RuntimePermissionProfileOverride::from_config(&self.config));	1
"permission profiles requiring direct runtime enforcement are incompatible with --use-legacy-landlock"	1
FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {	4
SandboxType::MacosSeatbelt => "seatbelt",	1
if use_legacy_landlock && !allow_network_for_proxy {	2
PermissionProfileSnapshot::legacy(PermissionProfile::read_only());	1
pub use bwrap::find_system_bwrap_in_path;	1
let scoped = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry::new(	1
use crate::models::AdditionalPermissionProfile;	2
additional_permissions: &AdditionalPermissionProfile,	2
impl From<CoreRequestPermissionProfile> for RequestPermissionProfile {	1
) -> PermissionProfile {	4
// TurnEnvironment::sandbox_context instead of the runtime-wide Landlock value.	1
permissions: &'a RequestPermissionProfile,	1
PermissionProfile::from_runtime_permissions(	1
"Optional prebuilt Linux bwrap executable. If omitted for Linux "	1
pub permissions: ExecPermissionProfile,	1
install_filesystem_landlock_rules_on_current_thread(writable_roots)?;	1
PermissionProfileSnapshot::legacy(PermissionProfile::Disabled);	2
codex_protocol::protocol::SandboxPolicy::ExternalSandbox {	1
seatbelt_args.push("--".to_string());	1
"activePermissionProfile": null,	1
assert_eq!(parsed[0].0.as_str(), "features.use_legacy_landlock");	1
append_read_only_subpath_args(&mut bwrap_args, &subpath, &allowed_write_paths)?;	1
use codex_sandboxing::find_system_bwrap_in_path;	1
SandboxPolicy::DangerFullAccess	2
use crate::protocol::SandboxPolicy;	2
let without_home = FileSystemSandboxPolicyContext {	1
use crate::launcher::preferred_bwrap_supports_argv0;	1
use_legacy_landlock,	1
FileSystemSandboxPolicy::unrestricted(),	1
Some(codex_app_server_protocol::SandboxPolicy::WorkspaceWrite {	1
impl FromStr for SandboxPolicy {	1
PermissionProfile::External { .. } => None,	2
return Ok(PermissionProfile::from_runtime_permissions(	3
let file_system = FileSystemSandboxPolicy::workspace_write(	1
"targets, bwrap is built with Cargo."	1
&FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(sandbox_policy, cwd),	1
use crate::landlock::apply_permission_profile_to_current_thread;	1
/// Use the legacy Landlock Linux sandbox fallback instead of the default	1
if !apply_seccomp_then_exec && !verify_fd_mounts.is_empty() {	1
network: NetworkSandboxPolicy,	6
let permission_profile = PermissionProfile::workspace_write();	3
file_system_sandbox_policy: &FileSystemSandboxPolicy,	20
PermissionProfileSelection {	1
CoreRequestPermissionProfile::default()	1
InvalidSandboxPolicyCwd {	1
return Ok(NormalizedWritableRoot::Subpath(normalized));	1
// Outer stage: bubblewrap first, then re-enter this binary in the	1
&fake_bwrap_path,	1
fn ensure_linux_bubblewrap_is_supported(	1
LandlockSandboxExecutableNotProvided,	1
let mut policy = FileSystemSandboxPolicy::restricted(vec![unreadable_glob_entry(	1
.bundled_resource("bwrap")	1
use seccompiler::apply_filter;	1
codex_core::config::system_bwrap_warning(config.permissions.permission_profile())	1
fn deny_policy(path: &Path) -> FileSystemSandboxPolicy {	1
LandlockRuleset(#[from] landlock::RulesetError),	1
codex_protocol::models::PermissionProfile::workspace_write(),	1
PermissionProfile {	1
#[cfg(all(target_os = "linux", not(bwrap_available)))]	1
permissions: V2GrantedPermissionProfile::default(),	1
"Codex's Linux sandbox uses bubblewrap and needs access to create user namespaces.";	1
PermissionProfile::from_runtime_permissions(	2
sandbox: v2::SandboxPolicy::DangerFullAccess,	1
let restricted = SandboxPolicy::ExternalSandbox {	1
fn ignores_system_bwrap_when_system_bwrap_lacks_perms() {	1
system_bwrap_warning_for_path(system_bwrap_path.as_deref())	1
fn canonicalizes_use_legacy_landlock_alias() {	1
system_bwrap_launcher_for_path_with_probe(fake_bwrap_path, |_| {	2
let file_system = FileSystemSandboxPolicy::read_only();	1
&& let Some(launcher) = system_bwrap_launcher_for_path(&path)	1
//! This mirrors the variants of [`codex_protocol::protocol::SandboxPolicy`], but	1
let legacy_policy = SandboxPolicy::WorkspaceWrite {	3
pub async fn run_command_under_landlock(	1
"external-sandbox" => Ok(SandboxPolicy::ExternalSandbox {	1
pub struct ResolvedPermissionProfileSelection<'a> {	1
use codex_protocol::permissions::NetworkSandboxPolicy;	1
Some(AdditionalPermissionProfile {	1
SandboxModeRequirement::ExternalSandbox => PermissionProfile::External {	1
F: FnMut(&str) -> Option<PermissionProfileToml>,	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_preserving_deny_entries(	1
use crate::permissions::FileSystemSandboxPolicy;	2
&FileSystemSandboxPolicy::unrestricted(),	5
PermissionProfile::External { .. } => FileSystemPermissionProfileContext::External,	1
SeccompInstall(#[from] seccompiler::Error),	1
SandboxPolicy::DangerFullAccess => Vec::new(),	1
impl From<CoreAdditionalPermissionProfile> for AdditionalPermissionProfile {	1
argv.extend(bwrap_args.args);	1
fn use_legacy_landlock_config_records_deprecation_notice() {	1
(None, Some(sandbox_policy)) => PermissionProfile::from_legacy_sandbox_policy_for_cwd(	1
impl From<&SandboxPolicy> for FileSystemSandboxPolicy {	1
pub(super) fn permission_profile(&self) -> PermissionProfile {	1
permissions: &RequestPermissionProfile,	1
NetworkSandboxPolicy::Restricted	4
bwrap_bin=source_outputs.bwrap_bin,	1
pub file_system_sandbox_policy: Option<RawFileSystemSandboxPolicy>,	1
params: PermissionProfileListParams,	2
let permissions = PermissionProfile::from_runtime_permissions(	1
fn ignores_system_bwrap_when_system_bwrap_is_missing() {	1
effective_permission_profile: PermissionProfile,	1
let effective_permission_profile = PermissionProfile::from_runtime_permissions_with_enforcement(	1
use codex_config::permissions_toml::PermissionProfileToml;	2
"codex-bwrap-synthetic-mount-targets-{effective_uid}"	1
use_legacy_landlock: prepared_call.config().use_legacy_landlock,	1
if !system_bwrap_has_user_namespace_access(system_bwrap_path, SYSTEM_BWRAP_PROBE_TIMEOUT) {	1
use codex_protocol::models::PermissionProfile;	1
use crate::seatbelt::MACOS_PATH_TO_SEATBELT_EXECUTABLE;	1
required_files.append(Path("codex-resources") / "bwrap")	1
permissions: CoreRequestPermissionProfile::default(),	2
return Err(CodexErr::Sandbox(SandboxErr::LandlockRestrict));	1
/// produced the active `PermissionProfile`.	1
// bubblewrap added `--argv0` in v0.9.0:	1
WritableRoot {	1
bwrap_args: &mut BwrapArgs,	6
PermissionProfileSnapshot::active_with_profile_workspace_roots(	2
use codex_protocol::protocol::FileSystemSandboxPolicy;	1
/// Options that control how bubblewrap is invoked.	1
export type { RequestPermissionProfile } from "./RequestPermissionProfile";	1
codex_protocol::permissions::NetworkSandboxPolicy::Restricted,	1
Ok(NormalizedWritableRoot::Literal(normalized))	1
pub(crate) permission_profile: PermissionProfile,	2
builder.sandbox_policy = SandboxPolicy::new_read_only_policy();	1
panic!("failed to set bubblewrap child parent-death signal: {err}");	1
) -> io::Result<(FileSystemSandboxPolicy, NetworkSandboxPolicy)> {	2
PermissionProfileSnapshot::legacy(environment_permission_profile);	1
#[experimental("thread/resume.activePermissionProfile")]	1
filtered.contains(r#"import type { SandboxPolicy } from "./SandboxPolicy";"#),	1
outputs.bwrap_bin,	1
let native_permissions: PermissionProfile =	1
CodexErr::UnsupportedOperation(crate::bwrap::WSL1_BWRAP_WARNING.to_string())	1
use crate::bwrap::BwrapNetworkMode;	1
pub use_legacy_landlock: bool,	7
use landlock::Compatible;	1
fn from(value: codex_protocol::protocol::SandboxPolicy) -> Self {	1
pub fn system_bwrap_warning(	1
PermissionProfile::read_only()	3
pub use windows::resolve_windows_restricted_token_filesystem_overrides;	1
targets: &[crate::bwrap::ProtectedCreateTarget],	1
PermissionProfileDe::Legacy(legacy) => legacy.into(),	1
Some(FileSystemSandboxPolicyContext {	1
let describe_profile = |profile: &PermissionProfile| {	1
Ok(SandboxPolicy::WorkspaceWrite {	1
FileSystemSandboxPolicy::from(&legacy_policy)	2
.expect("bwrap fs args");	1
fn seatbelt_regex_for_unreadable_glob(pattern: &str) -> Option<String> {	1
fn denied_reads_text(file_system_policy: &FileSystemSandboxPolicy, cwd: &Path) -> Option<String> {	1
#define PACKAGE_STRING "bubblewrap built for Codex"	2
fn current_permission_profile(&self) -> PermissionProfile {	1
PermissionProfileSnapshot::from_session_snapshot(	2
use codex_protocol::permissions::FileSystemSandboxPolicy;	6
append_missing_empty_file_bind_data_args(bwrap_args, path)	1
fn ensure_legacy_landlock_mode_supports_policy(	1
Self::External { .. } => FileSystemSandboxPolicy::external_sandbox(),	1
active_permission_profile: ActivePermissionProfile::new(	3
seatbelt_protected_metadata_name_regex(&root, &metadata_name).replace('"', "\\\"");	1
Self::Unrestricted => FileSystemSandboxPolicy::unrestricted(),	1
ReadOnlySandboxPolicy,	1
seatbelt_profile: MacosSeatbeltProfile::FileSystemHelper,	1
fn helper_env_preserves_windows_path_key_for_system_bwrap_discovery() {	1
sandbox_policy: Option<SandboxPolicy>,	1
codex_app_server_protocol::SandboxMode::ReadOnly => PermissionProfile::read_only(),	1
targets: &[crate::bwrap::SyntheticMountTarget],	1
PermissionProfile::Disabled,	1
let policy = FileSystemSandboxPolicy::restricted(vec![unreadable_glob_entry(	5
PermissionProfile::External { .. } => "external-sandbox",	1
use crate::permissions::NetworkSandboxPolicy;	2
} => codex_protocol::protocol::SandboxPolicy::WorkspaceWrite {	1
SandboxPolicy::WorkspaceWrite {	1
.field("use_legacy_landlock", &self.use_legacy_landlock)	1
system_bwrap_path.display()	1
Some(AdditionalPermissionProfile {	1
sandbox: SandboxPolicy::DangerFullAccess,	1
use codex_protocol::permissions::NetworkSandboxPolicy;	20
Landlock,	1
/// Removed legacy Linux bubblewrap opt-in flag retained as a no-op so old	1
ActivePermissionProfile::new(BUILT_IN_PERMISSION_PROFILE_WORKSPACE),	5
&codex_protocol::protocol::SandboxPolicy::new_workspace_write_policy(),	1
impl From<&FileSystemPermissions> for FileSystemSandboxPolicy {	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(&legacy_policy, cwd.path());	1
let permission_profile = PermissionProfile::from_runtime_permissions_with_enforcement(	6
impl Default for PermissionProfile {	1
ActivePermissionProfile::new(BUILT_IN_PERMISSION_PROFILE_WORKSPACE);	3
/// Exit status returned when bundled bubblewrap fails digest verification.	1
codex_process_hardening::disable_process_dumping()	1
PermissionProfile::Managed {	3
if !matches!(permission_profile, PermissionProfile::Disabled)	1
pub exec_server_permissions: &'a codex_protocol::models::PermissionProfile,	1
crate::bwrap::SyntheticMountTarget::missing_empty_directory(	1
/// Resolve the bubblewrap source directory used for build-time compilation.	1
file_system_sandbox_policy: &mut FileSystemSandboxPolicy,	1
FileSystemSandboxPolicy::restricted(expected_entries)	1
mod seatbelt;	1
.needs_direct_runtime_enforcement(NetworkSandboxPolicy::Restricted, cwd.path())	1
&PermissionProfile::read_only(),	1
use codex_shell_escalation::ResolvedPermissionProfile;	1
pub use windows::unsupported_windows_restricted_token_sandbox_reason;	1
|| (!use_legacy_landlock && !file_system_sandbox_policy.has_full_disk_write_access());	1
use codex_app_server_protocol::PermissionProfileListResponse;	1
build.compile("standalone_bwrap");	1
&SandboxPolicy::new_workspace_write_policy(),	2
fn finds_package_layout_bwrap_from_install_context() {	1
"failed to read bundled bubblewrap {} for digest verification: {err}",	1
serde_json::from_str::<RawFileSystemSandboxPolicy>(s)?	1
) -> SandboxPolicy {	2
"Codex could not find bubblewrap on PATH. ",	1
permission_profile: Constrained<PermissionProfileSnapshot>,	1
SandboxPolicyDeserialize::DangerFullAccess => Ok(SandboxPolicy::DangerFullAccess),	1
let request = CoreRequestPermissionProfile::try_from(request)	2
params.additional_permissions = Some(AdditionalPermissionProfile {	1
(FileSystemSandboxViolationReason::PolicyDenied, "seccomp"),	1
use crate::landlock::allow_network_for_proxy;	1
fn parse_permission_profile(value: &str) -> std::result::Result<PermissionProfile, String> {	1
fn permission_profile_allows_network_approval_flow(permission_profile: &PermissionProfile) -> bool {	1
pub fn from_permission_profile(permissions: PermissionProfile) -> Self {	1
key: "use_legacy_landlock",	1
append_empty_directory_args(bwrap_args, path);	1
runtime_permission_profile_override: Option<RuntimePermissionProfileOverride>,	1
let context = FileSystemSandboxPolicyContext {	1
network: codex_protocol::permissions::NetworkSandboxPolicy::Restricted,	1
pub struct RequestPermissionProfile {	2
pub(crate) struct UnsupportedLegacyPermissionProfile;	1
create_bwrap_flags(	1
// rules should keep their normal bwrap behavior, which can mask	1
use crate::launcher::exec_bwrap;	1
fn remove_synthetic_mount_target(target: &crate::bwrap::SyntheticMountTarget) {	1
// legacy Landlock filesystem pipeline.	1
.map_err(|err| format!("failed to clone bundled bubblewrap fd: {err}"))?;	1
fn network_access_from_policy(network_policy: NetworkSandboxPolicy) -> NetworkAccess {	1
pub use windows::permission_profile_supports_windows_restricted_token_sandbox;	1
|| (apply_landlock_fs && !file_system_sandbox_policy.has_full_disk_write_access())	1
// the denied parent read-only. Otherwise bubblewrap cannot mkdir the	1
impl ActivePermissionProfile {	2
pub fn try_from_permission_profile(permission_profile: &PermissionProfile) -> Result<Self> {	1
use super::RequestPermissionProfile;	1
LandlockSandboxExecutableNotProvided,	1
pub permissions: RequestPermissionProfile,	6
FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry::new(	1
NetworkSandboxPolicy::Enabled,	5
fn network_permissions() -> AdditionalPermissionProfile {	1
SandboxPolicy::ExternalSandbox { network_access } => {	1
permission_profile.ok_or(ResolvePermissionProfileError::MissingConfiguration)?;	1
let crate::bwrap::BwrapArgs {	2
file_system_policy: FileSystemSandboxPolicy,	1
PermissionProfile::Disabled	2
None => PermissionProfile::workspace_write(),	1
.set_permission_profile(PermissionProfile::Disabled)	1
let permission_profile = AdditionalPermissionProfile {	1
if matches!(permission_profile, PermissionProfile::Disabled)	1
PermissionProfile::Managed { .. }	2
use_legacy_landlock: req.turn_environment.config().use_legacy_landlock,	1
translate_legacy_bwrap_fd_mounts(&mut argv).expect("fd mounts should translate");	1
sandbox_policy: SandboxPolicy::new_read_only_policy(),	2
copy_executable(inputs.bwrap_bin, resources_dir / "bwrap", is_windows=False)	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_preserving_deny_entries(	1
Set CODEX_BWRAP_SOURCE_DIR to an existing checkout or vendor bubblewrap under codex-rs/vendor.",	1
use landlock::Access;	1
args.bwrap_bin,	1
sandbox_policy: Option<codex_app_server_protocol::SandboxPolicy>,	1
codex_protocol::permissions::NetworkSandboxPolicy::Restricted,	1
pub apply_seccomp_then_exec: bool,	1
pub struct ActivePermissionProfile {	2
use crate::permissions::NetworkSandboxPolicy;	1
codex_cli::run_command_under_seatbelt(	1
let system_bwrap_path = match AbsolutePathBuf::from_absolute_path(system_bwrap_path) {	1
use codex_protocol::models::AdditionalPermissionProfile as CoreAdditionalPermissionProfile;	3
&mut bwrap_args.args,	1
pub use codex_protocol::models::PermissionProfileSnapshot;	2
serde_json::from_value::<PermissionProfile>(serde_json::to_value(	1
NetworkSandboxPolicy::Restricted	1
panic!("failed to read fd flags for preserved bubblewrap file descriptor {fd}: {err}");	1
PermissionProfile::Managed { .. }	2
bwrap_args.args.push("--tmpfs".to_string());	1
std::fs::set_permissions(&fake_bwrap_path, std::fs::Permissions::from_mode(0o755))	1
&FileSystemSandboxPolicy::external_sandbox(),	1
panic!("failed to install bubblewrap signal forwarder for {signal}: {err}");	1
profile_selection: Option<PermissionProfileSelection>,	12
file_system = FileSystemSandboxPolicy::read_only();	1
let policy = FileSystemSandboxPolicy::restricted(vec![unreadable_glob_entry(format!(	3
type HostSandboxArgs = codex_cli::LandlockCommand;	1
fn current_active_permission_profile(&self) -> Option<ActivePermissionProfile> {	1
| PermissionProfile::External { .. } => PATCH_REJECTED_OUTSIDE_PROJECT_REASON,	1
turn_override: RuntimePermissionProfileTurnOverride::Preserve,	1
"metadata-name protections are outside the legacy SandboxPolicy writable-root contract"	1
panic!("failed to read bubblewrap stderr: {err}");	1
pub(crate) fn permission_profile(&self) -> PermissionProfile {	1
SandboxPolicy::WorkspaceWrite {	5
Ok(ResolvedPermissionProfileSelection {	1
pub fn to_runtime_permissions(&self) -> (FileSystemSandboxPolicy, NetworkSandboxPolicy) {	1
additional_permissions: Option<AdditionalPermissionProfile>,	6
.unwrap_or_else(|err| exit_with_bwrap_build_error(err));	1
permission_profile: PermissionProfileSnapshot::legacy(	1
.unwrap_or_else(|err| exit_with_bwrap_build_error(err))	1
impl From<NetworkSandboxPolicy> for NetworkPermissions {	1
&codex_protocol::permissions::FileSystemSandboxPolicy::restricted(Vec::new()),	1
SandboxPolicyDeserialize::WorkspaceWrite {	1
file_system_policy: &mut FileSystemSandboxPolicy,	1
sandbox_policy: SandboxPolicy::DangerFullAccess,	1
parent_permission_profile: PermissionProfile,	1
fn from(value: &SandboxPolicy) -> Self {	2
append_empty_directory_args(bwrap_args, path);	1
let args = create_bwrap_command_args(	4
let sandbox_policy = FileSystemSandboxPolicy::workspace_write(	1
write_executable(&expected_bwrap);	4
ActivePermissionProfile::read_only(),	2
pub fn unsupported_windows_restricted_token_sandbox_reason(	1
fn profile_has_managed_filesystem_restrictions(permission_profile: &PermissionProfile) -> bool {	1
use codex_app_server_protocol::GrantedPermissionProfile as V2GrantedPermissionProfile;	1
use crate::legacy_core::config::PermissionProfileSnapshot;	4
let permissions = PermissionProfile::from_runtime_permissions_with_enforcement(	1
sandbox_policy: &SandboxPolicy,	3
pub struct PermissionProfileToml {	1
"failed to open bundled bubblewrap {}: {err}",	1
"--apply-seccomp-then-exec".to_string(),	2
fn set_no_new_privs() -> Result<()> {	1
.set_permission_profile(PermissionProfile::Managed {	2
permission_profile: FileSystemPermissionProfileContext,	1
matches!(permission_profile, PermissionProfile::Managed { .. })	2
pub fn legacy_sandbox_policy(&self, cwd: &Path) -> SandboxPolicy {	1
| error @ SandboxTransformError::InvalidSandboxPolicyCwd { .. } => {	1
fn try_from(policy: RawFileSystemSandboxPolicy) -> Result<Self, Self::Error> {	1
.downcast_ref::<UnsupportedLegacyPermissionProfile>()	1
let writable = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {	1
crate::bwrap::SyntheticMountTargetKind::EmptyDirectory => {	1
pub(super) fn active_permission_profile(&self) -> Option<ActivePermissionProfile> {	1
let sandbox = PermissionProfile::read_only()	1
use codex_protocol::request_permissions::RequestPermissionProfile;	1
AdditionalPermissionProfile(AdditionalPermissionProfile),	1
pub(crate) fn permission_profile_with_workspace_roots(&self) -> PermissionProfile {	1
codex_protocol::protocol::SandboxPolicy::DangerFullAccess	2
pub fn resolve_windows_restricted_token_filesystem_overrides(	1
let args = create_seatbelt_command_args(CreateSeatbeltCommandArgsParams {	1
.map_err(|source| PermissionProfileResolutionError::DeserializeProfileToml { source })	1
AdditionalPermissionProfile {	3
fn system_bwrap_warning_for_path(system_bwrap_path: Option<&Path>) -> Option<String> {	1
pub(crate) fn exec_bwrap(mut argv: Vec<String>, preserved_files: Vec<File>) -> ! {	1
use codex_protocol::models::ActivePermissionProfile;	2
use seccompiler::SeccompRule;	1
use codex_sandboxing::permission_profile_supports_windows_restricted_token_sandbox;	1
use crate::config::PermissionProfileSnapshot;	3
bwrap_args.args.push("--perms".to_string());	1
pub(crate) permission_profile: &'a PermissionProfile,	1
/// When not set, the helper uses the default bubblewrap pipeline.	1
"prebuilt Linux bwrap executable",	1
eprintln!("error building bubblewrap command: {err}");	1
fn from(value: PermissionProfile) -> Self {	1
&& matches!(requested, PermissionProfile::Disabled)	1
.can_set(&PermissionProfile::Disabled),	4
fn sandbox_policy_allows_write(policy: &SandboxPolicy, path: &Path, cwd: &Path) -> bool {	1
translate_legacy_bwrap_fd_mounts(&mut argv)	1
fn file_system_permissions(path: &std::path::Path) -> AdditionalPermissionProfile {	1
&mut bwrap_args,	1
pub struct PermissionProfileListResponse {	1
.set_permission_profile(PermissionProfile::Disabled),	1
fn ensure_inner_stage_mode_is_valid(apply_seccomp_then_exec: bool, use_legacy_landlock: bool) {	1
use codex_sandboxing::seatbelt::create_seatbelt_command_args;	1
CoreRequestPermissionProfile {	1
&FileSystemSandboxPolicy::from(sandbox_policy),	1
enum WritableRootPathResolution {	1
/// server-authored `PermissionProfile`, so it must not reuse the cached primary	1
let permission_profile = PermissionProfile::workspace_write_with(	1
profile: PermissionProfile,	1
fn try_from(value: AdditionalPermissionProfile) -> Result<Self, Self::Error> {	1
if matches!(profile, PermissionProfile::Disabled) {	1
use codex_sandboxing::landlock::CODEX_LINUX_SANDBOX_ARG0;	2
let (policy, params) = build_seatbelt_access_policy(	1
permission_profile: Option<PermissionProfile>,	1
impl NetworkSandboxPolicy {	1
permissions: &PermissionProfile,	1
let parent_permission_profile = PermissionProfile::workspace_write();	1
fn app_server_workspace_write_profile(network_enabled: bool) -> PermissionProfile {	1
SandboxMode::ReadOnly => PermissionProfile::read_only(),	1
enum PermissionProfileDe {	1
base_network_sandbox_policy: NetworkSandboxPolicy,	1
use_legacy_landlock: self.use_legacy_landlock,	2
use crate::resolve_windows_restricted_token_filesystem_overrides;	1
pub fn from_legacy_sandbox_policy(sandbox_policy: &SandboxPolicy) -> Self {	2
Tagged(TaggedPermissionProfile),	1
.can_set(&PermissionProfile::workspace_write()),	1
NetworkSandboxPolicy::from(sandbox_policy),	2
run_bwrap_with_proc_fallback(	1
use codex_app_server_protocol::PermissionProfileSummary;	1
/// 2. The vendored bubblewrap tree under `codex-rs/vendor/bubblewrap`.	1
pub fn use_legacy_landlock(&self) -> bool {	1
use codex_protocol::protocol::WritableRoot;	4
PermissionProfileState::from_constrained_snapshot(permission_profile, snapshot)?;	1
ResolvedPermissionProfile(ResolvedPermissionProfile),	1
permission_profile = PermissionProfile::from_runtime_permissions(&file_system, network);	1
impl From<ActivePermissionProfile> for CoreActivePermissionProfile {	1
None => PermissionProfileSnapshot::legacy(effective_permission_profile),	1
pub fn from_permission_profile_with_cwd(permissions: PermissionProfile, cwd: PathUri) -> Self {	1
PermissionProfileSnapshot::from_session_snapshot(	3
pub fn system_bwrap_warning(permission_profile: &PermissionProfile) -> Option<String> {	1
.unwrap_or_else(|| panic!("bubblewrap argv is missing command separator '--'"));	1
let permission_profile: PermissionProfile = PermissionProfile::Managed {	1
use crate::models::ActivePermissionProfile;	2
create_seatbelt_command_args(CreateSeatbeltCommandArgsParams {	1
"expected vendored bubblewrap at {}, but it was not found.\n\	1
///   under bubblewrap with `--proc /proc`.	1
fn restricted_token_rejects_managed_network_before_spawn() {	1
* masking the symlink's current target is a TOCTTOU snapshot: bwrap would	1
SandboxPolicy::DangerFullAccess	1
mod bwrap;	2
PermissionProfile::workspace_write_with(	3
Constrained::allow_any(PermissionProfile::read_only()),	3
SandboxPolicy::ExternalSandbox {	2
sandbox_policy: &SandboxPolicy,	2
permission_profile_constraint: Option<&crate::Constrained<PermissionProfile>>,	1
/// Error from linux seccomp filter setup	1
"features.use_legacy_landlock".to_string()	1
let file_system_policy = PermissionProfile::read_only()	1
bwrap_bin=resolve_output_path(	1
mut additional_permissions: AdditionalPermissionProfile,	1
"Codex will use the bundled bubblewrap in the meantime.",	1
fn exit_with_bwrap_build_error(err: codex_protocol::error::CodexErr) -> ! {	1
) -> NetworkSandboxPolicy {	2
let base_network_sandbox_policy = NetworkSandboxPolicy::Restricted;	1
"--bwrap-bin",	1
PermissionProfile::Disabled | PermissionProfile::External { .. } => true,	1
Ok(SandboxPolicy::ReadOnly { network_access })	1
codex_app_server_protocol::SandboxPolicy::DangerFullAccess	1
assert_eq!(event.permission_profile, PermissionProfile::read_only());	1
PermissionProfile::from_runtime_permissions_with_enforcement(	1
key: "use_linux_sandbox_bwrap",	1
permission_profile: Constrained<PermissionProfile>,	1
app.harness_overrides.permission_profile = Some(PermissionProfile::workspace_write());	1
SandboxPolicyDeserialize::ReadOnly {	1
} => FileSystemSandboxPolicy {	1
PermissionProfile::External { network } => agent_config	1
fn non_legacy_file_system_sandbox_policy(&self) -> Option<RawFileSystemSandboxPolicy> {	1
/// The helper performs the actual sandboxing (bubblewrap by default + seccomp)	1
// to legacy Landlock on failure.	1
resolve_windows_restricted_token_filesystem_overrides(	1
PermissionProfile::Disabled,	2
//! Filesystem restrictions are enforced by bubblewrap in `linux_run_main`.	1
NetworkSandboxPolicy::Enabled	2
struct RuntimePermissionProfileOverride {	1
use_legacy_landlock: sandbox_context.use_legacy_landlock,	1
bwrap_args.args.push(if writable_descendants.is_empty() {	1
let requires_bubblewrap = allow_network_for_proxy	1
} => SandboxPolicy::WorkspaceWrite {	1
PermissionProfile::External { network } => Self::External { network },	1
fn sandbox_policy_probe_paths(policy: &SandboxPolicy, cwd: &Path) -> Vec<PathBuf> {	1
EscalationPermissions::ResolvedPermissionProfile(	1
expected_permissions: EscalationPermissions::AdditionalPermissionProfile(	1
) -> PermissionProfile {	8
) -> Result<NormalizedWritableRoot, SeatbeltPreparationError> {	1
fn detects_fd_backed_read_only_mount_support_in_system_bwrap_help() {	1
fn system_bwrap_capabilities(system_bwrap_path: &Path) -> Option<SystemBwrapCapabilities> {	1
let permission_profile = PermissionProfile::Disabled;	1
pub struct GrantedPermissionProfile {	1
NetworkSandboxPolicy::from(&sandbox_policy),	1
if apply_seccomp_then_exec && use_legacy_landlock {	1
create_seatbelt_command_args_with_profile(args, MacosSeatbeltProfile::Process)	1
build_bwrap_argv(	1
PermissionProfile::read_only(),	3
fn from(value: TaggedPermissionProfile) -> Self {	1
// PermissionProfile carries the active network sandbox bit, not the configured	1
BUILT_IN_PERMISSION_PROFILE_DANGER_FULL_ACCESS => Some(PermissionProfile::Disabled),	1
"--bwrap-bin",	1
current_permission_profile: &PermissionProfile,	1
codex_protocol::protocol::SandboxPolicy::WorkspaceWrite { .. }	1
use codex_protocol::models::PermissionProfile;	23
fn finds_npm_bundled_bwrap_next_to_target_vendor_dir() {	1
use crate::request_permissions::RequestPermissionProfile;	1
use landlock::AccessFs;	1
) -> Option<AdditionalPermissionProfile> {	4
export type { ActivePermissionProfile } from "./ActivePermissionProfile";	1
let network_sandbox_policy = NetworkSandboxPolicy::from(&sandbox_policy);	1
/// Opt-in: use the legacy Landlock Linux sandbox fallback.	1
Feature::UseLegacyLandlock => {	1
PermissionProfile::External { .. } => "external_sandbox",	1
PermissionProfileSnapshot::legacy(read_only_permission_profile(	1
impl TryFrom<ExecPermissionProfile> for PermissionProfile {	1
fn try_from(policy: FileSystemSandboxPolicy) -> Result<Self, Self::Error> {	1
fn run_bwrap_with_proc_fallback(	1
exec_bwrap(args, preserved_files);	2
extern "C" fn forward_signal_to_bwrap_child(signal: libc::c_int) {	1
emit_system_bwrap_warning(&app_event_tx, &config);	1
permission_profile: &PermissionProfile,	49
#[path = "bwrap_tests.rs"]	1
let default_permission_profile = PermissionProfile::read_only();	1
permission_profile: PermissionProfile::workspace_write(),	3
fn translate_legacy_bwrap_fd_mounts(argv: &mut Vec<String>) -> Result<(), String> {	1
requested_permissions: RequestPermissionProfile,	1
prompt_permissions: Option<AdditionalPermissionProfile>,	1
fn from(value: LegacyPermissionProfile) -> Self {	1
SandboxModeRequirement::ReadOnly => PermissionProfile::read_only(),	1
let workspace_write_profile = PermissionProfile::workspace_write_with(	2
) -> SandboxPolicy {	1
BUILT_IN_DANGER_FULL_ACCESS_PROFILE => Some(PermissionProfile::Disabled),	1
let permissions: AdditionalPermissionProfile =	1
bwrap_bin=resolve_optional_input_path(	1
fn can_write_path(&self, path: &PathUri, context: &FileSystemSandboxPolicyContext<'_>) -> bool {	1
use landlock::ABI;	1
target: crate::bwrap::SyntheticMountTarget,	1
panic!("bubblewrap argv is missing inner command after '--'");	1
use codex_protocol::request_permissions::RequestPermissionProfile as CoreRequestPermissionProfile;	5
bwrap_args.args.push(path_to_string(registry_mount));	2
"full-access" => matches!(current_permission_profile, PermissionProfile::Disabled),	1
.add_rules(landlock::path_beneath_rules(&["/dev/null"], access_rw))?	1
} = LandlockCommand::parse();	1
let permissions = PermissionProfile::from_runtime_permissions_with_enforcement(	1
let v2_policy = SandboxPolicy::WorkspaceWrite {	1
CoreActivePermissionProfile::read_only().into()	1
permission_profile_state: PermissionProfileState,	1
preserved_files: bwrap_args.preserved_files,	1
let mut args = create_seatbelt_command_args_with_profile(	1
NetworkSandboxPolicy::Enabled	3
.set_permission_profile(PermissionProfile::External { network }),	1
) -> Result<PermissionProfileToml, PermissionProfileResolutionError>	1
PermissionProfileSnapshot::legacy(read_only_guardian_permission_profile(	1
file_system_policy: &FileSystemSandboxPolicy,	6
#[error("Landlock was not able to fully enforce all sandbox rules")]	1
permission_profile: Option<PermissionProfile>,	2
// Proxy-only networking requires bubblewrap's isolated network namespace.	2
linux_cmd.push("--use-legacy-landlock".to_string());	2
root=DangerFullAccessSandboxPolicy(type="dangerFullAccess"),	1
export type { SandboxPolicy } from "./SandboxPolicy";	1
pub(crate) active_permission_profile: Option<ActivePermissionProfile>,	2
FileSystemSandboxPolicy::unrestricted(),	2
PermissionProfileToml {	1
("danger.txt", SandboxPolicy::DangerFullAccess),	1
// Legacy path: Landlock enforcement only, when bwrap sandboxing is not enabled.	1
!matches!(permission_profile, PermissionProfile::Disabled)	1
seatbelt_regex_for_glob(pattern, GlobMatch::Subtree)	1
permission_profile: PermissionProfile::workspace_write(),	4
let sandbox_policy = SandboxPolicy::ExternalSandbox {	1
pub file_system_sandbox_policy: &'a FileSystemSandboxPolicy,	1
profile: &PermissionProfile,	2
SandboxPolicy::ReadOnly { .. } => {	1
crate::bwrap::SyntheticMountTargetKind::EmptyDirectory => match fs::remove_dir(path) {	1
fn has_reopened_writable_descendant(writable_roots: &[WritableRoot]) -> bool {	1
pub use bwrap::system_bwrap_warning;	1
fn managed_network_enforces_seccomp_even_for_full_network_policy() {	1
requested: &PermissionProfile,	1
fn try_build_bwrap() -> Result<(), String> {	1
use codex_sandboxing::unsupported_windows_restricted_token_sandbox_reason;	1
// bubblewrap builds that do not support `--argv0`.	1
PermissionProfile::Disabled => false,	1
Ok(SandboxPolicy::ExternalSandbox { network_access })	1
let expected = AbsolutePathBuf::from_absolute_path(fake_bwrap_path).expect("absolute");	1
impl AdditionalPermissionProfile {	1
AppEvent::UpdateActivePermissionProfile(active_permission_profile) => {	1
target: crate::bwrap::ProtectedCreateTarget,	1
#[schemars(rename = "FileSystemSandboxPolicy")]	1
Ok(PermissionProfileListResponse { data, next_cursor })	1
let file_system_sandbox_policy = FileSystemSandboxPolicy::restricted(vec![	1
network_seccomp_mode(	3
/// Filesystem restrictions are intentionally handled by bubblewrap.	1
system_bwrap_capabilities(&fake_bwrap_path),	1
_profile_selection: Option<PermissionProfileSelection>,	3
fn prefers_system_bwrap_when_system_bwrap_lacks_argv0() {	1
PermissionProfile::read_only(),	2
match bundled_bwrap::launcher() {	1
PermissionProfile::Managed {	1
.map_err(|source| PermissionProfileResolutionError::SerializeProfileToml { source })?;	2
/// If network isolation is requested, we still wrap with bubblewrap so network	1
let policy = FileSystemSandboxPolicy::restricted(vec![	3
let permission_profile = PermissionProfile::workspace_write();	13
let use_legacy_landlock = self.config.features.use_legacy_landlock();	1
TaggedPermissionProfile::Managed {	1
/// 1. When needed, wrap the command with bubblewrap to construct the	1
/// 2. NetworkSandboxPolicy is restricted for the tool call.	1
// concrete `PermissionProfile`.	1
Feature::UseLegacyLandlock,	1
codex_protocol::protocol::SandboxPolicy::ReadOnly { .. }	1
let file_system_sandbox_policy = FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(	1
/// The runtime must honor `PermissionProfile`; this sidecar exists so clients	1
app.apply_permission_profile_selection(PermissionProfileSelection {	1
GrantedPermissionProfile {	1
internal_permissions: Option<AdditionalPermissionProfile>,	1
&PermissionProfile::Disabled,	1
if let SandboxPolicy::WorkspaceWrite { writable_roots, .. } = sandbox_policy {	1
build_seatbelt_access_policy(	1
NetworkSandboxPolicy::Enabled	1
use super::should_install_network_seccomp;	1
let null_fd = bwrap_args.preserved_files[0].as_raw_fd().to_string();	1
) -> Result<Option<AdditionalPermissionProfile>, String> {	1
pub(super) permission_profile: PermissionProfile,	1
fn writable_roots_text(writable_roots: Option<Vec<WritableRoot>>) -> Option<String> {	1
.file(src_dir.join("bubblewrap.c"))	1
use super::ActivePermissionProfile;	1
use crate::permissions_toml::PermissionProfileToml;	1
FileSystemSandboxPolicy::external_sandbox(),	1
"full-write policy with unreadable globs must still use bwrap"	1
"features.use_legacy_landlock" | "use_legacy_landlock" => {	1
SandboxPolicy::ReadOnly { network_access } => {	1
) -> Option<AdditionalPermissionProfile> {	4
use codex_protocol::models::AdditionalPermissionProfile as PermissionProfile;	1
"`[features].use_legacy_landlock` is deprecated and will be removed soon."	1
fn try_from(value: ExecPermissionProfile) -> Result<Self, Self::Error> {	1
.set_no_new_privs(true);	1
| PermissionProfile::Managed {	1
append_existing_unreadable_path_args(bwrap_args, unreadable_root, allowed_write_paths)	1
_permission_profile: &codex_protocol::models::PermissionProfile,	1
network: NetworkSandboxPolicy::Restricted,	17
fn from(error: landlock::PathFdError) -> Self {	1
panic!("failed to verify descriptor-backed bubblewrap mount: {err}");	1
PermissionProfileCatalogEntry {	1
impl RequestPermissionProfile {	1
additional_permissions: Option<&AdditionalPermissionProfile>,	6
permission_profile: PermissionProfile::read_only(),	11
Constrained::new(PermissionProfile::read_only(), |candidate| {	1
for source in ["bubblewrap.c", "bind-mount.c", "network.c", "utils.c"] {	1
active_permission_profile: ActivePermissionProfile::new(	1
pub sandbox: SandboxPolicy,	3
sandbox_policy: SandboxPolicy::ReadOnly {	1
fn build_seatbelt_access_policy(	1
fn extensible_builtin_parent_profile(profile_name: &str) -> Option<PermissionProfileToml> {	1
if bwrap_args.synthetic_mount_targets.is_empty()	1
path_resolution: WritableRootPathResolution,	1
use codex_sandboxing::resolve_windows_restricted_token_filesystem_overrides;	3
&& bwrap_args.protected_create_targets.is_empty()	1
self.seatbelt_profile,	1
use codex_protocol::models::PermissionProfileSnapshot;	3
&& profile.turn_override == RuntimePermissionProfileTurnOverride::Preserve	1
let mut bwrap_args = BwrapArgs {	1
//! In-process Linux sandbox primitives: `no_new_privs` and seccomp.	1
pub server_permission_profiles: HashMap<String, PermissionProfile>,	1
evaluate: impl FnOnce(&PathUri, &FileSystemSandboxPolicyContext<'_>) -> T,	1
fn new(targets: &[crate::bwrap::ProtectedCreateTarget]) -> Option<Self> {	1
fn managed_filesystem_sandbox_is_restricted(permission_profile: &PermissionProfile) -> bool {	1
impl RuntimePermissionProfileOverride {	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(&sandbox_policy, cwd);	1
let profile = PermissionProfile::Disabled;	1
FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry {	1
// Inner stage: apply seccomp/no_new_privs after bubblewrap has already	1
use codex_sandboxing::landlock::create_linux_sandbox_command_args_for_permission_profile;	1
let profile: PermissionProfile = PermissionProfile::External {	1
use codex_protocol::permissions::FileSystemSandboxPolicy;	16
&PermissionProfile::workspace_write(),	4
fn full_network_policy_without_managed_network_skips_seccomp() {	1
ExecPermissionProfile::External { network } => Self::External { network },	1
program: system_bwrap_path,	1
network: NetworkSandboxPolicy::Enabled,	2
bwrap_args	3
use codex_file_system::ExecPermissionProfile;	1
use crate::config::PermissionProfileState;	1
LandlockRestrict,	1
WorkspaceWriteSandboxPolicy,	1
fn build_preflight_bwrap_argv(	1
let network_sandbox_policy = NetworkSandboxPolicy::from(sandbox_policy);	1
let system_bwrap_path = find_system_bwrap_in_path();	1
impl FileSystemSandboxPolicy {	1
impl TryFrom<GrantedPermissionProfile> for CoreAdditionalPermissionProfile {	1
bwrap_args.args.push(path_to_string(subpath));	2
use codex_app_server_protocol::RequestPermissionProfile;	1
CoreAdditionalPermissionProfile {	1
pub enum PermissionProfileResolutionError {	1
pub fn permission_profile(&self) -> &PermissionProfile {	3
let requested_permissions = AdditionalPermissionProfile {	1
if matches!(permission_profile, PermissionProfile::Disabled) && sandbox_state_disable_network {	1
bwrap_args.args.push("--bind".to_string());	1
SandboxTransformError::InvalidSandboxPolicyCwd {	1
Ok(AdditionalPermissionProfile {	1
use crate::bwrap::WSL1_BWRAP_WARNING;	1
bwrap_args.args.push("--tmpfs".to_string());	1
granted_permissions: &AdditionalPermissionProfile,	1
"failed to create synthetic bubblewrap mount registry {}: {err}",	1
Some(true) => NetworkSandboxPolicy::Enabled,	1
PermissionProfileSnapshot::active(profile, active_profile),	1
let enabled = SandboxPolicy::ReadOnly {	1
append_empty_file_bind_data_args(bwrap_args, path)?;	2
permission_profile_state: PermissionProfileState,	1
.map(codex_protocol::request_permissions::RequestPermissionProfile::from)	1
permissions: codex_app_server_protocol::RequestPermissionProfile {	1
assert_eq!(thread.permission_profile, PermissionProfile::Disabled);	3
permission_profile: PermissionProfile::Disabled,	1
fn should_install_network_seccomp(	1
fn sorted_writable_roots(mut roots: Vec<WritableRoot>) -> Vec<WritableRoot> {	1
Self::Disabled => NetworkSandboxPolicy::Enabled,	1
//! - seccomp + `PR_SET_NO_NEW_PRIVS` applied in-process, and	1
let network_policy = NetworkSandboxPolicy::Restricted;	2
self.enabled(Feature::UseLegacyLandlock)	1
append_missing_empty_file_bind_data_args(bwrap_args, &first_missing_component)?;	1
tx.send(AppEvent::UpdateActivePermissionProfile(	1
) -> GrantedPermissionProfile {	1
use crate::config::PermissionProfileSnapshot;	3
let permission_profile = PermissionProfile::workspace_write();	1
run_bwrap_in_child_with_synthetic_mount_cleanup(bwrap_args);	1
pub use unix::ResolvedPermissionProfile;	1
panic!("failed to exec system bubblewrap {program_path}: {err}");	1
let Some(system_bwrap_path) = system_bwrap_path else {	1
let permission_profile = PermissionProfile::from_runtime_permissions(	3
target: &crate::bwrap::ProtectedCreateTarget,	2
FileSystemSandboxPolicy::external_sandbox(),	1
"Codex's Linux sandbox uses bubblewrap, which is not supported on WSL1 ",	1
fn from_permissions_and_cwd(permissions: PermissionProfile, cwd: Option<PathUri>) -> Self {	1
export type { PermissionProfileListResponse } from "./PermissionProfileListResponse";	1
enum FileSystemPermissionProfileContext {	1
const SYSTEM_BWRAP_PROGRAM: &str = "bwrap";	1
impl PermissionProfile {	1
impl TryFrom<AdditionalPermissionProfile> for CoreAdditionalPermissionProfile {	1
use_legacy_landlock: config.use_legacy_landlock,	1
.expect("create bwrap args");	4
build_seatbelt_unreadable_glob_policy(file_system_sandbox_policy, sandbox_policy_cwd);	1
additional_permissions: AdditionalPermissionProfile,	1
use codex_protocol::protocol::NetworkSandboxPolicy;	1
.ok_or_else(|| "bubblewrap argv is missing the command separator '--'".to_string())?;	1
let permission_profile_state = PermissionProfileState::from_constrained_active_profile(	1
"failed to read synthetic bubblewrap mount marker in {}: {err}",	1
PermissionProfile::Managed { .. } => {	5
SandboxPolicy::ReadOnly { network_access, .. } => {	1
NetworkSandboxPolicy::Enabled	1
) -> AdditionalPermissionProfile {	1
turn_override: RuntimePermissionProfileTurnOverride,	1
network_sandbox_policy: NetworkSandboxPolicy,	8
/// `FileSystemSandboxPolicy` for a thread.	1
use seccompiler::SeccompFilter;	1
let inner = build_inner_seccomp_command(InnerSeccompCommandArgs {	1
permission_profile: PermissionProfile::read_only(),	4
PermissionProfile::from_legacy_sandbox_policy(&SandboxPolicy::new_read_only_policy())	1
SandboxModeRequirement::WorkspaceWrite => PermissionProfile::workspace_write(),	1
let err = CoreAdditionalPermissionProfile::try_from(additional_permissions)	1
"seccomp",	1
impl TryFrom<RawFileSystemSandboxPolicy> for FileSystemSandboxPolicy {	1
materialize: impl FnOnce(FileSystemSandboxPolicy) -> FileSystemSandboxPolicy,	1
pub(crate) fn network_policy(&self) -> NetworkSandboxPolicy {	1
fn default_policy_with_unreadable_glob(pattern: String) -> FileSystemSandboxPolicy {	2
env_map.insert(CODEX_SANDBOX_ENV_VAR.to_string(), "seatbelt".to_string());	1
system_bwrap_capabilities: impl FnOnce(&Path) -> Option<SystemBwrapCapabilities>,	1
let profile = PermissionProfile::workspace_write();	1
expected: &SandboxPolicy,	1
use landlock::RulesetAttr;	1
impl From<CoreActivePermissionProfile> for ActivePermissionProfile {	1
bwrap_args.args.push(path_to_string(unreadable_root));	2
pub fn create_seatbelt_command_args(	1
CoreRequestPermissionProfile {	2
EscalationPermissions::AdditionalPermissionProfile(PermissionProfile {	1
.and_then(RuntimePermissionProfileOverride::turn_permission_profile),	2
return Ok(NormalizedWritableRoot::Subpath(normalized));	1
//! - bubblewrap used to construct the filesystem view before exec.	1
pub(crate) fn create_bwrap_command_args(	1
.set_permission_profile_from_session_snapshot(PermissionProfileSnapshot::active(	3
use crate::bwrap::is_wsl1;	1
/// The type name remains `LandlockCommand` for compatibility with existing	1
SelectPermissionProfile(PermissionProfileSelection),	1
use codex_app_server_protocol::RequestPermissionProfile;	1
writable_roots: Vec<WritableRoot>,	1
SandboxPolicy::ExternalSandbox { .. } => true,	1
let helper_read_roots = if sandbox.use_legacy_landlock {	1
let mut child = match Command::new(system_bwrap_path)	1
SandboxTransformError::InvalidSandboxPolicyCwd {	1
use codex_protocol::permissions::NetworkSandboxPolicy;	13
SandboxPolicy::ExternalSandbox { network_access } => {	1
self.runtime_permission_profile_override = Some(RuntimePermissionProfileOverride::from_config(&config));	1
mod bazel_bwrap;	1
effective_permissions: &AdditionalPermissionProfile,	1
fn network_seccomp_mode(	1
pub use codex_protocol::models::PermissionProfile;	1
fn permission_profile_display_name(permission_profile: &PermissionProfile) -> &'static str {	1
fn seatbelt_protected_metadata_name_regex(root: &AbsolutePathBuf, name: &str) -> String {	1
#[error("seccomp setup error")]	1
bwrap_bin: Path | None	2
.needs_direct_runtime_enforcement(NetworkSandboxPolicy::Restricted, cwd.path()),	4
use codex_protocol::request_permissions::RequestPermissionProfile as CoreRequestPermissionProfile;	1
NetworkSandboxPolicy::Restricted,	1
Ok(PermissionProfile::from_runtime_permissions(	1
use seccompiler::BpfProgram;	1
| SandboxPolicy::ReadOnly { .. } => vec![	1
fn synthetic_mount_marker_contents(target: &crate::bwrap::SyntheticMountTarget) -> &'static [u8] {	1
SandboxPolicy::WorkspaceWrite { writable_roots, .. } if !writable_roots.is_empty()	1
close_fd_or_panic(write_fd, "close write end in bubblewrap parent");	1
BUILT_IN_READ_ONLY_PROFILE => FileSystemSandboxPolicy::read_only(),	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(	2
CoreRequestPermissionProfile::default(),	1
"danger-full-access" => Ok(SandboxPolicy::DangerFullAccess),	1
pub(crate) use resolved_permission_profile::PermissionProfileState;	1
// as separate WritableRoot values and are checked independently.	1
PermissionProfile::from_legacy_sandbox_policy(&SandboxPolicy::DangerFullAccess);	1
fn append_empty_file_bind_data_args(bwrap_args: &mut BwrapArgs, path: &Path) -> Result<()> {	1
pub fn network_sandbox_policy(&self) -> NetworkSandboxPolicy {	2
fn append_missing_empty_file_bind_data_args(bwrap_args: &mut BwrapArgs, path: &Path) -> Result<()> {	1
.map_err(|_| UnsupportedLegacyPermissionProfile)?;	1
SandboxPolicy::WorkspaceWrite {	1
|| matches!(requested, PermissionProfile::External { .. })	1
let permission_profile = PermissionProfile::from_legacy_sandbox_policy(&sandbox_policy);	1
run_or_exec_bwrap(bwrap_args);	1
fn system_bwrap_has_user_namespace_access(system_bwrap_path: &Path, timeout: Duration) -> bool {	1
#[experimental("thread/fork.activePermissionProfile")]	1
fn normalize_file_system_policy_root_aliases(file_system_policy: &mut FileSystemSandboxPolicy) {	1
permission_profile: PermissionProfile::workspace_write(),	3
pub enum ExecPermissionProfile {	1
pub(crate) fn snapshot(&self) -> PermissionProfileSnapshot {	1
granted: AdditionalPermissionProfile,	1
&codex_app_server_protocol::SandboxPolicy::DangerFullAccess,	1
use codex_protocol::protocol::FileSystemSandboxPolicy;	3
panic!("failed to block bubblewrap forwarded signals: {err}");	1
mut parent: PermissionProfileToml,	1
let normalized_command_cwd = normalize_command_cwd_for_bwrap(command_cwd);	1
if build_bwrap:	1
"--apply-seccomp-then-exec".to_string(),	3
policy.needs_direct_runtime_enforcement(NetworkSandboxPolicy::Restricted, cwd.path(),)	2
.add_rules(landlock::path_beneath_rules(&["/"], access_ro))?	1
None => PermissionProfile::workspace_write(),	1
additional_permissions: Option<AdditionalPermissionProfile>,	14
network: NetworkSandboxPolicy,	1
SandboxPolicy::WorkspaceWrite { .. } => SandboxMode::WorkspaceWrite,	1
WritableRootsCapability,	1
sandbox: &codex_app_server_protocol::SandboxPolicy,	1
pub permission_profile: &'a PermissionProfile,	3
pub permissions: GrantedPermissionProfile,	1
RuntimePermissionProfileOverride::from_restored_config(&self.config),	1
use crate::bazel_bwrap;	1
PermissionProfile::Disabled => Self::Disabled,	1
PermissionProfile::Disabled	1
SandboxPolicy::WorkspaceWrite { .. } => false,	1
WritableRootPathResolution::PreserveMutableComponents,	1
fn normalize_command_cwd_for_bwrap(command_cwd: &Path) -> PathBuf {	1
|| bazel_bwrap_env_key_is_allowed(key)	1
SandboxPolicy::WorkspaceWrite { writable_roots, .. } => {	1
if !use_legacy_landlock {	1
append_unreadable_root_args(&mut bwrap_args, &unreadable_root, &allowed_write_paths)?;	1
additional_permissions: Some(v2::AdditionalPermissionProfile {	1
PermissionProfileList => "permissionProfile/list" {	1
fn from(error: landlock::RulesetError) -> Self {	1
if !system_bwrap_path.is_file() {	1
Some(ActivePermissionProfile::new(	1
PermissionProfileResolutionError::UnsupportedBuiltInParent {	1
runtime_permission_profile_override: Option<&PermissionProfile>,	1
use codex_sandboxing::landlock::allow_network_for_proxy;	1
RuntimePermissionProfileOverride::from_config(&resume_config);	1
pub struct WritableRoot {	1
system_bwrap_launcher_for_path_with_probe(system_bwrap_path, system_bwrap_capabilities)	1
base: Option<&AdditionalPermissionProfile>,	1
network_sandbox_policy: NetworkSandboxPolicy,	2
TaggedPermissionProfile::External { network } => Self::External { network },	1
system_bwrap_path: &Path,	1
PermissionProfile::read_only()	1
let legacy_policy = SandboxPolicy::new_workspace_write_policy();	1
NetworkSandboxPolicy::Restricted,	2
fn turn_permission_profile(&self) -> Option<&PermissionProfile> {	1
let expected = codex_protocol::models::PermissionProfile::workspace_write()	1
match preferred_bwrap_launcher() {	2
use super::network_seccomp_mode;	1
FileSystemSandboxPolicy::from_legacy_sandbox_policy_for_cwd(&expected, cwd.path())	1
fn exec_system_bwrap(	1
PermissionProfileSnapshot::active_with_profile_workspace_roots(	1
#[experimental("thread/start.activePermissionProfile")]	1
pub permission_profile: PermissionProfileSnapshot,	1
"failed to open synthetic bubblewrap mount registry lock {}: {err}",	1
codex_core::config::system_bwrap_warning(config.permissions.permission_profile())	1
let policy = FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry::new(	1
let read_only_profile = PermissionProfile::read_only();	1
.and_then(RuntimePermissionProfileOverride::turn_permission_profile),	1
fn managed_sandbox_active(permission_profile: &PermissionProfile) -> bool {	1
ActivePermissionProfile::new(":workspace"),	1
FileSystemSandboxPolicy::restricted(entries)	2
SandboxPolicy::WorkspaceWrite {	3
permission_profile = PermissionProfile::read_only();	1
assert!(translate_legacy_bwrap_fd_mounts(&mut argv).is_err());	1
SandboxPolicy::ExternalSandbox { .. } => Self::External,	1
pub mod landlock;	1
return Err(UnsupportedLegacyPermissionProfile.into());	1
ActivePermissionProfile::new("locked"),	2
/// Error from linux landlock	1
External { network: NetworkSandboxPolicy },	1
return FileSystemSandboxPolicy::from(sandbox_policy);	1
RequestPermissionProfile {	2
if permission_profile == &PermissionProfile::Disabled =>	1
fn build_seatbelt_unreadable_glob_policy(	1
pub(crate) fn permission_profile(&self) -> &PermissionProfile {	2
pub custom_permission_profiles: Vec<PermissionProfileCatalogEntry>,	1
if matches!(authority, PermissionProfile::External { .. })	1
use seccompiler::SeccompAction;	1
let active_profile = ActivePermissionProfile::new(selection.profile_id.clone());	1
) -> FileSystemSandboxPolicy {	3
"failed to exec bundled bubblewrap {} via {fd_path}: {err}",	1
policy: &FileSystemSandboxPolicy,	3
#[arg(long = "use-legacy-landlock", hide = true, default_value_t = false)]	1
/// `bwrap ... --perms 000 --ro-bind-data FD PATH`	1
fn translates_fd_mounts_for_legacy_system_bubblewrap() {	1
additional_permissions: Option<&AdditionalPermissionProfile>,	4
SandboxType::LinuxSeccomp => "seccomp",	1
PermissionProfile::default(),	1
Option<codex_app_server_protocol::SandboxPolicy>,	1
BUILT_IN_PERMISSION_PROFILE_READ_ONLY => Some(PermissionProfile::read_only()),	1
let mut policy = FileSystemSandboxPolicy::default();	2
PermissionProfile::from_runtime_permissions(policy, NetworkSandboxPolicy::Restricted),	1
CoreRequestPermissionProfile {	3
let mut expected = FileSystemSandboxPolicy::restricted(vec![	1
.set_permission_profile_from_session_snapshot(PermissionProfileSnapshot::active(	10
fn restricted_policy(entries: Vec<FileSystemSandboxEntry>) -> FileSystemSandboxPolicy {	1
if bwrap_bin is not None and not spec.is_linux:	1
build_seatbelt_access_policy(	1
additional_permissions: Option<&'a AdditionalPermissionProfile>,	3
candidates.push(exe_dir.join("bwrap"));	1
sandbox_policy: codex_protocol::protocol::SandboxPolicy::new_read_only_policy(),	1
PermissionProfile::from_runtime_permissions(&file_system, network)	1
.unwrap_or_else(|_| Some(FileSystemSandboxPolicy::restricted(Vec::new())))	1
selection: PermissionProfileSelection,	4
impl From<landlock::PathFdError> for CodexErr {	1
if use_legacy_landlock	1
pub fn to_legacy_sandbox_policy(&self, cwd: &Path) -> io::Result<SandboxPolicy> {	1
) -> Result<AdditionalPermissionProfile, String> {	2
"seatbelt sandbox is only available on macOS".to_string(),	1
/// `PermissionProfile` enum itself.	1
pub fn active_permission_profile(&self) -> Option<ActivePermissionProfile> {	2
active_permission_profile: &ActivePermissionProfile,	1
fn create_bwrap_flags(	1
.map(|root| WindowsWritableRoot {	1
pub fn summarize_sandbox_policy(sandbox_policy: &SandboxPolicy) -> String {	1
) -> Result<EffectivePermissions, ResolvePermissionProfileError> {	1
fn workspace_profile(network_policy: NetworkSandboxPolicy) -> PermissionProfile {	1
pub struct FileSystemSandboxPolicyContext<'a> {	1
"CARGO_BIN_EXE_bwrap",	1
file_system_sandbox_policy: &codex_protocol::permissions::FileSystemSandboxPolicy,	1
unimplemented!("unsupported architecture for seccomp filter");	1
exec_bwrap(bwrap_args.args, bwrap_args.preserved_files);	1
assert_eq!(usages[0].alias, "features.use_legacy_landlock");	1
panic!("failed to compile bubblewrap for Linux target: {err}");	1
Self::External { network } => Ok(SandboxPolicy::ExternalSandbox {	1
permission_profile_state: PermissionProfileState::from_constrained_legacy(	1
.unwrap_or_else(|err| panic!("invalid bundled bubblewrap fd path: {err}"));	1
// The outer helper must launch bubblewrap before this listener can arrive.	1
SandboxPolicy::ReadOnly {	1
/// Build the inner command that applies seccomp after bubblewrap.	1
PermissionProfile::from_legacy_sandbox_policy(	1
pub(crate) struct PermissionProfileState {	1
.set(PermissionProfileSnapshot::legacy(permission_profile))	1
pub data: Vec<PermissionProfileSummary>,	1
fn install_filesystem_landlock_rules_on_current_thread(	1
pub use debug_sandbox::run_command_under_landlock;	1
Some(codex_app_server_protocol::SandboxPolicy::ReadOnly {	1
fn should_apply_network_block(permission_profile: &PermissionProfile) -> bool {	1
entries.insert("use_legacy_landlock".to_string(), true);	1
pub network_sandbox_policy: NetworkSandboxPolicy,	2
&FileSystemSandboxPolicy::external_sandbox(),	1
if bwrap_args.preserved_files.is_empty() {	1
network: NetworkSandboxPolicy::Restricted,	2
Ok(crate::bwrap::BwrapArgs {	1
pub fn additional_permissions(&self) -> AdditionalPermissionProfile {	1
network: NetworkSandboxPolicy::Enabled,	1
let use_legacy_landlock = sandbox_state.as_ref().map_or_else(	1
active_permission_profile: &ActivePermissionProfile,	1
use crate::seatbelt::MacosSeatbeltProfile;	1
"failed to create synthetic bubblewrap mount marker directory {}: {err}",	1
import type { SandboxPolicy } from "./SandboxPolicy";	1
// sandboxed environment to apply seccomp. This path never falls back	1
pub fn legacy(permission_profile: PermissionProfile) -> Self {	1
FileSystemSandboxPolicy::restricted(vec![FileSystemSandboxEntry::new(	2
context: &FileSystemSandboxPolicyContext<'_>,	6
fn run_bwrap_in_child_with_synthetic_mount_cleanup(bwrap_args: crate::bwrap::BwrapArgs) -> ! {	1
SandboxPolicy::DangerFullAccess => "danger-full-access".to_string(),	1
sandbox_policy: v2::SandboxPolicy::DangerFullAccess,	1
apply_inner_command_argv0(&mut bwrap_args.args);	1
let restricted = SandboxPolicy::new_read_only_policy();	1
resolve_windows_restricted_token_filesystem_overrides(	2
SandboxPolicy::ReadOnly { .. } | SandboxPolicy::WorkspaceWrite { .. } => Self::Managed,	1
