Skip to content

docs: correct the managed execution trust boundary - #1757

Draft
luokerenx4 wants to merge 2 commits into
devfrom
codex/1062-managed-trust-docs
Draft

luokerenx4 wants to merge 2 commits into
devfrom
codex/1062-managed-trust-docs

Conversation

@luokerenx4

Copy link
Copy Markdown
Contributor

The runtime guide still tells readers that headless Codex is restricted to workspace-write, although merged #1433 deliberately made managed headless execution full access. That stale statement can make the peer-path behavior in #1062 look like an accidental escape from a containment guarantee that the product does not provide. This Draft corrects documentation only.

flowchart LR
  subgraph Mistaken_model
    A[Headless run] --> B[Docs claim Workspace sandbox]
    B --> C[Peer path appears outside promised boundary]
  end
  subgraph Current_contract
    D[Managed run on any surface] --> E[Native tools use host user authority]
    F[Peer path] --> G[Address only]
    G --> E
    E --> H[OS and native enterprise restrictions remain]
    I[Write in owning Workspace] --> J[Collaboration instruction, not path enforcement]
    K[Trading through alice-uta] --> L[Existing UTA mode and approvals]
  end
Loading

Remove the stale headless/interactive security distinction. Explain that the working directory and peer path are not containment capabilities, while own-Workspace writing remains guidance. Distinguish native host authority from the existing UTA service-level trading controls. Reuse the runtime owner guide and link to it from agent guidance; no new policy system.

Evidence: read #1062 and its current triage comment, merged #1433 and discussion, current Claude/Codex/Cursor/Grok/opencode/Pi launch code and workspace_path. Current Codex headless explicitly uses danger-full-access/never; Claude uses permission bypass with sandbox disabled. The historical headless-git prefix allow-list is no longer the current launch contract.

Validation: cross-checked the prose against current adapters and Web transport ownership, verified the relative guide target and source directories, and passed git diff --check. No runtime code changed, so no behavior tests or live native operations were performed.

Tradeoff: this clarifies the intentional trust boundary; it neither claims a new vulnerability nor implements host/cwd isolation. A future hard sandbox would be a separate architecture decision. No runtime permissions, security-sensitive settings, UTA policy, user data, release or deployment changed. Related: #1062, #1433.

@luokerenx4 luokerenx4 added workflow:parallel Autonomous parallel contribution; leave open for later acceptance theme:reliability Failure recovery, retries, loading, or resilience area:workspace Workspace, Session, templates, or sidebar lifecycle labels Oct 2, 2026
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
openalice-demo Ready Ready Preview Oct 2, 2026 10:41am UTC

Request Review

@luokerenx4 luokerenx4 added the review:deep Requires deliberate human review before merge label Oct 2, 2026

This branch was successfully deployed

1 active deployment
Preview — 9cde4480 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:workspace Workspace, Session, templates, or sidebar lifecycle review:deep Requires deliberate human review before merge theme:reliability Failure recovery, retries, loading, or resilience workflow:parallel Autonomous parallel contribution; leave open for later acceptance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants