Repository navigation
docs: correct the managed execution trust boundary - #1757
Draft
luokerenx4 wants to merge 2 commits into
Draft
luokerenx4 wants to merge 2 commits into
luokerenx4 wants to merge 2 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The runtime guide still tells readers that headless Codex is restricted to
workspace-write, although merged #1433 deliberately made managed headless execution full access. That stale statement can make the peer-path behavior in #1062 look like an accidental escape from a containment guarantee that the product does not provide. This Draft corrects documentation only.flowchart LR subgraph Mistaken_model A[Headless run] --> B[Docs claim Workspace sandbox] B --> C[Peer path appears outside promised boundary] end subgraph Current_contract D[Managed run on any surface] --> E[Native tools use host user authority] F[Peer path] --> G[Address only] G --> E E --> H[OS and native enterprise restrictions remain] I[Write in owning Workspace] --> J[Collaboration instruction, not path enforcement] K[Trading through alice-uta] --> L[Existing UTA mode and approvals] endRemove the stale headless/interactive security distinction. Explain that the working directory and
peer pathare not containment capabilities, while own-Workspace writing remains guidance. Distinguish native host authority from the existing UTA service-level trading controls. Reuse the runtime owner guide and link to it from agent guidance; no new policy system.Evidence: read #1062 and its current triage comment, merged #1433 and discussion, current Claude/Codex/Cursor/Grok/opencode/Pi launch code and
workspace_path. Current Codex headless explicitly usesdanger-full-access/never; Claude uses permission bypass with sandbox disabled. The historical headless-git prefix allow-list is no longer the current launch contract.Validation: cross-checked the prose against current adapters and Web transport ownership, verified the relative guide target and source directories, and passed
git diff --check. No runtime code changed, so no behavior tests or live native operations were performed.Tradeoff: this clarifies the intentional trust boundary; it neither claims a new vulnerability nor implements host/cwd isolation. A future hard sandbox would be a separate architecture decision. No runtime permissions, security-sensitive settings, UTA policy, user data, release or deployment changed. Related: #1062, #1433.