4 months ago
3f85481Codex review (commit 6af63e9, P1): codexSandboxConfig forced the Codex app-server sandbox to danger-full-access whenever the session ran with --yolo, before resolveSandboxPolicy could apply agentTargetPaths. Since children inherit the parent's yolo flag and Codex owns the native shell/write tools, a scoped child (e.g. targetPaths: ["src/auth"]) got full workspace write access under yolo. Now a scoped child keeps its configured (scoped) sandbox even under yolo; yolo still maps to approvalPolicy "never" separately. Only unscoped sessions widen to danger-full-access. Matches the built-in path, which never widens the sandbox for yolo (it auto-approves per-command escalation instead). Verified: check, typecheck, codex app-server tests (19).
Parent6af63e9