Skip to content

Track startup MITM CA env#26314

Closed
winston-openai wants to merge 8 commits into
dev/winston/mitm-platform-ca-rootsfrom
dev/winston/mitm-startup-ca-env
Closed

Track startup MITM CA env#26314
winston-openai wants to merge 8 commits into
dev/winston/mitm-platform-ca-rootsfrom
dev/winston/mitm-startup-ca-env

Conversation

@winston-openai

@winston-openai winston-openai commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

Why

Child-specific CA material can only be handled safely if the proxy remembers which CA variables came from process startup and how relative paths were originally resolved.

What

  • capture startup CA env values, including SSL_CERT_DIR, and the startup working directory
  • mark startup-derived CA variables when managed MITM rewrites them
  • export the private MITM-active marker used by later child-environment stages

Stack

Validation

  • just test -p codex-network-proxy

@winston-openai winston-openai marked this pull request as ready for review June 19, 2026 00:17

Copy link
Copy Markdown
Contributor Author

Closing as superseded by the focused #29013 and #29014 stack. The replacement isolates the persisted MITM private key and preserves file-backed custom CAs present at Codex startup, with zero codex-core changes. Per-command bundle materialization, generic sandbox carvebacks, and additional shell-snapshot plumbing are intentionally deferred because they are not required for this scoped completion work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant