Route Windows sandbox proxy traffic by restricting SID - #34613
Merged
copyberry[bot] merged 1 commit intoJul 21, 2026
Merged
Conversation
## Why Elevated Windows sandboxes need stable managed-proxy ports while preserving the network policy and environment attribution of each sandboxed process. ## What changed - Keep shared HTTP and SOCKS5 loopback ingress listeners alive across managed-proxy instances. - Add a per-route restricting SID to elevated sandbox tokens and dispatch incoming connections to the matching proxy policy after attributing the client process. - Reject connections without exactly one registered route, remove routes when their proxy handle is dropped, and keep unsandboxed Windows launches off the managed ingress. - Provision the elevated sandbox with the configured proxy ports and local-binding setting, honoring the selected profile and CLI overrides. ## Testing - Add Windows unit tests for TCP ownership attribution, route selection, restricting-token propagation, and setup settings. - Add an end-to-end Windows test covering stable ports, isolated environment policies, HTTP and SOCKS5 routing, and route teardown. GitOrigin-RevId: 783fac6e0f904dc9bb1955b75d4a5895e8bb9690
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/783fac6e0f904dc9bb1955b75d4a5895e8bb9690
branch
from
July 21, 2026 21:07
04a94ad to
999a715
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/783fac6e0f904dc9bb1955b75d4a5895e8bb9690
branch
July 21, 2026 21:08
daniribeiroBR
temporarily deployed
to
issue-triage
July 21, 2026 21:10 — with
GitHub Actions
Inactive
daniribeiroBR
temporarily deployed
to
issue-triage
July 21, 2026 21:10 — with
GitHub Actions
Inactive
daniribeiroBR
temporarily deployed
to
issue-triage
July 21, 2026 21:10 — with
GitHub Actions
Inactive
daniribeiroBR
temporarily deployed
to
issue-triage
July 21, 2026 21:11 — with
GitHub Actions
Inactive
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Route Windows sandbox proxy traffic by restricting SID
Why
Elevated Windows sandboxes need stable managed-proxy ports while preserving the network policy and environment attribution of each sandboxed process.
What changed
Testing