Skip to content

Allow network access for package-installing workflow turns - #65

Merged
frantic-openai merged 1 commit into
mainfrom
acod/fss-887-investigate-any-brix-run-fails-in-any-of-the-argon-clusters
Jun 1, 2026
Merged

Allow network access for package-installing workflow turns#65
frantic-openai merged 1 commit into
mainfrom
acod/fss-887-investigate-any-brix-run-fails-in-any-of-the-argon-clusters

Conversation

@andrew749

Copy link
Copy Markdown
Member

Context

Brix oaipkg installs in Symphony-launched FSS runs need DNS/network access, but the workflow turn sandbox did not enable it.

TL;DR

Allow Symphony workflow turns to use network/DNS for package installs.

Summary

  • Add networkAccess: true to the workflow turn sandbox policy.
  • Document the setting for package-manager and external-host workflows.

Alternatives

  • Leave safer code defaults unchanged and scope the allowance to this workflow.

Test Plan

  • /usr/bin/env mix run -e IO.inspect(...) before and after config change
  • /usr/bin/env mix specs.check
  • /usr/bin/env mix test test/symphony_elixir/workspace_and_config_test.exs
  • /usr/bin/env make all MIX="/usr/bin/env mix"

Summary:
- Enable network access for the default Symphony turn sandbox policy
  used by the checked-in workflow.
- Document that workflows running package managers or external host
  resolution need the networkAccess turn sandbox setting.

Rationale:
- The brix oaipkg install failure maps to Symphony launching Codex
  turns without an explicit network allowance, so DNS-dependent package
  installs can fail inside the turn sandbox.
- Keeping the change in WORKFLOW.md is the smallest durable fix for
  this orchestration path and avoids changing safer implementation
  defaults for other workflows.

Tests:
- /usr/bin/env mix run -e IO.inspect(SymphonyElixir.Config.codex_runtime_settings(...))
- /usr/bin/env mix specs.check
- /usr/bin/env mix test test/symphony_elixir/workspace_and_config_test.exs
- /usr/bin/env make all MIX="/usr/bin/env mix"

Co-authored-by: Codex <codex@openai.com>
@andrew749 andrew749 added the symphony Track Symphony work for codebase label May 4, 2026
jimoosciuc

This comment was marked as low quality.

jimoosciuc

This comment was marked as low quality.

chihsuan referenced this pull request in Automattic/symphony May 15, 2026
fix(codex): fail closed on missing sandbox startup
@REFaster

Copy link
Copy Markdown

BLOCKED-OPERATOR: clean MERGEABLE PR with green make-all and validate-pr-description, but it enables workflow sandbox network access. That is explicitly network/security-sensitive, so it needs operator approval rather than automation merge.

corylanou added a commit to digitaldrywood/symphony-elixir that referenced this pull request May 21, 2026
#### Context

Fixes #24. Upstream openai#65 enables workflow turn network access for package-installing turns so fresh worktrees can fetch dependencies during the first agent run.

#### TL;DR

*Allow configured workflow turns to use network access for package installs.*

#### Summary

- Add `networkAccess: true` to dogfood and GitHub workflow turn sandbox policies.
- Add the same flag to onboarding-generated GitHub workflows.
- Document when package-manager workflows need turn-level network access.

#### Alternatives

- Keep safer code defaults unchanged and require each workflow to opt in explicitly.

#### Test Plan

- [x] `mise exec -- mix test test/symphony_elixir/core_test.exs test/symphony_elixir/workspace_and_config_test.exs`
- [x] `make all` from `elixir/`
@frantic-openai
frantic-openai merged commit 0d85c27 into main Jun 1, 2026
2 of 3 checks passed
@frantic-openai
frantic-openai deleted the acod/fss-887-investigate-any-brix-run-fails-in-any-of-the-argon-clusters branch June 1, 2026 16:15
PouryaNoufallah96 added a commit to PouryaNoufallah96/symphony that referenced this pull request Jun 4, 2026
Sync with upstream (6 commits): README/docs + smoke-test notes, and the
networkAccess example-doc change (openai#65). PR openai#84 (Codex thread links + Linear
comment resumes) was added and then fully reverted upstream (openai#85), so this
merge carries no net code change — markdown only. Fork customizations
(team_key, Claude Code backend, ADO/GitHub adapters, Solid assigns) intact.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

symphony Track Symphony work for codebase

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants