Skip to content

Keep managed MITM CA private keys in proxy memory - #29013

Merged
viyatb-oai merged 23 commits into
mainfrom
dev/winston/mitm-ca-key-isolation
Jun 23, 2026
Merged

Keep managed MITM CA private keys in proxy memory#29013
viyatb-oai merged 23 commits into
mainfrom
dev/winston/mitm-ca-key-isolation

Conversation

@winston-openai

@winston-openai winston-openai commented Jun 19, 2026

Copy link
Copy Markdown
Contributor

Why

The managed MITM trust bundle must be readable by sandboxed commands. Persisting its sibling CA private key under $CODEX_HOME/proxy therefore requires a deny-read sandbox rule, but the Windows unelevated backend rejects deny-read paths and WSL1's legacy Landlock path cannot enforce that rule.

A persistent OS credential store also does not provide the same cross-platform boundary from other processes running as the same user. Keeping the signer inside the network proxy process avoids both problems: ordinary sandbox setup stays independent of CA-key state, and no private signing key is exposed through the filesystem or a persistent credential record.

What

  • generate one managed CA per proxy process and retain its private signer only in proxy memory
  • emit only content-addressed public CA certificates and trust bundles under $CODEX_HOME/proxy
  • hold a cross-process lease for each active public certificate and prune artifacts from inactive proxy processes
  • keep all CA ownership in codex-network-proxy; no codex-core or sandbox-policy changes
  • validate generated trust-bundle paths by their content hash
  • keep the public bundle readable by sandboxed commands on Windows, WSL1, macOS, and Linux

The independent startup custom-CA follow-up is #29014.

Validation

  • CODEX_HOME=/private/tmp/codex-test-home-network-proxy just test -p codex-network-proxy (179 tests)
  • just bazel-lock-check
  • just fix -p codex-network-proxy
  • just fmt

@viyatb-oai viyatb-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One compatibility question on the sandbox boundary.

Comment thread codex-rs/sandboxing/src/manager.rs Outdated
@winston-openai winston-openai changed the title Protect managed MITM CA private keys from sandboxed commands Keep managed MITM CA private keys in proxy memory Jun 23, 2026
@viyatb-oai viyatb-oai changed the title Keep managed MITM CA private keys in proxy memory Store managed MITM CA private keys in the OS keyring Jun 23, 2026
Co-authored-by: Codex noreply@openai.com
@viyatb-oai viyatb-oai changed the title Store managed MITM CA private keys in the OS keyring fix: store managed MITM CA private keys securely Jun 23, 2026
@winston-openai winston-openai changed the title fix: store managed MITM CA private keys securely Keep managed MITM CA private keys in proxy memory Jun 23, 2026
@viyatb-oai
viyatb-oai merged commit c5a9a95 into main Jun 23, 2026
46 of 47 checks passed
@viyatb-oai
viyatb-oai deleted the dev/winston/mitm-ca-key-isolation branch June 23, 2026 19:20
@github-actions github-actions Bot locked and limited conversation to collaborators Jun 23, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

2 participants