fix: overhaul how we spawn commands under seccomp/landlock on Linux

This commit is contained in:
Michael Bolin
2025-05-22 14:47:02 -07:00
parent cb379d7797
commit f7004111ae
16 changed files with 356 additions and 43 deletions

View File

@@ -0,0 +1,8 @@
# codex-linux-sandbox
This crate is responsible for producing:
- a `codex-linux-sandbox` standalone executable for Linux that is bundled with the Node.js version of the Codex CLI
- a lib crate that exposes the business logic of the executable as `run_main()` so that
- the `codex-exec` CLI can check if its arg0 is `codex-linux-sandbox` and, if so, execute as if it were `codex-linux-sandbox`
- this should also be true of the `codex` multitool CLI