Repository navigation
fix(codex_sdk): keep provider credentials out of Codex run artifacts - #203
Merged
Merged
Conversation
features.shell_snapshot=false was only applied for the ChatGPT subscription auth path. The relay/API-key path never got this override, so Codex's shell-snapshot capture stayed enabled while the raw provider key sat in the process env — leaking it into run_dir/.../shell_snapshots/*.sh. Fixes #84
features.shell_snapshot=false is accepted but not honoured by openai-codex 0.147.0. On a live run the flag was present in the Codex process argv and Codex still wrote shell_snapshots/*.sh 11 minutes later containing the raw provider key twice per file, so disabling the capture is not a control we own. On relay paths Codex never needed the credential: start_relay already receives it for the upstream hop, Codex only talks to the relay, and that provider is already configured with requires_openai_auth=false. The child's copy is now overwritten with a placeholder once the relay holds the real key, so an environment capture has nothing to serialise. Verified on a live run: snapshots record the placeholder, no run artifact contains the key, and no authentication errors. needs_relay is true for 10 of 11 providers. The openai provider goes direct and still requires the real key in its environment, which is unchanged. The shell_snapshot override is retained as defence in depth in case a future Codex release honours it. Co-authored-by: Cursor <cursoragent@cursor.com>
5 of 6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Codex captures its own environment into
shell_snapshots/*.sh, and on relayprovider routes
_client_process_envputs the provider key into thatenvironment, so the key was written verbatim into run artifacts (#84).
features.shell_snapshot=false(#196) is applied on every auth path, butopenai-codex 0.147.0 accepts the flag and still writes snapshots. The effective
fix: once
start_relayholds the real key for the upstream hop, the child'scopy is replaced with a placeholder. Codex authenticates only against the relay
(
requires_openai_auth=false), so it never needed the credential. The flag iskept as defence in depth.
Refs #84
Scope
praxist/plugins/agent_runtimes/codex_sdk/adapter.pyand its unit tests. Nopublic contract change.
The direct
openairoute still needs the real key in the Codex environmentand is not changed here. Existing snapshots in old run directories are not
scrubbed.
by every task and provider route.
Verification
ruff check/ruff format --check— clean (461 files)pyrefly check— 0 errorspytest— 3365 passed, 7 skippedrun_test_coverage.py unit --fail-under 90 --fail-under-statements 95— exit 0(95.03% statements);
integration— exit 0all
succeeded.Could not be run: the direct
openairoute, which this change does not cover.Checklist
.github/CONTRIBUTING.mdand the contribution terms inLICENSE.md.