Skip to content

fix(codex_sdk): keep provider credentials out of Codex run artifacts - #203

Merged
Glen-SP merged 2 commits into
mainfrom
validation/credential-redaction
Sep 23, 2026
Merged

Glen-SP merged 2 commits into
mainfrom
validation/credential-redaction

Conversation

@Glen-SP

@Glen-SP Glen-SP commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator

Summary

Codex captures its own environment into shell_snapshots/*.sh, and on relay
provider routes _client_process_env puts the provider key into that
environment, so the key was written verbatim into run artifacts (#84).

features.shell_snapshot=false (#196) is applied on every auth path, but
openai-codex 0.147.0 accepts the flag and still writes snapshots. The effective
fix: once start_relay holds the real key for the upstream hop, the child's
copy is replaced with a placeholder. Codex authenticates only against the relay
(requires_openai_auth=false), so it never needed the credential. The flag is
kept as defence in depth.

Refs #84

Scope

  • Affected modules or public contracts:
    praxist/plugins/agent_runtimes/codex_sdk/adapter.py and its unit tests. No
    public contract change.
  • Compatibility considerations: relay routes (10 of 11 providers) are covered.
    The direct openai route still needs the real key in the Codex environment
    and is not changed here. Existing snapshots in old run directories are not
    scrubbed.
  • Task-agnostic rationale: credential handling in the runtime adapter is shared
    by every task and provider route.

Verification

Check Before After
Flag present in Codex argv yes yes
Snapshots written yes yes (flag ignored)
Snapshots containing the real key all 0
Run artifacts containing the real key ≥ 2 per run 0 across 8 runs
  • ruff check / ruff format --check — clean (461 files)
  • pyrefly check — 0 errors
  • pytest — 3365 passed, 7 skipped
  • run_test_coverage.py unit --fail-under 90 --fail-under-statements 95 — exit 0
    (95.03% statements); integration — exit 0
  • The new test fails when the placeholder assignment is reverted.
  • Real tasks on this branch: 3 MLE-bench runs (2 gold) and 4 reference tasks,
    all succeeded.

Could not be run: the direct openai route, which this change does not cover.

Checklist

  • The change is focused and does not include unrelated generated files.
  • Tests cover the affected behavior.
  • Documentation, templates, examples, and skills were updated where needed.
  • No credentials, private task data, or research-run artifacts are included.
  • New dependencies and copied assets include their source and license terms.
  • I have read .github/CONTRIBUTING.md and the contribution terms in LICENSE.md.

SaraAbidHussain and others added 2 commits September 16, 2026 16:11
features.shell_snapshot=false was only applied for the ChatGPT
subscription auth path. The relay/API-key path never got this
override, so Codex's shell-snapshot capture stayed enabled while
the raw provider key sat in the process env — leaking it into
run_dir/.../shell_snapshots/*.sh.

Fixes #84
features.shell_snapshot=false is accepted but not honoured by openai-codex
0.147.0. On a live run the flag was present in the Codex process argv and Codex
still wrote shell_snapshots/*.sh 11 minutes later containing the raw provider key
twice per file, so disabling the capture is not a control we own.

On relay paths Codex never needed the credential: start_relay already receives it
for the upstream hop, Codex only talks to the relay, and that provider is already
configured with requires_openai_auth=false. The child's copy is now overwritten
with a placeholder once the relay holds the real key, so an environment capture
has nothing to serialise. Verified on a live run: snapshots record the
placeholder, no run artifact contains the key, and no authentication errors.

needs_relay is true for 10 of 11 providers. The openai provider goes direct and
still requires the real key in its environment, which is unchanged.

The shell_snapshot override is retained as defence in depth in case a future
Codex release honours it.

Co-authored-by: Cursor <cursoragent@cursor.com>
@Glen-SP
Glen-SP merged commit 5b50658 into main Sep 23, 2026
7 checks passed
@Glen-SP
Glen-SP deleted the validation/credential-redaction branch September 23, 2026 07:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants