diff --git a/packages/paperclip-runner/src/drivers/acpx/runtime-sandbox.test.ts b/packages/paperclip-runner/src/drivers/acpx/runtime-sandbox.test.ts index f11bfe067b..cd3eb07e8d 100644 --- a/packages/paperclip-runner/src/drivers/acpx/runtime-sandbox.test.ts +++ b/packages/paperclip-runner/src/drivers/acpx/runtime-sandbox.test.ts @@ -88,10 +88,7 @@ describe("ACPX runtime sandbox", () => { join(sandbox.agentHomeDirectory, "config.toml"), "utf8", ); - expect(config).toContain("shell_snapshot = false"); - expect(config).toContain( - 'exclude = ["OPENAI_API_KEY", "CODEX_API_KEY"]', - ); + expect(config).toBe("[features]\nshell_snapshot = false\n"); expect(config).not.toContain("provider-secret"); } expect(await readFile(sandbox.workspaceRecordPath, "utf8")).toBe( diff --git a/packages/paperclip-runner/src/drivers/acpx/runtime-sandbox.ts b/packages/paperclip-runner/src/drivers/acpx/runtime-sandbox.ts index 1bae88ec1d..3b4069507e 100644 --- a/packages/paperclip-runner/src/drivers/acpx/runtime-sandbox.ts +++ b/packages/paperclip-runner/src/drivers/acpx/runtime-sandbox.ts @@ -383,14 +383,12 @@ export async function prepareAcpxRuntimeSandbox(input: { // Codex shell snapshots serialize the provider process environment. // The ACPX sidecar receives a short-lived managed credential only so // it can authenticate the provider; that value must never become - // durable runtime state or enter a model-invoked shell. + // durable runtime state. Keep this identical to the proven native + // Codex isolation policy: broader shell-environment filtering can + // also affect provider startup and belongs at the launch boundary. "[features]", "shell_snapshot = false", "", - "[shell_environment_policy]", - 'exclude = ["OPENAI_API_KEY", "CODEX_API_KEY"]', - "ignore_default_excludes = false", - "", ].join("\n"), ); } diff --git a/tests/runner-e2e/redaction.ts b/tests/runner-e2e/redaction.ts index 5c42e529c6..e07adb402c 100644 --- a/tests/runner-e2e/redaction.ts +++ b/tests/runner-e2e/redaction.ts @@ -30,6 +30,9 @@ export function isEphemeralCodexRuntimeAuthFile( ) || /^instances\/[^/]+\/runtime\/paperclip-runner\/durable-sessions\/[^/]+\/codex-home\/auth\.json$/.test( relative, + ) || + /^instances\/[^/]+\/runtime\/paperclip-runner\/acpx\/acpx\/[^/]+\/codex-home\/auth\.json$/.test( + relative, ) ); } diff --git a/tests/runner-e2e/support.test.ts b/tests/runner-e2e/support.test.ts index e310b98640..e458566a6e 100644 --- a/tests/runner-e2e/support.test.ts +++ b/tests/runner-e2e/support.test.ts @@ -677,7 +677,7 @@ describe("runner E2E evidence redaction", () => { ).resolves.toMatchObject({ file: forbiddenConfig }); }); - it("recognizes both managed and durable-session Codex runtime auth files", () => { + it("recognizes managed and durable Codex runtime auth files", () => { const root = path.join(os.tmpdir(), "paperclip-home"); expect( isEphemeralCodexRuntimeAuthFile( @@ -688,6 +688,15 @@ describe("runner E2E evidence redaction", () => { ), ), ).toBe(true); + expect( + isEphemeralCodexRuntimeAuthFile( + root, + path.join( + root, + "instances/instance-1/runtime/paperclip-runner/acpx/acpx/session-1/codex-home/auth.json", + ), + ), + ).toBe(true); expect( isEphemeralCodexRuntimeAuthFile( root,