Use full access sandbox for NAS work mode

This commit is contained in:
2026-06-10 02:14:55 +09:00
parent 2b2ffd5d9d
commit 6918e18a87
3 changed files with 6 additions and 2 deletions

View File

@@ -18,7 +18,7 @@ CODEX_APP_SERVER_MODEL=gpt-5.5
CODEX_MODEL_REASONING_EFFORT=high CODEX_MODEL_REASONING_EFFORT=high
CODEX_SPEED_MODE=standard CODEX_SPEED_MODE=standard
CODEX_READONLY_SANDBOX=read-only CODEX_READONLY_SANDBOX=read-only
CODEX_WRITE_SANDBOX=workspace-write CODEX_WRITE_SANDBOX=danger-full-access
CODEX_RESUME_JSON_FLAG_STYLE=before_resume CODEX_RESUME_JSON_FLAG_STYLE=before_resume
# Optional: set this only if you want plain messages to behave like /ask. # Optional: set this only if you want plain messages to behave like /ask.

View File

@@ -39,6 +39,10 @@ Use `/work <prompt>` for write-capable tasks such as editing files, committing,
pushing, or opening pull requests. Plain text and `/ask` stay read-oriented by pushing, or opening pull requests. Plain text and `/ask` stay read-oriented by
default. default.
On Synology/NAS Docker deployments, keep `CODEX_WRITE_SANDBOX=danger-full-access`
for `/work`. The stricter `workspace-write` sandbox may fail with bubblewrap
namespace errors inside the container.
`/settings`, `/models`, `/schedules`, `/records`, and `/sessions` return inline `/settings`, `/models`, `/schedules`, `/records`, and `/sessions` return inline
buttons, so you can change speed/model/reasoning settings, delete schedules, buttons, so you can change speed/model/reasoning settings, delete schedules,
manage personal records, and switch or archive sessions without copying ids. manage personal records, and switch or archive sessions without copying ids.

View File

@@ -28,7 +28,7 @@ BOT_WORKSPACE_ROOT=$WorkspaceRoot
CODEX_BIN=codex CODEX_BIN=codex
CODEX_TIMEOUT_SECONDS=1800 CODEX_TIMEOUT_SECONDS=1800
CODEX_READONLY_SANDBOX=read-only CODEX_READONLY_SANDBOX=read-only
CODEX_WRITE_SANDBOX=workspace-write CODEX_WRITE_SANDBOX=danger-full-access
CODEX_RESUME_JSON_FLAG_STYLE=before_resume CODEX_RESUME_JSON_FLAG_STYLE=before_resume
ALLOW_PLAIN_TEXT=true ALLOW_PLAIN_TEXT=true
"@ | Set-Content -Path $envPath -Encoding UTF8 "@ | Set-Content -Path $envPath -Encoding UTF8