openclaw/docs/gateway
Josh Avant ba06376c79
fix: harden codex sandbox execution
Harden the Codex app-server native execution bridge for OpenClaw sandboxed runs. The change keeps core sandbox policy in OpenClaw while exposing the process, filesystem, and HTTP relay behavior Codex needs inside a scoped exec server.

The large exec-server/test files were split into focused modules before landing, and the PR was rebased onto current main with focused tests, Testbox changed checks, CI, and Codex autoreview green.

Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com>
2026-05-21 23:47:32 +01:00
..
security fix(gateway): allow bearer-auth session history reads (#81815) 2026-05-21 13:23:17 -07:00
authentication.md Fix gateway auth logout aborting active runs (#82346) 2026-05-15 18:36:49 -05:00
background-process.md feat(process): show input-wait hints in log and poll 2026-05-10 04:13:07 -04:00
bonjour.md fix(gateway): honor minimal discovery mode for wide-area DNS-SD [AI] (#80903) 2026-05-12 16:03:50 +05:30
bridge-protocol.md
cli-backends.md Remove codex-cli backend and migrate to Codex runtime 2026-05-14 10:07:18 +01:00
config-agents.md Add OpenRouter provider routing params (#84579) 2026-05-20 23:27:34 +10:00
config-channels.md fix(discord): cap component ttl at one day 2026-05-21 21:54:30 +01:00
config-tools.md fix(doctor): warn when sandbox hides MCP tools (#84742) 2026-05-21 03:28:27 +00:00
configuration-examples.md fix(messages): keep group visible replies automatic by default (#83498) 2026-05-18 09:48:58 +01:00
configuration-reference.md feat: add native mac dashboard window 2026-05-16 23:49:18 +01:00
configuration.md fix(messages): keep group visible replies automatic by default (#83498) 2026-05-18 09:48:58 +01:00
diagnostics.md fix(gateway): capture opt-in memory pressure snapshots (#82674) 2026-05-16 21:52:09 +01:00
discovery.md
doctor.md fix(auth): load legacy Codex OAuth sidecars in embedded secrets-runtime loaders (#85074) 2026-05-21 13:07:49 -07:00
gateway-lock.md Revert "refactor: move runtime state to SQLite" 2026-05-13 13:33:38 +01:00
health.md fix(gateway): capture opt-in memory pressure snapshots (#82674) 2026-05-16 21:52:09 +01:00
heartbeat.md Move Codex soul context to developer instructions (#84331) 2026-05-19 16:47:32 -07:00
index.md fix(webchat): show manual compaction progress 2026-05-16 13:58:44 +01:00
local-model-services.md docs: add ds4 provider guide 2026-05-13 14:45:34 +01:00
local-models.md fix: clarify provider timeout ceiling 2026-05-16 01:08:07 +01:00
logging.md Revert "refactor: move runtime state to SQLite" 2026-05-13 13:33:38 +01:00
multiple-gateways.md
network-model.md
openai-http-api.md fix(gateway): allow trusted-proxy local-direct password fallback (#82953) 2026-05-17 01:35:59 -05:00
openresponses-http-api.md fix(gateway): allow trusted-proxy local-direct password fallback (#82953) 2026-05-17 01:35:59 -05:00
openshell.md build: externalize slack openshell vertex plugins 2026-05-14 07:46:58 +01:00
opentelemetry.md fix(status): add gateway delivery health telemetry (#85016) 2026-05-21 16:55:29 +00:00
operator-scopes.md fix(gateway): allow bearer-auth session history reads (#81815) 2026-05-21 13:23:17 -07:00
pairing.md fix(gateway): allow trusted-proxy local-direct password fallback (#82953) 2026-05-17 01:35:59 -05:00
prometheus.md fix(status): add gateway delivery health telemetry (#85016) 2026-05-21 16:55:29 +00:00
protocol.md [codex] restore QR bootstrap operator handoff (#83684) 2026-05-19 20:59:09 +03:00
remote-gateway-readme.md
remote.md feat: add native mac dashboard window 2026-05-16 23:49:18 +01:00
sandbox-vs-tool-policy-vs-elevated.md fix(doctor): warn when sandbox hides MCP tools (#84742) 2026-05-21 03:28:27 +00:00
sandboxing.md fix: harden codex sandbox execution 2026-05-21 23:47:32 +01:00
secrets-plan-contract.md Revert "refactor: move runtime state to SQLite" 2026-05-13 13:33:38 +01:00
secrets.md fix(secrets): treat env refs as audit-safe auth values 2026-05-17 00:05:10 +01:00
tailscale.md
tools-invoke-http-api.md fix(gateway): allow trusted-proxy local-direct password fallback (#82953) 2026-05-17 01:35:59 -05:00
troubleshooting.md fix: improve gateway protocol mismatch diagnostics (#82908) 2026-05-17 06:33:34 +01:00
trusted-proxy-auth.md fix(gateway): allow trusted-proxy local-direct password fallback (#82953) 2026-05-17 01:35:59 -05:00