Skip to content

Selected profile cannot relax a root approval_policy = "never" #528

Description

@sylvesterkaczmarek

Summary

scanApprovalPolicy() does not use the same selected-profile precedence as the other effective Codex settings.

Model, reasoning effort, and provider resolution all prefer an explicitly configured value in the selected profile over the root value. Approval policy instead computes:

return config["approval_policy"] === "never" ||
  selectedScanProfile(config)?.["approval_policy"] === "never"
  ? "never"
  : "on-request";

If the root config says approval_policy = "never" and the selected profile explicitly says approval_policy = "on-request", this returns "never" rather than the selected profile's value.

Impact

This is not display-only. The resolved value is passed to codex.startThread({ approvalPolicy }), written into the scan recipe/preflight configuration, and projected into scanRuntimeCodexConfig().

A selected profile therefore cannot restore on-request approvals when the root config is more restrictive, even though profile-specific model/provider settings already override their root counterparts.

Expected behavior

If the selected profile has its own approval_policy, resolve that value first. Otherwise fall back to the root setting. Codex Security only needs to distinguish the supported never and on-request outcomes.

Suggested fix

Mirror scanModelProvider()/scanModelConfiguration() precedence for approval_policy, and add regression cases for both directions:

  • root never, selected profile on-request -> on-request;
  • root on-request, selected profile never -> never.

Activity

  1. mldangelo-oai commented on Oct 8, 2026

    @mldangelo-oai
    Collaborator

    #939 and #1103 also contain the selected-profile approval-policy fix. Both are still open, so it hasn’t reached main.

  2. added
    area:configProject configuration, profiles, schemas, and effective scan settings.
    area:sandboxExecution permissions, isolation, trusted paths, and filesystem access controls.
    bugSomething isn't working
    on Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:configProject configuration, profiles, schemas, and effective scan settings.area:sandboxExecution permissions, isolation, trusted paths, and filesystem access controls.bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions