Skip to content

security: enforce authority and pin browser egress - #8

Merged
AetherAI3 merged 11 commits into
mainfrom
codex/security
Sep 1, 2026
Merged

AetherAI3 merged 11 commits into
mainfrom
codex/security

Conversation

@AetherAI3

@AetherAI3 AetherAI3 commented Sep 1, 2026 •

Copy link
Copy Markdown
Owner

Scope

Integrates fail-closed API authority and browser navigation policy, then removes the browser-side
DNS time-of-check/time-of-use gap with a per-session pinned egress proxy.

Exact candidate head: 3efaa528a18fb7dd60a85a4b395bd7d5e7f31936

Security properties

  • Observer/controller bearer roles with duplicate-header rejection and fail-closed startup checks.
  • HTTP(S), redirect, subresource, WS, and WSS destinations authorized before connection.
  • Reviewed special-use IPv4/IPv6 ranges denied conservatively.
  • DNS answers published as immutable (host, port) -> numeric addresses connection plans.
  • Loopback-only SOCKS5 proxy performs numeric-only dials and never resolves DNS.
  • Unknown hosts, wrong ports, changed DNS answers, malformed SOCKS frames, excess concurrency,
    oversized buffers, and timeout paths fail closed.
  • Chrome is forced through the proxy with direct bypass, browser DNS, QUIC, and HTTP/2 disabled.
  • Chromium disables non-proxied WebRTC UDP so WebRTC cannot bypass the pinned TCP boundary.
  • Proxy/session cleanup is bounded and cancellation-drained.
  • The actual API socket remains numeric loopback; authenticated remote clients are supported only
    through a complete same-host HTTPS proxy tuple with an exact loopback peer.
  • Forwarding headers are rejected, Host and raw peer are validated, and Uvicorn proxy-header
    interpretation plus the unsafe import-string application entrypoint are disabled.
  • Injected authority callbacks are additive only; the complete core request boundary always runs
    first and cannot be replaced by a no-op test callback.

Validation state

Local Python execution is intentionally disabled while the workstation is under a guarded memory
floor. The bounded hosted validator is the execution gate for hash-locked install, formatting,
lint, strict type checking, and tests. Independent adversarial exact-head review is also required.

Ready evidence

  • Pull-request validation run 33521141440 passed the exact candidate head.
  • Hash-locked install, formatting, lint, strict type checking, and all 293 tests passed.
  • Independent adversarial exact-head review reported no unresolved CRITICAL, HIGH, MEDIUM, or LOW
    finding.

Container/noVNC acceptance remains a separate integration lane and is not claimed here.

@AetherAI3
AetherAI3 marked this pull request as ready for review September 1, 2026 14:44
@AetherAI3
AetherAI3 merged commit 8c2ab07 into main Sep 1, 2026
2 checks passed
@AetherAI3
AetherAI3 deleted the codex/security branch September 1, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant