|
193 | 193 | "enum": ["user", "auto_review", "guardian_subagent"] |
194 | 194 | }, |
195 | 195 | "serviceTier": { "type": ["string", "null"] }, |
| 196 | + "networkProxy": { |
| 197 | + "type": "object", |
| 198 | + "additionalProperties": false, |
| 199 | + "properties": { |
| 200 | + "enabled": { |
| 201 | + "type": "boolean", |
| 202 | + "default": false |
| 203 | + }, |
| 204 | + "profileName": { "type": "string" }, |
| 205 | + "baseProfile": { |
| 206 | + "type": "string", |
| 207 | + "enum": ["read-only", "workspace"] |
| 208 | + }, |
| 209 | + "mode": { |
| 210 | + "type": "string", |
| 211 | + "enum": ["limited", "full"] |
| 212 | + }, |
| 213 | + "domains": { |
| 214 | + "type": "object", |
| 215 | + "additionalProperties": { |
| 216 | + "type": "string", |
| 217 | + "enum": ["allow", "deny"] |
| 218 | + } |
| 219 | + }, |
| 220 | + "unixSockets": { |
| 221 | + "type": "object", |
| 222 | + "additionalProperties": { |
| 223 | + "type": "string", |
| 224 | + "enum": ["allow", "deny"] |
| 225 | + } |
| 226 | + }, |
| 227 | + "proxyUrl": { "type": "string" }, |
| 228 | + "socksUrl": { "type": "string" }, |
| 229 | + "enableSocks5": { "type": "boolean" }, |
| 230 | + "enableSocks5Udp": { "type": "boolean" }, |
| 231 | + "allowUpstreamProxy": { "type": "boolean" }, |
| 232 | + "allowLocalBinding": { "type": "boolean" }, |
| 233 | + "dangerouslyAllowNonLoopbackProxy": { "type": "boolean" }, |
| 234 | + "dangerouslyAllowAllUnixSockets": { "type": "boolean" } |
| 235 | + } |
| 236 | + }, |
196 | 237 | "defaultWorkspaceDir": { |
197 | 238 | "type": "string" |
198 | 239 | }, |
|
385 | 426 | "help": "Optional Codex app-server service tier. Use priority, flex, or null. Legacy fast is accepted as priority.", |
386 | 427 | "advanced": true |
387 | 428 | }, |
| 429 | + "appServer.networkProxy": { |
| 430 | + "label": "Network Proxy", |
| 431 | + "help": "Enable Codex permissions-profile networking for app-server commands.", |
| 432 | + "advanced": true |
| 433 | + }, |
| 434 | + "appServer.networkProxy.enabled": { |
| 435 | + "label": "Network Proxy Enabled", |
| 436 | + "help": "When enabled, OpenClaw defines a Codex permissions profile and selects it on thread start or resume instead of sandbox fields.", |
| 437 | + "advanced": true |
| 438 | + }, |
| 439 | + "appServer.networkProxy.profileName": { |
| 440 | + "label": "Network Proxy Profile", |
| 441 | + "help": "Codex permissions profile name generated for app-server network access.", |
| 442 | + "advanced": true |
| 443 | + }, |
| 444 | + "appServer.networkProxy.baseProfile": { |
| 445 | + "label": "Network Proxy Base", |
| 446 | + "help": "Filesystem access used by the generated profile. Defaults to read-only for read-only sandboxes and workspace otherwise.", |
| 447 | + "advanced": true |
| 448 | + }, |
| 449 | + "appServer.networkProxy.domains": { |
| 450 | + "label": "Network Domains", |
| 451 | + "help": "Domain allow and deny rules for Codex sandboxed networking.", |
| 452 | + "advanced": true |
| 453 | + }, |
| 454 | + "appServer.networkProxy.unixSockets": { |
| 455 | + "label": "Unix Sockets", |
| 456 | + "help": "Unix socket allow and deny rules for Codex sandboxed networking.", |
| 457 | + "advanced": true |
| 458 | + }, |
| 459 | + "appServer.networkProxy.proxyUrl": { |
| 460 | + "label": "HTTP Proxy URL", |
| 461 | + "help": "HTTP listener URL used by Codex sandboxed networking.", |
| 462 | + "advanced": true |
| 463 | + }, |
| 464 | + "appServer.networkProxy.socksUrl": { |
| 465 | + "label": "SOCKS Proxy URL", |
| 466 | + "help": "SOCKS listener URL used by Codex sandboxed networking.", |
| 467 | + "advanced": true |
| 468 | + }, |
| 469 | + "appServer.networkProxy.enableSocks5": { |
| 470 | + "label": "Enable SOCKS5", |
| 471 | + "help": "Expose SOCKS5 support for the generated Codex permissions profile.", |
| 472 | + "advanced": true |
| 473 | + }, |
| 474 | + "appServer.networkProxy.enableSocks5Udp": { |
| 475 | + "label": "Enable SOCKS5 UDP", |
| 476 | + "help": "Allow UDP over the SOCKS5 listener when SOCKS5 is enabled.", |
| 477 | + "advanced": true |
| 478 | + }, |
| 479 | + "appServer.networkProxy.allowUpstreamProxy": { |
| 480 | + "label": "Allow Upstream Proxy", |
| 481 | + "help": "Allow Codex sandboxed networking to chain through inherited HTTP(S)_PROXY or ALL_PROXY settings.", |
| 482 | + "advanced": true |
| 483 | + }, |
| 484 | + "appServer.networkProxy.allowLocalBinding": { |
| 485 | + "label": "Allow Local Binding", |
| 486 | + "help": "Permit broader local and private-network access through Codex sandboxed networking.", |
| 487 | + "advanced": true |
| 488 | + }, |
| 489 | + "appServer.networkProxy.mode": { |
| 490 | + "label": "Network Mode", |
| 491 | + "help": "Codex sandboxed networking mode for subprocess traffic.", |
| 492 | + "advanced": true |
| 493 | + }, |
| 494 | + "appServer.networkProxy.dangerouslyAllowNonLoopbackProxy": { |
| 495 | + "label": "Allow Non-Loopback Proxy", |
| 496 | + "help": "Permit non-loopback bind addresses for Codex sandboxed networking listeners.", |
| 497 | + "advanced": true |
| 498 | + }, |
| 499 | + "appServer.networkProxy.dangerouslyAllowAllUnixSockets": { |
| 500 | + "label": "Allow All Unix Sockets", |
| 501 | + "help": "Bypass Codex's Unix socket allowlist for tightly controlled environments.", |
| 502 | + "advanced": true |
| 503 | + }, |
388 | 504 | "appServer.defaultWorkspaceDir": { |
389 | 505 | "label": "Default Workspace", |
390 | 506 | "help": "Workspace used by /codex bind when --cwd is omitted.", |
|
0 commit comments