diff --git a/packages/primitives/src/agent-os.test.ts b/packages/primitives/src/agent-os.test.ts index ae84cea..5e0c996 100644 --- a/packages/primitives/src/agent-os.test.ts +++ b/packages/primitives/src/agent-os.test.ts @@ -9,6 +9,11 @@ describe("Codex agent-os config", () => { expect(config.software?.[0]).toBeTypeOf("object"); }); + it("allows outbound VM networking", () => { + const config = makeCodexAgentOsConfig(); + expect(config.permissions?.network).toBe("allow"); + }); + it("builds model-provider session env", () => { const env = codexSessionEnv( { diff --git a/packages/primitives/src/agent-os.ts b/packages/primitives/src/agent-os.ts index 176941f..163abe6 100644 --- a/packages/primitives/src/agent-os.ts +++ b/packages/primitives/src/agent-os.ts @@ -108,16 +108,22 @@ export const codexSessionEnv = ( export interface CodexAgentOsConfigInput { /** Extra software merged after the Codex+git bundle. */ readonly software?: NonNullable["software"]>; + /** VM permission overrides merged over the default network-enabled policy. */ + readonly permissions?: AgentOSConfigInput["permissions"]; } /** - * Builds an AgentOS actor config for a Codex-backed VM. The Codex CLI and git * are always present; software the caller passes is appended, never replacing - * the harness or git. Model-provider env is supplied per session via + * the harness or git. Outbound networking is explicitly enabled for repository + * and model-provider access. Model-provider env is supplied per session via * `codexSessionEnv`, not here — the actor config has no env field. */ export const makeCodexAgentOsConfig = ( input: CodexAgentOsConfigInput = {} ): AgentOSConfigInput => ({ + permissions: { + network: "allow", + ...input.permissions, + }, software: [...codexSoftware, ...(input.software ?? [])], });