{"title":"Selecting MXC Alone Does Not Restrict Networking in Codex 0.162.1","description":"Codex 0.162.1’s release-tagged source distinguishes backend preference, operation-level sandbox selection and generated policy. MXC selection alone does not establish restricted networking: a network-enabled permission profile without managed networking generates allow defaults for egress, ingress and host loopback.","dataset_id":"spd:which-codex-windows-configurations-actually-enforce-mxc-boundaries-f87e2b47","canonical_url":"https://superpowerdaily.com/research/which-codex-windows-configurations-actually-enforce-mxc-boundaries-f87e2b47","version_url":"https://superpowerdaily.com/research/which-codex-windows-configurations-actually-enforce-mxc-boundaries-f87e2b47","version":"Live","snapshot_hash":null,"date_created":null,"date_modified":"2026-10-10T02:38:44.789Z","license":{"name":"Superpower Daily data reuse terms","url":"https://superpowerdaily.com/terms"},"license_url":"https://superpowerdaily.com/terms","coverage_note":"The sample covers two listed releases, not all publicly released Codex versions. Detailed launch and network tracing applies only to 0.162.1; prerelease tracing covers selection controls only. The supplied release-index snapshot was retrieved at 20:32:23.998 UTC, after the original cutoff, although its listed release timestamps precede that cutoff.","measurement_technique":["Reassess saved evidence only, preserving the original collection cutoff of October 9, 2026, 20:31:10.299 UTC. This synthesis is not a new collection, experiment or runtime test.","Use the bounded sample identified in the supplied release-index snapshot: latest listed stable 0.162.1 and latest listed prerelease 0.163.0-alpha.4 available before cutoff. Trace selection, launch and network-policy generation for 0.162.1; trace selection controls only for 0.163.0-alpha.4.","Plan an evidence_matrix with columns for version, configuration or operation condition, selected backend, generated network policy or rejection, evidence reference and scope qualification. Use categorical findings rather than a quantitative chart.","Matrix row — 0.162.1, explicit windows.sandbox=\"mxc\": selects WindowsMxc subject to configuration constraints. Elevated and unelevated select the legacy restricted-token backend unless resolved MXC preference overrides them. Backend configuration does not establish that every operation enters a sandbox. Evidence: claim-02.","Matrix row — 0.162.1, features.prefer_mxc: automatic selection requires the feature, configuration eligibility and native availability. Otherwise the configured backend remains, potentially legacy containment or None. Effective local-binding restrictions matter, and managed network requirements outrank feature/profile binding values. Evidence: claim-03.","Matrix row — 0.162.1, operation-level selection: Forbid returns no sandbox; Require requests one; Auto evaluates filesystem, network and managed-network requirements before honoring WindowsMxc. This is not an audit of every caller or approval path. Evidence: claim-04.","Matrix row — 0.162.1, actual MXC invocation without managed networking: network-disabled profiles generate deny defaults for egress, ingress and host loopback; network-enabled profiles generate allow defaults for those categories. Packet-level enforcement was not tested. Evidence: claims-05 and -06.","Matrix row — 0.162.1, managed networking: requires an executor-local proxy context, dedicated nonzero proxy ports and allow_local_binding=true. Generated native policy denies non-loopback traffic by default but permits loopback ranges without port restrictions. It is not a native proxy-port-only loopback boundary. Evidence: claim-07. Source: https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/policy.rs . Other launch and validation evidence appears in the saved "],"methodology":["Reassess saved evidence only, preserving the original collection cutoff of October 9, 2026, 20:31:10.299 UTC. This synthesis is not a new collection, experiment or runtime test.","Use the bounded sample identified in the supplied release-index snapshot: latest listed stable 0.162.1 and latest listed prerelease 0.163.0-alpha.4 available before cutoff. Trace selection, launch and network-policy generation for 0.162.1; trace selection controls only for 0.163.0-alpha.4.","Plan an evidence_matrix with columns for version, configuration or operation condition, selected backend, generated network policy or rejection, evidence reference and scope qualification. Use categorical findings rather than a quantitative chart.","Matrix row — 0.162.1, explicit windows.sandbox=\"mxc\": selects WindowsMxc subject to configuration constraints. Elevated and unelevated select the legacy restricted-token backend unless resolved MXC preference overrides them. Backend configuration does not establish that every operation enters a sandbox. Evidence: claim-02.","Matrix row — 0.162.1, features.prefer_mxc: automatic selection requires the feature, configuration eligibility and native availability. Otherwise the configured backend remains, potentially legacy containment or None. Effective local-binding restrictions matter, and managed network requirements outrank feature/profile binding values. Evidence: claim-03.","Matrix row — 0.162.1, operation-level selection: Forbid returns no sandbox; Require requests one; Auto evaluates filesystem, network and managed-network requirements before honoring WindowsMxc. This is not an audit of every caller or approval path. Evidence: claim-04.","Matrix row — 0.162.1, actual MXC invocation without managed networking: network-disabled profiles generate deny defaults for egress, ingress and host loopback; network-enabled profiles generate allow defaults for those categories. Packet-level enforcement was not tested. Evidence: claims-05 and -06.","Matrix row — 0.162.1, managed networking: requires an executor-local proxy context, dedicated nonzero proxy ports and allow_local_binding=true. Generated native policy denies non-loopback traffic by default but permits loopback ranges without port restrictions. It is not a native proxy-port-only loopback boundary. Evidence: claim-07. Source: https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/policy.rs . Other launch and validation evidence appears in the saved "],"metrics":[{"label":"Verified observations","value":"0","detail":"0 measured fields"},{"label":"Supported claims","value":"9","detail":"9 material findings"},{"label":"Cited sources","value":"10","detail":"10 primary or authoritative"},{"label":"Research score","value":"79","detail":"Automated topic and evidence score"}],"columns":[{"key":"entity","label":"Entity"},{"key":"metric","label":"Metric"},{"key":"value","label":"Value"},{"key":"unit","label":"Unit"},{"key":"observed","label":"Observed"},{"key":"source","label":"Source"},{"key":"transform","label":"Transform"}],"data":[],"sources":[{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/native.rs","records":0},{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/sandboxing/src/manager.rs","records":0},{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/policy.rs","records":0},{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/lib.rs","records":0},{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.163.0-alpha.4/codex-rs/core/src/config/mod.rs","records":0},{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.163.0-alpha.4/codex-rs/core/src/config/windows_sandbox_config.rs","records":0},{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.163.0-alpha.4/codex-rs/config/src/config_requirements.rs","records":0},{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/core/src/config/mod.rs","records":0},{"name":"OpenAI","title":"raw.githubusercontent.com","url":"https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/core/src/config/windows_sandbox_config.rs","records":0},{"name":"OpenAI","title":"Releases · openai/codex","url":"https://github.com/openai/codex/releases","records":0}],"provenance":{"publisher":"Superpower Daily","source_count":10,"source_urls":["https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/native.rs","https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/sandboxing/src/manager.rs","https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/policy.rs","https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/lib.rs","https://raw.githubusercontent.com/openai/codex/rust-v0.163.0-alpha.4/codex-rs/core/src/config/mod.rs","https://raw.githubusercontent.com/openai/codex/rust-v0.163.0-alpha.4/codex-rs/core/src/config/windows_sandbox_config.rs","https://raw.githubusercontent.com/openai/codex/rust-v0.163.0-alpha.4/codex-rs/config/src/config_requirements.rs","https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/core/src/config/mod.rs","https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/core/src/config/windows_sandbox_config.rs","https://github.com/openai/codex/releases"],"methodology":["Reassess saved evidence only, preserving the original collection cutoff of October 9, 2026, 20:31:10.299 UTC. This synthesis is not a new collection, experiment or runtime test.","Use the bounded sample identified in the supplied release-index snapshot: latest listed stable 0.162.1 and latest listed prerelease 0.163.0-alpha.4 available before cutoff. Trace selection, launch and network-policy generation for 0.162.1; trace selection controls only for 0.163.0-alpha.4.","Plan an evidence_matrix with columns for version, configuration or operation condition, selected backend, generated network policy or rejection, evidence reference and scope qualification. Use categorical findings rather than a quantitative chart.","Matrix row — 0.162.1, explicit windows.sandbox=\"mxc\": selects WindowsMxc subject to configuration constraints. Elevated and unelevated select the legacy restricted-token backend unless resolved MXC preference overrides them. Backend configuration does not establish that every operation enters a sandbox. Evidence: claim-02.","Matrix row — 0.162.1, features.prefer_mxc: automatic selection requires the feature, configuration eligibility and native availability. Otherwise the configured backend remains, potentially legacy containment or None. Effective local-binding restrictions matter, and managed network requirements outrank feature/profile binding values. Evidence: claim-03.","Matrix row — 0.162.1, operation-level selection: Forbid returns no sandbox; Require requests one; Auto evaluates filesystem, network and managed-network requirements before honoring WindowsMxc. This is not an audit of every caller or approval path. Evidence: claim-04.","Matrix row — 0.162.1, actual MXC invocation without managed networking: network-disabled profiles generate deny defaults for egress, ingress and host loopback; network-enabled profiles generate allow defaults for those categories. Packet-level enforcement was not tested. Evidence: claims-05 and -06.","Matrix row — 0.162.1, managed networking: requires an executor-local proxy context, dedicated nonzero proxy ports and allow_local_binding=true. Generated native policy denies non-loopback traffic by default but permits loopback ranges without port restrictions. It is not a native proxy-port-only loopback boundary. Evidence: claim-07. Source: https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/policy.rs . Other launch and validation evidence appears in the saved "],"snapshot_hash":null},"distributions":{"csv":"https://superpowerdaily.com/api/research/which-codex-windows-configurations-actually-enforce-mxc-boundaries-f87e2b47?format=csv","json":"https://superpowerdaily.com/api/research/which-codex-windows-configurations-actually-enforce-mxc-boundaries-f87e2b47?format=json"}}