Research investigation R1009 / claim audit

Selecting MXC Alone Does Not Restrict Networking in Codex 0.162.1

Codex 0.162.1’s release-tagged source distinguishes backend preference, operation-level sandbox selection and generated policy. MXC selection alone does not establish restricted networking: a network-enabled permission profile without managed networking generates allow defaults for egress, ingress and host loopback.

Current public editionOct 10, 2026Oct 10, 2026
Verified observations
0

0 measured fields

Supported claims
9

9 material findings

Cited sources
10

10 primary or authoritative

Research score
79

Automated topic and evidence score

Interactive figureSelecting MXC Alone Does Not Restrict Networking...
CSV JSON
Data statusAwaiting verified observations

The sample covers two listed releases, not all publicly released Codex versions. Detailed launch and network tracing applies only to 0.162.1; prerelease tracing covers selection controls only. The supplied release-index snapshot was retrieved at 20:32:23.998 UTC, after the original cutoff, although its listed release timestamps precede that cutoff.

Verified observationNo chart values are being inferredLast updated Oct 10, 2026
Coverage note

The sample covers two listed releases, not all publicly released Codex versions. Detailed launch and network tracing applies only to 0.162.1; prerelease tracing covers selection controls only. The supplied release-index snapshot was retrieved at 20:32:23.998 UTC, after the original cutoff, although its listed release timestamps precede that cutoff.

Dataset ID
spd:which-codex-windows-configurations-actually-enforce-mxc-boundaries-f87e2b47
Stable URL
/research/which-codex-windows-configurations-actually-enforce-mxc-boundaries-f87e2b47
Version
Live
Coverage
Live collection
Records
0
Fields
7
Updated

Read the data

The records behind the figure

CSV JSON
Selecting MXC Alone Does Not Restrict Networking in Codex 0.162.1 data records
EntityMetricValueUnitObservedSourceTransform

Measurement technique

How to read this report

  1. 01Reassess saved evidence only, preserving the original collection cutoff of October 9, 2026, 20:31:10.299 UTC. This synthesis is not a new collection, experiment or runtime test.
  2. 02Use the bounded sample identified in the supplied release-index snapshot: latest listed stable 0.162.1 and latest listed prerelease 0.163.0-alpha.4 available before cutoff. Trace selection, launch and network-policy generation for 0.162.1; trace selection controls only for 0.163.0-alpha.4.
  3. 03Plan an evidence_matrix with columns for version, configuration or operation condition, selected backend, generated network policy or rejection, evidence reference and scope qualification. Use categorical findings rather than a quantitative chart.
  4. 04Matrix row — 0.162.1, explicit windows.sandbox="mxc": selects WindowsMxc subject to configuration constraints. Elevated and unelevated select the legacy restricted-token backend unless resolved MXC preference overrides them. Backend configuration does not establish that every operation enters a sandbox. Evidence: claim-02.
  5. 05Matrix row — 0.162.1, features.prefer_mxc: automatic selection requires the feature, configuration eligibility and native availability. Otherwise the configured backend remains, potentially legacy containment or None. Effective local-binding restrictions matter, and managed network requirements outrank feature/profile binding values. Evidence: claim-03.
  6. 06Matrix row — 0.162.1, operation-level selection: Forbid returns no sandbox; Require requests one; Auto evaluates filesystem, network and managed-network requirements before honoring WindowsMxc. This is not an audit of every caller or approval path. Evidence: claim-04.
  7. 07Matrix row — 0.162.1, actual MXC invocation without managed networking: network-disabled profiles generate deny defaults for egress, ingress and host loopback; network-enabled profiles generate allow defaults for those categories. Packet-level enforcement was not tested. Evidence: claims-05 and -06.
  8. 08Matrix row — 0.162.1, managed networking: requires an executor-local proxy context, dedicated nonzero proxy ports and allow_local_binding=true. Generated native policy denies non-loopback traffic by default but permits loopback ranges without port restrictions. It is not a native proxy-port-only loopback boundary. Evidence: claim-07. Source: https://raw.githubusercontent.com/openai/codex/rust-v0.162.1/codex-rs/mxc-sandbox/src/policy.rs . Other launch and validation evidence appears in the saved
Next report / 01AI Model Economics Index All research reports
YOUR READING SPACE

Notifications