diff --git a/README.md b/README.md index b765fb5..53be03f 100644 --- a/README.md +++ b/README.md @@ -160,7 +160,7 @@ The `safety-strategy` input determines how much access Codex receives on the run See [Protecting your `OPENAI_API_KEY`](./docs/security.md#protecting-your-openai_api_key) on the Security page for important details on this topic. -- **`drop-sudo` (default)** — On Linux and macOS runners, the action revokes the default user’s `sudo` membership before invoking Codex. Codex then runs as that user without superuser privileges. This change lasts for the rest of the job, so subsequent steps cannot rely on `sudo`; on Linux, group-authorized access to root-owned service sockets under `/run` is also removed. This is usually the safest choice on GitHub-hosted runners. +- **`drop-sudo` (default)** — On Linux and macOS runners, the action revokes the default user’s `sudo` membership before invoking Codex. Codex then runs as that user without superuser privileges. This change lasts for the rest of the job, so subsequent steps cannot rely on `sudo`; on Linux, group-authorized access to existing root-owned service sockets under `/run` is also removed. This is usually the safest choice on GitHub-hosted runners. - **`unprivileged-user`** — Runs Codex as the user provided via `codex-user`. Use this if you manage your own runner with a pre-created unprivileged account. Ensure the user can read the repository checkout and any files Codex needs. See [`unprivileged-user.yml`](./examples/unprivileged-user.yml) for an example of how to configure such an account on `ubuntu-latest`. - **`read-only`** — Executes Codex in a read-only sandbox. Codex can view files but cannot mutate the filesystem or access the network directly. The OpenAI API key still flows through the proxy, so Codex could read it if it can reach process memory. - **`unsafe`** — No privilege reduction. Codex runs as the default `runner` user (which typically has `sudo`). Only use this when you fully trust the prompt. On Windows runners this is the only supported choice and the action will fail if another option is provided. diff --git a/action.yml b/action.yml index 3bfa312..46c64e8 100644 --- a/action.yml +++ b/action.yml @@ -77,8 +77,8 @@ inputs: is only supported on Linux and macOS runners. This option is irreversible: if the default user has sudo privileges, they will be removed permanently for the duration of the job. On Linux, - group-authorized access to root-owned service sockets under `/run` is - also removed. + group-authorized access to existing root-owned service sockets under + `/run` is also removed. * `unprivileged-user` Run Codex as the specified user specified by the `codex-user` option (the user must already exist). Note the caller is responsible for ensuring the specified user has the privileges it needs