SIGN IN SIGN UP

refactor(codex)!: remove the untrusted sandbox mode

It passed `-a untrusted`, which Codex 0.152 removed (openai/codex#39630);
on current Codex the flag makes Codex exit at launch. Codex's replacement,
an untrusted project, also disables that repo's config, hooks and exec
policies and shows a consent screen on every launch, which is more than the
mode is worth.

`untrusted` is no longer a valid mode. Existing configs normalize to
`workspace` (like the retired `full-auto`) instead of becoming a config
error.

The Codex approval-gate test now runs in the default workspace mode and
triggers Codex's approval prompt with an escalation request
(sandbox_permissions: require_escalated), the prompt users actually hit.
A
aannoo committed
b66dd631746778eeceac5bcdb5dbc93b73f16446
Parent: 42c0744