Skip to content

Fix Windows 10 drive-letter opens for no-follow filesystem operations - #51511

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/51ffde4f77d2af45d18dfc4cb026d73a0e69b061
Oct 6, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/51ffde4f77d2af45d18dfc4cb026d73a0e69b061

Conversation

@copyberry

@copyberry copyberry Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Fix Windows 10 drive-letter opens for no-follow filesystem operations

Why

On Windows 10, strict native opens can reject the DOS drive alias itself as a reparse point, preventing no-follow filesystem operations on ordinary drive-letter paths.

What changed

Retry rejected drive-letter opens relative to a verified local volume root. Require the root to resolve to a physical disk volume directory without reparse attributes, and retain OBJ_DONT_REPARSE for paths beneath it so junctions remain blocked.

Testing

Add Windows tests for file creation and reading through the volume fallback, opening the drive root, and rejecting junction traversal and creation. Validate accepted volume-root names and verify that named pipes are rejected without establishing a client connection.

…#51511)

## Why

On Windows 10, strict native opens can reject the DOS drive alias itself as a reparse point, preventing no-follow filesystem operations on ordinary drive-letter paths.

## What changed

Retry rejected drive-letter opens relative to a verified local volume root. Require the root to resolve to a physical disk volume directory without reparse attributes, and retain `OBJ_DONT_REPARSE` for paths beneath it so junctions remain blocked.

## Testing

Add Windows tests for file creation and reading through the volume fallback, opening the drive root, and rejecting junction traversal and creation. Validate accepted volume-root names and verify that named pipes are rejected without establishing a client connection.

GitOrigin-RevId: 51ffde4f77d2af45d18dfc4cb026d73a0e69b061
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/51ffde4f77d2af45d18dfc4cb026d73a0e69b061 branch from 9114f6c to 9545947 Compare October 6, 2026 23:20
@chatgpt-codex-connector

Copy link
Copy Markdown
Contributor

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review 🔄 Running since 2026-10-06T23:20:51.960441Z 9114f6c PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@copyberry
copyberry Bot merged commit 9545947 into main Oct 6, 2026
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/51ffde4f77d2af45d18dfc4cb026d73a0e69b061 branch October 6, 2026 23:20
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@github-actions github-actions Bot locked and limited conversation to collaborators Oct 6, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant