Context
Found in the review of #6063 (feat(session-bridge): native channels adapter with loopback fallback), both flagged by Codex (P2) and left unfixed to keep the security-reviewed policy logic unchanged. Found while delivering spec container #5835.
Problem
select_transport is not fail-closed for MDM-only channel policy. The macOS plist and Windows registry policy sources are not read, so the native channels transport can be chosen while managed policy drops the events.
- Managed
allowedChannelPlugins lists are replaced across sources instead of merged, so a lower-precedence managed source's entries are lost.
Suggested fix
Read the MDM policy sources (macOS plist, Windows registry) and fail closed to the loopback transport when policy cannot be read or does not allow the channel. Merge allowedChannelPlugins across managed sources instead of replacing. Both changes need a security-reviewed fix with tests per source.
Related: #5835
Context
Found in the review of #6063 (
feat(session-bridge): native channels adapter with loopback fallback), both flagged by Codex (P2) and left unfixed to keep the security-reviewed policy logic unchanged. Found while delivering spec container #5835.Problem
select_transportis not fail-closed for MDM-only channel policy. The macOS plist and Windows registry policy sources are not read, so the native channels transport can be chosen while managed policy drops the events.allowedChannelPluginslists are replaced across sources instead of merged, so a lower-precedence managed source's entries are lost.Suggested fix
Read the MDM policy sources (macOS plist, Windows registry) and fail closed to the loopback transport when policy cannot be read or does not allow the channel. Merge
allowedChannelPluginsacross managed sources instead of replacing. Both changes need a security-reviewed fix with tests per source.Related: #5835