pub struct ProviderNativeNetworkSketch {
pub codex_network_access: Option<bool>,
}Expand description
Honest, partial provider-native network mapping (node-local).
Only measured / documented knobs appear here. Unknown JSON keys refuse at
load (deny_unknown_fields). Claude network is settings-shaped
(sandbox.network.allowedDomains / --settings) — not a Codex-style
bool argv; Kimi has no first-party network allowlist on the CLI;
Grok child-network is profile-shaped (--sandbox /
restrict_network in sandbox.toml), Linux-only, and does not block
in-process web/API — not a provider_native bool. Omit invented
claude_* / kimi_* / grok_* fields rather than fake flags; resolve
refuses when a required Codex-only mapping is asked of a non-Codex
provider. Inventories:
hatchery-websession-docs
research/claude-kimi-network-argv-vs-station-catalog-2026-10-02.md,
research/grok-linux-child-network-vs-station-catalog-2026-10-02.md.
Fields§
§codex_network_access: Option<bool>Codex networkAccess-shaped knob when measured. None = unmapped.