The Linux version seems to use bubblewrap + seccomp for a "workspace sandbox" automatically, in addition to the auto mode and/or user approval.
A VM would be even better, but people could presumably run this in one if we manage to convince them of higher sandboxing in general ?
The cli does that already with codex on linux
Bubblewrap gets a bit confused inside a Docker container. If anyone knows how to run Codex inside a Docker container on Linux without it constantly complaining about a broken bubblewrap, please tell.