Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): root-relative metadata exclusion (seatbelt) + ancestor-first bind order

4 months ago

05a13be
Authored
Claude6/5/2026, 6:04:47 PM
Codex review (commit f29e387):

- #LL (P2): my earlier recursive Seatbelt regex matched .git/.cowork ANYWHERE in
  the absolute path, including ANCESTOR segments — so a macOS workspace that
  legitimately lives under ~/.cowork (one-off chat workspaces at ~/.cowork/chats/<id>)
  had every write denied. Reverted to per-root -D subpath/literal exclusions
  (relative to each root) plus existing-nested enumeration, matching the bwrap
  backend (collectExistingProtectedMetadataDirs is now shared). Absent nested
  metadata is unmasked (documented limitation shared with bwrap). The nested scan
  runs only for EXPLICIT roots, never the /tmp scratch family.
- #KK (P2): now that the project root is added as a writable root after a
  subdirectory working dir, bwrap bound child-then-parent and the later parent
  bind shadowed the child's .git masks. Roots are now sorted ancestor-first
  (stable: unrelated roots keep input order) so masks are never re-exposed.

Verified: check, typecheck, docs:check, full suite (4669 pass; pre-existing UI
fails only). macOS enforcement (incl. the .cowork-ancestor case) covered by the
gated integration test.

https://claude.ai/code/session_01XTR8eUgxz3e9DNvz2Yak7n

Parentf29e387

5 files changed
  • docs/sandbox.md+5−3
  • src/platform/sandbox/bwrap.ts+20−2
  • src/platform/sandbox/seatbelt.ts+46−14
  • test/platform/sandbox.enforcement.integration.test.ts+15−0
  • test/platform/sandbox.test.ts+33−10