Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): reject writable roots in protected metadata; create child target dirs

4 months ago

17d25b5
Authored
Claude6/5/2026, 4:07:02 AM
Codex review (commit df0bdc0):
- policy.ts: drop any writable root whose path is inside .git/.cowork. The backend
  carve-outs only re-freeze those dirs *beneath* a writable root, so a child
  scoped directly to e.g. .git/hooks would otherwise stay writable and could
  install git hooks / mutate .cowork state (privilege escalation) (P1).
- bwrap.ts: create a child's nonexistent writable target dirs (injectable
  ensureDir) instead of dropping them, so a scoped child can run e.g.
  'mkdir src/new-feature' on Linux — matching macOS Seatbelt behavior (P2).
- test: strip stray NUL bytes that had crept into joinPairs assertions and make
  the join separator an explicit space; add coverage for both fixes.

Verified: bun run check, typecheck, sandbox + bash tests (45 pass).

Parentdf0bdc0

3 files changed
  • src/platform/sandbox/bwrap.ts+18−4
  • src/platform/sandbox/policy.ts+12−1
  • test/platform/sandbox.test.ts——