4 months ago
2e2c868Codex review (commit 3cc2206): - #Q (P2): the precomputed sandbox policy (preferred by the bash tool over deriving from shellPolicy) now treats an explicit shellPolicy of no_project_write as read-only even when no agentRole is set, so those turns can't run mutating bash with project write access. - #R (P2): canonicalize projectRoot/output/uploads roots before the protected metadata check, so a symlinked output/uploads dir (e.g. uploads -> .git/hooks) can't slip protected metadata in as a writable root that the backends would later resolve and bind. Verified: check, typecheck, full suite (4654 pass; pre-existing UI fails + flaky provider-timeout only).
Parent3cc2206