Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): honor read-only shell policy; canonicalize output/uploads before metadata filter

4 months ago

2e2c868
Authored
Claude6/5/2026, 3:39:08 PM
Codex review (commit 3cc2206):

- #Q (P2): the precomputed sandbox policy (preferred by the bash tool over
  deriving from shellPolicy) now treats an explicit shellPolicy of
  no_project_write as read-only even when no agentRole is set, so those turns
  can't run mutating bash with project write access.
- #R (P2): canonicalize projectRoot/output/uploads roots before the protected
  metadata check, so a symlinked output/uploads dir (e.g. uploads -> .git/hooks)
  can't slip protected metadata in as a writable root that the backends would
  later resolve and bind.

Verified: check, typecheck, full suite (4654 pass; pre-existing UI fails + flaky
provider-timeout only).

Parent3cc2206

4 files changed
  • src/agent.ts+7−1
  • src/platform/sandbox/policy.ts+12−4
  • test/agent.test.ts+8−0
  • test/platform/sandbox.test.ts+18−0