4 months ago
3bfd6d9Wire the SandboxManager into the bash tool and switch from pre-run command
filtering to OS-level enforcement with escalate-on-failure, modeled on Codex:
- bash.ts: resolve SandboxPolicy, run the command wrapped by the platform
sandbox, and only prompt (to retry unsandboxed) when a sandboxed run fails
in a way that looks like a sandbox denial (isLikelySandboxDenied).
- agent.ts: resolve sandboxPolicy from role + config + targetPaths onto ToolContext.
- config: add AgentConfig.sandbox ({ mode, network }) + AGENT_SANDBOX env override
+ config/defaults.json default (workspace-write, network enabled).
- InteractionManager.approveCommand: becomes a sandbox-escalation prompt (no more
regex classification); add sandbox_denied_escalation risk code.
- Remove the bypassable parse-based filtering: gut commandPolicy.ts to the
AgentShellPolicy type alias, delete src/utils/approval.ts.
- Update tests for escalate-on-failure; regenerate JSON-RPC schema.
Verified: full suite has identical residual failures to base (2 pre-existing
desktop DOM/ordering fails); typecheck + docs:check green.Parentfcccc11