Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): file-tool parity for workspace-write roots + protected-metadata + codex /tmp

4 months ago

3cc2206
Authored
Claude6/5/2026, 2:56:34 PM
Codex review (commit 3f85481):

- #O (P2): include the project root in unscoped workspace-write roots, so when
  workingDirectory is a subdirectory (e.g. AGENT_WORKING_DIR=src) bash can write
  root-level files (package.json) like write/edit do, without a full-access
  escalation. Plumbed projectRoot through agent.ts, bash.ts, and the codex config.
- #P (P2): drop output/uploads roots that sit inside protected metadata
  (.git/.cowork) before building the OS policy, so a mis-pointed output/uploads
  dir can't re-open metadata writes the backends keep read-only.
- #N (P2): the Codex app-server workspace-write policy now sets excludeSlashTmp
  when a writable root is nested under /tmp, mirroring the local bwrap/Seatbelt
  backends that skip a scratch root containing an assigned root — otherwise
  Codex-native tools could write sibling /tmp paths outside a /tmp-scoped child.

Verified: check, typecheck, full suite (4652 pass; pre-existing UI fails + 1 flaky
provider-timeout only).

Parent3f85481

6 files changed
  • src/agent.ts+3−0
  • src/platform/sandbox/policy.ts+14−7
  • src/runtime/codexAppServer/config.ts+10−1
  • src/tools/bash.ts+1−0
  • test/platform/sandbox.test.ts+27−0
  • test/runtime.codex-app-server.test.ts+4−1