4 months ago
3cc2206Codex review (commit 3f85481): - #O (P2): include the project root in unscoped workspace-write roots, so when workingDirectory is a subdirectory (e.g. AGENT_WORKING_DIR=src) bash can write root-level files (package.json) like write/edit do, without a full-access escalation. Plumbed projectRoot through agent.ts, bash.ts, and the codex config. - #P (P2): drop output/uploads roots that sit inside protected metadata (.git/.cowork) before building the OS policy, so a mis-pointed output/uploads dir can't re-open metadata writes the backends keep read-only. - #N (P2): the Codex app-server workspace-write policy now sets excludeSlashTmp when a writable root is nested under /tmp, mirroring the local bwrap/Seatbelt backends that skip a scratch root containing an assigned root — otherwise Codex-native tools could write sibling /tmp paths outside a /tmp-scoped child. Verified: check, typecheck, full suite (4652 pass; pre-existing UI fails + 1 flaky provider-timeout only).
Parent3f85481