Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): keep codex-cli scoped children within targetPaths under yolo

4 months ago

3f85481
Authored
Claude6/5/2026, 2:37:56 PM
Codex review (commit 6af63e9, P1): codexSandboxConfig forced the Codex app-server
sandbox to danger-full-access whenever the session ran with --yolo, before
resolveSandboxPolicy could apply agentTargetPaths. Since children inherit the
parent's yolo flag and Codex owns the native shell/write tools, a scoped child
(e.g. targetPaths: ["src/auth"]) got full workspace write access under yolo.

Now a scoped child keeps its configured (scoped) sandbox even under yolo; yolo
still maps to approvalPolicy "never" separately. Only unscoped sessions widen to
danger-full-access. Matches the built-in path, which never widens the sandbox
for yolo (it auto-approves per-command escalation instead).

Verified: check, typecheck, codex app-server tests (19).

Parent6af63e9

2 files changed
  • src/runtime/codexAppServer/config.ts+7−1
  • test/runtime.codex-app-server.test.ts+32−0