Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): portable bwrap probe; skip probing for full-access commands

4 months ago

4187440
Authored
Claude6/5/2026, 5:25:17 PM
Codex review (commit f8d476d):

- #EE (P2): the bwrap usability probe (#Y1) ran a hard-coded /bin/true inside the
  namespace, which does not exist on NixOS-style hosts — so a usable bubblewrap
  was cached as unusable and, with requireBackend=true default, every sandboxed
  command failed closed. Probe with the current runtime executable (process.execPath
  --version), which always exists and is visible via --ro-bind / /. Namespace
  failures still surface before the command runs.
- #GG (P2): SandboxManager.transform now returns the unwrapped command for
  danger-full-access BEFORE calling detectCapabilities(), so a full-access (incl.
  unscoped YOLO) command no longer triggers the synchronous bwrap probe for a
  backend it will not use.

#FF (dotted directory scopes like docs/v1.0 misclassified as files by
looksLikeFilePath) is left for the maintainer: it is the inverse of the just-added
dotless-file heuristic and a clean fix needs a trailing-slash/type contract on
targetPaths rather than another heuristic.

Verified: check, typecheck, full suite (4666 pass; pre-existing UI fails only).

https://claude.ai/code/session_01XTR8eUgxz3e9DNvz2Yak7n

Parentf8d476d

3 files changed
  • src/platform/sandbox/detect.ts+6−1
  • src/platform/sandbox/index.ts+11−7
  • test/platform/sandbox.enforcement.integration.test.ts+4−1