Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

feat(platform): sandbox backend parity across win32/darwin/linux

2 months ago

546fc25
Authored
Max Weinbach7/7/2026, 2:08:53 PM
One scratch-root definition (policy.scratchRoots) consumed by all three
backends (bwrap/seatbelt/windows) — Windows read-only and no-project-write
roles now get temp scratch like macOS/Linux (was a per-OS behavior split).
protectedMetadataPaths promoted from bwrap and shared. windows.ts uses
policyAllowsNetwork() for the --allow-network flag (fixes the
danger-full-access network-flag inversion) and one windowsSandboxHome()
resolver. detect.ts memoizes the Windows bundle probe per (helperPath,
sandboxHome) with a 30s TTL — it was re-hashing three binaries and spawning
'helper probe' on every sandboxed bash call — and gives seatbelt/bwrap
negative-result cooldowns so a transient failure no longer disables the
sandbox until restart. denied.ts adds win32/WSA network+access markers so the
escalation prompt fires on Windows too.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Parent9aec0ae

10 files changed
  • src/platform/sandbox/bwrap.ts+9−41
  • src/platform/sandbox/denied.ts+93−19
  • src/platform/sandbox/detect.ts+119−29
  • src/platform/sandbox/index.ts+9−2
  • src/platform/sandbox/policy.ts+92−0
  • src/platform/sandbox/seatbelt.ts+8−4
  • src/platform/sandbox/windows.ts+65−9
  • test/platform/sandbox.detect.cache.test.ts+168
−0
  • test/platform/sandbox.parity.test.ts+280−0
  • test/platform/sandbox.test.ts+10−4