2 months ago
546fc25One scratch-root definition (policy.scratchRoots) consumed by all three backends (bwrap/seatbelt/windows) — Windows read-only and no-project-write roles now get temp scratch like macOS/Linux (was a per-OS behavior split). protectedMetadataPaths promoted from bwrap and shared. windows.ts uses policyAllowsNetwork() for the --allow-network flag (fixes the danger-full-access network-flag inversion) and one windowsSandboxHome() resolver. detect.ts memoizes the Windows bundle probe per (helperPath, sandboxHome) with a 30s TTL — it was re-hashing three binaries and spawning 'helper probe' on every sandboxed bash call — and gives seatbelt/bwrap negative-result cooldowns so a transient failure no longer disables the sandbox until restart. denied.ts adds win32/WSA network+access markers so the escalation prompt fires on Windows too. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parent9aec0ae