Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): hard floors require an enforcing backend; don't follow symlinks in scan

4 months ago

5aa67b5
Authored
Claude6/5/2026, 5:06:01 PM
Codex review (commit 96d162c):

- #BB (P1): the Windows restricted-token helper provides process containment but
  not FS/scope enforcement, yet it satisfied requireBackend — so read-only
  delegates and scoped children ran unenforced on Windows. Transform results now
  carry enforcesScope (true only for Seatbelt/bwrap); hard-floor contexts
  (read-only roles, scoped children) pass requireEnforcingBackend and fail closed
  when no ENFORCING backend is available (absent or non-enforcing), with no
  unsandboxed fallback. Unscoped workspace-write on Windows still runs under the
  helper (partial containment + warning), preserving the Windows fix.
- #DD (P2): bwrap's nested-metadata scan no longer follows symlinks (lstat, skip
  symlinked dirs), so a  or self-referential link can't make it
  traverse outside the root or loop before the command runs.
- #CC (P2): docs/websocket-protocol.md now documents both ordinary approvals
  (dangerous:false, requires_manual_review) and sandbox-denial escalations.

Verified: check, typecheck, docs:check, full suite (4665 pass; pre-existing UI
fails + flaky provider-timeout only).

Parent96d162c

5 files changed
  • docs/websocket-protocol.md+9−4
  • src/platform/sandbox/bwrap.ts+11−1
  • src/platform/sandbox/index.ts+10−0
  • src/tools/bash.ts+33−5
  • test/tools/tools.bash.test.ts+37−9