Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): unenforceable-policy behavior + several review hardenings

4 months ago

5b85169
Authored
Claude6/5/2026, 12:44:57 PM
Implements the chosen 'run + visible warning' behavior and addresses the
Bugbot/Codex review round on 17d25b5:

- bash.ts/config: when the OS sandbox backend is unavailable, surface the
  warning in the command OUTPUT (not just logs); add sandbox.requireBackend
  (default false) to optionally fail closed instead of running unsandboxed.
- policy.ts: fix a regression — the protected-metadata filter now checks paths
  RELATIVE to the workspace, so one-off chat workspaces under ~/.cowork/chats
  are no longer wrongly dropped; only roots crossing the workspace's own
  .git/.cowork are rejected.
- bwrap.ts: canonicalize writable roots before binding (symlink-escape guard);
  mask protected metadata (.git/.cowork) even when absent so workspace-write
  can't create them (e.g. install git hooks).
- detect.ts: require an absolute COWORK_WIN_SANDBOX_HELPER (parity with
  COWORK_BWRAP_PATH) so a relative value can't pick a workspace executable.
- bash.ts: read the search path case-insensitively (Windows uses 'Path').
- index.ts/docs: correct the 'bwrap not found' message (trusted dirs /
  COWORK_BWRAP_PATH, not $PATH).

Verified: bun run check, typecheck, sandbox+bash tests (46); full suite residual
matches base (pre-existing desktop/flaky only).

Parent17d25b5

8 files changed
  • docs/sandbox.md+5−2
  • src/config.ts+1−0
  • src/platform/sandbox/bwrap.ts+22−4
  • src/platform/sandbox/detect.ts+3−1
  • src/platform/sandbox/index.ts+4−1
  • src/platform/sandbox/policy.ts+25−9
  • src/tools/bash.ts+43−2
  • test/platform/sandbox.test.ts+14−0