4 months ago
5b85169Implements the chosen 'run + visible warning' behavior and addresses the Bugbot/Codex review round on 17d25b5: - bash.ts/config: when the OS sandbox backend is unavailable, surface the warning in the command OUTPUT (not just logs); add sandbox.requireBackend (default false) to optionally fail closed instead of running unsandboxed. - policy.ts: fix a regression — the protected-metadata filter now checks paths RELATIVE to the workspace, so one-off chat workspaces under ~/.cowork/chats are no longer wrongly dropped; only roots crossing the workspace's own .git/.cowork are rejected. - bwrap.ts: canonicalize writable roots before binding (symlink-escape guard); mask protected metadata (.git/.cowork) even when absent so workspace-write can't create them (e.g. install git hooks). - detect.ts: require an absolute COWORK_WIN_SANDBOX_HELPER (parity with COWORK_BWRAP_PATH) so a relative value can't pick a workspace executable. - bash.ts: read the search path case-insensitively (Windows uses 'Path'). - index.ts/docs: correct the 'bwrap not found' message (trusted dirs / COWORK_BWRAP_PATH, not $PATH). Verified: bun run check, typecheck, sandbox+bash tests (46); full suite residual matches base (pre-existing desktop/flaky only).
Parent17d25b5