4 months ago
5eb57f3Cursor Bugbot (commit bb177ef) fixes: - bash.ts: never escalate a read-only policy to danger-full-access on a sandbox-denied failure — only workspace-write may be lifted, preserving the read-only floor for explorer/reviewer/research roles (High). - bash.ts: when sandboxed, resolve the inner shell to a concrete program before wrapping (absolute-exists or bare name found on PATH, incl. Windows exts), so machines with only powershell.exe no longer fail under the sandbox. - bash.ts: correct the child targetPaths description — scope is enforced by the OS sandbox (writes), not by static command parsing; reads aren't path-scoped. - cowork-win-sandbox: release all Win32 handles on wait/exit-code failure paths. Verified: bun run check, typecheck, tests (incl. new read-only-no-escalation test), crate build.
Parentbb177ef