Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): canonicalize existing prefix; uploads in roots; correct approval reasonCode

4 months ago

6af63e9
Authored
Claude6/5/2026, 2:26:07 PM
Codex review (commit cdeb8dd):

- #M (P1): canonicalizeRoot now resolves the longest EXISTING prefix and
  re-appends the missing tail, so a not-yet-created target below a symlinked
  parent (e.g. src/link/new.ts with src/link -> elsewhere) is correctly resolved
  and dropped instead of falling back to the unresolved in-workspace path.
- #L (P2): include uploadsDirectory in workspace-write writable roots (parity
  with the built-in file tools' write roots), so writing alongside uploads does
  not force a full-access escalation. Plumbed through agent.ts, bash.ts, and the
  Codex config resolver.
- #K (P2): approveCommand only labels a sandbox-denial retry as
  sandbox_denied_escalation (dangerous); other callers (e.g. Codex app-server
  command/file approvals, custom tools) are ordinary 'requires_manual_review'
  approvals and are no longer mislabeled.

Updated codex app-server + AgentSession approval tests for the new (correct)
writable-roots and reasonCode. Verified: check, typecheck, full suite (4650 pass).

Parentc0bcba6

9 files changed
  • src/agent.ts+1−0
  • src/platform/sandbox/policy.ts+28−5
  • src/runtime/codexAppServer/config.ts+1−0
  • src/server/session/InteractionManager.ts+22−9
  • src/tools/bash.ts+1−0
  • test/platform/sandbox.test.ts+30−0
  • test/runtime.codex-app-server.test.ts+1−1
  • test/server/interactionManager.approval.test.ts+8
−0
  • test/session/agentSession.lifecycle.test.ts+2−1