4 months ago
7c4c5f1Codex review (commit 5b85169): - policy.ts: reject absolute/escaping child targetPaths (e.g. /home/user/.ssh) — they must stay within the workspace, so a child can't gain broad shell write by naming an external target (P1). - policy.ts + seatbelt/bwrap: add /tmp (and /private/tmp) scratch only when it would not over-scope an explicit writable root under it, so a child scoped to /tmp/proj/src no longer gets all of /tmp writable (shared withTmpScratch). - bash.ts: never escalate a scoped child's (targetPaths) denial to full access — otherwise --yolo auto-approval would bypass the child scope entirely. - denied.ts + bash.ts: when network is restricted by policy, treat network / DNS failures as sandbox denials too, so the escalate-on-failure retry path is reachable for network-isolated work. Verified: bun run check, typecheck, sandbox + bash tests (49).
Parent5b85169