Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): clamp targetPaths to workspace; tighten /tmp, escalation, net denials

4 months ago

7c4c5f1
Authored
Claude6/5/2026, 12:59:11 PM
Codex review (commit 5b85169):
- policy.ts: reject absolute/escaping child targetPaths (e.g. /home/user/.ssh) —
  they must stay within the workspace, so a child can't gain broad shell write
  by naming an external target (P1).
- policy.ts + seatbelt/bwrap: add /tmp (and /private/tmp) scratch only when it
  would not over-scope an explicit writable root under it, so a child scoped to
  /tmp/proj/src no longer gets all of /tmp writable (shared withTmpScratch).
- bash.ts: never escalate a scoped child's (targetPaths) denial to full access —
  otherwise --yolo auto-approval would bypass the child scope entirely.
- denied.ts + bash.ts: when network is restricted by policy, treat network /
  DNS failures as sandbox denials too, so the escalate-on-failure retry path is
  reachable for network-isolated work.

Verified: bun run check, typecheck, sandbox + bash tests (49).

Parent5b85169

7 files changed
  • src/platform/sandbox/bwrap.ts+4−7
  • src/platform/sandbox/denied.ts+26−2
  • src/platform/sandbox/policy.ts+38−15
  • src/platform/sandbox/seatbelt.ts+5−9
  • src/tools/bash.ts+9−4
  • test/platform/sandbox.test.ts+28−0
  • test/tools/tools.bash.test.ts+19−0