Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

feat(sandbox): add Windows native helper crate (restricted token + Job Object)

4 months ago

7f3e618
Authored
Claude6/5/2026, 3:20:27 AM
Add crates/cowork-win-sandbox: a Rust helper that is the Windows counterpart to
sandbox-exec/bwrap. The TS SandboxManager prepends it to the command; it runs
the child under a restricted (LUA) token inside a kill-on-close Job Object,
cribbed from Codex's windows-sandbox-rs restricted-token path.

- CLI contract matches src/platform/sandbox/windows.ts (--mode/--writable-root/
  --cwd/--allow-network/--).
- Win32 code is #[cfg(windows)]-gated; the crate builds on Linux (stub path),
  so the scaffold is verifiable in CI. The Win32 path must be built + verified
  on a Windows runner (documented in the crate README).
- v1 enforces privilege reduction + process containment; per-root ACL filesystem
  scoping and WFP network isolation are tracked TODOs.
- detectCapabilities searches the binary/resources dirs (plus the
  COWORK_WIN_SANDBOX_HELPER override) for the bundled helper.

Note: Windows sandbox enforcement is unverified pending a Windows CI build.

Parent3bfd6d9

7 files changed
  • crates/cowork-win-sandbox/.gitignore+1−0
  • crates/cowork-win-sandbox/Cargo.lock+173−0
  • crates/cowork-win-sandbox/Cargo.toml+28−0
  • crates/cowork-win-sandbox/README.md+63−0
  • crates/cowork-win-sandbox/src/main.rs+259−0
  • src/platform/sandbox/index.ts+22−1
  • src/platform/sandbox/windows.ts+1−1