2 months ago
8c5824fThe workspace YOLO toggle previously only auto-approved ordinary command approvals on the native runtime: commands still ran inside the OS sandbox and every sandbox-denial escalation still prompted, so the toggle appeared to do nothing. The Codex app-server runtime already lifted the sandbox under YOLO; this aligns the native path on the same semantics. - resolveSandboxPolicy now accepts yolo and lifts an unscoped, non-read-only session to danger-full-access; hard floors (explicit read-only mode, read-only roles, scoped children targetPaths) are never widened - agent.ts passes yolo into the per-turn sandbox policy and ToolContext; the bash tool's fallback resolution matches - the codex runtime's duplicated yolo/sandbox override is replaced by the shared resolver input - InteractionManager auto-approves everything under YOLO, sandbox-denial retries included; hard floors never reach that path because bash never offers them an escalation - desktop toggle renamed to "YOLO mode" with copy that says what it actually does; CLI/REPL/docs updated to match Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DoiK2RdQDZCh1hMHpqHsQ9
Parentaa8542e