Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): run Windows commands under the restricted-token helper

4 months ago

96d162c
Authored
Claude6/5/2026, 4:48:55 PM
Codex review (commit b1e98ae, #X P1): with requireBackend=true default, every
Windows bash command failed closed (SANDBOX_REQUIRED) because the Win32 helper was
treated as backend-unavailable, so stock Windows sessions could not run any shell
command. Per maintainer decision, select the helper as a backend.

SandboxManager.transform now wraps the command with cowork-win-sandbox.exe
(restricted LUA token + kill-on-close Job Object = process containment) and
reports sandbox "windows-restricted". Because per-root FS ACL scoping and WFP
network isolation are still TODOs, the result carries a warning that filesystem/
network scoping is NOT enforced, surfaced as a [sandbox] notice on every Windows
command (the bash tool no longer claims it "ran without an OS sandbox" when a
partial backend wrapped it).

Verified: check, typecheck, docs:check, full suite (4665 pass; pre-existing UI
fails only). Real helper execution is covered by the gated Windows integration
test, to run on a Windows host before merge.

Parentbd0b6b8

4 files changed
  • docs/sandbox.md+7−5
  • src/platform/sandbox/index.ts+20−3
  • src/tools/bash.ts+11−7
  • test/platform/sandbox.test.ts+11−6