4 months ago
96d162cCodex review (commit b1e98ae, #X P1): with requireBackend=true default, every Windows bash command failed closed (SANDBOX_REQUIRED) because the Win32 helper was treated as backend-unavailable, so stock Windows sessions could not run any shell command. Per maintainer decision, select the helper as a backend. SandboxManager.transform now wraps the command with cowork-win-sandbox.exe (restricted LUA token + kill-on-close Job Object = process containment) and reports sandbox "windows-restricted". Because per-root FS ACL scoping and WFP network isolation are still TODOs, the result carries a warning that filesystem/ network scoping is NOT enforced, surfaced as a [sandbox] notice on every Windows command (the bash tool no longer claims it "ran without an OS sandbox" when a partial backend wrapped it). Verified: check, typecheck, docs:check, full suite (4665 pass; pre-existing UI fails only). Real helper execution is covered by the gated Windows integration test, to run on a Windows host before merge.
Parentbd0b6b8