Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): require approval before the unsandboxed fallback

4 months ago

b1e98ae
Authored
Claude6/5/2026, 4:14:24 PM
Codex review (commit e8eb7bc, P1): when sandbox.requireBackend is false and no OS
backend is available, a restrictive command fell through to an unsandboxed run with
full filesystem access and only a post-hoc warning — no approval — even in a
non-YOLO session. The escalate-on-failure path already prompts before running
unsandboxed; the backend-unavailable fallback now does too.

runShellCommandWithExec takes an approveUnsandboxed callback and consults it before
the fallback loop (restrictive policy + backend unavailable); the bash tool wires
it to ctx.approveCommand with reason 'sandbox_unavailable' (a non-escalation reason,
so YOLO auto-approves while non-YOLO confirms). danger-full-access is unaffected.

#V (scoped-child bash reads) is declined as a duplicate of the documented decision
that bash reads are intentionally unscoped (full read confinement = a separate
sandbox mode).

Verified: check, typecheck, docs:check, full suite (4658 pass; pre-existing UI fails
+ flaky provider-timeout only).

Parente8eb7bc

3 files changed
  • docs/sandbox.md+2−1
  • src/tools/bash.ts+35−0
  • test/tools/tools.bash.test.ts+43−0