4 months ago
b1e98aeCodex review (commit e8eb7bc, P1): when sandbox.requireBackend is false and no OS backend is available, a restrictive command fell through to an unsandboxed run with full filesystem access and only a post-hoc warning — no approval — even in a non-YOLO session. The escalate-on-failure path already prompts before running unsandboxed; the backend-unavailable fallback now does too. runShellCommandWithExec takes an approveUnsandboxed callback and consults it before the fallback loop (restrictive policy + backend unavailable); the bash tool wires it to ctx.approveCommand with reason 'sandbox_unavailable' (a non-escalation reason, so YOLO auto-approves while non-YOLO confirms). danger-full-access is unaffected. #V (scoped-child bash reads) is declined as a duplicate of the documented decision that bash reads are intentionally unscoped (full read confinement = a separate sandbox mode). Verified: check, typecheck, docs:check, full suite (4658 pass; pre-existing UI fails + flaky provider-timeout only).
Parente8eb7bc