Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): address review — read-only floor, path scope, PATH hardening

4 months ago

bb177ef
Authored
Claude6/5/2026, 3:39:32 AM
Bugbot + Codex review fixes:
- policy.ts: read-only roles are now a hard floor — checked before the
  danger-full-access short-circuit, so explorer/reviewer/research children can
  never be escalated to full access by global config (High).
- policy.ts: resolve relative targetPaths/outputDirectory against the workspace
  (workingDirectory), not the server process cwd.
- bash.ts: when a ToolContext lacks a resolved sandboxPolicy, derive it from the
  role + config instead of defaulting to danger-full-access, so delegate paths
  that don't set the field still enforce read-only/scoped-write.
- detect.ts: resolve bwrap only from trusted system dirs (or COWORK_BWRAP_PATH),
  not $PATH — prevents a workspace-planted node_modules/.bin/bwrap from hijacking
  argv[0] and escaping the sandbox.
- denied.ts: add Windows "access is denied" so escalate-on-failure triggers on
  Windows ACL/token denials.
- cowork-win-sandbox: terminate the suspended child and close all handles if
  AssignProcessToJobObject fails (no suspended orphan).

Verified: typecheck, bun run check, full test suite (no new failures), crate build.

Parent93dacf8

6 files changed
  • crates/cowork-win-sandbox/src/main.rs+12−4
  • src/platform/sandbox/denied.ts+1−0
  • src/platform/sandbox/detect.ts+27−6
  • src/platform/sandbox/policy.ts+14−9
  • src/tools/bash.ts+16−1
  • test/platform/sandbox.test.ts——