4 months ago
bb177efBugbot + Codex review fixes: - policy.ts: read-only roles are now a hard floor — checked before the danger-full-access short-circuit, so explorer/reviewer/research children can never be escalated to full access by global config (High). - policy.ts: resolve relative targetPaths/outputDirectory against the workspace (workingDirectory), not the server process cwd. - bash.ts: when a ToolContext lacks a resolved sandboxPolicy, derive it from the role + config instead of defaulting to danger-full-access, so delegate paths that don't set the field still enforce read-only/scoped-write. - detect.ts: resolve bwrap only from trusted system dirs (or COWORK_BWRAP_PATH), not $PATH — prevents a workspace-planted node_modules/.bin/bwrap from hijacking argv[0] and escaping the sandbox. - denied.ts: add Windows "access is denied" so escalate-on-failure triggers on Windows ACL/token denials. - cowork-win-sandbox: terminate the suspended child and close all handles if AssignProcessToJobObject fails (no suspended orphan). Verified: typecheck, bun run check, full test suite (no new failures), crate build.
Parent93dacf8