Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): read-only floors under yolo/fallback; probe bwrap usability

4 months ago

bd0b6b8
Authored
Claude6/5/2026, 4:37:40 PM
Codex/Bugbot review (commit b1e98ae):

- #Z (P1): codex-cli yolo no longer widens an explicitly read-only sandbox
  (config mode/AGENT_SANDBOX read-only) to danger-full-access; yolo only relaxes
  the approval policy. Scoped children and read-only stay hard floors.
- #Y2 (P2): read-only roles and scoped children (targetPaths) now fail closed
  when no OS backend is available, regardless of requireBackend — the unsandboxed
  fallback is offered only to unscoped workspace-write sessions.
- #AA (Low): the bash-tool fallback policy (when ctx.sandboxPolicy is unset) now
  honors an explicit no_project_write shell policy too, matching agent.ts.
- #Y1 (P2): detectCapabilities probes whether bwrap can actually create user
  namespaces (cached), so an installed-but-unusable bwrap is treated as
  unavailable (fail-closed/fallback) instead of erroring during sandbox setup.

Verified: check, typecheck, full suite (4661 pass; pre-existing UI fails + flaky
provider-timeout only).

Parentccb1e89

6 files changed
  • src/platform/sandbox/detect.ts+41−0
  • src/platform/sandbox/index.ts+6−2
  • src/runtime/codexAppServer/config.ts+8−5
  • src/tools/bash.ts+13−2
  • test/runtime.codex-app-server.test.ts+28−0
  • test/tools/tools.bash.test.ts+36−0