Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): scope child targetPaths everywhere; honor escalation reason; Codex+delegate scope; env inherit

4 months ago

c0bcba6
Authored
Claude6/5/2026, 2:13:59 PM
Codex/Bugbot review (commit cdeb8dd):

- #F (P1): the sandbox-denial escalation reason was dropped by the server
  approveCommand wrappers (runUserMessageTurn, runTurnInvocation) and the
  RuntimeRunTurnParams type, so the YOLO 'always prompt for escalation' guard
  never fired. Forward { reason } through the whole chain.
- #C/#J (P1): validate child targetPaths at the shared AgentControl.spawn
  chokepoint (covers the spawnAgent tool AND the JSON-RPC agent-spawn path).
  Reject if ANY entry is outside the workspace, an escaping symlink, or inside
  .git/.cowork (a mixed scope must not let edit/write touch protected metadata),
  and reject an empty list instead of silently widening to the whole workspace.
- #A (P1): plumb agentTargetPaths into RuntimeRunTurnParams and forward it from
  agent.ts + DelegateRunner so the Codex app-server sandbox policy scopes native
  FS/shell tools to the child's targetPaths.
- #G (P1): DelegateRunner now forwards shellPolicy too, so read-only delegate
  roles (reviewer/explorer) stay read-only under the codex-cli provider.
- #I (P2): sandboxed bash inherits process.env when no toolEnv is set (raw
  delegate context), instead of replacing the env with only sandbox markers.

Verified: bun run check, typecheck, full suite (4647 pass; 2 pre-existing UI fails).

Parentcdeb8dd

12 files changed
  • src/agent.ts+1−0
  • src/platform/sandbox/policy.ts+32−15
  • src/runtime/codexAppServer/config.ts+1−0
  • src/runtime/types.ts+3−1
  • src/server/agents/AgentControl.ts+22−0
  • src/server/agents/DelegateRunner.ts+5−0
  • src/server/session/turnExecution/runTurnInvocation.ts+2−2
  • src/server/session/turnExecution/runUserMessageTurn.ts
+2
−2
  • src/tools/bash.ts+5−1
  • src/tools/spawnAgent.ts+21−14
  • test/spawnAgent.tool.test.ts+19−2
  • test/tools/tools.bash.test.ts+30−0