4 months ago
c0bcba6Codex/Bugbot review (commit cdeb8dd):
- #F (P1): the sandbox-denial escalation reason was dropped by the server
approveCommand wrappers (runUserMessageTurn, runTurnInvocation) and the
RuntimeRunTurnParams type, so the YOLO 'always prompt for escalation' guard
never fired. Forward { reason } through the whole chain.
- #C/#J (P1): validate child targetPaths at the shared AgentControl.spawn
chokepoint (covers the spawnAgent tool AND the JSON-RPC agent-spawn path).
Reject if ANY entry is outside the workspace, an escaping symlink, or inside
.git/.cowork (a mixed scope must not let edit/write touch protected metadata),
and reject an empty list instead of silently widening to the whole workspace.
- #A (P1): plumb agentTargetPaths into RuntimeRunTurnParams and forward it from
agent.ts + DelegateRunner so the Codex app-server sandbox policy scopes native
FS/shell tools to the child's targetPaths.
- #G (P1): DelegateRunner now forwards shellPolicy too, so read-only delegate
roles (reviewer/explorer) stay read-only under the codex-cli provider.
- #I (P2): sandboxed bash inherits process.env when no toolEnv is set (raw
delegate context), instead of replacing the env with only sandbox markers.
Verified: bun run check, typecheck, full suite (4647 pass; 2 pre-existing UI fails).Parentcdeb8dd