Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): reject child targetPaths that all resolve outside the workspace

4 months ago

c73f2d1
Authored
Claude6/5/2026, 1:20:43 PM
Codex/Bugbot follow-up to the targetPaths clamp (commit 7c4c5f1): when every
targetPath was dropped (outside the workspace or under .git/.cowork),
deriveWritableRoots returned an empty set while the policy stayed workspace-write,
so the OS sandbox left only temp scratch writable and scoped bash tasks failed
without a clear error.

- policy.ts: extract the clamp as filterTargetPathsToWorkspace (single source of
  truth, reused by deriveWritableRoots).
- spawnAgent.ts: fail fast at spawn with a clear, actionable error when targetPaths
  resolve to no usable in-workspace scope, instead of silently running a child
  that can write nowhere useful.
- docs/sandbox.md: document the clamp + spawn-time rejection.

Verified: bun run check, typecheck, docs:check, sandbox + spawnAgent + bash tests.

Parent975e72f

5 files changed
  • docs/sandbox.md+6−0
  • src/platform/sandbox/policy.ts+31−15
  • src/tools/spawnAgent.ts+19−2
  • test/platform/sandbox.test.ts+24−1
  • test/spawnAgent.tool.test.ts+12−0