Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): harden scoped child shell access

4 months ago

ccb1e89
Authored
mweinbach6/5/2026, 4:27:58 PM
Remove bash from targetPath-scoped child toolsets so scoped agents cannot use shell reads outside their assignment while retaining path-scoped read/write/edit/glob/grep tools.

Harden Linux sandbox generation by masking existing nested protected metadata directories under explicit writable roots and treating common dotless target files such as Dockerfile and Makefile as file roots.

Keep sandbox root canonicalization deterministic for synthetic missing paths and update regression coverage for canonical app-server roots, macOS temp aliases, dotless file targets, nested metadata, and scoped child tool exposure.

Parentb1e98ae

7 files changed
  • src/platform/sandbox/bwrap.ts+57−5
  • src/platform/sandbox/policy.ts+1−0
  • src/tools/index.ts+5−1
  • test/platform/sandbox.enforcement.integration.test.ts+1−1
  • test/platform/sandbox.test.ts+61−4
  • test/runtime.codex-app-server.test.ts+9−2
  • test/tools/tools.createTools.test.ts+11−0