4 months ago
cdeb8ddCodex/Bugbot review (commit a3302cf): - policy.ts (High): filterTargetPathsToWorkspace now resolves symlinks and re-checks containment, so an in-workspace symlink whose real target escapes the workspace (e.g. src/link -> /home/user/secrets) is dropped instead of becoming a writable bind/allow in bwrap/seatbelt. The canonical path is returned so the backends bind the verified one. - seatbelt.ts (P1): empty writable roots now emit NO write section (fail closed via the base deny) instead of a bare '(allow file-write*)', which is an unconditional write allow in SBPL. - seatbelt.ts (P2): each writable root also gets a '(literal ...)' allow so a file-valued scope (e.g. src/new.ts) can be written directly, not just paths beneath it. Verified: bun run check, typecheck, sandbox tests.
Parenta3302cf