Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): drop symlink-escaping targetPaths; harden seatbelt write policy

4 months ago

cdeb8dd
Authored
Claude6/5/2026, 1:54:26 PM
Codex/Bugbot review (commit a3302cf):

- policy.ts (High): filterTargetPathsToWorkspace now resolves symlinks and
  re-checks containment, so an in-workspace symlink whose real target escapes
  the workspace (e.g. src/link -> /home/user/secrets) is dropped instead of
  becoming a writable bind/allow in bwrap/seatbelt. The canonical path is
  returned so the backends bind the verified one.
- seatbelt.ts (P1): empty writable roots now emit NO write section (fail closed
  via the base deny) instead of a bare '(allow file-write*)', which is an
  unconditional write allow in SBPL.
- seatbelt.ts (P2): each writable root also gets a '(literal ...)' allow so a
  file-valued scope (e.g. src/new.ts) can be written directly, not just paths
  beneath it.

Verified: bun run check, typecheck, sandbox tests.

Parenta3302cf

3 files changed
  • src/platform/sandbox/policy.ts+14−2
  • src/platform/sandbox/seatbelt.ts+14−1
  • test/platform/sandbox.test.ts+17−0