Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox,agents): address PR #159 review threads

3 months ago

d60786a
Authored
mweinbach6/9/2026, 10:58:08 PM
- bash: keep COWORK_ARTIFACT_RUNTIME_NODE_MODULES / _NODE_RESOLVER /
  NODE_OPTIONS in the sandbox env allowlist. They are not baked into the
  shell prelude (only PATH dirs + COWORK_SOFFICE are), so without them the
  managed @oai/artifact-tool runtime fails to resolve for sandboxed
  presentation/artifact helper commands. Corrected the stale comment.
- sandbox/denied: stop classifying bare EACCES (mkdir/npm) as a
  non-sandbox failure — that IS the error a sandboxed write-scope block
  produces, and an unsandboxed retry fixes it, so the escalation prompt
  must be offered. Only the Docker daemon-socket case (a group-membership
  issue escalation can't fix) stays on the non-sandbox list.
- AgentControl: count only running/initializing children toward the
  per-parent concurrency cap. Completed-but-open children no longer block
  sequential spawn→wait→spawn workflows; a fork-bomb of concurrent running
  children is still bounded.

Updates the sandbox EACCES test and adds an AgentControl regression test
for completed-but-open children.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Parentebe8bf3

5 files changed
  • src/platform/sandbox/denied.ts+5−4
  • src/server/agents/AgentControl.ts+10−3
  • src/tools/bash.ts+14−5
  • test/agentControl.test.ts+60−0
  • test/platform/sandbox.test.ts+10−4