Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(tools): bash resolves shells via exec.which on both lanes; sandbox env via platform.env

2 months ago

daa1c80
Authored
Max Weinbach7/7/2026, 11:58:51 AM
Both execution lanes now bind the shell binary through the ONE resolver
(platform/exec.which: case-insensitive PATH key, quote-aware split, PATHEXT)
instead of a hand-rolled walk in the sandboxed lane vs spawn-layer lookup in
the unsandboxed lane — the two could bind different binaries on one machine.

The sandbox child env moves to platform/env.minimalSandboxEnv with the
per-platform allowlist: sandboxed git/gh/npm/pip on Windows finally see
USERPROFILE, HOMEDRIVE/HOMEPATH, APPDATA, LOCALAPPDATA, ProgramData,
ProgramFiles(+x86), PYTHONUTF8 — closing the HIGH audit finding that
sandboxed commands lost their config/credential dirs on Windows only. POSIX
lookups are now exact-key (env IS case-sensitive there).

Deletes bash.ts's local allowlist, minimalSandboxEnv, readPathVar, and
resolveInnerCandidate (4 fewer private platform implementations).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Parente724434

2 files changed
  • src/tools/bash.ts+20−108
  • test/tools/tools.bash.test.ts+22−1