Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

feat(sandbox): recursive seatbelt metadata exclusion, danger-mode scope floor, platform enforcement tests

4 months ago

e8eb7bc
Authored
Claude6/5/2026, 3:56:12 PM
Codex review (commit 2e2c868) + maintainer request:

- #S (P2): seatbelt now excludes protected metadata (.git/.cowork) RECURSIVELY via
  a path regex (require-not (regex #"/\.git(/|$)")), so nested repos/worktrees/
  submodules at any depth under a writable root stay read-only (was top-level only).
- #U (P2): a scoped child (targetPaths) stays workspace-write-scoped even when the
  workspace config is danger-full-access — the explicit scope is a hard floor and
  is no longer lifted to unsandboxed full access.
- #T: documented the bwrap top-level-only metadata limitation (bind-based; per
  command recursive enumeration is impractical) in docs/sandbox.md, per the agreed
  trade-off. macOS is recursive; prefer narrow targetPaths on Linux for nested cases.

Platform enforcement tests (maintainer request): new
test/platform/sandbox.enforcement.integration.test.ts spawns the REAL backend
(macOS sandbox-exec, Linux bubblewrap, Windows restricted-token helper) and asserts
allow/deny + targetPaths scoping on a real kernel. Gated by platform + backend
availability, so it skips on the Linux CI image; run on macOS/Windows before merge
(see docs/sandbox.md > Verification).

Verified: check, typecheck, docs:check, full suite (4657 pass; integration gated-skip
here; pre-existing UI fails only).

Parent2e2c868

5 files changed
  • docs/sandbox.md+22−8
  • src/platform/sandbox/policy.ts+8−2
  • src/platform/sandbox/seatbelt.ts+14−24
  • test/platform/sandbox.enforcement.integration.test.ts+248−0
  • test/platform/sandbox.test.ts+33−3