4 months ago
e8eb7bcCodex review (commit 2e2c868) + maintainer request: - #S (P2): seatbelt now excludes protected metadata (.git/.cowork) RECURSIVELY via a path regex (require-not (regex #"/\.git(/|$)")), so nested repos/worktrees/ submodules at any depth under a writable root stay read-only (was top-level only). - #U (P2): a scoped child (targetPaths) stays workspace-write-scoped even when the workspace config is danger-full-access — the explicit scope is a hard floor and is no longer lifted to unsandboxed full access. - #T: documented the bwrap top-level-only metadata limitation (bind-based; per command recursive enumeration is impractical) in docs/sandbox.md, per the agreed trade-off. macOS is recursive; prefer narrow targetPaths on Linux for nested cases. Platform enforcement tests (maintainer request): new test/platform/sandbox.enforcement.integration.test.ts spawns the REAL backend (macOS sandbox-exec, Linux bubblewrap, Windows restricted-token helper) and asserts allow/deny + targetPaths scoping on a real kernel. Gated by platform + backend availability, so it skips on the Linux CI image; run on macOS/Windows before merge (see docs/sandbox.md > Verification). Verified: check, typecheck, docs:check, full suite (4657 pass; integration gated-skip here; pre-existing UI fails only).
Parent2e2c868