Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): use the project root as the scope/metadata boundary

4 months ago

f29e387
Authored
Claude6/5/2026, 5:42:21 PM
Codex review (commit 4187440):

- #II (P2): for a subdirectory working directory (e.g. AGENT_WORKING_DIR=src), the
  protected-metadata filter for output/uploads/project roots was relative to the
  working dir, so a config root like <repo>/.git/hooks looked 'outside' it and
  slipped through the .git/.cowork carve-out. deriveWritableRoots now filters
  these roots relative to the PROJECT root.
- #JJ (P2): child targetPaths were contained within the working directory, so a
  scoped child could not target project-root files (e.g. ../package.json) that the
  file tools and unscoped sandbox already allow. targetPaths now resolve against
  the working directory but are CONTAINED within the project root (escapes outside
  the project, and .git/.cowork, are still rejected). spawnAgent/AgentControl pass
  the project root to isUsableTargetPath.

#HH (bundling cowork-win-sandbox.exe into packaged Windows builds) is a CI/packaging
task requiring a Windows Rust build + electron-builder resource copy; left for the
maintainer as part of the documented Win32 CI follow-up.

Verified: check, typecheck, full suite (4668 pass; pre-existing UI fails only).

https://claude.ai/code/session_01XTR8eUgxz3e9DNvz2Yak7n

Parent4187440

4 files changed
  • src/platform/sandbox/policy.ts+49−21
  • src/server/agents/AgentControl.ts+8−1
  • src/tools/spawnAgent.ts+8−1
  • test/platform/sandbox.test.ts+28−0