3 months ago
f6618e7The sandbox `network: false` policy constrains the bash shell sandbox (the executed command's network access) — it is NOT meant to disable the agent's own first-party tools. This PR had wrongly coupled them, so a no-network session also lost webFetch, webSearch, and Gemini's provider-native web search. MCP was never gated and stays working. Reverts: - webFetch/webSearch: drop the policyAllowsNetwork execute guards. - google-native: drop the networkAllowed threading (agent.ts, runtime types, buildGoogleStreamOptions) so provider-native web search follows the user's nativeWebSearch setting, not the shell sandbox. - remove the tests that asserted the old (incorrect) gating. bash shell-sandbox network enforcement is unchanged. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parent28903fd