4 months ago
fcccc11Introduce src/platform/sandbox/: a SandboxManager that translates a
platform-agnostic SandboxPolicy (read-only / workspace-write /
danger-full-access) into a concrete sandboxed command by prepending a
per-platform wrapper to the {file,args} argv, modeled on OpenAI Codex.
- policy.ts: SandboxPolicy type + role/config resolution + writable-root derivation
- seatbelt.ts: macOS sandbox-exec .sbpl generation (port of seatbelt.rs)
- bwrap.ts: Linux bubblewrap arg generation (port of bwrap.rs, FS+network)
- windows.ts: native-helper invocation builder (CLI contract for the helper)
- detect.ts: capability probes (sandbox-exec / bwrap / helper)
- denied.ts: is-likely-sandbox-denied heuristic for escalate-on-failure
- index.ts: SandboxManager.transform + marker env vars
Not yet wired into bash.ts; default behavior is unchanged.Parenta96cee2