Repository navigation
fix(sandbox): let an agent write in the project it was hired to work in - #591
Open
snehithareddy28 wants to merge 2 commits into
Open
snehithareddy28 wants to merge 2 commits into
snehithareddy28 wants to merge 2 commits into
Conversation
Since 0.4.6 a spawned agent cannot write inside its own assigned project cwd. Every Bash command that writes there — git commits and merges, build output, rm, test artifacts — fails with "Operation not permitted", and the only way through is turning the sandbox off for each command, which gives up the whole layer to get work done. Read-only commands are unaffected, which is why this reads as a broken agent rather than a sandbox. The per-agent settings file declares `sandbox.filesystem.allowWrite` as the paths BESIDES cwd — the agent's own hive folder, the hive root, the palace. That was written on the evidence that bypass mode still wrote cwd itself, verified live against claude 2.1.239. It no longer holds: once allowWrite is present it is the whole answer, so the one directory the agent was pointed at is the one directory it cannot write. Name cwd in the list. It costs nothing where it was already implied, and restores the agent's workspace where it is not. This does not widen the sandbox — the agent could always read cwd, and everything outside these paths stays denied. Both layers get it, as before: `allowWrite` governs Bash children and `permissions.additionalDirectories` governs Edit/Write, and with only one the agent deadlocks on its own inbox. The gate is unchanged, so an agent spawned without a sandbox request stays exactly as unsandboxed as it was. test/auto-mode-sandbox.test.cjs covers the reported shape — a project cwd that no other path in the list happens to cover — plus dedup when cwd is also passed as an extra writable dir. Both fail on main. Closes HarnessMD#449
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
Closes #449. Since v0.4.6 a spawned agent cannot write inside its own assigned project
cwd. Every Bash command that writes there —gitcommits and merges, build output,rm, test artifacts — fails withOperation not permitted, and the only way through is disabling the Bash sandbox per command, which gives up the whole layer to get any work done. Read-only commands are unaffected, which is why this presents as a broken agent rather than as a sandbox.The per-agent settings file declares
sandbox.filesystem.allowWriteas the paths besidescwd— the agent's own hive folder, the hive root, the palace. The comment inhive.tssays so, and it was written on real evidence: verified live against claude 2.1.239, bypass mode still wrotecwditself. That no longer holds. OnceallowWriteis present it is the whole answer, so the one directory the agent was pointed at became the one directory it could not write.The fix names
cwdin the list. It costs nothing where it was already implied, and restores the agent's workspace where it is not.What this deliberately does not do:
cwd, and it is the single directory the agent was hired to work in. Everything outside these paths stays denied —touch $HOME/xstill fails, which is the property the sandbox was turned on for.allowWritegoverns Bash children andpermissions.additionalDirectoriesgoverns the Edit/Write tools; with only one the agent deadlocks on its own inbox, as the existing comment records.Type of change
Evidence
Before
After
Notes for review:
test/auto-mode-sandbox.test.cjsgains the reported shape — a projectcwdthat is not a parent of the hive, so nothing else in the list happens to cover it — and a dedup case for whencwdis also passed as an extra writable dir. The file's existing exact-list assertion is updated to includecwd, which is the behaviour change stated plainly rather than loosened into acontains.main.sandboxWritableDirs()is untouched and still means "besides cwd". codex takes that same list through--add-dir, where-s workspace-writealready grants the workspace, so its behaviour is unchanged.npm run typecheckand the fullnpm run test:focusedsuite (836/836 on this branch) pass locally.Discord: asr2805