Problem
The explicit shared resources added in #287 are checked against registered workspace roots and control paths, but the CLI does not pass conversationWorktreeRoot into assertEnvironmentResourceIsolation. The conversation worktree container is also absent from the native sandbox's protectedPaths.
An environment can therefore declare a read-write resource that contains the conversation worktree container. A sandbox inheriting that resource gets a write grant to sibling conversations' checkouts, even though its own workspace root does not overlap the resource. Environment definitions and conversation worktrees are a supported combination.
Reproduction / expected behavior
Configure a native worker with conversation worktrees under /private/store/conversations and an explicit read-write cache resource at /private/store. Keep the registered source checkout elsewhere. Resource admission currently checks the source checkout and existing control paths, but omits the conversation container. Commands can consequently reach sibling conversation checkouts beneath the inherited writable store.
Reject resources that overlap the conversation worktree root in either direction, including aliases caught by mount isolation. Preserve legitimate shared caches outside the worktree container. Add an admission test combining environment resources and conversation worktrees, plus a live isolation regression for sibling checkouts.
Bugbot reported this inherited issue on the ClickHouse import: https://github.com/ClickHouse/ai/pull/4170#discussion_r4165351953
Affected code: packages/code/src/cli.ts, the resource isolation call and native protectedPaths.
Problem
The explicit shared resources added in #287 are checked against registered workspace roots and control paths, but the CLI does not pass
conversationWorktreeRootintoassertEnvironmentResourceIsolation. The conversation worktree container is also absent from the native sandbox's protectedPaths.An environment can therefore declare a read-write resource that contains the conversation worktree container. A sandbox inheriting that resource gets a write grant to sibling conversations' checkouts, even though its own workspace root does not overlap the resource. Environment definitions and conversation worktrees are a supported combination.
Reproduction / expected behavior
Configure a native worker with conversation worktrees under
/private/store/conversationsand an explicit read-write cache resource at/private/store. Keep the registered source checkout elsewhere. Resource admission currently checks the source checkout and existing control paths, but omits the conversation container. Commands can consequently reach sibling conversation checkouts beneath the inherited writable store.Reject resources that overlap the conversation worktree root in either direction, including aliases caught by mount isolation. Preserve legitimate shared caches outside the worktree container. Add an admission test combining environment resources and conversation worktrees, plus a live isolation regression for sibling checkouts.
Bugbot reported this inherited issue on the ClickHouse import: https://github.com/ClickHouse/ai/pull/4170#discussion_r4165351953
Affected code:
packages/code/src/cli.ts, the resource isolation call and native protectedPaths.