feat: workspace confinement for agent file/shell tools (#937) #952

Closed
sleepy wants to merge 2 commits from fix/937-workspace-confinement into dev
Owner

Summary

Add workspace folder selection and confinement for agent tools. Prevents the agent from operating outside intended directories.

Changes

Settings

  • workspace_folder — new setting in settings.json (absolute path to workspace dir)
  • Resolution chain: TOOL_SANDBOX_DIRS env > workspace_folder setting > process cwd
  • Settings tool aliases: workspace / workspace folder
  • Validation: must be absolute path to existing directory

Tool Confinement

  • File tools (read/write/edit/grep/glob/ls) — sandboxed to workspace dir
  • Bash — starts in workspace cwd, but NOT fully sandboxed (can reach outside with absolute paths)
  • Symlink escape prevention — symlinks are followed before sandbox check; if they resolve outside workspace, access is denied
  • Path validation — uses both abspath and realpath for platform compatibility (e.g. macOS /etc → /private/etc)

System Prompt

  • Injects active workspace path and confinement rules
  • Agent is informed that file tools are confined and shell starts in workspace

Tests

  • 39 new tests covering: workspace resolution, path validation, symlink escapes, bash cwd confinement, settings integration, prompt integration

Fixes

  • Blocked path check uses both abspath + realpath for symlinked dirs
  • Sandbox dirs normalized with realpath for consistent cross-platform comparison
  • Write path validation detects symlink targets outside sandbox
  • macOS /var → /private/var symlink handled consistently
## Summary Add workspace folder selection and confinement for agent tools. Prevents the agent from operating outside intended directories. ## Changes ### Settings - **`workspace_folder`** — new setting in `settings.json` (absolute path to workspace dir) - Resolution chain: `TOOL_SANDBOX_DIRS` env > `workspace_folder` setting > process cwd - Settings tool aliases: `workspace` / `workspace folder` - Validation: must be absolute path to existing directory ### Tool Confinement - **File tools** (read/write/edit/grep/glob/ls) — sandboxed to workspace dir - **Bash** — starts in workspace cwd, but NOT fully sandboxed (can reach outside with absolute paths) - **Symlink escape prevention** — symlinks are followed before sandbox check; if they resolve outside workspace, access is denied - **Path validation** — uses both `abspath` and `realpath` for platform compatibility (e.g. macOS `/etc` → `/private/etc`) ### System Prompt - Injects active workspace path and confinement rules - Agent is informed that file tools are confined and shell starts in workspace ### Tests - 39 new tests covering: workspace resolution, path validation, symlink escapes, bash cwd confinement, settings integration, prompt integration ## Fixes - Blocked path check uses both abspath + realpath for symlinked dirs - Sandbox dirs normalized with realpath for consistent cross-platform comparison - Write path validation detects symlink targets outside sandbox - macOS `/var` → `/private/var` symlink handled consistently
- Port edit_file with unified diff output (exact string replacement, replace_all support)
- Port grep tool (regex search, ripgrep-first with Python fallback, .gitignore-aware)
- Port glob tool (recursive file pattern matching, skips hidden dirs)
- Port ls tool (directory listing, folders-first, sizes)
- Port get_workspace tool (report active workspace folder)
- Add line-range support to read_file (offset/limit parameters)
- Add diff output to write_file (unified diff when overwriting)
- Register all new tools in tool handler registry and execution dispatch
- Add schemas for all new tools in core_schemas.py
- Add new tools to NON_ADMIN_BLOCKED_TOOLS security policy
- Add diff display support in format_tool_result
- 38 comprehensive tests covering all new tools

Refs: #936
Add workspace folder selection and confinement for agent tools:

- Add workspace_folder setting (settings.json) with resolution chain:
  TOOL_SANDBOX_DIRS env > workspace_folder setting > process cwd
- Gate bash tool to workspace cwd (starts in workspace, can still reach
  outside with absolute paths — not fully sandboxed)
- Gate file tools (read/write/edit/grep/glob/ls) to workspace sandbox
- Symlink escape prevention: follow symlinks before sandbox check,
  detect and block symlinks that resolve outside workspace
- Path validation uses both abspath and realpath to handle platform
  differences (e.g. macOS /etc → /private/etc)
- Inject workspace path and confinement rules into agent system prompt
- Add settings tool aliases: 'workspace' / 'workspace folder' → workspace_folder
- Validate workspace_folder setting (must be absolute existing directory)
- Add comprehensive test suite (39 tests) for workspace resolution,
  path validation, symlink escapes, bash cwd confinement, and
  settings integration

Fixes:
- Blocked path check now uses both abspath + realpath for symlinked dirs
- Sandbox dirs normalized with realpath for consistent comparison
- Write path validation detects symlink targets outside sandbox
- macOS /var → /private/var symlink handled consistently
sleepy closed this pull request 2026-06-18 18:33:45 +02:00

Pull request closed

Sign in to join this conversation.
No description provided.