Skip to content

fix(workspace): make folder selection reliable - #6100

Draft
RaresKeY wants to merge 9 commits into
odysseus-dev:devfrom
RaresKeY:fix/workspace-picker-ux
Draft

RaresKeY wants to merge 9 commits into
odysseus-dev:devfrom
RaresKeY:fix/workspace-picker-ux

Conversation

@RaresKeY

@RaresKeY RaresKeY commented Aug 17, 2026 •

Copy link
Copy Markdown
Member

Summary

Make workspace selection one server-owned transaction instead of a browser-local hint. Use this folder now validates the current typed value without requiring Enter, reports exact failures, offers safe creation for missing folders below a managed default workspace, refreshes the selected folder before persisting it, and keeps the signed-in user's selection consistent across browsers and computers.

Startup and setup defensively create the named default workspace under the application data root. The picker opens there, lists its folders, adds a New folder action and visible selection status, and updates the shell wording for the process-sandbox core contract in #6120. Server validation rejects broad, sensitive, application-data, malformed, and unsafe symlink paths at both the picker and execution boundaries.

Stack

This PR is a direct sibling follow-up to #6120 and is now rebased onto the current #6120 head a1a47d5b2. Its seven focused commits consume the process-core workspace-policy contract; #6119 and #6118 are transitive through #6120, while #6084, #5819, and #5821 are separate authority/provenance slices and are not part of this stack.

Target branch

  • This PR targets dev, not main. All PRs land in dev; main is curated by the maintainer at each release. If your PR is on main by accident, click "Edit" on this PR and change the base.

Linked Issue

Fixes #6099

Part of #6091

Part of #5815

Depends on PR #6120

Related: #3104, #5914, and Discussion #4438

Copilot follow-up

Revalidated all six Copilot findings after rebasing onto #6120. Four findings remained current and are addressed in commit 213edc2bf: bind-time workspace validation now applies the process-sandbox policy; every chat/slash action refreshes server-owned selection; managed-folder creation fails closed without no-follow directory primitives; and clear operations prepare the default workspace before committing the server tombstone.

Two findings were already resolved before this follow-up: tmux sandbox setup failures now return the structured blocked result, and the threat-model text accurately describes private procfs plus brokered HTTP(S) networking.

Type of Change

  • Bug fix (non-breaking — fixes a confirmed issue)
  • New feature (non-breaking — adds new behaviour)
  • Breaking change (changes or removes existing behaviour)
  • Refactor / cleanup (behaviour unchanged)
  • Documentation only
  • CI / tooling / configuration

Checklist

How to Test

  1. Run python -m pytest -q tests/test_workspace_picker.py tests/test_workspace_confine.py tests/test_execution_sandbox.py tests/test_process_execution_mode.py tests/test_process_sandbox_dispatch.py tests/test_sandbox_network_policy.py tests/test_agent_bash_windows.py; the current rebased head passes 131 tests with 31 platform skips.
  2. Run node --check static/js/workspace.js, node --check static/js/chat.js, node --check static/js/slashCommands.js, Python compilation for the changed Python modules, and git diff --check origin/dev...HEAD; each should exit successfully.
  3. Start the app, open Select workspace, type an existing folder, and click Use this folder without pressing Enter. Verify the canonical folder is selected and its contents are refreshed.
  4. Enter a missing child below the managed default workspace. Verify the picker offers creation, creates it only after confirmation, and rejects missing paths outside that root, sensitive paths, application data, filesystem roots, files, malformed paths, and symlink escapes with a visible reason.
  5. Use New folder, clear the selection, reload, and open the same account in a second browser. Verify selected and explicitly cleared state synchronizes through server preferences and is available before the first chat or slash-command action.
  6. Simulate a failed folder refresh after validation and confirm the previously selected workspace remains active rather than persisting a half-completed change.

Current exact-head validation passes 131 tests with 31 platform skips.

Not run: live application interaction, Docker/native runtime, desktop/mobile rendering, or screenshot/clip capture.

Visual / UI changes — REQUIRED if you touched anything that renders

This changes workspace-picker controls, inline status, and folder-creation interaction. Running-app visual evidence is required before marking the PR ready for review.

  • Screenshot or short clip of the change in the running app, attached below. Mobile screenshot too if the change affects mobile.
  • Style match: the change reuses the existing modal, button, input, muted-text, border, and color-variable system without adding a parallel visual language.
  • No new component patterns. The existing workspace modal is extended rather than replaced.
  • I am not an LLM agent submitting a bulk PR. This is a focused, one-off, user-directed fix rather than an automated or mass submission.

Screenshots / clips

Pending running-app desktop/mobile capture of existing-folder selection, missing-folder creation, visible disabled reason, and second-browser synchronization.

@github-actions

Copy link
Copy Markdown

⚠️ PR description is complete; validation evidence is still outstanding

Changed-file classification: UI-sensitive.

Author-reported runtime / visual state

  • The author explicitly reports that app/runtime validation was not performed.
  • The screenshot/clip checkbox is not checked for this UI-sensitive change.
  • The Screenshots / clips section does not contain an actual attachment or link.

Checkboxes are author attestations. GitHub Actions results remain the execution evidence for CI; this check does not prove that a local command ran.


This comment updates automatically when the description or changed files change.

@github-actions github-actions Bot added needs runtime validation Runtime validation not attested — tick the app-run box after running it, or state the gap needs visual evidence UI-sensitive change without an attested screenshot or clip from the running app labels Aug 17, 2026
Comment thread routes/workspace_routes.py Dismissed
Comment thread routes/workspace_routes.py Dismissed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Dismissed
Comment thread routes/workspace_routes.py Dismissed
Comment thread src/tool_execution.py Dismissed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread routes/workspace_routes.py Fixed
Comment thread src/tool_execution.py Fixed
Comment thread src/tool_execution.py Fixed
@RaresKeY
RaresKeY force-pushed the fix/workspace-picker-ux branch 3 times, most recently from d6491f7 to 2af64a0 Compare August 17, 2026 16:43
@RaresKeY
RaresKeY requested a balanced review from Copilot August 18, 2026 03:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Makes workspace selection server-owned and reliable while incorporating the stacked Linux process-sandbox foundation.

Changes:

  • Adds persisted workspace validation, creation, synchronization, and picker UI.
  • Introduces Bubblewrap, seccomp, and brokered-network process isolation.
  • Expands regression coverage across workspace and sandbox behavior.

Reviewed changes

Copilot reviewed 47 out of 47 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
THREAT_MODEL.md Documents sandbox behavior.
tests/test_workspace_picker.py Tests picker workflows and persistence.
tests/test_workspace_confine.py Extends workspace confinement tests.
tests/test_seccomp_policy.py Verifies generated seccomp policy.
tests/test_seccomp_launcher.py Tests launcher security and failures.
tests/test_seccomp_generator.py Tests architecture verification.
tests/test_sandbox_network_policy.py Tests network-policy propagation.
tests/test_foreground_model_routing.py Tests web-toggle network mapping.
tests/test_agent_bash_windows.py Tests unsupported-platform blocking.
tests/seccomp_probe.c Probes runtime syscall restrictions.
static/style.css Styles picker status and controls.
static/js/workspace.js Implements server-synchronized picker behavior.
static/js/slashCommands.js Integrates workspace persistence with commands.
static/js/chat.js Synchronizes workspace before chat actions.
src/tool_schemas.py Updates workspace tool description.
src/tool_index.py Updates indexed tool description.
src/tool_execution.py Adds workspace and network-policy enforcement.
src/teacher_escalation.py Propagates sandbox network profiles.
src/execution_sandbox.py Constructs the process sandbox.
src/constants.py Defines managed workspace and log paths.
src/bg_monitor.py Restores background-job network policy.
src/bg_jobs.py Sandboxes detached jobs.
src/agent_tools/subprocess_tools.py Sandboxes Bash, Python, and tmux.
src/agent_tools/filesystem_tools.py Updates workspace status wording.
src/agent_loop.py Propagates sandbox network profiles.
setup.py Creates the managed workspace during setup.
security/seccomp/README.md Documents seccomp generation and installation.
security/seccomp/policy.json Defines sandbox syscall policy.
security/seccomp/odysseus-seccomp-launcher.c Implements the trusted launcher.
security/seccomp/Makefile Builds and installs the launcher.
security/seccomp/generated_inner_policy.h Supplies generated syscall allowlists.
security/seccomp/generate.py Generates deterministic policy artifacts.
security/egress/README.md Documents brokered egress.
security/egress/odysseus_egress_bridge.py Bridges sandbox traffic to the broker.
security/egress/Makefile Installs trusted egress helpers.
routes/workspace_routes.py Adds workspace persistence and creation APIs.
routes/chat_routes.py Maps web preference to network policy.
Dockerfile Installs sandbox dependencies and helpers.
docker-compose.yml Applies the outer seccomp profile.
docker-compose.gpu-nvidia.yml Applies seccomp to NVIDIA deployment.
docker-compose.gpu-amd.yml Applies seccomp to AMD deployment.
app.py Creates the default workspace at startup.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/tool_execution.py
Comment on lines +320 to 321
resolved, _reason = validate_workspace(raw)
return resolved
Comment thread static/js/workspace.js Outdated
Comment thread routes/workspace_routes.py Outdated
Comment thread routes/workspace_routes.py Outdated
Comment thread src/agent_tools/subprocess_tools.py Outdated
Comment thread THREAT_MODEL.md Outdated
@RaresKeY
RaresKeY force-pushed the fix/workspace-picker-ux branch from 2af64a0 to 8548f99 Compare August 19, 2026 10:40

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs runtime validation Runtime validation not attested — tick the app-run box after running it, or state the gap needs visual evidence UI-sensitive change without an attested screenshot or clip from the running app

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Workspace picker ignores typed paths and lacks a server-owned default

3 participants