Conversation
|
Changed-file classification: UI-sensitive. Author-reported runtime / visual state
Checkboxes are author attestations. GitHub Actions results remain the execution evidence for CI; this check does not prove that a local command ran. This comment updates automatically when the description or changed files change. |
d6491f7 to
2af64a0
Compare
There was a problem hiding this comment.
Pull request overview
Makes workspace selection server-owned and reliable while incorporating the stacked Linux process-sandbox foundation.
Changes:
- Adds persisted workspace validation, creation, synchronization, and picker UI.
- Introduces Bubblewrap, seccomp, and brokered-network process isolation.
- Expands regression coverage across workspace and sandbox behavior.
Reviewed changes
Copilot reviewed 47 out of 47 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| THREAT_MODEL.md | Documents sandbox behavior. |
| tests/test_workspace_picker.py | Tests picker workflows and persistence. |
| tests/test_workspace_confine.py | Extends workspace confinement tests. |
| tests/test_seccomp_policy.py | Verifies generated seccomp policy. |
| tests/test_seccomp_launcher.py | Tests launcher security and failures. |
| tests/test_seccomp_generator.py | Tests architecture verification. |
| tests/test_sandbox_network_policy.py | Tests network-policy propagation. |
| tests/test_foreground_model_routing.py | Tests web-toggle network mapping. |
| tests/test_agent_bash_windows.py | Tests unsupported-platform blocking. |
| tests/seccomp_probe.c | Probes runtime syscall restrictions. |
| static/style.css | Styles picker status and controls. |
| static/js/workspace.js | Implements server-synchronized picker behavior. |
| static/js/slashCommands.js | Integrates workspace persistence with commands. |
| static/js/chat.js | Synchronizes workspace before chat actions. |
| src/tool_schemas.py | Updates workspace tool description. |
| src/tool_index.py | Updates indexed tool description. |
| src/tool_execution.py | Adds workspace and network-policy enforcement. |
| src/teacher_escalation.py | Propagates sandbox network profiles. |
| src/execution_sandbox.py | Constructs the process sandbox. |
| src/constants.py | Defines managed workspace and log paths. |
| src/bg_monitor.py | Restores background-job network policy. |
| src/bg_jobs.py | Sandboxes detached jobs. |
| src/agent_tools/subprocess_tools.py | Sandboxes Bash, Python, and tmux. |
| src/agent_tools/filesystem_tools.py | Updates workspace status wording. |
| src/agent_loop.py | Propagates sandbox network profiles. |
| setup.py | Creates the managed workspace during setup. |
| security/seccomp/README.md | Documents seccomp generation and installation. |
| security/seccomp/policy.json | Defines sandbox syscall policy. |
| security/seccomp/odysseus-seccomp-launcher.c | Implements the trusted launcher. |
| security/seccomp/Makefile | Builds and installs the launcher. |
| security/seccomp/generated_inner_policy.h | Supplies generated syscall allowlists. |
| security/seccomp/generate.py | Generates deterministic policy artifacts. |
| security/egress/README.md | Documents brokered egress. |
| security/egress/odysseus_egress_bridge.py | Bridges sandbox traffic to the broker. |
| security/egress/Makefile | Installs trusted egress helpers. |
| routes/workspace_routes.py | Adds workspace persistence and creation APIs. |
| routes/chat_routes.py | Maps web preference to network policy. |
| Dockerfile | Installs sandbox dependencies and helpers. |
| docker-compose.yml | Applies the outer seccomp profile. |
| docker-compose.gpu-nvidia.yml | Applies seccomp to NVIDIA deployment. |
| docker-compose.gpu-amd.yml | Applies seccomp to AMD deployment. |
| app.py | Creates the default workspace at startup. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| resolved, _reason = validate_workspace(raw) | ||
| return resolved |
2af64a0 to
8548f99
Compare
Summary
Make workspace selection one server-owned transaction instead of a browser-local hint. Use this folder now validates the current typed value without requiring Enter, reports exact failures, offers safe creation for missing folders below a managed default workspace, refreshes the selected folder before persisting it, and keeps the signed-in user's selection consistent across browsers and computers.
Startup and setup defensively create the named default workspace under the application data root. The picker opens there, lists its folders, adds a New folder action and visible selection status, and updates the shell wording for the process-sandbox core contract in #6120. Server validation rejects broad, sensitive, application-data, malformed, and unsafe symlink paths at both the picker and execution boundaries.
Stack
This PR is a direct sibling follow-up to #6120 and is now rebased onto the current #6120 head
a1a47d5b2. Its seven focused commits consume the process-core workspace-policy contract; #6119 and #6118 are transitive through #6120, while #6084, #5819, and #5821 are separate authority/provenance slices and are not part of this stack.Target branch
dev, notmain. All PRs land indev;mainis curated by the maintainer at each release. If your PR is onmainby accident, click "Edit" on this PR and change the base.Linked Issue
Fixes #6099
Part of #6091
Part of #5815
Depends on PR #6120
Related: #3104, #5914, and Discussion #4438
Copilot follow-up
Revalidated all six Copilot findings after rebasing onto #6120. Four findings remained current and are addressed in commit
213edc2bf: bind-time workspace validation now applies the process-sandbox policy; every chat/slash action refreshes server-owned selection; managed-folder creation fails closed without no-follow directory primitives; and clear operations prepare the default workspace before committing the server tombstone.Two findings were already resolved before this follow-up: tmux sandbox setup failures now return the structured blocked result, and the threat-model text accurately describes private procfs plus brokered HTTP(S) networking.
Type of Change
Checklist
devdocker compose uporuvicorn app:app) and verified the change works end-to-end. Type-checks and unit tests are not enough.How to Test
python -m pytest -q tests/test_workspace_picker.py tests/test_workspace_confine.py tests/test_execution_sandbox.py tests/test_process_execution_mode.py tests/test_process_sandbox_dispatch.py tests/test_sandbox_network_policy.py tests/test_agent_bash_windows.py; the current rebased head passes 131 tests with 31 platform skips.node --check static/js/workspace.js,node --check static/js/chat.js,node --check static/js/slashCommands.js, Python compilation for the changed Python modules, andgit diff --check origin/dev...HEAD; each should exit successfully.Current exact-head validation passes 131 tests with 31 platform skips.
Not run: live application interaction, Docker/native runtime, desktop/mobile rendering, or screenshot/clip capture.
Visual / UI changes — REQUIRED if you touched anything that renders
This changes workspace-picker controls, inline status, and folder-creation interaction. Running-app visual evidence is required before marking the PR ready for review.
Screenshots / clips
Pending running-app desktop/mobile capture of existing-folder selection, missing-folder creation, visible disabled reason, and second-browser synchronization.