-
Notifications
You must be signed in to change notification settings - Fork 3
plat 383
github-actions[bot] edited this page Oct 3, 2026
·
1 revision
| Coordination | Value |
|---|---|
| State | fixed on main (this commit); not deployed |
| Date | 2026-10-03 |
| Owner | security-sandbox |
| Related | PLAT-373 (1ebd1aba9), 8b6e85d61; found by ai-work-0b's code review |
1ebd1aba9 let the shell accept any existing absolute folder outside the
workspace, and cliPolicyPath kept absolute grants in the CLI sandbox policy.
On a server that turned a workflow's folder_access into a real grant, and
folder_access only needed workflow ownership (no admin-assigned roots check,
unlike Work folders). A member could grant their agents the service account's
config or another user's home. CDPHostDownloadsPath also granted the service
account's ~/Downloads on any server where CDP defaulted on.
- Manifest update: a new or changed
folder_accesspath must be inside the caller's admin-assigned roots (admins exempt; unchanged grants kept), the same check as adding a Work folder (checkWorkflowFolderGrants). - CLI sandbox policy: absolute grants are kept only on a person's own Mac and
dropped on every server (
cliPolicyPath). - Shell: the outside-folder exception applies only on a person's own Mac in native mode (macOS, NATIVE_WORKSPACE, not multi-user, no slots); servers refuse outside grants as before. The terminal's unconfined rule also now requires not multi-user.
- Host Downloads: granted only in local single-user CDP mode, or when a deployment names the folder explicitly.
- Done:
workflow_folder_grant_roots_test.go,TestCLISandboxPolicyDropsHostGrantsOnServers,TestIsExistingHostGrant,TestInteractiveShellUnconfinedNeverOnAMultiUserMac,cdp_host_downloads_test.go. - Left: on servers, legitimately assigned Work folders are not in native CLI sandboxes (they were not before either); allow them from the assigned roots when needed. A workflow.json edited outside the API is not root-checked.
Auto-synced from docs/ on main. Edit there, not here.