-
Notifications
You must be signed in to change notification settings - Fork 3
plat 395
github-actions[bot] edited this page Oct 6, 2026
·
1 revision
| Field | Value |
|---|---|
| State | deployed |
| Priority | - |
| Product | sandbox |
| Area | general |
| Summary | fixed on main, not deployed: the blanket read grant on Workflow/ is gone; a chat reads its own workflow and attached ones (bridge tools and the CLI sandbox alike). |
| Coordination | Value |
|---|---|
| State | fixed on main; not deployed |
| Date | 2026-10-03 |
| Owner | security-sandbox |
| Related | PLAT-394 (Seatbelt on a Mac), PLAT-364 |
The owner's sandbox self-test in a salesoutreach Builder chat (Codex, Native
agent tools on) read another workflow's workflow.json. Every chat's folder
guard granted read on the whole Workflow/ tree (server.go, delegation.go,
and the bridge shell in tool_setup.go); Seatbelt and Landlock enforced that
grant as written.
A chat reads its own workflow and the workflows attached to it (#workflow
mentions, Builder attachments), nothing else under Workflow/.
-
Workflow/removed from the three read-grant lists; attached workflows still arrive as read-only folders, the chat's own workflow as its write grant. - Generic chat's prompt no longer says
ls Workflow/; it asks the user to attach the workflow.
- A Codex Builder chat still listed all of
Workflow/: workflow Builder chats took their read root fromtokenSessionWorkflowReadRoot, which scoped only API-token sessions and gave app sessions the whole tree. It now returns the chat's own workflow for every session, and nothing for an unresolved folder. The other guard setters (workflow runs, external Builder, Work, project delegation) already granted only their own folder.
- Owner re-runs the sandbox self-test: step 6 should now be refused.
PLAT-395, fixed on main, not
deployed: the blanket read grant on Workflow/ is gone; a chat reads its own
workflow and attached ones (bridge tools and the CLI sandbox alike).
Auto-synced from docs/ on main. Edit there, not here.