Repository navigation
Keep the sandbox guard working after the agent changes directory - #225
Open
yichao-liang wants to merge 1 commit into
Open
yichao-liang wants to merge 1 commit into
yichao-liang wants to merge 1 commit into
Conversation
The PreToolUse guard ran as "python3 .claude/validate_sandbox.py", and a hook command runs in the session's current directory. Domino seed 0 of the from-assets round fixes_r5 ran "cd reference/base_sim" early in level 1; from then on the hook could not be found, every Read, Write, Edit, Glob, Grep and Bash call failed, the Bash call that would have cd'ed back included, and the agent worked through run_python alone for the rest of the run. The guard also took the current directory as the sandbox root, so from a subdirectory it would have denied even "cd ..". The settings now name the guard by absolute path, the guard takes the sandbox from its own location, and relative paths resolve against the working directory the hook input names.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
python3 .claude/validate_sandbox.py, and a hook command runs in the session's current directory..claude/settings.jsonnow names the guard by absolute path (sandbox_settings(sandbox_dir)), so acdcannot lose it.cd ...It now takes the sandbox from its own location, and resolves relative paths against the working directory the hook input names (
cwd).Why
Domino seed 0 of the EMPIRIC from assets round fixes_r5 ran
cd reference/base_simearly in level 1.From then on the hook could not be found, so every Read, Write, Edit, Glob, Grep and Bash call failed, the Bash call that would have cd'ed back included.
The agent worked through
run_pythonalone for the rest of the run ("Bash, Read, and Write have been unusable for the whole run"); it won, but could not look at its rendered scenes.Every arm that runs in the local sandbox has the same exposure.
Test plan
test_sandbox_guard.py::test_hook_survives_a_cd_into_a_subdirectory: the hook command from the generated settings, run through the shell fromreference/base_sim, allowscd ../..and reads of the sandbox's files, and still denies a file outside the sandbox. On the old settings and guard the command fails to start, and the guard deniescd ../...execand now gives it a__file__.🤖 Generated with Claude Code