Skip to content

Sandbox improvements - WebSearch follows allow-list. Agent can work egress policy server to request user for additions to network policy. - #720

Merged
rohitprasad15 merged 8 commits into
mainfrom
sandbox-chip-site-card
Oct 4, 2026
Merged

rohitprasad15 merged 8 commits into
mainfrom
sandbox-chip-site-card

Conversation

@rohitprasad15

@rohitprasad15 rohitprasad15 commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Web search tools did not follow the allow-list in sandbox mode. This PR fixes that.
CLI tools could still fail if certain hosts are blocked. The agent is now made aware of sandboxing, and can now request addition to the allow-list. ToolRunner inside sandbox can request OpenShell Policy engine for recent blocks and let agent know. Then the agent can ask User for certain hosts to be added.

What changed

  • Web tools follow the list. Web fetch, web search and browser open check the allowed sites. A site off the list raises a card: allow once, this session, or always.
  • The agent can ask for a site. A new tool, request_network_access, takes exact host names and a reason. Only a User can answer its card: this session, always, or deny. Full access cannot grant it.
  • Commands say what was blocked. A command's result names the sites the sandbox blocked while it ran, and says plainly that they may or may not be why it failed. On OpenShell this is read from the sandbox's log.
  • The session shows its sandbox. A chip in the header names the sandbox and counts its sites. The Access section lists them: sites from Settings, and sites allowed for this session, which can be added or taken back there.
  • Docs: the three sandbox pages describe all of the above, and that connectors and MCP servers are not covered by the list.

Tested

  • pytest 2,765, vitest 502, Playwright 327.
  • Tested on the macOS sandbox and on OpenShell 0.0.116 (Docker Desktop, macOS): blocked command

With "Only the sites you allow", web_fetch and web_search reach only listed sites: a listed site runs with no card, an unlisted one is refused in Bypass and raises a person-only card otherwise.
"Always allow" on that card adds the site to the machine's list (OPE-219).
…s allow"

The durable choice adds the site to the machine's sandbox list (OPE-219).
Green with the sandbox and its sites, amber for a session opened before the sandbox was switched on, nothing when the machine has no sandbox; click for folders, sites and logins (OPE-218).
Gallery states for the allowed-sites card.
…ls follow the list

"Always allow" now copies the list back as the store keeps it, so the chip matches Settings.
The three sandbox pages say web search and fetch follow the list; connectors and MCP do not.
"This session" and "Always allow" now reach the session's commands at once.
OpenShell: the policy is rendered again and set on the sandbox; macOS and Windows: the session's own proxy takes the host.
A new tool, request_network_access, raises a card only a person answers: this session, always, or deny.
A command's result names the sites the sandbox blocked while it ran, and the agent is told the live list each turn.
The header chip lists the sites allowed for this session apart from the machine's.
Sites from Settings are listed plain; sites allowed for this session are marked "Session only".
The person can allow one more for the session or take one back; the running sandbox follows at once.
…ocked

The sandbox's own log is followed from outside; a refusal reaches us up to half a second late.
A failed command waits for it; one that arrives after its result is told with the next result.
@rohitprasad15 rohitprasad15 changed the title Sandbox: web tools follow the allowed sites, the agent can ask for a site, and the session shows its list Sandbox improvements - WebSearch follows allow-list. Agent can work egress policy server to request user for additions to network policy. Oct 4, 2026
@rohitprasad15
rohitprasad15 marked this pull request as ready for review October 4, 2026 00:55
@rohitprasad15
rohitprasad15 merged commit fd6b31e into main Oct 4, 2026
6 checks passed
@rohitprasad15
rohitprasad15 deleted the sandbox-chip-site-card branch October 4, 2026 00:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant