Sandbox improvements - WebSearch follows allow-list. Agent can work egress policy server to request user for additions to network policy. - #720
Merged
Conversation
With "Only the sites you allow", web_fetch and web_search reach only listed sites: a listed site runs with no card, an unlisted one is refused in Bypass and raises a person-only card otherwise. "Always allow" on that card adds the site to the machine's list (OPE-219).
…s allow" The durable choice adds the site to the machine's sandbox list (OPE-219).
Green with the sandbox and its sites, amber for a session opened before the sandbox was switched on, nothing when the machine has no sandbox; click for folders, sites and logins (OPE-218). Gallery states for the allowed-sites card.
…ls follow the list "Always allow" now copies the list back as the store keeps it, so the chip matches Settings. The three sandbox pages say web search and fetch follow the list; connectors and MCP do not.
"This session" and "Always allow" now reach the session's commands at once. OpenShell: the policy is rendered again and set on the sandbox; macOS and Windows: the session's own proxy takes the host.
A new tool, request_network_access, raises a card only a person answers: this session, always, or deny. A command's result names the sites the sandbox blocked while it ran, and the agent is told the live list each turn. The header chip lists the sites allowed for this session apart from the machine's.
Sites from Settings are listed plain; sites allowed for this session are marked "Session only". The person can allow one more for the session or take one back; the running sandbox follows at once.
…ocked The sandbox's own log is followed from outside; a refusal reaches us up to half a second late. A failed command waits for it; one that arrives after its result is told with the next result.
rohitprasad15
marked this pull request as ready for review
October 4, 2026 00:55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Web search tools did not follow the allow-list in sandbox mode. This PR fixes that.
CLI tools could still fail if certain hosts are blocked. The agent is now made aware of sandboxing, and can now request addition to the allow-list. ToolRunner inside sandbox can request OpenShell Policy engine for recent blocks and let agent know. Then the agent can ask User for certain hosts to be added.
What changed
request_network_access, takes exact host names and a reason. Only a User can answer its card: this session, always, or deny. Full access cannot grant it.Tested