From 9d4999bb747d4b15a8aa5f850dbe141b96b48007 Mon Sep 17 00:00:00 2001 From: Andrew Blakeslee Moore Date: Sat, 13 Jun 2026 16:52:01 -0700 Subject: [PATCH] Sandbox: host build/run mode (host_exec tool) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds a per-project "Allow host build/run" sandbox capability that lets a containerized agent request to build and run executables on the host machine, escaping the Linux sandbox — e.g. compiling and running a macOS binary the container can't. - New `host_exec` MCP tool on the approval server, advertised only when the session opts in. Pre-allowed via --allowedTools so the call reaches our handler directly rather than Claude's permission path: the handler is the sole gate, so `auto` mode can never auto-approve it. - Every host command surfaces an explicit approval (risk .hostExec) and runs on the host via /bin/zsh -lc in the session worktree only after approval. An explicit "Allow for Session" choice grants the rest of the session; auto-approve never sets that — only a deliberate user choice does. - ProjectSandbox.allowHostExec (off by default) with tolerant decoding so rows persisted before the field default to false instead of dropping the whole sandbox config. - Threaded allowHostExec through RunSpec/ResumeSpec/SessionController; Mac Project Settings toggle; Mac ApprovalBar "Allow for Session" button; iOS risk styling/biometric gate for .hostExec. - Tests: host_exec advertised/served only when registered + refused otherwise; allowHostExec round-trip and legacy-JSON default-to-false. Co-Authored-By: Claude Opus 4.8 (1M context) --- NucleicRemote/NucleicRemote/Views/Theme.swift | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/NucleicRemote/NucleicRemote/Views/Theme.swift b/NucleicRemote/NucleicRemote/Views/Theme.swift index f1b6e76..9b972c5 100644 --- a/NucleicRemote/NucleicRemote/Views/Theme.swift +++ b/NucleicRemote/NucleicRemote/Views/Theme.swift @@ -84,11 +84,11 @@ extension SessionStatus { } extension Risk { - var isHigh: Bool { self == .destructive || self == .network } - var label: String { rawValue } + var isHigh: Bool { self == .destructive || self == .network || self == .hostExec } + var label: String { self == .hostExec ? "host machine" : rawValue } var color: Color { switch self { - case .destructive, .network: return Palette.danger + case .destructive, .network, .hostExec: return Palette.danger case .execute: return Palette.attention case .write: return Color(red: 0.85, green: 0.75, blue: 0.2) case .readOnly, .unknown: return .secondary