Sandbox: host build/run mode (host_exec tool)

Adds a per-project "Allow host build/run" sandbox capability that lets a
containerized agent request to build and run executables on the host
machine, escaping the Linux sandbox — e.g. compiling and running a macOS
binary the container can't.

- New `host_exec` MCP tool on the approval server, advertised only when the
  session opts in. Pre-allowed via --allowedTools so the call reaches our
  handler directly rather than Claude's permission path: the handler is the
  sole gate, so `auto` mode can never auto-approve it.
- Every host command surfaces an explicit approval (risk .hostExec) and runs
  on the host via /bin/zsh -lc in the session worktree only after approval.
  An explicit "Allow for Session" choice grants the rest of the session;
  auto-approve never sets that — only a deliberate user choice does.
- ProjectSandbox.allowHostExec (off by default) with tolerant decoding so
  rows persisted before the field default to false instead of dropping the
  whole sandbox config.
- Threaded allowHostExec through RunSpec/ResumeSpec/SessionController; Mac
  Project Settings toggle; Mac ApprovalBar "Allow for Session" button; iOS
  risk styling/biometric gate for .hostExec.
- Tests: host_exec advertised/served only when registered + refused
  otherwise; allowHostExec round-trip and legacy-JSON default-to-false.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
This commit is contained in:
2026-06-13 16:52:01 -07:00
co-authored by Claude Opus 4.8
parent 644851e179
commit 9d4999bb74
@@ -84,11 +84,11 @@ extension SessionStatus {
} }
extension Risk { extension Risk {
var isHigh: Bool { self == .destructive || self == .network } var isHigh: Bool { self == .destructive || self == .network || self == .hostExec }
var label: String { rawValue } var label: String { self == .hostExec ? "host machine" : rawValue }
var color: Color { var color: Color {
switch self { switch self {
case .destructive, .network: return Palette.danger case .destructive, .network, .hostExec: return Palette.danger
case .execute: return Palette.attention case .execute: return Palette.attention
case .write: return Color(red: 0.85, green: 0.75, blue: 0.2) case .write: return Color(red: 0.85, green: 0.75, blue: 0.2)
case .readOnly, .unknown: return .secondary case .readOnly, .unknown: return .secondary