From 984f02c180beb55684b080201d0e20f678a6740a Mon Sep 17 00:00:00 2001 From: David Pierce Date: Mon, 6 Apr 2026 22:18:10 +0000 Subject: [PATCH] relax tool sandboxing overrides for plan mode to match defaults. (#24762) --- packages/core/src/policy/policies/sandbox-default.toml | 3 +-- packages/core/src/policy/sandboxPolicyManager.ts | 2 +- 2 files changed, 2 insertions(+), 3 deletions(-) diff --git a/packages/core/src/policy/policies/sandbox-default.toml b/packages/core/src/policy/policies/sandbox-default.toml index 796902f0b4..6e2db3fd03 100644 --- a/packages/core/src/policy/policies/sandbox-default.toml +++ b/packages/core/src/policy/policies/sandbox-default.toml @@ -2,7 +2,7 @@ network = false readonly = true approvedTools = [] -allowOverrides = false +allowOverrides = true [modes.default] network = false @@ -17,4 +17,3 @@ approvedTools = ['sed', 'grep', 'awk', 'perl', 'cat', 'echo', 'Add-Content', 'Se allowOverrides = true [commands] - diff --git a/packages/core/src/policy/sandboxPolicyManager.ts b/packages/core/src/policy/sandboxPolicyManager.ts index 8b3d9a5744..84b627eb92 100644 --- a/packages/core/src/policy/sandboxPolicyManager.ts +++ b/packages/core/src/policy/sandboxPolicyManager.ts @@ -64,7 +64,7 @@ export class SandboxPolicyManager { network: false, readonly: true, approvedTools: [], - allowOverrides: false, + allowOverrides: true, }, default: { network: false,