Skip to content

Sandboxed agent launch: keep --config, run worktree setup with repo access, scan only real flags #516

Description

@tps-flint

Found in a post-merge review of #474, and reproduced.

  • The attested re-exec under nono keeps --config, so tps agent start --config <file> works when nono is installed.
  • Worktree setup and cleanup can reach the base repository's metadata inside the sandbox, or run before entering it. Today they silently do nothing under a real nono.
  • The sandbox-flag scan reads only tps's own arguments: --sandbox <word> inside a message or a wrapped command is not a flag.

Acceptance: a test for each that fails on main. Where the behaviour depends on nono, at least one test runs the real nono profile, where available in CI.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions