fix(cli): pass sandbox_config and restrict_to_workspace to playbook SubagentManager - #827
Merged
0xKT merged 1 commit intoOct 3, 2026
Conversation
…ubagentManager Forward tools.sandbox and tools.restrict_to_workspace from the root configuration to SubagentManager instances created in playbook_run and _stint_driver. Also forward ProviderPool to _stint_driver so subagents can share provider resources.
0xKT
approved these changes
Oct 3, 2026
Member
|
Merged, thanks @truecallerabreham! This closes the gap where One note for anyone reading later: DAG nodes still bypass the manager's sandbox executor until #796 is fixed, so the sandbox half of this takes full effect once that lands. Appreciate the contribution, and we'll take a look at #813 as well. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Forward
tools.sandboxandtools.restrict_to_workspacefrom the root configuration toSubagentManagerinstances constructed inplaybook_runand_stint_driver. Also provideProviderPoolto_stint_driverso subagents share provider instances.Previously, running a playbook via the CLI omitted both
sandbox_configandrestrict_to_workspacewhen instantiatingSubagentManager, which caused playbook subagents to run uncontained on the host machine without respecting configured sandbox boundaries or workspace directory restrictions.Type
Verification
uv run ruff check raven/cli/playbook_commands.py tests/test_cli_playbook_commands.py: passeduv run pytest tests/test_cli_playbook_commands.py -k "subagent_manager_sandbox": 2 passeduv run pytest tests/test_cli_playbook_commands.py: 64 passedpython scripts/check_commit_messages.py origin/main..HEAD: passedpython scripts/check_source_language.py origin/main..HEAD: passedpython scripts/check_large_files.py origin/main..HEAD: passedRelevant tests pass locally
Relevant lint / type checks pass locally
User-facing docs or screenshots are updated when needed
Risk
Subagents invoked through playbook runs will now inherit sandbox configuration (e.g. boxlite isolation, network access limits) and workspace containment if configured, instead of bypassing them. If sandboxing is disabled (
none), behavior remains unconstrained. Rollback is a revert of this commit.Related Issues
Fixes #798