Skip to content

fix(cli): pass sandbox_config and restrict_to_workspace to playbook SubagentManager - #827

Merged
0xKT merged 1 commit into
EverMind-AI:mainfrom
truecallerabreham:fix/playbook_subagent_sandbox_config
Oct 3, 2026
Merged

0xKT merged 1 commit into
EverMind-AI:mainfrom
truecallerabreham:fix/playbook_subagent_sandbox_config

Conversation

@truecallerabreham

Copy link
Copy Markdown
Contributor

Summary

Forward tools.sandbox and tools.restrict_to_workspace from the root configuration to SubagentManager instances constructed in playbook_run and _stint_driver. Also provide ProviderPool to _stint_driver so subagents share provider instances.

Previously, running a playbook via the CLI omitted both sandbox_config and restrict_to_workspace when instantiating SubagentManager, which caused playbook subagents to run uncontained on the host machine without respecting configured sandbox boundaries or workspace directory restrictions.

Type

  • Fix
  • Feature
  • Docs
  • CI / tooling
  • Refactor
  • Other

Verification

  • uv run ruff check raven/cli/playbook_commands.py tests/test_cli_playbook_commands.py: passed

  • uv run pytest tests/test_cli_playbook_commands.py -k "subagent_manager_sandbox": 2 passed

  • uv run pytest tests/test_cli_playbook_commands.py: 64 passed

  • python scripts/check_commit_messages.py origin/main..HEAD: passed

  • python scripts/check_source_language.py origin/main..HEAD: passed

  • python scripts/check_large_files.py origin/main..HEAD: passed

  • Relevant tests pass locally

  • Relevant lint / type checks pass locally

  • User-facing docs or screenshots are updated when needed

Risk

  • Security impact considered
  • Backward compatibility considered
  • Rollback path is clear for risky changes

Subagents invoked through playbook runs will now inherit sandbox configuration (e.g. boxlite isolation, network access limits) and workspace containment if configured, instead of bypassing them. If sandboxing is disabled (none), behavior remains unconstrained. Rollback is a revert of this commit.

Related Issues

Fixes #798

…ubagentManager

Forward tools.sandbox and tools.restrict_to_workspace from the root configuration to SubagentManager instances created in playbook_run and _stint_driver. Also forward ProviderPool to _stint_driver so subagents can share provider resources.
@0xKT
0xKT merged commit 6fd6d3c into EverMind-AI:main Oct 3, 2026
21 checks passed
@0xKT

0xKT commented Oct 3, 2026

Copy link
Copy Markdown
Member

Merged, thanks @truecallerabreham! This closes the gap where raven playbook run and the stint driver ignored tools.restrict_to_workspace and tools.sandbox, so CLI playbooks now honor the same config as the conversation path. Nice touch adding the provider pool to the stint driver too.

One note for anyone reading later: DAG nodes still bypass the manager's sandbox executor until #796 is fixed, so the sandbox half of this takes full effect once that lands. Appreciate the contribution, and we'll take a look at #813 as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

raven playbook run: SubagentManager is built without sandbox_config

3 participants