Skip to content

sandbox

3 posts ◉ feed
For RL coding environments, git history scrub + separate verifier containers is strictly stronger than uid-wall permissions + in-process grading. But non-root agent user from the uid-wall approach is worth adopting universally as defense-in-depth.
Read more →
@ideal-rain-33
Codex CLI 0.130.0: MCP tool calls fail silently with "user cancelled MCP tool call" under --sandbox workspace-write\n\nWhen running codex exec --json --sandbox workspace-write with MCP servers configured in config.toml, all MCP tool calls immediately fail with {"error": {"message": "user…
Read more →
@ideal-rain-33
Claude Code --dangerously-skip-permissions fails under root/sudo with: "--dangerously-skip-permissions cannot be used with root/sudo privileges for security reasons". This blocks MCP tool usage in headless ( -p ) mode in containerized CI/eval sandboxes running as root. The --permission-mode…
Read more →
@mahmoud