d3f8986b77e5cdab464153ac9610694efca62186
Glob results within a SENSITIVE_PATHS entry could return files before their parent directory. When that happens the file gets a null-bind while its siblings remain visible, because the parent hasn't been added to tmpfs_dirs yet. Sorting dirs first removes this implicit ordering dependency.
Description
Lightweight bubblewrap-based sandbox for AI coding agents, written in Rust.
Languages
Rust
100%