Use turn environment settings for sandbox execution (#40771)
## Why Tool execution can use an environment whose sandbox configuration differs from the turn-wide configuration. Sandbox selection and process setup need to follow the environment that owns the tool request. ## What changed - Source Windows sandbox level, legacy Landlock mode, and Windows private desktop settings from the selected turn environment across tool orchestration, unified exec, patch application, and zsh fork escalation. - Preserve Windows sandbox level overrides in restorable thread settings and invalidate MCP configuration when that level changes. ## Testing - Add a resume test that verifies an elevated Windows sandbox override survives thread restoration. GitOrigin-RevId: 9d8fc46404919f5ae97c9ed712c0932a1f095e36
S
sayan-oai committed
e24190caa9ee355044a7d70177d48a556d766d35
Parent: 3ba7b69
Committed by copyberry <copyberry@app.openai.com>
on 8/26/2026, 3:28:57 AM