Skip to content

sandbox network grants don't persist after approving — network access stays denied, fails with context canceled #703

Description

@Svector-anu

i think i found a bug with zero's sandbox network permissions.

i was trying to run git push to a gitlawb:// remote. zero prompted me for network access, i clicked allow, but the command still failed with context canceled. i retried several times and approved it each time, but it kept failing.

i checked the sandbox state:

zero sandbox policy
network: deny
backend: macos-seatbelt

and zero sandbox grants list returns:

No persistent sandbox grants.

~/.config/zero/sandbox-grants.json also doesn't exist.

so it looks like clicking allow isn't actually persisting or applying the network grant, and the sandbox continues blocking the network request. the context canceled error also makes it pretty difficult to tell that the sandbox is the cause.

running the same git push outside of zero's sandbox worked fine.

environment

  • zero 0.1.0
  • macos 15.7.7, sandbox backend macos-seatbelt

repro

$ zero sandbox policy
mode: enforce
network: deny
backend: macos-seatbelt
grants: /Users/macbook/.config/zero/sandbox-grants.json

$ zero sandbox grants list
No persistent sandbox grants.

$ cat ~/.config/zero/sandbox-grants.json
cat: No such file or directory

screenshot

(adding below — will drop it in as a comment)

Activity

  1. Svector-anu commented on Jul 16, 2026

    @Svector-anu
    Author
    Image
  2. PierrunoYT commented on Jul 17, 2026

    @PierrunoYT
    Contributor

    Checking now!

  3. PierrunoYT commented on Jul 18, 2026

    @PierrunoYT
    Contributor

    Confirmed a network-classification gap affecting this repro: Zero classified git clone as network-sensitive, but not git push. As a result, the initial approval for git push did not enable network access in the sandbox and the command depended on post-failure denial detection, which is unreliable when a custom transport exits with context canceled.

    I opened #726 to classify git push as network access before execution, so approving the prompt applies the temporary network-enabled sandbox profile immediately.

    Regression coverage includes the reported custom-remote shape (git push gitlawb main) at both analyzer and risk-classifier layers. Full tests and vet pass; govulncheck reports no vulnerabilities; diff-scoped lint reports 0 issues.

    One clarification: an absent sandbox-grants.json, an empty sandbox grants list, and the base policy continuing to show network: deny are expected for allow-once/session network approvals. Network grants are temporary in-memory overlays rather than persistent shell grants.

  4. added
    issue-approvedReviewed and approved by the core team; community PRs may implement this issue.
    on Jul 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    issue-approvedReviewed and approved by the core team; community PRs may implement this issue.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions