diff --git a/codex-rs/windows-sandbox-rs/src/lib.rs b/codex-rs/windows-sandbox-rs/src/lib.rs index 33c154fa88..70e39cacb4 100644 --- a/codex-rs/windows-sandbox-rs/src/lib.rs +++ b/codex-rs/windows-sandbox-rs/src/lib.rs @@ -388,7 +388,7 @@ mod windows_impl { &mut env_map, &command, /*inherit_path*/ false, - /*add_git_safe_directory*/ false, + /*add_git_safe_directory*/ true, )?; let policy = common.policy; let current_dir = common.current_dir; diff --git a/codex-rs/windows-sandbox-rs/src/unified_exec/backends/legacy.rs b/codex-rs/windows-sandbox-rs/src/unified_exec/backends/legacy.rs index c9a982b695..8e42c7554b 100644 --- a/codex-rs/windows-sandbox-rs/src/unified_exec/backends/legacy.rs +++ b/codex-rs/windows-sandbox-rs/src/unified_exec/backends/legacy.rs @@ -320,7 +320,7 @@ pub(crate) async fn spawn_windows_sandbox_session_legacy( &mut env_map, &command, /*inherit_path*/ false, - /*add_git_safe_directory*/ false, + /*add_git_safe_directory*/ true, )?; if !common.policy.has_full_disk_read_access() { anyhow::bail!("Restricted read-only access requires the elevated Windows sandbox backend");