Describe the bug
Actual: The hook ran at session start, and its log showed it. After I added readonlyPaths ( /home//.copilot , /home//.nvm ) and readwritePaths ( …/.copilot/.cache/copilot/marketplaces , …/.copilot/installed-plugins , …/.copilot/plugin-data ) to sandbox.userPolicy.filesystem , it never runs again. /env still lists the hook. The hook's first statement in the command appends a line to $COPILOT_PLUGIN_DATA/hook-invoked.log , and that file is never created. No warning is shown, and the process logs contain no hook entries. Run by hand, the same command works.
Also unclear in the docs: The settings reference documents only filesystem.deniedPaths . It doesn't document readonlyPaths or readwritePaths , though the hooks docs say to grant hooks access via sandbox.userPolicy .
Affected version
GitHub Copilot CLI 1.0.94.
Steps to reproduce the behavior
- Enable Sandbox
- Configure and install a sessionStart-Hook
- add readonly-Paths and readwrite-Paths (see above for which) to settings.json
- restart session, exit and then check whether the hook wrote logs -> no log written
- exit copilot
- run the hook's command manually -> log written
Expected behavior
Expected: A plugin's hooks/hooks.json SessionStart command hook runs at every fresh start.
Additional context
WSL2 (Ubuntu), sandbox enabled.
Describe the bug
Actual: The hook ran at session start, and its log showed it. After I added readonlyPaths ( /home//.copilot , /home//.nvm ) and readwritePaths ( …/.copilot/.cache/copilot/marketplaces , …/.copilot/installed-plugins , …/.copilot/plugin-data ) to sandbox.userPolicy.filesystem , it never runs again. /env still lists the hook. The hook's first statement in the command appends a line to $COPILOT_PLUGIN_DATA/hook-invoked.log , and that file is never created. No warning is shown, and the process logs contain no hook entries. Run by hand, the same command works.
Also unclear in the docs: The settings reference documents only filesystem.deniedPaths . It doesn't document readonlyPaths or readwritePaths , though the hooks docs say to grant hooks access via sandbox.userPolicy .
Affected version
GitHub Copilot CLI 1.0.94.
Steps to reproduce the behavior
Expected behavior
Expected: A plugin's hooks/hooks.json SessionStart command hook runs at every fresh start.
Additional context
WSL2 (Ubuntu), sandbox enabled.