2026-07-09 16:05:44 +08:00
|
|
|
{
|
|
|
|
|
"extends": "../../../tsconfig.base.json",
|
|
|
|
|
"compilerOptions": {
|
|
|
|
|
"rootDir": "src",
|
|
|
|
|
"outDir": "lib/types"
|
|
|
|
|
},
|
|
|
|
|
"include": [
|
|
|
|
|
"src"
|
|
|
|
|
],
|
|
|
|
|
"references": [
|
|
|
|
|
{
|
|
|
|
|
"path": "../../../vendor/cosmokit"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"path": "../../../vendor/cordis"
|
|
|
|
|
},
|
2026-08-06 10:23:26 +08:00
|
|
|
{
|
|
|
|
|
"path": "../../../native/landlock-run/packages/entry"
|
|
|
|
|
},
|
2026-07-09 16:05:44 +08:00
|
|
|
{
|
|
|
|
|
"path": "../../util/brand"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"path": "../../llm/llm"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"path": "../../sandbox/sandbox"
|
|
|
|
|
},
|
feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.
- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
deployment default mode + workspaceRoot and the per-session override event,
renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
write/edit by the per-call mode (read-only denies, workspace-write contains to
the workspace + temp roots via the shared writableRoots, danger passes
through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
ladder, denial/hint markers, approveEscalation) both tool families use;
approveEscalation takes a structural approver so dsh-sandbox gains no
approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
that disabled the fs stack under confined modes.
RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00
|
|
|
{
|
|
|
|
|
"path": "../../sandbox/sandbox-policy"
|
|
|
|
|
},
|
2026-07-09 16:05:44 +08:00
|
|
|
{
|
2026-08-13 00:36:22 +08:00
|
|
|
"path": "../../shell/shell"
|
2026-07-09 16:05:44 +08:00
|
|
|
},
|
|
|
|
|
{
|
2026-08-13 00:36:22 +08:00
|
|
|
"path": "../../shell/bash-local"
|
2026-07-19 22:13:50 +08:00
|
|
|
},
|
|
|
|
|
{
|
2026-08-13 00:36:22 +08:00
|
|
|
"path": "../../runtime-diagnostics/invariants"
|
2026-07-09 16:05:44 +08:00
|
|
|
}
|
|
|
|
|
]
|
|
|
|
|
}
|