deepseek-harness/docs
Huanqi Cao 5fea4b7c4b feat(sandbox): derive the windows-acl write SID per workspace, not per session
The per-session random write SID forced a full tree propagation per
session per server lifetime (minutes on large workspaces). The write
SID is now the per-workspace identity derived from the canonical
workspace path (workspaceWriteSid: sha256 -> S-1-4-x-y), stored
nowhere: the workspace-root ACE materializes once per workspace per
machine and every later provision hits the exact-ACE skip.

- workspace ACEs are STANDING (never revoked - the reuse cache); temp
  ACEs stay revocable (disposed with the provider), so an inheritable
  ACE never outlives its session's temp dir on the ambient temp root
- AclSandbox requires the write SID under workspace-write; read-only
  parses/grants nothing; the runner derives the SID itself (the
  --write-sid flag's presence still marks the seam-managed contract)
- the acl-session record drops writeSid (sessionId/workspace/tempDir
  remain): the SID-tamper surface and its validation are gone
- sandbox-local holds two grant maps: standing workspace grants and
  revocable per-session temp grants

Docs (README pair, design note pair, catalogs, type-equiv) and the
acl-session/grant/acl/probe/runner suites updated; workspace-sid.spec
pins the derivation contract.
2026-08-09 10:44:35 +08:00
..
cookbook cleanup(cli): remove dsh-cli-demo 2026-08-08 15:08:07 +08:00
cordis-api docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
cordis-tutorial docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
i18n docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
postmortem docs: rename core-data-structures/ to subsystems/ 2026-08-09 01:27:09 +08:00
subsystems feat(sandbox): derive the windows-acl write SID per workspace, not per session 2026-08-09 10:44:35 +08:00
user docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
agent-lifecycle.md fix inbox lifecycle downstream contracts 2026-07-31 22:00:39 +08:00
AGENTS.md docs(subsystems): open core.md on agent creation/ownership and the Agent contract; enforce a complete folder index 2026-08-09 01:34:23 +08:00
api-gateway.i18n.yaml fix(docs): keep doc typecheck on Host sources 2026-08-08 11:52:18 +08:00
api-gateway.md fix(docs): keep doc typecheck on Host sources 2026-08-08 11:52:18 +08:00
api-gateway.zh.md fix(docs): keep doc typecheck on Host sources 2026-08-08 11:52:18 +08:00
architecture.i18n.yaml docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
architecture.md docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
architecture.zh.md docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
capability-seams.md refactor(packages): merge timeout/ into guard/, rename cordis/ to self-modification/ 2026-08-09 01:21:12 +08:00
config-catalog.md feat(sandbox): derive the windows-acl write SID per workspace, not per session 2026-08-09 10:44:35 +08:00
cordis-paper.pdf docs: add cordis paper 2026-07-31 15:54:36 +08:00
cordis-primer.i18n.yaml docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
cordis-primer.md docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
cordis-primer.zh.md docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
defensive-patterns.i18n.yaml Merge remote-tracking branch 'origin/master' into xtr/react-loop-simplification 2026-08-05 20:43:30 +08:00
defensive-patterns.md Merge remote-tracking branch 'origin/master' into xtr/react-loop-simplification 2026-08-05 20:43:30 +08:00
defensive-patterns.zh.md Merge remote-tracking branch 'origin/master' into xtr/react-loop-simplification 2026-08-05 20:43:30 +08:00
development.i18n.yaml docs: give subsystems/ its own README index; retire the data-structures-catalog framing 2026-08-09 01:32:39 +08:00
development.md docs: give subsystems/ its own README index; retire the data-structures-catalog framing 2026-08-09 01:32:39 +08:00
development.zh.md docs: give subsystems/ its own README index; retire the data-structures-catalog framing 2026-08-09 01:32:39 +08:00
event-producer-consumer.md docs(agent-note): flip the regrouping note to implemented 2026-08-09 01:25:24 +08:00
glossary.i18n.yaml cleanup: replace FIXMEs with tracked issues 2026-08-08 00:04:55 +08:00
glossary.md cleanup: replace FIXMEs with tracked issues 2026-08-08 00:04:55 +08:00
glossary.zh.md cleanup: replace FIXMEs with tracked issues 2026-08-08 00:04:55 +08:00
graph-atlas.md docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
module-graph.md chore(docs): regenerate module graph for merged tree 2026-08-09 03:19:09 +08:00
persistence-catalog.md feat(sandbox): derive the windows-acl write SID per workspace, not per session 2026-08-09 10:44:35 +08:00
testing.i18n.yaml refactor(packages): dissolve ui/ and rename sdk/ to scaffold/ 2026-08-09 01:21:12 +08:00
testing.md refactor(packages): dissolve ui/ and rename sdk/ to scaffold/ 2026-08-09 01:21:12 +08:00
testing.zh.md refactor(packages): dissolve ui/ and rename sdk/ to scaffold/ 2026-08-09 01:21:12 +08:00
tool-catalog.md Merge remote-tracking branch 'origin/feat/windows-pwsh-default' into feat/windows-acl-sandbox 2026-08-09 02:53:48 +08:00
tool-execution-pipeline.md Merge remote-tracking branch 'origin/master' into feat/send-unify 2026-07-23 22:41:45 +08:00
web-styling.i18n.yaml docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
web-styling.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
web-styling.zh.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00