deepseek-harness/docs
imccyu 1b1ba96d4f fix(tool-cordis): replace the pass-through ctx proxy with a whitelist façade
Review finding (#220): the guarded proxy only special-cased ctx.tools, so
mount code could reach an UNGUARDED context through ctx.root, ctx.extend(), or
a service instance's .ctx, then ctx.root.tools.register({…}) to bypass the
marker check and host-realm normalization — a raw vm-realm result would later
error a real agent turn at the session-log plainness check.

The sandbox ctx is now a whitelist façade, not a pass-through proxy: it exposes
only what a mount needs — tools.register (marker-guarded), on/once, provide, the
timer helpers, and injected services resolved through a guarded get — and denies
every framework-plumbing member (root, parent, fiber, reflect, registry, extend,
isolate, intercept, plugin, set, mixin, …) with a teaching error. Injected
services are wrapped so a method returning a Context is rejected on the way back
(the .ctx escape), closing the one indirect leak. There is no context-valued
member left to reach; cross-mount provide/inject is untouched (the plugin's own
inject and the fiber's pending/active gating are unchanged). ctx.plugin (child
plugins) and ctx.set are denied by design; ctx.effect is deferred (FIXME).

Adds tests/sandbox-context.spec.ts covering the escape class (root/extend/fiber/
plugin/set/… denied, the classic root.tools.register bypass, the .ctx escape,
read-only writes) plus the async-service and symbol/in-operator paths for 100%
coverage. RFC/README/tool-catalog/config-catalog updated; api-catalog.ts
regenerated (also picks up the codeRuntime service that entered on the master
merge and was left stale).
2026-07-09 13:57:03 +08:00
..
cookbook docs: the governing principle — every LLM request is reconstructable from the session log 2026-07-06 03:49:35 +08:00
cordis-catalog Merge remote-tracking branch 'origin/master' into timeout-design 2026-07-08 15:40:56 +08:00
core-data-structures Merge remote-tracking branch 'origin/master' into timeout-design 2026-07-08 15:40:56 +08:00
i18n docs: equal-authority pairing with sidecar consistency records 2026-07-03 07:41:24 -07:00
postmortem fix(docs): address Codex review round 3 — last three moved-policy citations 2026-07-04 16:02:39 +08:00
rfc fix(tool-cordis): replace the pass-through ctx proxy with a whitelist façade 2026-07-09 13:57:03 +08:00
agent-lifecycle.md docs: address graph review placement 2026-07-05 02:54:01 +08:00
AGENTS.md docs: tighten development onboarding wording 2026-07-07 19:03:14 +08:00
architecture.md Merge remote-tracking branch 'origin/master' into timeout-design 2026-07-08 15:40:56 +08:00
capability-seams.md chore: register the cordis group across repo gates and docs 2026-07-09 13:57:03 +08:00
config-catalog.md fix(tool-cordis): replace the pass-through ctx proxy with a whitelist façade 2026-07-09 13:57:03 +08:00
cordis-primer.md docs: split cordis primer from architecture map 2026-07-05 19:07:34 +08:00
defensive-patterns.md docs(AGENTS): rewrite the root standing orders to the 1,500-word budget 2026-07-04 14:22:47 +08:00
development.i18n.yaml Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
development.md Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
development.zh.md Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
event-producer-consumer.md Merge remote-tracking branch 'origin/master' into timeout-design 2026-07-09 11:52:18 +08:00
graph-atlas.md chore: register the cordis group across repo gates and docs 2026-07-09 13:57:03 +08:00
module-graph.md chore: register the cordis group across repo gates and docs 2026-07-09 13:57:03 +08:00
persistence-catalog.md Merge remote-tracking branch 'origin/master' into worktree-export-jsdoc-gate 2026-07-07 09:34:12 +08:00
testing.md Merge remote-tracking branch 'origin/master' into code-runtime-worker 2026-07-08 14:44:23 +08:00
tool-catalog.md fix(tool-cordis): replace the pass-through ctx proxy with a whitelist façade 2026-07-09 13:57:03 +08:00
tool-execution-pipeline.md feat(timeout): add tools/execute seam + tool-timeout policy plugin 2026-07-08 10:10:37 +08:00