deepseek-harness/docs
kingwl 2dc62497ce feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.

- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
  deployment default mode + workspaceRoot and the per-session override event,
  renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
  Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
  write/edit by the per-call mode (read-only denies, workspace-write contains to
  the workspace + temp roots via the shared writableRoots, danger passes
  through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
  re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
  ladder, denial/hint markers, approveEscalation) both tool families use;
  approveEscalation takes a structural approver so dsh-sandbox gains no
  approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
  confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
  and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
  that disabled the fs stack under confined modes.

RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00
..
cookbook python: derive release version from repository 2026-07-13 17:49:01 +08:00
cordis-catalog feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
core-data-structures feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
i18n docs(i18n): align single-exe terminology 2026-07-13 22:09:41 +08:00
postmortem fix(docs): address Codex review round 3 — last three moved-policy citations 2026-07-04 16:02:39 +08:00
rfc feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
agent-lifecycle.md docs: align the agent-scope contracts 2026-07-11 22:55:40 +08:00
AGENTS.md make wordcount budget guidance clearer and dedup docs 2026-07-10 00:20:35 +08:00
architecture.md feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
capability-seams.md feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
config-catalog.md feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
cordis-primer.md fix(scope): harden lifecycle ownership foundation 2026-07-12 08:57:05 +08:00
defensive-patterns.md docs(AGENTS): rewrite the root standing orders to the 1,500-word budget 2026-07-04 14:22:47 +08:00
development.i18n.yaml fix(workflow): bootstrap source worker transforms 2026-07-12 06:19:53 +08:00
development.md fix(workflow): bootstrap source worker transforms 2026-07-12 06:19:53 +08:00
development.zh.md fix(workflow): bootstrap source worker transforms 2026-07-12 06:19:53 +08:00
event-producer-consumer.md feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
glossary.md docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
graph-atlas.md chore: register the cordis group across repo gates and docs 2026-07-09 13:57:03 +08:00
module-graph.md feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
persistence-catalog.md feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
testing.md fix(pkg): support worker-backed tools in single exe 2026-07-13 21:40:33 +08:00
tool-catalog.md refactor(core): remove owner-final assembly machinery 2026-07-13 13:09:41 +08:00
tool-execution-pipeline.md refactor: narrow synchronous extension contracts 2026-07-13 11:58:55 +08:00