deepseek-harness/docs/core-data-structures
kingwl 2dc62497ce feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.

- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
  deployment default mode + workspaceRoot and the per-session override event,
  renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
  Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
  write/edit by the per-call mode (read-only denies, workspace-write contains to
  the workspace + temp roots via the shared writableRoots, danger passes
  through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
  re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
  ladder, denial/hint markers, approveEscalation) both tool families use;
  approveEscalation takes a structural approver so dsh-sandbox gains no
  approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
  confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
  and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
  that disabled the fs stack under confined modes.

RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00
..
approval.md docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
bash.md fix(review): reconcile sandbox and approval contracts 2026-07-11 21:37:38 +08:00
code-runtime.md feat: Code Mode — the registry's mode config, the SDK codegen, and the run_code bridge 2026-07-08 12:58:23 +08:00
compaction.md docs(compact): sync the compactIfNeeded prose signature with the sessionPrefix parameter 2026-07-08 22:40:38 +08:00
core.md Merge remote-tracking branch 'origin/master' into session-query 2026-07-13 14:27:31 +08:00
filesystem.md feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
llm-streaming.md docs: make the service map the front door of architecture.md 2026-07-05 01:22:17 +08:00
persistence.md docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
sandbox.md fix(review): reconcile sandbox and approval contracts 2026-07-11 21:37:38 +08:00
scope.md docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
session-query.md refactor(session-query): narrow phase one to exact reads 2026-07-11 12:20:35 +08:00
session.md fix(session-query): address review round 1 2026-07-10 17:29:52 +08:00
skills.md docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
subagent.md docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
system-prompt.md refactor(core): remove owner-final assembly machinery 2026-07-13 13:09:41 +08:00
tools.md refactor(core): remove owner-final assembly machinery 2026-07-13 13:09:41 +08:00
user-interaction.md refactor: colocate user interaction with ui packages 2026-07-09 17:59:02 +08:00
web.md build: upgrade to 22.19 for deps 2026-07-07 17:39:04 +08:00
workflow.md workflow: meta rides the seam as data — the engine never evaluates it 2026-07-09 20:09:10 +08:00