deepseek-harness/scripts
kingwl 2dc62497ce feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.

- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
  deployment default mode + workspaceRoot and the per-session override event,
  renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
  Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
  write/edit by the per-call mode (read-only denies, workspace-write contains to
  the workspace + temp roots via the shared writableRoots, danger passes
  through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
  re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
  ladder, denial/hint markers, approveEscalation) both tool families use;
  approveEscalation takes a structural approver so dsh-sandbox gains no
  approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
  confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
  and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
  that disabled the fs stack under confined modes.

RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00
..
snapshots/python-sdk-single-exe/advanced test(pkg): snapshot advanced Python SDK executable flow 2026-07-13 23:31:26 +08:00
build-exe-for-python-sdk.ts python: close runtime packaging and platform wheels 2026-07-13 16:34:09 +08:00
build-python-release.py python: derive release version from repository 2026-07-13 17:49:01 +08:00
check-vendor-manifest.sh Add lefthook git hooks with a vendor-manifest guard 2026-06-11 15:07:55 +08:00
check-workspace-constraints.ts fix(pkg): support worker-backed tools in single exe 2026-07-13 21:40:33 +08:00
demo-code-mode.mjs fix(permission): address human review feedback 2026-07-14 01:09:44 +08:00
doc-budgets.manifest.json feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
doc-typecheck.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00
gen-config-catalog.ts feat(example): sandbox-acp-agent — the live composition; RFCs to implemented 2026-07-10 15:44:38 +08:00
gen-cordis-api.ts scripts: gen-cordis-api — the generated runtime API catalog pipeline 2026-07-09 13:57:03 +08:00
gen-cordis-catalog.ts docs(rfc): align scoped runtime contracts 2026-07-12 22:49:46 +08:00
gen-doc-graphs.ts feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity 2026-07-14 20:05:57 +08:00
gen-module-graph.ts Merge remote-tracking branch 'origin/master' into session-query 2026-07-14 08:36:06 +08:00
gen-persistence-catalog.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
gen-rfc-index.ts docs(rfc): define and enforce a uniform RFC format; adopt it across the corpus 2026-07-05 22:58:25 +08:00
gen-tool-catalog.ts refactor(core): remove owner-final assembly machinery 2026-07-13 13:09:41 +08:00
install-lefthook.mjs fix(dev): make hooks and bash seams safer 2026-06-17 21:26:44 +08:00
jsdoc.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
markdown.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
package-graph.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
publint-all.ts chore: parallelize pre-push gates 2026-07-06 00:52:00 +08:00
repo-files.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
rfc-index.ts docs(rfc): define and enforce a uniform RFC format; adopt it across the corpus 2026-07-05 22:58:25 +08:00
run-gates.ts Merge branch 'master' into worktree-singleexe 2026-07-14 00:07:22 +08:00
smoke-python-runtime.py test(pkg): snapshot advanced Python SDK executable flow 2026-07-13 23:31:26 +08:00
translation-pairing.manifest.json python: deepseek-harness SDK and runtime carrier packages 2026-07-13 15:50:09 +08:00
type-equiv.manifest.json Merge remote-tracking branch 'origin/master' into session-query 2026-07-13 14:27:31 +08:00
verify-doc-budgets.ts docs(budgets): ceilings carry at least 5% working headroom 2026-07-04 17:20:18 +08:00
verify-doc-refs.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
verify-export-jsdoc.ts fix review findings: CI leaf-gate wiring, heritage return surface, AGENTS.md self-containedness 2026-07-07 20:30:34 +08:00
verify-md-links.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
verify-md-wrap.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
verify-mermaid.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00
verify-node-next-types.ts docs: update rewriteRelativeImportExtensions to current rfc 2026-06-22 09:03:28 +08:00
verify-package-paths.ts chore: tighten TypeScript duplication lint 2026-07-14 00:24:04 +08:00
verify-rfc-classification.ts docs(rfc): define and enforce a uniform RFC format; adopt it across the corpus 2026-07-05 22:58:25 +08:00
verify-rfc-format.ts docs(rfc): address Codex review — fence-aware format gate, exact corpus counts 2026-07-05 23:45:34 +08:00
verify-runtime-closure.ts python: close runtime packaging and platform wheels 2026-07-13 16:34:09 +08:00
verify-scoped-dispatch.ts feat(dx): scopeHost, agent-aware ACP presentation, and the scoped-dispatch drift gate 2026-07-09 02:38:54 +08:00
verify-translation-pairing.ts python: deepseek-harness SDK and runtime carrier packages 2026-07-13 15:50:09 +08:00
verify-type-equiv.ts fix(scripts): replace async fs glob with globSync (failed on Node 22.18) 2026-07-07 17:15:41 +08:00