deepseek-harness/docs
Yichen Jiang a90ccc4453 revert(sandbox): withdraw the credential-document read denial
The `readDenyPaths` policy field shipped in the previous commit broke Linux
confinement outright. bwrap has to create the `/dev/null` bind's mount point
inside a tree its own profile has already made read-only, so it refused the
entire confinement whenever the parent directory was absent — every host that
has not stored a credential yet, including a fresh install:

  bwrap: Can't mkdir parents for /home/runner/.dsh/.env: Read-only file system

which the executor correctly classifies as SANDBOX_UNAVAILABLE, so every
confined bash call failed closed. Landlock cannot subtract from its own `/`
read grant, so it reported `partial` enforcement on every confined call for a
file it never hid, with no way to switch the denial off (schemastery fills an
omitted array with `[]`, so empty and omitted were indistinguishable).

A protection that breaks confinement where it works and misreports it where it
does not is worse than a documented absence. Revert the field, both expressible
backends, the enforcement downgrade, and the policy default; state the residue
plainly in the credentials-local READMEs — file mode stops other OS users, not
the model — and keep the OS-keychain provider recorded as the real answer.

The narrower discipline stands: no surface hoists the credential document into
`process.env`, and the model is never handed a resolved path to it.
2026-07-30 17:09:42 +08:00
..
cookbook refactor: migrate linting to Oxlint 2026-07-29 14:32:11 +08:00
cordis-catalog revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
cordis-tutorial docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
core-data-structures revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
i18n Merge branch 'master' into fix/translation-brief-uncommitted-pair 2026-07-29 20:54:30 +08:00
postmortem docs(i18n): record proofread README pairs 2026-07-29 15:30:44 +08:00
user Merge remote-tracking branch 'origin/master' into xtr/agent-loop-message-machine 2026-07-27 16:48:38 +08:00
agent-lifecycle.md refactor(agent): return request retry action 2026-07-27 21:17:49 +08:00
AGENTS.md docs(notes): archive low-value decision records 2026-07-26 23:06:00 +08:00
architecture.i18n.yaml refactor(agent): scope queue actions to edit and remove 2026-07-30 01:58:51 +08:00
architecture.md refactor(agent): scope queue actions to edit and remove 2026-07-30 01:58:51 +08:00
architecture.zh.md refactor(agent): scope queue actions to edit and remove 2026-07-30 01:58:51 +08:00
capability-seams.md Merge branch 'worktree-config-settings-seam' into worktree-llm-dynamic-config 2026-07-30 14:33:36 +08:00
config-catalog.md revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
cordis-primer.i18n.yaml docs(i18n): clarify Cordis and test wording 2026-07-24 14:21:15 +08:00
cordis-primer.md Merge remote-tracking branch 'origin/master' into worktree/pr343-retarget-latest-master 2026-07-23 13:40:29 +08:00
cordis-primer.zh.md docs(i18n): clarify Cordis and test wording 2026-07-24 14:21:15 +08:00
defensive-patterns.i18n.yaml docs(security): include password names in scrub rule 2026-07-28 09:40:33 -07:00
defensive-patterns.md docs(security): include password names in scrub rule 2026-07-28 09:40:33 -07:00
defensive-patterns.zh.md docs(security): include password names in scrub rule 2026-07-28 09:40:33 -07:00
development.i18n.yaml docs: correct the Oxlint workflow contract 2026-07-29 23:45:06 +08:00
development.md docs: correct the Oxlint workflow contract 2026-07-29 23:45:06 +08:00
development.zh.md docs: correct the Oxlint workflow contract 2026-07-29 23:45:06 +08:00
event-producer-consumer.md docs(credentials): record the third-review contracts across READMEs, catalogs, and a new Agent Note 2026-07-30 16:37:28 +08:00
glossary.i18n.yaml docs: align Goal Round step cardinality 2026-07-24 12:10:40 +08:00
glossary.md docs: align Goal Round step cardinality 2026-07-24 12:10:40 +08:00
glossary.zh.md docs(i18n): allow zero-step Goal Rounds 2026-07-23 21:13:34 +08:00
graph-atlas.md docs(graphs): retain archived rationale link 2026-07-26 23:08:47 +08:00
module-graph.md docs(credentials): record the third-review contracts across READMEs, catalogs, and a new Agent Note 2026-07-30 16:37:28 +08:00
persistence-catalog.md Merge remote-tracking branch 'origin/master' into worktree-renameweb 2026-07-29 21:45:29 +08:00
testing.i18n.yaml build(web): rebuild plugin bundles before the browser lane 2026-07-28 18:14:22 +08:00
testing.md build(web): rebuild plugin bundles before the browser lane 2026-07-28 18:14:22 +08:00
testing.zh.md build(web): rebuild plugin bundles before the browser lane 2026-07-28 18:14:22 +08:00
tool-catalog.md Merge latest master into skill catalog hot refresh 2026-07-28 01:10:33 +08:00
tool-execution-pipeline.md Merge remote-tracking branch 'origin/master' into feat/send-unify 2026-07-23 22:41:45 +08:00
typert-catalog-integration-design.i18n.yaml refactor(cordis): generate catalogs from Typert models 2026-07-29 23:55:12 +08:00
typert-catalog-integration-design.md refactor(cordis): generate catalogs from Typert models 2026-07-29 23:55:12 +08:00
typert-catalog-integration-design.zh.md refactor(cordis): generate catalogs from Typert models 2026-07-29 23:55:12 +08:00
web-styling.i18n.yaml docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
web-styling.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
web-styling.zh.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00