deepseek-harness/docs/core-data-structures
Yichen Jiang a90ccc4453 revert(sandbox): withdraw the credential-document read denial
The `readDenyPaths` policy field shipped in the previous commit broke Linux
confinement outright. bwrap has to create the `/dev/null` bind's mount point
inside a tree its own profile has already made read-only, so it refused the
entire confinement whenever the parent directory was absent — every host that
has not stored a credential yet, including a fresh install:

  bwrap: Can't mkdir parents for /home/runner/.dsh/.env: Read-only file system

which the executor correctly classifies as SANDBOX_UNAVAILABLE, so every
confined bash call failed closed. Landlock cannot subtract from its own `/`
read grant, so it reported `partial` enforcement on every confined call for a
file it never hid, with no way to switch the denial off (schemastery fills an
omitted array with `[]`, so empty and omitted were indistinguishable).

A protection that breaks confinement where it works and misreports it where it
does not is worse than a documented absence. Revert the field, both expressible
backends, the enforcement downgrade, and the policy default; state the residue
plainly in the credentials-local READMEs — file mode stops other OS users, not
the model — and keep the OS-keychain provider recorded as the real answer.

The narrower discipline stands: no surface hoists the credential document into
`process.env`, and the model is never handed a resolved path to it.
2026-07-30 17:09:42 +08:00
..
approval.i18n.yaml docs(i18n): mirror ACP-automation edits into the zh pairs from master 2026-07-25 01:58:42 +08:00
approval.md Merge remote-tracking branch 'origin/master' into worktree/acp-automation-protocol 2026-07-24 23:43:10 +08:00
approval.zh.md docs(i18n): mirror ACP-automation edits into the zh pairs from master 2026-07-25 01:58:42 +08:00
bash.i18n.yaml subprocess: one explicit env channel on the spawn spec 2026-07-27 04:14:51 +08:00
bash.md subprocess: one explicit env channel on the spawn spec 2026-07-27 04:14:51 +08:00
bash.zh.md subprocess: one explicit env channel on the spawn spec 2026-07-27 04:14:51 +08:00
code-runtime.i18n.yaml docs(i18n): refresh core translations for latest master 2026-07-23 19:29:01 +08:00
code-runtime.md Merge branch 'worktree/pr343-retarget-latest-master' into worktree/pr344-retarget-stack 2026-07-23 19:10:25 +08:00
code-runtime.zh.md docs(i18n): refresh core translations for latest master 2026-07-23 19:29:01 +08:00
commands.i18n.yaml docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
commands.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
commands.zh.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
compaction.i18n.yaml cleanup(session): isolate trajectory inspection 2026-07-28 11:39:53 +08:00
compaction.md cleanup(session): isolate trajectory inspection 2026-07-28 11:39:53 +08:00
compaction.zh.md cleanup(session): isolate trajectory inspection 2026-07-28 11:39:53 +08:00
core.i18n.yaml docs(credentials): record the third-review contracts across READMEs, catalogs, and a new Agent Note 2026-07-30 16:37:28 +08:00
core.md docs(credentials): record the third-review contracts across READMEs, catalogs, and a new Agent Note 2026-07-30 16:37:28 +08:00
core.zh.md docs(credentials): record the third-review contracts across READMEs, catalogs, and a new Agent Note 2026-07-30 16:37:28 +08:00
credentials.i18n.yaml docs: bilingual credentials/settings-consumer documentation, catalogs, and gates 2026-07-29 14:20:06 +08:00
credentials.md docs: bilingual credentials/settings-consumer documentation, catalogs, and gates 2026-07-29 14:20:06 +08:00
credentials.zh.md docs: bilingual credentials/settings-consumer documentation, catalogs, and gates 2026-07-29 14:20:06 +08:00
filesystem.i18n.yaml docs(i18n): refresh core translations for latest master 2026-07-23 19:29:01 +08:00
filesystem.md Merge branch 'worktree/pr343-retarget-latest-master' into worktree/pr344-retarget-stack 2026-07-23 19:10:25 +08:00
filesystem.zh.md docs(i18n): refresh core translations for latest master 2026-07-23 19:29:01 +08:00
goal.i18n.yaml Merge remote-tracking branch 'origin/master' into xtr/agent-loop-message-machine 2026-07-26 16:45:27 +08:00
goal.md Merge remote-tracking branch 'origin/master' into xtr/agent-loop-message-machine 2026-07-26 16:45:27 +08:00
goal.zh.md Merge remote-tracking branch 'origin/master' into xtr/agent-loop-message-machine 2026-07-26 16:45:27 +08:00
llm-streaming.i18n.yaml refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
llm-streaming.md refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
llm-streaming.zh.md refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
lsp.i18n.yaml docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
lsp.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
lsp.zh.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
persistence.i18n.yaml fix(subagent): publish inherited policy facts to telemetry 2026-07-29 00:39:56 +08:00
persistence.md fix(subagent): publish inherited policy facts to telemetry 2026-07-29 00:39:56 +08:00
persistence.zh.md fix(subagent): publish inherited policy facts to telemetry 2026-07-29 00:39:56 +08:00
pty.i18n.yaml docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
pty.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
pty.zh.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
sandbox.i18n.yaml revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
sandbox.md revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
sandbox.zh.md revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
scope.i18n.yaml docs(i18n): normalize core terminology 2026-07-23 18:45:56 +08:00
scope.md Merge refreshed docs/i18n-batch-core into docs/i18n-batch-cds-postmortem 2026-07-22 22:26:24 +08:00
scope.zh.md docs(i18n): normalize core terminology 2026-07-23 18:45:56 +08:00
session-query.i18n.yaml Merge remote-tracking branch 'origin/master' into session-query-tool 2026-07-25 14:17:24 +08:00
session-query.md Merge remote-tracking branch 'origin/master' into session-query-tool 2026-07-25 14:17:24 +08:00
session-query.zh.md Merge remote-tracking branch 'origin/master' into session-query-tool 2026-07-25 14:17:24 +08:00
session-reference.i18n.yaml refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
session-reference.md refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
session-reference.zh.md refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
session-title.i18n.yaml fix(session-title): typed rename rejection, provenance invariant, contract docs 2026-07-29 20:10:42 +08:00
session-title.md fix(session-title): typed rename rejection, provenance invariant, contract docs 2026-07-29 20:10:42 +08:00
session-title.zh.md fix(session-title): typed rename rejection, provenance invariant, contract docs 2026-07-29 20:10:42 +08:00
session.i18n.yaml feat(typert): add compiler-independent type pipeline 2026-07-29 23:45:42 +08:00
session.md feat(typert): add compiler-independent type pipeline 2026-07-29 23:45:42 +08:00
session.zh.md feat(typert): add compiler-independent type pipeline 2026-07-29 23:45:42 +08:00
settings.i18n.yaml docs(settings): third-review contracts across READMEs, catalogs, and the write-path integrity note 2026-07-30 14:09:04 +08:00
settings.md docs(settings): third-review contracts across READMEs, catalogs, and the write-path integrity note 2026-07-30 14:09:04 +08:00
settings.zh.md docs(settings): third-review contracts across READMEs, catalogs, and the write-path integrity note 2026-07-30 14:09:04 +08:00
skills.i18n.yaml Merge remote-tracking branch 'origin/master' into worktree/pr823-retarget-latest-20260729 2026-07-29 23:36:49 +08:00
skills.md Merge remote-tracking branch 'origin/master' into worktree/pr823-retarget-latest-20260729 2026-07-29 23:36:49 +08:00
skills.zh.md Merge remote-tracking branch 'origin/master' into worktree/pr823-retarget-latest-20260729 2026-07-29 23:36:49 +08:00
spill.i18n.yaml docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
spill.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
spill.zh.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
subagent.i18n.yaml docs(subagent): restore refusal contract comment 2026-07-25 15:25:52 +08:00
subagent.md docs(subagent): restore refusal contract comment 2026-07-25 15:25:52 +08:00
subagent.zh.md docs(subagent): restore refusal contract comment 2026-07-25 15:25:52 +08:00
subprocess.i18n.yaml Merge remote-tracking branch 'origin/worktree-process-service-seam' into subprocess-simpl/d-one-env-channel 2026-07-27 11:31:38 +08:00
subprocess.md Merge remote-tracking branch 'origin/worktree-process-service-seam' into subprocess-simpl/d-one-env-channel 2026-07-27 11:31:38 +08:00
subprocess.zh.md Merge remote-tracking branch 'origin/worktree-process-service-seam' into subprocess-simpl/d-one-env-channel 2026-07-27 11:31:38 +08:00
system-prompt.i18n.yaml docs(i18n): normalize core terminology 2026-07-23 18:45:56 +08:00
system-prompt.md Merge refreshed docs/i18n-batch-core into docs/i18n-batch-cds-postmortem 2026-07-22 22:26:24 +08:00
system-prompt.zh.md docs(i18n): normalize core terminology 2026-07-23 18:45:56 +08:00
tasks.i18n.yaml docs(tasks): bring the zh side of the tasks pairs along after the master merge 2026-07-26 20:59:05 +08:00
tasks.md Merge remote-tracking branch 'origin/master' into worktree-tasks-service-seam 2026-07-26 20:28:37 +08:00
tasks.zh.md docs(tasks): bring the zh side of the tasks pairs along after the master merge 2026-07-26 20:59:05 +08:00
token-meter.i18n.yaml docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
token-meter.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
token-meter.zh.md docs: translate remaining non-README documentation 2026-07-26 02:33:29 +08:00
tools.i18n.yaml refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
tools.md refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
tools.zh.md refactor: identify and freeze messages at creation 2026-07-28 13:55:59 +08:00
user-interaction.i18n.yaml docs(i18n): mirror ACP-automation edits into the zh pairs from master 2026-07-25 01:58:42 +08:00
user-interaction.md Merge remote-tracking branch 'origin/master' into worktree/acp-automation-protocol 2026-07-24 23:43:10 +08:00
user-interaction.zh.md Merge remote-tracking branch 'origin/master' into worktree/acp-automation-protocol 2026-07-24 23:43:10 +08:00
web.i18n.yaml docs(i18n): clarify review terminology 2026-07-24 14:21:36 +08:00
web.md Merge refreshed docs/i18n-batch-core into docs/i18n-batch-cds-postmortem 2026-07-22 22:26:24 +08:00
web.zh.md docs(i18n): clarify review terminology 2026-07-24 14:21:36 +08:00
workflow.i18n.yaml docs(i18n): normalize core terminology 2026-07-23 18:45:56 +08:00
workflow.md Merge refreshed docs/i18n-batch-core into docs/i18n-batch-cds-postmortem 2026-07-22 22:26:24 +08:00
workflow.zh.md docs(i18n): normalize core terminology 2026-07-23 18:45:56 +08:00