deepseek-harness/docs
imccyu db857f62c0 docs(tool-cordis): state the sandbox stance as steering, not containment
The sandbox docs overclaimed a containment contract the design never makes:
"capability access is routed through cordis services, never Node built-ins,
so everything a mounted plugin does stays inspectable and disposable". The
host-realm helpers on the sandbox global (harness, console, btoa) are
reachable functions, so mount code that goes looking can reach the host realm
through one of them — accepted under the trust stance, because the ctx a
mount ultimately receives is fully privileged anyway. Reword the sandbox
module doc, the README trust stance, and the RFC sandbox-semantics section to
say exactly that: the traps and small global surface STEER honest code onto
the cordis services; they are not a security boundary.
2026-07-09 18:51:44 +08:00
..
cookbook docs: the governing principle — every LLM request is reconstructable from the session log 2026-07-06 03:49:35 +08:00
cordis-catalog Merge remote-tracking branch 'origin/master' into timeout-design 2026-07-08 15:40:56 +08:00
core-data-structures Merge remote-tracking branch 'origin/master' into timeout-design 2026-07-08 15:40:56 +08:00
i18n docs: equal-authority pairing with sidecar consistency records 2026-07-03 07:41:24 -07:00
postmortem fix(docs): address Codex review round 3 — last three moved-policy citations 2026-07-04 16:02:39 +08:00
rfc docs(tool-cordis): state the sandbox stance as steering, not containment 2026-07-09 18:51:44 +08:00
agent-lifecycle.md docs: address graph review placement 2026-07-05 02:54:01 +08:00
AGENTS.md docs: tighten development onboarding wording 2026-07-07 19:03:14 +08:00
architecture.md Merge remote-tracking branch 'origin/master' into timeout-design 2026-07-08 15:40:56 +08:00
capability-seams.md chore: register the cordis group across repo gates and docs 2026-07-09 13:57:03 +08:00
config-catalog.md fix(tool-cordis): replace the pass-through ctx proxy with a whitelist façade 2026-07-09 13:57:03 +08:00
cordis-primer.md docs: split cordis primer from architecture map 2026-07-05 19:07:34 +08:00
defensive-patterns.md docs(AGENTS): rewrite the root standing orders to the 1,500-word budget 2026-07-04 14:22:47 +08:00
development.i18n.yaml Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
development.md Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
development.zh.md Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
event-producer-consumer.md Merge remote-tracking branch 'origin/master' into timeout-design 2026-07-09 11:52:18 +08:00
graph-atlas.md chore: register the cordis group across repo gates and docs 2026-07-09 13:57:03 +08:00
module-graph.md chore: register the cordis group across repo gates and docs 2026-07-09 13:57:03 +08:00
persistence-catalog.md Merge remote-tracking branch 'origin/master' into worktree-export-jsdoc-gate 2026-07-07 09:34:12 +08:00
testing.md Merge remote-tracking branch 'origin/master' into code-runtime-worker 2026-07-08 14:44:23 +08:00
tool-catalog.md fix(tool-cordis): gate façade services on inject, and make tools.get read-only 2026-07-09 13:57:03 +08:00
tool-execution-pipeline.md feat(timeout): add tools/execute seam + tool-timeout policy plugin 2026-07-08 10:10:37 +08:00