core.md read as a type grab-bag: LLM wire vocabulary up front, the agent/loop story buried, and no correspondence to packages/core. It now opens on the packages/core control spine — the package-by-package loop map with a Page column into session/system-prompt/tools/scope — and keeps only what the spine group declares plus the repo-wide patterns: the Agent handle with its delivery/cancellation/interception contracts, the SessionEvent envelope, branded ids, the …Map pattern. The conversation vocabulary (Message/ContentBlock, the model request, adapters — 17 type-equiv blocks) moves to llm-streaming.md, which now declares packages/llm end-to-end; the duplicate ContentBlockMap paste near its seam section folds into the moved section, and the manifest, LINK_MAP, README table rows, website label (Core data structures → Core), and inbound anchors follow. Every packages/<group>/README pair is now a thin front door in one shape: a why-first intro (bash's seam-pattern-first paragraph rewritten as 'shell execution for the agent'), the package table, and a closing pointer to the owning docs/subsystems page — the bash-style table stays the load-bearing middle. Load-bearing trailing paragraphs relocate rather than vanish: the fs no-timeout rationale becomes a filesystem.md section (both languages), session's four sectioned tables merge into one 12-row table, examples' legacy-bin H2 collapses to a pointer at jsonrpc-demo's README, and design rationale that already lives in an Agent Note or subsystem page is now linked instead of restated. All 40 pair records re-recorded.
1.2 KiB
1.2 KiB
sandbox/:进程沙箱能力家族
English | 中文
本家族将逐会话限制策略应用于进程执行。它覆盖与宿主共享文件系统和内核的子进程;隔离环境会替换完整的能力实现,而不是在此注册。
| 包 | 职责 | ctx key |
|---|---|---|
sandbox/ |
定义进程沙箱服务和共享升权词汇 | ctx.sandbox |
sandbox-local/ |
提供本地平台限制后端 | 注册到 ctx.sandbox |
sandbox-policy/ |
解析持久的逐会话沙箱策略 | ctx.sandboxPolicy |
沙箱决策记录了能力边界,文件系统集成决策记录了跨家族策略的使用方式。
子系统参考——模式与强制执行、按调用策略、包装 argv 方言、故障关闭错误——见 docs/subsystems/sandbox.md;边界与跨家族阶段见沙箱与跨家族 fs 沙箱 Agent Note。