The three-entry cordis.yml (dsh-sandbox-local + dsh-bash-sandbox at a read-only default + dsh-approval) served over ACP: the first live approval composition. Recorded snapshot scenarios pin the wire end to end — config-options advertisement, the mode-switching arc as the suite pinned header (both switches, the prompt-section delta, one changed-by-the-user notice per knob, a confined write landing under the switched mode), and both escalation branches over scripted permissionAnswers (a grant runs confined under workspace-write; a rejection executes nothing and pins the fail-closed text). The with-key escalation e2e drives a real model + real runner + the real bridge answerer, world-verified; ci.yml snapshot lane and e2e.yml install bubblewrap so the confined replays actually execute. Both RFCs move to implemented/ (Decision/Consequences form, deferred phases tracked in their own sections), with every cross-reference flipped.
11 lines
428 B
JSON
11 lines
428 B
JSON
{
|
|
"steps": [
|
|
{ "op": "initialize" },
|
|
{ "op": "newSession" },
|
|
{ "op": "setConfigOption", "configId": "sandbox-mode", "value": "workspace-write" },
|
|
{ "op": "setConfigOption", "configId": "approval-policy", "value": "never" },
|
|
{ "op": "setConfigOptionExpectError", "configId": "sandbox-mode", "value": "yolo" },
|
|
{ "op": "setConfigOptionExpectError", "configId": "reasoning-effort", "value": "max" }
|
|
]
|
|
}
|