Files
deepseek-harness/packages/sandbox/README.md
T
kingwl 2dc62497ce feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.

- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
  deployment default mode + workspaceRoot and the per-session override event,
  renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
  Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
  write/edit by the per-call mode (read-only denies, workspace-write contains to
  the workspace + temp roots via the shared writableRoots, danger passes
  through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
  re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
  ladder, denial/hint markers, approveEscalation) both tool families use;
  approveEscalation takes a structural approver so dsh-sandbox gains no
  approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
  confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
  and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
  that disabled the fs stack under confined modes.

RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00

2.4 KiB

sandbox/ — process-sandbox capability family

The confinement half of the capability-seam split: an abstract provider interface, platform backends, and the shared policy home. Consumers hand ctx.sandbox the exact argv they are about to spawn and spawn the returned (wrapped) argv instead; policy (SandboxPolicy: mode + workspace root) rides each call, so different consumers confine under different policies at the same instant. All product packages.

Package Role ctx key
sandbox/ Abstract process-sandbox seam (the SandboxProvider contract + the mode/enforcement/policy vocabulary) plus the shared ESCALATION kit (approveEscalation, the strictly-wider ladder, the denial/hint markers) and the writableRoots derivation every enforcement dialect shares ctx.sandbox
sandbox-local/ Local backends by platform chain: Linux bwrap else the landlock-run launcher (the npm-distributed node-addon-landlock-run family, built and released from its own repository), darwin sandbox-exec/Seatbelt — multi-candidate chains functionally probed, sole candidates selected directly, verdict cached, fail-closed (registers ctx.sandbox)
sandbox-policy/ The policy home: the deployment default (mode + workspace-write boundary root) and the per-session sandbox/mode override (event + fold + write path). Both enforcing families read it, so bash and fs can never confine to different roots ctx.sandboxPolicy

The seam confines SAME-WORLD subprocesses only (shared filesystem and kernel). Containers, microVMs, and remote executors are NOT backends here — they replace whole capability implementations (ctx.bash, ctx.fs) as environment-coherent groups; the boundary is recorded in the sandbox RFC.

Consumers today: bash/bash-sandbox (wraps ['bash', '-c', command] through ctx.sandbox) and fs/fs-sandbox (an in-process path fence, not an argv wrapper — reads ctx.sandboxPolicy and enforces the shared mode on write/edit). The cross-family boundary is the sandbox RFC's cross-family fs sandbox phase; the shared vocabulary lets both families teach the model one denial marker and one escalation flow.