Files
deepseek-harness/packages/sandbox
Tianyi Cui a7a5be1703 docs(notes): archive low-future-value Agent Notes
Run the dsh-archive-agent-notes audit over every active Agent Note on
current master, judging each record by whether its rationale still guides
work rather than by size or age.

- Archive 453 implemented bilingual triplets (417,882 English words):
  completed UI chrome, narrow adapters, closed bug fixes, implementation
  walkthroughs whose package READMEs, docs pages, generators, or successor
  notes now carry the useful behavior, and 51 records fully superseded by
  a later active note. Keep 201 implemented notes whose ownership rules,
  negative guarantees, durable or wire semantics, security rules,
  reintroduction conditions, or still-tempting rejected alternatives
  remain useful.
- Reject 7 proposals whose premise is gone or whose work shipped in
  amended form under other records; delete 2 rejected notes that no
  longer prevent a plausible mistake.
- Retarget every remaining inbound link to the archived path, and repair
  active prose that named an archived record as the owner of a live fact:
  parenthetical citations drop, ownership sentences redirect to the
  README, docs page, or active note that states the fact, and history
  citations say so. Chinese files link the English archived path because
  the pairing gate treats the frozen tree as outside the bilingual corpus.
- Seal 1,359 new frozen artifacts; existing seals are unchanged and
  outbound links from archived notes are neither inspected nor repaired.
- Regenerate docs/config-catalog.md after the hook-bridge comment edits
  shifted two source line numbers.
2026-09-05 14:37:32 +08:00
..
2026-09-04 15:38:55 +08:00
2026-09-04 15:38:55 +08:00

description, kind
description kind
The process-sandbox package group: the confinement seam, per-platform backends, the shared policy resolver, and the Windows write-restriction rung. package-group

packages/sandbox

English | 中文

Summary

The sandbox/ group confines subprocess execution to a file-effect policy: commands run read-only, write only under the session workspace (workspace-write), or run unrestricted (danger-full-access). Four packages deliver it: the confinement service (sandbox/), the per-platform backends for Linux, macOS, and Windows (sandbox-local/), the shared policy resolver (sandbox-policy/), and the Windows write-restriction backend (sandbox-windows-acl/). A confined call that a policy denies can retry through a user-approved one-time escalation. Confinement is same-world only: it shares the host kernel and filesystem, while containers, microVMs, and remote executors replace whole capabilities instead of registering here.

Table of Contents


Packages

Four packages play the confinement roles; the subsystem reference owns the exhaustive contracts and the per-call policy semantics.

Package Role ctx key
sandbox/ Confinement service contract: modes, enforcement, per-call policy, and the escalation vocabulary ctx.sandbox
sandbox-local/ Per-platform confinement backends: Linux bwrap then Landlock, macOS Seatbelt, Windows restricted token registers on ctx.sandbox
sandbox-policy/ Shared policy home: deployment defaults and per-session mode overrides for every enforcing family ctx.sandboxPolicy
sandbox-windows-acl/ Windows write restriction: confined children may write only in the workspace and a private temp directory — (mounted by sandbox-local as the win32 backend)

Start with the subsystem reference for the shared vocabulary, then the confinement decision and its cross-family extension.

Dev Note

Working context for maintainers — click to expand

None.