Run the dsh-archive-agent-notes audit over every active Agent Note on current master, judging each record by whether its rationale still guides work rather than by size or age. - Archive 453 implemented bilingual triplets (417,882 English words): completed UI chrome, narrow adapters, closed bug fixes, implementation walkthroughs whose package READMEs, docs pages, generators, or successor notes now carry the useful behavior, and 51 records fully superseded by a later active note. Keep 201 implemented notes whose ownership rules, negative guarantees, durable or wire semantics, security rules, reintroduction conditions, or still-tempting rejected alternatives remain useful. - Reject 7 proposals whose premise is gone or whose work shipped in amended form under other records; delete 2 rejected notes that no longer prevent a plausible mistake. - Retarget every remaining inbound link to the archived path, and repair active prose that named an archived record as the owner of a live fact: parenthetical citations drop, ownership sentences redirect to the README, docs page, or active note that states the fact, and history citations say so. Chinese files link the English archived path because the pairing gate treats the frozen tree as outside the bilingual corpus. - Seal 1,359 new frozen artifacts; existing seals are unchanged and outbound links from archived notes are neither inspected nor repaired. - Regenerate docs/config-catalog.md after the hook-bridge comment edits shifted two source line numbers.
description, kind
| description | kind |
|---|---|
| The process-sandbox package group: the confinement seam, per-platform backends, the shared policy resolver, and the Windows write-restriction rung. | package-group |
packages/sandbox
English | 中文
Summary
The sandbox/ group confines subprocess execution to a file-effect policy: commands run read-only, write only under the session workspace (workspace-write), or run unrestricted (danger-full-access). Four packages deliver it: the confinement service (sandbox/), the per-platform backends for Linux, macOS, and Windows (sandbox-local/), the shared policy resolver (sandbox-policy/), and the Windows write-restriction backend (sandbox-windows-acl/). A confined call that a policy denies can retry through a user-approved one-time escalation. Confinement is same-world only: it shares the host kernel and filesystem, while containers, microVMs, and remote executors replace whole capabilities instead of registering here.
Table of Contents
Packages
Four packages play the confinement roles; the subsystem reference owns the exhaustive contracts and the per-call policy semantics.
| Package | Role | ctx key |
|---|---|---|
sandbox/ |
Confinement service contract: modes, enforcement, per-call policy, and the escalation vocabulary | ctx.sandbox |
sandbox-local/ |
Per-platform confinement backends: Linux bwrap then Landlock, macOS Seatbelt, Windows restricted token | registers on ctx.sandbox |
sandbox-policy/ |
Shared policy home: deployment defaults and per-session mode overrides for every enforcing family | ctx.sandboxPolicy |
sandbox-windows-acl/ |
Windows write restriction: confined children may write only in the workspace and a private temp directory | — (mounted by sandbox-local as the win32 backend) |
Related documentation
Start with the subsystem reference for the shared vocabulary, then the confinement decision and its cross-family extension.
- Process sandbox subsystem — modes, per-call policy, wrapped-argv dialects, and fail-closed errors.
- The subprocess sandbox decision — the capability boundary, escalation choreography, and deferred phases.
- Cross-family file sandbox decision — the shared policy home and the sandboxed filesystem provider.
- Windows ACL restricted-token sandbox decision — why raw ACL restricted tokens over mxc and AppContainer.
Dev Note
Working context for maintainers — click to expand
None.