fix(fs-local): bound overwrite contextual diff bases

Rebuild of the fs-overwrite-diff-bound branch on current master. Adds the
diffBasisMaxBytes Config field (10 MiB default, capped by runtime
allocation/decode limits), gates both overwrite sides, and reads the prior
basis from the bounded opened descriptor in cancellation-aware chunks; any
post-stat size change returns a null basis. Also pins the one-extra-byte
growth probe with a regression and drops the now-covered v8 ignore.
This commit is contained in:
ZiyaZhang
2026-08-07 11:05:27 -07:00
parent a29a0a4773
commit 16c1eaf546
19 changed files with 452 additions and 47 deletions

View File

@@ -41,10 +41,10 @@ import type {} from '@deepseek-ai/dsh-sandbox-policy'
import { isPathUnder } from './containment.ts'
/**
* Plugin config: the local backend's knobs, verbatim (only `cwd`, the resolve
* base for relative paths). The sandbox default (mode + `workspace-write`
* fallback root) is NOT here — `ctx.sandboxPolicy` resolves each calling
* session for every enforcing capability.
* Plugin config: the local backend's knobs verbatim (`cwd` resolution default
* and `diffBasisMaxBytes` overwrite-presentation bound). The sandbox default
* (mode + `workspace-write` fallback root) is NOT here — `ctx.sandboxPolicy`
* resolves each calling session for every enforcing capability.
*/
export type Config = LocalConfig