feat(sandbox): derive the windows-acl write SID per workspace, not per session
The per-session random write SID forced a full tree propagation per session per server lifetime (minutes on large workspaces). The write SID is now the per-workspace identity derived from the canonical workspace path (workspaceWriteSid: sha256 -> S-1-4-x-y), stored nowhere: the workspace-root ACE materializes once per workspace per machine and every later provision hits the exact-ACE skip. - workspace ACEs are STANDING (never revoked - the reuse cache); temp ACEs stay revocable (disposed with the provider), so an inheritable ACE never outlives its session's temp dir on the ambient temp root - AclSandbox requires the write SID under workspace-write; read-only parses/grants nothing; the runner derives the SID itself (the --write-sid flag's presence still marks the seam-managed contract) - the acl-session record drops writeSid (sessionId/workspace/tempDir remain): the SID-tamper surface and its validation are gone - sandbox-local holds two grant maps: standing workspace grants and revocable per-session temp grants Docs (README pair, design note pair, catalogs, type-equiv) and the acl-session/grant/acl/probe/runner suites updated; workspace-sid.spec pins the derivation contract.
This commit is contained in:
@@ -498,16 +498,16 @@ Source: [`packages/core/session/src/types.ts:276`](../packages/core/session/src/
|
||||
|
||||
```ts persistence-catalog
|
||||
/**
|
||||
* The session's windows-acl write identity was provisioned — log-only
|
||||
* The session's windows-acl write record was provisioned — log-only
|
||||
* (like `sandbox/mode`; NOT a surface event, carries no `surfaceOp`):
|
||||
* durable and replayable, never in the model transcript. The LAST such
|
||||
* event owned by the session is its record ({@link sessionAclRecord});
|
||||
* the provider appends exactly one on the session's first Windows
|
||||
* confined execution.
|
||||
* confined execution. The write SID itself is NOT stored — it is the
|
||||
* per-workspace identity derived from `workspace`
|
||||
* (`workspaceWriteSid`).
|
||||
*/
|
||||
'sandbox/acl-session': {
|
||||
/** The orphan write SID (`S-1-4-x-y`) whose ACEs form the session's write allowlist. */
|
||||
writeSid: string
|
||||
/** The owning session — the binding a fork's copied event cannot satisfy. */
|
||||
sessionId: SessionId
|
||||
/** The workspace root the grant applies to (the session's immutable cwd, as resolved). */
|
||||
@@ -517,7 +517,7 @@ Source: [`packages/core/session/src/types.ts:276`](../packages/core/session/src/
|
||||
}
|
||||
```
|
||||
|
||||
Source: [`packages/sandbox/sandbox-local/src/acl-session.ts:36`](../packages/sandbox/sandbox-local/src/acl-session.ts)
|
||||
Source: [`packages/sandbox/sandbox-local/src/acl-session.ts:43`](../packages/sandbox/sandbox-local/src/acl-session.ts)
|
||||
|
||||
#### `sandbox/mode` — log-only
|
||||
|
||||
|
||||
Reference in New Issue
Block a user