A continuable background child (the default backgroundMode for both delegation tools) never received the parent session's explicit sandbox/approval overrides: materialization applied only child composition, so a danger-full-access parent produced workspace-write children whose every out-of-workspace operation raised an approval prompt. Move the one-shot driver's capture/append pair into the shared child-agent module (captureDelegatedPolicyOverrides / appendDelegatedPolicyOverrides) and call it from both paths: startContinuable captures before its first await, only fresh materialization appends the source-tagged events (after any fork seed), and a cold resume replays the persisted delegation events instead of re-capturing the parent. Adds the continuable inheritance unit suite, the ACP snapshot scenario subagent-continuable-inheritance (fails without the fix), the continuable policy-inheritance Agent Note, and the seam-level README contract, with bilingual counterparts. Fixes #1692
20 lines
775 B
TypeScript
20 lines
775 B
TypeScript
import type { Context } from 'cordis'
|
|
import { setSandboxMode } from '@deepseek-ai/dsh-sandbox-policy'
|
|
import type {} from '@deepseek-ai/dsh-agent'
|
|
|
|
export const name = 'parent-sandbox-override'
|
|
|
|
/**
|
|
* Snapshot-only overlay: switch each ROOT session to `read-only` at creation —
|
|
* the UI "Access" switch equivalent (one runtime `sandbox/mode` event on the
|
|
* session log) — so the scenario proves a continuable background child
|
|
* inherits the parent's explicit override as a `source: 'delegation'` event
|
|
* instead of falling back to the deployment default.
|
|
*/
|
|
export function apply(ctx: Context): void {
|
|
ctx.on('agent/created', ({ agent }) => {
|
|
if (agent.session.header.parentSession !== undefined) return
|
|
setSandboxMode(agent.session, 'read-only')
|
|
})
|
|
}
|