Files
deepseek-harness/website/zh-CN/api/harness/sandbox.md
lintianle 2cde2a9032 Merge origin/master into feat/website-docs
Conflict resolution notes:
- package.json/run-gates: both sides' new doc-sync gates kept (master's
  scoped-events/readme gates + this branch's website-api/website-yaml);
  js-yaml devDeps deduped (master added them independently).
- pnpm-workspace/knip: website AND python/sdk-runtime entries kept.
- doc-typecheck/verify-type-equiv: master's condensed headers kept, website
  glob retained in both scan scopes.
- vendor/cordis/src/fiber.ts: master's lifecycle-hardening code taken; this
  branch's richer FiberState JSDoc reapplied on top. vendor/README.md logs
  both local modifications (hardening = 6, JSDoc enrichment = 7).
- pnpm-lock: regenerated from master's side (pnpm install).

Post-merge sync the gates forced (the system working as designed):
- verify-website-yaml caught 4 stale plugin names from master's package
  reorg (dsh-stdio-agent -> dsh-stdio-demo, dsh-acp-agent -> dsh-acp-demo);
  8 references fixed across guide/ and develop/.
- gen-website-api picked up master's 6 new services automatically
  (ctx.approval/permission/sandbox/sessionQuery/skills/tasks -> 6 new pages
  + sidebar); api/index.md hub updated to list them.
- AGENTS.md budget ceiling 1370 -> 1400: the website rows (layout line + two
  command lines) and master's own growth collided with the old ceiling; all
  three website rows are load-bearing (new top-level dir, new CI command).
2026-07-16 21:36:43 +08:00

1.4 KiB

ctx.sandbox

SandboxProvider (abstract seam) — provided by @deepseek-ai/dsh-sandbox.

Abstract process-sandbox service. confine must return enforcing argv or fail closed at wrap or runner-execution time; silent unconfined passthrough is forbidden. Functional probes arbitrate multi-runner chains and may be skipped for a sole candidate, whose own refusal remains the fail-closed end.

Source

ctx.sandbox.confine(argv, policy)

abstract confine(argv: readonly string[], policy: SandboxPolicy): ConfinedArgv

Wrap argv so it executes confined under policy on this host; the caller spawns the returned argv in place of its own.

  • argv — the exact argv the caller is about to spawn (program plus arguments), NOT a shell string — a shell-shaped consumer passes ['bash', '-c', command].
  • policy — the file-effect policy this execution runs under, carried per call (see SandboxPolicy).

Returns the argv to spawn instead, plus the enforcement completeness the selected backend achieves for it.

Source