test(snapshot): cover session-scoped sandbox roots

This commit is contained in:
Tianyi Cui
2026-07-21 01:16:29 +08:00
parent dc874a90bd
commit 7677d49c93
16 changed files with 186 additions and 19 deletions
@@ -0,0 +1,14 @@
# Session-root sandbox snapshot overlay. The generated ACP session cwd lives
# under the user's home, while this deployment fallback deliberately points at
# /tmp. A workspace-write mutation can therefore succeed only when the calling
# session's cwd replaces the process-level fallback root.
- id: base
name: '@cordisjs/plugin-include'
config:
path: ./cordis.yml
patches:
- id: sandbox-policy
name: '@deepseek-ai/dsh-sandbox-policy'
config:
mode: !!js "process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')"
workspaceRoot: /tmp