feat(mode): the access cap — plan mode composes with the sandbox instead of banning bash
A ModeDefinition may declare access: the widest sandbox access shell commands run under while the mode holds, on the SANDBOX_MODES ladder. The bash seam gains the resolution point to hang it on: BashExecutor. resolveMode(session) folds override ?? default and dispatches the new bash/resolve-mode waterfall; dsh-tool-bash consults it at both the stamping site and the escalation baseline; dsh-mode's clamp listener takes the ladder minimum per call. Two independent log folds compose at read time — the mode never writes the sandbox knob, so the two switch in any order and the knob re-emerges intact on exit. The built-in plan definition ships access: read-only with the bash trio allowlisted CONDITIONALLY: both policy layers admit bash/bash_output/ bash_kill only while a confining executor is mounted (an unconfinable shell cannot honor the cap), and a bash call carrying sandbox_permissions under a cap is denied at the gate — no widening mid-mode; the widened step belongs in the plan. examples/plan-acp-agent swaps bash-local for sandbox-local + bash-sandbox (workspace-write default, clamped read-only inside plan) plus the approval seam; the re-recorded plan-mode arc runs a real cat inside plan under the clamped sandbox, and modes-advertise now pins the sandbox-mode and approval config options. RFC amended to the landed shape (access cap section, orthogonality FAQ, deferred item resolved into effects self-declaration).
This commit is contained in:
@@ -7,13 +7,18 @@ import { defineAcpSnapshotSuite, type Scenario, type SnapshotSuiteOptions } from
|
||||
* the sibling `cordis.snapshot.yml` replay overlay by the bin under
|
||||
* `DSH_SNAPSHOT=replay`).
|
||||
*
|
||||
* The recorded scenarios re-execute the fs tools for real on replay (the
|
||||
* replay overlay swaps only the model); their prompts pin the model to
|
||||
* The recorded scenarios re-execute the fs tools AND the sandboxed bash
|
||||
* executor for real on replay (the replay overlay swaps only the model), so
|
||||
* the plan-mode arc doubles as a live check of plan's read-only `access`
|
||||
* cap: the recorded `cat` runs under the host's actual runner (Seatbelt on
|
||||
* macOS, bwrap on Linux CI). The recorded commands stay `cat`-shaped —
|
||||
* byte-identical across those backends and across GNU/BSD userlands — and
|
||||
* the transcripts carry NO sandbox denial (a denied command's stderr is the
|
||||
* backend's dialect; the denial→marker path is pinned at dsh-tool-bash's
|
||||
* unit tier, and the cap's clamp at dsh-mode's). Prompts pin the model to
|
||||
* RELATIVE paths, because a recorded absolute temp path would neither replay
|
||||
* on another host nor normalize (the normalizers scrub the RUN's own cwd,
|
||||
* not the recording's). The gate's deny path is pinned at the unit tier
|
||||
* (packages/mode/mode/tests) — the recorded model never calls a filtered
|
||||
* tool, which is the behavior the soft layer exists to produce.
|
||||
* not the recording's).
|
||||
*/
|
||||
|
||||
function snapshotModeFromEnv(value: string | undefined): SnapshotSuiteOptions['mode'] {
|
||||
|
||||
Reference in New Issue
Block a user