# Conflicts: # docs/config-catalog.md # docs/cordis-catalog/events.md # docs/cordis-catalog/services.md # docs/event-producer-consumer.md # docs/persistence-catalog.md # examples/acp-agent/cordis.yml # examples/acp-agent/tests/snapshots/advanced-toolchain/session.1.jsonl # examples/acp-agent/tests/snapshots/advanced-toolchain/session.2.jsonl # examples/acp-agent/tests/snapshots/advanced-toolchain/session.jsonl # examples/acp-agent/tests/snapshots/both-mode-turn/session.jsonl # examples/acp-agent/tests/snapshots/permission-switching/session.jsonl # examples/acp-agent/tests/snapshots/skill-load/session.jsonl # examples/acp-agent/tests/snapshots/text-turn/session.jsonl # packages/bash/bash-sandbox/src/index.ts # packages/bash/bash/src/types.ts # packages/bash/tool-bash/src/index.ts # packages/fs/fs/src/index.ts # packages/sandbox/sandbox-policy/src/session-mode.ts # packages/ui/permission/src/index.ts # packages/ui/permission/tests/permission.spec.ts # scripts/doc-budgets.manifest.json
sandbox/ — process-sandbox capability family
The confinement half of the capability-seam split: an abstract provider interface, platform backends, and the shared policy home. Consumers hand ctx.sandbox the exact argv they are about to spawn and spawn the returned (wrapped) argv instead; policy (SandboxPolicy: mode + workspace root) rides each call, so different consumers confine under different policies at the same instant. All product packages.
| Package | Role | ctx key |
|---|---|---|
sandbox/ |
Abstract process-sandbox seam (the SandboxProvider contract + the mode/enforcement/policy vocabulary) plus the shared ESCALATION kit (approveEscalation, the strictly-wider ladder, the denial/hint markers) and the writableRoots derivation every enforcement dialect shares |
ctx.sandbox |
sandbox-local/ |
Local backends by platform chain: Linux bwrap else the landlock-run launcher (the npm-distributed node-addon-landlock-run family, built and released from its own repository), darwin sandbox-exec/Seatbelt — multi-candidate chains functionally probed, sole candidates selected directly, verdict cached, fail-closed |
(registers ctx.sandbox) |
sandbox-policy/ |
The policy home: the deployment default (mode + workspace-write boundary root) and the per-session sandbox/mode override (event + fold + write path). Both enforcing families read it, so bash and fs can never confine to different roots |
ctx.sandboxPolicy |
The seam confines SAME-WORLD subprocesses only (shared filesystem and kernel). Containers, microVMs, and remote executors are NOT backends here — they replace whole capability implementations (ctx.bash, ctx.fs) as environment-coherent groups; the boundary is recorded in the sandbox RFC.
Consumers today: bash/bash-sandbox (wraps ['bash', '-c', command] through ctx.sandbox) and fs/fs-sandbox (an in-process path fence, not an argv wrapper — reads ctx.sandboxPolicy and enforces the shared mode on write/edit). The cross-family boundary is the sandbox RFC's cross-family fs sandbox phase; the shared vocabulary lets both families teach the model one denial marker and one escalation flow.