packages/sandbox

September 6, 2026 · View on GitHub

English | 中文

Summary

The sandbox/ group confines subprocess execution to a file-effect policy: commands run read-only, write only under the session workspace (workspace-write), or run unrestricted (danger-full-access). Four packages deliver it: the confinement service (sandbox/), the per-platform backends for Linux, macOS, and Windows (sandbox-local/), the shared policy resolver (sandbox-policy/), and the Windows write-restriction backend (sandbox-windows-acl/). A confined call that a policy denies can retry through a user-approved one-time escalation. Confinement is same-world only: it shares the host kernel and filesystem, while containers, microVMs, and remote executors replace whole capabilities instead of registering here.

Table of Contents


Packages

Four packages play the confinement roles; the subsystem reference owns the exhaustive contracts and the per-call policy semantics.

PackageRolectx key
sandbox/Confinement service contract: modes, enforcement, per-call policy, and the escalation vocabularyctx.sandbox
sandbox-local/Per-platform confinement backends: Linux bwrap then Landlock, macOS Seatbelt, Windows restricted tokenregisters on ctx.sandbox
sandbox-policy/Shared policy home: deployment defaults and per-session mode overrides for every enforcing familyctx.sandboxPolicy
sandbox-windows-acl/Windows write restriction: confined children may write only in the workspace and a private temp directory— (mounted by sandbox-local as the win32 backend)

Start with the subsystem reference for the shared vocabulary, then the confinement decision and its cross-family extension.

Dev Note

Working context for maintainers — click to expand

None.