You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
一句话问题:OS sandbox / gondolin 该停在官方 example、OpenPI 权限门(#497),还是 #169 的 Security seam?
这不是 commit 计划。倾向 Discuss。本轮未安装、未运行社区 sandbox 包。不提议新安装器。Pi 继续拥有 install / update / uninstall。
本帖讨论的是 OS 隔离,不是 #497 的 allow/ask/deny policy。两件事不要合成一个实现。
为什么目录里这个机制看起来有趣
冻结身份(last-seen 2026-09-08):
sandbox/example@anthropic-ai/sandbox-runtimegondolin/examplepi-sandbox(carderne)@erichll/pi-sandbox官方 examples 已经提供 OS 隔离缝。社区包把 seatbelt / bwrap / 交互批准打成产品。OpenPI 若再自研一套 isolation language,会变成 #169 明确不想做的 in-house Security 产品。
和 OpenPI 已有能力的重叠
workspace-cleanup-guard:路径删除门,不是 OS sandbox。@amaster.ai/pi-computer-use(npm 0.1.14,2026-09-02)是高特权桌面自动化,应保持 out-of-tree,不和 sandbox 讨论绑在一起。六问(AGENTS.md)
@quintinshaw/pi-dynamic-workflows式 fail-open,OpenPI 不接受)。/openpi-setup,不新开命令。结论倾向
Discuss,不是 Adopt。 默认倾向:先用官方 example + #497 policy;只有官方缝明显不够时,才把 OS isolation 写进 #169 seam 的兼容合同。不 merge 社区
pi-sandbox。关联:#169、#497、#299、#314、#312。研究记录:
docs/research/PI_COMMUNITY_PLUGIN_SURVEY_2026-09-08.md。All reactions