Files
qwen-code/packages/cli/src/utils/sandbox-macos-minimal.sb

16 lines
346 B
Plaintext

(version 1)
;; allow everything by default
(allow default)
;; deny all writes EXCEPT under project directory, temp directory, stdout/stderr and /dev/null
(deny file-write*)
(allow file-write*
(subpath (param "TARGET_DIR"))
(subpath (param "TMP_DIR"))
(literal "/dev/stdout")
(literal "/dev/stderr")
(literal "/dev/null")
)