## Approval is not a sandbox

Boundary Desk ends by separating two claims that often get compressed into one\:&#32;“the application admitted the call” and “the environment allowed the effect\.”

Approval is an application\-level decision\.&#32;It neither changes the process’s OS authority nor certifies every action the implementation may perform\.&#32;A successful call can still have effects outside the boundary its name suggests\,&#32;and an approved call can still fail later\.

### Provider safety is an independent required decision

Inspect&#32;`boundary-provider-check-no-ui`\.&#32;It combines a read declaration\,&#32;yolo\,&#32;`autoApprove: true`\,&#32;user allow\,&#32;no UI\,&#32;and synthetic pending computer safety metadata\.

**Prediction\:**&#32;does any of that automatic approval acknowledge the pending safety check\?

**Recorded answer\:**&#32;no\.&#32;The wrapper emitted an approval lifecycle pair ending false\,&#32;executed nothing\,&#32;and reported that pending provider safety checks had no interactive UI\.&#32;`providerSafetyApproved`&#32;remained false\.

In&#32;`boundary-provider-check-approved`\,&#32;the recording adapter selected Approve\.&#32;The prompt included&#32;`Fictional seed shelf check`\;&#32;the context flag became true and the inert executor recorded one call\.

The source makes pending checks independently require approval\,&#32;regardless of yolo\,&#32;ordinary user allow\,&#32;or forwarded xdev admission\.&#32;It obtains computer actions and pending checks from provider metadata\,&#32;not by treating arbitrary prose as a safety grant\.

The proof here is deliberately narrow\:&#32;synthetic metadata passed through the actual wrapper\.&#32;No provider delivered a request\,&#32;no screenshot was taken\,&#32;and no desktop input occurred\.&#32;This local acknowledgement mechanism is also not the entirety of a provider’s safety policy or refusal behavior\.

### An OS error arrives at another seam

Now inspect&#32;`boundary-fallback-no-handler`\.&#32;The actual&#32;`writeFileWithFallback()`&#32;helper received an injected BunFile\-shaped primitive whose&#32;`write()`&#32;throws a synthetic&#32;`EACCES`&#32;error\.&#32;No fallback handler was registered\.

**Recorded answer\:**&#32;one primitive attempt\,&#32;zero successful effects\,&#32;and the identical error object rethrown\.&#32;There was no privileged channel and no recovered write\.

Compare the two error\-classification cases\:

| Case | Error data | Recorded classification |
| --- | ---: | --- |
| `boundary-fallback-code-precedence` | Structured code&#32;`ENOENT`\;&#32;message mentions a path containing&#32;`EACCES` | Not permission\-denied\. |
| `boundary-fallback-message` | No structured code\;&#32;Error message contains&#32;`EACCES` | Permission\-denied\. |

`isPermissionDeniedError()`&#32;treats a structured code as authoritative\.&#32;Only when that structured information is absent does its message fallback apply\.&#32;A word in a pathname is not an OS denial\,&#32;and a classified denial is not an acquired grant\.

### What a file fallback contract actually provides

The source supports a later host seam for selected native ordinary\-file byte writes and unlinks after permission errors\.&#32;Direct&#32;`EPERM`\,&#32;`EACCES`\,&#32;and&#32;`EROFS`&#32;can qualify\.&#32;A registered write fallback also enables a special check for a denied parent\-directory creation that Bun initially presents as&#32;`ENOENT`\;&#32;an ordinary missing or invalid path is not automatically a permission boundary\.

The destination is resolved according to the primitive’s semantics\.&#32;Writes follow the final symlink target\;&#32;unlinks leave the final link itself as the object to remove\.&#32;An unverifiable write destination is not handed to a handler\.&#32;Delete handlers use a separate registry\,&#32;and&#32;`confirmedFile: false`&#32;does not authorize recursive removal\.

Those registries are process\-wide\.&#32;A request’s origin session can differ from the session that registered a handler and owns its UI\.&#32;Returning true tells native code to proceed as though the supported primitive succeeded\;&#32;it is not itself proof that bytes became durable\.

These are host contracts to understand\,&#32;**not a broker exercise for this route**\.&#32;The existing&#32;[Permission\-denied file fallbacks](<https://present-sketch-tp94.here.now/chapters/extensions-permission-denied-file-fallbacks>)&#32;chapter retains the complete adapter and its missing real\-broker prerequisites\.&#32;No elevated writer is supplied here\.

### Several effects remain outside this particular seam

A native byte\-write fallback is not exhaustive syscall interception\.&#32;It does not universally cover arbitrary extension filesystem calls\,&#32;shell or subprocess writes\,&#32;archive\-member rewrites\,&#32;SQLite row operations\,&#32;ACP client\-side writes\,&#32;independent LSP workspace edits\,&#32;or formatter subprocess mutations\.

Similarly\,&#32;the approval wrapper is not a restriction on arbitrary imported JavaScript\.&#32;The supplied&#32;`isProjectTrusted()`&#32;compatibility method returns true\;&#32;it does not establish a per\-directory consent prompt or OS sandbox\.&#32;Tool selection\,&#32;approval\,&#32;and trust in loaded code must remain separate subjects\.

Canonical path handling reduces particular misrouting risks\.&#32;Do not promote it into a general claim that every race\,&#32;host process\,&#32;network route\,&#32;or external side effect is constrained by the same policy\.

The private verifier’s launcher used a clean environment and an OS sandbox with named restrictions\.&#32;Those restrictions describe that evidence\-producing child\,&#32;not an OMP feature installed for the reader and not a full sandbox validation suite\.&#32;Its effect counters cover instrumented seams\,&#32;not every possible effect of arbitrary imports\.

**Paper checkpoint\:**&#32;can Approve repair&#32;`EACCES`\,&#32;and does a fallback returning true independently prove durable bytes\?&#32;**Worked answer\:**&#32;neither\.&#32;Approval admits an application call\.&#32;The OS\/host still governs the primitive\;&#32;a handler’s success is a contract that a real implementation must satisfy and verify\.

**Failure boundary\:**&#32;the private fallback case was injected\,&#32;while the existing focused tests include local kernel\-permission fixtures and stand\-ins\.&#32;Neither establishes a real privileged broker or blanket OS isolation\.

**Source anchors\:**&#32;`packages/coding-agent/src/extensibility/extensions/wrapper.ts`&#32;—&#32;`computerSafetyChecks`\,&#32;`approvalArgs`\,&#32;`ExtensionToolWrapper.execute`\;&#32;`packages/coding-agent/src/tools/file-write-fallback.ts`&#32;—&#32;`isPermissionDeniedError`\,&#32;`writeFileWithFallback`\,&#32;`deleteFileWithFallback`\,&#32;`withFileMutationSession`\;&#32;`packages/coding-agent/src/tools/path-utils.ts`&#32;—&#32;`resolveSyscallTarget`\;&#32;`packages/coding-agent/src/extensibility/extensions/runner.ts`&#32;—&#32;`createContext`\,&#32;fallback initialization\/disposal\.
