pub const HARNESS_SCRATCH_DIR: &str = "cosh";Expand description
Centralized path guard that combines lexical validation with filesystem canonicalization.
Every tool that accepts filesystem paths should use this guard to ensure consistent security checks. Usage:
let guard = PathGuard::new(&self.root, self.allowlist.as_deref(), self.blocklist.as_deref());
let safe_path = guard.resolve(path)?;The error message is uniform across all tools, making it easy for the AI agent to understand why a path was denied. Name of the harness scratch directory (under the OS temp dir).
The harness writes truncated tool-output logs here (see harness::truncate)
and the model reads them back with fs_read/find_grep. Temp dirs are
ephemeral by nature, so this directory is exempt from the outside-root
denial — but never from the blocklist, which keeps priority.
The exemption is shared by every tool using this guard (reads AND writes): writes into the scratch dir are still gated by the harness approval dialog in Build/Ask modes — the guard alone no longer blocks them.