91c0e32035
The Docker backend currently turns any non-empty allowed_domains list into unrestricted bridge networking even though no per-domain enforcement exists. Keep Docker networking disabled and emit a warning until the backend can actually honor domain policies. Constraint: Preserve a small, reviewable fix instead of designing a full Docker egress filter Rejected: Keep bridge networking with docs-only clarification | leaves silently overbroad behavior in place Confidence: high Scope-risk: narrow Reversibility: clean Directive: If Docker domain policies are re-enabled later, add true enforcement before widening network access Tested: PYTHONPATH=src pytest -q tests/test_sandbox/test_docker_backend.py tests/test_sandbox/test_adapter.py Tested: PYTHONPATH=src ruff check src tests Not-tested: Full pytest suite in this environment (collection fails because optional pyperclip dependency is missing) Related: #150