Workspace
dict[str, VFS]
required
The backend at each prefix, such as
{"/": RAMVFS(), "/s3": S3VFS(config)}.MountMode
default:"MountMode.READ"
The mode a mount gets when it sets none:
READ, WRITE or EXEC.str
The profile a session gets when it names none.
AskHandler
Answers an ask while the line waits. Without one, asks wait in
ws.decisions.cache, index, store, runtimes, clis, env, secrets, command_limits, …) are the top-level YAML keys.
ws.session
Session every call below runs as. It creates the session when the id is new and adopts it when it exists. profile and mounts apply only on create, and raise ValueError for an existing session. ws.create_session is the same call without the handle.
ws.list_sessions, ws.close_session
ws.cancel, ws.kill
cancel cancels the running and queued lines, whichever way they came in, and returns once they have ended; each ends with MirageAbortError. kill kills the background jobs (cmd &) and the processes runtimes started. Each answers how many it stopped.
ws.snapshot, Workspace.load
target and source are a path or a file object, or an object key with s3=. snapshot answers the tar’s size in bytes. While it captures, new lines and file writes wait, and running ones get 30 seconds to end, else it raises OSError (EBUSY); disk mount files are streamed, never held whole. See Snapshots for what a tar holds.
ws.copy
ws.decisions
pending() lists every session’s, pending("agent") one session’s, and an answer never reaches another session. outcome is Outcome.ALLOW or Outcome.DENY. Scope.ONCE answers the one line, so its retry runs or is refused; Scope.SESSION allows every line the rule covers for the rest of that session.
ws.close
Session
ws.session. Every call on it answers under the session’s profile, working directory and environment. ws.shell, ws.glob, ws.vfs and ws.tools are the same calls as the workspace’s default session.
str
SessionState
The session’s record, as
ws.list_sessions answers it.Ops
The file API, below.
MirageToolOperations
The agent tools, below.
session.shell
bytes | AsyncIterator[bytes]
The line’s stdin. An async iterator streams it.
str
A working directory for this line only. A
cd in the line does not leak.dict[str, str]
Variables for this line only.
asyncio.Event
Setting it stops the line and raises
MirageAbortError.bool
default:"True"
False keeps the line out of history.session.glob
session.explain
session.shell or a session.vfs call would do, without running it: a line’s verdict and parse tree, a VFS call’s verdict and error, each with every policy’s answer. See Explain.
session.vfs
The file API, run as the session. Paths are absolute, bytes arebytes. A missing path raises FileNotFoundError and a refused one PermissionError.
session.tools
is_error, never an exception. call takes a tool’s name and its JSON input, the form an agent loop gets from the model. The session has one table, shared by every caller, so write and edit refuse a file the agent has not read in full, or one that changed since it read it. names() is the tools the session’s profile leaves it, which MCP, RPC and the agent adapters offer: shell needs a command the allow list installs, ls and grep those commands, write and edit a mount the session may write.
mirage.workspace.tools.tool_descriptions has each tool’s description and JSON schema to hand the model, and the agent adapters wire the tools into each framework. MirageToolOperations(session, stale_write_protection=False), from mirage.workspace.tools.tool_operations, is a table without the read guard.