Removed the named sandbox concept. One config file: sandbox.yaml (installed to ~/.config/ollie/sandbox.yaml). Removed sandbox-remote.yaml, moved restricted.yaml to doc/ as a sample. Removed the 'sandbox' arg from tool dispatch.
Move server-only packages under their respective cmd directories: olliesrv: - agent/ -> cmd/olliesrv/internal/agent/ - backend/ -> cmd/olliesrv/internal/backend/ - bypass/ -> cmd/olliesrv/internal/bypass/ - fs/ -> cmd/olliesrv/internal/fs/ - prompts/ -> cmd/olliesrv/internal/prompts/ - session/ -> cmd/olliesrv/internal/session/ toolsrv: - Server-only code (exec9p, fs9p, server9p, spec9p, auth9p) -> cmd/toolsrv/ - sandbox/ -> cmd/toolsrv/internal/sandbox/ - Keep shared client code (client9p, spawn, registry, meta) in toolsrv/ - Add toolsrv/types.go for shared types (ToolResult, ToolResultContent) This enforces package boundaries - code in cmd/*/internal/ cannot be imported by external packages, while shared code remains importable.