resolve_workspace(
self,
cwd: str,
project_root: str | None
) -> ServerConfigResolve directory-bound policy for one server workspace.
Project-scoped policy (PROJECT_WORKSPACE_FIELDS) is valid only for
the directory it was resolved against: it came from the launch-time CLI
and that project's trust decisions. Reusing it for another directory
would apply one project's MCP servers, sandbox setup, and extensions to
a different, possibly untrusted, checkout.
So the launch project keeps its policy verbatim, and any other project
starts from nothing: MCP and sandbox setup are dropped rather than
rediscovered, and extension trust is re-read from the trust store for
that project. _same_workspace_project fails closed, so an
unresolvable path also takes the drop branch.