caomengxuan666/dsh-niu--packages-shell-niu-sandbox ↗★ 4

@cmx666/dsh-niu-sandbox

Sandbox-consuming implementation of the DeepSeek Harness Niubash executor seam (confines every command via ctx.sandbox, reports denial/enforcement result facts) 适合需要对Agent执行的Niubash命令进行安全隔离与权限限制的系统。

Package
@cmx666/dsh-niu-sandbox
Compatibility
Unverified
Harness peer range
^0.1.0-rc.6
Cordis peer range
^4.0.1
Version
0.1.0-rc.7
Last updated
Sep 22, 2026

Install

This plugin has no verified bundle, or compatibility checks failed. Read the repository notes first. Read the full README ↗

@cmx666/dsh-niu-sandbox

English | 中文

Sandbox-consuming Niubash implementation of the ctx.shell executor seam: every command runs as -c confined through ctx.sandbox, with the selected mode, enforcement, and denial facts stamped on each settled result. The Niubash twin of @deepseek-ai/dsh-pwsh-sandbox, a call-for-call mirror — the confinement substance is platform-neutral: on Windows the sandbox seam resolves to the ACL restricted-token runner chain (@deepseek-ai/dsh-sandbox-windows-acl), on Linux/macOS to bwrap/Landlock/Seatbelt.

The executor inherits @cmx666/dsh-niu-local's process mechanics and consumes its argv-level seam (argv() / runArgv() / startArgv() / onProcessDone()) to wrap the exact niu invocation through the provider. The sandbox policy (mode + workspace root) is NOT this package's config: it rides each call from ctx.sandboxPolicy (tool calls pass the calling session's resolved policy; direct calls fall back to deployment policy).

Behavior

  • danger-full-access: commands run through the local executor unchanged; results carry sandbox: { mode, denied: false }.
  • Confined modes (read-only, workspace-write): the niu argv is wrapped by ctx.sandbox.confine(); runner-launch refusal fails closed with SANDBOX_UNAVAILABLE (foreground throw, background runnerFailed fact), and a denied write classifies against the selected backend's denialSignatures into sandbox.denied.

Model Experience

Confinement works, denial surfaces as command failure

What the model sees

The confined command's own stderr (e.g. Access to the path '...' is denied. under the Windows ACL runner); the tool layer converts classified denials into the standard permission-denied surface exactly as it does for the bash tool.

Token effect

No model-visible text beyond the command's stderr and the tool layer's standard denial surface.

KV Cache effect

None directly; the denial surface belongs to the tool layer.

Known Limitations and Deferred Work

  • Reads are unrestricted on Windows (the ACL runner restricts writes only); the read boundary is documented in @deepseek-ai/dsh-sandbox-windows-acl.
  • Windows workspace-write temp authority is private per live session/workspace pair; agentless calls receive a fresh private directory per invocation. The ambient temp root is never granted, and the runner rewrites TMP/TEMP to the private directory before spawning.
  • Windows read-only grants no explicit writable root but remains partial because the restricted token must retain Everyone. Objects whose DACL grants Everyone write access — including compatible opens of the NUL device — remain ambient authority; niu's > /dev/null-style redirection semantics inherit whatever the backend grants.
  • No real-provider e2e suite yet — the ACL-runner integration coverage lives in the pwsh twin's tests/acl.e2e.ts (the runner is provider-side and shared), so niu exercises the same runner through the shared seam.