YMRwithNoworry/dsh-niubash-only ↗★ 1

dsh-niubash-only

Niubash-only shell executor and Bash-dialect teaching for DeepSeek Harness (dsh 0.1.5-rc.2): every ctx.shell execution runs as `niu -c`, PowerShell/cmd/WSL/nu handoffs are refused, PowerShell habits are refused before they spawn, a failed call carries an actionable hint, and the model is taught what Niubash on Windows actually supports. 适合Windows上需要严格使用Niubash并纠正PowerShell习惯的用户。

패키지
dsh-niubash-only
호환성
미검증
Harness peer 범위
^0.1.5-rc.2
Cordis peer 범위
^4.0.2
버전
0.1.0
라이선스
MIT
최근 업데이트
2026. 9. 21.

설치

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:YMRwithNoworry/dsh-niubash-only

配置

补丁层默认配置(cordis.patch.yml):

- id: niubash-executor
  name: dsh-niubash-only/executor
  config:
    timeoutMs: 120000
    maxTimeoutMs: 600000
    maxOutputBytes: 64000
    graceMs: 3000
    enforceNiubashOnly: true   # 拒绝把命令交给别的 shell
    dialectLint: true          # spawn 前拒绝 PowerShell/CMD 习惯,并给出 Bash 写法
    dialectHints: true         # 失败时按真实错误文本追加一行 Niubash hint
    requireNiubash: true       # 找不到 niu 就启动失败(而不是每次调用都失败)
    verifyNiubash: true        # 启动时跑一次 `niu --version`
    probeNativeShells: true    # 探测本机 bash/sh 是否解析到 Niubash,决定是否放行
    smokeTest: true            # 启动时跑一条真实命令,起不来就当场把原因报出来
    sandbox: false             # 直接在本机运行:ctx.sandbox 不包裹、不拦截 niu

- id: niubash-teaching
  name: dsh-niubash-only/teaching
  config:
    guide: full                # full | compact | off
    rules: true
    rewriteToolDescriptions: true

执行器可选项:

字段默认含义
niuPath$DSH_NIU_PATH → PATH → 安装目录 → niu.exeNiubash 可执行文件
niuArgs['-c']argv 前缀,命令追加在最后
enforceNiubashOnlytrue守卫开关
foreignShellAllowlist[]整条命令匹配的正则(字符串),命中则放行(守卫与方言预检共用)
dialectLinttruespawn 前拒掉 PowerShell/CMD 习惯
dialectHintstrue失败时在 stderr 末尾追加一行 Niubash hint (…)
requireNiubashtrue无法解析 niu 时启动即失败
verifyNiubash / verifyTimeoutMstrue / 10000启动探测 niu --version 及其超时
smokeTesttrue启动时走一次真实调用路径(echo niubash-smoke-ok),把"命令根本起不来"这类启动期故障写在启动日志里
probeNativeShellstrue启动探测 command -v bash; command -v sh,据此决定 bash/sh 放行与否
sandboxfalse是否让 ctx.sandbox 包裹 shell 命令。默认关:niu 直接在本机以 harness 进程的身份运行,结果的 sandbox 事实报 mode: danger-full-access,会话要了受限模式时额外报 bypassed: 。设为 true 则走第一方原来的包裹与拒绝判定(此时 Niubash 1.1.4 在受限模式下起不来,见下节)

可执行文件解析顺序:niuPath → DSH_NIU_PATH → PATH 里第一个含 niu.exe 的目录 → 已知安装目录(%LOCALAPPDATA%\Programs\Niubash、%ProgramFiles%\Niubash、%ProgramFiles(x86)%\Niubash)→ 裸 niu.exe。 安装目录这一档是刻意的:Niubash 安装程序把目录加进用户 PATH 后广播环境变更,但已经在运行的 harness 进程仍持有启动时的环境——回退到文档化的安装目录,可以让部署不必重启宿主。

cwd、timeoutMs、maxTimeoutMs、maxOutputBytes、maxSpillBytes、graceMs 沿用 dsh 自己的 shell 设置命名空间,settings.yaml 的 shell: 段仍然可以热改预算。

在本 profile 的 cordis.patch.yml 里按 id 覆盖即可,例如:

- id: niubash-executor
  config:
    niuPath: 'C:\Users\me\AppData\Local\Programs\Niubash\niu.exe'
    enforceNiubashOnly: false