{"_id":"@cmx666/dsh-winuxsh-sandbox","_rev":"2-c7c6d5960b2ce6963725d7ece2b88ca6","name":"@cmx666/dsh-winuxsh-sandbox","dist-tags":{"latest":"0.1.0-rc.6"},"versions":{"0.1.0-rc.6":{"name":"@cmx666/dsh-winuxsh-sandbox","version":"0.1.0-rc.6","license":"MIT","_id":"@cmx666/dsh-winuxsh-sandbox@0.1.0-rc.6","maintainers":[{"name":"cmx666","email":"2507560089@qq.com"}],"homepage":"https://github.com/deepseek-ai/deepseek-harness#readme","bugs":{"url":"https://github.com/deepseek-ai/deepseek-harness/issues"},"dist":{"shasum":"357b16203868d6831ef6c604cf3b4d4db237113c","tarball":"https://registry.npmjs.org/@cmx666/dsh-winuxsh-sandbox/-/dsh-winuxsh-sandbox-0.1.0-rc.6.tgz","fileCount":6,"integrity":"sha512-2Tmgx5S2qfenobAfeDz1UoeJxtTqTDJSRXcqyPYsH3l2XqZ7DTfOXcCeUT4SbGFQimK8Y4v9GM8Al+Fl4cB9sg==","signatures":[{"sig":"MEUCIQCqfd9+t8hszdBKyKfsXrPc6aP9bIInvtnNiz7PGQrkdAIgTnvxpmYy1DrYGXczDyV+mkKFLCv3qKLlk0eAGMpRfw8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":8997},"main":"lib/index.js","type":"module","types":"lib/types/index.d.ts","exports":{".":{"types":"./lib/types/index.d.ts","default":"./lib/index.js"},"./src/*":"./src/*","./invariant":{"types":"./lib/types/invariant.d.ts","default":"./lib/invariant.js"},"./package.json":"./package.json"},"gitHead":"d96e380465383f15cc0c9370eaecd53acd8d1c03","_npmUser":{"name":"cmx666","email":"2507560089@qq.com"},"repository":{"url":"git+https://github.com/deepseek-ai/deepseek-harness.git","type":"git","directory":"packages/shell/winuxsh-sandbox"},"_npmVersion":"10.9.2","description":"Sandbox-consuming implementation of the DeepSeek Harness winuxsh executor seam (confines every command via ctx.sandbox, reports denial/enforcement result facts)","directories":{},"_nodeVersion":"22.17.1","dependencies":{"@cmx666/dsh-winuxsh-local":"^0.1.0-rc.6","@deepseek-ai/dsh-pwsh-sandbox":"^0.1.0-rc.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-shell":"^0.1.0-rc.6","@deepseek-ai/dsh-sandbox":"^0.1.0-rc.6","@deepseek-ai/dsh-invariants":"^0.1.0-rc.6","@deepseek-ai/dsh-sandbox-policy":"^0.1.0-rc.6","@deepseek-ai/dsh-subprocess-local":"^0.1.0-rc.6"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-shell":"^0.1.0-rc.6","@deepseek-ai/dsh-sandbox":"^0.1.0-rc.6","@deepseek-ai/dsh-invariants":"^0.1.0-rc.6","@deepseek-ai/dsh-sandbox-policy":"^0.1.0-rc.6"},"_npmOperationalInternal":{"tmp":"tmp/dsh-winuxsh-sandbox_0.1.0-rc.6_1786689075317_0.3122979739983993","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @cmx666/dsh-niu-* (Niubash). Use @cmx666/dsh-niu-bundle."}},"time":{"created":"2026-08-14T06:31:15.095Z","modified":"2026-09-22T08:04:23.109Z","0.1.0-rc.6":"2026-08-14T06:31:15.465Z"},"bugs":{"url":"https://github.com/deepseek-ai/deepseek-harness/issues"},"license":"MIT","homepage":"https://github.com/deepseek-ai/deepseek-harness#readme","repository":{"url":"git+https://github.com/deepseek-ai/deepseek-harness.git","type":"git","directory":"packages/shell/winuxsh-sandbox"},"description":"Sandbox-consuming implementation of the DeepSeek Harness winuxsh executor seam (confines every command via ctx.sandbox, reports denial/enforcement result facts)","maintainers":[{"name":"cmx666","email":"2507560089@qq.com"}],"readme":"# @cmx666/dsh-winuxsh-sandbox\n\n[English](README.md) | 中文\n\n沙盒消费型的 [`ctx.shell` 执行器 seam](../shell/) 的 Winuxsh 实现：每条命令以 `<winuxsh> -c <command>` 运行，**经 `ctx.sandbox` 隔离**，选定模式、强制完整性、拒绝事实都盖在每次结算的结果上。它是 [`@deepseek-ai/dsh-pwsh-sandbox`](../pwsh-sandbox/) 的 winuxsh 孪生，逐调用镜像——隔离实体本身是平台无关的：Windows 上沙盒 seam 解析到 ACL 受限令牌 runner 链（[`@deepseek-ai/dsh-sandbox-windows-acl`](../../sandbox/sandbox-windows-acl/)），Linux/macOS 上解析到 bwrap/Landlock/Seatbelt。\n\n执行器继承 [`@cmx666/dsh-winuxsh-local`](../winuxsh-local/) 的进程机制，并消费其 argv 级 seam（`argv()` / `runArgv()` / `startArgv()` / `onProcessDone()`）把精确的 winuxsh 调用经 provider 包装。沙盒策略（模式 + 工作区根目录）不是本包的配置：每次调用由 `ctx.sandboxPolicy` 随行（工具层传调用会话解析后的策略；直接调用回退到部署策略）。\n\n## 行为\n\n- `danger-full-access`：命令经本地执行器原样运行；结果携带 `sandbox: { mode, denied: false }`。\n- 受限模式（`read-only`、`workspace-write`）：winuxsh argv 由 `ctx.sandbox.confine()` 包装；runner 启动失败按 fail-closed 抛 `SANDBOX_UNAVAILABLE`（前台抛错、后台记 `runnerFailed` 事实），被拒绝的写按所选后端的 `denialSignatures` 分类为 `sandbox.denied`。\n\n## 模型体验\n\n### 隔离生效，拒绝以命令失败呈现\n\n#### 模型看到什么\n\n受限命令自身的 stderr（Windows ACL runner 下如 `Access to the path '...' is denied.`）；工具层把分类后的拒绝转成标准权限拒绝面，与 bash 工具完全一致。\n\n#### Token 影响\n\n除命令 stderr 与工具层标准拒绝面外，无额外模型可见文本。\n\n#### KV Cache 影响\n\n无直接影响；拒绝呈现面属于工具层。\n\n## 已知限制与后续工作\n\n- **Windows 上读不受限**（ACL runner 只限写）；读边界文档在 `@deepseek-ai/dsh-sandbox-windows-acl`。\n- **Windows workspace-write 的临时权限按每个活跃的会话/工作区对私有**；无 agent（智能体）的调用每次都获得一个新的私有目录。环境临时根目录绝不会被授权，runner 会在 spawn 前将 TMP/TEMP 重写为该私有目录。\n- **Windows read-only 不授予任何显式可写根目录，但仍为部分强制执行**，因为受限令牌必须保留 Everyone。DACL 向 Everyone 授予写访问的对象——包括以兼容方式打开的 NUL 设备——仍构成环境权限来源；winuxsh 的 `> /dev/null` 式重定向语义继承后端授予的权限。\n- **尚无真实 provider 的 e2e 套件**——ACL runner 集成覆盖在 pwsh 孪生的 `tests/acl.e2e.ts` 中（runner 属于 provider 侧且共享），winuxsh 通过同一 seam 复用同一 runner。\n","readmeFilename":"README.zh.md"}