Files
deepseek-harness/packages/bash
Huanqi Cao 6478da61e3 fix(sandbox): harden the per-session record and the ACL runner failure paths (review round v6)
Durable record: bound to the owning session id and validated at the fold (orphan-SID shape, temp path inside the host temp root) — a fork's copied parent record no longer provisions the child, and a tampered record fails loud. Private temp dir: random unguessable name persisted in the record, created exclusively (pre-existing entries and reparse points fail EEXIST). Persistence: a fresh provision kicks an immediate flush (no write-behind debounce), narrowing the crash window to the flush latency — documented as the one self-healing gap. Runner-failure rules: exit-gated on 127 so a confined command that prints the signature on a non-127 exit is never misclassified. Spawn: AssignProcessToJobObject failure terminates the suspended child (no hanging orphans). SandboxExecutionPolicy.sessionId is the branded SessionId. Boundary docs: qualifying clause on the absolutist sentences, NULL-DACL Known Limitation, 'full' scoped to the supported NTFS surface, CLM gate comment.
2026-08-08 23:23:38 +08:00
..

bash/ — bash capability family

English | 中文

The capability family spans the canonical executor seam, its implementations, the shared shell environment, and the model-facing tools. All are product packages.

Package Role ctx key
bash/ Defines the executor contract shared by implementations and consumers. ctx.bash
bash-local/ Executes commands through the local subprocess service. (registers ctx.bash)
bash-sandbox/ Applies the configured sandbox backend before local execution. (registers ctx.bash)
pwsh-local/ Executes PowerShell commands with Windows-specific process behavior. (registers ctx.bash)
bash-env/ Provides the managed DSH_* environment shared by shell tools. ctx.bashEnv
tool-bash/ Exposes Bash execution and background-task integration to the model. (registers on ctx.tools)
tool-pwsh/ Exposes PowerShell execution to the model. (registers on ctx.tools)

A leaf cordis.yml selects one executor implementation and the model-facing tools it needs. A sandboxed composition also selects a ctx.sandbox provider; the ACP example shows one complete wiring.