Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed. - @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions). - @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules). - @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec. - bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled. Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
bash/ — bash capability family
English | 中文
The capability family spans the canonical executor seam, its implementations, the shared shell environment, and the model-facing tools. All are product packages.
| Package | Role | ctx key |
|---|---|---|
bash/ |
Defines the executor contract shared by implementations and consumers. | ctx.bash |
bash-local/ |
Executes commands through the local subprocess service. |
(registers ctx.bash) |
bash-sandbox/ |
Applies the configured sandbox backend before local execution. |
(registers ctx.bash) |
pwsh-local/ |
Executes PowerShell commands with Windows-specific process behavior. | (registers ctx.bash) |
bash-env/ |
Provides the managed DSH_* environment shared by shell tools. |
ctx.bashEnv |
tool-bash/ |
Exposes Bash execution and background-task integration to the model. | (registers on ctx.tools) |
tool-pwsh/ |
Exposes PowerShell execution to the model. | (registers on ctx.tools) |
A leaf cordis.yml selects one executor implementation and the model-facing tools it needs. A sandboxed composition also selects a ctx.sandbox provider; the ACP example shows one complete wiring.