mirror of
https://github.com/deepseek-ai/deepseek-harness
synced 2026-08-15 21:04:50 +00:00
Under read-only and workspace-write the Windows ACL sandbox leaves programs unable to open named pipes, so a piped-stdio spawn fails with EPERM. State that boundary in the pwsh tool description next to the ConstrainedLanguage contract, pin it in the tool tests, and bring the package README and both implemented Agent Notes current with it.
bash/ — bash capability family
English | 中文
The capability family spans the canonical executor seam, its implementations, the shared shell environment, and the model-facing tools. All are product packages.
| Package | Role | ctx key |
|---|---|---|
bash/ |
Defines the executor contract shared by implementations and consumers. | ctx.bash |
bash-local/ |
Executes commands through the local subprocess service. |
(registers ctx.bash) |
bash-sandbox/ |
Applies the configured sandbox backend before local execution. |
(registers ctx.bash) |
pwsh-local/ |
Executes PowerShell commands with Windows-specific process behavior. | (registers ctx.bash) |
bash-env/ |
Provides the managed DSH_* environment shared by shell tools. |
ctx.bashEnv |
tool-bash/ |
Exposes Bash execution and background-task integration to the model. | (registers on ctx.tools) |
tool-pwsh/ |
Exposes PowerShell execution to the model. | (registers on ctx.tools) |
A leaf cordis.yml selects one executor implementation and the model-facing tools it needs. A sandboxed composition also selects a ctx.sandbox provider; the ACP example shows one complete wiring.
The subsystem reference — request/spec vocabulary, results, background processes, the service, and events — is docs/subsystems/bash.md.