mirror of
https://github.com/deepseek-ai/deepseek-harness
synced 2026-08-15 21:04:50 +00:00
tool-pwsh now renders sandbox denial facts (denial marker + same-turn escalation hint, runner-failed notice on background reads) and advertises the sandbox_permissions/justification escalation pair resolved through ctx.approval before execution — the shared fail-closed sequence from dsh-sandbox, with the tool name 'pwsh'. The description teaches the ConstrainedLanguage contract under the Windows sandbox (both confined modes run pwsh in CLM: Add-Type, non-core .NET statics, COM, and reflection fail; the mode cannot be lifted — probe-verified, pinned by LANGMODE assertions in the runner suite and description assertions in the tool suite). The stale pwsh-sandbox JSDoc ('the tool owns approval') and the parity notes' superseded 'minus sandbox' claims are corrected.
bash/ — bash capability family
English | 中文
The capability family spans the canonical executor seam, its implementations, the shared shell environment, and the model-facing tools. All are product packages.
| Package | Role | ctx key |
|---|---|---|
bash/ |
Defines the executor contract shared by implementations and consumers. | ctx.bash |
bash-local/ |
Executes commands through the local subprocess service. |
(registers ctx.bash) |
bash-sandbox/ |
Applies the configured sandbox backend before local execution. |
(registers ctx.bash) |
pwsh-local/ |
Executes PowerShell commands with Windows-specific process behavior. | (registers ctx.bash) |
bash-env/ |
Provides the managed DSH_* environment shared by shell tools. |
ctx.bashEnv |
tool-bash/ |
Exposes Bash execution and background-task integration to the model. | (registers on ctx.tools) |
tool-pwsh/ |
Exposes PowerShell execution to the model. | (registers on ctx.tools) |
A leaf cordis.yml selects one executor implementation and the model-facing tools it needs. A sandboxed composition also selects a ctx.sandbox provider; the ACP example shows one complete wiring.