Files
deepseek-harness/packages/bash
Huanqi Cao 83f835e4cb feat(pwsh): mirror the bash sandbox surface — denial rendering, escalation, and the ConstrainedLanguage contract
tool-pwsh now renders sandbox denial facts (denial marker + same-turn escalation hint, runner-failed notice on background reads) and advertises the sandbox_permissions/justification escalation pair resolved through ctx.approval before execution — the shared fail-closed sequence from dsh-sandbox, with the tool name 'pwsh'. The description teaches the ConstrainedLanguage contract under the Windows sandbox (both confined modes run pwsh in CLM: Add-Type, non-core .NET statics, COM, and reflection fail; the mode cannot be lifted — probe-verified, pinned by LANGMODE assertions in the runner suite and description assertions in the tool suite). The stale pwsh-sandbox JSDoc ('the tool owns approval') and the parity notes' superseded 'minus sandbox' claims are corrected.
2026-08-08 20:11:21 +08:00
..

bash/ — bash capability family

English | 中文

The capability family spans the canonical executor seam, its implementations, the shared shell environment, and the model-facing tools. All are product packages.

Package Role ctx key
bash/ Defines the executor contract shared by implementations and consumers. ctx.bash
bash-local/ Executes commands through the local subprocess service. (registers ctx.bash)
bash-sandbox/ Applies the configured sandbox backend before local execution. (registers ctx.bash)
pwsh-local/ Executes PowerShell commands with Windows-specific process behavior. (registers ctx.bash)
bash-env/ Provides the managed DSH_* environment shared by shell tools. ctx.bashEnv
tool-bash/ Exposes Bash execution and background-task integration to the model. (registers on ctx.tools)
tool-pwsh/ Exposes PowerShell execution to the model. (registers on ctx.tools)

A leaf cordis.yml selects one executor implementation and the model-facing tools it needs. A sandboxed composition also selects a ctx.sandbox provider; the ACP example shows one complete wiring.