omdsh-dev/sandbox-mxc
微软跨平台沙盒支持
已收录
2
Security
Bundle 已验证
预览
功能介绍
微软跨平台沙盒支持。
适合
- 需要为 Bash 或 PTY 消费方提供微软跨平台 MXC 沙箱后端的 DSH 部署。
- 要求故障关闭执行器资格检查、完整文件影响策略和版本化结果信封结算的团队。
不适合
- 缺少可用 Bubblewrap 或用户命名空间的 Linux 宿主,以及无法满足 MXC 平台验收要求的环境。
- 无法从 GitHub Packages 获取 main 分支所需修补版 MXC SDK、且未改用 vendor SDK 分支的安装;旧版 DSH 宿主还需要 legacy 集成补丁。
README
@deepseek-ai/dsh-sandbox-mxc
| English | 中文 |
The MXC sandbox provider extracted from the DSH feat-mxc implementation as one standalone external bundle. The repository keeps two delivery faces in one Git repository:
-
maincontains the registry-backed provider from DSHfeat-mxc. -
feat-mxc-vendor-sdkcarries the same provider with the pinned SDK and native executors invendor-sdk/for offline packed-install rehearsal.
Repository shape
package.json # standalone provider package and dsh.bundle manifest
cordis.patch.yml # explicit sandbox-mxc profile row
src/ # provider, invariant, and Windows environment helpers
tests/ # unit, parity, and publish-path tests
lib/ # generated install artifacts
vendor-sdk/ # vendor branch only: SDK runtime and native executors
docs/ # detailed provider documentation
legacy/ # DSH host integration patch for older snapshots
The package exports @deepseek-ai/dsh-sandbox-mxc and its invariant companion. Its runtime peers are the DSH sandbox seam, subprocess environment helper, invariants package, and Cordis. The patched @dsh-external/mxc-sdk remains a runtime dependency: main resolves the dsh release tag from GitHub Packages, while the vendor branch replaces it with file:./vendor-sdk.
Bundle behavior
The bundle contributes an explicit, disabled opt-in row:
- id: sandbox-mxc
name: '@deepseek-ai/dsh-sandbox-mxc'
disabled: true
config:
enabled: true
useResultEnvelope: true
Enable the row in a profile only after the target DSH host supplies the prepare/settlement sandbox seam and the patched MXC SDK is available. The bundle does not silently replace an existing sandbox row; legacy/mxc-host-integration.patch contains the host cutover for DSH snapshots that need it.
The provider remains fail-closed. prepare() refuses to run unless enabled: true, and functional qualification must prove the exact bundled executor before a launch is returned. The provider compiles complete file-effect policy, preserves the exact payload argv/cwd/environment, settles versioned result envelopes, and releases per-run capture artifacts.
Development
A full source-plane check uses a sibling DSH checkout. For the latest extracted implementation, point external-plugins/deepseek-harness at the compatible feat-mxc checkout, install the SDK or use the vendor branch, then run:
pnpm install
pnpm run typecheck
pnpm test
pnpm run prepare
pnpm pack --dry-run
The prepare script builds directly from src/, so a Git installation does not require DSH project references at runtime. pnpm test:e2e runs the packed-install and real-executor rehearsals when the platform, SDK, and native executor are available.
Model Experience
This provider adds no model-visible prompt, tool, or result text. It supplies the sandbox capability consumed by DSH bash and PTY plugins; the sandbox seam owns the SANDBOX_UNAVAILABLE error and any user-facing denial semantics.
Known Limitations and Deferred Work
- Linux MXC qualification requires usable Bubblewrap/user namespaces.
- macOS and Windows acceptance remains platform-dependent; Windows Tier 3 requires explicit host DACL permission.
- The registry-backed
mainbranch requires GitHub Packages access to resolve@dsh-external/mxc-sdk@dsh; usefeat-mxc-vendor-sdkfor the tracked offline carrier. - Older DSH snapshots require
legacy/mxc-host-integration.patchbecause a bundle cannot add missing sandbox prepare/settlement APIs by itself.
常见问题常见问题
在启用了 DSH 的终端中执行已验证命令 dsh plugin --profile default add github:omdsh-dev/sandbox-mxc。命令会解析公开 package 元数据,并保持插件与本页展示的目录身份一致。
兼容性以页面上展示的 bundle 与 profile 状态为准。如果某个 profile 尚未检测到,请先保持禁用,并在生产启用前阅读仓库文档。
GitHub 链接和 activity 元数据是 release 与维护状态的来源。新版本发布后重新查看本页,确认目录已经观察到最新版本。