omdsh-dev/sandbox-nono
nono沙盒支持
已收录
3
Security
Bundle 已验证
功能介绍
nono 沙盒支持。
适合
- 希望使用基于 Landlock 或 Seatbelt 类执行机制、并保持故障关闭的 Linux x64 GNU DSH 部署。
- 希望显式启用独立沙箱后端、且不静默替换现有 sandbox 行的 Profile。
不适合
- Windows 和非 linux-x64-gnu 宿主,因为当前提交的载体仅包含 linux-x64-gnu 原生绑定。
- 要求修复绑定后无需重载插件即可恢复可用的环境;功能探测结论会在提供器生命周期内缓存。
README
@deepseek-ai/dsh-sandbox-nono
| English | 中文 |
The nono (Landlock/Seatbelt) backend as an installable DSH profile bundle. This standalone package contains the sandbox provider, its invariant companion, the bundle patch, and the vendored @dsh-external/nono-ts native executor carrier.
Repository shape
package.json # standalone package and dsh.bundle manifest
cordis.patch.yml # explicit sandbox-nono provider row
docs/ # detailed bilingual Nono documentation
src/ # provider and invariant companion
tests/ # unit and real-wrapper integration tests
vendor-nono-ts/ # pinned native binding and executor wrapper
lib/ # generated install artifacts
The bundle adds a distinct sandbox-nono row disabled by default. Enable it from a profile overlay when the deployment wants the Nono backend; the existing DSH sandbox row is not silently renamed or replaced.
- id: sandbox-nono
name: '@deepseek-ai/dsh-sandbox-nono'
disabled: false
config:
probeTimeoutMs: 5000
The provider fails closed with SANDBOX_UNAVAILABLE when the host has no vendored binding, the platform has no backend, or the functional channel probe does not prove enforcement. The SDK owns binding resolution, launch argv composition, wrapper failure classification, and channel qualification.
Detailed behavior and limitations: docs/nono.md.
Development
A full typecheck expects the DSH checkout beside this repository:
../../deepseek-harness
pnpm install
pnpm run typecheck
pnpm test
pnpm run build
pnpm run test:e2e
The prepare script builds directly from src/, so a package installation does not depend on the sibling checkout at runtime. The vendored carrier currently contains only the Linux x64 GNU binding; unsupported hosts intentionally fail closed.
Model Experience
Indirectly, through @deepseek-ai/dsh-bash-sandbox and @deepseek-ai/dsh-tool-bash, which render enforcement and denial facts. The @deepseek-ai/dsh-sandbox seam owns the SANDBOX_UNAVAILABLE text.
Known Limitations and Deferred Work
- Only the
linux-x64-gnunative binding is committed; other platforms need a matching carrier undervendor-nono-ts/native/. - Windows has no Nono backend and fails closed.
- The functional probe verdict is cached for the provider lifetime; repairing a binding requires reloading the plugin.
常见问题常见问题
在启用了 DSH 的终端中执行已验证命令 dsh plugin --profile default add github:omdsh-dev/sandbox-nono。命令会解析公开 package 元数据,并保持插件与本页展示的目录身份一致。
兼容性以页面上展示的 bundle 与 profile 状态为准。如果某个 profile 尚未检测到,请先保持禁用,并在生产启用前阅读仓库文档。
GitHub 链接和 activity 元数据是 release 与维护状态的来源。新版本发布后重新查看本页,确认目录已经观察到最新版本。