Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed. - @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions). - @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules). - @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec. - bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled. Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2.4 KiB
2.4 KiB
@deepseek-ai/dsh-pwsh-sandbox
English | 中文
沙盒消费型的 ctx.bash 执行器 seam 的 PowerShell 实现:每条命令以 pwsh -NoLogo -NoProfile -NonInteractive -Command <command> 运行,经 ctx.sandbox 隔离,选定模式、强制完整性、拒绝事实都盖在每次结算的结果上。它是 @deepseek-ai/dsh-bash-sandbox 的 pwsh 孪生,按 pwsh 执行器与工具决策 逐调用镜像——隔离实体本身是平台无关的:Windows 上沙盒 seam 解析到 ACL 受限令牌 runner 链(@deepseek-ai/dsh-sandbox-windows-acl),Linux/macOS 上解析到 bwrap/Landlock/Seatbelt。
执行器继承 @deepseek-ai/dsh-pwsh-local 的进程机制,并消费其 argv 级 seam(argv() / runArgv() / startArgv() / onProcessDone())把精确的 pwsh 调用经 provider 包装。沙盒策略(模式 + 工作区根目录)不是本包的配置:每次调用由 ctx.sandboxPolicy 随行(工具层传调用会话解析后的策略;直接调用回退到部署策略)。
行为
danger-full-access:命令经本地执行器原样运行;结果携带sandbox: { mode, denied: false }。- 受限模式(
read-only、workspace-write):pwsh argv 由ctx.sandbox.confine()包装;runner 启动失败按 fail-closed 抛SANDBOX_UNAVAILABLE(前台抛错、后台记runnerFailed事实),被拒绝的写按所选后端的denialSignatures分类为sandbox.denied。
模型体验
隔离生效,拒绝以命令失败呈现
模型看到受限命令自身的 stderr(Windows ACL runner 下如 Access to the path '...' is denied.);工具层把分类后的拒绝转成标准权限拒绝面,与 bash 工具完全一致。
已知限制与后续工作
- Windows 上读不受限(ACL runner 只限写);读边界文档在
@deepseek-ai/dsh-sandbox-windows-acl。 - Windows workspace-write 的临时区域是真实临时目录(
GetTempPathW),与 Landlock 授予/tmp同语义——按运行创建私有临时目录需要 runner 改写环境块,留待后续。 - Windows read-only 是严格零授权——连 NUL 设备都不可写;
> $null重定向不受影响(后端包有文档)。