sandbox-nono
Manifest valid@deepseek-ai/dsh-sandbox-nono
English | 中文
The nono (Landlock/Seatbelt) backend as an installable DSH profile bundle. This standalone package contains the sandbox provider, its invariant companion, the bundle patch, and the vendored @dsh-external/nono-ts native executor carrier.
Repository shape
package.json # standalone package and dsh.bundle manifest
cordis.patch.yml # explicit sandbox-nono provider row
docs/ # detailed bilingual Nono documentation
src/ # provider and invariant companion
tests/ # unit and real-wrapper integration tests
vendor-nono-ts/ # pinned native binding and executor wrapper
lib/ # generated install artifacts
The bundle adds a distinct sandbox-nono row disabled by default. Enable it from a profile overlay when the deployment wants the Nono backend; the existing DSH sandbox row is not silently renamed or replaced.
- id: sandbox-nono
name: '@deepseek-ai/dsh-sandbox-nono'
disabled: false
config:
probeTimeoutMs: 5000
The provider fails closed with SANDBOX_UNAVAILABLE when the host has no vendored binding, the platform has no backend, or the functional channel probe does not prove enforcement. The SDK owns binding resolution, launch argv composition, wrapper failure classification, and channel qualification.
Detailed behavior and limitations: docs/nono.md.
Development
A full typecheck expects the DSH checkout beside this repository:
../../deepseek-harness
pnpm install
pnpm run typecheck
pnpm test
pnpm run build
pnpm run test:e2e
The prepare script builds directly from src/, so a package installation does not depend on the sibling checkout at runtime. The vendored carrier currently contains only the Linux x64 GNU binding; unsupported hosts intentionally fail closed.
Model Experience
Indirectly, through @deepseek-ai/dsh-bash-sandbox and @deepseek-ai/dsh-tool-bash, which render enforcement and denial facts. The @deepseek-ai/dsh-sandbox seam owns the SANDBOX_UNAVAILABLE text.
Known Limitations and Deferred Work
- Only the
linux-x64-gnunative binding is committed; other platforms need a matching carrier undervendor-nono-ts/native/. - Windows has no Nono backend and fails closed.
- The functional probe verdict is cached for the provider lifetime; repairing a binding requires reloading the plugin.
Comments
Loading…
From the same category
by awesome-dsh-plugin
A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表
★ 17.5k
CC0-1.0
Python
Sep 30, 2026
by zhu1090093659
DeepSeek Harness (DSH) Web Plugin Aggregation Ecosystem · Everything is a plugin, distributed via the Creative Workshop
★ 8.2k
↓ 134/wk
Apache-2.0
TypeScript
Oct 1, 2026
dsh plugin --profile web add dsh-webby yjh051108
dsh-routing-suite — injector + router-standard kit: install the runtime injector first, then the task-aware reasoning-mode router preset (measured P1-P23).
★ 7k
MIT
JavaScript
Sep 18, 2026
dsh plugin --profile web add @dsh-external/dsh-super-injectorby strukto-ai
The World's First Virtual Terminal for AI Agents
★ 3.7k
↓ 264/wk
Apache-2.0
TypeScript
Oct 1, 2026
dsh plugin --profile agent add @struktoai/mirage-dshby xmanrui
通过扫码或机器人凭据把IM机器人接入DeepSeek Harness(支持飞书、微信、钉钉、企业微信、QQ、Slack、Telegram、Discord和WhatsApp)。 Connect IM bots to DeepSeek Harness via QR code or credentials (9 channels).
★ 1.6k
↓ 16.4k/wk
MIT
JavaScript
Oct 1, 2026
dsh plugin --profile web add @xmanrui/dsh-imby hyhmrright
AI code reviews grounded in 12 classic engineering books — decay risk diagnostics with book citations, severity labels, and 6 analysis modes including full-sweep auto-fix
★ 1.5k
MIT
JavaScript
Sep 28, 2026