DeepSeek Harness Plugin

omdsh-dev/sandbox-nono

Stars ★ 2 Category Security & Permissions Added 2026-08-13

Support for the nono sandbox backend.

Install

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:omdsh-dev/sandbox-nono

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

English | 中文

The nono (Landlock/Seatbelt) backend as an installable DSH profile bundle. This standalone package contains the sandbox provider, its invariant companion, the bundle patch, and the vendored @dsh-external/nono-ts native executor carrier.

Repository shape

package.json              # standalone package and dsh.bundle manifest
cordis.patch.yml          # explicit sandbox-nono provider row
docs/                     # detailed bilingual Nono documentation
src/                      # provider and invariant companion
tests/                    # unit and real-wrapper integration tests
vendor-nono-ts/           # pinned native binding and executor wrapper
lib/                      # generated install artifacts

The bundle adds a distinct sandbox-nono row disabled by default. Enable it from a profile overlay when the deployment wants the Nono backend; the existing DSH sandbox row is not silently renamed or replaced.

- id: sandbox-nono
  name: '@deepseek-ai/dsh-sandbox-nono'
  disabled: false
  config:
    probeTimeoutMs: 5000

The provider fails closed with SANDBOX_UNAVAILABLE when the host has no vendored binding, the platform has no backend, or the functional channel probe does not prove enforcement. The SDK owns binding resolution, launch argv composition, wrapper failure classification, and channel qualification.

Detailed behavior and limitations: docs/nono.md.

Development

A full typecheck expects the DSH checkout beside this repository:

../../deepseek-harness
pnpm install
pnpm run typecheck
pnpm test
pnpm run build
pnpm run test:e2e

The prepare script builds directly from src/, so a package installation does not depend on the sibling checkout at runtime. The vendored carrier currently contains only the Linux x64 GNU binding; unsupported hosts intentionally fail closed.

Model Experience

Indirectly, through @deepseek-ai/dsh-bash-sandbox and @deepseek-ai/dsh-tool-bash, which render enforcement and denial facts. The @deepseek-ai/dsh-sandbox seam owns the SANDBOX_UNAVAILABLE text.

Known Limitations and Deferred Work

  • Only the linux-x64-gnu native binding is committed; other platforms need a matching carrier under vendor-nono-ts/native/.
  • Windows has no Nono backend and fails closed.
  • The functional probe verdict is cached for the provider lifetime; repairing a binding requires reloading the plugin.

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.