跳到主内容

dsh-sandbox-local 使用指南

提供本地进程沙箱后端,支持 Linux bwrap/Landlock、macOS Seatbelt、Windows ACL,通过平台探测选择可用运行器并失败关闭,为 dsh-bash-sandbox 等消费者提供隔离执行环境

本文为派生内容(基于 wiki / faq / compatibility_json 自动组装),非 AI 即时创作。

本文由本站基于该插件已收录的字段自动派生(wiki / faq / compatibility_json / readme),非 AI 即时创作。每节末尾标源字段。

快速上手

提供本地进程沙箱后端,支持 Linux bwrap/Landlock、macOS Seatbelt、Windows ACL,通过平台探测选择可用运行器并失败关闭,为 dsh-bash-sandbox 等消费者提供隔离执行环境

— 源: plugins.ai_summary

安装与验证

dsh plugin --profile web add npm:@deepseek-ai/dsh-sandbox-local

复制以上命令在 DSH Web Profile 内运行。安装完成后在「插件列表」启用即可。

— 源: plugins.install

关键要点

  • id: sandbox
  • Landlock may be partial — older supported kernel ABIs confine only the access classes they expose, reported as enforcement: 'partial' rather than overstated as full.
  • Seatbelt depends on deprecated sandbox-exec — macOS still ships it, but this provider cannot replace or probe that private policy engine if Apple removes it.
  • Runner selection is cached for the provider lifetime — installing, removing, or repairing a runner requires reloading the plugin before selection changes.

— 源: plugin_wiki.readme_zh (fallback readme_raw)

踩坑提醒

安装前请审阅上游仓库;本指南基于已收录字段自动派生,可能滞后于最新版本。如发现与官方文档冲突,请以上游为准。

— 来源:通用规则