2026-08-07 00:15:55 +08:00
|
|
|
# The dsh-base Windows platform layer: applied by the dsh launcher on win32
|
2026-08-07 01:20:40 +08:00
|
|
|
# hosts, between the bundle layers and the user layers. Windows cannot run
|
|
|
|
|
# the POSIX-only sandboxed stacks, so this layer swaps the shipped bash stack
|
2026-08-07 01:41:32 +08:00
|
|
|
# for the PowerShell stack AND drops the whole permission surface: no OS
|
|
|
|
|
# runner exists on Windows (landlock/bwrap/seatbelt are POSIX-only), so any
|
|
|
|
|
# policy would be theater — the unconfined shell could bypass fs-only path
|
|
|
|
|
# rules with one command. Windows therefore degrades to danger-full-access:
|
2026-08-07 01:20:40 +08:00
|
|
|
# unconfined pwsh + unconfined fs (`dsh-fs-local`), no permission switcher
|
2026-08-07 01:41:32 +08:00
|
|
|
# (dsh-permission requires a confining executor), and no approval service —
|
|
|
|
|
# nothing in the roster asks for approval, and the model is never told
|
|
|
|
|
# approval exists or that requests are auto-rejected.
|
2026-08-07 01:20:40 +08:00
|
|
|
# The launcher reads THIS file from the base bundle package (never through
|
|
|
|
|
# dsh.bundle.patch — that field names the one universal layer). A Windows
|
|
|
|
|
# host that prefers bash or confinement overrides these rows through its
|
|
|
|
|
# profile or home cordis.patch.yml.
|
2026-08-07 19:21:49 +08:00
|
|
|
# The bash-restore recipe must be complete: disable pwsh-local and tool-pwsh
|
|
|
|
|
# AND re-enable bash-sandbox and tool-bash (plus permission/ui-permission only
|
|
|
|
|
# if the switcher is wanted) — both executors register the same 'bash'
|
|
|
|
|
# service, so re-enabling the bash rows while pwsh-local stays inserted fails
|
|
|
|
|
# loud at load on a duplicate registration.
|
|
|
|
|
# The ui-permission disable targets a row owned by dsh-web-app, not dsh-base:
|
|
|
|
|
# a base-only profile (e.g. the `dsh plugin --profile` default template) has
|
|
|
|
|
# no such row, and the no-match logs a harmless warning on every load.
|
2026-08-07 00:15:55 +08:00
|
|
|
|
|
|
|
|
- id: bash-sandbox
|
|
|
|
|
disabled: true
|
|
|
|
|
|
|
|
|
|
- id: tool-bash
|
|
|
|
|
disabled: true
|
|
|
|
|
|
|
|
|
|
- id: permission
|
|
|
|
|
disabled: true
|
|
|
|
|
|
|
|
|
|
- id: ui-permission
|
|
|
|
|
disabled: true
|
|
|
|
|
|
2026-08-07 01:20:40 +08:00
|
|
|
- id: sandbox
|
|
|
|
|
disabled: true
|
|
|
|
|
|
|
|
|
|
- id: sandbox-policy
|
|
|
|
|
disabled: true
|
|
|
|
|
|
|
|
|
|
- id: fs-sandbox
|
|
|
|
|
disabled: true
|
|
|
|
|
|
|
|
|
|
- id: approval
|
2026-08-07 01:41:32 +08:00
|
|
|
disabled: true
|
2026-08-07 01:20:40 +08:00
|
|
|
|
2026-08-07 00:15:55 +08:00
|
|
|
- insert:
|
|
|
|
|
- id: pwsh-local
|
|
|
|
|
name: '@deepseek-ai/dsh-pwsh-local'
|
|
|
|
|
|
|
|
|
|
- id: tool-pwsh
|
|
|
|
|
name: '@deepseek-ai/dsh-tool-pwsh'
|
2026-08-07 01:20:40 +08:00
|
|
|
|
|
|
|
|
- id: fs-local
|
|
|
|
|
name: '@deepseek-ai/dsh-fs-local'
|