Files
deepseek-harness/packages/shell
Tianyi Cui a7a5be1703 docs(notes): archive low-future-value Agent Notes
Run the dsh-archive-agent-notes audit over every active Agent Note on
current master, judging each record by whether its rationale still guides
work rather than by size or age.

- Archive 453 implemented bilingual triplets (417,882 English words):
  completed UI chrome, narrow adapters, closed bug fixes, implementation
  walkthroughs whose package READMEs, docs pages, generators, or successor
  notes now carry the useful behavior, and 51 records fully superseded by
  a later active note. Keep 201 implemented notes whose ownership rules,
  negative guarantees, durable or wire semantics, security rules,
  reintroduction conditions, or still-tempting rejected alternatives
  remain useful.
- Reject 7 proposals whose premise is gone or whose work shipped in
  amended form under other records; delete 2 rejected notes that no
  longer prevent a plausible mistake.
- Retarget every remaining inbound link to the archived path, and repair
  active prose that named an archived record as the owner of a live fact:
  parenthetical citations drop, ownership sentences redirect to the
  README, docs page, or active note that states the fact, and history
  citations say so. Chinese files link the English archived path because
  the pairing gate treats the frozen tree as outside the bilingual corpus.
- Seal 1,359 new frozen artifacts; existing seals are unchanged and
  outbound links from archived notes are neither inspected nor repaired.
- Regenerate docs/config-catalog.md after the hook-bridge comment edits
  shifted two source line numbers.
2026-09-05 14:37:32 +08:00
..
2026-09-04 15:38:55 +08:00
2026-09-04 15:38:55 +08:00
2026-09-04 15:38:55 +08:00
2026-09-04 15:38:55 +08:00
2026-09-04 15:38:55 +08:00

description, kind
description kind
The bash capability family for deployments and maintainers choosing and composing a shell executor, sandboxing, and the model-facing bash and pwsh tools. package-group

shell/ — bash capability family

English | 中文

Summary

The shell group provides command execution to agents: run a foreground command and read its bounded output, or start a background process and poll it, on POSIX with Bash and on Windows with PowerShell. Exactly one executor implementation is mounted per composition; the sandboxing executors confine every command through the sandbox capability, and the model-facing bash and pwsh tools sit on top of whichever executor is mounted. Choose a Bash executor for POSIX, a PowerShell executor for Windows, and pick the sandboxing variant when commands need file-level confinement.

Table of Contents


Packages

Package Role ctx key
shell Defines the executor contract: foreground runs, background handles, and request resolution ctx.shell
bash-local Runs Bash commands as fresh bash -c processes on POSIX registers ctx.shell
bash-sandbox Runs Bash commands confined through the sandbox capability, reporting denials as facts registers ctx.shell
pwsh-local Runs PowerShell commands as fresh pwsh -Command processes on Windows registers ctx.shell
pwsh-sandbox Runs PowerShell commands confined through the sandbox capability registers ctx.shell
shell-env Supplies the managed DSH_* environment every shell command receives ctx.shellEnv
tool-bash Exposes Bash execution and background jobs to the model as the bash tool registers on ctx.tools
tool-bash-persistent Runs model shell calls in one owner-isolated persistent Bash session registers on ctx.tools
tool-pwsh Exposes PowerShell execution to the model as the pwsh tool registers on ctx.tools
tool-pwsh-persistent Runs model shell calls in one owner-isolated persistent PowerShell session registers on ctx.tools

A profile layer selects exactly one executor implementation (the win32 layer swaps the POSIX rows for the pwsh ones; mounting two fails loud on the duplicate service registration) and the model-facing tools it needs. A sandboxed composition also selects a ctx.sandbox provider and ctx.sandboxPolicy; the base bundle owns the shipped wiring.


  • Bash executor subsystem — the shared request/spec vocabulary, results, background processes, and the service contract.
  • Sandbox subsystem — the confinement capability the sandboxing executors consume.

Dev Note

None.