dshbase

Plugin directory / Developer / sandbox-nono

sandbox-nono

Unverified omdsh-dev

✓ Actively maintained Builds on 2 official DSH packages Pure TypeScript

View on GitHub ↗ ← Back to plugin directory

3Stars
0Forks
0Open issues
TypeScriptLanguage
2026-08-15Last push
Cross-platformPlatform

What it does

nono sandbox support

Our take
Unverified — not yet verified

nono sandbox support Not yet verified — install and test it yourself.

“Unverified” means our automated CI has not yet installed this plugin. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

Plugin author? Get the “Verified” label — submit your own evidence (screenshots, logs, or a short demo) and we'll review and flip the badge.

Submit verification evidence ↗

README

@deepseek-ai/dsh-sandbox-nono

English | 中文

The nono (Landlock/Seatbelt) backend as an installable DSH profile bundle. This standalone package contains the sandbox provider, its invariant companion, the bundle patch, and the vendored @dsh-external/nono-ts native executor carrier.

Repository shape

package.json              # standalone package and dsh.bundle manifest
cordis.patch.yml          # explicit sandbox-nono provider row
docs/                     # detailed bilingual Nono documentation
src/                      # provider and invariant companion
tests/                    # unit and real-wrapper integration tests
vendor-nono-ts/           # pinned native binding and executor wrapper
lib/                      # generated install artifacts

The bundle adds a distinct sandbox-nono row disabled by default. Enable it from a profile overlay when the deployment wants the Nono backend; the existing DSH sandbox row is not silently renamed or replaced.

- id: sandbox-nono
  name: '@deepseek-ai/dsh-sandbox-nono'
  disabled: false
  config:
    probeTimeoutMs: 5000

The provider fails closed with SANDBOX_UNAVAILABLE when the host has no vendored binding, the platform has no backend, or the functional channel probe does not prove enforcement. The SDK owns binding resolution, launch argv composition, wrapper failure classification, and channel qualification.

Detailed behavior and limitations: docs/nono.md.

Development

A full typecheck expects the DSH checkout beside this repository:

../../deepseek-harness
pnpm install
pnpm run typecheck
pnpm test
pnpm run build
pnpm run test:e2e

The prepare script builds directly from src/, so a package installation does not depend on the sibling checkout at runtime. The vendored carrier currently contains only the Linux x64 GNU binding; unsupported hosts intentionally fail closed.

Model Experience

Indirectly, through @deepseek-ai/dsh-bash-sandbox and @deepseek-ai/dsh-tool-bash, which render enforcement and denial facts. The @deepseek-ai/dsh-sandbox seam owns the SANDBOX_UNAVAILABLE text.

Known Limitations and Deferred Work

  • Only the linux-x64-gnu native binding is committed; other platforms need a matching carrier under vendor-nono-ts/native/.
  • Windows has no Nono backend and fails closed.
  • The functional probe verdict is cached for the provider lifetime; repairing a binding requires reloading the plugin.

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install sandbox-nono for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:omdsh-dev/sandbox-nono

Headless (CLI) profile:

dsh plugin --profile headless add github:omdsh-dev/sandbox-nono

Test report

Not yet L3-verified — see failure note below if we already ran it.

Status: pending
Note: 验证: install-fail (0.1.0-rc.6) Browse all pending failures →

When to use it

Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.

Who it's for

Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.

For developers — extending it

The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Developer

Browse all 7795 plugins →