Preface

DeepSeek Harness (DSH) provides a unified ctx.shell interface for Agent development. In Windows environments, developers often need to invoke Git Bash or WSL to execute specific Linux/MSYS commands. The dsh-win-multi-bash plugin introduces a shell-select executor and additional model tools, resolving the limitation of a single Shell interface that cannot directly call these environments while maintaining compatibility with native PowerShell (pwsh).

Plugin Positioning

This is a client plugin maintained by Dinosaur-MC and licensed under the MIT open-source license. It extends DSH’s Shell capabilities, supporting request routing to Git Bash, WSL, and PowerShell within the same ctx.shell context.

Core Features

The plugin primarily provides the following capabilities:

  1. Model Tools: Adds two new model tools, git_bash and wsl_bash, corresponding to the MSYS and Linux dialects.
  2. Executor: Introduces a shell-select executor responsible for assigning request.shell or the default route to a specific backend.
  3. Routing Policy: The default route remains pwsh, ensuring that existing behavior remains unchanged when no explicit bash-family tool is invoked.
  4. Auto-Detection: Supports automatic detection of Git Bash, with a detection order that includes PATH, the Windows registry, and Git installation root directory layouts.
  5. Sandbox Support: Supports multiple sandboxing mechanisms (auto, bwrap, windows-acl) and the requireSandbox configuration option.

Installation and Enablement

The current source text does not provide specific installation command strings. It is recommended to review the repository or plugin directory via the following links for installation guidance.

  • GitHub: https://github.com/Dinosaur-MC/dsh-win-multi-bash
  • Skill Directory: https://www.skillhub.cn/plugins/Dinosaur-MC/dsh-win-multi-bash

Typical Usage

Configuring Sandbox Requirements

In cordis.patch.yml, you can configure requireSandbox for a backend to reject unrestricted execution:

# cordis.patch.yml
config:
  backends: [git-bash, wsl-bash, pwsh]
  default: pwsh
  gitBash: { requireSandbox: true }
  wslBash: { requireSandbox: true }

Enabling WSL Sandbox

The sandbox mechanism for wsl_bash relies on bubblewrap inside the distribution. Install it in Ubuntu/Debian distributions:

wsl.exe -d Ubuntu-24.04 -e sudo apt-get install -y bubblewrap
wsl.exe -d Ubuntu-24.04 -e bash -c "command -v bwrap && bwrap --version"

After installation, the dsh web process must be restarted (or Shell settings must be rebuilt) to re-probe the sandbox status.

Path Conversion Handling

Git Bash automatically converts POSIX paths to Windows paths. If a command needs to be passed as-is to a Windows-native program (such as wsl.exe), set MSYS_NO_PATHCONV=1:

MSYS_NO_PATHCONV=1 wsl.exe -e ls /root

Use Cases and Notes

  • Sandbox Limitations: git_bash usually cannot be fully sandboxed in Git for Windows deployments, and the sandbox mechanism may occasionally degrade to unrestricted execution; the wsl_bash sandbox relies on bubblewrap inside the distribution.
  • Denial Classification: Sandbox denial behavior is classified only when a command exits with a non-zero exit code.
  • Sandbox Scope: Sandboxing only restricts file operations (workspace-write / read-only) and does not restrict network or other resources.
  • Version Requirements: The plugin depends on @deepseek-ai/cordis and related DSH components, and requires Node.js version ^22.19.0 || >=24.0.0.
  • Path Compatibility: When using Git Bash tools, MSYS paths must be converted to Windows paths (for example, /d/WorkSpace/foo to D:\WorkSpace\foo) for use by DSH’s file tools, while paths used inside Bash should remain in MSYS format.

Summary

dsh-win-multi-bash provides flexible Shell routing capabilities for DSH Agent development on Windows, supports Git Bash and WSL integration, and offers basic sandbox protection mechanisms. For developers who need to use multiple Shell types together in Windows environments, this is a practical supplemental tool.