Introduction

In the development workflow of DeepSeek Harness (DSH), Agent policies, official permissions, and session-specific requirements often overlap. Managing these layers directly can blur permission boundaries and increase security risks. Existing permission models lack an intuitive configuration entry point and unified convergence logic when handling complex session scenarios.

What This Is

dsh-session-permissions is a plugin that provides session-level permission control for DSH. It was developed by maintainer xingyingyuzhui to resolve the uncertainty caused by multi-layer permission stacking. The plugin defines effective permissions by calculating the intersection of three layers and provides a sandbox mode “pinning” mechanism for Claw sessions to ensure permissions are not accidentally relaxed.

Core Features

Permission View and Calculation

After opening any session, a new “Permissions” tab appears in the session area. Effective permissions are calculated based on the intersection of the following three layers:
1. Official permissions
2. Agent policies
3. Session overrides

Different session types use different calculation logic:
* Workspace sessions: Only official permissions apply; the plugin does not intercept or tighten them.
* Claw sessions: Combine official presets ∩ Claw hard cap ∩ Agent policies ∩ session overrides.

Tool and File Boundaries

  • Tool support: Supports read, write, edit, apply_patch, exec (DSH’s bash is an alias for this tool).
  • File boundaries: Controlled via workspaceAccess; supports none, ro (read-only), rw (read-write), and all.
  • Path validation: Uses OpenClaw’s isPathInside for path checking.
  • Composite tool: str_replace_editor maps to read/write/edit according to the command.

Sandbox Pinning Mechanism

  • Official sandbox pinning: Claw sessions automatically inherit and pin the official sandbox mode, tightening restrictions only and never relaxing them.
  • Ceiling convergence: When saving a session, the system tightens permissions according to the ceiling; options exceeding the ceiling in the UI are unselectable.

Installation and Activation

Run the following command to install the plugin. After installation, restart the dsh web service.

dsh plugin --profile web add github:xingyingyuzhui/dsh-session-permissions

After installation, it is recommended to also install dsh-agent-gate to handle audit and interception logic.

Typical Usage

  • Session configuration: Open any session and click the new “Permissions” tab in the session area to configure it.
  • Claw session automatic handling: Claw sessions automatically inherit and pin the official sandbox mode, requiring no manual configuration.

Applicable Scenarios and Notes

Permission Limits

  • Maximum permission limit: Claw sessions cannot reach the official maximum permission danger-full-access (unrestricted terminal, no prompting).
  • Shell limit: The maximum Shell permission is allowlist.
  • File access: File read/write can be set to all, but Shell access is strictly limited.

Data and Behavior

  • Data storage: Permission configurations are stored in ~/.dsh/session-permissions/<sessionId>.json.
  • Impact after uninstallation: After uninstalling the plugin, pinned sandbox modes in already-open sessions remain effective, but MCP/skill/path interception stops.
  • BOOTSTRAP.md: If BOOTSTRAP.md exists in the project root directory, the official sandbox is first pinned to allow writing to the current workspace; the gate only permits persona files and ask_user_question.

Security Notice

This plugin runs with the permissions of the current dsh process. Before installation, it is recommended to review the source code and license.

Summary

dsh-session-permissions addresses the complexity of session permission management in DSH by providing a visual Permissions tab and strict sandbox pinning strategy. It ensures clear permission boundaries through three-layer intersection calculation and prevents permission escalation through its tightening mechanism. The related code is available on GitHub.