deepseek-harness/packages/bash
2026-07-13 23:42:54 +08:00
..
bash fix(review): reconcile sandbox and approval contracts 2026-07-11 21:37:38 +08:00
bash-local feat(example): sandbox-acp-agent — the live composition; RFCs to implemented 2026-07-10 15:44:38 +08:00
bash-sandbox fix(review): reconcile sandbox and approval contracts 2026-07-11 21:37:38 +08:00
tool-bash chore: gate TypeScript duplication in CI 2026-07-13 23:42:54 +08:00
README.md feat(bash): the sandboxed executor — per-call policy carrier, denial facts, runner-failure classification 2026-07-10 15:43:02 +08:00

bash/ — bash capability family

The canonical three-package capability seam (see capability seams): an abstract executor interface, concrete implementations, and the model-facing tool that consumes it. All product packages.

Package Role ctx key
bash/ Abstract bash executor seam (interface + vocabulary; sandbox result facts carry the sandbox/ seam's mode/enforcement vocabulary) ctx.bash
bash-local/ Local-subprocess BashExecutor implementation (registers ctx.bash)
bash-sandbox/ Sandbox-consuming BashExecutor (wraps every command argv via ctx.sandbox, stamps denial/enforcement facts; extends bash-local's mechanics) (registers ctx.bash)
tool-bash/ Model-facing bash/bash_output/bash_kill tool schemas (registers on ctx.tools)

The interface lives at bash/bash/. bash-sandbox replacing bash-local without touching the interface or the tool is the split doing exactly what it exists for — a leaf cordis.yml picks one executor entry, plus a ctx.sandbox provider entry for the confined one (see examples/sandbox-acp-agent).