跳到主要内容

dsh-ubuntu-sandbox

已验证

@hakehuang/dsh-ubuntu-sandbox · v0.1.1 · MIT

Remote SSH Ubuntu sandbox for DeepSeek Harness: run bash on a remote host with a persistent (tmux) session plus remote read/write/list tools, sharing the host store of @linxin666/dsh-ssh.

安装

dsh plugin add @hakehuang/dsh-ubuntu-sandbox

用 dsh --profile default --dump-config 确认 layer 已生效 —— 参见安装指南。

源码

发布到 npm 但没有公开仓库。安装前请检查包内容。

标签

作者

说明文档

dsh-ubuntu-sandbox

把一台远程 Ubuntu 主机(SSH)当作 agent 的工作沙盒,用法和本地命令行一致: 远程执行 bash + 远程文件读写/列表,并持久化远端工作目录。

与 @linxin666/dsh-ssh 共享主机配置 (~/.dsh/dsh-ssh.json)——在 dsh-ssh 的 SSH 面板里配好(或从 ~/.ssh/config 导入)的主机,沙盒立即可用,无需重复录入凭据。

安装

dsh plugin --profile <profile> add @hakehuang/dsh-ubuntu-sandbox

装完重启 DSH。会话保持默认开启,需要远端已装 tmux(sudo apt-get install -y tmux); 主机在 @linxin666/dsh-ssh 的 SSH 面板里添加,或写进 ~/.dsh/dsh-ssh.json。 docs/ 目录是一个自建的 Community Market 目录源(见 docs/README.md)。

Agent 工具

工具 用途
sb_cwd 查看/切换沙盒主机 alias 与持久化的远端 cwd(类似 cd)
sb_session 会话保持开关(on/off/status/reset),由每 alias 一个 detach 的 tmux shell 支撑
sb_exec 在远端跑 bash(默认每次调用全新无状态 shell;打开会话后则在同一持久 bash 里执行——cd/export/后台任务跨调用保持)
sb_ls 列远端目录(ls -la 风格,目录优先)
sb_read 读远端文本文件(有上限,二进制会拒读 → 用 ssh_download)
sb_write 写 UTF-8 文本到远端文件(自动 mkdir -p 父目录)

会话保持需要远端已装 tmux;会话模式下长命令超时不会被强杀, 可用 sb_session action:reset 恢复。

本机↔远端之间的大文件/二进制传输用 dsh-ssh 的 ssh_upload / ssh_download; 访问远端内网端口用 ssh_tunnel。

目录结构

  • lib/index.js — 插件根(name = 'ubuntu-sandbox',注入 tools / systemPrompt,schemastery Config,agent 宣告)。
  • lib/host-store.js — 只读读取 ~/.dsh/dsh-ssh.json。
  • lib/state.js — ~/.dsh/dsh-ubuntu-sandbox.json(沙盒 alias 覆盖、各 alias 的 cwd、accept-new 主机指纹)。
  • lib/engine.js — ssh2 引擎(连接池、带超时与输出上限的 exec、流式 SFTP 读写/列表、tmux 持久会话支持;错误信息已脱敏)。
  • lib/tools.js — 六个 sb_* 工具。
  • cordis.patch.yml — bundle 层 loader patch(行 ubuntu-sandbox)。

安全说明

  • 凭据只从 ~/.dsh/dsh-ssh.json 读取(0600,由 dsh-ssh 维护);本插件不写、不打印任何密钥。
  • 主机指纹按 alias accept-new 固化在沙盒状态文件里。
  • 远端命令输出原样返回(与 dsh-ssh 相同),宣告文案已提醒 env 之类可能带出敏感信息。
  • 仅直连:跳板机场景请用 dsh-ssh 自带的工具。

构建 / 安装

纯 ESM JavaScript,无需构建。激活方式:作为 profile bundle 挂载(依赖 + dsh.profile.bundles 条目,包需存在于 profile 的 node_modules),随后重启 DSH。

版权

版权所有 © zephyrrtos.cn working group(保留所有权利)。

本项目以 MIT 许可证发布——见 LICENSE;上述版权归属即该许可证要求保留的署名。