DSH Plugins
返回列表
🧩

dsh-workspace-write-plus

admin-security 更新于 2026.09.08

在终端中运行以下命令:

dsh plugin install yzxxy010/dsh-workspace-write-plus

将以下提示词粘贴到 DeepSeek Harness 对话框中:

在 DeepSeek Harness 终端中执行 dsh plugin install yzxxy010/dsh-workspace-write-plus 安装本插件,安装后重启 DSH 即可在权限选择器中看到「工作区修改++」选项。项目源码地址:https://github.com/yzxxy010/dsh-workspace-write-plus

插件介绍

Running DeepSeek Harness on Windows hits a very specific wall: the official Workspace-Write permission tier wraps every child process in a restricted token, but Git for Windows and MSYS rely on memory-mapped files and named pipes that simply will not function under that restriction. Even git --version fails, let alone clone or push. Git is not broken; the sandbox and MSYS are incompatible.

This plugin adds a fourth tier to the permission selector: Workspace-Write++. The idea is deliberately restrained. File writes remain confined to the workspace, so you do not hand the model full disk access. But any binary that matches the allow-list (bash and pwsh by default) is exempted from the process sandbox and gets a full token, so MSYS can open the memory mappings and pipes it needs. The allow-list lives in Settings, one entry per line, and supports both bare file-name matching and glob-style path patterns for precise control. Edits take effect immediately.

It is built for Windows users who run DSH day-to-day, need Git and Shell scripts to work reliably, and want to keep the model contained without granting it complete filesystem access. Workspace-Write++ is not a shortcut to Full Access; it simply splits the sandbox granularity a half-step finer: the file boundary stays, and only the specific binaries you name are let out of the process sandbox.

使用场景

  • Windows 上 git clone、git push 等命令因 MSYS 令牌限制无法启动子进程
  • 需要在受限权限下执行 Shell 脚本但不想开放全盘文件访问
  • 按需放行 bash、pwsh 等特定程序绕过进程沙箱限制

适合人员

  • Windows 平台 DeepSeek Harness 日常用户
  • 依赖 Git 工作流正常运行的开发者
  • 需要精细控制权限边界的行政安全团队