dsh-workspace-write-plus
在终端中运行以下命令:
dsh plugin install yzxxy010/dsh-workspace-write-plus
将以下提示词粘贴到 DeepSeek Harness 对话框中:
在 DeepSeek Harness 终端中执行 dsh plugin install yzxxy010/dsh-workspace-write-plus 安装本插件,安装后重启 DSH 即可在权限选择器中看到「工作区修改++」选项。项目源码地址:https://github.com/yzxxy010/dsh-workspace-write-plus
插件介绍
Running DeepSeek Harness on Windows hits a very specific wall: the official Workspace-Write permission tier wraps every child process in a restricted token, but Git for Windows and MSYS rely on memory-mapped files and named pipes that simply will not function under that restriction. Even git --version fails, let alone clone or push. Git is not broken; the sandbox and MSYS are incompatible.
This plugin adds a fourth tier to the permission selector: Workspace-Write++. The idea is deliberately restrained. File writes remain confined to the workspace, so you do not hand the model full disk access. But any binary that matches the allow-list (bash and pwsh by default) is exempted from the process sandbox and gets a full token, so MSYS can open the memory mappings and pipes it needs. The allow-list lives in Settings, one entry per line, and supports both bare file-name matching and glob-style path patterns for precise control. Edits take effect immediately.
It is built for Windows users who run DSH day-to-day, need Git and Shell scripts to work reliably, and want to keep the model contained without granting it complete filesystem access. Workspace-Write++ is not a shortcut to Full Access; it simply splits the sandbox granularity a half-step finer: the file boundary stays, and only the specific binaries you name are let out of the process sandbox.
使用场景
- Windows 上 git clone、git push 等命令因 MSYS 令牌限制无法启动子进程
- 需要在受限权限下执行 Shell 脚本但不想开放全盘文件访问
- 按需放行 bash、pwsh 等特定程序绕过进程沙箱限制
适合人员
- Windows 平台 DeepSeek Harness 日常用户
- 依赖 Git 工作流正常运行的开发者
- 需要精细控制权限边界的行政安全团队