yzxxy010/dsh-workspace-write-plus

DSH 第四档权限 工作区修改++:文件仍锁工作区,通配符放行 Git Bash 等进程沙箱。

Project Overview项目介绍

This is a permission-tier plugin built specifically for DeepSeek Harness, targeting the Windows-only pain point where the stock "Workspace Write" mode breaks Git Bash and PowerShell by wrapping child processes in a restricted token. That token blocks the memory-mapped files and named pipes MSYS / Git for Windows rely on, producing "fatal error - couldn't create signal pipe, Win32 error 5". The plugin adds a fourth entry, "Workspace Write++", to the permission selector: file writes are still constrained to the workspace, but executables on an allow-list skip the process sandbox. By default the list permits bash and pwsh, and installation is a single command: dsh plugin --profile web add https://github.com/yzxxy010/dsh-workspace-write-plus. After restarting DSH, the new tier appears beside the input box and is addressable as /permission workspace-write++.

Typical workflow: the user picks "Workspace Write++" for the session so git --version and shell scripts run without repeated approval prompts. Additional programs can be released through Settings → Workspace Write++, where each line is either a bare filename or a glob path. The README emphasises that on Windows Git Bash is often launched from PowerShell, so both must be on the list to prevent child processes from inheriting the restricted token. The tier is intended for users who want toolchains such as Git and pwsh available without granting the model full disk access.

Dependencies and limits are Windows-only: a bare entry matches the executable name in any directory, * does not cross directories while ** spans arbitrary depth, and an empty list effectively degrades the tier to "write to workspace with no prompts but still sandboxed". A separate "Write files outside workspace" toggle, off by default, lets write/edit tools target paths beyond the workspace and is independent of the shell allow-list. The plugin ships under the MIT licence and is published as a bundle manifest.

这是一款为 DeepSeek Harness 量身定做的权限档位插件,专门解决 Windows 上"工作区写入"模式跑 Git Bash / PowerShell 时被进程沙箱卡住的痛点。官方子进程令牌会阻断 MSYS 需要的内存映射和命名管道,触发 "couldn't create signal pipe" 错误;插件在权限选择器中追加第四档"工作区修改++",文件范围仍受限于工作区,但名单内的可执行文件跳过进程沙箱,默认放行 bash 与 pwsh。安装命令为 dsh plugin --profile web add https://github.com/yzxxy010/dsh-workspace-write-plus,装后重启 DSH,输入框旁的权限选择器里出现"工作区修改++",对应指令 /permission workspace-write++。

典型用法是用户选上"工作区修改++"后,直接在该会话里执行 git 或运行脚本而无需反复审批;如果想放行更多程序,可以进入"设置 → 工作区修改++"增删名单。它适合那些只想把 Git Bash、PowerShell 或特定工具链放出来、又不希望把整个磁盘交给模型的 Windows 用户,兼顾了安全边界与开发工具可用性。

依赖方面,插件仅在 Windows 上有意义,名单匹配规则区分纯文件名与带通配符路径,* 不跨目录、** 可跨多层;空名单时该档退化为"工作区写入但不弹审批"。另外还有一个独立的"工作区外写文件"开关,默认关闭,开启后 write/edit 可以写到工作区之外。许可为 MIT。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 5 stars - very few users, little community feedback星标只有 5,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add https://github.com/yzxxy010/dsh-workspace-write-plus

把 yzxxy010/dsh-workspace-write-plus 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

工作区修改++

Windows 上用 DeepSeek Harness,一跑 git 就炸:

fatal error - couldn't create signal pipe, Win32 error 5

这不是 Git 坏了。官方「工作区写入」会给子进程套一层受限令牌,Git for Windows / MSYS 需要内存映射和命名管道,一套上就起不来。

这个插件在权限选择器里加第四档:工作区修改++。文件还是只能改工作区,但放行的程序(默认 Git Bash 和 PowerShell)不再套那层进程沙箱。选上之后,git --version 就能正常出来。

它不是「完全访问」。不想把整个磁盘交给模型的时候用这一档。

安装

dsh plugin --profile web add https://github.com/yzxxy010/dsh-workspace-write-plus

装完重启一次 DSH。输入框旁边的权限选择器里会出现 工作区修改++,命令是 /permission workspace-write++。

怎么用

  1. 选中 工作区修改++
  2. 该 git、该跑脚本就直接跑
  3. 想放行别的程序,打开 设置 → 工作区修改++

默认已经放行了 bash 和 pwsh。Windows 上 Git Bash 往往是从 PowerShell 拉起来的,两个都要放,子进程才不会继续继承受限令牌。

放行规则

设置页是一份可增删的名单,一行一条。改完立刻生效,存在 DSH 自己的设置里,重启还在。

你写下的 实际匹配
bash 任意目录里的 bash.exe
pwsh 任意目录里的 PowerShell
aa 任意目录里的 aa.exe
**/Git/bin/bash.exe 只放行 Git 自带的那一个 bash
C:/Program Files/Git/** Git 安装目录下的所有程序
* 这一档里所有程序都不套进程沙箱

不带斜杠,只看文件名;带斜杠或 * / **,按路径匹配。* 不跨目录,** 可以跨任意多层。

名单留空的话,所有程序仍走进程沙箱——等于这一档退化成「工作区写入、但不弹审批」。

另外还有一个单独开关:工作区外写文件。默认关。打开后,write / edit 也可以写到工作区外面。这和放行 Shell 不是一回事,按需再开。

和另外三档

权限选择器里还是那四个格子,底层沙箱模式其实只有三种。++ 是一档预设,不是新的沙箱类型。

文件 进程沙箱 审批
只读 不能写 包裹 要问
工作区写入 只能写工作区 包裹,Windows 上 Git Bash 会挂 要问
工作区修改++ 只能写工作区 命中规则的程序跳过 不问
完全访问 不限制 不包裹 不问

许可

MIT。

← 上一个 Prev dsh-writing-remote 下一个 Next DeepSeek_Prism →