dshbase

插件目录 / Developer / dsh-shell-termux

dsh-shell-termux

已验证 · 实测可装 kelai141

✓ 持续维护 基于 6 个官方 DSH 包 纯 TypeScript

查看 GitHub ↗ ← 返回插件目录

0Stars
0Forks
0未关闭 issue
TypeScript语言
2026-08-15最近推送
跨平台平台

功能简介

dsh 的安卓/Termux bash 能力提供者——显式 Termux 环境注入、探测诊断、诚实的应用域沙箱声明。

✅
我们的评价
可用 — 实测通过,早期项目

dsh 的安卓/Termux bash 能力提供者——显式 Termux 环境注入、探测诊断、诚实的应用域沙箱声明。 实测能干净安装、正常启动。早期项目,但功能可用。

「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。

README

dsh-shell-termux

[🌐 中文说明 / 中文 README](README.zh.md) > **DeepSeek Harness × Android 生态** · https://github.com/kelai141/dsh-mobile-apk(壳 APK)· https://github.com/kelai141/dsh-client-ui-responsive(移动 UI)· https://github.com/kelai141/dsh-host-web-compat(浏览器兼容) Android/Termux bash capability provider for https://github.com/deepseek-ai/deepseek-harness. Registers as ctx.shell on Android so the model's bash tool executes in a controlled Termux environment — no fake sandboxing, no dependency on the ambient environment being accidentally right.

Why

On Android the upstream bash-sandbox fails closed (no bwrap/landlock/seatbelt platform chain), so the bash tool is dead out of the box. This provider replaces it with an honest Termux execution world: explicit environment injection, probe diagnostics, and a declared app-domain sandbox semantics (workspace-write + enforcement: 'partial').

Quick start

**Prerequisite**: a Termux installation with bash (pkg install bash). **1. Install** — put the package into the profile's node_modules (healed fallback resolves its @deepseek-ai/* dependencies to the running dsh instance): ``sh

from the profile directory (~/.dsh/profiles/web)

npm install /path/to/dsh-shell-termux-0.1.0.tgz

or manually: unpack into <profile>/node_modules/@dsh-android/dsh-shell-termux/

` **2. Mount** — add to the profile's cordis.patch.yml: `yaml - id: bash-sandbox disabled: true - insert: - id: shell-termux name: '@dsh-android/dsh-shell-termux' config: bashPath: /data/data/com.termux/files/usr/bin/bash prefix: /data/data/com.termux/files/usr home: /data/data/com.termux/files/home cwd: /data/data/com.termux/files/home timeoutMs: 120000 maxTimeoutMs: 600000 ` **3. Restart** the dsh service and verify with --dump-config (the row must be present, not disabled).

Configuration

| key | meaning | default | |---|---|---| |
bashPath | absolute bash binary path | required | | prefix | Termux prefix root (contains bin/ lib/) | required | | home | Termux home directory | required | | termuxVersion | TERMUX_VERSION value injected | 0.118.3 | | extraPath | extra PATH entries prepended (e.g. /system/bin) | [] | | cwd / timeoutMs / maxTimeoutMs / maxOutputBytes / maxSpillBytes / graceMs | inherited local-executor knobs (editable via shell settings) | mirror dsh-bash-local |

What it does

- **Controlled environment** — every spawn injects
PATH/LD_LIBRARY_PATH/HOME/PREFIX/TERMUX_VERSION/SHELL explicitly; execution never depends on the launcher environment. - **Reuses local mechanics** — extends LocalBashExecutor (runArgv/startArgv): process-group SIGTERM→SIGKILL, output caps + spill, grace period, background lifecycle, teardown ownership. - **Honest sandbox declaration** — sandboxMode = 'workspace-write' (so permission presets mount) with per-process enforcement: 'partial': the protection boundary is the Android app domain (SELinux u0_aXXX) plus the approval flow, not a path-level confiner. - **Probe diagnostics** — probe() reports bash presence/version and missing toolchain packages (pkg install bash coreutils findutils grep ripgrep hints). Misconfigured bash fails loud with repair guidance.

Verification

-
probe() status: full / partial / unusable with a missing-package list; - fault injection: point bashPath at a missing binary → structured error (shell-termux: <path> is not executable; run 'pkg install bash' …) returned to the model.

License

MIT. Contains code derived from
@deepseek-ai/dsh-bash-local (MIT, © 2026 DeepSeek) — see NOTICE. Design rationale: docs/design.md`.

安装

🧩 让 Agent 自动装(推荐)

装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:

dsh plugin add dshbase-catalog

然后对 agent 说「帮我装 dsh-shell-termux」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。

该插件是 GitHub 源码(未发 npm)——直接从仓库装:

Web profile:

dsh plugin --profile web add github:kelai141/dsh-shell-termux

Headless(CLI)profile:

dsh plugin --profile headless add github:kelai141/dsh-shell-termux

实测报告

验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。

使用场景

扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。

适合谁

想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。

二次开发建议

工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。

安全:尚未扫描——我们的每日静态扫描将很快覆盖它。

分享徽章

Developer 里更多

浏览全部 7797 个插件 →