dsh-bash-native: Native Windows Bash Execution for DeepSeek Harness
spookywaste/dsh-bash-native
A native Windows POSIX bash executor for DeepSeek Harness, built on the Rust brush engine without WSL or MSYS layers, supporting DSH's three-tier permission policies and background jobs.
dsh-bash-native is a DSH plugin that gives DeepSeek Harness a genuinely native POSIX bash on Windows through a Rust-built brush engine, with no WSL or MSYS compatibility layer involved. It removes the per-command cost of running POSIX scripts on Windows, where a compatibility layer forks a full process and a Linux VM adds a boundary round trip. The plugin ships its engine and toolchain with the package and verifies them at resolution time, honors the harness's three file-access tiers, reports background jobs through the job system, and exposes a model-visible environment contract. It is maintained by SpookyWaste under the MIT license and targets Windows x64 only.
How to Install
dsh plugin --profile web add dsh-bash-native- Category
- Tools & Capabilities
- Platform
- DSH Plugin
- Author
- spookywaste
- Distribution
- Plugin
dsh-bash-native Key Features
dsh-bash-native Repo Summary
What Does It Do?
spookywaste/dsh-bash-native is a DSH plugin for DeepSeek Harness that provides a genuinely native POSIX bash on Windows through a Rust-built brush engine, without relying on WSL or an MSYS compatibility layer. It removes the per-command cost of running POSIX scripts on Windows, where a compatibility layer forks a full process for every subshell or external command and a Linux VM adds a boundary round trip. The plugin ships its engine and toolchain with the package and verifies them at resolution time, honors the harness's three file-access tiers, reports background jobs through the job system, and exposes a model-visible environment contract. It is maintained by SpookyWaste under the MIT license and targets Windows x64 only.
Core Features
- Native bash engine: commands are handed to the bundled brush engine, with
echo,cat,ls,cp,rm, andsortresolved as builtins so they work even with an emptyPATH, and no compatibility layer or VM boundary in the path. - Three-tier permission policy: it obeys the
read-only/workspace-write/danger-full-accessfile policies, routing engine argv through the sandbox in restricted tiers and spawning directly in the unrestricted tier while reporting the tier truthfully. - Background jobs and output spill: background jobs are reported through the job system, and output beyond the in-memory limit spills to a file whose path is returned with the result.
- Path and script compatibility patches:
/tmpbecomes an alias when the shell resolves paths, drive-mount aliases make/c/Windows/System32equalC:\Windows\System32, CRLF scripts written on Windows are read as text, andbash script.sh,bash -c,sh -c, plus Makefile/npm hooks that call bash, all work. - Artifact verification with stamping: each resolution checks the engine artifact against the sha256 in the lock file, and records size and mtime in a local verified directory so unchanged artifacts skip the repeated hash.
- No interference with other presets: the web surface mounts it through its own agent preset and the agent surface enables it via overlay, so it does not replace the host shell and other presets' pwsh tools keep working.
How to Use This Plugin?
After enabling it in DSH, set Native Bash (Windows) as the default preset or switch to it inside a session, and shell commands issued by the model then run on the native brush engine. The runtime requires Windows x64, Node 24, and a compatible DSH version; scripts can be invoked as bash script.sh, bash -c, or sh -c, while executing a script directly by path such as ./s.sh is not supported yet. To adjust behavior, you can switch artifact verification to hash every time, or set the escape hatch on a single command to turn off path rewriting.
How to Troubleshoot This Plugin?
- A background job has no PID,
$!is empty, orjobsreports a finished job as Running: this happens when the shell did not register a process for that job (builtins, functions, bundled tools), so check liveness withwaitrather thankill -0. jobs/jobs -pinside command substitution shows an empty table, orkill %1 %2errors out:killaccepts only one target at a time, and Windows does not deliver signals, so every signal ends as 128+n (TERM 143, KILL 137).awk '/x/{print}'receives a rewritten path, orsed '/x/d'reports invalid command code: drive rewriting cannot tell a path from a program's script operand, so rewrite asawk '$0 ~ /x/'or disable path rewriting for that command.- The engine itself is still in preview, so treat suspected defects by following the official guidance to fix or report them.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: spookywaste/dsh-bash-native. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
