返回源码地图

packages/ssh/sandbox-ssh/src/index.ts

main snapshot · da00f7f5358f · 正文引用章节 10;完整原文可核对,不声称全文件人工逐行审计

完整原文供逐行核对;页面收录不代表每行都经过人工语义审核。MIT 许可见 许可证。

1/** Remote argv wrapper that selects and applies the sandbox on the SSH host. */
2import { SandboxProvider, SandboxUnavailableError } from '@deepseek-ai/dsh-sandbox'
3import type { ConfinedArgv, SandboxPolicy } from '@deepseek-ai/dsh-sandbox'
4import type {} from '@deepseek-ai/dsh-ssh'
5import { z } from 'zod'
6
7const factsSchema = z.object({ argv: z.array(z.string()).min(1), enforcement: z.enum(['full', 'partial']), denialSignatures: z.array(z.string()), runnerFailureRules: z.array(z.object({ allowedExitCodes: z.array(z.number().int()).optional(), fatalSignatures: z.array(z.string()), informationalLines: z.array(z.string()).optional() }).strict()) }).strict()
8
9/** Resolve each confinement request on the same host as its filesystem and subprocess providers. */
10export class SshSandboxProvider extends SandboxProvider {
11 static inject = ['ssh']
12
13 override async confine(argv: readonly string[], policy: SandboxPolicy, signal?: AbortSignal): Promise<ConfinedArgv> {
14 signal?.throwIfAborted()
15 try {
16 const confined = await this.ctx.ssh.request('sandbox', { argv, policy }, factsSchema, signal)
17 signal?.throwIfAborted()
18 return {
19 ...confined,
20 runnerFailureRules: confined.runnerFailureRules.map(rule => ({
21 fatalSignatures: rule.fatalSignatures,
22 ...(rule.allowedExitCodes === undefined ? {} : { allowedExitCodes: rule.allowedExitCodes }),
23 ...(rule.informationalLines === undefined ? {} : { informationalLines: rule.informationalLines }),
24 })),
25 }
26 } catch (error) {
27 signal?.throwIfAborted()
28 throw new SandboxUnavailableError(policy.mode, error instanceof Error ? error.message : String(error))
29 }
30 }
31}
32
33export default SshSandboxProvider