omdsh-dev/sandbox-nono
nono sandbox support
Packages the nono (Landlock/Seatbelt) sandbox backend as an installable DSH profile bundle: the sandbox provider, its invariant companion, the bundle patch and the vendored @dsh-external/nono-ts native executor carrier. The bundle adds a distinct sandbox-nono row that is disabled by default and enabled from a profile overlay when a deployment wants the Nono backend, with probeTimeoutMs configurable while the existing DSH sandbox row is left untouched. The SDK owns binding resolution, launch argv composition, wrapper failure classification and channel qualification, so the provider can prove enforcement before allowing work to run.
Install
⚠️ Install command not yet confirmed — check the README on GitHub for the exact command.
Compatibility
The README notes the vendored carrier currently contains only the Linux x64 GNU binding; unsupported hosts intentionally fail closed and Windows has no Nono backend. The provider fails closed with SANDBOX_UNAVAILABLE when the host has no vendored binding, the platform has no backend, or the functional channel probe does not prove enforcement. A full typecheck expects the DSH checkout beside the repository (../../deepseek-harness).
Details
- Repo: omdsh-dev/sandbox-nono
- Category: Infrastructure & Deployment
- Stars: 3
- Version: No npm version resolvable on 2026-09-13 (registry 404); no published install command in the README
- Last push: 2026-08-11
- First seen: 2026-08-10
Recent updates
The README documents the provider's row, the vendored binding scope and its limitations rather than a release history; verify the repository for current state.
FAQ
- How do I install it?
- The README does not publish a one-line install command — it documents the package/bundle shape and the development workflow, and the sandbox-nono row must be enabled from a profile overlay. Verify the current distribution method in the repository.
- Does it replace the default sandbox?
- No — the README states it adds a distinct sandbox-nono row (disabled by default) and does not silently rename or replace the existing DSH sandbox row.
- Which platforms work?
- Only Linux x64 GNU has a committed native binding; the README says unsupported hosts and Windows fail closed, with SANDBOX_UNAVAILABLE when enforcement cannot be proven.
Alternatives
FrankZhangIronly/dsh-system-control · khiqwq/dsh-credentials-system · AcidGr/dsh-web-lan-access