npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dsh-unsandboxed-winbash

v0.1.7

Published

Windows 上给 dsh 增加 Git Bash(MSYS2)工具的插件:Git Bash 无法在文件沙箱内启动(MSYS 运行时需要的命名管道被受限 token 拒绝),所以本插件在沙箱之外执行它,并在工具描述里写明这一点;pwsh、权限预设与 fs 工具的沙箱保持不变。Adds a Git Bash (MSYS2) tool to dsh on Windows: Git Bash cannot start inside the harness file sandbox (its MSYS runt

Readme

dsh-unsandboxed-winbash

中文 | English

ci DSH npm release DSH node downloads license

Windows 上的 Git Bash(MSYS2)工具插件。它向会话新增一个 winbash 工具,直接以 Git for Windows 的 bash 执行命令并修好 MSYS 的 PATH;命令在文件沙箱之外执行,工具描述也写明了这一点。

为什么需要它

Windows 上 dsh 不提供任何 bash 工具:@deepseek-ai/dsh-base 在 win32 上同时禁用了 dsh-bash-sandbox 与 dsh-tool-bash。手工打开也无效,因为 Windows 沙箱装不下 MSYS2——受限 token 拒绝创建 MSYS 信号处理所需的命名管道。以下为 Windows 11 + dsh 0.1.5-rc.1 的沙箱内实测:

| 尝试 | 结果 | | --- | --- | | bash -c(PATH 解析到 C:\Windows\System32\bash.exe) | Bash/Service/CreateInstance/E_ACCESSDENIED | | wsl.exe -e bash -c | Wsl/Service/CreateInstance/E_ACCESSDENIED | | C:\Program Files\Git\usr\bin\bash.exe -c | fatal error - couldn't create signal pipe, Win32 error 5 |

功能

  • 新增 winbash 工具:以 bash -c 执行命令,返回 stdout、stderr 与退出码;非零退出按结果上报,不作为工具错误。
  • Git Bash 自动发现:usr\bin\bash.exe(真实 MSYS2)优先于 bin\bash.exe 包装器,按 Git for Windows 的常见安装位置查找;bashPath 可显式指定。
  • PATH 修复:把 Git 的 usr\bin、mingw64\bin、cmd 前置。Windows 的 PATH 通常只有 Git\cmd,不前置时 ls、grep、sed、awk、find、sleep、wc 全部 command not found。
  • 有界输出:保留 maxOutputBytes 窗口,超出部分写入 spill 文件并在结果里给出路径;多字节边界不会被截断成乱码。
  • 环境擦除:复用 @deepseek-ai/dsh-subprocess 的 scrubbedParentEnv,只转发 dshEnv 与 Git 需要的变量。
  • 超时与中断:deadline 到期或调用被中止时按整树终止(taskkill /T /F)。Windows 上子进程被杀后 stdio 管道不保证关闭,因此在 exit 上结算,并用 drainMs 有界排空。
  • 后台任务:run_in_background 走宿主的 ctx.jobs 注册表,可增量读取输出。
  • 命令内部一律显式调用 Git Bash,不用裸 bash:Windows 上它解析到 WSL shim,是另一个 shell。

安装

# 从 npm 安装并注册到 web profile(推荐)
dsh plugin --profile web add dsh-unsandboxed-winbash

# 仅下载 npm package
npm install dsh-unsandboxed-winbash

# 或从 GitHub 安装
dsh plugin --profile web add github:xswt442-cmd/dsh-unsandboxed-winbash

包内声明了 dsh.bundle,bundle 补丁自行挂载工具行,无需手工改 cordis.patch.yml。安装后重启 DSH Web 生效。

配置

- insert:
    - id: tool-winbash
      name: dsh-unsandboxed-winbash/tool
      config:
        bashPath: ''          # 显式指定 Git Bash 路径(默认自动发现)
        gitPathPrefix: true   # 把 Git 的 usr\bin / mingw64\bin / cmd 前置到 PATH
        extraPath: ''         # 额外 PATH 前缀,';' 分隔(排在最前)
        drainMs: 250          # 子进程退出后等待输出排空的上限
        timeoutMs: 120000     # 命令默认超时
        maxTimeoutMs: 600000
        maxOutputBytes: 64000
        maxSpillBytes: 67108864
        enableRunInBackground: true

Git Bash 自动发现顺序:%ProgramFiles%\Git\usr\bin\bash.exe → %ProgramFiles%\Git\bin\bash.exe → %LOCALAPPDATA%\Programs\Git\usr\bin\bash.exe → %ProgramFiles(x86)%\Git\...。找不到且未配置 bashPath 时,只在调用 winbash 时报错,挂载本身不失败。

安全与边界

  • 命令在文件沙箱之外执行:MSYS 无法在 ACL 受限 token 下启动,这是本插件存在的前提。工具描述里写明,且不提供 sandbox_permissions 升级面——没有可升级的起点。
  • 不替换任何服务,只新增一个工具:pwsh、权限预设、/permission 命令与 fs 工具仍受各自的沙箱与审批策略约束。
  • 需要受限、可审计的文件改动请用 fs 工具。
  • 命令内的凭证类环境变量(*KEY*、*TOKEN*、*SECRET*、*PASSWORD*)不传给子进程;dshEnv 与 Git 需要的变量除外。
  • 超时或被中止时按整树终止;后台任务在宿主退出时同步清理进程树。

平台与兼容性

| 项目 | 要求 | | --- | --- | | 平台 | Windows(win32) | | DSH | >=0.1.5-rc.3 | | Node.js | >=20 | | 依赖 | Git for Windows(提供 Git Bash) |

其他平台不需要本插件:dsh-tool-bash 与 dsh-bash-sandbox 在非 win32 上默认启用。

开发与验证

test/e2e/ 会启动真实 Git Bash 并写 spill 文件,必须在非沙箱 shell 中运行;test/unit/ 不启动任何进程,沙箱内亦可,test/unit/layout.test.mjs 守住这个分层。修改后运行:

npm test          # 纯单元,沙箱内亦可
npm run test:e2e  # 需要非沙箱 shell
npm run docs:check
npm pack --dry-run

License

MIT