bainianlaoyao/bash-on-windows

On Windows, the available bash tool is limited to Git Bash and PowerShell is disabled.

bash-on-windows is a DeepSeek Harness bundle + agent presets that, on Windows, makes the only available bash tool Git Bash and disables PowerShell. It works on three planes: a host bundle patch that enables tool-bash/bash-sandbox and disables tool-pwsh/pwsh-sandbox; three derived bash-only presets (standard-bash, code-bash, cordis-bash) installed as junctions so the model only sees bash without editing shipped harness files; and a standalone escalation-inert plugin that hides the sandbox escalation vocabulary (sandbox_permissions/justification) from the model's tool catalog and neutralizes same-mode escalation echoes at runtime -- without modifying any official package, so a dsh upgrade cannot lose it.

Development & Runtime ★ 2 updated 2026-08-16
View on GitHub ↗

Install

dsh plugin --profile web add github:bainianlaoyao/bash-on-windows

Two planes: install the host bundle patch with the dsh plugin --profile web add github:bainianlaoyao/bash-on-windows line above (or the npm distribution dsh plugin --profile web add dsh-bash-on-windows, published as 0.1.0 -- registry re-verified 2026-09-30, repository field back-links to github.com/bainianlaoyao/bash-on-windows, MIT), then install the three bash-only session presets with powershell -ExecutionPolicy Bypass -File scripts/install.ps1. Restart dsh and pick the standard-bash / code-bash / cordis-bash preset. Prerequisite: Git for Windows installed (bash on PATH).

Compatibility

Windows only (the README scopes it to win32; non-Windows is untouched). Requires Git for Windows (bash on PATH). On win32 the default sandbox is danger-full-access with approval never, which the README states is a hard requirement of Git Bash's cygwin runtime (a DSH_PERMISSION_MODE escape hatch is provided).

Details

Recent updates

The README documents that the three derived presets come from DeepSeek Harness agent presets (each preset directory carries a LICENSE.deepseek-harness), the re-generation script scripts/build-presets.mjs to run after a dsh upgrade, the scripts/check-rows.mjs contract test for the bash-only invariants and the escalation-inert strip/sanitize/family-gate logic, and the uninstall path via install.ps1 -Uninstall.

FAQ

How do I install bash-on-windows?
Per the README: dsh plugin --profile web add github:bainianlaoyao/bash-on-windows (or the npm form dsh-bash-on-windows), then powershell -ExecutionPolicy Bypass -File scripts/install.ps1 for the presets, then restart dsh and pick a bash-only preset. Git for Windows is required.
Does it modify the official harness?
No. The README states the escalation-inert plugin delivers the old harness-core patch behaviour as an installable plugin, so no official package is modified and a dsh upgrade cannot lose it; the presets are derived files installed as junctions rather than edits to shipped files.
What is the security implication?
The README's SECURITY note states that on win32 the default sandbox is danger-full-access with approval never, a hard requirement of Git Bash's cygwin runtime -- review SECURITY.md before deploying.

Alternatives

MAXeaglet/dsh-bash-terminal · dongsheng123132/dsh-terminal · mervyn-teo/dsh-plugin-terminal

More plugins in Development & Runtime

Browse more in Development & Runtime

Guides for Development & Runtime plugins