tancheng33/dsh-code-runtime-container
Container-isolated backend for the ctx.codeRuntime seam: each Code Mode program runs in a fresh container with no network, a read-only rootfs, dropped capabilities, and kernel-enforced memory, CPU and pid ceilings.
Moves Code Mode execution off the agent's own process. A run_code program is model-written code, and the shipped worker-thread backend executes it inside the agent process with the agent's network access, filesystem and environment; this backend instead spawns a fresh container per run with no network, a read-only root filesystem, all capabilities dropped and kernel ceilings on memory, CPU and pids, so a deployment that cannot accept bash-equivalent containment gets a real isolation boundary for code execution. The README contrasts the two substrates side by side and documents the semantics the seam has to preserve.
Install
⚠️ Install command not yet confirmed — check the README on GitHub for the exact command.
Compatibility
README: it implements the DeepSeek Harness code-execution seam (ctx.codeRuntime) with a container substrate. The shipped worker-thread backend runs Code Mode programs in the agent's own process; this backend runs each program in a fresh container with --network=none, a read-only root filesystem, every capability dropped and kernel-enforced memory, CPU and pid ceilings. The README quotes the upstream repository's own statement that only the worker-thread backend ships and that a hard security boundary awaits a container backend, and it publishes a threat model and a limitations section.
Details
- Repo: tancheng33/dsh-code-runtime-container
- Category: Development & Runtime
- Stars: 0
- Version: Source install (no registry version asserted; repo 0★, MIT, last push 2026-08-16)
- Last push: 2026-08-16
- First seen: 2026-08-16
Recent updates
The README documents the motivation, the threat model, the semantics and the limitations rather than a release-by-release table.
FAQ
- Why would I need this?
- The README's argument is that the shipped worker-thread backend runs Code Mode programs inside the agent's own process with the agent's network and filesystem access, and that a deployment which cannot accept that needs a container backend.
- What isolation does it provide?
- Per the README: a fresh container per run, --network=none, a read-only root filesystem, every capability dropped, and kernel-enforced memory, CPU and pid ceilings.
- How do I install it?
- The README's line names the bundle but leaves the --profile value blank, and the npm name returned 404 on 2026-09-17, so confirm the package source and use your own profile name.