seek://map/dsha
DSHA
#android #mobile #launcher
TL;DR
A no-root, no-Termux Android launcher: the APK bundles an offline Ubuntu 24.04 arm64 rootfs with the proroot runtime, so apt, PTYs and native-module builds all work on the phone — plus wireless-ADB device control, Keystore-encrypted data retention and a self-check/self-heal system.
DSHA fills the map's mobile gap with the container route to on-device DSH: a single APK carrying an offline Ubuntu 24.04 rootfs and the proroot runtime, so the harness and its plugins run unmodified on a phone — no root, no Termux, no terminal skills required. The README is unusually candid: it documents the sandbox limits it cannot fix, keeps a security-model page, marks its performance numbers as on-device measurements, and states a large refactor is in progress with slower updates meanwhile.
Facts
- platforms
- Android 8.0+ · arm64-v8a
- license
- MIT
- note
- README 自述大规模重构进行中、更新放缓;bash 沙箱隔离在安卓上不可用(容器与 Termux 路线相同),权限默认 danger-full-access,可在配置页改档。
Key points
- The APK bundles an offline Ubuntu 24.04 arm64 rootfs: apt, interactive PTYs and native-module builds work out of the box, so upstream plugins run unmodified — no root, no Termux, no command line
- The default runtime is proroot — in-process path translation via LD_PRELOAD plus binary patching, no ptrace overhead; per its README, on-device benchmarks total +58% on key items (+82% for stat-heavy work) — self-reported numbers
- The agent can operate the phone: built-in wireless ADB pairing without Shizuku, an app bridge for notifications and confirmations, a guard for dangerous commands, and a streaming on-screen overlay
- Data survives uninstall: sessions and settings live in Documents/dshdata, API keys are encrypted in the Android Keystore, and backups rotate with a pre-restore health check
- Per its README, the project ships self-checks with auto-repair, self-heal scripts, plain-language plugin-failure diagnosis, and offline-verified incremental script updates
FAQ
How is this different from Termux-based routes?
Per the README's comparison table, DSHA takes the container route — proot/proroot over a full glibc rootfs, working right after the APK install; the Termux route runs bare on bionic and is theoretically faster but needs per-package adaptation. Sandboxing is equally limited on both routes.
Does the bash sandbox work?
No. Per the README, bubblewrap needs unprivileged user namespaces that Android sepolicy does not grant — neither the container nor the Termux route can get around it; confinement relies on dsh permission tiers, defaulting to danger-full-access and switchable to workspace-write or read-only.
Which devices are supported?
Per its README, arm64-v8a on Android 8.0+ only; the APK is roughly 370 MB — the price of the bundled Ubuntu environment. Zhuoyitong (卓易通) and HarmonyOS anco compatibility is unverified.
Official references
- docsGitHub README ↗
- docsSecurity model ↗