Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
58 lines
2.1 KiB
YAML
58 lines
2.1 KiB
YAML
# POC overlay: keep the advanced headless agent and model-facing tools, but
|
|
# place its filesystem and process substrate in one short-lived E2B sandbox;
|
|
# the generic Bash, PTY, and LSP consumers compose above them.
|
|
#
|
|
# One-world invariant: e2b.cwd, sandbox-policy.workspaceRoot, and bash-local's
|
|
# default workdir (implicit host process.cwd()) must all name the same remote
|
|
# directory. Only e2b.cwd is created at sandbox open; dropping its !!js line
|
|
# falls back to /home/user/workspace while Bash and PTY keep targeting the
|
|
# host path, so every tool call fails with a remote spawn error.
|
|
- id: base
|
|
name: '@deepseek-ai/cordis-plugin-include'
|
|
config:
|
|
path: ./advanced.cordis.yml
|
|
patches:
|
|
- id: subprocess
|
|
name: '@deepseek-ai/dsh-subprocess-local'
|
|
disabled: true
|
|
- id: fs-local
|
|
name: '@deepseek-ai/dsh-fs-local'
|
|
disabled: true
|
|
- insert:
|
|
- id: e2b
|
|
name: '@deepseek-ai/dsh-e2b'
|
|
config:
|
|
cwd: !!js process.cwd()
|
|
timeoutMs: 300000
|
|
- id: subprocess-e2b
|
|
name: '@deepseek-ai/dsh-subprocess-e2b'
|
|
- id: fs-e2b
|
|
name: '@deepseek-ai/dsh-fs-e2b'
|
|
- id: sandbox-policy
|
|
name: '@deepseek-ai/dsh-sandbox-policy'
|
|
config:
|
|
mode: danger-full-access
|
|
workspaceRoot: !!js process.cwd()
|
|
- id: pty
|
|
name: '@deepseek-ai/dsh-pty'
|
|
- id: pty-local
|
|
name: '@deepseek-ai/dsh-pty-local'
|
|
- id: tool-pty
|
|
name: '@deepseek-ai/dsh-tool-pty'
|
|
- id: lsp
|
|
name: '@deepseek-ai/dsh-lsp'
|
|
- id: lsp-local
|
|
name: '@deepseek-ai/dsh-lsp-local'
|
|
config:
|
|
servers:
|
|
typescript:
|
|
command: npx
|
|
args: [--yes, typescript-language-server@5.0.0, --stdio]
|
|
extensionToLanguage:
|
|
.ts: typescript
|
|
.tsx: typescriptreact
|
|
.js: javascript
|
|
.jsx: javascriptreact
|
|
- id: tool-lsp
|
|
name: '@deepseek-ai/dsh-tool-lsp'
|