The three release sequences shipped with publishConfig.access: restricted, so nothing in the @deepseek-ai scope was installable from outside the organization. A restricted dependency is what actually blocks a public consumer: every harness package declares the vendored framework as a peerDependency, and dsh-sandbox-local declares the Landlock entry as a dependency. Those two sequences therefore go public first — the nine vendor/* packages and the three native/landlock-run packages — while the dsh family stays restricted until its own sequence is opened deliberately. No public package requires a restricted one in this arrangement. Access is now per sequence, so no publish path can pass --access: one flag cannot express two levels and would override the manifest that owns the fact. publish.ts stops passing it, matching the native workflow, and check-workspace-constraints holds each manifest to its own sequence's level, which is what stops the scope from drifting one package at a time. Harness consumers reference the Landlock entry as workspace:^ instead of workspace:*, so a published harness package accepts the entry's patch and minor releases. The entry keeps workspace:* for its platform packages, where the binary must match the entry version exactly. Two rationales that named a private registry no longer describe the vendored sequence; they now state the durable reason, which is that the verification must not depend on the registry already carrying matching versions.
shell/ — bash capability family
English | 中文
The capability family spans the canonical executor seam, its implementations, the shared shell environment, and the model-facing tools. All are product packages.
| Package | Role | ctx key |
|---|---|---|
shell/ |
Defines the executor contract shared by Service Providers and Consumers. | ctx.shell |
bash-local/ |
Executes commands through the local subprocess service. |
(registers ctx.shell) |
bash-sandbox/ |
Applies the configured sandbox backend before local execution. |
(registers ctx.shell) |
pwsh-local/ |
Executes PowerShell commands with Windows-specific process behavior. | (registers ctx.shell) |
shell-env/ |
Provides the managed DSH_* environment shared by shell tools. |
ctx.shellEnv |
tool-bash/ |
Exposes Bash execution and background-job integration to the model. | (registers on ctx.tools) |
tool-pwsh/ |
Exposes PowerShell execution to the model. | (registers on ctx.tools) |
A leaf cordis.yml selects one executor implementation and the model-facing tools it needs. A sandboxed composition also selects a ctx.sandbox provider; the ACP example shows one complete wiring.
The subsystem reference — request/spec vocabulary, results, background processes, the service, and events — is docs/subsystems/shell.md.