1504 hand-written ranges pointing at workspace members become workspace:^, so pnpm pack substitutes each member's real version at publication: sibling peerDependencies follow the family version instead of being pinned at ^0.0.1, and a reference to a vendored package follows that package's own line. Without this, publishing 0.0.2 ships peer ranges naming a version that does not exist, and 0.0.1-rc.1 does not satisfy ^0.0.1 either. It also retires ranges that had gone stale against the workspace: ^4.0.0-rc.6 for a 4.0.0-rc.7 checkout, ^3.17.0 for schemastery 3.18.0. workspace:* stays where an exact published version is the point, which is how the Landlock entry pins its platform packages. A workspace constraint now requires the protocol, so a new package cannot reintroduce a hand-written range. The same constraint caught packages/boot/cmdline arriving on master without the publishable trio, which this change completes.
api/ — Remote API layers
English | 中文
The application-facing Remote stack. remotes owns BFF policy and the selected business API, while gateway implements the TypeRT unary RPC endpoints shared by Host and Client environments.
| Package | Role | ctx key |
|---|---|---|
remotes/ |
Host Agent/Session lookup policy and Client Remote contribution assembly | no service; configures ctx.typert and consumes ctx.remote |
gateway/ |
Host TypeRT dispatcher and Client Remote endpoint | ctx.typertGateway / ctx.remote |
The runtime dependency direction is remotes → gateway → connection → webserver: the BFF consumes the shared TypeRTClientRemote contract, Gateway delegates transport to Connection, and Connection mounts on the HTTP server. Cordis service injection and Client module metadata preserve this order without importing the concrete Gateway from the Remotes Client entry.
Known Limitations and Deferred Work
- Connection and WebServer remain at
client/connectionandhost/webserver; a later package-only move can place them underapi/connectionandapi/webserverwithout changing their service contracts. - The legacy API Proxy remains at
host/apiproxyas the fallback for methods not yet migrated to Remote. It consumes the Host resolver owned byapi-remotesso migrated and legacy methods retain one Agent/Session identity policy.