Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
@deepseek-ai/dsh-e2b
English | 中文
Shared lifecycle owner for one E2B sandbox. The filesystem and subprocess adapters inject ctx.e2b, await its single SDK handle, and therefore inhabit the same remote Linux working tree and process world. The package pins e2b@2.29.1; the family map lists the opt-in composition.
Configuration
- id: e2b
name: '@deepseek-ai/dsh-e2b'
config:
cwd: /home/user/workspace
timeoutMs: 300000
- id: subprocess-e2b
name: '@deepseek-ai/dsh-subprocess-e2b'
- id: fs-e2b
name: '@deepseek-ai/dsh-fs-e2b'
apiKey is optional and otherwise reads E2B_API_KEY; the key configures the host SDK connection and is never installed in the sandbox. cwd defaults to /home/user/workspace and must be an absolute POSIX path. timeoutMs defaults to five minutes and controls the sandbox lifetime; expiry deletes the sandbox.
Lifecycle and ownership
Construction starts one sandbox creation. Before resolving getSandbox(), the service creates cwd and the private cwd/.dsh-e2b adapter-state directory, verifies that the reserved path is a real directory rather than a symlink or another file type, then sets it to mode 0700. Each adapter-internal E2B command shell receives a fresh randomized root-level HOME, so the SDK's fixed login shell does not resolve profile files from the mutable user home before the control command.
Disposal first prevents new handle acquisition, then awaits setup and deletes the sandbox. A SandboxNotFoundError means expiry or another owner already deleted it and is accepted as quiescence. Initial directory setup failure makes one deletion attempt; the configured E2B timeout bounds a second failure. Provider plugins must load after this owner and dispose before it.
Model Experience
None, as this shared runtime owner registers no model-visible context; provider adapters and their consumers own any rendered effects.
KV Cache effect
No direct invalidation; this package does not contribute request tokens.
Known Limitations and Deferred Work
- This is not a whole-harness runtime — Cordis services, agent/session state, session logs, LLM requests, skills, and SDK-side buffers stay in the host process.
- Sandbox state is ephemeral — disposal and timeout delete the sandbox; reconnect, pause/leave retention, templates, volumes, and snapshots are outside this POC.
- No deployment platform is configured — network policy, host-workspace synchronization, and sandbox discovery are outside this POC.
cwdis a resolution convention, not containment — adapters and commands can address other sandbox paths; E2B network access retains the base image's policy.