Files
deepseek-harness/packages/util/atomic-write
imccyu 2c85c484d3 build(release): reference workspace members through the workspace protocol
1504 hand-written ranges pointing at workspace members become workspace:^, so
pnpm pack substitutes each member's real version at publication: sibling
peerDependencies follow the family version instead of being pinned at ^0.0.1,
and a reference to a vendored package follows that package's own line. Without
this, publishing 0.0.2 ships peer ranges naming a version that does not exist,
and 0.0.1-rc.1 does not satisfy ^0.0.1 either.

It also retires ranges that had gone stale against the workspace: ^4.0.0-rc.6
for a 4.0.0-rc.7 checkout, ^3.17.0 for schemastery 3.18.0.

workspace:* stays where an exact published version is the point, which is how
the Landlock entry pins its platform packages.

A workspace constraint now requires the protocol, so a new package cannot
reintroduce a hand-written range. The same constraint caught packages/boot/cmdline
arriving on master without the publishable trio, which this change completes.
2026-08-11 00:17:09 +08:00
..

dsh-atomic-write

English | 中文

Zero-dependency atomic file replacement shared by file-backed stores that must never leave partial, symlink-hijacked, or wider-than-intended content on disk — the user-settings document (dsh-settings-local) and the credentials store (dsh-credentials-local).

Surface

import { withFileLock, writeFileAtomic } from '@deepseek-ai/dsh-atomic-write'

declare const text: string
declare const render: (previous: string) => string

await writeFileAtomic('/home/u/.dsh/settings.yaml', text, { mode: 0o600 })

// Read-modify-write against the same file from several processes.
await withFileLock('/home/u/.dsh/settings.yaml', async () => {
  await writeFileAtomic('/home/u/.dsh/settings.yaml', render(text), { mode: 0o600 })
})

writeFileAtomic commits one already-rendered string. The contract, in the order failures would exploit it:

  • Exclusive-create temp (wx, random suffix): the open refuses to follow a symlink planted at a guessable temp path.
  • The fresh inode carries mode through the rename: replacing a wider-permission file narrows it without a chmod race. mode is required so the permission decision stays visible at every call site (subject to the process umask, like every fresh inode).
  • rename replaces a symlinked target itself, never writing through to its referent.
  • Same-directory sibling keeps the rename on one filesystem, so the swap stays atomic.
  • Parent directories are created; on any failure the temp is removed and the failure rethrown; readers observe either the old or the new complete content.

withFileLock serializes the writers of one file across processes, for the read-render-commit cycles a bare atomic commit cannot make safe on its own. The lock is a wx-created <filename>.lock sibling, so readers never contend; waiters back off exponentially and fail with a timeout rather than block forever. A contender never removes the existing lock: age cannot distinguish a crashed owner from a paused live writer.

Model Experience

None, as this is a pure filesystem primitive; nothing here reaches a model request.

KV Cache effect

None; nothing here enters a request prefix.

Known Limitations and Deferred Work

  • Atomic, not durable — no fsync of the file or its directory, so after a crash the rename may be observed unwound. The file-backed stores here re-read and republish on boot, keeping durability the caller's policy.
  • String content only — no Buffer or stream form until a consumer needs one.
  • Orphaned locks require operator recovery — a process that exits while holding the lock can leave the sibling behind. Later writers time out without deleting it; an operator removes it only after verifying that no writer still owns it. File age alone is not safe evidence of abandonment.