Files
deepseek-harness/packages/bash
imccyu 97eb14a007 build(release): make the release set publishable under the private scope
Every package under packages/, apps/, and vendor/ drops "private": true and
declares publishConfig.access "restricted": the repository now states which
packages it publishes instead of deciding it at publish time. Each one also
declares its repository and directory, which is how a consumer of a private
package reaches its source.

The Landlock packages move to restricted with them. They have never been
published, so nothing anonymous depends on them today, and the whole
@deepseek-ai scope stays private.

The workspace constraint that required every package to be private now applies
to non-members only, and asserts the publishable trio on each release member.
2026-08-11 00:09:31 +08:00
..

bash/ — bash capability family

English | 中文

The capability family spans the canonical executor seam, its implementations, the shared shell environment, and the model-facing tools. All are product packages.

Package Role ctx key
bash/ Defines the executor contract shared by Service providers and Consumers. ctx.bash
bash-local/ Executes commands through the local subprocess service. (registers ctx.bash)
bash-sandbox/ Applies the configured sandbox backend before local execution. (registers ctx.bash)
pwsh-local/ Executes PowerShell commands with Windows-specific process behavior. (registers ctx.bash)
bash-env/ Provides the managed DSH_* environment shared by shell tools. ctx.bashEnv
tool-bash/ Exposes Bash execution and background-task integration to the model. (registers on ctx.tools)
tool-pwsh/ Exposes PowerShell execution to the model. (registers on ctx.tools)

A leaf cordis.yml selects one executor implementation and the model-facing tools it needs. A sandboxed composition also selects a ctx.sandbox provider; the ACP example shows one complete wiring.

The subsystem reference — request/spec vocabulary, results, background processes, the service, and events — is docs/subsystems/bash.md.