Files
deepseek-harness/packages/util/native-command
imccyu 97eb14a007 build(release): make the release set publishable under the private scope
Every package under packages/, apps/, and vendor/ drops "private": true and
declares publishConfig.access "restricted": the repository now states which
packages it publishes instead of deciding it at publish time. Each one also
declares its repository and directory, which is how a consumer of a private
package reaches its source.

The Landlock packages move to restricted with them. They have never been
published, so nothing anonymous depends on them today, and the whole
@deepseek-ai scope stays private.

The workspace constraint that required every package to be private now applies
to non-members only, and asserts the publishable trio on each release member.
2026-08-11 00:09:31 +08:00
..

dsh-native-command

English | 中文

A zero-dependency no-shell execFile runner shared by host-native OS integrations: one runNativeCommand(command, args, signal) call spawns the executable directly (never a shell string), captures utf8 stdout/stderr, propagates the caller's abort into child termination, and hides the transient console window on Windows. Failures reject with the exit code and both captured streams attached, so callers classify (missing tool, cancelled, real failure) without re-running anything.

Its two consumers are the host-side native integrations: the directory-picker-native backend's OS chooser commands and the gateway's open-with-default-application hand-off (dsh-host-apiproxy host.openPath). The NativeCommandRunner type is their injectable command boundary.

It is a library, not a service or plugin: no ctx, registers nothing, holds no state, emits no events.

Surface

import { runNativeCommand, type NativeCommandRunner } from '@deepseek-ai/dsh-native-command'

Model Experience

None, as this is host-side subprocess plumbing; nothing here reaches a model request.

KV Cache effect

None; this package neither assembles nor sends a provider request.

Known Limitations and Deferred Work

  • No output bounding — both streams buffer unbounded in memory; every current caller invokes small native tools whose output is a path or an error line. Adopt dsh-retention bounding before pointing this at commands with meaningful output volume.