Overview
dsh-multi-workspace
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
- **Shell commands stay confined to the session workspace.** The multi-workspace widening applies to the fs tools only (layer 2 re-issues each denied write with the target workspace's root). The command sandbox seam (`@deepseek-ai/dsh-sandbox-local`, windows-acl / bwrap / seatbelt) reads only the single `policy.workspaceRoot`, so `pwsh` / bash writes outside the session workspace are still denied. - **The fs fallback silently retries under `workspace-write`** without going through the approval flow. That is the plugin's intended "write immediately" behavior — make sure the registered workspaces are trusted. - The wrapped `resolve()` must return a **plain object** (own `mode` / `workspaceRoot` / `sessionId`): executors spread the policy (`{ ...policy }`), and a prototype-based copy silently drops those keys, making the windows-acl runner fail with `--workspace undefined` (`SANDBOX_UNAVAILABLE`). `test/smoke.mjs` guards this regression.
