概览
dsh-multi-workspace
README / ZH
插件文档
目录摘要
dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。
在 GitHub 阅读完整 READMELIMITATIONS
已知限制
- **Shell commands stay confined to the session workspace.** The multi-workspace widening applies to the fs tools only (layer 2 re-issues each denied write with the target workspace's root). The command sandbox seam (`@deepseek-ai/dsh-sandbox-local`, windows-acl / bwrap / seatbelt) reads only the single `policy.workspaceRoot`, so `pwsh` / bash writes outside the session workspace are still denied. - **The fs fallback silently retries under `workspace-write`** without going through the approval flow. That is the plugin's intended "write immediately" behavior — make sure the registered workspaces are trusted. - The wrapped `resolve()` must return a **plain object** (own `mode` / `workspaceRoot` / `sessionId`): executors spread the policy (`{ ...policy }`), and a prototype-based copy silently drops those keys, making the windows-acl runner fail with `--workspace undefined` (`SANDBOX_UNAVAILABLE`). `test/smoke.mjs` guards this regression.
