docs(bundle): complete the Windows pwsh default contract per review

- apps/cli/reference/README: state the win32 permission/sandbox/approval
  degradation so the workspace-write promise no longer misleads Windows users
- bundle README + agent note: give the complete bash-restore recipe (disable
  pwsh-local/tool-pwsh and re-enable bash-sandbox/tool-bash), since both
  executors register the same bash service and an incomplete recipe fails
  loud at load
- windows.cordis.patch.yml: header comment notes the recipe and that the
  ui-permission row belongs to dsh-web-app (base-only profiles get a
  harmless no-match warning)
- profile-boot.ts: rewrap composeProfile JSDoc
- re-record i18n hashes for the touched bilingual pairs
This commit is contained in:
Huanqi Cao
2026-08-07 19:21:49 +08:00
parent 94f61d29fa
commit 1ee773317c
11 changed files with 25 additions and 17 deletions
@@ -13,6 +13,14 @@
# dsh.bundle.patch — that field names the one universal layer). A Windows
# host that prefers bash or confinement overrides these rows through its
# profile or home cordis.patch.yml.
# The bash-restore recipe must be complete: disable pwsh-local and tool-pwsh
# AND re-enable bash-sandbox and tool-bash (plus permission/ui-permission only
# if the switcher is wanted) — both executors register the same 'bash'
# service, so re-enabling the bash rows while pwsh-local stays inserted fails
# loud at load on a duplicate registration.
# The ui-permission disable targets a row owned by dsh-web-app, not dsh-base:
# a base-only profile (e.g. the `dsh plugin --profile` default template) has
# no such row, and the no-match logs a harmless warning on every load.
- id: bash-sandbox
disabled: true