Files
deepseek-harness/packages/storage/domain
imccyu 507dd25a3a fix(storage,workspace): review-bot findings — emit isolation, domain ownership, null globals
- domain/changed emission is isolated from the write path: an observer
  throwing synchronously can no longer turn a committed (durable +
  in-memory) write into a rejection; the failure is logged and later
  writes proceed.
- Domain lifecycle belongs to the opening consumer: Domain gains an
  idempotent close() (drain, unit close, reservation release), the
  facility stops registering effects on its own context and instead
  closes any still-open domains on unmount; WorkspaceRegistry holds its
  domain through its own effect, so disposing and re-mounting the
  consumer no longer wedges on already-open.
- defineDomain rejects a global schema accepting null at declaration
  time: JSON null is the medium's absence sentinel, so a nullable global
  could never round-trip; failing loud at the spec keeps set(null)
  unrepresentable.

Regression tests cover all three (hostile listener, close/reopen and
consumer re-mount, nullable-global rejection).
2026-07-25 11:08:04 +08:00
..

@deepseek-ai/dsh-domain

Domain data form for the DeepSeek Harness storage hub: mounts ctx.storage.domain, opening schema-validated KV domains over configured storage backends. A domain is declared once with defineDomain (zod record schemas, z.infer-derived types), opened through DomainFacility.open, and served from authoritative in-memory state — reads are synchronous, writes serialize on one per-domain chain, reach durability on the routed backend first, then update memory and emit domain/changed. The opening consumer owns the handle's lifecycle and releases it with Domain.close() (idempotent; typically its own ctx.effect disposer); domains still open when the plugin unmounts are closed by the facility.

Design rationale, open semantics, and the storage/domain layer split live in the Agent Note.

Configuration

key meaning
backend Default backend name for every domain (required; no universally correct medium exists).
routes Per-domain overrides: domain name → backend name.

Model Experience

Durable domain state

What the model sees

Nothing. The package registers no tools, injects no prompts, and appends no session events; it stores non-session data (workspace records, future session sidecars) behind ctx.storage.domain and emits only the in-process domain/changed event, which reaches a model only if a consumer package renders it through its own documented surface.

Token effect

Zero. No text from this package enters any model request.

KV Cache effect

Independent: domain reads and writes never touch request prefixes, so nothing here can invalidate provider cache reuse.

Known Limitations and Deferred Work

  • Single-process change visibilitydomain/changed is an in-process event; a second host process or a reconnecting GUI observes no changes until the cross-process revision pattern deferred in the Agent Note lands.
  • No cross-table transactions, secondary indexes, or multi-segment keys — each write touches one record; triggers and rework points for these extensions are tabled in the Agent Note's deferred-work list.