Files
deepseek-harness/packages
imccyu d9dcf5a484 fix(release): close the review findings on the release sequences
The root manifest carries the dsh family version. bump writes it with the
members, because the workspace constraint requires them to match, and that
constraint now accepts a prerelease segment: without both, release:dsh 0.0.2
left the root behind and 0.0.1-rc.1 could satisfy neither check.

The Landlock workflow no longer passes --access public, which overrode the
restricted publishConfig this repository just adopted for those packages.

Vendored change detection reads build inputs when a package publishes build
output, and vendor/cordis publishes the src its export map already pointed at:
its lib/ is untracked, so a real source edit read as 'nothing changed' and the
next publish would fail on a version whose bytes moved. The next version also
takes the last published version as its baseline, so a re-sync that restores a
lower upstream version cannot recompute a version already on the registry, and
bump confirms the registry carries what the newest tag names.

Tag prefixes are constructed rather than recovered from a full tag, which a
hyphenated version defeated. Pack runs group per ref so concurrent pull requests
stop displacing each other, the publish job carries the global group, and the
unused id-token permission is gone.

Every release script sits behind an entry guard, which is what lets the pure
judgements carry tests: tag naming, publish order and cycle reporting, version
arithmetic, payload policy, and the change judgement.

The Agent Note moves to implemented and states what shipped: one probe command,
the registry confirmation that now exists, and byte reproducibility recorded as
assumed rather than measured.
2026-08-11 01:26:36 +08:00
..
2026-08-10 16:34:20 +08:00

Packages

English | 中文

npm scope: @deepseek-ai/dsh-*; Cordis Service subclasses and function plugins contribute through ctx.effect(), ctx.on(), or ctx.waterfall(). Rules: package, root.

Hierarchy

Groups hold packages/<group>/<pkg>/; names stay @deepseek-ai/dsh-<pkg>. Group READMEs own package/ctx-key maps.

Group Role Release expectation
core/ Product API spine: sessions, prompts, tools, agent services, and the concrete loop Product — stable surface
api/ Remote BFF assembly and TypeRT RPC gateway Product — stable surface
typert/ Type graph generation, artifact loading, and runtime registry Product — stable surface
goal/ Same-session goal persistence and lifecycle Product — stable surface
feedback/ Human feedback Product — stable surface
llm/ LLM capability family: the abstract service + provider adapters Product — stable surface
e2b/ E2B providers POC
subprocess/ Subprocess capability family: Service Definition + local process-tree provider Product — stable surface
bash/ Bash capability family: executor seam, local impl, model-facing tool Product — stable surface
pty/ Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools Product — stable surface
code-runtime/ Code-execution capability family: Service Definition + worker-thread provider + Code Mode Consumer Product — stable surface
sandbox/ Process-confinement seam; bwrap/Landlock/Seatbelt backends Product — stable surface
fs/ Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools Product — stable surface
lsp/ LSP capability family: seam, generic stdio provider, and the lsp tool Product — stable surface
skill/ Skill capability family: the provider registry, local provider, and model-facing catalog/loader Product — stable surface
compact/ Compaction capability family: Service Definition + basic provider + command Consumer Product — stable surface
context/ Model-visible request context, including workspace instructions and time context Product — stable surface
subagent/ Subagent capability family: the provider-registry contract and the model-facing delegation tool Product — stable surface
tasks/ Generic background-task runtime and model-facing task_* control tools Product — stable surface
workflow/ Workflow seam, worker-thread engine, and model-facing workflow/ralph tools Product — stable surface
web/ Web capability family: seam, search/fetch provider impls, and the model-facing web tools Product — stable surface
attachment/ Durable attachment identity, validation, local content-addressed storage Product — stable surface
spill/ Spill capability family: storage seam, local impl, tool-result spill policy Product — stable surface
todo/ The model-facing todo_write tool Product — stable surface
plan/ Plan collaboration state with a direct entry command and reviewed exit Product — stable surface
preset/ Per-session agent composition from preset cordis.yml files Product — stable surface
guard/ Loop-hygiene guards: advisory repeat-call reminders + the tools/execute deadline enforcer Product — stable surface
bundle/ Installable dsh --profile patch layers Product — stable surface
self-modification/ Agent runtime self-modification: live plugin/service inspection and model-written plugin mount/unmount (design) Product — stable surface
hooks/ Hook bridges + the shared Claude Code / Codex wire-protocol library Product — stable surface
session/ Durable session data plane: persistence seam + JSONL/SQLite backends, projection seam, log-backed titles, session reporting Product — stable surface
session-query/ Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search Product — stable surface
settings/ User-settings seam + file-backed provider Product — stable surface
credentials/ Credential-reference seam + env-over-.env provider Product — stable surface
storage/ Non-session storage hub + backends + domain form Product — stable surface
workspace/ Workspace entity Product — stable surface
scaffold/ Create/launch/drive project tooling: helper, launcher, initializer, wire protocol with both ends, launcher telemetry Product — stable surface
acp/ Automation-only Agent Client Protocol server Product — stable surface
interaction/ Human-collaboration plane: approval/interaction seams, permission preset, commands, ask-user tool Product — stable surface
boot/ Shared app-bin boot glue Product — stable surface
host/ Web-GUI host half: API gateway + HTTP route server Product — stable surface
client/ Web-GUI browser half: shell, wire, object services, slots, ui-* plugins Product — stable surface
experimental/ Prototypes and internal plugins Unreleased
examples/ Demo bundles (agent-spine + CLI/ACP/JSON-RPC bins) leaves load Support — example infra
support/ Support infrastructure (testkits, invariants, replay, Loader smokes) Support — lower compatibility expectations
util/ Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) Support — small, stable, harness-dep-free

New packages join existing groups; new groups update their README and this table.

Dependencies

The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).

Extension plugins depend on Service Definitions, never concrete providers. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities separate Service Definition / Service provider / Consumer roles when they evolve independently; see capability seams.

Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.