Files
deepseek-harness/packages/examples/jsonrpc-demo
imccyu 2c85c484d3 build(release): reference workspace members through the workspace protocol
1504 hand-written ranges pointing at workspace members become workspace:^, so
pnpm pack substitutes each member's real version at publication: sibling
peerDependencies follow the family version instead of being pinned at ^0.0.1,
and a reference to a vendored package follows that package's own line. Without
this, publishing 0.0.2 ships peer ranges naming a version that does not exist,
and 0.0.1-rc.1 does not satisfy ^0.0.1 either.

It also retires ranges that had gone stale against the workspace: ^4.0.0-rc.6
for a 4.0.0-rc.7 checkout, ^3.17.0 for schemastery 3.18.0.

workspace:* stays where an exact published version is the point, which is how
the Landlock entry pins its platform packages.

A workspace constraint now requires the protocol, so a new package cannot
reintroduce a hand-written range. The same constraint caught packages/boot/cmdline
arriving on master without the publishable trio, which this change completes.
2026-08-11 00:17:09 +08:00
..

@deepseek-ai/dsh-jsonrpc-demo

English | 中文

Bin-only app that boots an external cordis.yml; its jsonrpc entry serves SDK clients over newline-delimited stdio. The config composes the spine, backends, and serving plugin. The published dsh-jsonrpc-agent bin resolves bare plugins from the configuration project. The Python SDK's dsh-jsonrpc-agent-pkg single-executable runtime uses lib/packaged-bin.js instead: packaged bare plugins resolve from its closed runtime tree, while relative plugins remain configuration-relative.

Config discovery

The first non-empty channel wins: $DSH_CORDIS_CONFIG, then positional argv[2]. If neither names an existing file, the bin prints one-line usage to stderr and exits 1; there is no working-directory or built-in fallback. dsh-app-boot makes plugin load failures fatal. This protocol does not use DSH_SNAPSHOT.

A config without dsh-jsonrpc is valid and serves nothing; the bin does not designate a server plugin.

Exit lifecycle

stdin EOF and SIGTERM dispose the root to quiescence and exit 0; SIGINT exits 130 after the same disposal. EOF may cut off an in-flight turn as documented in the distribution Agent Note. The jsonrpc plugin owns response-before-exit protocol shutdown; both paths are idempotent and safe to race.

stdout is the protocol

stdout carries only JSON-RPC frames. The bin and boot guards diagnose on stderr, and the config must omit stdout loggers.

Model Experience

Indirectly, through the plugins loaded from the external cordis.yml, which own every model-bound prompt, schema, message, and result; this bin adds none of its own.

KV Cache effect

No direct invalidation; the named consumer owns any request-prefix changes.

Known Limitations and Deferred Work

  • The bin cannot prove that the config serves JSON-RPC — a valid config with no dsh-jsonrpc entry boots successfully and serves nothing.
  • No built-in or default config exists — every launch must provide DSH_CORDIS_CONFIG or a positional path, and deployment owns the complete plugin tree and stdout discipline.
  • stdin EOF cuts off in-flight work — client disappearance disposes the root immediately; callers that need orderly completion use the protocol-level shutdown request.