Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
@deepseek-ai/dsh-host-directory-picker-native
English | 中文
The native-OS-chooser backend of the directory-picker seam: NativeDirectoryPicker registers ctx.directoryPicker with the native capability, whose pick(signal) opens one native chooser per call and resolves the chosen absolute path (null on cancel). Platform tools run without a shell: osascript on macOS and Zenity with a KDialog fallback on Linux; the caller's abort terminates the native process. Windows opens the modern IFileOpenDialog in a spawned child process — a koffi-driven COM conversation on the child's main thread with the best thread DPI awareness the host accepts (per-monitor-v2 first), aborted by posting WM_CLOSE to the dialog thread. Only viable when the operator sits at the host's display — remote deployments compose -browse instead. The command boundary (DirectoryPickerRunner) and platform facts are injectable. The shared no-shell subprocess runner lives in dsh-native-command.
Dual-face package: the browser half (./client) registers a renderless flow occupant into ui-workspace's two directory-flow holes — each open request drives host.pickDirectory and reports the one outcome (picked path / cancel / failure) through the hole's owner conversation. Both directory-flow declarations must be live before either contribution installs. One cordis.yml row therefore composes both sides of the native interaction; the client carries no capability-kind branching, and mounting a second flow package fails at load (the holes are single kind).
Model Experience
None, as the backend serves the GUI host's directory selection; nothing here reaches a model request.
KV Cache effect
None; this package neither assembles nor sends a provider request.
Known Limitations and Deferred Work
- Linux requires desktop tooling — with neither Zenity nor KDialog installed,
pickrejects with an actionable error; it does not fall back to a typed-path prompt (the browse backend is that fallback at the composition level). - Windows has no mechanism fallback — the child-process picker through packaged koffi is the only native tier, so a COM refusal or dialog crash surfaces the failure. The browse backend remains the fallback at the composition level.