Review fix (ds-review-bot critical #2 on #623): the first-turn event stamp had a durability hole no turn anchoring can close — an idle SessionStart- style injection persists a complete one-shot turn before any prompt turn opens, so a crash in that window left a resumable-looking child with no inherited policy, falling back to a possibly wider deployment default. The captured overrides now ride the child's creation meta into its immutable SessionHeader (sandboxMode/approvalPolicy, neutral strings at the session boundary — the delegationDepth precedent), durable from the moment the session exists: no listener ordering can starve the baseline and no crash window can lose it. overrideOf(session) on both policy services resolves fold(events past header.seedLength) ?? header baseline, validating against the closed vocabulary on read; stampOverride and the prompt-submit listener machinery are deleted. The header field rides both persistence backends (JSONL header line; SQLite sessions columns, SCHEMA_VERSION 11 — pre-release, no migration). pty-local reads through overrideOf so PTY spawns see the baseline too. Red-first: header-durability-before-any-turn test (the injection crash window shape), baseline/seed-boundary/closed-vocabulary contract tests in both service suites; the real-wall suite (race, veto, fork stale-seed, grandchild) re-anchored on header assertions and green. The Agent Note's Alternatives now records the superseded event-stamping iteration with the review evidence; bilingual docs updated.
ui/ — human and SDK-client integration surfaces
English | 中文
Human-facing channels and the out-of-process SDK server. These are product packages: real interfaces that a person or SDK client drives.
| Package | Role | ctx key |
|---|---|---|
commands/ |
Human-command registry: shared discovery metadata, scoped shadowing, cancellation, and direct UI dispatch | ctx.commands |
user-approval/ |
One-shot user-approval mechanism, closed outcome vocabulary, audit events, and per-session approval policy | ctx.approval |
permission/ |
User-facing permission presets (workspace-write/danger-full-access): one product-level select bundling the sandbox-mode and approval-policy knobs, written through to their session events |
ctx.permission |
user-interaction/ |
Abstract human question/answer seam used by UI-backed confirmation tools | ctx.userInteraction |
tool-ask-user/ |
Model-facing ask_user_question tool over ctx.userInteraction |
(registers on ctx.tools) |
tui/ |
Interactive pi-tui terminal channel; renders session titles/events and tool intents, answers ctx.userInteraction, and hosts effect-owned plugin overlays |
ctx.tui (drives ctx.agents) |
jsonrpc/ |
Stdio JSON-RPC server for out-of-process SDK clients | (drives ctx.agents) |
app-boot/ |
Shared boot glue for the app bins: .env loading, fail-loud Loader guards, snapshot-aware config resolution, the settle-the-tree boot sequence |
(library for the bins) |
A UI integration is a client-driver plugin, not a loop change: it consumes the existing agent/* event taxonomy and the dsh-agent factory. tui is the interactive terminal front door and supplies the terminal-local ctx.tui extension service; jsonrpc serves out-of-process SDK clients, while non-interactive one-shot tasks use cli-demo. commands is the human-only discovery and dispatch plane consumed by TUI; command input and output do not become model messages.
user-approval, user-interaction, and tool-ask-user live here because asking a human is a UI-backed product affordance, not part of the providerless core spine. user-approval owns the one-shot ctx.approval decision mechanism and its policy tier; answerers remain with the channel or automation transport that owns the agent. user-interaction remains provider-neutral (ctx.userInteraction), while tool-ask-user is its model-facing consumer and interactive app packages provide concrete providers.
The runnable app bundles composed over agent-spine-demo live in examples/ (tui-demo, acp-demo, jsonrpc-demo). acp-demo and jsonrpc-demo own boot bins; the tui-demo bundle is booted by the product dsh CLI. ui/ keeps the reusable human/SDK channel plugins and shared app-boot glue; the automation-only ACP transport lives in acp/. Each front door owns its stdout policy, and a leaf cordis.yml supplies backends and optional tools.