The browser e2e lane had been failing wholesale since this stack moved the agent plane into presets, and nothing caught it: 34 of 48 files. Two of the causes are product defects, not test breakage. `bashEnv` goes back to the host plane. `apps/cli/src/web.ts` injects it to publish `DSH_WEB_URL`/`DSH_WEB_MODE`, so the earlier note that "nothing outside the agent plane injects bashEnv" was simply wrong — behind a preset's `shell` realm those variables reached no shell at all, and a `dsh web` agent could not find the address of its own interface. This is the same criterion that returned `subagents`: a host row that injects a service resolves before any session exists and has no agent to key by, so the service is host-plane. `tool-bash` consumes the host registry from inside the preset, which works because an agent context chains to the host; only the reverse is invisible. `tool-subagent-report` goes back with it. It is not a tool this agent calls: it registers a continuable SETUP on the host `subagents` singleton, and that list is not scope-aware. One copy per mounted preset meant every child was handed `report` once per live session, so the second registration threw and a cold subagent resume failed with `subagent-not-resumable` — a diagnostic three layers removed from the cause. The lane's own composition facts follow. Skill roots resolve inside a preset now, a subtree include patches cannot reach, so the scaffold pins the roots' documented environment fallback for its whole lifetime rather than for the boot — presets mount per session. Without it the developer's real `~/.dsh/skills` enters replay requests and goldens while CI sees none. The `apps/cli` composition test pins `storage-json` for the same reason: unpinned it wrote, and then read back, the developer's own `~/.dsh/storages/`. Three tests now address through an agent what they used to read off the root context, because that is where the thing lives: the tool catalog, the skill registry, and the token meter. The seeded-history projection baseline asserts the opposite of what it did — a detached session yields a preset-plane projection only from a durable checkpoint written while it was live, and this seed was written straight to persistence and never ran. Goldens re-recorded for the hero's preset chip and the settings nav entry.
Packages
English | 中文
Packages use the @deepseek-ai/dsh-* scope. Each is a Cordis Service subclass or function plugin; contributions use ctx.effect(), ctx.on(), or ctx.waterfall(). Authoring rules: package and root.
Hierarchy
Packages live at packages/<group>/<pkg>/; groups are containers, while names remain @deepseek-ai/dsh-<pkg>. Each group README is the canonical package/ctx-key map.
| Group | Role | Release expectation |
|---|---|---|
core/ |
Product API spine: sessions, prompts, tools, agent services, and the concrete loop | Product — stable surface |
typert/ |
Type graph generation, artifact loading, and runtime registry | Product — stable surface |
goal/ |
Persisted same-session goal state and lifecycle | Product — stable surface |
llm/ |
LLM capability family: the abstract service + provider adapters | Product — stable surface |
subprocess/ |
Subprocess capability family: spawn seam + local process-tree implementation | Product — stable surface |
bash/ |
Bash capability family: executor seam, local impl, model-facing tool | Product — stable surface |
pty/ |
Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools | Product — stable surface |
code-runtime/ |
Code-execution capability family: the runtime seam for model-written programs + a worker-thread backend | Product — stable surface |
sandbox/ |
Process-confinement seam; bwrap/Landlock/Seatbelt backends | Product — stable surface |
fs/ |
Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools | Product — stable surface |
lsp/ |
LSP capability family: seam, generic stdio provider, and the lsp tool |
Product — stable surface |
skill/ |
Skill capability family: the provider registry, local provider, and model-facing catalog/loader | Product — stable surface |
compact/ |
Compaction capability family: the abstract seam + a basic backend (tool deferred) | Product — stable surface |
context/ |
Model-visible request context, including workspace instructions and time context | Product — stable surface |
subagent/ |
Subagent capability family: the provider-registry seam and the model-facing delegation tool | Product — stable surface |
tasks/ |
Generic background-task runtime and model-facing task_* control tools |
Product — stable surface |
workflow/ |
Workflow capability family: the script-engine seam, worker-thread engine, and model-facing workflow and fresh-agent ralph tools |
Product — stable surface |
web/ |
Web capability family: seam, search/fetch provider impls, and the model-facing web tools | Product — stable surface |
spill/ |
Spill capability family: storage seam, local impl, tool-result spill policy | Product — stable surface |
todo/ |
The model-facing todo_write tool |
Product — stable surface |
plan/ |
Plan collaboration state with a direct entry command and reviewed exit | Product — stable surface |
preset/ |
Per-session agent composition from preset cordis.yml files |
Product — stable surface |
timeout/ |
Tool-call tools/execute deadline enforcement |
Product — stable surface |
guard/ |
Loop-hygiene advisory repeat-call reminders | Product — stable surface |
bundle/ |
Installable dsh --profile patch layers |
Product — stable surface |
cordis/ |
Cordis runtime integration: self-inspection, temporary Plugins, restricted repository Plugin loading | Product — stable surface |
hooks/ |
Hook bridges + the shared Claude Code / Codex wire-protocol library | Product — stable surface |
session-persistence/ |
Persistence seam + JSONL/SQLite backends | Product — stable surface |
session-projection/ |
Projection seam: domain fold units serve whole values | Product — stable surface |
session-query/ |
Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search | Product — stable surface |
session-title/ |
Log-backed session titles: fallback service and opt-in LLM providers | Product — stable surface |
settings/ |
User-settings seam + file-backed provider | Product — stable surface |
credentials/ |
Credential-reference seam + env-over-.env provider |
Product — stable surface |
telemetry/ |
Session reporting: capture/redact seam, OTel backend | Product — stable surface |
storage/ |
Non-session storage hub + backends + domain form | Product — stable surface |
workspace/ |
Workspace entity | Product — stable surface |
sdk/ |
Project SDK tooling | Product — stable surface |
acp/ |
Automation-only Agent Client Protocol server | Product — stable surface |
ui/ |
JSON-RPC integration, approval/interaction seams, ask-user tool | Product — stable surface |
host/ |
Web-GUI host half: API gateway + HTTP route server | Product — stable surface |
client/ |
Web-GUI browser half: shell, wire, object services, slots, ui-* plugins |
Product — stable surface |
experimental/ |
Prototypes and internal plugins | Unreleased |
examples/ |
Demo bundles (agent-spine + CLI/ACP/JSON-RPC bins) leaves load | Support — example infra |
support/ |
Support infrastructure (testkits, invariants, replay, Loader smokes) | Support — lower compatibility expectations |
util/ |
Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) |
Support — small, stable, harness-dep-free |
New packages join existing groups; new groups update their README and this table.
Dependencies
The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).
Extension plugins depend on interfaces, never the concrete loop. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities split into interface / implementation / consumer packages; see capability seams.
Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.