Files
deepseek-harness/packages/client
Yichen Jiang e6483f0afc feat(settings): detect stale writers with a revision, and announce raw changes
The remaining P1 from the #939 review, plus the P2 it shares a mechanism with.

Nothing carried a version, so two tabs editing one namespace silently
overwrote each other — reproduced as tab B's `reasoning` lost to tab A's
older draft. The seam's per-namespace write queue orders writes; it cannot
tell a fresh writer from one replaying a snapshot a predecessor superseded.

Each namespace now carries a monotonic `revision` over its RAW section. A
write may send `expectedRevision`, checked at the FRONT of the queue (not at
call time, which would race the very predecessor it guards against); a
mismatch rejects with `SettingsConflictError` → `settings-conflict` on the
wire, carrying both revisions. The editor captures the revision it opened at
and, on conflict, asks the user to reopen rather than replaying its snapshot.

The same counter fixes the missing broadcast. `settings/updated` is gated on
the resolved value — correct for consumers, wrong for configuration surfaces:
storing an override equal to the composition base leaves the resolved value
alone while changing what the document says (the field is now overridden, not
inherited) and moving every open editor's revision. `settings/document-updated
(ns, revision)` fires on any raw-section change, in-process or external, and
`host/settings-changed` now rides it.

That event also closes the stale model picker: editing a provider's `models`
changes no route, so `llm/adapters-updated` never fired and an open picker
kept serving the old catalog. A change to an exposed provider namespace now
emits `host/models-changed` too — that namespace holds the catalog.

Docs: both sides of the five touched README pairs, a type-equiv block for
`SettingsPathOp`, and an Agent Note recording what the plane exposes and who
may overwrite what. The deferred wire-redaction gaps (secrets behind
union/intersection/transform, `.default(...)` in the served envelope, schema
text in rejection messages, `new Function` rehydration, pi-ai's `headers`) are
recorded as TODO(settings-wire-redaction) and in Known Limitations rather than
half-fixed.
2026-07-30 19:24:21 +08:00
..

client/ — web-GUI browser half

English | 中文

The browser side of the dsh web GUI: shell kernel, module system, wire consumer, React-free object services, the slot system, and the ui-* feature-plugin roster. Authoring rules live in AGENTS.md; the host half is host/. All product packages, named @deepseek-ai/dsh-client-<name>.

Package Role ctx key / slot
web/ Shell kernel: AppWebEntry runs the two-stage boot over the host-pushed entry graph (boots the tree)
modules/ Client module system: browser peer of Node's ESM loader as a lazy CJS table under the vendored cordis Loader (module face)
web-react/ Shell-side React glue: createSlotRenderer + SessionProvider render seats (renderer install)
connection/ Wire consumer both ends: browser ctx.connection (shared api client + stream loop) and the node half mounting the /api route with its browser-trust fence ctx.connection
runtime/ Client cordis boot and React-free object services: slots, Sessions, Workspaces, per-session bindings ctx.slots ctx.sessions ctx.workspaces
hmr/ Dev-only hot reload for fetch-arrival client plugins (--dev graphs) (dev entry)
locale/ Browser locale preference (zh/en) plus the ns×locale dictionary registry ctx.locale
ui-slots/ Slot registry pure core: SlotMap merging, single register API, the four-share props family (types + core)
ui-theme/ Theme preference over the --dsw-* token stylesheets (light/dark/system) ctx.theme
ui-primitives/ Pure React atoms: icons, Button/Pill/Menu/Modal/Input, markdown family (component library)
ui-layout/ Shell three-column AppFrame; declares sidebar / conversation / details / conversation.empty ctx.layout
ui-sidebar/ Sidebar shell: Workspace/session rail, search, collapse; declares sidebar.workspaces (slot host)
ui-workspace/ Shared Workspace picker: browser region + hero picker over the same creation flow (fills sidebar.workspaces, conversation.hero.workspace)
ui-conversation/ Conversation domain: skeleton, chat view, input dock, per-tool row slots (slot host)
ui-trajectory/ Trajectory/Waterfall view tabs; the minimal pure-consumer plugin exemplar (fills conversation.view)
ui-command/ Command surface: session-keyed directory cache, / source, three-kind dispatch ctx.command
ui-slash/ Input trigger pipeline: / and @ detection, grouped candidate menu, source roster ctx.slash
ui-skill/ /-trigger skill reference source over the skill.list RPC (registers into ctx.slash)
ui-subagent/ @-trigger subagent reference source over the sessions snapshot (registers into ctx.slash)
ui-model/ Model selection: /model popupSelect + the composer model seat over ModelService ctx.models
ui-question/ Web ask_user_question: host half mounts the tool, browser half fills the composer seat (fills conversation.composer)
ui-settings/ Settings shell: trigger chrome + modal panel; declares the settings.* slots (slot host)
ui-settings-general/ Settings ownerless copy: chrome content + General section skeleton (fills settings.*)
ui-models/ Models settings nav entry (content column lands in a later phase) (fills settings.section)

Feature UI composes only through the slot system (ctx.slots.register) — the slot system standard is the definitive model; the web client architecture note owns the loading chain and object layer.