Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
@deepseek-ai/dsh-client-schema-form
English | 中文
Schema/draft model layer for settings editors. The wire's settings.describe carries each namespace's serialized schemastery schema (schema.toJSON() ref envelope); rehydrateSchema turns it back into a live validator with new Schema(json) — the same schema object that validates a section on the host validates drafts in the browser, so client-side validation never drifts from the Service Definition's. Editors render their own controls (the Models page hand-writes its card around the fields it probes here); this package owns no React and no rendering.
Contract
The unit of editing is a draft user section: a plain object edited immutably (setPath materializes intermediates, deletePath is the per-field reset — dropping the key falls the resolved value back to the composition base and schema defaults). A field's presence in the draft marks it overridden (hasPath) — presence semantics, not value comparison, exactly mirroring the settings seam's layering. nodeAtPath resolves the schema node addressed by a configurable-provider directory settingsPath (object properties by name, dict entries through inner), so an editor can probe which fields a provider's profile carries (and their meta.role) before deciding what to render; an unresolvable path returns undefined so the caller degrades loudly instead of rendering a wrong subtree. validateDraft(schema, draft) runs the rehydrated validator and returns its failure message, letting pages reject an invalid draft before writing.
Model Experience
None, as this package backs browser configuration editors; nothing here reaches a model request.
KV Cache effect
None; this package neither assembles nor sends a provider request.
Known Limitations and Deferred Work
- Rehydration executes the served envelope —
rehydrateSchemareconstructs a live schemastery validator, and schemastery revives serialized callbacks throughnew Function, so the schema envelope is executable content rather than inert data. This is safe only for an envelope from the same trusted host that serves the page; the protocol provides no inert cross-trust representation. - Validation is draft-level, not per-field —
validateDraftreports schemastery's first failure message, including its$.path; it does not map errors onto individual controls. - No generic renderer — consumers build feature-specific forms over these helpers. The Web config-plane Agent Note records that trade-off.