2026-06-16 21:00:24 +08:00
<!-- Generated by scripts/gen - module - graph.ts — do not edit by hand.
Run `pnpm run gen-module-graph` to regenerate. -->
# Module dependency graph
2026-07-05 01:25:58 +08:00
Inter-package dependencies among the `@deepseek-ai/dsh-*` harness packages, derived from each package's `peerDependencies` (the canonical runtime-dependency signal) and grouped by the `packages/<group>/<pkg>` hierarchy. An edge `a --> b` means package `a` depends on package `b` . Names have the `@deepseek-ai/dsh-` prefix stripped.
2026-06-16 21:00:24 +08:00
```mermaid
2026-07-05 01:25:58 +08:00
flowchart TD
subgraph group_util["packages/util"]
pkg_brand["brand"]
2026-07-12 16:30:01 +08:00
pkg_home["home"]
2026-07-05 16:49:39 +08:00
pkg_paths["paths"]
2026-07-07 09:31:53 +08:00
pkg_retention["retention"]
2026-07-06 16:23:52 +08:00
pkg_timeout["timeout"]
2026-07-05 01:25:58 +08:00
end
subgraph group_llm["packages/llm"]
pkg_llm["llm"]
pkg_llm_deepseek["llm-deepseek"]
pkg_llm_pi_ai["llm-pi-ai"]
2026-07-15 14:47:29 +08:00
pkg_token_meter["token-meter"]
2026-07-05 01:25:58 +08:00
end
subgraph group_core["packages/core"]
pkg_agent["agent"]
pkg_agent_loop["agent-loop"]
2026-07-08 23:54:03 +08:00
pkg_scope["scope"]
2026-07-05 01:25:58 +08:00
pkg_session["session"]
pkg_system_prompt["system-prompt"]
pkg_tools["tools"]
end
subgraph group_bash["packages/bash"]
pkg_bash["bash"]
pkg_bash_local["bash-local"]
2026-07-09 16:05:44 +08:00
pkg_bash_sandbox["bash-sandbox"]
2026-07-05 01:25:58 +08:00
pkg_tool_bash["tool-bash"]
end
subgraph group_fs["packages/fs"]
pkg_fs["fs"]
pkg_fs_local["fs-local"]
pkg_fs_policy["fs-policy"]
pkg_tool_fs["tool-fs"]
2026-07-09 20:44:32 +08:00
pkg_tool_fs_search["tool-fs-search"]
2026-07-05 01:25:58 +08:00
end
2026-07-10 14:19:06 +08:00
subgraph group_skill["packages/skill"]
pkg_skill["skill"]
pkg_skill_local["skill-local"]
pkg_tool_skill["tool-skill"]
end
2026-07-05 01:25:58 +08:00
subgraph group_compact["packages/compact"]
pkg_compact["compact"]
pkg_compact_basic["compact-basic"]
end
subgraph group_subagent["packages/subagent"]
pkg_subagent["subagent"]
pkg_subagent_acp["subagent-acp"]
pkg_subagent_fork["subagent-fork"]
pkg_subagent_inprocess["subagent-inprocess"]
pkg_subagent_spawn["subagent-spawn"]
rename: @deepseek-ai/dsh-subagent-process -> @deepseek-ai/dsh-subagent-subprocess
The extracted library's name sat one edit away from @deepseek-ai/dsh-subagent-inprocess
(process/inprocess), inviting a typo'd import to silently resolve to the wrong
package. subagent-subprocess also reads as the deliberate counterpart to
subagent-inprocess (in-process vs. subprocess), matching how the two shared
drivers actually differ.
Package directory, npm name, module doc, JSDoc module tags, test-file name and
its temp-dir prefixes, the subagent-acp import and its Config/tsconfig/package.json
references, root tsconfig.json/tsconfig.build.json/knip.json entries, and the
packages/subagent group README all renamed together; regenerated
docs/module-graph.md and docs/config-catalog.md. Pure rename — no behavior,
export, or Config shape changed.
2026-07-09 13:42:03 +08:00
pkg_subagent_subprocess["subagent-subprocess"]
2026-07-05 01:25:58 +08:00
pkg_tool_subagent["tool-subagent"]
end
subgraph group_web["packages/web"]
pkg_tool_web["tool-web"]
pkg_web["web"]
pkg_web_fetch_local["web-fetch-local"]
pkg_web_search_deepseek["web-search-deepseek"]
pkg_web_search_exa["web-search-exa"]
pkg_web_search_perplexity["web-search-perplexity"]
end
2026-07-08 19:20:50 +08:00
subgraph group_spill["packages/spill"]
pkg_spill["spill"]
pkg_spill_local["spill-local"]
pkg_spill_policy["spill-policy"]
end
2026-07-08 10:06:07 +08:00
subgraph group_timeout["packages/timeout"]
pkg_timeout_policy["timeout-policy"]
end
2026-07-05 01:25:58 +08:00
subgraph group_todo["packages/todo"]
pkg_tool_todo["tool-todo"]
end
2026-07-08 11:50:12 +08:00
subgraph group_cordis["packages/cordis"]
pkg_tool_cordis["tool-cordis"]
end
2026-07-05 01:25:58 +08:00
subgraph group_hooks["packages/hooks"]
pkg_hook_protocol["hook-protocol"]
pkg_hooks_claude["hooks-claude"]
pkg_hooks_codex["hooks-codex"]
end
subgraph group_session_persistence["packages/session-persistence"]
pkg_session_persistence["session-persistence"]
pkg_session_persistence_jsonl["session-persistence-jsonl"]
pkg_session_persistence_sqlite["session-persistence-sqlite"]
end
2026-07-10 16:51:19 +08:00
subgraph group_session_query["packages/session-query"]
pkg_session_query["session-query"]
end
2026-07-05 01:25:58 +08:00
subgraph group_support["packages/support"]
feat(acp-snapshot): extract the ACP snapshot suite into a support package
The snapshot tier's machinery leaves examples/acp-agent/tests for
packages/support/acp-snapshot (@deepseek-ai/dsh-acp-snapshot), where the
coverage gate measures it and a second example can consume it instead of
forking it: harness.ts (runScenario, parameterized by an AgentUnderTest
{binScript, configPath, tsconfigPath} instead of module constants),
normalize.ts (moved verbatim), and suite.ts (defineAcpSnapshotSuite — the
per-scenario golden/log compares, record write-back, per-suite header pin
with its uniformity guard, and the fixture guard block, lifted from
acp.snapshot.ts). The example file collapses to its scenario table plus
one factory call; env reading (DSH_SNAPSHOT) stays at that edge.
The exactly-one-pin meta-test generalizes from the hardcoded text-turn
name to "exactly one per suite" — which scenario pins is the scenario
table's reviewable choice (per-suite pinning per the proposal RFC).
Extraction parity: pnpm run test:snapshot is 36 passed + fs-policy-reject
failing BEFORE AND AFTER (BSD-sed environment failure, reproduced at the
base commit in a clean worktree — the recorded golden's sed -i syntax is
GNU-only), with zero byte changes under examples/acp-agent/tests/snapshots/.
Coverage for the new src files lands in the next commit.
2026-07-08 01:44:20 +08:00
pkg_acp_snapshot["acp-snapshot"]
2026-07-16 17:39:53 +08:00
pkg_agent_loop_testkit["agent-loop-testkit"]
2026-07-05 01:25:58 +08:00
pkg_invariants["invariants"]
pkg_llm_replay["llm-replay"]
2026-07-14 05:00:54 +08:00
pkg_loader_smoke["loader-smoke"]
2026-07-05 01:25:58 +08:00
end
subgraph group_ui["packages/ui"]
pkg_acp["acp"]
2026-07-05 01:53:13 +08:00
pkg_app_boot["app-boot"]
2026-07-11 14:08:12 +08:00
pkg_jsonrpc["jsonrpc"]
feat(permission): user-facing permission presets — one Permissions select over the two knobs
A preset names a bundle of the two mechanism knobs — request =
workspace-write + ask, yolo = danger-full-access + never — so the editor
shows ONE 'Permissions' select where the sandbox-mode and approval-policy
tiers stay orthogonal capabilities (the Codex /approvals shape: presets over
two dials). ctx.permission (dsh-permission) owns the config-defined table,
validates the default preset's bundle against the composed knob defaults at
load (fails loud), and writes a switch THROUGH: one log-only
permission/preset event (the audit fact reverse-mapping cannot recover —
the planned 'agent' preset shares request's knob values and differs only in
composed policy) plus each knob event via its own setter, deduped — a
net-zero switch appends nothing. Every knob consumer keeps reading its own
fold, untouched.
The current preset DERIVES from the effective knob values — the fold breaks
bundle ties, a knob state outside the table is the reserved 'custom' value
(a state, not an error: shown while it holds, switchable FROM, never a
target), and defaultPreset disappears (zero-event state reverse-maps from
the composition defaults).
The ACP bridge drops the two per-knob selects for the one preset select
(advertised only when ctx.permission is composed); pending/anchor/no-op
semantics carry over unchanged, with the no-op echo acknowledged before
vocabulary validation so a client re-pushing a derived 'custom' current
never errors. The sandbox variant example composes the
service with a workspace-write default; the permission-switching,
escalation-approved and escalation-rejected scenarios are re-recorded under
it (escalations now target an outside-workspace /tmp path under
danger-full-access, self-cleaning) and config-options is re-authored on the
single-select wire.
2026-07-12 21:03:41 +08:00
pkg_permission["permission"]
2026-07-15 02:02:11 +08:00
pkg_stdio["stdio"]
2026-07-05 17:05:33 +08:00
pkg_tool_ask_user["tool-ask-user"]
2026-07-17 12:01:37 +08:00
pkg_tui["tui"]
2026-07-11 21:37:38 +08:00
pkg_user_approval["user-approval"]
2026-07-09 17:55:01 +08:00
pkg_user_interaction["user-interaction"]
2026-07-05 01:25:58 +08:00
end
2026-07-08 02:17:24 +08:00
subgraph group_code_runtime["packages/code-runtime"]
pkg_code_runtime["code-runtime"]
feat: add the worker-thread code runtime (dsh-code-runtime-worker)
The shipped backend of the code-execution seam, per the Code Mode RFC's
worker-thread section: one fresh Node worker per run, executing the
model's TypeScript after a host-side type-strip (wrapped in an
async-function shell so top-level return/await parse, sliced back out
position-preserved), bindings bridged over the message port under
hostile-peer rules (own-property name lookup, at-most-once replies,
post-settlement drops, null-prototype namespaces), logs streamed eagerly
with an in-band truncation marker, and two independent budgets — measured
event-loop busy time (computeMs) plus a never-pausing wall ceiling
(maxWallMs) — funneling into worker.terminate(). env: {} and execArgv: []
keep the isolate hermetic; disposal aborts in-flight runs and awaits
worker exits.
The worker entry loads unbuilt via Node's native type stripping
(src/worker.ts, erasable-only) and ships built as a sibling tsdown bundle
(lib/worker.js); tests/built-lib.e2e.ts pins the built load path under
plain node and joins the built-artifact smoke gate. Unit suites cover the
bootstrap in-process (fake port) and the runtime over real workers,
per-file 100%.
2026-07-08 11:00:06 +08:00
pkg_code_runtime_worker["code-runtime-worker"]
2026-07-08 02:17:24 +08:00
end
2026-07-14 16:04:34 +08:00
subgraph group_context["packages/context"]
pkg_time_context["time-context"]
2026-07-16 16:01:06 +08:00
pkg_workspace_context["workspace-context"]
2026-07-14 16:04:34 +08:00
end
2026-07-15 15:57:57 +08:00
subgraph group_examples["packages/examples"]
pkg_acp_demo["acp-demo"]
pkg_agent_spine_demo["agent-spine-demo"]
pkg_jsonrpc_demo["jsonrpc-demo"]
pkg_stdio_demo["stdio-demo"]
end
2026-07-08 14:24:20 +08:00
subgraph group_guard["packages/guard"]
pkg_repeat_tool_guard["repeat-tool-guard"]
2026-07-08 02:17:24 +08:00
end
2026-07-07 23:21:54 +08:00
subgraph group_mcp["packages/mcp"]
pkg_mcp_client["mcp-client"]
end
2026-07-09 15:42:37 +08:00
subgraph group_sandbox["packages/sandbox"]
pkg_sandbox["sandbox"]
pkg_sandbox_local["sandbox-local"]
end
2026-07-15 18:17:38 +08:00
subgraph group_sdk["packages/sdk"]
pkg_helper["helper"]
pkg_scripts["scripts"]
end
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
subgraph group_tasks["packages/tasks"]
pkg_tasks["tasks"]
pkg_tool_tasks["tool-tasks"]
end
2026-07-06 03:14:07 +08:00
subgraph group_workflow["packages/workflow"]
pkg_tool_workflow["tool-workflow"]
pkg_workflow["workflow"]
2026-07-09 19:06:55 +08:00
pkg_workflow_workerthread["workflow-workerthread"]
2026-07-06 03:14:07 +08:00
end
2026-07-05 01:25:58 +08:00
pkg_llm --> pkg_brand
feat: add the worker-thread code runtime (dsh-code-runtime-worker)
The shipped backend of the code-execution seam, per the Code Mode RFC's
worker-thread section: one fresh Node worker per run, executing the
model's TypeScript after a host-side type-strip (wrapped in an
async-function shell so top-level return/await parse, sliced back out
position-preserved), bindings bridged over the message port under
hostile-peer rules (own-property name lookup, at-most-once replies,
post-settlement drops, null-prototype namespaces), logs streamed eagerly
with an in-band truncation marker, and two independent budgets — measured
event-loop busy time (computeMs) plus a never-pausing wall ceiling
(maxWallMs) — funneling into worker.terminate(). env: {} and execArgv: []
keep the isolate hermetic; disposal aborts in-flight runs and awaits
worker exits.
The worker entry loads unbuilt via Node's native type stripping
(src/worker.ts, erasable-only) and ships built as a sibling tsdown bundle
(lib/worker.js); tests/built-lib.e2e.ts pins the built load path under
plain node and joins the built-artifact smoke gate. Unit suites cover the
bootstrap in-process (fake port) and the runtime over real workers,
per-file 100%.
2026-07-08 11:00:06 +08:00
pkg_code_runtime_worker --> pkg_code_runtime
2026-07-15 18:17:38 +08:00
pkg_helper --> pkg_brand
pkg_scripts --> pkg_app_boot
2026-07-05 01:25:58 +08:00
pkg_llm_deepseek --> pkg_llm
pkg_llm_pi_ai --> pkg_llm
pkg_session --> pkg_brand
pkg_session --> pkg_llm
2026-07-09 01:21:27 +08:00
pkg_session --> pkg_scope
2026-07-05 01:25:58 +08:00
pkg_system_prompt --> pkg_llm
2026-07-12 22:49:46 +08:00
pkg_system_prompt --> pkg_scope
2026-07-05 01:25:58 +08:00
pkg_fs --> pkg_brand
pkg_fs --> pkg_llm
pkg_web --> pkg_llm
2026-07-09 15:42:37 +08:00
pkg_sandbox --> pkg_llm
2026-07-15 14:47:29 +08:00
pkg_token_meter --> pkg_llm
pkg_token_meter --> pkg_session
2026-07-05 01:25:58 +08:00
pkg_agent --> pkg_brand
pkg_agent --> pkg_llm
2026-07-12 22:49:46 +08:00
pkg_agent --> pkg_scope
2026-07-05 01:25:58 +08:00
pkg_agent --> pkg_session
2026-07-05 20:54:48 +08:00
pkg_agent --> pkg_system_prompt
2026-07-09 16:05:44 +08:00
pkg_bash --> pkg_sandbox
pkg_bash --> pkg_session
2026-07-05 01:25:58 +08:00
pkg_fs_local --> pkg_fs
pkg_fs_policy --> pkg_fs
2026-07-10 14:19:06 +08:00
pkg_skill_local --> pkg_fs
2026-07-12 16:30:01 +08:00
pkg_skill_local --> pkg_home
2026-07-10 14:19:06 +08:00
pkg_skill_local --> pkg_skill
2026-07-05 01:25:58 +08:00
pkg_compact --> pkg_llm
pkg_compact --> pkg_session
2026-07-06 16:23:52 +08:00
pkg_web_fetch_local --> pkg_timeout
2026-07-05 01:25:58 +08:00
pkg_web_fetch_local --> pkg_web
pkg_web_search_deepseek --> pkg_web
pkg_web_search_exa --> pkg_web
pkg_web_search_perplexity --> pkg_web
2026-07-08 19:20:50 +08:00
pkg_spill --> pkg_brand
pkg_spill --> pkg_llm
pkg_spill --> pkg_session
2026-07-05 01:25:58 +08:00
pkg_session_persistence --> pkg_session
pkg_llm_replay --> pkg_llm
pkg_llm_replay --> pkg_session
2026-07-09 15:42:37 +08:00
pkg_sandbox_local --> pkg_llm
pkg_sandbox_local --> pkg_sandbox
2026-07-09 16:05:44 +08:00
pkg_bash_local --> pkg_bash
pkg_bash_local --> pkg_timeout
2026-07-05 01:25:58 +08:00
pkg_compact_basic --> pkg_agent
pkg_compact_basic --> pkg_compact
pkg_compact_basic --> pkg_llm
pkg_compact_basic --> pkg_session
2026-07-15 14:47:29 +08:00
pkg_compact_basic --> pkg_token_meter
2026-07-08 19:20:50 +08:00
pkg_spill_local --> pkg_spill
2026-07-09 16:05:44 +08:00
pkg_hook_protocol --> pkg_bash
pkg_hook_protocol --> pkg_session
2026-07-05 01:25:58 +08:00
pkg_session_persistence_jsonl --> pkg_session
pkg_session_persistence_jsonl --> pkg_session_persistence
pkg_session_persistence_sqlite --> pkg_session
pkg_session_persistence_sqlite --> pkg_session_persistence
2026-07-10 16:51:19 +08:00
pkg_session_query --> pkg_llm
pkg_session_query --> pkg_session
pkg_session_query --> pkg_session_persistence
2026-07-05 01:25:58 +08:00
pkg_invariants --> pkg_agent
pkg_invariants --> pkg_llm
2026-07-12 22:49:46 +08:00
pkg_invariants --> pkg_scope
2026-07-05 01:25:58 +08:00
pkg_invariants --> pkg_session
2026-07-11 21:37:38 +08:00
pkg_user_approval --> pkg_agent
pkg_user_approval --> pkg_brand
pkg_user_approval --> pkg_llm
2026-07-11 23:14:09 +08:00
pkg_user_approval --> pkg_scope
2026-07-11 21:37:38 +08:00
pkg_user_approval --> pkg_session
pkg_user_approval --> pkg_system_prompt
2026-07-09 17:55:01 +08:00
pkg_user_interaction --> pkg_agent
pkg_user_interaction --> pkg_llm
2026-07-14 16:04:34 +08:00
pkg_time_context --> pkg_agent
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
pkg_tasks --> pkg_agent
pkg_tasks --> pkg_brand
2026-07-12 17:10:02 +08:00
pkg_tasks --> pkg_session
refactor(tasks): declare-then-execute — ctx.tasks.start() replaces register()
start({ kind, label, owner, run }) preflights everything that can fail
(the attachSurface fence, validation, the owner-cleanup attach) BEFORE
invoking the producer's run() starter, then commits atomically —
'work started but never got a collectable id' is now structurally
impossible instead of a producer try/catch rollback obligation (the
P1 review fix, rebuilt on #185's declare/execute split). Producers
lose their catch-wraps; the leak tests now pin the stronger property
that a failed preflight never spawns anything. TaskRegistration splits
into TaskStart (identity + run) and TaskHooks (cancel/done/readOutput);
docs, type-equiv manifest, catalogs, and both RFCs move with it.
2026-07-09 21:53:48 +08:00
pkg_tasks --> pkg_timeout
2026-07-06 03:14:07 +08:00
pkg_workflow --> pkg_agent
pkg_workflow --> pkg_brand
pkg_workflow --> pkg_llm
2026-07-15 23:50:33 +08:00
pkg_workflow --> pkg_session
2026-07-09 15:25:18 +08:00
pkg_tools --> pkg_agent
pkg_tools --> pkg_code_runtime
pkg_tools --> pkg_llm
2026-07-11 23:14:09 +08:00
pkg_tools --> pkg_scope
2026-07-09 15:25:18 +08:00
pkg_tools --> pkg_session
pkg_tools --> pkg_system_prompt
2026-07-11 21:37:38 +08:00
pkg_tools --> pkg_user_approval
2026-07-09 16:05:44 +08:00
pkg_bash_sandbox --> pkg_bash
pkg_bash_sandbox --> pkg_bash_local
pkg_bash_sandbox --> pkg_sandbox
feat(permission): user-facing permission presets — one Permissions select over the two knobs
A preset names a bundle of the two mechanism knobs — request =
workspace-write + ask, yolo = danger-full-access + never — so the editor
shows ONE 'Permissions' select where the sandbox-mode and approval-policy
tiers stay orthogonal capabilities (the Codex /approvals shape: presets over
two dials). ctx.permission (dsh-permission) owns the config-defined table,
validates the default preset's bundle against the composed knob defaults at
load (fails loud), and writes a switch THROUGH: one log-only
permission/preset event (the audit fact reverse-mapping cannot recover —
the planned 'agent' preset shares request's knob values and differs only in
composed policy) plus each knob event via its own setter, deduped — a
net-zero switch appends nothing. Every knob consumer keeps reading its own
fold, untouched.
The current preset DERIVES from the effective knob values — the fold breaks
bundle ties, a knob state outside the table is the reserved 'custom' value
(a state, not an error: shown while it holds, switchable FROM, never a
target), and defaultPreset disappears (zero-event state reverse-maps from
the composition defaults).
The ACP bridge drops the two per-knob selects for the one preset select
(advertised only when ctx.permission is composed); pending/anchor/no-op
semantics carry over unchanged, with the no-op echo acknowledged before
vocabulary validation so a client re-pushing a derived 'custom' current
never errors. The sandbox variant example composes the
service with a workspace-write default; the permission-switching,
escalation-approved and escalation-rejected scenarios are re-recorded under
it (escalations now target an outside-workspace /tmp path under
danger-full-access, self-cleaning) and config-options is re-authored on the
single-select wire.
2026-07-12 21:03:41 +08:00
pkg_permission --> pkg_bash
pkg_permission --> pkg_sandbox
pkg_permission --> pkg_session
pkg_permission --> pkg_user_approval
2026-07-05 01:25:58 +08:00
pkg_agent_loop --> pkg_agent
pkg_agent_loop --> pkg_llm
2026-07-09 01:21:27 +08:00
pkg_agent_loop --> pkg_scope
2026-07-05 01:25:58 +08:00
pkg_agent_loop --> pkg_session
pkg_agent_loop --> pkg_session_persistence
pkg_agent_loop --> pkg_system_prompt
pkg_agent_loop --> pkg_tools
pkg_tool_bash --> pkg_agent
pkg_tool_bash --> pkg_bash
2026-07-12 16:30:01 +08:00
pkg_tool_bash --> pkg_home
2026-07-05 01:25:58 +08:00
pkg_tool_bash --> pkg_llm
2026-07-09 16:05:44 +08:00
pkg_tool_bash --> pkg_sandbox
2026-07-10 20:52:27 +08:00
pkg_tool_bash --> pkg_session_persistence
2026-07-05 20:54:48 +08:00
pkg_tool_bash --> pkg_system_prompt
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
pkg_tool_bash --> pkg_tasks
2026-07-05 01:25:58 +08:00
pkg_tool_bash --> pkg_tools
2026-07-11 21:37:38 +08:00
pkg_tool_bash --> pkg_user_approval
2026-07-05 01:25:58 +08:00
pkg_tool_fs --> pkg_fs
pkg_tool_fs --> pkg_llm
pkg_tool_fs --> pkg_session
pkg_tool_fs --> pkg_system_prompt
pkg_tool_fs --> pkg_tools
2026-07-09 20:44:32 +08:00
pkg_tool_fs_search --> pkg_bash
pkg_tool_fs_search --> pkg_llm
pkg_tool_fs_search --> pkg_retention
pkg_tool_fs_search --> pkg_session
pkg_tool_fs_search --> pkg_spill
pkg_tool_fs_search --> pkg_system_prompt
pkg_tool_fs_search --> pkg_tools
2026-07-10 14:19:06 +08:00
pkg_tool_skill --> pkg_agent
pkg_tool_skill --> pkg_llm
pkg_tool_skill --> pkg_skill
pkg_tool_skill --> pkg_tools
2026-07-05 01:25:58 +08:00
pkg_subagent --> pkg_agent
2026-07-18 14:26:14 +08:00
pkg_subagent --> pkg_brand
2026-07-05 01:25:58 +08:00
pkg_subagent --> pkg_llm
2026-07-09 05:21:06 +08:00
pkg_subagent --> pkg_scope
2026-07-15 23:50:33 +08:00
pkg_subagent --> pkg_session
2026-07-05 01:25:58 +08:00
pkg_subagent --> pkg_tools
pkg_tool_web --> pkg_llm
pkg_tool_web --> pkg_system_prompt
pkg_tool_web --> pkg_tools
pkg_tool_web --> pkg_web
2026-07-08 19:20:50 +08:00
pkg_spill_policy --> pkg_llm
pkg_spill_policy --> pkg_retention
pkg_spill_policy --> pkg_session
pkg_spill_policy --> pkg_spill
pkg_spill_policy --> pkg_tools
2026-07-08 10:06:07 +08:00
pkg_timeout_policy --> pkg_llm
pkg_timeout_policy --> pkg_timeout
pkg_timeout_policy --> pkg_tools
2026-07-05 01:25:58 +08:00
pkg_tool_todo --> pkg_agent
pkg_tool_todo --> pkg_session
pkg_tool_todo --> pkg_tools
Merge origin/master: scope-aware fusion of the tools/execute seam, session-prefix, and tool-cordis
Master brought 50 commits (the tool-cordis group, dsh-code-runtime + worker,
the tools/execute around-dispatch seam + timeout-policy, repeat-tool-guard,
agent/session-prefix, the ui reorganization). Beyond the ten textual
conflicts, the merge reconciles master's new seams with this branch's
scoped-registration world:
- tools/execute (new waterfall around core dispatch): dispatched with the
SAME exec.agent carrier as the pre/post waterfalls — an agent.ctx wrapper
times/retries only its own agent's calls — and its base thunk resolves the
tool through the caller's visible view (get(exec.name, exec.agent)), so a
scoped/shadowed tool dispatches and a restricted-away global stays
UNKNOWN_TOOL. Declared this: Scoped<ToolRegistry> with the scope-filtered
doc sentence; invariants table + verify-scoped-dispatch pin it (21 events).
- agent/session-prefix (new waterfall, once per loop instance): composed via
the fused agentEvents dispatcher (scope-filtered like every agent-subject
event), declared this: Scoped<Agent>, table-pinned. agent/pre-step keeps
master's new sessionPrefix parameter with this branch's Scoped this.
- timeout-policy reads the budget through the caller's visible view
(get(exec.name, exec.agent)): a scoped tool's own timeoutMs governs its
calls; a global name-twin's budget is never misapplied to a shadowing
per-agent variant.
- tool-cordis: cordis_inspect's tools section lists the CALLING agent's view
(its description promises "what you can call"); the sandbox tool façade's
reads resolve through the mount's own scope, mirroring where its register
lands writes; sandboxRegisterTool's return type carries the exact-disposer
union honestly. dsh-scope declared as peer+dev with the project reference.
- doc-sync chain unions master's verify-cordis-api with this branch's
verify-scoped-dispatch; the generated catalogs, event matrix (the
zero-dispatcher guard passes over master's new events), module graph, and
the cordis api-catalog are regenerated on the merged surface.
Full gate sequence green on the merged tree: typecheck, lint, per-file 100%
coverage (2668 tests), snapshots (38), doc-sync, module graph, build,
hygiene, demo smoke.
2026-07-09 23:24:42 +08:00
pkg_tool_cordis --> pkg_scope
2026-07-08 11:50:12 +08:00
pkg_tool_cordis --> pkg_tools
2026-07-05 01:25:58 +08:00
pkg_hooks_codex --> pkg_agent
pkg_hooks_codex --> pkg_hook_protocol
pkg_hooks_codex --> pkg_llm
pkg_hooks_codex --> pkg_session
2026-07-10 20:52:27 +08:00
pkg_hooks_codex --> pkg_session_persistence
2026-07-05 01:25:58 +08:00
pkg_hooks_codex --> pkg_tools
2026-07-16 17:39:53 +08:00
pkg_agent_loop_testkit --> pkg_agent
pkg_agent_loop_testkit --> pkg_llm
pkg_agent_loop_testkit --> pkg_session
pkg_agent_loop_testkit --> pkg_system_prompt
pkg_agent_loop_testkit --> pkg_tools
2026-07-05 01:25:58 +08:00
pkg_acp --> pkg_agent
feat(modes): per-session sandbox/approval switching — the session log as the store, ACP config options
effective(session) = findLast(the session own knob events)?.value ?? the
composition-config default. One log-only event per knob, owned by its
domain (bash/sandbox-mode in dsh-bash, approval/policy in dsh-approval),
each exporting the same three-piece kit: the event declaration, a pure
fold, and THE write path — a switch IS its event; no owner service, no
facts map. Restart immunity and multi-session isolation fall out of the
log replay by construction.
Execution follows the fold on both sides: the bash tool stamps
escalation grant > session override > executor default, and the approval
seam prepends the never-gate that auto-rejects before any interactive
answerer. Visibility is two layers per knob: a per-agent prompt section
states the effective value on every request (logged through
request/header*, so what-the-model-was-told replays from the log), and an
agent/pre-step narrator injects at most one coalesced delta notice with
positional attribution (user switch vs operator/config drift). The ACP
bridge advertises one capability-gated select per composable knob with
currentValue folded per session, validates set_config_option against the
closed vocabularies, and anchors idle switches at the next turn
prompt-submit under the turn-enclosure contract.
2026-07-09 16:41:03 +08:00
pkg_acp --> pkg_bash
2026-07-05 01:25:58 +08:00
pkg_acp --> pkg_llm
feat(permission): user-facing permission presets — one Permissions select over the two knobs
A preset names a bundle of the two mechanism knobs — request =
workspace-write + ask, yolo = danger-full-access + never — so the editor
shows ONE 'Permissions' select where the sandbox-mode and approval-policy
tiers stay orthogonal capabilities (the Codex /approvals shape: presets over
two dials). ctx.permission (dsh-permission) owns the config-defined table,
validates the default preset's bundle against the composed knob defaults at
load (fails loud), and writes a switch THROUGH: one log-only
permission/preset event (the audit fact reverse-mapping cannot recover —
the planned 'agent' preset shares request's knob values and differs only in
composed policy) plus each knob event via its own setter, deduped — a
net-zero switch appends nothing. Every knob consumer keeps reading its own
fold, untouched.
The current preset DERIVES from the effective knob values — the fold breaks
bundle ties, a knob state outside the table is the reserved 'custom' value
(a state, not an error: shown while it holds, switchable FROM, never a
target), and defaultPreset disappears (zero-event state reverse-maps from
the composition defaults).
The ACP bridge drops the two per-knob selects for the one preset select
(advertised only when ctx.permission is composed); pending/anchor/no-op
semantics carry over unchanged, with the no-op echo acknowledged before
vocabulary validation so a client re-pushing a derived 'custom' current
never errors. The sandbox variant example composes the
service with a workspace-write default; the permission-switching,
escalation-approved and escalation-rejected scenarios are re-recorded under
it (escalations now target an outside-workspace /tmp path under
danger-full-access, self-cleaning) and config-options is re-authored on the
single-select wire.
2026-07-12 21:03:41 +08:00
pkg_acp --> pkg_permission
feat(modes): per-session sandbox/approval switching — the session log as the store, ACP config options
effective(session) = findLast(the session own knob events)?.value ?? the
composition-config default. One log-only event per knob, owned by its
domain (bash/sandbox-mode in dsh-bash, approval/policy in dsh-approval),
each exporting the same three-piece kit: the event declaration, a pure
fold, and THE write path — a switch IS its event; no owner service, no
facts map. Restart immunity and multi-session isolation fall out of the
log replay by construction.
Execution follows the fold on both sides: the bash tool stamps
escalation grant > session override > executor default, and the approval
seam prepends the never-gate that auto-rejects before any interactive
answerer. Visibility is two layers per knob: a per-agent prompt section
states the effective value on every request (logged through
request/header*, so what-the-model-was-told replays from the log), and an
agent/pre-step narrator injects at most one coalesced delta notice with
positional attribution (user switch vs operator/config drift). The ACP
bridge advertises one capability-gated select per composable knob with
currentValue folded per session, validates set_config_option against the
closed vocabularies, and anchors idle switches at the next turn
prompt-submit under the turn-enclosure contract.
2026-07-09 16:41:03 +08:00
pkg_acp --> pkg_sandbox
2026-07-05 01:25:58 +08:00
pkg_acp --> pkg_session
pkg_acp --> pkg_session_persistence
2026-07-15 13:33:42 +08:00
pkg_acp --> pkg_system_prompt
2026-07-05 01:25:58 +08:00
pkg_acp --> pkg_tools
2026-07-11 21:37:38 +08:00
pkg_acp --> pkg_user_approval
2026-07-05 17:05:33 +08:00
pkg_acp --> pkg_user_interaction
pkg_tool_ask_user --> pkg_agent
pkg_tool_ask_user --> pkg_tools
pkg_tool_ask_user --> pkg_user_interaction
2026-07-10 14:32:44 +08:00
pkg_workspace_context --> pkg_agent
pkg_workspace_context --> pkg_fs
pkg_workspace_context --> pkg_llm
pkg_workspace_context --> pkg_paths
pkg_workspace_context --> pkg_session
pkg_workspace_context --> pkg_tools
2026-07-08 14:24:20 +08:00
pkg_repeat_tool_guard --> pkg_agent
pkg_repeat_tool_guard --> pkg_tools
2026-07-07 23:21:54 +08:00
pkg_mcp_client --> pkg_llm
pkg_mcp_client --> pkg_tools
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
pkg_tool_tasks --> pkg_agent
pkg_tool_tasks --> pkg_system_prompt
pkg_tool_tasks --> pkg_tasks
pkg_tool_tasks --> pkg_tools
2026-07-06 03:14:07 +08:00
pkg_tool_workflow --> pkg_agent
pkg_tool_workflow --> pkg_llm
pkg_tool_workflow --> pkg_system_prompt
pkg_tool_workflow --> pkg_tools
pkg_tool_workflow --> pkg_workflow
2026-07-05 01:25:58 +08:00
pkg_subagent_acp --> pkg_agent
pkg_subagent_acp --> pkg_llm
2026-07-15 23:50:33 +08:00
pkg_subagent_acp --> pkg_session
2026-07-05 01:25:58 +08:00
pkg_subagent_acp --> pkg_subagent
rename: @deepseek-ai/dsh-subagent-process -> @deepseek-ai/dsh-subagent-subprocess
The extracted library's name sat one edit away from @deepseek-ai/dsh-subagent-inprocess
(process/inprocess), inviting a typo'd import to silently resolve to the wrong
package. subagent-subprocess also reads as the deliberate counterpart to
subagent-inprocess (in-process vs. subprocess), matching how the two shared
drivers actually differ.
Package directory, npm name, module doc, JSDoc module tags, test-file name and
its temp-dir prefixes, the subagent-acp import and its Config/tsconfig/package.json
references, root tsconfig.json/tsconfig.build.json/knip.json entries, and the
packages/subagent group README all renamed together; regenerated
docs/module-graph.md and docs/config-catalog.md. Pure rename — no behavior,
export, or Config shape changed.
2026-07-09 13:42:03 +08:00
pkg_subagent_acp --> pkg_subagent_subprocess
2026-07-05 01:25:58 +08:00
pkg_subagent_inprocess --> pkg_agent
pkg_subagent_inprocess --> pkg_llm
pkg_subagent_inprocess --> pkg_session
pkg_subagent_inprocess --> pkg_subagent
Structured output on the subagent seam: schema subset, capture runtime, spawn/fork support
Carved out of #170 per review feedback — the foundation the workflow tool
builds on, now standing alone on master:
- dsh-tools: the structured-output JSON Schema subset (StructuredOutputSchema,
assertSupportedOutputSchema, validateStructuredValue) — rejects loud outside
the enforced subset, listing every violation
- dsh-subagent: SubagentStartRequest.outputSchema / SubagentResult.structured
become a real capability; the service rejects a schema'd request whose
provider lacks it
- dsh-subagent-inprocess: the shared structured runtime — one global
structured_output capture tool, a prepend final-assembly listener that
strips the placeholder for plain agents and swaps in the run's own schema
(plus the calling instruction as a trailing section) for structured
children, an agent/turn-continuation veto once captured, and the
capture/nudge loop in the run driver (structuredNudgeRetries, cancellation
honored mid-nudge); lifetime refcounted by backends and live runs
- subagent-spawn / subagent-fork flip outputSchema: true
One deliberate divergence from the #170 revision: the backends do NOT add
'tools' to their plugin inject. Doing so deferred their apply past the todo
plugin, and the delegation tool mirrors provider lifecycle — so the
model-visible tool order of every existing prompt changed, invalidating every
recorded snapshot fixture. The runtime now gates its capture-tool registration
on tools availability itself (sync when live, a scoped inject fiber when the
Loader starts the backend first), keeping this PR byte-invisible to existing
transcripts: all 35 snapshot scenarios pass against master's fixtures
unchanged.
2026-07-06 23:29:08 +08:00
pkg_subagent_inprocess --> pkg_system_prompt
pkg_subagent_inprocess --> pkg_tools
2026-07-05 01:25:58 +08:00
pkg_tool_subagent --> pkg_agent
pkg_tool_subagent --> pkg_llm
pkg_tool_subagent --> pkg_subagent
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
pkg_tool_subagent --> pkg_tasks
2026-07-05 01:25:58 +08:00
pkg_tool_subagent --> pkg_tools
pkg_hooks_claude --> pkg_agent
pkg_hooks_claude --> pkg_hook_protocol
pkg_hooks_claude --> pkg_llm
pkg_hooks_claude --> pkg_session
2026-07-10 20:52:27 +08:00
pkg_hooks_claude --> pkg_session_persistence
2026-07-05 01:25:58 +08:00
pkg_hooks_claude --> pkg_subagent
pkg_hooks_claude --> pkg_tools
2026-07-11 14:08:12 +08:00
pkg_jsonrpc --> pkg_agent
pkg_jsonrpc --> pkg_llm
pkg_jsonrpc --> pkg_llm_deepseek
2026-07-15 23:51:45 +08:00
pkg_jsonrpc --> pkg_scope
2026-07-11 14:08:12 +08:00
pkg_jsonrpc --> pkg_session
pkg_jsonrpc --> pkg_subagent
2026-07-15 23:50:33 +08:00
pkg_stdio --> pkg_agent
pkg_stdio --> pkg_agent_loop
pkg_stdio --> pkg_llm
pkg_stdio --> pkg_session
pkg_stdio --> pkg_user_interaction
2026-07-19 11:37:14 +08:00
pkg_tui --> pkg_agent
pkg_tui --> pkg_agent_loop
pkg_tui --> pkg_llm
pkg_tui --> pkg_session
pkg_tui --> pkg_tools
pkg_tui --> pkg_user_interaction
2026-07-15 15:57:57 +08:00
pkg_agent_spine_demo --> pkg_agent
pkg_agent_spine_demo --> pkg_agent_loop
2026-07-15 16:53:56 +08:00
pkg_agent_spine_demo --> pkg_home
2026-07-15 15:57:57 +08:00
pkg_agent_spine_demo --> pkg_invariants
pkg_agent_spine_demo --> pkg_llm
pkg_agent_spine_demo --> pkg_session
pkg_agent_spine_demo --> pkg_skill
pkg_agent_spine_demo --> pkg_skill_local
pkg_agent_spine_demo --> pkg_system_prompt
2026-07-15 16:57:03 +08:00
pkg_agent_spine_demo --> pkg_tasks
2026-07-15 15:57:57 +08:00
pkg_agent_spine_demo --> pkg_tool_bash
pkg_agent_spine_demo --> pkg_tool_skill
2026-07-15 16:57:03 +08:00
pkg_agent_spine_demo --> pkg_tool_tasks
2026-07-15 15:57:57 +08:00
pkg_agent_spine_demo --> pkg_tools
2026-07-15 17:04:16 +08:00
pkg_agent_spine_demo --> pkg_workspace_context
2026-07-09 19:06:55 +08:00
pkg_workflow_workerthread --> pkg_agent
pkg_workflow_workerthread --> pkg_brand
pkg_workflow_workerthread --> pkg_llm
2026-07-12 03:51:55 +08:00
pkg_workflow_workerthread --> pkg_session
2026-07-09 19:06:55 +08:00
pkg_workflow_workerthread --> pkg_subagent
pkg_workflow_workerthread --> pkg_tools
pkg_workflow_workerthread --> pkg_workflow
2026-07-05 01:25:58 +08:00
pkg_subagent_fork --> pkg_agent
pkg_subagent_fork --> pkg_session
pkg_subagent_fork --> pkg_subagent
pkg_subagent_fork --> pkg_subagent_inprocess
pkg_subagent_spawn --> pkg_subagent
pkg_subagent_spawn --> pkg_subagent_inprocess
2026-07-15 15:57:57 +08:00
pkg_acp_demo --> pkg_acp
pkg_acp_demo --> pkg_agent_spine_demo
pkg_acp_demo --> pkg_app_boot
pkg_acp_demo --> pkg_session_persistence_jsonl
pkg_acp_demo --> pkg_tools
pkg_acp_demo --> pkg_user_interaction
2026-07-15 17:04:16 +08:00
pkg_acp_demo --> pkg_workspace_context
2026-07-15 15:57:57 +08:00
pkg_stdio_demo --> pkg_agent
2026-07-15 23:50:33 +08:00
pkg_stdio_demo --> pkg_agent_loop
2026-07-15 15:57:57 +08:00
pkg_stdio_demo --> pkg_agent_spine_demo
pkg_stdio_demo --> pkg_app_boot
pkg_stdio_demo --> pkg_llm
pkg_stdio_demo --> pkg_session
pkg_stdio_demo --> pkg_session_persistence_jsonl
pkg_stdio_demo --> pkg_stdio
pkg_stdio_demo --> pkg_tool_ask_user
pkg_stdio_demo --> pkg_tools
2026-07-17 12:01:37 +08:00
pkg_stdio_demo --> pkg_tui
2026-07-15 15:57:57 +08:00
pkg_stdio_demo --> pkg_user_interaction
2026-07-15 17:04:16 +08:00
pkg_stdio_demo --> pkg_workspace_context
2026-06-16 21:00:24 +08:00
```
2026-07-05 01:25:58 +08:00
| Package | Group | Depends on |
| --- | --- | --- |
| [`brand` ](../packages/util/brand ) | `util` | — |
2026-07-12 16:30:01 +08:00
| [`home` ](../packages/util/home ) | `util` | — |
2026-07-05 16:49:39 +08:00
| [`paths` ](../packages/util/paths ) | `util` | — |
2026-07-07 09:31:53 +08:00
| [`retention` ](../packages/util/retention ) | `util` | — |
2026-07-06 16:23:52 +08:00
| [`timeout` ](../packages/util/timeout ) | `util` | — |
2026-07-08 23:54:03 +08:00
| [`scope` ](../packages/core/scope ) | `core` | — |
2026-07-10 14:19:06 +08:00
| [`skill` ](../packages/skill/skill ) | `skill` | — |
2026-07-09 14:19:36 +08:00
| [`subagent-subprocess` ](../packages/subagent/subagent-subprocess ) | `subagent` | — |
feat(acp-snapshot): extract the ACP snapshot suite into a support package
The snapshot tier's machinery leaves examples/acp-agent/tests for
packages/support/acp-snapshot (@deepseek-ai/dsh-acp-snapshot), where the
coverage gate measures it and a second example can consume it instead of
forking it: harness.ts (runScenario, parameterized by an AgentUnderTest
{binScript, configPath, tsconfigPath} instead of module constants),
normalize.ts (moved verbatim), and suite.ts (defineAcpSnapshotSuite — the
per-scenario golden/log compares, record write-back, per-suite header pin
with its uniformity guard, and the fixture guard block, lifted from
acp.snapshot.ts). The example file collapses to its scenario table plus
one factory call; env reading (DSH_SNAPSHOT) stays at that edge.
The exactly-one-pin meta-test generalizes from the hardcoded text-turn
name to "exactly one per suite" — which scenario pins is the scenario
table's reviewable choice (per-suite pinning per the proposal RFC).
Extraction parity: pnpm run test:snapshot is 36 passed + fs-policy-reject
failing BEFORE AND AFTER (BSD-sed environment failure, reproduced at the
base commit in a clean worktree — the recorded golden's sed -i syntax is
GNU-only), with zero byte changes under examples/acp-agent/tests/snapshots/.
Coverage for the new src files lands in the next commit.
2026-07-08 01:44:20 +08:00
| [`acp-snapshot` ](../packages/support/acp-snapshot ) | `support` | — |
2026-07-14 05:00:54 +08:00
| [`loader-smoke` ](../packages/support/loader-smoke ) | `support` | — |
2026-07-05 01:53:13 +08:00
| [`app-boot` ](../packages/ui/app-boot ) | `ui` | — |
2026-07-08 02:17:24 +08:00
| [`code-runtime` ](../packages/code-runtime/code-runtime ) | `code-runtime` | — |
2026-07-15 15:57:57 +08:00
| [`jsonrpc-demo` ](../packages/examples/jsonrpc-demo ) | `examples` | — |
2026-07-05 01:25:58 +08:00
| [`llm` ](../packages/llm/llm ) | `llm` | [`brand` ](../packages/util/brand ) |
feat: add the worker-thread code runtime (dsh-code-runtime-worker)
The shipped backend of the code-execution seam, per the Code Mode RFC's
worker-thread section: one fresh Node worker per run, executing the
model's TypeScript after a host-side type-strip (wrapped in an
async-function shell so top-level return/await parse, sliced back out
position-preserved), bindings bridged over the message port under
hostile-peer rules (own-property name lookup, at-most-once replies,
post-settlement drops, null-prototype namespaces), logs streamed eagerly
with an in-band truncation marker, and two independent budgets — measured
event-loop busy time (computeMs) plus a never-pausing wall ceiling
(maxWallMs) — funneling into worker.terminate(). env: {} and execArgv: []
keep the isolate hermetic; disposal aborts in-flight runs and awaits
worker exits.
The worker entry loads unbuilt via Node's native type stripping
(src/worker.ts, erasable-only) and ships built as a sibling tsdown bundle
(lib/worker.js); tests/built-lib.e2e.ts pins the built load path under
plain node and joins the built-artifact smoke gate. Unit suites cover the
bootstrap in-process (fake port) and the runtime over real workers,
per-file 100%.
2026-07-08 11:00:06 +08:00
| [`code-runtime-worker` ](../packages/code-runtime/code-runtime-worker ) | `code-runtime` | [`code-runtime` ](../packages/code-runtime/code-runtime ) |
2026-07-15 18:17:38 +08:00
| [`helper` ](../packages/sdk/helper ) | `sdk` | [`brand` ](../packages/util/brand ) |
| [`scripts` ](../packages/sdk/scripts ) | `sdk` | [`app-boot` ](../packages/ui/app-boot ) |
2026-07-05 01:25:58 +08:00
| [`llm-deepseek` ](../packages/llm/llm-deepseek ) | `llm` | [`llm` ](../packages/llm/llm ) |
| [`llm-pi-ai` ](../packages/llm/llm-pi-ai ) | `llm` | [`llm` ](../packages/llm/llm ) |
2026-07-09 01:21:27 +08:00
| [`session` ](../packages/core/session ) | `core` | [`brand` ](../packages/util/brand ), [`llm` ](../packages/llm/llm ), [`scope` ](../packages/core/scope ) |
2026-07-12 22:49:46 +08:00
| [`system-prompt` ](../packages/core/system-prompt ) | `core` | [`llm` ](../packages/llm/llm ), [`scope` ](../packages/core/scope ) |
2026-07-05 01:25:58 +08:00
| [`fs` ](../packages/fs/fs ) | `fs` | [`brand` ](../packages/util/brand ), [`llm` ](../packages/llm/llm ) |
| [`web` ](../packages/web/web ) | `web` | [`llm` ](../packages/llm/llm ) |
2026-07-09 15:42:37 +08:00
| [`sandbox` ](../packages/sandbox/sandbox ) | `sandbox` | [`llm` ](../packages/llm/llm ) |
2026-07-15 14:47:29 +08:00
| [`token-meter` ](../packages/llm/token-meter ) | `llm` | [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ) |
2026-07-12 22:49:46 +08:00
| [`agent` ](../packages/core/agent ) | `core` | [`brand` ](../packages/util/brand ), [`llm` ](../packages/llm/llm ), [`scope` ](../packages/core/scope ), [`session` ](../packages/core/session ), [`system-prompt` ](../packages/core/system-prompt ) |
2026-07-11 23:04:27 +08:00
| [`bash` ](../packages/bash/bash ) | `bash` | [`sandbox` ](../packages/sandbox/sandbox ), [`session` ](../packages/core/session ) |
2026-07-05 01:25:58 +08:00
| [`fs-local` ](../packages/fs/fs-local ) | `fs` | [`fs` ](../packages/fs/fs ) |
| [`fs-policy` ](../packages/fs/fs-policy ) | `fs` | [`fs` ](../packages/fs/fs ) |
2026-07-12 16:30:01 +08:00
| [`skill-local` ](../packages/skill/skill-local ) | `skill` | [`fs` ](../packages/fs/fs ), [`home` ](../packages/util/home ), [`skill` ](../packages/skill/skill ) |
2026-07-05 01:25:58 +08:00
| [`compact` ](../packages/compact/compact ) | `compact` | [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ) |
2026-07-06 16:23:52 +08:00
| [`web-fetch-local` ](../packages/web/web-fetch-local ) | `web` | [`timeout` ](../packages/util/timeout ), [`web` ](../packages/web/web ) |
2026-07-05 01:25:58 +08:00
| [`web-search-deepseek` ](../packages/web/web-search-deepseek ) | `web` | [`web` ](../packages/web/web ) |
| [`web-search-exa` ](../packages/web/web-search-exa ) | `web` | [`web` ](../packages/web/web ) |
| [`web-search-perplexity` ](../packages/web/web-search-perplexity ) | `web` | [`web` ](../packages/web/web ) |
2026-07-08 19:20:50 +08:00
| [`spill` ](../packages/spill/spill ) | `spill` | [`brand` ](../packages/util/brand ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ) |
2026-07-05 01:25:58 +08:00
| [`session-persistence` ](../packages/session-persistence/session-persistence ) | `session-persistence` | [`session` ](../packages/core/session ) |
| [`llm-replay` ](../packages/support/llm-replay ) | `support` | [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ) |
2026-07-09 15:42:37 +08:00
| [`sandbox-local` ](../packages/sandbox/sandbox-local ) | `sandbox` | [`llm` ](../packages/llm/llm ), [`sandbox` ](../packages/sandbox/sandbox ) |
2026-07-09 16:05:44 +08:00
| [`bash-local` ](../packages/bash/bash-local ) | `bash` | [`bash` ](../packages/bash/bash ), [`timeout` ](../packages/util/timeout ) |
2026-07-15 14:47:29 +08:00
| [`compact-basic` ](../packages/compact/compact-basic ) | `compact` | [`agent` ](../packages/core/agent ), [`compact` ](../packages/compact/compact ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`token-meter` ](../packages/llm/token-meter ) |
2026-07-08 19:20:50 +08:00
| [`spill-local` ](../packages/spill/spill-local ) | `spill` | [`spill` ](../packages/spill/spill ) |
2026-07-09 16:05:44 +08:00
| [`hook-protocol` ](../packages/hooks/hook-protocol ) | `hooks` | [`bash` ](../packages/bash/bash ), [`session` ](../packages/core/session ) |
2026-07-05 01:25:58 +08:00
| [`session-persistence-jsonl` ](../packages/session-persistence/session-persistence-jsonl ) | `session-persistence` | [`session` ](../packages/core/session ), [`session-persistence` ](../packages/session-persistence/session-persistence ) |
| [`session-persistence-sqlite` ](../packages/session-persistence/session-persistence-sqlite ) | `session-persistence` | [`session` ](../packages/core/session ), [`session-persistence` ](../packages/session-persistence/session-persistence ) |
2026-07-10 16:51:19 +08:00
| [`session-query` ](../packages/session-query/session-query ) | `session-query` | [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`session-persistence` ](../packages/session-persistence/session-persistence ) |
2026-07-12 22:49:46 +08:00
| [`invariants` ](../packages/support/invariants ) | `support` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`scope` ](../packages/core/scope ), [`session` ](../packages/core/session ) |
2026-07-11 23:14:09 +08:00
| [`user-approval` ](../packages/ui/user-approval ) | `ui` | [`agent` ](../packages/core/agent ), [`brand` ](../packages/util/brand ), [`llm` ](../packages/llm/llm ), [`scope` ](../packages/core/scope ), [`session` ](../packages/core/session ), [`system-prompt` ](../packages/core/system-prompt ) |
2026-07-09 17:55:01 +08:00
| [`user-interaction` ](../packages/ui/user-interaction ) | `ui` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ) |
2026-07-16 17:47:51 +08:00
| [`time-context` ](../packages/context/time-context ) | `context` | [`agent` ](../packages/core/agent ) |
2026-07-12 17:10:02 +08:00
| [`tasks` ](../packages/tasks/tasks ) | `tasks` | [`agent` ](../packages/core/agent ), [`brand` ](../packages/util/brand ), [`session` ](../packages/core/session ), [`timeout` ](../packages/util/timeout ) |
2026-07-15 23:50:33 +08:00
| [`workflow` ](../packages/workflow/workflow ) | `workflow` | [`agent` ](../packages/core/agent ), [`brand` ](../packages/util/brand ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ) |
2026-07-11 23:14:09 +08:00
| [`tools` ](../packages/core/tools ) | `core` | [`agent` ](../packages/core/agent ), [`code-runtime` ](../packages/code-runtime/code-runtime ), [`llm` ](../packages/llm/llm ), [`scope` ](../packages/core/scope ), [`session` ](../packages/core/session ), [`system-prompt` ](../packages/core/system-prompt ), [`user-approval` ](../packages/ui/user-approval ) |
2026-07-09 16:05:44 +08:00
| [`bash-sandbox` ](../packages/bash/bash-sandbox ) | `bash` | [`bash` ](../packages/bash/bash ), [`bash-local` ](../packages/bash/bash-local ), [`sandbox` ](../packages/sandbox/sandbox ) |
feat(permission): user-facing permission presets — one Permissions select over the two knobs
A preset names a bundle of the two mechanism knobs — request =
workspace-write + ask, yolo = danger-full-access + never — so the editor
shows ONE 'Permissions' select where the sandbox-mode and approval-policy
tiers stay orthogonal capabilities (the Codex /approvals shape: presets over
two dials). ctx.permission (dsh-permission) owns the config-defined table,
validates the default preset's bundle against the composed knob defaults at
load (fails loud), and writes a switch THROUGH: one log-only
permission/preset event (the audit fact reverse-mapping cannot recover —
the planned 'agent' preset shares request's knob values and differs only in
composed policy) plus each knob event via its own setter, deduped — a
net-zero switch appends nothing. Every knob consumer keeps reading its own
fold, untouched.
The current preset DERIVES from the effective knob values — the fold breaks
bundle ties, a knob state outside the table is the reserved 'custom' value
(a state, not an error: shown while it holds, switchable FROM, never a
target), and defaultPreset disappears (zero-event state reverse-maps from
the composition defaults).
The ACP bridge drops the two per-knob selects for the one preset select
(advertised only when ctx.permission is composed); pending/anchor/no-op
semantics carry over unchanged, with the no-op echo acknowledged before
vocabulary validation so a client re-pushing a derived 'custom' current
never errors. The sandbox variant example composes the
service with a workspace-write default; the permission-switching,
escalation-approved and escalation-rejected scenarios are re-recorded under
it (escalations now target an outside-workspace /tmp path under
danger-full-access, self-cleaning) and config-options is re-authored on the
single-select wire.
2026-07-12 21:03:41 +08:00
| [`permission` ](../packages/ui/permission ) | `ui` | [`bash` ](../packages/bash/bash ), [`sandbox` ](../packages/sandbox/sandbox ), [`session` ](../packages/core/session ), [`user-approval` ](../packages/ui/user-approval ) |
2026-07-19 13:30:45 +08:00
| [`agent-loop` ](../packages/core/agent-loop ) | `core` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`scope` ](../packages/core/scope ), [`session` ](../packages/core/session ), [`session-persistence` ](../packages/session-persistence/session-persistence ), [`system-prompt` ](../packages/core/system-prompt ), [`tools` ](../packages/core/tools ) |
2026-07-16 16:45:52 +08:00
| [`tool-bash` ](../packages/bash/tool-bash ) | `bash` | [`agent` ](../packages/core/agent ), [`bash` ](../packages/bash/bash ), [`home` ](../packages/util/home ), [`llm` ](../packages/llm/llm ), [`sandbox` ](../packages/sandbox/sandbox ), [`session-persistence` ](../packages/session-persistence/session-persistence ), [`system-prompt` ](../packages/core/system-prompt ), [`tasks` ](../packages/tasks/tasks ), [`tools` ](../packages/core/tools ), [`user-approval` ](../packages/ui/user-approval ) |
2026-07-05 01:25:58 +08:00
| [`tool-fs` ](../packages/fs/tool-fs ) | `fs` | [`fs` ](../packages/fs/fs ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`system-prompt` ](../packages/core/system-prompt ), [`tools` ](../packages/core/tools ) |
2026-07-09 20:44:32 +08:00
| [`tool-fs-search` ](../packages/fs/tool-fs-search ) | `fs` | [`bash` ](../packages/bash/bash ), [`llm` ](../packages/llm/llm ), [`retention` ](../packages/util/retention ), [`session` ](../packages/core/session ), [`spill` ](../packages/spill/spill ), [`system-prompt` ](../packages/core/system-prompt ), [`tools` ](../packages/core/tools ) |
2026-07-10 14:19:06 +08:00
| [`tool-skill` ](../packages/skill/tool-skill ) | `skill` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`skill` ](../packages/skill/skill ), [`tools` ](../packages/core/tools ) |
2026-07-18 14:26:14 +08:00
| [`subagent` ](../packages/subagent/subagent ) | `subagent` | [`agent` ](../packages/core/agent ), [`brand` ](../packages/util/brand ), [`llm` ](../packages/llm/llm ), [`scope` ](../packages/core/scope ), [`session` ](../packages/core/session ), [`tools` ](../packages/core/tools ) |
2026-07-05 01:25:58 +08:00
| [`tool-web` ](../packages/web/tool-web ) | `web` | [`llm` ](../packages/llm/llm ), [`system-prompt` ](../packages/core/system-prompt ), [`tools` ](../packages/core/tools ), [`web` ](../packages/web/web ) |
2026-07-08 19:20:50 +08:00
| [`spill-policy` ](../packages/spill/spill-policy ) | `spill` | [`llm` ](../packages/llm/llm ), [`retention` ](../packages/util/retention ), [`session` ](../packages/core/session ), [`spill` ](../packages/spill/spill ), [`tools` ](../packages/core/tools ) |
2026-07-08 10:06:07 +08:00
| [`timeout-policy` ](../packages/timeout/timeout-policy ) | `timeout` | [`llm` ](../packages/llm/llm ), [`timeout` ](../packages/util/timeout ), [`tools` ](../packages/core/tools ) |
2026-07-05 01:25:58 +08:00
| [`tool-todo` ](../packages/todo/tool-todo ) | `todo` | [`agent` ](../packages/core/agent ), [`session` ](../packages/core/session ), [`tools` ](../packages/core/tools ) |
Merge origin/master: scope-aware fusion of the tools/execute seam, session-prefix, and tool-cordis
Master brought 50 commits (the tool-cordis group, dsh-code-runtime + worker,
the tools/execute around-dispatch seam + timeout-policy, repeat-tool-guard,
agent/session-prefix, the ui reorganization). Beyond the ten textual
conflicts, the merge reconciles master's new seams with this branch's
scoped-registration world:
- tools/execute (new waterfall around core dispatch): dispatched with the
SAME exec.agent carrier as the pre/post waterfalls — an agent.ctx wrapper
times/retries only its own agent's calls — and its base thunk resolves the
tool through the caller's visible view (get(exec.name, exec.agent)), so a
scoped/shadowed tool dispatches and a restricted-away global stays
UNKNOWN_TOOL. Declared this: Scoped<ToolRegistry> with the scope-filtered
doc sentence; invariants table + verify-scoped-dispatch pin it (21 events).
- agent/session-prefix (new waterfall, once per loop instance): composed via
the fused agentEvents dispatcher (scope-filtered like every agent-subject
event), declared this: Scoped<Agent>, table-pinned. agent/pre-step keeps
master's new sessionPrefix parameter with this branch's Scoped this.
- timeout-policy reads the budget through the caller's visible view
(get(exec.name, exec.agent)): a scoped tool's own timeoutMs governs its
calls; a global name-twin's budget is never misapplied to a shadowing
per-agent variant.
- tool-cordis: cordis_inspect's tools section lists the CALLING agent's view
(its description promises "what you can call"); the sandbox tool façade's
reads resolve through the mount's own scope, mirroring where its register
lands writes; sandboxRegisterTool's return type carries the exact-disposer
union honestly. dsh-scope declared as peer+dev with the project reference.
- doc-sync chain unions master's verify-cordis-api with this branch's
verify-scoped-dispatch; the generated catalogs, event matrix (the
zero-dispatcher guard passes over master's new events), module graph, and
the cordis api-catalog are regenerated on the merged surface.
Full gate sequence green on the merged tree: typecheck, lint, per-file 100%
coverage (2668 tests), snapshots (38), doc-sync, module graph, build,
hygiene, demo smoke.
2026-07-09 23:24:42 +08:00
| [`tool-cordis` ](../packages/cordis/tool-cordis ) | `cordis` | [`scope` ](../packages/core/scope ), [`tools` ](../packages/core/tools ) |
2026-07-10 20:52:27 +08:00
| [`hooks-codex` ](../packages/hooks/hooks-codex ) | `hooks` | [`agent` ](../packages/core/agent ), [`hook-protocol` ](../packages/hooks/hook-protocol ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`session-persistence` ](../packages/session-persistence/session-persistence ), [`tools` ](../packages/core/tools ) |
2026-07-19 13:30:45 +08:00
| [`agent-loop-testkit` ](../packages/support/agent-loop-testkit ) | `support` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`system-prompt` ](../packages/core/system-prompt ), [`tools` ](../packages/core/tools ) |
2026-07-15 13:33:42 +08:00
| [`acp` ](../packages/ui/acp ) | `ui` | [`agent` ](../packages/core/agent ), [`bash` ](../packages/bash/bash ), [`llm` ](../packages/llm/llm ), [`permission` ](../packages/ui/permission ), [`sandbox` ](../packages/sandbox/sandbox ), [`session` ](../packages/core/session ), [`session-persistence` ](../packages/session-persistence/session-persistence ), [`system-prompt` ](../packages/core/system-prompt ), [`tools` ](../packages/core/tools ), [`user-approval` ](../packages/ui/user-approval ), [`user-interaction` ](../packages/ui/user-interaction ) |
2026-07-09 17:55:01 +08:00
| [`tool-ask-user` ](../packages/ui/tool-ask-user ) | `ui` | [`agent` ](../packages/core/agent ), [`tools` ](../packages/core/tools ), [`user-interaction` ](../packages/ui/user-interaction ) |
2026-07-16 16:01:06 +08:00
| [`workspace-context` ](../packages/context/workspace-context ) | `context` | [`agent` ](../packages/core/agent ), [`fs` ](../packages/fs/fs ), [`llm` ](../packages/llm/llm ), [`paths` ](../packages/util/paths ), [`session` ](../packages/core/session ), [`tools` ](../packages/core/tools ) |
2026-07-08 14:24:20 +08:00
| [`repeat-tool-guard` ](../packages/guard/repeat-tool-guard ) | `guard` | [`agent` ](../packages/core/agent ), [`tools` ](../packages/core/tools ) |
2026-07-07 23:21:54 +08:00
| [`mcp-client` ](../packages/mcp/mcp-client ) | `mcp` | [`llm` ](../packages/llm/llm ), [`tools` ](../packages/core/tools ) |
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
| [`tool-tasks` ](../packages/tasks/tool-tasks ) | `tasks` | [`agent` ](../packages/core/agent ), [`system-prompt` ](../packages/core/system-prompt ), [`tasks` ](../packages/tasks/tasks ), [`tools` ](../packages/core/tools ) |
2026-07-06 03:14:07 +08:00
| [`tool-workflow` ](../packages/workflow/tool-workflow ) | `workflow` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`system-prompt` ](../packages/core/system-prompt ), [`tools` ](../packages/core/tools ), [`workflow` ](../packages/workflow/workflow ) |
2026-07-15 23:50:33 +08:00
| [`subagent-acp` ](../packages/subagent/subagent-acp ) | `subagent` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`subagent` ](../packages/subagent/subagent ), [`subagent-subprocess` ](../packages/subagent/subagent-subprocess ) |
Structured output on the subagent seam: schema subset, capture runtime, spawn/fork support
Carved out of #170 per review feedback — the foundation the workflow tool
builds on, now standing alone on master:
- dsh-tools: the structured-output JSON Schema subset (StructuredOutputSchema,
assertSupportedOutputSchema, validateStructuredValue) — rejects loud outside
the enforced subset, listing every violation
- dsh-subagent: SubagentStartRequest.outputSchema / SubagentResult.structured
become a real capability; the service rejects a schema'd request whose
provider lacks it
- dsh-subagent-inprocess: the shared structured runtime — one global
structured_output capture tool, a prepend final-assembly listener that
strips the placeholder for plain agents and swaps in the run's own schema
(plus the calling instruction as a trailing section) for structured
children, an agent/turn-continuation veto once captured, and the
capture/nudge loop in the run driver (structuredNudgeRetries, cancellation
honored mid-nudge); lifetime refcounted by backends and live runs
- subagent-spawn / subagent-fork flip outputSchema: true
One deliberate divergence from the #170 revision: the backends do NOT add
'tools' to their plugin inject. Doing so deferred their apply past the todo
plugin, and the delegation tool mirrors provider lifecycle — so the
model-visible tool order of every existing prompt changed, invalidating every
recorded snapshot fixture. The runtime now gates its capture-tool registration
on tools availability itself (sync when live, a scoped inject fiber when the
Loader starts the backend first), keeping this PR byte-invisible to existing
transcripts: all 35 snapshot scenarios pass against master's fixtures
unchanged.
2026-07-06 23:29:08 +08:00
| [`subagent-inprocess` ](../packages/subagent/subagent-inprocess ) | `subagent` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`subagent` ](../packages/subagent/subagent ), [`system-prompt` ](../packages/core/system-prompt ), [`tools` ](../packages/core/tools ) |
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
| [`tool-subagent` ](../packages/subagent/tool-subagent ) | `subagent` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`subagent` ](../packages/subagent/subagent ), [`tasks` ](../packages/tasks/tasks ), [`tools` ](../packages/core/tools ) |
2026-07-10 20:52:27 +08:00
| [`hooks-claude` ](../packages/hooks/hooks-claude ) | `hooks` | [`agent` ](../packages/core/agent ), [`hook-protocol` ](../packages/hooks/hook-protocol ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`session-persistence` ](../packages/session-persistence/session-persistence ), [`subagent` ](../packages/subagent/subagent ), [`tools` ](../packages/core/tools ) |
2026-07-15 23:51:45 +08:00
| [`jsonrpc` ](../packages/ui/jsonrpc ) | `ui` | [`agent` ](../packages/core/agent ), [`llm` ](../packages/llm/llm ), [`llm-deepseek` ](../packages/llm/llm-deepseek ), [`scope` ](../packages/core/scope ), [`session` ](../packages/core/session ), [`subagent` ](../packages/subagent/subagent ) |
2026-07-15 23:50:33 +08:00
| [`stdio` ](../packages/ui/stdio ) | `ui` | [`agent` ](../packages/core/agent ), [`agent-loop` ](../packages/core/agent-loop ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`user-interaction` ](../packages/ui/user-interaction ) |
2026-07-19 11:37:14 +08:00
| [`tui` ](../packages/ui/tui ) | `ui` | [`agent` ](../packages/core/agent ), [`agent-loop` ](../packages/core/agent-loop ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`tools` ](../packages/core/tools ), [`user-interaction` ](../packages/ui/user-interaction ) |
2026-07-17 18:35:48 +08:00
| [`agent-spine-demo` ](../packages/examples/agent-spine-demo ) | `examples` | [`agent` ](../packages/core/agent ), [`agent-loop` ](../packages/core/agent-loop ), [`home` ](../packages/util/home ), [`invariants` ](../packages/support/invariants ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`skill` ](../packages/skill/skill ), [`skill-local` ](../packages/skill/skill-local ), [`system-prompt` ](../packages/core/system-prompt ), [`tasks` ](../packages/tasks/tasks ), [`tool-bash` ](../packages/bash/tool-bash ), [`tool-skill` ](../packages/skill/tool-skill ), [`tool-tasks` ](../packages/tasks/tool-tasks ), [`tools` ](../packages/core/tools ), [`workspace-context` ](../packages/context/workspace-context ) |
2026-07-12 03:51:55 +08:00
| [`workflow-workerthread` ](../packages/workflow/workflow-workerthread ) | `workflow` | [`agent` ](../packages/core/agent ), [`brand` ](../packages/util/brand ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`subagent` ](../packages/subagent/subagent ), [`tools` ](../packages/core/tools ), [`workflow` ](../packages/workflow/workflow ) |
2026-07-05 01:25:58 +08:00
| [`subagent-fork` ](../packages/subagent/subagent-fork ) | `subagent` | [`agent` ](../packages/core/agent ), [`session` ](../packages/core/session ), [`subagent` ](../packages/subagent/subagent ), [`subagent-inprocess` ](../packages/subagent/subagent-inprocess ) |
| [`subagent-spawn` ](../packages/subagent/subagent-spawn ) | `subagent` | [`subagent` ](../packages/subagent/subagent ), [`subagent-inprocess` ](../packages/subagent/subagent-inprocess ) |
2026-07-16 16:01:06 +08:00
| [`acp-demo` ](../packages/examples/acp-demo ) | `examples` | [`acp` ](../packages/ui/acp ), [`agent-spine-demo` ](../packages/examples/agent-spine-demo ), [`app-boot` ](../packages/ui/app-boot ), [`session-persistence-jsonl` ](../packages/session-persistence/session-persistence-jsonl ), [`tools` ](../packages/core/tools ), [`user-interaction` ](../packages/ui/user-interaction ), [`workspace-context` ](../packages/context/workspace-context ) |
2026-07-19 11:37:14 +08:00
| [`stdio-demo` ](../packages/examples/stdio-demo ) | `examples` | [`agent` ](../packages/core/agent ), [`agent-loop` ](../packages/core/agent-loop ), [`agent-spine-demo` ](../packages/examples/agent-spine-demo ), [`app-boot` ](../packages/ui/app-boot ), [`llm` ](../packages/llm/llm ), [`session` ](../packages/core/session ), [`session-persistence-jsonl` ](../packages/session-persistence/session-persistence-jsonl ), [`stdio` ](../packages/ui/stdio ), [`tool-ask-user` ](../packages/ui/tool-ask-user ), [`tools` ](../packages/core/tools ), [`tui` ](../packages/ui/tui ), [`user-interaction` ](../packages/ui/user-interaction ), [`workspace-context` ](../packages/context/workspace-context ) |