2026-07-22 10:55:17 +08:00
|
|
|
{
|
|
|
|
|
"name": "@deepseek-ai/dsh",
|
2026-08-06 04:40:32 +08:00
|
|
|
"description": "dsh CLI: profile boot, plugin management, and the browser UI alias",
|
2026-08-30 21:19:29 +08:00
|
|
|
"version": "0.1.2-alpha.2",
|
2026-08-11 00:02:53 +08:00
|
|
|
"publishConfig": {
|
2026-08-13 18:05:10 +08:00
|
|
|
"access": "public"
|
2026-08-11 00:02:53 +08:00
|
|
|
},
|
|
|
|
|
"repository": {
|
|
|
|
|
"type": "git",
|
|
|
|
|
"url": "git+https://github.com/deepseek-ai/deepseek-harness.git",
|
|
|
|
|
"directory": "apps/cli"
|
|
|
|
|
},
|
2026-07-22 10:55:17 +08:00
|
|
|
"type": "module",
|
|
|
|
|
"bin": {
|
|
|
|
|
"dsh": "lib/bin.js"
|
|
|
|
|
},
|
|
|
|
|
"files": [
|
refactor(preset): bundle the shipped presets inside dsh-agent-presets
Review asked why the launcher special-cases one plugin's row. It no
longer does: the four shipped compositions move into the package
(presets/, in files), dsh-agent-presets resolves its own shipped root
and prepends it before configured roots (includeShippedRoot, default
true, opt-out for bare-machinery embedders), and the per-composition
derived patch, its spec, and the dump layer are deleted — profile-boot
and dump-config return to plain layer stacking. The always-load
guarantee now rides the schema default instead of patch ordering, so a
whole-config replacement keeps the shipped set and the squash, reload
freeze, and dump divergence stop being possible.
Gate globs, the web scaffold, and both preset browser lanes drop their
hand-fed shipped roots; the roster e2e keeps asserting configured roots
beside the shipped four against the built lib.
Fixes #2863.
2026-08-21 12:37:57 +08:00
|
|
|
"lib/*.js"
|
2026-07-22 10:55:17 +08:00
|
|
|
],
|
2026-08-20 19:19:07 +08:00
|
|
|
"dsh": {
|
|
|
|
|
"configTrees": [
|
2026-08-30 02:29:53 +08:00
|
|
|
{
|
|
|
|
|
"mount": "config/agent-presets",
|
|
|
|
|
"path": "../../packages/preset/agent-presets/presets",
|
|
|
|
|
"scanRoster": true
|
|
|
|
|
}
|
2026-08-20 19:19:07 +08:00
|
|
|
]
|
|
|
|
|
},
|
2026-08-13 01:46:57 +08:00
|
|
|
"license": "MIT",
|
2026-07-22 10:55:17 +08:00
|
|
|
"dependencies": {
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/cordis": "workspace:^",
|
fix(release): close the review findings on the release sequences
The root manifest carries the dsh family version. bump writes it with the
members, because the workspace constraint requires them to match, and that
constraint now accepts a prerelease segment: without both, release:dsh 0.0.2
left the root behind and 0.0.1-rc.1 could satisfy neither check.
The Landlock workflow no longer passes --access public, which overrode the
restricted publishConfig this repository just adopted for those packages.
Vendored change detection reads build inputs when a package publishes build
output, and vendor/cordis publishes the src its export map already pointed at:
its lib/ is untracked, so a real source edit read as 'nothing changed' and the
next publish would fail on a version whose bytes moved. The next version also
takes the last published version as its baseline, so a re-sync that restores a
lower upstream version cannot recompute a version already on the registry, and
bump confirms the registry carries what the newest tag names.
Tag prefixes are constructed rather than recovered from a full tag, which a
hyphenated version defeated. Pack runs group per ref so concurrent pull requests
stop displacing each other, the publish job carries the global group, and the
unused id-token permission is gone.
Every release script sits behind an entry guard, which is what lets the pure
judgements carry tests: tag naming, publish order and cycle reporting, version
arithmetic, payload policy, and the change judgement.
The Agent Note moves to implemented and states what shipped: one probe command,
the registry confirmation that now exists, and byte reproducibility recorded as
assumed rather than measured.
2026-08-11 01:26:36 +08:00
|
|
|
"@deepseek-ai/cordis-plugin-hmr": "workspace:^",
|
|
|
|
|
"@deepseek-ai/cordis-plugin-include": "workspace:^",
|
|
|
|
|
"@deepseek-ai/cordis-plugin-loader": "workspace:^",
|
|
|
|
|
"@deepseek-ai/cordis-plugin-timer": "workspace:^",
|
2026-08-23 01:44:10 +08:00
|
|
|
"@deepseek-ai/dsh-acp-app": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-agent-instructions": "workspace:^",
|
2026-08-13 00:36:22 +08:00
|
|
|
"@deepseek-ai/dsh-agent-tool-presentation": "workspace:^",
|
2026-07-22 10:55:20 +08:00
|
|
|
"@deepseek-ai/dsh-app-boot": "workspace:^",
|
2026-08-06 04:40:32 +08:00
|
|
|
"@deepseek-ai/dsh-base": "workspace:^",
|
2026-08-12 23:51:31 +08:00
|
|
|
"@deepseek-ai/dsh-client-ui-agent-preset": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-client-ui-cordis": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-cmdline": "workspace:^",
|
fix(cli): boot the composition test the way the profile boot now does
The shipped surface stopped being two yml files: `base.cordis.yml` and
`web.cordis.yml` are bundle patch layers now, applied over an empty preset
root. This test still opened the old paths, so it failed before asserting
anything. It composes the same two layers the profile boot composes, over the
same empty root, and heals the flat module fallback the way the boot does —
the root lives outside this workspace, so bare plugin names have no other way
to resolve.
The web bundle's runtime row is disabled beside the webserver: it injects
`httpServer`, so a disabled port leaves it pending forever. It owns dist
serving and the URL prompt line, neither of which decides an agent's
capabilities.
`apps/cli` declares the packages the shipped agent presets name again. The
bundle split emptied its plugin dependencies, and the flat fallback links only
the app's dependency closure — so a preset row naming `dsh-persona` resolved
to nothing, and every preset mount failed. Which packages the shipped
presets compose is not implied by any bundle: the presets live beside this
app's config, so this app is what has to declare them.
2026-08-06 21:20:56 +08:00
|
|
|
"@deepseek-ai/dsh-command-compact": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-command-goal": "workspace:^",
|
2026-08-13 00:36:22 +08:00
|
|
|
"@deepseek-ai/dsh-compaction-basic": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-compaction-tool-result-pruner": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-cordis-client-runner": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-fs-local": "workspace:^",
|
fix(cli): boot the composition test the way the profile boot now does
The shipped surface stopped being two yml files: `base.cordis.yml` and
`web.cordis.yml` are bundle patch layers now, applied over an empty preset
root. This test still opened the old paths, so it failed before asserting
anything. It composes the same two layers the profile boot composes, over the
same empty root, and heals the flat module fallback the way the boot does —
the root lives outside this workspace, so bare plugin names have no other way
to resolve.
The web bundle's runtime row is disabled beside the webserver: it injects
`httpServer`, so a disabled port leaves it pending forever. It owns dist
serving and the URL prompt line, neither of which decides an agent's
capabilities.
`apps/cli` declares the packages the shipped agent presets name again. The
bundle split emptied its plugin dependencies, and the flat fallback links only
the app's dependency closure — so a preset row naming `dsh-persona` resolved
to nothing, and every preset mount failed. Which packages the shipped
presets compose is not implied by any bundle: the presets live beside this
app's config, so this app is what has to declare them.
2026-08-06 21:20:56 +08:00
|
|
|
"@deepseek-ai/dsh-goal": "workspace:^",
|
2026-08-13 00:36:22 +08:00
|
|
|
"@deepseek-ai/dsh-goal-round-driver": "workspace:^",
|
2026-08-06 04:40:32 +08:00
|
|
|
"@deepseek-ai/dsh-headless": "workspace:^",
|
2026-08-13 00:36:22 +08:00
|
|
|
"@deepseek-ai/dsh-home-paths": "workspace:^",
|
chore(repo): wire profile apps and the renamed runtime through builds
Update workspace manifests, the lockfile, Host project references, Knip inputs, package constraints, vendoring rewrites, and Python runtime build/smoke scripts for sdk-app, acp-app, and @deepseek-ai/dsh-sdk-python-runtime. Add the ACP hook packages to the dsh dependency closure so installed profile materialization resolves the same plugins as source workspaces.
Keep Python distribution outputs deliberately unchanged: the wheel modules, executable names, and smoke targets retain their public identities even though their private npm carrier moved. Constraint fixtures pin the new package locations and catch missing application dependencies on every platform.
2026-08-23 01:49:21 +08:00
|
|
|
"@deepseek-ai/dsh-hooks-claude-code": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-hooks-codex": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-jobs-local": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-launch-environment": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-mcp-client": "workspace:^",
|
fix(cli): boot the composition test the way the profile boot now does
The shipped surface stopped being two yml files: `base.cordis.yml` and
`web.cordis.yml` are bundle patch layers now, applied over an empty preset
root. This test still opened the old paths, so it failed before asserting
anything. It composes the same two layers the profile boot composes, over the
same empty root, and heals the flat module fallback the way the boot does —
the root lives outside this workspace, so bare plugin names have no other way
to resolve.
The web bundle's runtime row is disabled beside the webserver: it injects
`httpServer`, so a disabled port leaves it pending forever. It owns dist
serving and the URL prompt line, neither of which decides an agent's
capabilities.
`apps/cli` declares the packages the shipped agent presets name again. The
bundle split emptied its plugin dependencies, and the flat fallback links only
the app's dependency closure — so a preset row naming `dsh-persona` resolved
to nothing, and every preset mount failed. Which packages the shipped
presets compose is not implied by any bundle: the presets live beside this
app's config, so this app is what has to declare them.
2026-08-06 21:20:56 +08:00
|
|
|
"@deepseek-ai/dsh-persona": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-plan-mode": "workspace:^",
|
2026-08-07 00:15:55 +08:00
|
|
|
"@deepseek-ai/dsh-pwsh-local": "workspace:^",
|
2026-08-08 13:44:05 +08:00
|
|
|
"@deepseek-ai/dsh-pwsh-sandbox": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-schedule": "workspace:^",
|
feat(profiles): add the SDK application bundle
Introduce @deepseek-ai/dsh-sdk-app as the thin application layer for the built-in sdk profile. The bundle contributes the JSON-RPC server and startup-only profile metadata, while dsh-base continues to own the shared agent, provider, persistence, and tool composition.
Publish ctx.appReady from the launcher only after the Loader tree and launcher-owned setup succeed. The stdio lifetime binding leaves stdin unread until the protocol transport claims it and defers EOF exit 0 until readiness commits, so early protocol frames remain buffered and a racing startup failure remains the nonzero process outcome. Fiber disposal cancels both pending lifecycle listeners.
Register the bundle in the CLI resolver closure, generated configuration catalog, workspace graph, and built-bin smoke. Startup tests prove that base plus sdk-app exposes the SDK server without taking ownership of shared runtime plugins; focused and built-bin regressions cover early input, EOF readiness, and startup-error precedence.
2026-08-23 01:43:36 +08:00
|
|
|
"@deepseek-ai/dsh-sdk-app": "workspace:^",
|
feat(bundle): ship the standalone sdk-minimal profile
Add a startup-only sdk-minimal template whose sole bundle inserts the complete JSON-RPC agent tree over the empty profile root. The roster is an explicit composition allowlist: it contains one DeepSeek adapter, the minimal agent spine, persistent Bash, the string-replace editor, local execution, and JSONL persistence, while dsh-base and Web remain absent.
Reuse the SDK app startup provider so the new profile retains help, stdin EOF, and bounded launcher shutdown semantics. Make that provider render its configured profile name, which keeps both sdk and sdk-minimal help truthful without duplicating process lifecycle code.
Register the package in the CLI closure, TypeScript graph, lockfile, Knip policy, and bilingual bundle references. Exact manifest, row-roster, profile-template, config-dump, and HMR tests make later additions visible instead of relying on a blacklist.
2026-08-24 14:50:41 +08:00
|
|
|
"@deepseek-ai/dsh-sdk-minimal": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-session-projection": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-session-reference": "workspace:^",
|
fix(cli): boot the composition test the way the profile boot now does
The shipped surface stopped being two yml files: `base.cordis.yml` and
`web.cordis.yml` are bundle patch layers now, applied over an empty preset
root. This test still opened the old paths, so it failed before asserting
anything. It composes the same two layers the profile boot composes, over the
same empty root, and heals the flat module fallback the way the boot does —
the root lives outside this workspace, so bare plugin names have no other way
to resolve.
The web bundle's runtime row is disabled beside the webserver: it injects
`httpServer`, so a disabled port leaves it pending forever. It owns dist
serving and the URL prompt line, neither of which decides an agent's
capabilities.
`apps/cli` declares the packages the shipped agent presets name again. The
bundle split emptied its plugin dependencies, and the flat fallback links only
the app's dependency closure — so a preset row naming `dsh-persona` resolved
to nothing, and every preset mount failed. Which packages the shipped
presets compose is not implied by any bundle: the presets live beside this
app's config, so this app is what has to declare them.
2026-08-06 21:20:56 +08:00
|
|
|
"@deepseek-ai/dsh-skill": "workspace:^",
|
2026-08-13 00:36:22 +08:00
|
|
|
"@deepseek-ai/dsh-skill-filesystem": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-terminal": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-terminal-bash": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-time-context": "workspace:^",
|
2026-08-06 09:27:44 +08:00
|
|
|
"@deepseek-ai/dsh-tmux-context": "workspace:^",
|
fix(cli): boot the composition test the way the profile boot now does
The shipped surface stopped being two yml files: `base.cordis.yml` and
`web.cordis.yml` are bundle patch layers now, applied over an empty preset
root. This test still opened the old paths, so it failed before asserting
anything. It composes the same two layers the profile boot composes, over the
same empty root, and heals the flat module fallback the way the boot does —
the root lives outside this workspace, so bare plugin names have no other way
to resolve.
The web bundle's runtime row is disabled beside the webserver: it injects
`httpServer`, so a disabled port leaves it pending forever. It owns dist
serving and the URL prompt line, neither of which decides an agent's
capabilities.
`apps/cli` declares the packages the shipped agent presets name again. The
bundle split emptied its plugin dependencies, and the flat fallback links only
the app's dependency closure — so a preset row naming `dsh-persona` resolved
to nothing, and every preset mount failed. Which packages the shipped
presets compose is not implied by any bundle: the presets live beside this
app's config, so this app is what has to declare them.
2026-08-06 21:20:56 +08:00
|
|
|
"@deepseek-ai/dsh-token-meter": "workspace:^",
|
2026-08-06 09:27:44 +08:00
|
|
|
"@deepseek-ai/dsh-tool-ask-user": "workspace:^",
|
fix(cli): boot the composition test the way the profile boot now does
The shipped surface stopped being two yml files: `base.cordis.yml` and
`web.cordis.yml` are bundle patch layers now, applied over an empty preset
root. This test still opened the old paths, so it failed before asserting
anything. It composes the same two layers the profile boot composes, over the
same empty root, and heals the flat module fallback the way the boot does —
the root lives outside this workspace, so bare plugin names have no other way
to resolve.
The web bundle's runtime row is disabled beside the webserver: it injects
`httpServer`, so a disabled port leaves it pending forever. It owns dist
serving and the URL prompt line, neither of which decides an agent's
capabilities.
`apps/cli` declares the packages the shipped agent presets name again. The
bundle split emptied its plugin dependencies, and the flat fallback links only
the app's dependency closure — so a preset row naming `dsh-persona` resolved
to nothing, and every preset mount failed. Which packages the shipped
presets compose is not implied by any bundle: the presets live beside this
app's config, so this app is what has to declare them.
2026-08-06 21:20:56 +08:00
|
|
|
"@deepseek-ai/dsh-tool-bash": "workspace:^",
|
2026-07-31 14:28:52 +08:00
|
|
|
"@deepseek-ai/dsh-tool-bash-persistent": "workspace:^",
|
2026-07-30 20:25:13 +08:00
|
|
|
"@deepseek-ai/dsh-tool-cordis": "workspace:^",
|
fix(cli): boot the composition test the way the profile boot now does
The shipped surface stopped being two yml files: `base.cordis.yml` and
`web.cordis.yml` are bundle patch layers now, applied over an empty preset
root. This test still opened the old paths, so it failed before asserting
anything. It composes the same two layers the profile boot composes, over the
same empty root, and heals the flat module fallback the way the boot does —
the root lives outside this workspace, so bare plugin names have no other way
to resolve.
The web bundle's runtime row is disabled beside the webserver: it injects
`httpServer`, so a disabled port leaves it pending forever. It owns dist
serving and the URL prompt line, neither of which decides an agent's
capabilities.
`apps/cli` declares the packages the shipped agent presets name again. The
bundle split emptied its plugin dependencies, and the flat fallback links only
the app's dependency closure — so a preset row naming `dsh-persona` resolved
to nothing, and every preset mount failed. Which packages the shipped
presets compose is not implied by any bundle: the presets live beside this
app's config, so this app is what has to declare them.
2026-08-06 21:20:56 +08:00
|
|
|
"@deepseek-ai/dsh-tool-fs": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-fs-search": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-goal": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-tool-jobs": "workspace:^",
|
2026-08-07 00:15:55 +08:00
|
|
|
"@deepseek-ai/dsh-tool-pwsh": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-tool-pwsh-persistent": "workspace:^",
|
fix(cli): boot the composition test the way the profile boot now does
The shipped surface stopped being two yml files: `base.cordis.yml` and
`web.cordis.yml` are bundle patch layers now, applied over an empty preset
root. This test still opened the old paths, so it failed before asserting
anything. It composes the same two layers the profile boot composes, over the
same empty root, and heals the flat module fallback the way the boot does —
the root lives outside this workspace, so bare plugin names have no other way
to resolve.
The web bundle's runtime row is disabled beside the webserver: it injects
`httpServer`, so a disabled port leaves it pending forever. It owns dist
serving and the URL prompt line, neither of which decides an agent's
capabilities.
`apps/cli` declares the packages the shipped agent presets name again. The
bundle split emptied its plugin dependencies, and the flat fallback links only
the app's dependency closure — so a preset row naming `dsh-persona` resolved
to nothing, and every preset mount failed. Which packages the shipped
presets compose is not implied by any bundle: the presets live beside this
app's config, so this app is what has to declare them.
2026-08-06 21:20:56 +08:00
|
|
|
"@deepseek-ai/dsh-tool-ralph": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-skill": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-str-replace-editor": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-subagent": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-subagent-control": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-todo": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-web": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-tool-workflow": "workspace:^",
|
2026-08-06 04:40:32 +08:00
|
|
|
"@deepseek-ai/dsh-web-app": "workspace:^",
|
2026-08-22 23:44:56 +08:00
|
|
|
"@deepseek-ai/dsh-webhook": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-webhook-github": "workspace:^",
|
2026-08-13 00:36:22 +08:00
|
|
|
"@deepseek-ai/dsh-workflow-worker-thread": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/schemastery": "workspace:^",
|
2026-07-25 12:02:28 +08:00
|
|
|
"commander": "^15.0.0",
|
2026-08-03 23:04:45 +08:00
|
|
|
"js-yaml": "^4.2.0",
|
|
|
|
|
"node-addon-require-builtin": "^0.1.4"
|
2026-07-25 01:19:47 +08:00
|
|
|
},
|
|
|
|
|
"devDependencies": {
|
chore(repo): wire profile apps and the renamed runtime through builds
Update workspace manifests, the lockfile, Host project references, Knip inputs, package constraints, vendoring rewrites, and Python runtime build/smoke scripts for sdk-app, acp-app, and @deepseek-ai/dsh-sdk-python-runtime. Add the ACP hook packages to the dsh dependency closure so installed profile materialization resolves the same plugins as source workspaces.
Keep Python distribution outputs deliberately unchanged: the wheel modules, executable names, and smoke targets retain their public identities even though their private npm carrier moved. Constraint fixtures pin the new package locations and catch missing application dependencies on every platform.
2026-08-23 01:49:21 +08:00
|
|
|
"@agentclientprotocol/sdk": "1.4.0",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-acp": "workspace:^",
|
2026-08-07 15:33:56 +08:00
|
|
|
"@deepseek-ai/dsh-agent": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-attachment-local": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-bash-local": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-credentials-local": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-deepseek-llm-api-extensions": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-experimental-agent-team": "workspace:^",
|
2026-08-25 11:42:33 +08:00
|
|
|
"@deepseek-ai/dsh-experimental-agent-team-profile": "workspace:^",
|
2026-08-28 16:52:07 +08:00
|
|
|
"@deepseek-ai/dsh-experimental-code-runtime-python": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-experimental-tool-agent-team": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-fs-observation-policy": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-fs-sandbox": "workspace:^",
|
2026-08-13 00:36:22 +08:00
|
|
|
"@deepseek-ai/dsh-host-frontend-static": "workspace:^",
|
2026-08-06 04:40:32 +08:00
|
|
|
"@deepseek-ai/dsh-host-webserver": "workspace:^",
|
2026-08-07 15:33:56 +08:00
|
|
|
"@deepseek-ai/dsh-llm": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-llm-deepseek": "workspace:^",
|
2026-08-07 21:41:22 +08:00
|
|
|
"@deepseek-ai/dsh-llm-mock-server": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-llm-pi-ai": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-llm-replay": "workspace:^",
|
2026-08-06 04:40:32 +08:00
|
|
|
"@deepseek-ai/dsh-loader-smoke": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-plugin-package-inventory-deepseek": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-sandbox-local": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-sandbox-policy": "workspace:^",
|
2026-08-07 15:33:56 +08:00
|
|
|
"@deepseek-ai/dsh-session": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-session-checkpoint-policy": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-session-log-deepseek": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-session-persistence-jsonl": "workspace:^",
|
2026-08-25 06:08:14 +08:00
|
|
|
"@deepseek-ai/dsh-session-query": "workspace:^",
|
2026-08-27 16:05:51 +08:00
|
|
|
"@deepseek-ai/dsh-shell-env": "workspace:^",
|
feat(agent-presets): make the default preset a user setting
`config.default` becomes the composition base of an `agent-presets` settings
namespace, so the user document layers over the deployment's engineering
default and a person can change which preset new sessions get without a
restart.
The value is read per resolution rather than snapshotted: a hot-reloaded
document takes effect on the next session created, and every running session
stays on the preset it was composed from — which is the same rule the
session-header guard enforces from the other side.
`resolve()` read `config.default` directly, which would have made the whole
setting inert; it now goes through `defaultId` like every other caller.
The write-protection test is rewritten against a temp profile root. It was
passing vacuously: the un-overridden Loader REWRITES the composition it read —
stamping `disabled: true` onto the self-disposing row — so the committed
fixture had been mutated by the very run that proved the bug, and every later
run compared against the damaged file and passed. Building the preset in a
temp directory makes the assertion immune to its own failure mode, and it now
fails with a visible `+ disabled: true` when the override is removed.
Review follow-ups on this layer. The exported schema is
`AgentPresetSettingsSchema`, symmetric with the `AgentPresetSettings`
interface it resolves and self-describing at an import site. The `session.create`
JSDoc promised "the deployment's default preset" for an omitted `agentPreset`,
which this layer makes false — it now names the effective default. The
constructor records why it does not use `installSettingsSection`: that helper
re-judges what a consumer DERIVED across attach and detach, and nothing here is
derived. The provider-unload test disposes the fiber `ctx.plugin()` handed back
instead of reaching into `ctx.reflect.store`, and the write-protection wait says
why slack is the right shape for an absence assertion.
The real composition covers the layering too. `apps/cli` boots the shipped
`cordis.yml`, stores `agent-presets.default`, and asserts an unnamed session
composes from it — the package suite proves the layering against a hand-built
context, this proves the roster and the settings provider are wired to each
other. That test also pins the settings row at a temp file: it defaulted to
`$DSH_HOME/settings.yaml`, so a developer's own stored default decided the
outcome of a file whose whole point is that only the shipped root does.
The Agent Note records the per-resolution read and its correspondence with the
session header, and the vacuous-test finding above.
2026-08-04 00:07:11 +08:00
|
|
|
"@deepseek-ai/dsh-settings": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-settings-file": "workspace:^",
|
fix(subagent): compose children from their parent's preset
Tool and prompt-section visibility is inherited along dsh-scope's parent
chain, and an agent's scope key is minted with no parent. Per-session agent
presets moved every model-facing row onto the agent plane and made
AgentPresets.mount() the one thing that binds that link, from the api-proxy's
session create, resume, and fork paths. The two in-process subagent drivers
installed only the per-child persona and tool filter, so a child's scope chain
had length one and its registry view resolved the global layer alone — which
is empty wherever a preset roster is composed. One-shot children reached the
model with no tools, continuable ones with only the host-plane `report`, and
neither carried its parent's persona, workspace context, or skill catalog.
AgentPresets.composeFrom() joins one agent to the standing composition another
already runs on. It is a bind, not a mount: the child gets its parent's exact
generation, so a composition edited since the parent started cannot fork it
onto another one, and it is synchronous, which is what lets a child creation
window use it. applyChildComposition() now takes the parent and performs the
join first, making a child composed without it unrepresentable at the call
sites. childSessionMeta() records the joined id so a cold read rebuilds the
composition the child actually ran under.
The audit that followed found two api-proxy readers on the wrong authority:
presenterScopeFor() and the live-agent branch of assertPresetUnchanged() both
read header.agentPreset, which goes stale the moment a blank session switches
preset. A switched session's cold transcript resolved presenters in the older
composition's layer and silently degraded to generic cards, and the gateway
refused to adopt a live session under the preset it actually runs while
accepting the one it left. Both now resolve through resolveSessionPreset(),
matching the resume branch fifteen lines above. The owning architecture Agent
Note carried the stale claim that the header records what a session runs; it
is corrected to name the header/log pair and its three readers.
Fixes #2165
2026-08-10 17:46:34 +08:00
|
|
|
"@deepseek-ai/dsh-subagent": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-subagent-fork-in-process": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-subagent-spawn-in-process": "workspace:^",
|
|
|
|
|
"@deepseek-ai/dsh-subprocess-local": "workspace:^",
|
2026-08-06 04:40:32 +08:00
|
|
|
"@deepseek-ai/dsh-system-prompt": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-tool-subagent-report": "workspace:^",
|
2026-08-30 02:29:53 +08:00
|
|
|
"@deepseek-ai/dsh-tools": "workspace:^",
|
2026-08-24 10:00:15 +08:00
|
|
|
"@deepseek-ai/dsh-user-approval": "workspace:^",
|
refactor(cli)!: one shared base config with per-surface overlays
`dsh` shipped two config trees that were 43 rows the same: apps/cli/cordis.yml
composed web as 74 flat rows, while the TUI booted examples/tui-agent/cordis.yml
whose single `@deepseek-ai/dsh-tui-demo` row mounted twelve plugins behind a
twenty-key pass-through Config. Neither file was what its location claimed —
apps/cli hardcoded the "example" as the product default and the "demo" bundle
was the application — and every capability change had to be made twice.
- apps/cli/base.cordis.yml holds the 43 shared rows; tui.cordis.yml and
web.cordis.yml are patch lists stating only what differs per surface
- overlays apply as SIBLING patch lists at one include level, because include
patches never cross an include boundary. Precedence: base < surface <
(--config | personal ~/.dsh/config.yaml) < launcher flag/profile patches
- `--config` now applies an overlay INSTEAD OF the personal one, so a demo or
test tree never inherits the user's route; new `--config-replace` boots a file
as the entire tree (the old `--config` behaviour). Both survive /resume
- vendor/include: index each `insert`ed row as it is added so a later patch can
configure or disable it. Upstream built the id index once before the patch
loop, leaving every surface-only row — the whole TUI front door — silently
unpatchable from user config. Logged as local modification 8
- session identity moves to dsh-agent-loop's CONFIGURED_AGENT_IDENTITIES_KEY;
dsh-tui's MAIN_SESSION_ID_KEY is deleted (only the bundle read it)
- delete examples/tui-agent, examples/cordis-agent, packages/examples/tui-demo;
TUI tests → apps/cli/tests, cordis e2e → packages/cordis/tool-cordis/tests,
examples/code-mode survives as an overlay leaf
- `dsh web` gains --config, threaded into AppCLIEntry as an extra overlay
Three latent defects surfaced and are fixed here: the TUI captured the optional
sessionQuery service once at construction and could permanently disable /resume
when it won the mount race; the session-store root silently reverted to a
project-local ./.sessions; --config-replace was dropped by the resume handoff.
Verified by booting each tree through the real Loader (TUI 55 entries, web 75,
zero unsettled) rather than reading YAML. All eight terminal snapshots replay
byte-identically; 14/14 PTY smoke, 112/112 snapshots, 25/25 doc-sync, hygiene
and lint clean.
2026-07-29 13:58:21 +08:00
|
|
|
"@types/js-yaml": "^4.0.9",
|
2026-08-25 00:59:04 +08:00
|
|
|
"@types/ws": "8.18.1",
|
|
|
|
|
"execa": "^10.0.0",
|
|
|
|
|
"ws": "8.21.0"
|
2026-07-22 10:55:17 +08:00
|
|
|
}
|
|
|
|
|
}
|