2026-07-03 01:13:52 +08:00
<!-- Generated by scripts/gen - doc - graphs.ts - do not edit by hand.
Run `pnpm run gen-doc-graphs` to regenerate. -->
# Capability Seams And Core Services
A service can be a core spine service, a swappable capability seam, or a bundle/composition point. The graph shows the package that owns the service declaration, known implementation packages, and packages that consume the service directly.
```mermaid
flowchart LR
2026-07-23 15:20:47 +08:00
pkg_attachment["attachment"]
svc_attachments["ctx.attachments< br / > Durable binary attachment storage"]
pkg_attachment_local["attachment-local"]
pkg_host_runtime["host-runtime"]
pkg_llm_pi_ai["llm-pi-ai"]
2026-07-03 01:13:52 +08:00
pkg_llm["llm"]
svc_llm["ctx.llm< br / > LLM adapter registry"]
pkg_llm_deepseek["llm-deepseek"]
pkg_llm_replay["llm-replay"]
pkg_agent_loop["agent-loop"]
2026-08-13 00:36:22 +08:00
pkg_compaction_basic["compaction-basic"]
2026-08-22 20:03:23 +08:00
pkg_deepseek_llm_api_extensions["deepseek-llm-api-extensions"]
svc_deepseekLlmApiExtensions["ctx.deepseekLlmApiExtensions< br / > Official DeepSeek request extensions"]
2026-08-22 02:02:38 +08:00
pkg_session_log_deepseek["session-log-deepseek"]
2026-08-22 20:03:23 +08:00
pkg_plugin_package_inventory_deepseek["plugin-package-inventory-deepseek"]
2026-07-15 14:47:29 +08:00
pkg_token_meter["token-meter"]
svc_tokenMeter["ctx.tokenMeter< br / > Replay token measurement"]
2026-08-13 00:36:22 +08:00
pkg_compaction_tool_result_pruner["compaction-tool-result-pruner"]
svc_toolResultPruner["ctx.toolResultPruner< br / > Model-free tool-result pruning"]
2026-07-03 01:13:52 +08:00
pkg_session["session"]
svc_sessions["ctx.sessions< br / > In-memory session store"]
pkg_agent["agent"]
pkg_session_persistence["session-persistence"]
2026-07-10 16:51:19 +08:00
pkg_session_query["session-query"]
2026-07-15 10:51:38 +08:00
pkg_session_query_sqlite["session-query-sqlite"]
2026-07-03 01:13:52 +08:00
pkg_subagent_inprocess["subagent-inprocess"]
pkg_invariants["invariants"]
2026-08-10 11:28:38 -07:00
pkg_message_feedback["message-feedback"]
2026-08-22 21:13:53 +08:00
pkg_api_session_controller["api-session-controller"]
svc_sessionController["ctx.sessionController< br / > Host Session Remote controller"]
pkg_apiproxy["apiproxy"]
2026-08-23 06:14:32 +08:00
pkg_api_workspace_controller["api-workspace-controller"]
svc_workspaceController["ctx.workspaceController< br / > Host Workspace Remote controller"]
2026-07-19 19:19:57 +08:00
svc_invariants["ctx.invariants< br / > Package-owned invariant registry"]
pkg_scope["scope"]
2026-07-28 23:48:35 +08:00
pkg_typert_registry["typert-registry"]
svc_typert["ctx.typert< br / > Runtime type registry"]
pkg_typert_loader["typert-loader"]
2026-08-05 11:17:47 +08:00
pkg_api_gateway["api-gateway"]
2026-08-13 00:36:22 +08:00
svc_typertGateway["ctx.typertGateway< br / > Typert Host invocation gateway"]
2026-07-03 01:13:52 +08:00
svc_sessionPersistence["ctx.sessionPersistence< br / > Durable session persistence seam"]
pkg_session_persistence_jsonl["session-persistence-jsonl"]
pkg_session_persistence_sqlite["session-persistence-sqlite"]
fix(bash): close managed environment review gaps
The managed DSH_* runtime path was correct, but its public extension and documentation contracts were incomplete. A contributor following the README could access ctx.bashEnv without declaring an injection, the new environment types had no drift-checked catalog entries, and the capability graph omitted three packages that now query sessionPersistence.
Declare the README injection, catalog DshEnvironmentKey and DshEnvironment, and add tool-bash plus both hook bridges to the generated persistence consumer graph. Keep BashEnvRegistry.list() contributor-only for now because no production caller treats it as exhaustive, but record the built-in enumeration gap before diagnostics, prompt, or UI code depends on it.
Validated on the exact resulting tree with typecheck, lint, coverage, snapshot, documentation, module-graph, build, hygiene, demo-smoke, and built-artifact checks.
2026-07-15 00:04:00 +08:00
pkg_tool_bash["tool-bash"]
2026-08-13 00:36:22 +08:00
pkg_hooks_claude_code["hooks-claude-code"]
fix(bash): close managed environment review gaps
The managed DSH_* runtime path was correct, but its public extension and documentation contracts were incomplete. A contributor following the README could access ctx.bashEnv without declaring an injection, the new environment types had no drift-checked catalog entries, and the capability graph omitted three packages that now query sessionPersistence.
Declare the README injection, catalog DshEnvironmentKey and DshEnvironment, and add tool-bash plus both hook bridges to the generated persistence consumer graph. Keep BashEnvRegistry.list() contributor-only for now because no production caller treats it as exhaustive, but record the built-in enumeration gap before diagnostics, prompt, or UI code depends on it.
Validated on the exact resulting tree with typecheck, lint, coverage, snapshot, documentation, module-graph, build, hygiene, demo-smoke, and built-artifact checks.
2026-07-15 00:04:00 +08:00
pkg_hooks_codex["hooks-codex"]
feat(settings): add user-settings seam (ctx.settings) + file provider
Two-package capability family mirroring session-persistence/:
- dsh-settings: abstract Settings service — namespace registry with
caller-fiber effect registrations, layered resolution (schema defaults
< composition base < user document), schemastery validation,
per-namespace deep-equal commit detection, and the settings/updated
event. Boot/registration validation fails loud; provider publishes
keep last-good per namespace.
- dsh-settings-local: settings.yaml/.json provider — resolveSpec
defaulting to $DSH_HOME/settings.yaml, chokidar hot reload,
content-equality self-write suppression, atomic 0600 tmp+rename
writes, comment-preserving YAML namespace patching.
Consumers register inside ctx.inject(['settings'], …), so every
composition works unchanged without a mounted provider. Real Loader +
Include composition test proves cordis.yml boot and external-edit hot
propagation; HMR disposal test proves registry cleanup. Both packages
hold per-file 100% coverage.
Doc budgets rise 1705→1710 (AGENTS.md) and 835→845 (packages/README.md):
one structural line per file for the new package group.
Agent Note: .agents/notes/implemented/architecture/2026-07-28-user-settings-seam.md
2026-07-28 17:30:12 +08:00
pkg_settings["settings"]
svc_settings["ctx.settings< br / > User-settings seam"]
2026-08-13 00:36:22 +08:00
pkg_settings_file["settings-file"]
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
pkg_credentials["credentials"]
svc_credentials["ctx.credentials< br / > Credential seam"]
pkg_credentials_local["credentials-local"]
2026-08-13 15:33:29 +08:00
pkg_authorization["authorization"]
svc_authorization["ctx.authorization< br / > Authorization flow registry"]
2026-07-23 03:06:57 +08:00
pkg_session_telemetry["session-telemetry"]
2026-08-13 00:36:22 +08:00
svc_sessionTelemetry["ctx.sessionTelemetry< br / > Session telemetry seam"]
2026-07-23 03:06:57 +08:00
pkg_session_telemetry_otel["session-telemetry-otel"]
chore(storage,workspace): gates — coverage, catalogs, bilingual note
- Per-file 100% coverage across the five new packages (invariant
companion suites, failure-injection negatives, lifecycle and
malformed-medium branches).
- Canonical README Model Experience / Known Limitations sections; new
storage/ and workspace/ group READMEs; packages/README.md rows (budget
ceiling raised 760 → 790 for the two new groups).
- Cordis catalog/type-link registrations, service-role classification,
and regenerated catalogs/graphs for the new services and events.
- Agent Note: English body + i18n pairing record; design-sketch fences
opted out of doc-typecheck as ignore-check.
- Two exactOptionalPropertyTypes/discriminant fixes in new tests.
doc-sync (24 gates), typecheck, hygiene, and the five-package suite
(92 tests) all pass.
2026-07-24 22:49:57 +08:00
pkg_storage["storage"]
svc_storage["ctx.storage< br / > Non-session storage hub"]
pkg_storage_json["storage-json"]
pkg_storage_sqlite["storage-sqlite"]
2026-07-25 01:11:39 +08:00
pkg_storage_domain["storage-domain"]
2026-07-25 16:04:48 +08:00
svc_storageDomain["ctx.storageDomain< br / > Domain data facility"]
chore(storage,workspace): gates — coverage, catalogs, bilingual note
- Per-file 100% coverage across the five new packages (invariant
companion suites, failure-injection negatives, lifecycle and
malformed-medium branches).
- Canonical README Model Experience / Known Limitations sections; new
storage/ and workspace/ group READMEs; packages/README.md rows (budget
ceiling raised 760 → 790 for the two new groups).
- Cordis catalog/type-link registrations, service-role classification,
and regenerated catalogs/graphs for the new services and events.
- Agent Note: English body + i18n pairing record; design-sketch fences
opted out of doc-typecheck as ignore-check.
- Two exactOptionalPropertyTypes/discriminant fixes in new tests.
doc-sync (24 gates), typecheck, hygiene, and the five-package suite
(92 tests) all pass.
2026-07-24 22:49:57 +08:00
pkg_workspace["workspace"]
2026-08-10 11:28:38 -07:00
svc_messageFeedback["ctx.messageFeedback< br / > Lifecycle-bound message feedback"]
2026-08-13 00:36:22 +08:00
svc_workspaceRegistry["ctx.workspaceRegistry< br / > Workspace entity registry"]
2026-07-23 20:16:14 +08:00
svc_sessionQuery["ctx.sessionQuery< br / > Session reads, traces, filters, and search"]
2026-07-21 16:46:48 +08:00
pkg_session_reference["session-reference"]
2026-07-24 15:09:55 +08:00
pkg_tool_session_query["tool-session-query"]
2026-07-27 15:25:33 +08:00
pkg_file_reference["file-reference"]
2026-08-14 16:18:40 +08:00
svc_fileReferences["ctx.fileReferences< br / > File reference discovery"]
2026-07-27 15:25:33 +08:00
pkg_file_reference_local["file-reference-local"]
2026-08-13 00:36:22 +08:00
svc_sessionReferenceResolver["ctx.sessionReferenceResolver< br / > Cross-session snapshot preparation"]
2026-07-21 01:54:00 +08:00
pkg_session_title["session-title"]
svc_sessionTitle["ctx.sessionTitle< br / > Log-backed session titles"]
2026-08-13 00:36:22 +08:00
pkg_session_title_first_prompt_llm["session-title-first-prompt-llm"]
pkg_session_title_all_prompts_llm["session-title-all-prompts-llm"]
2026-07-03 01:13:52 +08:00
pkg_system_prompt["system-prompt"]
svc_systemPrompt["ctx.systemPrompt< br / > System prompt assembly registry"]
pkg_tools["tools"]
2026-07-04 12:50:06 +08:00
pkg_tool_fs["tool-fs"]
2026-08-13 00:36:22 +08:00
pkg_tool_terminal["tool-terminal"]
2026-07-04 12:50:06 +08:00
pkg_tool_web["tool-web"]
2026-07-11 22:55:40 +08:00
svc_tools["ctx.tools< br / > Tool registry and guarded execution pipeline"]
2026-07-05 17:05:33 +08:00
pkg_tool_ask_user["tool-ask-user"]
2026-07-08 11:50:12 +08:00
pkg_tool_cordis["tool-cordis"]
2026-07-05 16:50:29 +08:00
pkg_tool_skill["tool-skill"]
2026-07-03 01:13:52 +08:00
pkg_tool_subagent["tool-subagent"]
pkg_tool_todo["tool-todo"]
2026-08-13 00:36:22 +08:00
pkg_user_questions["user-questions"]
svc_userQuestions["ctx.userQuestions< br / > Human question/answer seam"]
2026-07-22 16:57:23 +08:00
pkg_plan_mode["plan-mode"]
svc_planMode["ctx.planMode< br / > Plan collaboration state"]
2026-08-08 14:04:53 +08:00
pkg_agent_presets["agent-presets"]
svc_agentPresets["ctx.agentPresets< br / > Per-session agent composition"]
2026-07-19 22:11:59 +08:00
pkg_commands["commands"]
svc_commands["ctx.commands< br / > Human command registry"]
2026-07-28 01:09:55 +08:00
pkg_session_projection["session-projection"]
svc_sessionProjections["ctx.sessionProjections< br / > Session projection units"]
pkg_host_apiproxy["host-apiproxy"]
2026-07-28 02:11:31 +08:00
pkg_session_projection_cache["session-projection-cache"]
svc_sessionProjectionCache["ctx.sessionProjectionCache< br / > Persisted projection cache"]
2026-07-05 16:50:29 +08:00
pkg_skill["skill"]
2026-07-08 15:50:38 +08:00
svc_skills["ctx.skills< br / > Skill provider registry"]
2026-08-05 21:50:44 +08:00
pkg_skill_badge["skill-badge"]
2026-08-13 00:36:22 +08:00
pkg_skill_filesystem["skill-filesystem"]
2026-07-19 13:30:45 +08:00
svc_agents["ctx.agents< br / > Agent service"]
2026-07-24 01:40:25 +08:00
pkg_acp["acp"]
2026-08-09 12:13:58 +08:00
pkg_agent_default_model["agent-default-model"]
svc_agentDefaultModel["ctx.agentDefaultModel< br / > Default Agent model selection"]
pkg_headless["headless"]
2026-07-03 01:13:52 +08:00
svc_agentLoop["ctx.agentLoop< br / > Concrete loop driver"]
2026-07-15 15:57:57 +08:00
pkg_agent_spine_demo["agent-spine-demo"]
2026-07-19 18:47:34 +08:00
pkg_goal["goal"]
svc_goals["ctx.goals< br / > Same-session goal domain"]
2026-08-07 21:04:33 +08:00
pkg_e2b["e2b"]
svc_e2b["ctx.e2b< br / > E2B sandbox lifecycle owner"]
pkg_fs_e2b["fs-e2b"]
pkg_subprocess_e2b["subprocess-e2b"]
2026-07-26 14:10:46 +08:00
pkg_subprocess["subprocess"]
svc_subprocess["ctx.subprocess< br / > Subprocess seam"]
pkg_subprocess_local["subprocess-local"]
2026-07-03 01:13:52 +08:00
pkg_bash_local["bash-local"]
2026-07-09 16:05:44 +08:00
pkg_bash_sandbox["bash-sandbox"]
2026-08-13 00:36:22 +08:00
pkg_terminal_bash["terminal-bash"]
pkg_lsp_stdio["lsp-stdio"]
feat(subprocess): migrate lsp-local, subagent-acp, and the env scrubs onto the seam
Review direction (tianyicui, PR #660): in a stacked PR, change all other
process-running places to use the new service.
- lsp-local: LspConnection spawns through ctx.subprocess (piped protocol
streams + a no-spill collected stderr tail); its private process-tree
helpers (POSIX group signalling, Windows taskkill, liveness polling) are
deleted in favor of the seam's handle verbs, and its buildChildEnv now
rides scrubbedParentEnv (LSP children also stop inheriting stale DSH_*).
The plugin injects 'subprocess'; compositions/tests mount
dsh-subprocess-local.
- subagent-acp: the ACP child spawns through the seam (piped ndjson streams,
inherited stderr); spawn failure surfaces through done-rejection into the
same startup race; disposal is handle.dispose with the plugin's configured
graces. dsh-subagent-subprocess is DELETED — its dispose ladder and scrub
are the seam's, and the isolated-config-dir helper had no consumer.
- mcp-client, pty-local, sdk-helper: adopt scrubbedParentEnv as the one
scrub definition (their spawns stay put by ownership: the MCP SDK and
node-pty own those calls; the SDK wizard runs outside any composition).
- Coverage: per-file 100% over every touched src file, with each v8 ignore
carrying a platform or contract reason; new suites cover stdio
dispositions, the dispose ladder tiers, injected-win32 tree semantics,
waitForExit, settled-kill/terminate no-ops, and spawn-failure disposal.
- Docs: consumer-migration Agent Note (en; zh follows in this PR), seam note
updated in place, subprocess.md rewritten for the reshaped vocabulary
(type-equiv re-registered), READMEs and SERVICE_ROLES updated, taskkill
added to knip ignoreBinaries.
2026-07-26 15:27:59 +08:00
pkg_subagent_acp["subagent-acp"]
2026-08-04 16:02:17 +08:00
pkg_subagent_codex["subagent-codex"]
2026-08-04 20:57:55 +08:00
pkg_subagent_claude_code["subagent-claude-code"]
2026-08-13 00:36:22 +08:00
pkg_shell["shell"]
svc_shell["ctx.shell< br / > Bash executor seam"]
2026-08-02 21:46:53 +08:00
pkg_pwsh_local["pwsh-local"]
pkg_tool_pwsh["tool-pwsh"]
2026-08-13 00:36:22 +08:00
pkg_shell_env["shell-env"]
svc_shellEnv["ctx.shellEnv< br / > Managed bash environment registry"]
pkg_terminal["terminal"]
svc_terminals["ctx.terminals< br / > Persistent PTY session registry"]
2026-07-09 15:42:37 +08:00
pkg_sandbox["sandbox"]
svc_sandbox["ctx.sandbox< br / > Process-sandbox seam"]
pkg_sandbox_local["sandbox-local"]
2026-07-20 13:59:18 +08:00
pkg_sandbox_policy["sandbox-policy"]
feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.
- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
deployment default mode + workspaceRoot and the per-session override event,
renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
write/edit by the per-call mode (read-only denies, workspace-write contains to
the workspace + temp roots via the shared writableRoots, danger passes
through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
ladder, denial/hint markers, approveEscalation) both tool families use;
approveEscalation takes a structural approver so dsh-sandbox gains no
approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
that disabled the fs stack under confined modes.
RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00
svc_sandboxPolicy["ctx.sandboxPolicy< br / > Sandbox policy home"]
pkg_fs_sandbox["fs-sandbox"]
2026-07-09 15:25:18 +08:00
pkg_approval["approval"]
svc_approval["ctx.approval< br / > Approval seam"]
2026-08-13 00:36:22 +08:00
pkg_permission_presets["permission-presets"]
svc_permissionPresets["ctx.permissionPresets< br / > Permission presets"]
2026-07-08 02:17:24 +08:00
pkg_code_runtime["code-runtime"]
svc_codeRuntime["ctx.codeRuntime< br / > Code-execution seam"]
feat: add the worker-thread code runtime (dsh-code-runtime-worker)
The shipped backend of the code-execution seam, per the Code Mode RFC's
worker-thread section: one fresh Node worker per run, executing the
model's TypeScript after a host-side type-strip (wrapped in an
async-function shell so top-level return/await parse, sliced back out
position-preserved), bindings bridged over the message port under
hostile-peer rules (own-property name lookup, at-most-once replies,
post-settlement drops, null-prototype namespaces), logs streamed eagerly
with an in-band truncation marker, and two independent budgets — measured
event-loop busy time (computeMs) plus a never-pausing wall ceiling
(maxWallMs) — funneling into worker.terminate(). env: {} and execArgv: []
keep the isolate hermetic; disposal aborts in-flight runs and awaits
worker exits.
The worker entry loads unbuilt via Node's native type stripping
(src/worker.ts, erasable-only) and ships built as a sibling tsdown bundle
(lib/worker.js); tests/built-lib.e2e.ts pins the built load path under
plain node and joins the built-artifact smoke gate. Unit suites cover the
bootstrap in-process (fake port) and the runtime over real workers,
per-file 100%.
2026-07-08 11:00:06 +08:00
pkg_code_runtime_worker["code-runtime-worker"]
2026-07-04 12:50:06 +08:00
pkg_fs["fs"]
svc_fs["ctx.fs< br / > Filesystem provider seam"]
pkg_fs_local["fs-local"]
2026-08-13 00:36:22 +08:00
pkg_fs_observation_policy["fs-observation-policy"]
pkg_compaction["compaction"]
svc_compaction["ctx.compaction< br / > Compaction seam"]
2026-07-03 01:13:52 +08:00
pkg_subagent["subagent"]
2026-07-27 00:00:14 +08:00
svc_subagents["ctx.subagents< br / > Subagent provider and continuation service"]
2026-08-13 00:36:22 +08:00
pkg_subagent_spawn_in_process["subagent-spawn-in-process"]
pkg_subagent_fork_in_process["subagent-fork-in-process"]
2026-08-05 05:24:23 +08:00
pkg_subagent_dsh_sdk["subagent-dsh-sdk"]
feat(subagent): continuable background subagents
Implement the continuable background subagents RFC: a durable child
session with a series of Task-backed activations, each disposing its
run before the Task settles.
- dsh-subagent: rename SubagentRun.sendMessage to strict steer, drop
run-level resume, add SubagentProvider.resume dispatch via
SubagentService.resume, the continuation start field, and the
versioned model-hidden subagent/descriptor session event.
- dsh-subagent-inprocess/-spawn/-fork: publish the control-allocated
child id, append the descriptor inside the initial turn, implement
cold resume from the child's own transcript under the live parent
scope, and strict running-only steer.
- dsh-subagent-control (new): SubagentControlService owning stable
child ids, descriptor snapshot/fold/authorization, Task-backed
activation with settle-then-dispose ordering, the process-local
active-run association, and steer-or-resume sendMessage routing.
- dsh-tool-subagent: background route branches on the provider's
resume capability (continuable via the control service; one-shot
task for ACP), returning both child and task ids.
- dsh-tool-subagent-control (new): the globally named send_message
tool rendering steered/started routes.
Keyless coverage spans Task ownership and disposal ordering, running
delivery, cold follow-up, descriptor rejection and rollback, known-id
reconstruction, kill during lookup, admission races, and a new
subagent-continuable ACP snapshot scenario.
2026-07-23 17:07:38 +08:00
pkg_tool_subagent_control["tool-subagent-control"]
2026-07-20 00:51:19 +08:00
pkg_tool_ralph["tool-ralph"]
2026-08-19 22:44:23 +08:00
pkg_agent_team["agent-team"]
svc_agentTeams["ctx.agentTeams< br / > Agent Teams coordination domain"]
pkg_tool_agent_team["tool-agent-team"]
2026-08-13 00:36:22 +08:00
pkg_jobs["jobs"]
svc_jobs["ctx.jobs< br / > Background job registry"]
pkg_jobs_local["jobs-local"]
pkg_tool_jobs["tool-jobs"]
2026-07-04 12:50:06 +08:00
pkg_web["web"]
svc_web["ctx.web< br / > Web access provider registry"]
pkg_web_search_exa["web-search-exa"]
pkg_web_search_perplexity["web-search-perplexity"]
pkg_web_search_deepseek["web-search-deepseek"]
2026-08-13 00:36:22 +08:00
pkg_web_fetch_http["web-fetch-http"]
2026-07-08 19:20:50 +08:00
pkg_spill["spill"]
2026-07-13 11:07:27 +08:00
svc_spillStore["ctx.spillStore< br / > Spill storage seam"]
2026-07-08 19:20:50 +08:00
pkg_spill_local["spill-local"]
pkg_spill_policy["spill-policy"]
2026-07-28 15:44:53 +08:00
pkg_directory_picker["directory-picker"]
svc_directoryPicker["ctx.directoryPicker< br / > Workspace-directory picking seam"]
2026-07-28 21:07:28 +08:00
pkg_directory_picker_native["directory-picker-native"]
2026-07-28 15:44:53 +08:00
pkg_directory_picker_browse["directory-picker-browse"]
2026-07-25 02:15:58 +08:00
pkg_webserver["webserver"]
2026-08-13 00:36:22 +08:00
svc_webServer["ctx.webServer< br / > HTTP route registration"]
2026-07-25 02:15:58 +08:00
pkg_connection["connection"]
pkg_modules["modules"]
pkg_hmr["hmr"]
2026-08-13 00:36:22 +08:00
svc_clientModules["ctx.clientModules< br / > Client plugin graph host"]
2026-07-06 03:14:07 +08:00
pkg_workflow["workflow"]
2026-08-13 00:36:22 +08:00
svc_workflowEngine["ctx.workflowEngine< br / > Workflow script engine"]
pkg_workflow_worker_thread["workflow-worker-thread"]
2026-07-06 03:14:07 +08:00
pkg_tool_workflow["tool-workflow"]
2026-08-22 23:44:56 +08:00
pkg_webhook["webhook"]
svc_webhookRuntime["ctx.webhookRuntime< br / > Webhook rule runtime"]
pkg_webhook_github["webhook-github"]
2026-08-13 02:22:10 +08:00
pkg_lsp["lsp"]
svc_lsp["ctx.lsp< br / > Language-server navigation seam"]
pkg_lsp_local["lsp-local"]
pkg_tool_lsp["tool-lsp"]
svc_apiProxy["ctx.apiProxy< br / > Host API dispatch"]
pkg_cordis_host_runner["cordis-host-runner"]
svc_dynamicCordisRunner["ctx.dynamicCordisRunner< br / > Dynamic Cordis package host runner"]
svc_cordisInspect["ctx.cordisInspect< br / > Dynamic Cordis inspect registry"]
2026-07-09 15:36:08 +08:00
pkg_acp --> svc_approval
2026-07-03 01:13:52 +08:00
pkg_agent --> svc_agents
2026-08-09 12:13:58 +08:00
pkg_agent_default_model --> svc_agentDefaultModel
2026-07-03 01:13:52 +08:00
pkg_agent_loop --> svc_agentLoop
2026-08-08 14:04:53 +08:00
pkg_agent_presets --> svc_agentPresets
2026-08-19 22:44:23 +08:00
pkg_agent_team --> svc_agentTeams
2026-08-05 11:17:47 +08:00
pkg_api_gateway --> svc_typertGateway
2026-08-22 21:13:53 +08:00
pkg_api_session_controller --> svc_sessionController
2026-08-23 06:14:32 +08:00
pkg_api_workspace_controller --> svc_workspaceController
2026-08-13 02:22:10 +08:00
pkg_apiproxy --> svc_apiProxy
2026-07-09 15:25:18 +08:00
pkg_approval --> svc_approval
2026-07-23 15:20:47 +08:00
pkg_attachment --> svc_attachments
pkg_attachment_local --> svc_attachments
2026-08-13 15:33:29 +08:00
pkg_authorization --> svc_authorization
2026-08-13 00:36:22 +08:00
pkg_bash_local --> svc_shell
pkg_bash_sandbox --> svc_shell
2026-07-08 02:17:24 +08:00
pkg_code_runtime --> svc_codeRuntime
feat: add the worker-thread code runtime (dsh-code-runtime-worker)
The shipped backend of the code-execution seam, per the Code Mode RFC's
worker-thread section: one fresh Node worker per run, executing the
model's TypeScript after a host-side type-strip (wrapped in an
async-function shell so top-level return/await parse, sliced back out
position-preserved), bindings bridged over the message port under
hostile-peer rules (own-property name lookup, at-most-once replies,
post-settlement drops, null-prototype namespaces), logs streamed eagerly
with an in-band truncation marker, and two independent budgets — measured
event-loop busy time (computeMs) plus a never-pausing wall ceiling
(maxWallMs) — funneling into worker.terminate(). env: {} and execArgv: []
keep the isolate hermetic; disposal aborts in-flight runs and awaits
worker exits.
The worker entry loads unbuilt via Node's native type stripping
(src/worker.ts, erasable-only) and ships built as a sibling tsdown bundle
(lib/worker.js); tests/built-lib.e2e.ts pins the built load path under
plain node and joins the built-artifact smoke gate. Unit suites cover the
bootstrap in-process (fake port) and the runtime over real workers,
per-file 100%.
2026-07-08 11:00:06 +08:00
pkg_code_runtime_worker --> svc_codeRuntime
2026-07-19 22:11:59 +08:00
pkg_commands --> svc_commands
2026-08-13 00:36:22 +08:00
pkg_compaction --> svc_compaction
pkg_compaction_basic --> svc_compaction
pkg_compaction_tool_result_pruner --> svc_toolResultPruner
2026-08-13 02:22:10 +08:00
pkg_cordis_host_runner --> svc_cordisInspect
pkg_cordis_host_runner --> svc_dynamicCordisRunner
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
pkg_credentials --> svc_credentials
pkg_credentials_local --> svc_credentials
2026-08-22 20:03:23 +08:00
pkg_deepseek_llm_api_extensions --> svc_deepseekLlmApiExtensions
2026-07-28 15:44:53 +08:00
pkg_directory_picker --> svc_directoryPicker
pkg_directory_picker_browse --> svc_directoryPicker
2026-07-28 21:07:28 +08:00
pkg_directory_picker_native --> svc_directoryPicker
2026-08-07 21:04:33 +08:00
pkg_e2b --> svc_e2b
2026-07-27 15:25:33 +08:00
pkg_file_reference --> svc_fileReferences
pkg_file_reference_local --> svc_fileReferences
2026-07-04 12:50:06 +08:00
pkg_fs --> svc_fs
2026-08-07 21:04:33 +08:00
pkg_fs_e2b --> svc_fs
2026-07-04 12:50:06 +08:00
pkg_fs_local --> svc_fs
feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.
- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
deployment default mode + workspaceRoot and the per-session override event,
renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
write/edit by the per-call mode (read-only denies, workspace-write contains to
the workspace + temp roots via the shared writableRoots, danger passes
through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
ladder, denial/hint markers, approveEscalation) both tool families use;
approveEscalation takes a structural approver so dsh-sandbox gains no
approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
that disabled the fs stack under confined modes.
RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00
pkg_fs_sandbox --> svc_fs
2026-07-19 18:47:34 +08:00
pkg_goal --> svc_goals
2026-07-19 19:19:57 +08:00
pkg_invariants --> svc_invariants
2026-08-13 00:36:22 +08:00
pkg_jobs --> svc_jobs
pkg_jobs_local --> svc_jobs
2026-07-03 01:13:52 +08:00
pkg_llm --> svc_llm
pkg_llm_deepseek --> svc_llm
pkg_llm_pi_ai --> svc_llm
pkg_llm_replay --> svc_llm
2026-08-13 02:22:10 +08:00
pkg_lsp --> svc_lsp
pkg_lsp_local --> svc_lsp
2026-08-10 11:28:38 -07:00
pkg_message_feedback --> svc_messageFeedback
2026-08-13 00:36:22 +08:00
pkg_modules --> svc_clientModules
pkg_permission_presets --> svc_permissionPresets
2026-07-22 16:57:23 +08:00
pkg_plan_mode --> svc_planMode
2026-08-22 20:03:23 +08:00
pkg_plugin_package_inventory_deepseek --> svc_deepseekLlmApiExtensions
2026-08-13 00:36:22 +08:00
pkg_pwsh_local --> svc_shell
2026-07-09 15:42:37 +08:00
pkg_sandbox --> svc_sandbox
pkg_sandbox_local --> svc_sandbox
2026-07-20 13:59:18 +08:00
pkg_sandbox_policy --> svc_sandboxPolicy
2026-07-03 01:13:52 +08:00
pkg_session --> svc_sessions
2026-08-22 02:02:38 +08:00
pkg_session_log_deepseek --> svc_deepseekLlmApiExtensions
2026-07-03 01:13:52 +08:00
pkg_session_persistence --> svc_sessionPersistence
pkg_session_persistence_jsonl --> svc_sessionPersistence
pkg_session_persistence_sqlite --> svc_sessionPersistence
2026-07-28 01:09:55 +08:00
pkg_session_projection --> svc_sessionProjections
2026-07-28 02:11:31 +08:00
pkg_session_projection_cache --> svc_sessionProjectionCache
2026-07-10 16:51:19 +08:00
pkg_session_query --> svc_sessionQuery
2026-07-23 20:16:14 +08:00
pkg_session_query_sqlite --> svc_sessionQuery
2026-08-13 00:36:22 +08:00
pkg_session_reference --> svc_sessionReferenceResolver
pkg_session_telemetry --> svc_sessionTelemetry
pkg_session_telemetry_otel --> svc_sessionTelemetry
2026-07-21 01:54:00 +08:00
pkg_session_title --> svc_sessionTitle
2026-08-13 00:36:22 +08:00
pkg_session_title_all_prompts_llm --> svc_sessionTitle
pkg_session_title_first_prompt_llm --> svc_sessionTitle
feat(settings): add user-settings seam (ctx.settings) + file provider
Two-package capability family mirroring session-persistence/:
- dsh-settings: abstract Settings service — namespace registry with
caller-fiber effect registrations, layered resolution (schema defaults
< composition base < user document), schemastery validation,
per-namespace deep-equal commit detection, and the settings/updated
event. Boot/registration validation fails loud; provider publishes
keep last-good per namespace.
- dsh-settings-local: settings.yaml/.json provider — resolveSpec
defaulting to $DSH_HOME/settings.yaml, chokidar hot reload,
content-equality self-write suppression, atomic 0600 tmp+rename
writes, comment-preserving YAML namespace patching.
Consumers register inside ctx.inject(['settings'], …), so every
composition works unchanged without a mounted provider. Real Loader +
Include composition test proves cordis.yml boot and external-edit hot
propagation; HMR disposal test proves registry cleanup. Both packages
hold per-file 100% coverage.
Doc budgets rise 1705→1710 (AGENTS.md) and 835→845 (packages/README.md):
one structural line per file for the new package group.
Agent Note: .agents/notes/implemented/architecture/2026-07-28-user-settings-seam.md
2026-07-28 17:30:12 +08:00
pkg_settings --> svc_settings
2026-08-13 00:36:22 +08:00
pkg_settings_file --> svc_settings
pkg_shell --> svc_shell
pkg_shell_env --> svc_shellEnv
2026-07-05 16:50:29 +08:00
pkg_skill --> svc_skills
2026-08-05 21:50:44 +08:00
pkg_skill_badge --> svc_skills
2026-08-13 00:36:22 +08:00
pkg_skill_filesystem --> svc_skills
2026-07-13 11:07:27 +08:00
pkg_spill --> svc_spillStore
pkg_spill_local --> svc_spillStore
chore(storage,workspace): gates — coverage, catalogs, bilingual note
- Per-file 100% coverage across the five new packages (invariant
companion suites, failure-injection negatives, lifecycle and
malformed-medium branches).
- Canonical README Model Experience / Known Limitations sections; new
storage/ and workspace/ group READMEs; packages/README.md rows (budget
ceiling raised 760 → 790 for the two new groups).
- Cordis catalog/type-link registrations, service-role classification,
and regenerated catalogs/graphs for the new services and events.
- Agent Note: English body + i18n pairing record; design-sketch fences
opted out of doc-typecheck as ignore-check.
- Two exactOptionalPropertyTypes/discriminant fixes in new tests.
doc-sync (24 gates), typecheck, hygiene, and the five-package suite
(92 tests) all pass.
2026-07-24 22:49:57 +08:00
pkg_storage --> svc_storage
2026-07-25 16:04:48 +08:00
pkg_storage_domain --> svc_storageDomain
chore(storage,workspace): gates — coverage, catalogs, bilingual note
- Per-file 100% coverage across the five new packages (invariant
companion suites, failure-injection negatives, lifecycle and
malformed-medium branches).
- Canonical README Model Experience / Known Limitations sections; new
storage/ and workspace/ group READMEs; packages/README.md rows (budget
ceiling raised 760 → 790 for the two new groups).
- Cordis catalog/type-link registrations, service-role classification,
and regenerated catalogs/graphs for the new services and events.
- Agent Note: English body + i18n pairing record; design-sketch fences
opted out of doc-typecheck as ignore-check.
- Two exactOptionalPropertyTypes/discriminant fixes in new tests.
doc-sync (24 gates), typecheck, hygiene, and the five-package suite
(92 tests) all pass.
2026-07-24 22:49:57 +08:00
pkg_storage_json --> svc_storage
pkg_storage_sqlite --> svc_storage
2026-07-03 01:13:52 +08:00
pkg_subagent --> svc_subagents
pkg_subagent_acp --> svc_subagents
2026-08-04 20:57:55 +08:00
pkg_subagent_claude_code --> svc_subagents
2026-08-04 16:02:17 +08:00
pkg_subagent_codex --> svc_subagents
2026-08-04 18:38:05 +08:00
pkg_subagent_dsh_sdk --> svc_subagents
2026-08-13 00:36:22 +08:00
pkg_subagent_fork_in_process --> svc_subagents
pkg_subagent_spawn_in_process --> svc_subagents
2026-07-26 14:10:46 +08:00
pkg_subprocess --> svc_subprocess
2026-08-07 21:04:33 +08:00
pkg_subprocess_e2b --> svc_subprocess
2026-07-26 14:10:46 +08:00
pkg_subprocess_local --> svc_subprocess
2026-07-03 01:13:52 +08:00
pkg_system_prompt --> svc_systemPrompt
2026-08-13 00:36:22 +08:00
pkg_terminal --> svc_terminals
pkg_terminal_bash --> svc_terminals
2026-07-15 14:47:29 +08:00
pkg_token_meter --> svc_tokenMeter
2026-07-03 01:13:52 +08:00
pkg_tools --> svc_tools
2026-07-28 23:48:35 +08:00
pkg_typert_registry --> svc_typert
2026-08-13 00:36:22 +08:00
pkg_user_questions --> svc_userQuestions
2026-07-04 12:50:06 +08:00
pkg_web --> svc_web
2026-08-13 00:36:22 +08:00
pkg_web_fetch_http --> svc_web
2026-07-04 12:50:06 +08:00
pkg_web_search_deepseek --> svc_web
pkg_web_search_exa --> svc_web
pkg_web_search_perplexity --> svc_web
2026-08-22 23:44:56 +08:00
pkg_webhook --> svc_webhookRuntime
2026-08-13 00:36:22 +08:00
pkg_webserver --> svc_webServer
pkg_workflow --> svc_workflowEngine
pkg_workflow_worker_thread --> svc_workflowEngine
pkg_workspace --> svc_workspaceRegistry
2026-08-09 12:13:58 +08:00
svc_agentDefaultModel --> pkg_headless
svc_agentDefaultModel --> pkg_host_apiproxy
2026-07-15 15:57:57 +08:00
svc_agentLoop --> pkg_agent_spine_demo
2026-08-19 22:44:23 +08:00
svc_agentTeams --> pkg_tool_agent_team
2026-07-03 01:13:52 +08:00
svc_agents --> pkg_acp
svc_agents --> pkg_agent_loop
svc_agents --> pkg_subagent_inprocess
2026-08-13 02:22:10 +08:00
svc_apiProxy --> pkg_connection
2026-07-09 16:37:10 +08:00
svc_approval --> pkg_tool_bash
2026-07-09 15:25:18 +08:00
svc_approval --> pkg_tools
2026-07-23 15:20:47 +08:00
svc_attachments --> pkg_host_runtime
svc_attachments --> pkg_llm_pi_ai
2026-08-13 15:33:29 +08:00
svc_authorization --> pkg_llm_pi_ai
2026-08-13 00:36:22 +08:00
svc_clientModules --> pkg_hmr
feat: Code Mode — the registry's mode config, the SDK codegen, and the run_code bridge
The dsh-tools half of the Code Mode RFC (its fourth, final change): the
registry gains its first config — mode: native | code | both — and OWNS how
its tools reach the model. 'code' contributes exactly one wire tool,
run_code, plus a lazy tools:sdk prompt section declaring every other tool
as a generated TypeScript API (jsonSchemaToTs: total over the defineTool
subset, unknown degradation, lexicographic byte-identical rendering);
'both' ships both representations; 'native' is byte-for-byte the old
behavior. Non-native modes fail every assembly loudly without a
typescript-language ctx.codeRuntime.
run_code's dispatch bridge: JSON-normalizes each binding argument before
dispatch (what dispatches is what the tool/code-dispatch event logs — the
append can never fail on payload shape; BigInt/circulars reject that one
call), serializes all program tool calls through a per-run queue (even
Promise.all — no concurrency-safety metadata yet), routes every sub-call
through tools/pre-execute → tools/post-execute (a deny rejects the
program-side promise), drops sub-call additionalContext (no safe outlet
mid-run; pinned), owns a run-scoped abort that follows the outer signal in
and fires on settlement (in-flight sub-dispatch aborted, queued abandoned,
queue drained before returning), and converts a failed run into
CodeRunFailedError → a structured isError carrying kind + captured logs.
tool/code-dispatch joins SessionEventMap by declaration merging (log-only;
deriveMessages ignores it).
The composed surface: the tools config forwards through agent-core and
both app packages; examples/code-agent + demo:code run the worker runtime
under mode code (keyless boot smoke + a with-key e2e proving the collapsed
[run_code] header, the dispatch events, and the file the program wrote);
two new snapshot scenarios (code-mode-turn, both-mode-turn) record the SDK
section, collapsed header, dispatch events, and result card — each its own
header-pinning class (the harness gains per-scenario config overlays and
per-class pins). Catalogs, graphs, cookbook, hooks-bridge notes, and the
RFC (moved to implemented/, restructured to decision-era headings) updated
in the same change.
2026-07-08 12:58:23 +08:00
svc_codeRuntime --> pkg_tools
2026-08-13 00:36:22 +08:00
svc_compaction --> pkg_compaction_basic
2026-08-13 02:22:10 +08:00
svc_cordisInspect --> pkg_tool_cordis
2026-07-30 10:53:39 +08:00
svc_credentials --> pkg_apiproxy
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
svc_credentials --> pkg_llm_deepseek
svc_credentials --> pkg_llm_pi_ai
2026-08-22 20:03:23 +08:00
svc_deepseekLlmApiExtensions --> pkg_llm_deepseek
2026-07-28 15:44:53 +08:00
svc_directoryPicker --> pkg_apiproxy
2026-08-13 02:22:10 +08:00
svc_dynamicCordisRunner --> pkg_tool_cordis
2026-08-07 21:04:33 +08:00
svc_e2b --> pkg_fs_e2b
svc_e2b --> pkg_subprocess_e2b
2026-07-04 12:50:06 +08:00
svc_fs --> pkg_tool_fs
2026-07-19 19:19:57 +08:00
svc_invariants --> pkg_agent
svc_invariants --> pkg_agent_loop
svc_invariants --> pkg_scope
svc_invariants --> pkg_session
2026-08-13 00:36:22 +08:00
svc_jobs --> pkg_tool_bash
svc_jobs --> pkg_tool_jobs
svc_jobs --> pkg_tool_subagent
svc_jobs --> pkg_tool_terminal
2026-07-03 01:13:52 +08:00
svc_llm --> pkg_agent_loop
2026-08-13 00:36:22 +08:00
svc_llm --> pkg_compaction_basic
2026-08-13 02:22:10 +08:00
svc_lsp --> pkg_tool_lsp
2026-07-09 16:05:44 +08:00
svc_sandbox --> pkg_bash_sandbox
2026-08-13 00:36:22 +08:00
svc_sandbox --> pkg_terminal_bash
feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.
- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
deployment default mode + workspaceRoot and the per-session override event,
renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
write/edit by the per-call mode (read-only denies, workspace-write contains to
the workspace + temp roots via the shared writableRoots, danger passes
through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
ladder, denial/hint markers, approveEscalation) both tool families use;
approveEscalation takes a structural approver so dsh-sandbox gains no
approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
that disabled the fs stack under confined modes.
RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00
svc_sandboxPolicy --> pkg_bash_sandbox
svc_sandboxPolicy --> pkg_fs_sandbox
2026-08-13 00:36:22 +08:00
svc_sandboxPolicy --> pkg_terminal_bash
2026-08-22 21:13:53 +08:00
svc_sessionController --> pkg_apiproxy
2026-07-03 01:13:52 +08:00
svc_sessionPersistence --> pkg_agent_loop
2026-08-13 00:36:22 +08:00
svc_sessionPersistence --> pkg_hooks_claude_code
fix(bash): close managed environment review gaps
The managed DSH_* runtime path was correct, but its public extension and documentation contracts were incomplete. A contributor following the README could access ctx.bashEnv without declaring an injection, the new environment types had no drift-checked catalog entries, and the capability graph omitted three packages that now query sessionPersistence.
Declare the README injection, catalog DshEnvironmentKey and DshEnvironment, and add tool-bash plus both hook bridges to the generated persistence consumer graph. Keep BashEnvRegistry.list() contributor-only for now because no production caller treats it as exhaustive, but record the built-in enumeration gap before diagnostics, prompt, or UI code depends on it.
Validated on the exact resulting tree with typecheck, lint, coverage, snapshot, documentation, module-graph, build, hygiene, demo-smoke, and built-artifact checks.
2026-07-15 00:04:00 +08:00
svc_sessionPersistence --> pkg_hooks_codex
2026-08-10 11:28:38 -07:00
svc_sessionPersistence --> pkg_message_feedback
2026-07-10 16:51:19 +08:00
svc_sessionPersistence --> pkg_session_query
2026-07-15 10:51:38 +08:00
svc_sessionPersistence --> pkg_session_query_sqlite
fix(bash): close managed environment review gaps
The managed DSH_* runtime path was correct, but its public extension and documentation contracts were incomplete. A contributor following the README could access ctx.bashEnv without declaring an injection, the new environment types had no drift-checked catalog entries, and the capability graph omitted three packages that now query sessionPersistence.
Declare the README injection, catalog DshEnvironmentKey and DshEnvironment, and add tool-bash plus both hook bridges to the generated persistence consumer graph. Keep BashEnvRegistry.list() contributor-only for now because no production caller treats it as exhaustive, but record the built-in enumeration gap before diagnostics, prompt, or UI code depends on it.
Validated on the exact resulting tree with typecheck, lint, coverage, snapshot, documentation, module-graph, build, hygiene, demo-smoke, and built-artifact checks.
2026-07-15 00:04:00 +08:00
svc_sessionPersistence --> pkg_tool_bash
2026-07-28 02:11:31 +08:00
svc_sessionProjectionCache --> pkg_host_apiproxy
2026-07-28 01:09:55 +08:00
svc_sessionProjections --> pkg_host_apiproxy
svc_sessionProjections --> pkg_session_title
svc_sessionProjections --> pkg_tool_todo
2026-07-21 16:46:48 +08:00
svc_sessionQuery --> pkg_session_reference
2026-07-24 15:09:55 +08:00
svc_sessionQuery --> pkg_tool_session_query
2026-07-03 01:13:52 +08:00
svc_sessions --> pkg_agent
svc_sessions --> pkg_agent_loop
svc_sessions --> pkg_invariants
2026-08-10 11:28:38 -07:00
svc_sessions --> pkg_message_feedback
2026-07-03 01:13:52 +08:00
svc_sessions --> pkg_session_persistence
2026-07-10 16:51:19 +08:00
svc_sessions --> pkg_session_query
2026-07-15 10:51:38 +08:00
svc_sessions --> pkg_session_query_sqlite
2026-07-03 01:13:52 +08:00
svc_sessions --> pkg_subagent_inprocess
2026-07-30 10:53:39 +08:00
svc_settings --> pkg_apiproxy
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
svc_settings --> pkg_llm_deepseek
svc_settings --> pkg_llm_pi_ai
2026-08-13 00:36:22 +08:00
svc_shell --> pkg_hooks_claude_code
svc_shell --> pkg_hooks_codex
svc_shell --> pkg_tool_bash
svc_shell --> pkg_tool_pwsh
svc_shellEnv --> pkg_tool_bash
svc_shellEnv --> pkg_tool_pwsh
2026-07-05 16:50:29 +08:00
svc_skills --> pkg_tool_skill
2026-07-13 11:07:27 +08:00
svc_spillStore --> pkg_spill_policy
2026-07-25 01:11:39 +08:00
svc_storage --> pkg_storage_domain
2026-08-10 11:28:38 -07:00
svc_storageDomain --> pkg_message_feedback
2026-07-25 16:04:48 +08:00
svc_storageDomain --> pkg_workspace
2026-07-20 00:51:19 +08:00
svc_subagents --> pkg_tool_ralph
2026-07-03 01:13:52 +08:00
svc_subagents --> pkg_tool_subagent
2026-07-27 00:00:14 +08:00
svc_subagents --> pkg_tool_subagent_control
refactor(subprocess): rename the process seam to subprocess and address review
Review feedback (tianyicui): 'process' is a poor service name. The family is
now packages/subprocess/ — @deepseek-ai/dsh-subprocess (ctx.subprocess,
abstract SubprocessService, Subprocess* vocabulary) and
@deepseek-ai/dsh-subprocess-local (LocalSubprocessService) — renamed
throughout code, compositions, docs (en+zh, pairs re-recorded), catalogs,
and gates. 'subprocess' is the precise term for managed OS children (the
Python-stdlib sense), avoids colliding with Node's global process object,
and reads as one system beside dsh-subagent-subprocess.
ds-review-bot findings addressed:
- kill() on a settled handle is now a no-op (no signal to a possibly-reused
pgid, no referenced grace timer delaying exit); pinned by a spy test.
- The moved DshEnvironmentKey/DshEnvironment/CollectedOutput types get
drift-checked type-equiv blocks on the new subprocess.md page, restoring
their manifest registration.
- subprocess.md is registered in the core.md sub-page index (en+zh).
2026-07-26 12:43:14 +08:00
svc_subprocess --> pkg_bash_local
svc_subprocess --> pkg_bash_sandbox
2026-08-13 00:36:22 +08:00
svc_subprocess --> pkg_lsp_stdio
feat(subprocess): migrate lsp-local, subagent-acp, and the env scrubs onto the seam
Review direction (tianyicui, PR #660): in a stacked PR, change all other
process-running places to use the new service.
- lsp-local: LspConnection spawns through ctx.subprocess (piped protocol
streams + a no-spill collected stderr tail); its private process-tree
helpers (POSIX group signalling, Windows taskkill, liveness polling) are
deleted in favor of the seam's handle verbs, and its buildChildEnv now
rides scrubbedParentEnv (LSP children also stop inheriting stale DSH_*).
The plugin injects 'subprocess'; compositions/tests mount
dsh-subprocess-local.
- subagent-acp: the ACP child spawns through the seam (piped ndjson streams,
inherited stderr); spawn failure surfaces through done-rejection into the
same startup race; disposal is handle.dispose with the plugin's configured
graces. dsh-subagent-subprocess is DELETED — its dispose ladder and scrub
are the seam's, and the isolated-config-dir helper had no consumer.
- mcp-client, pty-local, sdk-helper: adopt scrubbedParentEnv as the one
scrub definition (their spawns stay put by ownership: the MCP SDK and
node-pty own those calls; the SDK wizard runs outside any composition).
- Coverage: per-file 100% over every touched src file, with each v8 ignore
carrying a platform or contract reason; new suites cover stdio
dispositions, the dispose ladder tiers, injected-win32 tree semantics,
waitForExit, settled-kill/terminate no-ops, and spawn-failure disposal.
- Docs: consumer-migration Agent Note (en; zh follows in this PR), seam note
updated in place, subprocess.md rewritten for the reshaped vocabulary
(type-equiv re-registered), READMEs and SERVICE_ROLES updated, taskkill
added to knip ignoreBinaries.
2026-07-26 15:27:59 +08:00
svc_subprocess --> pkg_subagent_acp
2026-08-04 20:57:55 +08:00
svc_subprocess --> pkg_subagent_claude_code
2026-08-04 16:02:17 +08:00
svc_subprocess --> pkg_subagent_codex
2026-08-13 00:36:22 +08:00
svc_subprocess --> pkg_terminal_bash
2026-07-03 01:13:52 +08:00
svc_systemPrompt --> pkg_agent_loop
2026-07-04 12:50:06 +08:00
svc_systemPrompt --> pkg_tool_fs
2026-08-13 00:36:22 +08:00
svc_systemPrompt --> pkg_tool_terminal
2026-07-04 12:50:06 +08:00
svc_systemPrompt --> pkg_tool_web
2026-07-03 01:13:52 +08:00
svc_systemPrompt --> pkg_tools
2026-08-13 00:36:22 +08:00
svc_terminals --> pkg_tool_terminal
svc_tokenMeter --> pkg_compaction_basic
svc_toolResultPruner --> pkg_compaction_basic
2026-07-03 01:13:52 +08:00
svc_tools --> pkg_agent_loop
2026-07-05 17:05:33 +08:00
svc_tools --> pkg_tool_ask_user
2026-07-03 01:13:52 +08:00
svc_tools --> pkg_tool_bash
2026-07-08 11:50:12 +08:00
svc_tools --> pkg_tool_cordis
2026-07-04 12:50:06 +08:00
svc_tools --> pkg_tool_fs
2026-07-05 16:50:29 +08:00
svc_tools --> pkg_tool_skill
2026-07-03 01:13:52 +08:00
svc_tools --> pkg_tool_subagent
2026-08-13 00:36:22 +08:00
svc_tools --> pkg_tool_terminal
2026-07-03 01:13:52 +08:00
svc_tools --> pkg_tool_todo
2026-07-04 12:50:06 +08:00
svc_tools --> pkg_tool_web
2026-08-05 11:17:47 +08:00
svc_typert --> pkg_api_gateway
2026-07-28 23:48:35 +08:00
svc_typert --> pkg_typert_loader
2026-08-13 00:36:22 +08:00
svc_userQuestions --> pkg_tool_ask_user
2026-07-04 12:50:06 +08:00
svc_web --> pkg_tool_web
2026-08-13 00:36:22 +08:00
svc_webServer --> pkg_connection
svc_webServer --> pkg_hmr
svc_webServer --> pkg_modules
2026-08-22 23:44:56 +08:00
svc_webhookRuntime --> pkg_webhook_github
2026-08-13 00:36:22 +08:00
svc_workflowEngine --> pkg_tool_ralph
svc_workflowEngine --> pkg_tool_workflow
svc_workspaceRegistry --> pkg_apiproxy
svc_fs -. event gate .-> pkg_fs_observation_policy
2026-07-03 01:13:52 +08:00
```
2026-07-04 12:50:06 +08:00
| ctx key | Role | Owner | Implementations | Direct consumers | Companion plugins | Note |
| --- | --- | --- | --- | --- | --- | --- |
2026-07-25 22:35:22 +08:00
| `ctx.attachments` | `seam` | [`attachment` ](../packages/attachment/attachment ) | [`attachment-local` ](../packages/attachment/attachment-local ) | `host-runtime` , [`llm-pi-ai` ](../packages/llm/llm-pi-ai ) | - | The host commits accepted images before session events; provider adapters resolve authorized durable references into provider-native content. |
2026-08-13 00:36:22 +08:00
| `ctx.llm` | `seam` | [`llm` ](../packages/llm/llm ) | [`llm-deepseek` ](../packages/llm/llm-deepseek ), [`llm-pi-ai` ](../packages/llm/llm-pi-ai ), [`llm-replay` ](../packages/test-support/llm-replay ) | [`agent-loop` ](../packages/core/agent-loop ), [`compaction-basic` ](../packages/compaction/compaction-basic ) | - | Adapters register provider implementations; the loop and compaction call the provider-neutral stream service. |
2026-08-22 02:02:38 +08:00
| `ctx.deepseekLlmApiExtensions` | `seam` | [`deepseek-llm-api-extensions` ](../packages/llm/deepseek-llm-api-extensions ) | [`session-log-deepseek` ](../packages/session/session-log-deepseek ), [`plugin-package-inventory-deepseek` ](../packages/llm/plugin-package-inventory-deepseek ) | [`llm-deepseek` ](../packages/llm/llm-deepseek ) | - | Plugins prepare independent top-level fields; the official adapter merges them and commits their delivery state after HTTP acceptance. |
2026-08-13 00:36:22 +08:00
| `ctx.tokenMeter` | `core` | [`token-meter` ](../packages/llm/token-meter ) | - | [`compaction-basic` ](../packages/compaction/compaction-basic ) | - | Owns isolated per-session replay folds; pressure consumers share immutable revisioned measurements. |
| `ctx.toolResultPruner` | `core` | [`compaction-tool-result-pruner` ](../packages/compaction/compaction-tool-result-pruner ) | - | [`compaction-basic` ](../packages/compaction/compaction-basic ) | - | Rewrites oversized current tool results through replayable single-node surface replacements before summary compaction. |
| `ctx.sessions` | `core` | [`session` ](../packages/core/session ) | - | [`agent-loop` ](../packages/core/agent-loop ), [`agent` ](../packages/core/agent ), [`session-persistence` ](../packages/session/session-persistence ), [`session-query` ](../packages/session-query/session-query ), [`session-query-sqlite` ](../packages/session-query/session-query-sqlite ), `subagent-inprocess` , [`invariants` ](../packages/runtime-diagnostics/invariants ), [`message-feedback` ](../packages/feedback/message-feedback ) | - | Owns append-only Session instances and emits the durable session event feed. |
2026-08-22 21:13:53 +08:00
| `ctx.sessionController` | `core` | [`api-session-controller` ](../packages/api/session-controller ) | - | `apiproxy` | - | Owns Session commands, cold reads, durable-event following, live control state, and Agent activation policy; apiProxy reuses its inspection and Agent-resolution operations for Session-aware domains. |
2026-08-23 06:14:32 +08:00
| `ctx.workspaceController` | `core` | [`api-workspace-controller` ](../packages/api/workspace-controller ) | - | - | - | Owns Workspace commands and reconnect-safe Workspace state delivery through the generated Remote namespace. |
2026-08-13 00:36:22 +08:00
| `ctx.invariants` | `core` | [`invariants` ](../packages/runtime-diagnostics/invariants ) | - | [`session` ](../packages/core/session ), [`agent` ](../packages/core/agent ), [`scope` ](../packages/core/scope ), [`agent-loop` ](../packages/core/agent-loop ) | - | Companion subpaths register owner-local checks; the service owns selection, uniqueness, child fibers, and package-attributed failures. |
2026-08-07 15:48:29 +08:00
| `ctx.typert` | `core` | [`typert-registry` ](../packages/typert/registry ) | - | [`typert-loader` ](../packages/typert/loader ), [`api-gateway` ](../packages/api/gateway ) | - | Plugins register live zod contributions directly or through dsh-typert-loader; the API gateway consumes invocation descriptors and providers, while other runtime consumers query schemas and reflection metadata at their own edges. |
| `ctx.typertGateway` | `core` | [`api-gateway` ](../packages/api/gateway ) | - | - | - | Associates generated Remote descriptors with live Cordis services, resolves registered identities, and exposes unary calls through the shared Connection RPC carrier. |
2026-08-13 00:36:22 +08:00
| `ctx.sessionPersistence` | `seam` | [`session-persistence` ](../packages/session/session-persistence ) | [`session-persistence-jsonl` ](../packages/session/session-persistence-jsonl ), [`session-persistence-sqlite` ](../packages/session/session-persistence-sqlite ) | [`agent-loop` ](../packages/core/agent-loop ), [`tool-bash` ](../packages/shell/tool-bash ), [`hooks-claude-code` ](../packages/hooks/hooks-claude-code ), [`hooks-codex` ](../packages/hooks/hooks-codex ), [`session-query` ](../packages/session-query/session-query ), [`session-query-sqlite` ](../packages/session-query/session-query-sqlite ), [`message-feedback` ](../packages/feedback/message-feedback ) | - | Backends persist the same SessionEvent vocabulary; apps choose a backend at composition time. |
| `ctx.settings` | `seam` | [`settings` ](../packages/settings/settings ) | [`settings-file` ](../packages/settings/settings-file ) | [`llm-deepseek` ](../packages/llm/llm-deepseek ), [`llm-pi-ai` ](../packages/llm/llm-pi-ai ), `apiproxy` | - | Plugins register namespace schemas and resolve layered values; providers store the raw document. The LLM adapters register their entry config as the composition base under the user section; the web gateway serves redacted layered descriptors and writes the user layer. |
2026-07-30 10:53:39 +08:00
| `ctx.credentials` | `seam` | [`credentials` ](../packages/credentials/credentials ) | [`credentials-local` ](../packages/credentials/credentials-local ) | [`llm-deepseek` ](../packages/llm/llm-deepseek ), [`llm-pi-ai` ](../packages/llm/llm-pi-ai ), `apiproxy` | - | Configuration carries references to secrets; providers own the values. Consumers resolve per operation, so a rotated credential reaches the very next request; the web gateway exposes value-free views and write-only storage. |
2026-08-13 15:33:29 +08:00
| `ctx.authorization` | `seam` | [`authorization` ](../packages/credentials/authorization ) | - | [`llm-pi-ai` ](../packages/llm/llm-pi-ai ) | - | Flows are registered by the plugin that knows how to obtain one credential and keyed by the record they write; the seam owns the conversation and the one-attempt-per-key lifecycle, never the protocol. |
2026-08-13 00:36:22 +08:00
| `ctx.sessionTelemetry` | `seam` | [`session-telemetry` ](../packages/session/session-telemetry ) | [`session-telemetry-otel` ](../packages/session/session-telemetry-otel ) | - | - | The seam captures, redacts, and hands session records to one backend; nothing else consumes the service — its output leaves the process. |
2026-07-25 16:04:48 +08:00
| `ctx.storage` | `seam` | [`storage` ](../packages/storage/storage ) | [`storage-json` ](../packages/storage/storage-json ), [`storage-sqlite` ](../packages/storage/storage-sqlite ) | [`storage-domain` ](../packages/storage/storage-domain ) | - | Backends register side by side under names; data forms (domain first) mount on the hub and translate typed operations into opaque KV-unit primitives. |
2026-08-10 11:28:38 -07:00
| `ctx.storageDomain` | `core` | [`storage-domain` ](../packages/storage/storage-domain ) | - | [`workspace` ](../packages/workspace/workspace ), [`message-feedback` ](../packages/feedback/message-feedback ) | - | Waits for every configured backend, then publishes the domain form as one lifecycle-bound service for typed durable state. |
| `ctx.messageFeedback` | `core` | [`message-feedback` ](../packages/feedback/message-feedback ) | - | - | - | Owns local per-assistant-message feedback, lifecycle and target validation, per-item compare-and-set, and the Host unary Remote contract without entering Session history or telemetry. |
2026-08-13 00:36:22 +08:00
| `ctx.workspaceRegistry` | `core` | [`workspace` ](../packages/workspace/workspace ) | - | `apiproxy` | - | Owns WorkspaceId-branded records over the domain facility; stable sessionIds accounts drive Host RPC and GUI projections. |
2026-07-24 15:09:55 +08:00
| `ctx.sessionQuery` | `seam` | [`session-query` ](../packages/session-query/session-query ) | [`session-query-sqlite` ](../packages/session-query/session-query-sqlite ) | [`session-reference` ](../packages/context/session-reference ), [`tool-session-query` ](../packages/session-query/tool-session-query ) | - | The interface supplies exact reads, filters, and traces; its concrete backend adds full-text reconciliation, ranking, snippets, and cursor generations, while the model consumer owns workspace authority and cursor-free rendering. |
refactor(reference): serve discovery through typert Remote faces
Replace the legacy reference.* API Proxy domain with @Remote methods on the
owning services, following the typert gateway design master adopted on
2026-08-02 (message-feedback and plugin-inventory precedents):
- FileReferenceService and SessionReferenceResolver extend TypertRemoteService;
fileReferences/list and sessionReferenceResolver/candidates are unary Remote
methods cancelled through the reserved trailing signal, and the candidates
face attaches each candidate's canonical mention under the configured limit
- move the wire types to type-only ./types subpaths (FileReferenceCandidate,
SessionReferenceMentionCandidate) and export ./typert plus ./remote artifacts
- mount both contributions in the api-remotes client assembly; ui-reference
consumes ctx.remote instead of connection.api.references and registers zh/en
locale dictionaries for its sections and labels
- delete the reference.* routes, schemas, map rows, client stubs, and fixtures;
the connection fixture serves the Remote endpoints instead
- release deliverPrompt admission listeners when the agent is disposed with the
prepared prompt still pending, and cover the reference-* RpcError codes in
the schema spec
- add the missing tsconfig paths for the /grammar and /types subpaths (clean-
tree vitest could not resolve @deepseek-ai/dsh-file-reference/grammar)
- regenerate the cordis catalog, capability seams, and event matrix; update the
owning bilingual READMEs, Agent Notes, and the reference-composer golden
2026-08-17 18:35:04 +08:00
| `ctx.fileReferences` | `seam` | [`file-reference` ](../packages/context/file-reference ) | [`file-reference-local` ](../packages/context/file-reference-local ) | - | - | The interface returns path-only completion candidates within the addressed Agent cwd through its unary Remote contract; providers own namespace access and ranking without reading file contents. |
2026-08-13 00:36:22 +08:00
| `ctx.sessionReferenceResolver` | `core` | [`session-reference` ](../packages/context/session-reference ) | - | - | - | Projects bounded current-surface conversation snapshots into durable untrusted message context; host adapters own mention syntax. |
| `ctx.sessionTitle` | `seam` | [`session-title` ](../packages/session/session-title ) | [`session-title-first-prompt-llm` ](../packages/session/session-title-first-prompt-llm ), [`session-title-all-prompts-llm` ](../packages/session/session-title-all-prompts-llm ) | - | - | Owns the deterministic fallback, latest-title fold, and sole optional asynchronous provider registration. |
| `ctx.systemPrompt` | `core` | [`system-prompt` ](../packages/core/system-prompt ) | - | [`agent-loop` ](../packages/core/agent-loop ), [`tools` ](../packages/core/tools ), [`tool-fs` ](../packages/fs/tool-fs ), [`tool-terminal` ](../packages/terminal/tool-terminal ), [`tool-web` ](../packages/web/tool-web ) | - | Collects prompt sections and model-facing tool schemas for each step. |
| `ctx.tools` | `core` | [`tools` ](../packages/core/tools ) | - | [`agent-loop` ](../packages/core/agent-loop ), [`tool-ask-user` ](../packages/interaction/tool-ask-user ), [`tool-bash` ](../packages/shell/tool-bash ), [`tool-cordis` ](../packages/extensions/tool-cordis ), [`tool-fs` ](../packages/fs/tool-fs ), [`tool-terminal` ](../packages/terminal/tool-terminal ), [`tool-skill` ](../packages/skill/tool-skill ), [`tool-subagent` ](../packages/subagent/tool-subagent ), [`tool-todo` ](../packages/todo/tool-todo ), [`tool-web` ](../packages/web/tool-web ) | - | Registers capabilities, owns Code Mode transport, and routes calls through pre-policy, monotonic guards, around dispatch, post-policy, and final-result observation. |
| `ctx.userQuestions` | `seam` | [`user-questions` ](../packages/interaction/user-questions ) | - | [`tool-ask-user` ](../packages/interaction/tool-ask-user ) | - | UI front ends provide the active human-answer provider; tool-ask-user pauses a tool call on the provider-neutral ask() promise. |
2026-07-24 01:40:25 +08:00
| `ctx.planMode` | `core` | [`plan-mode` ](../packages/plan/plan-mode ) | - | - | - | Folds logged plan/mode state, flushes user selections at turn boundaries, renders deployment-owned guidance, registers /plan, and keeps the plan-exit schema stable across transitions. |
2026-08-08 14:04:53 +08:00
| `ctx.agentPresets` | `core` | [`agent-presets` ](../packages/preset/agent-presets ) | - | - | - | Discovers preset directories over trusted and user-authored roots and mounts one preset cordis.yml under an agent scope during creation, rejecting a row that never activates or that publishes into the root service realm. |
refactor(packages): dissolve ui/ and rename sdk/ to scaffold/
git mv per the regrouping RFC: the five human-collaboration seams and
tui join packages/interaction/, app-boot becomes packages/boot/, and
jsonrpc joins the renamed scaffold/ (formerly sdk/) as its server half
beside client/protocol/create-sdk/helper/scripts/telemetry, whose
folders drop the legacy sdk- prefix. Three new group README triplets
replace the ui/ and sdk/ ones; tsconfig references/paths/globs,
knip keys, vitest globs, gate scripts, catalogs, docs, and the
lockfile follow. Adds the four settled FIXME rename markers
(dsh-sdk-server, dsh-sdk-telemetry, dsh-sdk-helper, dsh-sdk-scripts).
The scaffold folders diverge from their npm names until those renames
land, so tsconfig.base.json maps the three affected names explicitly
beside the group wildcard. Also repairs two pre-existing stale-path
classes the strengthened sweep surfaced: docs/web-styling.md's retired
web-ui host package and type-model spec fixture-literal joins.
app-boot's three Loader-composition specs time out at the default 5s
under full-suite parallel load on this filesystem (pre-existing;
pass isolated with --testTimeout=30000); interaction/scaffold/boot
suites otherwise green (687 passed).
2026-07-30 03:13:49 +08:00
| `ctx.commands` | `core` | [`commands` ](../packages/interaction/commands ) | - | - | - | Plugins register direct human commands without sending invocations to the model. |
refactor(session): fold the session family into packages/session/
git mv the 12 packages from session-persistence/, session-projection/,
session-title/, and telemetry/ into one session/ group per the
regrouping RFC; merge the four group READMEs into one bilingual
triplet; rewrite the group segment in tsconfig references (intra-group
references shorten to ../<pkg>), tsconfig.base.json paths/globs,
knip.json keys, vitest include, gate scripts, and authored doc/note
citations; regenerate module graph, doc graphs, catalogs, and the
lockfile importer keys. No npm names change.
Full unit suite: 8779 passed; the 18 reported failures reproduce as
env flakes (ambient-proxy IPv6 tunneling, watched-dir inotify
timeouts under parallel load) — each passes in isolation with
NO_PROXY set, matching their known pre-existing behavior on master.
2026-07-30 01:52:06 +08:00
| `ctx.sessionProjections` | `core` | [`session-projection` ](../packages/session/session-projection ) | - | [`tool-todo` ](../packages/todo/tool-todo ), [`session-title` ](../packages/session/session-title ), [`host-apiproxy` ](../packages/host/apiproxy ) | - | Domains register state-driven fold units; the eager drive keeps per-session watermark states and api-proxy serves baselines and pushes changed values. |
| `ctx.sessionProjectionCache` | `core` | [`session-projection-cache` ](../packages/session/session-projection-cache ) | - | [`host-apiproxy` ](../packages/host/apiproxy ) | - | Durably checkpoints projection unit states per session (throttled + turn/end/detach mandatory points) and serves the cold-read ladder: cache row + persistence tail replay, so listings never load full logs. |
2026-08-13 00:36:22 +08:00
| `ctx.skills` | `seam` | [`skill` ](../packages/skill/skill ) | [`skill-badge` ](../packages/skill/skill-badge ), [`skill-filesystem` ](../packages/skill/skill-filesystem ) | [`tool-skill` ](../packages/skill/tool-skill ) | - | Merges provider skill catalogs; tool-skill renders the session-prefix catalog and loads complete skill bodies. |
| `ctx.agents` | `core` | [`agent` ](../packages/core/agent ) | - | [`agent-loop` ](../packages/core/agent-loop ), [`acp` ](../packages/acp/acp ), `subagent-inprocess` | - | Owns live Agent handles, the create/resume factory seam, and process-local initiator propagation. |
2026-07-22 15:13:12 +08:00
| `ctx.agentDefaultModel` | `core` | [`agent-default-model` ](../packages/core/agent-default-model ) | - | [`headless` ](../packages/bundle/headless ), [`host-apiproxy` ](../packages/host/apiproxy ) | - | Layers the default ModelSelection through settings so direct and Host-backed Agent entry points share one state owner. |
2026-07-15 15:57:57 +08:00
| `ctx.agentLoop` | `bundle` | [`agent-loop` ](../packages/core/agent-loop ) | - | [`agent-spine-demo` ](../packages/examples/agent-spine-demo ) | - | The one concrete loop plugin; extension packages depend on dsh-agent events and services, not on this package. |
2026-07-19 18:47:34 +08:00
| `ctx.goals` | `core` | [`goal` ](../packages/goal/goal ) | - | - | - | Folds revisioned objective state from the session log and keeps live continuation activation process-local. |
2026-08-07 21:04:33 +08:00
| `ctx.e2b` | `core` | [`e2b` ](../packages/e2b/e2b ) | - | [`fs-e2b` ](../packages/e2b/fs-e2b ), [`subprocess-e2b` ](../packages/e2b/subprocess-e2b ) | - | Owns one shared E2B SDK handle, remote working directory, and final sandbox disposition so both fundamental E2B providers inhabit the same Linux runtime. |
2026-08-13 00:36:22 +08:00
| `ctx.subprocess` | `seam` | [`subprocess` ](../packages/subprocess/subprocess ) | [`subprocess-local` ](../packages/subprocess/subprocess-local ), [`subprocess-e2b` ](../packages/e2b/subprocess-e2b ) | [`bash-local` ](../packages/shell/bash-local ), [`bash-sandbox` ](../packages/shell/bash-sandbox ), [`terminal-bash` ](../packages/terminal/terminal-bash ), [`lsp-stdio` ](../packages/lsp/lsp-stdio ), [`subagent-acp` ](../packages/subagent/subagent-acp ), [`subagent-codex` ](../packages/subagent/subagent-codex ), [`subagent-claude-code` ](../packages/subagent/subagent-claude-code ) | - | The bash executors, the PTY shell backend, the LSP host, and the out-of-process ACP, Codex, and Claude Code subagent backends spawn through ctx.subprocess; the service owns process coordinates, tree/session lifetime, stdio dispositions, terminal mechanics, and kill escalation. |
| `ctx.shell` | `seam` | [`shell` ](../packages/shell/shell ) | [`bash-local` ](../packages/shell/bash-local ), [`bash-sandbox` ](../packages/shell/bash-sandbox ), [`pwsh-local` ](../packages/shell/pwsh-local ) | [`tool-bash` ](../packages/shell/tool-bash ), [`tool-pwsh` ](../packages/shell/tool-pwsh ), [`hooks-claude-code` ](../packages/hooks/hooks-claude-code ), [`hooks-codex` ](../packages/hooks/hooks-codex ) | - | The model-facing shell tools and hook bridges consume this seam; sandboxed, remote, or PowerShell executors replace bash-local without touching them. |
| `ctx.shellEnv` | `core` | [`shell-env` ](../packages/shell/shell-env ) | - | [`tool-bash` ](../packages/shell/tool-bash ), [`tool-pwsh` ](../packages/shell/tool-pwsh ) | - | Plugins declare effect-scoped DSH_* facts; each shell tool collects one trusted snapshot per execution and its executor rebuilds the namespace. |
| `ctx.terminals` | `seam` | [`terminal` ](../packages/terminal/terminal ) | [`terminal-bash` ](../packages/terminal/terminal-bash ) | [`tool-terminal` ](../packages/terminal/tool-terminal ) | - | The registry owns exact-Agent session identity and cleanup; backends own terminal mechanics, while tool-terminal exposes the owner-scoped model tools. |
| `ctx.sandbox` | `seam` | [`sandbox` ](../packages/sandbox/sandbox ) | [`sandbox-local` ](../packages/sandbox/sandbox-local ) | [`bash-sandbox` ](../packages/shell/bash-sandbox ), [`terminal-bash` ](../packages/terminal/terminal-bash ) | - | Consumers hand over the exact argv they are about to spawn; same-world backends wrap it under a per-call policy and report enforcement. |
| `ctx.sandboxPolicy` | `core` | [`sandbox-policy` ](../packages/sandbox/sandbox-policy ) | - | [`bash-sandbox` ](../packages/shell/bash-sandbox ), [`fs-sandbox` ](../packages/fs/fs-sandbox ), [`terminal-bash` ](../packages/terminal/terminal-bash ) | - | The one home for the deployment default mode + workspace root; only the sandboxed executor and provider read the service (the tool layers use the pure `sandbox/mode` fold it also exports). Both enforcing families read it so bash and fs cannot confine to different roots. |
| `ctx.approval` | `seam` | `approval` | [`acp` ](../packages/acp/acp ) | [`tools` ](../packages/core/tools ), [`tool-bash` ](../packages/shell/tool-bash ) | - | One-shot permission decisions dispatched over the `approval/request` waterfall; answerers are listeners (the ACP bridge for its own agents), absence fails closed to `unavailable` . |
| `ctx.permissionPresets` | `core` | [`permission-presets` ](../packages/interaction/permission-presets ) | - | - | - | User-facing preset table (`workspace-write` /`danger-full-access` ) bundling the sandbox-mode and approval-policy knobs; a switch writes one `permission/preset` event through to both knob events. |
| `ctx.codeRuntime` | `seam` | [`code-runtime` ](../packages/code-runtime/code-runtime ) | `code-runtime-worker` | [`tools` ](../packages/core/tools ) | - | Runs one model-written program against host-provided async bindings; backends differ by substrate and language (the tool registry consumes it for Code Mode). |
| `ctx.fs` | `seam` | [`fs` ](../packages/fs/fs ) | [`fs-local` ](../packages/fs/fs-local ), [`fs-sandbox` ](../packages/fs/fs-sandbox ), [`fs-e2b` ](../packages/e2b/fs-e2b ) | [`tool-fs` ](../packages/fs/tool-fs ) | [`fs-observation-policy` ](../packages/fs/fs-observation-policy ) | tool-fs executes read/write/edit through ctx.fs; fs-sandbox fences mutations by the shared sandbox mode; fs-observation-policy contributes observed-state checks through the fs/* event gate. |
| `ctx.compaction` | `seam` | [`compaction` ](../packages/compaction/compaction ) | [`compaction-basic` ](../packages/compaction/compaction-basic ) | [`compaction-basic` ](../packages/compaction/compaction-basic ) | - | The basic backend consumes post-step pressure and request-error recovery events; there is no model-facing compact tool. |
| `ctx.subagents` | `seam` | [`subagent` ](../packages/subagent/subagent ) | [`subagent-spawn-in-process` ](../packages/subagent/subagent-spawn-in-process ), [`subagent-fork-in-process` ](../packages/subagent/subagent-fork-in-process ), [`subagent-acp` ](../packages/subagent/subagent-acp ), [`subagent-codex` ](../packages/subagent/subagent-codex ), [`subagent-claude-code` ](../packages/subagent/subagent-claude-code ), [`subagent-dsh-sdk` ](../packages/subagent/subagent-dsh-sdk ) | [`tool-subagent` ](../packages/subagent/tool-subagent ), [`tool-subagent-control` ](../packages/subagent/tool-subagent-control ), [`tool-ralph` ](../packages/workflow/tool-ralph ) | - | Providers implement transports; the service also owns optional Activation-based continuation orchestration, tool-subagent selects one-shot or continuable delegation, tool-subagent-control delivers follow-ups, and tool-ralph requires one fresh structured-output route. |
2026-08-19 22:44:23 +08:00
| `ctx.agentTeams` | `core` | `agent-team` | - | `tool-agent-team` | - | Owns the implicit-root roster, durable peer mailbox, shared task DAG, and continuable-child lifecycle; tool-agent-team contributes the scoped model policy and controls. |
2026-08-13 00:36:22 +08:00
| `ctx.jobs` | `seam` | [`jobs` ](../packages/jobs/jobs ) | [`jobs-local` ](../packages/jobs/jobs-local ) | [`tool-bash` ](../packages/shell/tool-bash ), [`tool-terminal` ](../packages/terminal/tool-terminal ), [`tool-subagent` ](../packages/subagent/tool-subagent ), [`tool-jobs` ](../packages/jobs/tool-jobs ) | - | Producers (background bash, PTY sends, and subagent delegations) register running work; tool-jobs is the model-facing controller that reads, lists, and kills it; jobs-local is the process-local registry. |
| `ctx.web` | `seam` | [`web` ](../packages/web/web ) | [`web-search-exa` ](../packages/web/web-search-exa ), [`web-search-perplexity` ](../packages/web/web-search-perplexity ), [`web-search-deepseek` ](../packages/web/web-search-deepseek ), [`web-fetch-http` ](../packages/web/web-fetch-http ) | [`tool-web` ](../packages/web/tool-web ) | - | Search and fetch providers register into one ctx.web seam; tool-web owns the stable model-facing names. |
2026-07-13 11:07:27 +08:00
| `ctx.spillStore` | `seam` | [`spill` ](../packages/spill/spill ) | [`spill-local` ](../packages/spill/spill-local ) | [`spill-policy` ](../packages/spill/spill-policy ) | - | The backend saves oversized tool text and returns a model-facing locator plus retrieval hint; spill-policy is the tools/post-execute consumer that decides when to spill. |
2026-07-29 02:11:31 +08:00
| `ctx.directoryPicker` | `seam` | `directory-picker` | `directory-picker-native` , `directory-picker-browse` | `apiproxy` | - | Discriminated interaction capability: the native backend opens one OS chooser on the host display, the browse backend serves listing/creation primitives for the in-app browser; dual-face backends fill ui-workspace directory-flow slots from their browser halves (no wire advertisement). |
2026-08-13 00:36:22 +08:00
| `ctx.webServer` | `core` | `webserver` | - | `connection` , `modules` , `hmr` | - | Plain node:http carrier: named-route registry, index transform taps, and the static dist fallback; web-transport plugins register their own routes. |
| `ctx.clientModules` | `core` | `modules` | - | `hmr` | - | Composes the __DSH_BOOT__ entry graph from an incremental dsh.client scan, serves plugin bundles, and notifies rebuilt/graph-changed subscribers. |
| `ctx.workflowEngine` | `seam` | [`workflow` ](../packages/workflow/workflow ) | [`workflow-worker-thread` ](../packages/workflow/workflow-worker-thread ) | [`tool-workflow` ](../packages/workflow/tool-workflow ), [`tool-ralph` ](../packages/workflow/tool-ralph ) | - | One engine per context, as in bash, with no named-provider registry; the general workflow and fixed Ralph consumers start runs whose agent() calls fan out through ctx.subagents. |
2026-08-22 23:44:56 +08:00
| `ctx.webhookRuntime` | `core` | [`webhook` ](../packages/webhook/webhook ) | - | [`webhook-github` ](../packages/webhook/webhook-github ) | - | Provider adapters dispatch authenticated deliveries; trusted plugins register independent process-local rules, and the runtime turns non-null results into ordinary Workspace-backed Sessions without delivery or completion state. |
2026-08-13 02:22:10 +08:00
| `ctx.lsp` | `seam` | [`lsp` ](../packages/lsp/lsp ) | `lsp-local` | [`tool-lsp` ](../packages/lsp/tool-lsp ) | - | Provider registration and selection plus normalized query execution over exactly four operations; the seam offers no protocol escape hatch, so a backend translates into the normalized request and result. |
| `ctx.apiProxy` | `core` | `apiproxy` | - | `connection` | - | The transport-agnostic host gateway face: it dispatches browser API calls, and each open host stream subscribes to the events it forwards rather than being pushed to through a broadcast verb. |
| `ctx.dynamicCordisRunner` | `core` | [`cordis-host-runner` ](../packages/extensions/cordis-host-runner ) | - | [`tool-cordis` ](../packages/extensions/tool-cordis ) | - | Owns the in-memory definition registry, the vm sandbox for host halves, and the request-run round trip; browser pages reach the same service over the wire through its remote namespace. |
| `ctx.cordisInspect` | `core` | [`cordis-host-runner` ](../packages/extensions/cordis-host-runner ) | - | [`tool-cordis` ](../packages/extensions/tool-cordis ) | - | Registers host inspect providers, mirrors the client provider manifest, and routes client queries through the dynamic Cordis transport. |
2026-07-05 02:54:01 +08:00
Maintenance mode: hybrid: services are discovered from Cordis declarations; interface/implementation/consumer roles are classified in `scripts/gen-doc-graphs.ts` with a completeness guard.