2026-07-11 14:08:26 +08:00
{
"name" : "dsh-jsonrpc-agent-pkg" ,
2026-07-14 00:40:36 +08:00
"description" : "Dependency-only deploy root defining the executable and Python runtime closure; pnpm deploy materializes this manifest and node_modules." ,
2026-07-11 14:08:26 +08:00
"version" : "0.0.1" ,
"private" : true ,
"type" : "module" ,
"dependencies" : {
2026-08-06 11:57:00 +08:00
"@cordisjs/plugin-group" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@cordisjs/plugin-include" : "workspace:^" ,
"@cordisjs/plugin-loader" : "workspace:^" ,
"@cordisjs/plugin-timer" : "workspace:^" ,
"@deepseek-ai/dsh-acp" : "workspace:^" ,
"@deepseek-ai/dsh-agent" : "workspace:^" ,
"@deepseek-ai/dsh-agent-loop" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-agent-spine-demo" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-app-boot" : "workspace:^" ,
"@deepseek-ai/dsh-bash" : "workspace:^" ,
2026-08-02 14:17:46 +08:00
"@deepseek-ai/dsh-bash-env" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-bash-local" : "workspace:^" ,
"@deepseek-ai/dsh-brand" : "workspace:^" ,
"@deepseek-ai/dsh-code-runtime" : "workspace:^" ,
"@deepseek-ai/dsh-code-runtime-worker" : "workspace:^" ,
2026-07-20 12:11:06 +08:00
"@deepseek-ai/dsh-command-goal" : "workspace:^" ,
2026-07-19 22:11:59 +08:00
"@deepseek-ai/dsh-commands" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-compact" : "workspace:^" ,
"@deepseek-ai/dsh-compact-basic" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-compact-tool-result-prune" : "workspace:^" ,
"@deepseek-ai/dsh-credentials" : "workspace:^" ,
feat(config)!: one ordering for configuration sources, and a bootstrap deny rule
$DSH_HOME/.env had just become an ordinary environment layer, which left the
harness resolving user-facing values from a flattened process.env that could
no longer say where a value came from. A key stored through the web page
stayed shadowed by an older key in the user's own .env. An endpoint could be
redirected by the project: the invoking directory's .env is materialized like
every other layer, and a base URL decides where a resolved API key is sent, so
a DEEPSEEK_BASE_URL written into a model-editable workspace would send the
user's credential — and the prompts carrying their code — to whatever host
that file named.
Give every user-facing value one ordering, with four kinds of source:
explicit for this run per-operation override, CLI argument
> authored by deployment --config / --config-replace
> this launch's shell inherited process environment
> product-managed store settings.yaml, .credentials.yaml
> discovered file $DSH_HOME/.env
> defaults schema default, shipped base, public default
The domains differ only in which tiers exist. The earlier split — credentials
ranking the environment over the managed file while settings ranked over the
environment — was inconsistent: the distinguishing fact is who authored the
source, not the domain.
packages/util/environment owns an immutable snapshot with per-layer
provenance. getFrom(name, sources) searches only the layers a caller names,
and omitting one is a refusal rather than a demotion: the adapters ask for
['process', 'user-env'], so no reordering can let a project file back into a
decision it was excluded from.
isBootstrapOnly rejects, before anything is materialized, any .env setting a
variable that governs how a process launches (PATH, SHELL, NODE_OPTIONS,
LD_PRELOAD), where code or model-visible instructions load from (the whole
DSH_* namespace, HOME, XDG_*), or how the network is reached (proxy and CA
variables). The namespace is denied wholesale so a switch added later cannot
become settable by being forgotten, and there is no opt-out.
verify-config-source-ownership keeps both rules: no unregistered process.env
read under packages/*/*/src (26 allowlisted with reasons), and no apiKey,
baseURL, or headers inlined from the environment in shipped Cordis config —
removing those inlines is what makes the deployment tier meaningful.
2026-08-04 16:17:32 +08:00
"@deepseek-ai/dsh-environment" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-fs" : "workspace:^" ,
"@deepseek-ai/dsh-fs-local" : "workspace:^" ,
"@deepseek-ai/dsh-fs-policy" : "workspace:^" ,
2026-07-19 23:55:33 +08:00
"@deepseek-ai/dsh-goal" : "workspace:^" ,
"@deepseek-ai/dsh-goal-session" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-hook-protocol" : "workspace:^" ,
"@deepseek-ai/dsh-hooks-claude" : "workspace:^" ,
"@deepseek-ai/dsh-hooks-codex" : "workspace:^" ,
"@deepseek-ai/dsh-invariants" : "workspace:^" ,
"@deepseek-ai/dsh-jsonrpc" : "workspace:^" ,
2026-07-15 15:57:57 +08:00
"@deepseek-ai/dsh-jsonrpc-demo" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-llm" : "workspace:^" ,
"@deepseek-ai/dsh-llm-deepseek" : "workspace:^" ,
"@deepseek-ai/dsh-llm-pi-ai" : "workspace:^" ,
2026-07-20 03:34:19 +08:00
"@deepseek-ai/dsh-llm-retry" : "workspace:^" ,
2026-07-14 19:50:25 +08:00
"@deepseek-ai/dsh-paths" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-permission" : "workspace:^" ,
"@deepseek-ai/dsh-plan-mode" : "workspace:^" ,
2026-07-29 14:12:27 +08:00
"@deepseek-ai/dsh-pty" : "workspace:^" ,
"@deepseek-ai/dsh-pty-local" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-repeat-tool-guard" : "workspace:^" ,
2026-07-21 16:46:48 +08:00
"@deepseek-ai/dsh-retention" : "workspace:^" ,
2026-07-13 16:34:09 +08:00
"@deepseek-ai/dsh-sandbox" : "workspace:^" ,
2026-07-29 14:12:27 +08:00
"@deepseek-ai/dsh-sandbox-local" : "workspace:^" ,
feat(sandbox): cross-family file sandbox — one policy home, sandboxed fs provider, fs escalation parity
Extend SandboxMode enforcement from bash to the filesystem tools, the sandbox
RFC's deferred cross-family phase.
- dsh-sandbox-policy (new, ctx.sandboxPolicy): the single home for the
deployment default mode + workspaceRoot and the per-session override event,
renamed bash/sandbox-mode -> sandbox/mode and moved here with its fold/setter.
Decouples the bash seam from dsh-session.
- dsh-fs-sandbox (new): SandboxedFileSystem extends LocalFileSystem and fences
write/edit by the per-call mode (read-only denies, workspace-write contains to
the workspace + temp roots via the shared writableRoots, danger passes
through); reads pass through. Structured FS_SANDBOX_DENIED; in-lock parent
re-canonicalization. A policy fence in trusted code, not a kernel boundary.
- dsh-sandbox: the shared escalation kit (writableRoots, the strictly-wider
ladder, denial/hint markers, approveEscalation) both tool families use;
approveEscalation takes a structural approver so dsh-sandbox gains no
approval/agent dependency, and both tools stay duplication-free.
- tool-fs: write/edit advertise sandbox_permissions/justification under a
confining ctx.fs, map FS_SANDBOX_DENIED to the shared [sandbox: ...] marker,
and resolve the same one-approved-wider retry.
- examples/acp-agent: composes sandbox-policy + fs-sandbox, drops the gating
that disabled the fs stack under confined modes.
RFC docs/rfc/implemented/feature/2026-07-14-cross-family-fs-sandbox.md; the old
sandbox RFC's In-process/deferred/FAQ sections updated to shipped fact.
2026-07-14 20:05:57 +08:00
"@deepseek-ai/dsh-sandbox-policy" : "workspace:^" ,
2026-07-13 16:34:09 +08:00
"@deepseek-ai/dsh-scope" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-sdk-protocol" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-session" : "workspace:^" ,
2026-07-21 15:23:45 +08:00
"@deepseek-ai/dsh-session-checkpoint-policy" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-session-persistence" : "workspace:^" ,
"@deepseek-ai/dsh-session-persistence-jsonl" : "workspace:^" ,
"@deepseek-ai/dsh-session-persistence-sqlite" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-session-projection" : "workspace:^" ,
2026-07-21 16:46:48 +08:00
"@deepseek-ai/dsh-session-query" : "workspace:^" ,
2026-07-23 20:16:14 +08:00
"@deepseek-ai/dsh-session-query-sqlite" : "workspace:^" ,
2026-07-21 16:46:48 +08:00
"@deepseek-ai/dsh-session-reference" : "workspace:^" ,
2026-07-21 01:53:24 +08:00
"@deepseek-ai/dsh-session-title" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-settings" : "workspace:^" ,
2026-07-13 16:34:09 +08:00
"@deepseek-ai/dsh-skill" : "workspace:^" ,
"@deepseek-ai/dsh-skill-local" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-subagent" : "workspace:^" ,
"@deepseek-ai/dsh-subagent-acp" : "workspace:^" ,
"@deepseek-ai/dsh-subagent-fork" : "workspace:^" ,
"@deepseek-ai/dsh-subagent-inprocess" : "workspace:^" ,
"@deepseek-ai/dsh-subagent-spawn" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-subprocess" : "workspace:^" ,
"@deepseek-ai/dsh-subprocess-local" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-system-prompt" : "workspace:^" ,
2026-07-14 09:59:21 +08:00
"@deepseek-ai/dsh-tasks" : "workspace:^" ,
2026-07-26 05:13:39 +08:00
"@deepseek-ai/dsh-tasks-local" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-timeout" : "workspace:^" ,
"@deepseek-ai/dsh-timeout-policy" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-token-meter" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-tool-ask-user" : "workspace:^" ,
"@deepseek-ai/dsh-tool-bash" : "workspace:^" ,
2026-07-29 14:12:27 +08:00
"@deepseek-ai/dsh-tool-bash-persistent" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-tool-cordis" : "workspace:^" ,
"@deepseek-ai/dsh-tool-fs" : "workspace:^" ,
2026-07-19 23:55:33 +08:00
"@deepseek-ai/dsh-tool-goal" : "workspace:^" ,
2026-07-13 16:34:09 +08:00
"@deepseek-ai/dsh-tool-skill" : "workspace:^" ,
2026-07-30 19:46:04 +08:00
"@deepseek-ai/dsh-tool-str-replace-editor" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-tool-subagent" : "workspace:^" ,
feat(subagent): continuable background subagents
Implement the continuable background subagents RFC: a durable child
session with a series of Task-backed activations, each disposing its
run before the Task settles.
- dsh-subagent: rename SubagentRun.sendMessage to strict steer, drop
run-level resume, add SubagentProvider.resume dispatch via
SubagentService.resume, the continuation start field, and the
versioned model-hidden subagent/descriptor session event.
- dsh-subagent-inprocess/-spawn/-fork: publish the control-allocated
child id, append the descriptor inside the initial turn, implement
cold resume from the child's own transcript under the live parent
scope, and strict running-only steer.
- dsh-subagent-control (new): SubagentControlService owning stable
child ids, descriptor snapshot/fold/authorization, Task-backed
activation with settle-then-dispose ordering, the process-local
active-run association, and steer-or-resume sendMessage routing.
- dsh-tool-subagent: background route branches on the provider's
resume capability (continuable via the control service; one-shot
task for ACP), returning both child and task ids.
- dsh-tool-subagent-control (new): the globally named send_message
tool rendering steered/started routes.
Keyless coverage spans Task ownership and disposal ordering, running
delivery, cold follow-up, descriptor rejection and rollback, known-id
reconstruction, kill during lookup, admission races, and a new
subagent-continuable ACP snapshot scenario.
2026-07-23 17:07:38 +08:00
"@deepseek-ai/dsh-tool-subagent-control" : "workspace:^" ,
2026-07-14 09:59:21 +08:00
"@deepseek-ai/dsh-tool-tasks" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-tool-todo" : "workspace:^" ,
"@deepseek-ai/dsh-tool-web" : "workspace:^" ,
"@deepseek-ai/dsh-tool-workflow" : "workspace:^" ,
"@deepseek-ai/dsh-tools" : "workspace:^" ,
2026-08-05 23:18:35 +08:00
"@deepseek-ai/dsh-type-meta" : "workspace:^" ,
2026-07-13 16:34:09 +08:00
"@deepseek-ai/dsh-user-approval" : "workspace:^" ,
2026-07-11 14:08:26 +08:00
"@deepseek-ai/dsh-user-interaction" : "workspace:^" ,
"@deepseek-ai/dsh-web" : "workspace:^" ,
"@deepseek-ai/dsh-web-fetch-local" : "workspace:^" ,
"@deepseek-ai/dsh-web-search-deepseek" : "workspace:^" ,
"@deepseek-ai/dsh-web-search-exa" : "workspace:^" ,
"@deepseek-ai/dsh-web-search-perplexity" : "workspace:^" ,
"@deepseek-ai/dsh-workflow" : "workspace:^" ,
"@deepseek-ai/dsh-workflow-workerthread" : "workspace:^" ,
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
"@deepseek-ai/dsh-workspace-context" : "workspace:^" ,
"cordis" : "workspace:^" ,
"schemastery" : "workspace:^"
2026-07-11 14:08:26 +08:00
}
}