deepseek-harness/packages/ui
Turtle ad4aeacd19 fix(hmr,include): settle a failing boot instead of a silent exit 13
Master's transactional loader made the invalid-provider PTY case regress:
the HMR main watcher's initial scan refreshed the include mid-initial-apply,
the concurrent group updates stranded the include fiber, and once serialized
the failing apply's rollback deadlocked on HMR's refresh drain — dsh exited
13 with no diagnostic and the terminal stranded, the exact symptom this
branch fixes. Serialize every include child-tree mutation through one queue
and pass ignoreInitial to the HMR main watcher; the failing boot now settles
through boot()'s labelled rejection with the tree disposed and exit 1. The
PTY case asserts the settled diagnostic; the fail-loud release remains the
guard for rejections boot cannot see.
2026-08-03 14:14:20 +08:00
..
app-boot fix(hmr,include): settle a failing boot instead of a silent exit 13 2026-08-03 14:14:20 +08:00
commands Merge commit 'ecbf75a5e70f662b6420375140cf12eb6bac7860' into worktree/retarget-pr885-20260729 2026-07-29 21:37:43 +08:00
jsonrpc Merge commit 'refs/codex/pr1006/master' into worktree/pr1006-merge-20260731 2026-07-31 01:55:19 +08:00
permission merge master and address permission settings review 2026-07-31 13:24:30 +08:00
tool-ask-user docs(i18n): address automated review 2026-07-29 17:46:06 +08:00
tui fix(subagent): confirm steering request admission 2026-08-02 04:34:16 +08:00
user-approval feat(system-prompt): cache dynamic policy context 2026-07-30 22:09:15 +08:00
user-interaction fix(web): keep the plan card to decisions it can actually answer 2026-07-30 19:38:18 +08:00
README.i18n.yaml docs(ui): drop unrelated translation churn 2026-07-29 21:36:07 +08:00
README.md docs(ui): drop unrelated translation churn 2026-07-29 21:36:07 +08:00
README.zh.md docs(ui): drop unrelated translation churn 2026-07-29 21:36:07 +08:00

ui/ — human and SDK-client integration surfaces

English | 中文

Human-facing channels and the out-of-process SDK server. These are product packages: real interfaces that a person or SDK client drives.

Package Role ctx key
commands/ Human-command registry: shared discovery metadata, scoped shadowing, cancellation, and direct UI dispatch ctx.commands
user-approval/ One-shot user-approval mechanism, closed outcome vocabulary, audit events, and per-session approval policy ctx.approval
permission/ User-facing permission presets (workspace-write/danger-full-access): one product-level select bundling the sandbox-mode and approval-policy knobs, written through to their session events ctx.permission
user-interaction/ Abstract human question/answer seam used by UI-backed confirmation tools ctx.userInteraction
tool-ask-user/ Model-facing ask_user_question tool over ctx.userInteraction (registers on ctx.tools)
tui/ Interactive pi-tui terminal channel; renders session titles/events and tool intents, answers ctx.userInteraction, and hosts effect-owned plugin overlays ctx.tui (drives ctx.agents)
jsonrpc/ Stdio JSON-RPC server for out-of-process SDK clients (drives ctx.agents)
app-boot/ Shared boot glue for the app bins: .env loading, fail-loud Loader guards, snapshot-aware config resolution, the settle-the-tree boot sequence (library for the bins)

A UI integration is a client-driver plugin, not a loop change: it consumes the existing agent/* event taxonomy and the dsh-agent factory. tui is the interactive terminal front door and supplies the terminal-local ctx.tui extension service; jsonrpc serves out-of-process SDK clients, while non-interactive one-shot tasks use cli-demo. commands is the human-only discovery and dispatch plane consumed by TUI; command input and output do not become model messages.

user-approval, user-interaction, and tool-ask-user live here because asking a human is a UI-backed product affordance, not part of the providerless core spine. user-approval owns the one-shot ctx.approval decision mechanism and its policy tier; answerers remain with the channel or automation transport that owns the agent. user-interaction remains provider-neutral (ctx.userInteraction), while tool-ask-user is its model-facing consumer and interactive app packages provide concrete providers.

The runnable app bundles composed over agent-spine-demo live in examples/ (tui-demo, acp-demo, jsonrpc-demo). acp-demo and jsonrpc-demo own boot bins; the tui-demo bundle is booted by the product dsh CLI. ui/ keeps the reusable human/SDK channel plugins and shared app-boot glue; the automation-only ACP transport lives in acp/. Each front door owns its stdout policy, and a leaf cordis.yml supplies backends and optional tools.