The packaged dsh launcher must expose installation modules to profile-local plugins without writing symlinks into pkg's virtual filesystem. The first review fix selected ESM exports correctly in ordinary Node, but real carrier execution exposed package metadata and VFS behavior that a synthetic tree did not cover: executable and declaration packages have no import entry, legacy main fields rely on Node probing, and pkg's Windows VFS prevents filesystem package-scope resolution from seeing exports such as zod/mini and @google/genai/web. Resolve explicit exports directly from each installed manifest with the maintained resolve.exports package under Node import conditions. Publish only package-local candidate files that exist, reject escaping or malformed targets, preserve the package installation URL without realpath, and keep Node's legacy resolver only for exports-less packages. This avoids pkg filesystem package lookup entirely while retaining fail-loud behavior for broken runtime entries. Add regression coverage for import-only, nested, symlinked, zod-style, and genai-style condition maps; unavailable and types-only entries; invalid and escaping targets; executable/declaration packages; extensionless main; and legacy index fallback. profile.ts remains at 100% statements, branches, functions, and lines. Update the bilingual package and Agent Note contracts, replace the runtime dependency and generated notice, and regenerate the lockfile through pnpm.
Packages
English | 中文
npm scope: @deepseek-ai/dsh-*; Cordis Service subclasses and function plugins contribute through ctx.effect(), ctx.on(), or ctx.waterfall(). Rules: package, root.
Hierarchy
Groups hold packages/<group>/<pkg>/; names stay @deepseek-ai/dsh-<pkg>. Group READMEs own package/ctx-key maps.
| Group | Role | Release expectation |
|---|---|---|
core/ |
Product API spine: sessions, prompts, tools, agent services, and the concrete loop | Product — stable API |
api/ |
Remote BFF assembly and Typert RPC gateway | Product — stable API |
typert/ |
Type graph generation, artifact loading, and runtime registry | Product — stable API |
goal/ |
Same-session goal persistence and lifecycle | Product — stable API |
schedule/ |
Session-local scheduled follow-ups | Product — stable API |
feedback/ |
Human feedback | Product — stable API |
identity/ |
Shared anonymous identity | Product — stable API |
llm/ |
LLM capability family: the abstract service + provider adapters | Product — stable API |
e2b/ |
E2B providers | POC |
subprocess/ |
Subprocess capability family: Service Definition, local process-tree provider, and shared Win32 process library | Product — stable API |
shell/ |
Bash capability family: executor seam, local impl, model-facing tool | Product — stable API |
terminal/ |
Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools | Product — stable API |
code-runtime/ |
Code-execution capability family: Service Definition + worker-thread provider + Code Mode Consumer | Product — stable API |
sandbox/ |
Process-confinement seam; bwrap/Landlock/Seatbelt backends | Product — stable API |
fs/ |
Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools | Product — stable API |
lsp/ |
LSP capability family: seam, generic stdio provider, and the lsp tool |
Product — stable API |
skill/ |
Skill capability family: the provider registry, local provider, and model-facing catalog/loader | Product — stable API |
compaction/ |
Compaction capability family: Service Definition + basic provider + command Consumer | Product — stable API |
context/ |
Model-visible request context, including workspace instructions and time context | Product — stable API |
subagent/ |
Subagent capability family: the provider-registry contract and the model-facing delegation tool | Product — stable API |
jobs/ |
Generic background-job runtime and model-facing job_* control tools |
Product — stable API |
experimental/ |
Private prototypes and internal-only plugins | Unreleased |
workflow/ |
Workflow seam, worker-thread engine, and model-facing workflow/ralph tools |
Product — stable API |
webhook/ |
Verified external events, rules, and fire-and-forget Workspace Sessions | Product — stable API |
web/ |
Web capability family: seam, search/fetch provider impls, and the model-facing web tools | Product — stable API |
attachment/ |
Durable attachment identity, validation, local content-addressed storage | Product — stable API |
spill/ |
Spill capability family: storage seam, local impl, tool-result spill policy | Product — stable API |
todo/ |
The model-facing todo_write tool |
Product — stable API |
plan/ |
Plan collaboration state with a direct entry command and reviewed exit | Product — stable API |
preset/ |
Per-session agent composition from preset cordis.yml files |
Product — stable API |
guard/ |
Loop-hygiene guards: advisory repeat-call reminders + the tools/execute deadline enforcer |
Product — stable API |
bundle/ |
Installable dsh --profile patch layers |
Product — stable API |
extensions/ |
Agent runtime self-modification: live plugin/service inspection and model-written plugin mount/unmount (design) | Product — stable API |
hooks/ |
Hook bridges + the shared Claude Code / Codex wire-protocol library | Product — stable API |
session/ |
Durable session data plane: persistence seam + JSONL/SQLite backends, projection seam, log-backed titles, session reporting | Product — stable API |
session-query/ |
Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search | Product — stable API |
settings/ |
User-settings seam + file-backed provider | Product — stable API |
credentials/ |
Credential reference/record seam + env-over-.env provider + authorization flows |
Product — stable API |
storage/ |
Non-session storage hub + backends + domain form | Product — stable API |
workspace/ |
Workspace entity | Product — stable API |
sdk/ |
Out-of-process SDK: JSON-RPC protocol and TypeScript client/server | Product — stable API |
acp/ |
Automation-only Agent Client Protocol server | Product — stable API |
interaction/ |
Human-collaboration plane: approval/interaction seams, permission preset, commands, ask-user tool | Product — stable API |
boot/ |
Shared app-bin boot glue | Product — stable API |
host/ |
Web-GUI host half: API gateway + HTTP route server | Product — stable API |
client/ |
Web-GUI browser half: shell, wire, object services, slots, ui-* plugins |
Product — stable API |
examples/ |
Reusable demo bundles for runnable example leaves | Support — example infra |
test-support/ |
Support infrastructure (testkits, invariants, replay, Loader smokes) | Support — lower compatibility expectations |
util/ |
Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) |
Support — small, stable, harness-dep-free |
New packages join existing groups; new groups update their README and this table.
Dependencies
The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).
Extension plugins depend on Service Definitions, never concrete providers. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities separate Service Definition / Service Provider / Consumer roles when they evolve independently; see capability seams.
Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.