Files
deepseek-harness/packages
Tianyi Cui d801f262d8 fix(python-sdk): resolve packaged proxies from real module entries
The packaged dsh launcher must expose installation modules to profile-local plugins without writing symlinks into pkg's virtual filesystem. The first review fix selected ESM exports correctly in ordinary Node, but real carrier execution exposed package metadata and VFS behavior that a synthetic tree did not cover: executable and declaration packages have no import entry, legacy main fields rely on Node probing, and pkg's Windows VFS prevents filesystem package-scope resolution from seeing exports such as zod/mini and @google/genai/web.

Resolve explicit exports directly from each installed manifest with the maintained resolve.exports package under Node import conditions. Publish only package-local candidate files that exist, reject escaping or malformed targets, preserve the package installation URL without realpath, and keep Node's legacy resolver only for exports-less packages. This avoids pkg filesystem package lookup entirely while retaining fail-loud behavior for broken runtime entries.

Add regression coverage for import-only, nested, symlinked, zod-style, and genai-style condition maps; unavailable and types-only entries; invalid and escaping targets; executable/declaration packages; extensionless main; and legacy index fallback. profile.ts remains at 100% statements, branches, functions, and lines. Update the bilingual package and Agent Note contracts, replace the runtime dependency and generated notice, and regenerate the lockfile through pnpm.
2026-08-24 17:28:27 +08:00
..
2026-08-21 19:48:58 +08:00
2026-08-21 19:48:58 +08:00
2026-08-21 19:48:58 +08:00
2026-08-21 19:48:58 +08:00
2026-08-21 19:48:58 +08:00
2026-08-21 19:48:58 +08:00
2026-08-21 19:48:58 +08:00
2026-08-21 19:48:58 +08:00

Packages

English | 中文

npm scope: @deepseek-ai/dsh-*; Cordis Service subclasses and function plugins contribute through ctx.effect(), ctx.on(), or ctx.waterfall(). Rules: package, root.

Hierarchy

Groups hold packages/<group>/<pkg>/; names stay @deepseek-ai/dsh-<pkg>. Group READMEs own package/ctx-key maps.

Group Role Release expectation
core/ Product API spine: sessions, prompts, tools, agent services, and the concrete loop Product — stable API
api/ Remote BFF assembly and Typert RPC gateway Product — stable API
typert/ Type graph generation, artifact loading, and runtime registry Product — stable API
goal/ Same-session goal persistence and lifecycle Product — stable API
schedule/ Session-local scheduled follow-ups Product — stable API
feedback/ Human feedback Product — stable API
identity/ Shared anonymous identity Product — stable API
llm/ LLM capability family: the abstract service + provider adapters Product — stable API
e2b/ E2B providers POC
subprocess/ Subprocess capability family: Service Definition, local process-tree provider, and shared Win32 process library Product — stable API
shell/ Bash capability family: executor seam, local impl, model-facing tool Product — stable API
terminal/ Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools Product — stable API
code-runtime/ Code-execution capability family: Service Definition + worker-thread provider + Code Mode Consumer Product — stable API
sandbox/ Process-confinement seam; bwrap/Landlock/Seatbelt backends Product — stable API
fs/ Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools Product — stable API
lsp/ LSP capability family: seam, generic stdio provider, and the lsp tool Product — stable API
skill/ Skill capability family: the provider registry, local provider, and model-facing catalog/loader Product — stable API
compaction/ Compaction capability family: Service Definition + basic provider + command Consumer Product — stable API
context/ Model-visible request context, including workspace instructions and time context Product — stable API
subagent/ Subagent capability family: the provider-registry contract and the model-facing delegation tool Product — stable API
jobs/ Generic background-job runtime and model-facing job_* control tools Product — stable API
experimental/ Private prototypes and internal-only plugins Unreleased
workflow/ Workflow seam, worker-thread engine, and model-facing workflow/ralph tools Product — stable API
webhook/ Verified external events, rules, and fire-and-forget Workspace Sessions Product — stable API
web/ Web capability family: seam, search/fetch provider impls, and the model-facing web tools Product — stable API
attachment/ Durable attachment identity, validation, local content-addressed storage Product — stable API
spill/ Spill capability family: storage seam, local impl, tool-result spill policy Product — stable API
todo/ The model-facing todo_write tool Product — stable API
plan/ Plan collaboration state with a direct entry command and reviewed exit Product — stable API
preset/ Per-session agent composition from preset cordis.yml files Product — stable API
guard/ Loop-hygiene guards: advisory repeat-call reminders + the tools/execute deadline enforcer Product — stable API
bundle/ Installable dsh --profile patch layers Product — stable API
extensions/ Agent runtime self-modification: live plugin/service inspection and model-written plugin mount/unmount (design) Product — stable API
hooks/ Hook bridges + the shared Claude Code / Codex wire-protocol library Product — stable API
session/ Durable session data plane: persistence seam + JSONL/SQLite backends, projection seam, log-backed titles, session reporting Product — stable API
session-query/ Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search Product — stable API
settings/ User-settings seam + file-backed provider Product — stable API
credentials/ Credential reference/record seam + env-over-.env provider + authorization flows Product — stable API
storage/ Non-session storage hub + backends + domain form Product — stable API
workspace/ Workspace entity Product — stable API
sdk/ Out-of-process SDK: JSON-RPC protocol and TypeScript client/server Product — stable API
acp/ Automation-only Agent Client Protocol server Product — stable API
interaction/ Human-collaboration plane: approval/interaction seams, permission preset, commands, ask-user tool Product — stable API
boot/ Shared app-bin boot glue Product — stable API
host/ Web-GUI host half: API gateway + HTTP route server Product — stable API
client/ Web-GUI browser half: shell, wire, object services, slots, ui-* plugins Product — stable API
examples/ Reusable demo bundles for runnable example leaves Support — example infra
test-support/ Support infrastructure (testkits, invariants, replay, Loader smokes) Support — lower compatibility expectations
util/ Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) Support — small, stable, harness-dep-free

New packages join existing groups; new groups update their README and this table.

Dependencies

The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).

Extension plugins depend on Service Definitions, never concrete providers. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities separate Service Definition / Service Provider / Consumer roles when they evolve independently; see capability seams.

Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.