`dsh` shipped two config trees that were 43 rows the same: apps/cli/cordis.yml composed web as 74 flat rows, while the TUI booted examples/tui-agent/cordis.yml whose single `@deepseek-ai/dsh-tui-demo` row mounted twelve plugins behind a twenty-key pass-through Config. Neither file was what its location claimed — apps/cli hardcoded the "example" as the product default and the "demo" bundle was the application — and every capability change had to be made twice. - apps/cli/base.cordis.yml holds the 43 shared rows; tui.cordis.yml and web.cordis.yml are patch lists stating only what differs per surface - overlays apply as SIBLING patch lists at one include level, because include patches never cross an include boundary. Precedence: base < surface < (--config | personal ~/.dsh/config.yaml) < launcher flag/profile patches - `--config` now applies an overlay INSTEAD OF the personal one, so a demo or test tree never inherits the user's route; new `--config-replace` boots a file as the entire tree (the old `--config` behaviour). Both survive /resume - vendor/include: index each `insert`ed row as it is added so a later patch can configure or disable it. Upstream built the id index once before the patch loop, leaving every surface-only row — the whole TUI front door — silently unpatchable from user config. Logged as local modification 8 - session identity moves to dsh-agent-loop's CONFIGURED_AGENT_IDENTITIES_KEY; dsh-tui's MAIN_SESSION_ID_KEY is deleted (only the bundle read it) - delete examples/tui-agent, examples/cordis-agent, packages/examples/tui-demo; TUI tests → apps/cli/tests, cordis e2e → packages/cordis/tool-cordis/tests, examples/code-mode survives as an overlay leaf - `dsh web` gains --config, threaded into AppCLIEntry as an extra overlay Three latent defects surfaced and are fixed here: the TUI captured the optional sessionQuery service once at construction and could permanently disable /resume when it won the mount race; the session-store root silently reverted to a project-local ./.sessions; --config-replace was dropped by the resume handoff. Verified by booting each tree through the real Loader (TUI 55 entries, web 75, zero unsettled) rather than reading YAML. All eight terminal snapshots replay byte-identically; 14/14 PTY smoke, 112/112 snapshots, 25/25 doc-sync, hygiene and lint clean.
ui/ — human and SDK-client integration surfaces
English | 中文
Human-facing channels and the out-of-process SDK server. These are product packages: real interfaces that a person or SDK client drives.
| Package | Role | ctx key |
|---|---|---|
commands/ |
Human-command registry: shared discovery metadata, scoped shadowing, cancellation, and direct UI dispatch | ctx.commands |
user-approval/ |
One-shot user-approval mechanism, closed outcome vocabulary, audit events, and per-session approval policy | ctx.approval |
permission/ |
User-facing permission presets (workspace-write/danger-full-access): one product-level select bundling the sandbox-mode and approval-policy knobs, written through to their session events |
ctx.permission |
user-interaction/ |
Abstract human question/answer seam used by UI-backed confirmation tools | ctx.userInteraction |
tool-ask-user/ |
Model-facing ask_user_question tool over ctx.userInteraction |
(registers on ctx.tools) |
tui/ |
Interactive pi-tui terminal channel; renders session titles/events and tool intents, answers ctx.userInteraction, and hosts effect-owned plugin overlays |
ctx.tui (drives ctx.agents) |
jsonrpc/ |
Stdio JSON-RPC server for out-of-process SDK clients | (drives ctx.agents) |
app-boot/ |
Shared boot glue for the app bins: .env loading, fail-loud Loader guards, snapshot-aware config resolution, the settle-the-tree boot sequence |
(library for the bins) |
A UI integration is a client-driver plugin, not a loop change: it consumes the existing agent/* event taxonomy and the dsh-agent factory. tui is the interactive terminal front door and supplies the terminal-local ctx.tui extension service; jsonrpc serves out-of-process SDK clients, while non-interactive one-shot tasks use cli-demo. commands is the human-only discovery and dispatch plane consumed by TUI; command input and output do not become model messages.
user-approval, user-interaction, and tool-ask-user live here because asking a human is a UI-backed product affordance, not part of the providerless core spine. user-approval owns the one-shot ctx.approval decision mechanism and its policy tier; answerers remain with the channel or automation transport that owns the agent. user-interaction remains provider-neutral (ctx.userInteraction), while tool-ask-user is its model-facing consumer and interactive app packages provide concrete providers.
The runnable app bundles composed over agent-spine-demo live in examples/ (cli-demo, acp-demo, jsonrpc-demo). acp-demo and jsonrpc-demo own boot bins; The product dsh CLI uses no bundle: it boots the flat config trees in apps/cli. ui/ keeps the reusable human/SDK channel plugins and shared app-boot glue; the automation-only ACP transport lives in acp/. Each front door owns its stdout policy, and a leaf cordis.yml supplies backends and optional tools.