Files
deepseek-harness/packages
Yichen Jiang 9f996be8e3 fix(web-config): close the wire boundary, the redacted-replace data loss, and three P2s
Five findings from the #939 review, each reproduced before being fixed.

**Configuration reads are as privileged as writes.** `settings.describe`
returns every exposed namespace's configuration and `credentials.describe`
reports whether an arbitrary environment-variable name is configured and from
where — reconnaissance no anonymous caller should have. Both join
PRIVILEGED_METHODS, so the whole configuration plane is loopback-only until
real authentication exists; `trustedHosts` was never authentication. The model
catalog stays reachable: it carries no endpoints or key state, and a LAN
client's model picker legitimately needs it. Asserted over a real HTTP server,
because the Host header a browser actually sends is what decides this.

**The proxy serves only namespaces a registered model provider addresses.**
The settings seam is general — any plugin may register one — but the Web
configuration plane is the model-provider surface. Without the gate, every
future `settings.register()` would silently become remotely readable and
writable configuration. An unregistered namespace and an unexposed one answer
identically, so no caller can enumerate the registry one probe at a time.

**Path-addressed writes replace the redacted-document rebuild.** The editor
reads the REDACTED descriptor, so rebuilding a section from it and replacing
wholesale deleted every literal secret the wire never returned — reproduced as
`{baseURL, reasoning}` in, stored `apiKey` gone out. `settings.mutate` applies
set/unset ops to the section as it stands at the front of the seam's write
queue, and the client names only fields it can see, so an unseen secret is
untouched by construction rather than by care.

P2s in the same pass: `llm/adapters-updated` now contains async listener
rejections (an uncontained one escaped as unhandledRejection, contradicting
the documented "observer failures are contained"); llm-deepseek's retry-policy
swap uses the atomic `registration.replace` instead of dispose-then-register,
which published `[]` then `["deepseek-official"]` so an observer saw the
provider disappear and come back; and a transport rejection no longer strands
the page in `loading` or a card in `busy`, with removal failures surfaced on
the page banner instead of swallowed.
2026-07-30 18:30:15 +08:00
..

Packages

English | 中文

Packages use the @deepseek-ai/dsh-* scope. Each is a Cordis Service subclass or function plugin; contributions use ctx.effect(), ctx.on(), or ctx.waterfall(). Authoring rules: package and root.

Hierarchy

Packages live at packages/<group>/<pkg>/; groups are containers, while names remain @deepseek-ai/dsh-<pkg>. Each group README is the canonical package/ctx-key map.

Group Role Release expectation
core/ Product API spine: sessions, prompts, tools, agent services, and the concrete loop Product — stable surface
typert/ Type graph generation, artifact loading, and runtime registry Product — stable surface
goal/ Persisted same-session goal state and lifecycle Product — stable surface
llm/ LLM capability family: the abstract service + provider adapters Product — stable surface
subprocess/ Subprocess capability family: spawn seam + local process-tree implementation Product — stable surface
bash/ Bash capability family: executor seam, local impl, model-facing tool Product — stable surface
pty/ Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools Product — stable surface
code-runtime/ Code-execution capability family: the runtime seam for model-written programs + a worker-thread backend Product — stable surface
sandbox/ Process-confinement seam; bwrap/Landlock/Seatbelt backends Product — stable surface
fs/ Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools Product — stable surface
lsp/ LSP capability family: seam, generic stdio provider, and the lsp tool Product — stable surface
skill/ Skill capability family: the provider registry, local provider, and model-facing catalog/loader Product — stable surface
compact/ Compaction capability family: the abstract seam + a basic backend (tool deferred) Product — stable surface
context/ Model-visible request context, including workspace instructions and time context Product — stable surface
subagent/ Subagent capability family: the provider-registry seam and the model-facing delegation tool Product — stable surface
tasks/ Generic background-task runtime and model-facing task_* control tools Product — stable surface
workflow/ Workflow capability family: the script-engine seam, worker-thread engine, and model-facing workflow and fresh-agent ralph tools Product — stable surface
web/ Web capability family: seam, search/fetch provider impls, and the model-facing web tools Product — stable surface
spill/ Spill capability family: storage seam, local impl, tool-result spill policy Product — stable surface
todo/ The model-facing todo_write tool Product — stable surface
plan/ Plan collaboration state with a direct entry command and reviewed exit Product — stable surface
timeout/ Tool-call timeout policy: the tools/execute deadline enforcer Product — stable surface
guard/ Loop-hygiene guards: advisory repeat-call reminders Product — stable surface
cordis/ Self-referential runtime toolset: inspect the live runtime's plugins and services, mount/unmount model-written plugins (design) Product — stable surface
hooks/ Hook bridges + the shared Claude Code / Codex wire-protocol library Product — stable surface
session-persistence/ Persistence seam + JSONL/SQLite backends Product — stable surface
session-projection/ Projection seam: domain fold units serve whole values Product — stable surface
session-query/ Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search Product — stable surface
session-title/ Log-backed session titles: fallback service and opt-in LLM providers Product — stable surface
settings/ User-settings seam + file-backed provider Product — stable surface
credentials/ Credential-reference seam + env-over-.env provider Product — stable surface
telemetry/ Session reporting: capture/redact seam, OTel backend Product — stable surface
storage/ Non-session storage hub + backends + domain form Product — stable surface
workspace/ Workspace entity Product — stable surface
sdk/ Project SDK tooling Product — stable surface
acp/ Automation-only Agent Client Protocol server Product — stable surface
ui/ TUI and JSON-RPC integrations, approval/interaction seams, ask-user tool Product — stable surface
host/ Web-GUI host half: API gateway + HTTP route server Product — stable surface
client/ Web-GUI browser half: shell, wire, object services, slots, ui-* plugins Product — stable surface
experimental/ Prototypes and internal plugins Unreleased
examples/ Demo bundles (agent-spine + TUI/CLI/ACP/JSON-RPC bins) leaves load Support — example infra
support/ Support infrastructure (testkits, invariants, replay, Loader smokes) Support — lower compatibility expectations
util/ Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) Support — small, stable, harness-dep-free

New packages join existing groups; new groups update their README and this table.

Dependencies

The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).

Extension plugins depend on interfaces, never the concrete loop. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities split into interface / implementation / consumer packages; see capability seams.

Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.