Files
deepseek-harness/packages/client/ui-command/README.md
T
imccyu 83c2115de8 refactor(client): command decorations replace the hostBacked contribution mode
A popup on a host command is not a second command — it is what that
command's BARE invocation does on this client. CommandContribution loses
hostBacked (contributions are pure client commands again; a host-name
collision fails loud, unchanged for /model), and the contract gains
CommandDecoration + command.decorate(): key = the HOST command name, no
catalog row, no claim participation. Dispatch consults decorations only on
the bare paths (menu pick / bare enter) after the host row resolves; space
and argued enter never see them — the two edges hostBacked had to guard
explicitly hold by construction in the decoration model. A decorated name
with no host row in the session's directory never fires (a decoration
cannot manufacture a command).

ui-permission switches register→decorate with zero behavior change
(options still read the permissions projection; a pick still submits
'/permission <preset>'). Specs rewrite to the decoration semantics: no
catalog row, bare-enter popup vs argued-enter host claim, space host
claim, no-host-row miss, unavailable fall-through, duplicate fail-loud.
2026-07-29 12:01:36 +08:00

4.1 KiB

@deepseek-ai/dsh-client-ui-command

English | 中文

Client command surface (ctx.command): the session-keyed command-directory cache, the / command source with matchSpace/matchEnter adjudication hooks, three-kind dispatch (execute / popupSelect / leadingInput), and the popupSelect registration face for business packages. Contract: the web command surfaces Agent Note.

src/client/contract.ts is the frozen business face: CommandServiceContract.register(name, spec) and decorate(name, spec) are everything a business package consumes; CommandUiSpec{options, onSelect} keeps popup data self-served — the shell component is this package's and business never sees it. A contribution is a client-owned command (a host-name collision fails loud); a decoration hangs a bare-invocation popup on an EXISTING host command — the host keeps its catalog row, argument claim (space / argued enter), and lifecycle logging, and a decorated name with no host row in the session's directory simply never fires. Command kinds derive per dispatch, never per registration: a host descriptor with input is leadingInput, a registered CommandUiSpec is popupSelect, everything else is execute.

CommandDirectory (src/client/directory.ts) is the one wire-derived cache, keyed by session: every session is agent-backed, so command.list({sessionId}) is the only address shape and the source's scope-birth warm hook prewarms the session's entry. Entries are soft-invalidated by the commands/changed typed event (old snapshot serves while the repull flies), hard-invalidated by connection/reset, epoch-guarded so a superseded pull can never overwrite a newer one. matchSpace answers synchronously from this cache only; matchEnter strong-waits it on the SubmitAttempt signal and rejects on warmup failure — a / line is never silently downgraded to a plain prompt.

PopupSelectController (src/client/popup.ts) is the headless shell state: PopupSelectView self-registers into conversation.input.overlay (the SlotMap key is ui-conversation's; this package pulls the declaration in with a type-only import — no runtime edge). The shell is a transient layer holding focus while open; token-segment consumption after onSelect runs both branches through consumeTokenSegment (menu-path span CAS, enter-path bare-token equality) against the draft face the wiring layer binds via bindDraft.

The /client export surface is the plugin body (apply/inject), CommandService, the directory and popup classes with their state types, and the frozen contract types; the shell component itself is internal to the overlay registration.

Model Experience

Indirectly, through the host command.execute RPC this package's dispatch and claim.submit paths trigger: a matched command's handler mutates host domain state that other packages project into the next request (the /plan handler flips plan mode, whose owning package injects its plan:policy system-prompt section), while the command line itself, the detached result, and every menu/notice rendering stay client-side and never enter the session log.

KV Cache effect

None directly; this package neither assembles nor sends a provider request. Command handlers it triggers may change what the owning host packages contribute to the next request's system prompt (a section appearing or disappearing replaces earlier request tokens and invalidates the provider prefix from that point), but that effect is owned and documented by each command's host package.

Known Limitations and Deferred Work

  • The popupSelect shell has no shipped business consumer — model selection (host selectModel) is the design's reference case and lands with its own feature work; until then the shell is exercised by package tests only.
  • Detached-result notices fall back to the console off-session — the fire-and-forget paths route results to the triggering session's composer via SessionInput.notify; after session teardown the console line is the only remaining surface.