1504 hand-written ranges pointing at workspace members become workspace:^, so pnpm pack substitutes each member's real version at publication: sibling peerDependencies follow the family version instead of being pinned at ^0.0.1, and a reference to a vendored package follows that package's own line. Without this, publishing 0.0.2 ships peer ranges naming a version that does not exist, and 0.0.1-rc.1 does not satisfy ^0.0.1 either. It also retires ranges that had gone stale against the workspace: ^4.0.0-rc.6 for a 4.0.0-rc.7 checkout, ^3.17.0 for schemastery 3.18.0. workspace:* stays where an exact published version is the point, which is how the Landlock entry pins its platform packages. A workspace constraint now requires the protocol, so a new package cannot reintroduce a hand-written range. The same constraint caught packages/boot/cmdline arriving on master without the publishable trio, which this change completes.
@deepseek-ai/dsh-storage-sqlite
English | 中文
SQLite backend for the storage hub: registers as backend sqlite, serving the kv facet over one node:sqlite database file (or :memory:). Design and trade-offs: domain KV storage Agent Note.
Storage model
Document-per-row: each unit table becomes a physical "u_<unit>_<table>" (key TEXT PRIMARY KEY, value TEXT) STRICT table whose value is the record's JSON text, so one key updates one row (the reason to route a high-churn domain here instead of the JSON backend). Unit identity lives in two metadata tables — units stamps each unit's format version at first open and rejects a differing descriptor with version-mismatch; unit_globals holds each unit's global singleton row. The physical layout version lives in PRAGMA user_version; any other stamped value rejects (unreleased format, no migrations). Unit and table names are validated against the hub's UNIT_NAME_RE before they reach DDL, so no external input is ever interpolated into SQL identifiers.
Every write primitive is a single prepared statement — SQLite's per-statement atomicity satisfies the KV contract without explicit transactions, and write ordering stays the caller's responsibility (the domain layer's write chain). Missing directories and database files are created owner-only (0o700/0o600), matching the session-persistence SQLite backend.
Configuration (schemastery)
interface Config {
path: string // SQLite database file path, or ':memory:' for an in-process DB
journalMode?: 'wal' | 'delete' | 'truncate' | 'persist' // journal_mode pragma; default 'wal'
}
Model Experience
Stored domain records
What the model sees
Nothing. This backend contributes no prompt, tool, or schema; it persists non-session domain data (workspace records, future session sidecar metadata) behind ctx.storage for host-side consumers only.
Token effect
Zero live-request tokens.
KV Cache effect
None — the backend never touches live request prefixes.
Known Limitations and Deferred Work
DatabaseSyncis synchronous — each write blocks the event loop for its (single-statement) duration; acceptable at domain-data scale.- No busy-wait or retry policy — another connection holding a write transaction rejects the operation immediately; there is no multi-process write protection.
- Only the current
STORAGE_SQLITE_SCHEMA_VERSIONopens — any other stamped version is rejected rather than migrated (pre-release stance). openDatabaseduplicates the session-persistence SQLite open sequence — extraction into a shared media layer is deferred to the planned session-backend migration (see the Agent Note's reuse audit).