Files
deepseek-harness/packages/attachment/attachment
imccyu ec601ca13d build(vendor): rescope the vendored Cordis packages into @deepseek-ai
Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it
prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`,
`verify-translation-pairing --write` for the touched bilingual pairs,
`gen-doc-graphs`, and one typert snapshot whose ids embed character offsets.
`pnpm run rescope-vendor --check` verifies the result.

Renames nine vendored packages (cordis, cosmokit, schemastery and the six
@cordisjs plugins) and every reference that resolves them: manifest names and
dependency keys, module specifiers including declare-module merges, cordis.yml
plugin names, tsconfig paths, every Markdown fence, and `docs/` prose.
Directory names, upstream versions, and dependency ranges are unchanged, so
vendor/README.md still reads as an upstream snapshot; its manifest table gains
an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed
at each fork's origin.

The tutorial tier follows the rename end to end: its yaml fences named plugins
the Loader can no longer resolve, its `ts ignore-check` fences disagreed with
the compiled fences beside them, and its prose quoted both. The contracts that
told readers to keep upstream names — the root convention and the vendoring
cookbook's tree comment and manifest invariant — now say to rescope instead.

Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle
purity gate now names the vendored libraries a browser bundle inlines, and the
files where a bare `cordis` is an agent-preset id keep that product data.
2026-08-10 22:04:13 +08:00
..

@deepseek-ai/dsh-attachment

English | 中文

The durable attachment seam. ctx.attachments validates and atomically commits immutable image bytes, then returns a serializable ImageAttachmentRef; consumers never persist browser paths, object URLs, provider URLs, or base64 in session events.

Unsent composer images remain browser-owned temporary drafts. validateImage runs the same admission policy without persisting; batch writers validate every member first so a malformed member cannot strand earlier members as unreferenced objects. saveImage commits each accepted image before any model-visible session event is published, and readImage verifies the content-addressed object against its logged metadata.

Model Experience

Indirectly, through the role-neutral core ImageBlock and provider adapters that resolve its durable reference.

KV Cache effect

Adding an image changes the provider request and therefore invalidates the affected request suffix.

Known Limitations and Deferred Work

  • Version one accepts PNG, JPEG, WebP, and GIF only.
  • Retention and garbage collection are deferred because resumed and forked sessions may share immutable objects.
  • Generic files, audio, video, and persistent unsent drafts require separate lifecycle and provider contracts.