Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
api/ — Remote API layers
English | 中文
The application-facing Remote stack. remotes owns BFF policy and the selected business API, while gateway implements the TypeRT unary RPC endpoints shared by Host and Client environments.
| Package | Role | ctx key |
|---|---|---|
remotes/ |
Host Agent/Session lookup policy and Client Remote contribution assembly | no service; configures ctx.typert and consumes ctx.remote |
gateway/ |
Host TypeRT dispatcher and Client Remote endpoint | ctx.typertGateway / ctx.remote |
The runtime dependency direction is remotes → gateway → connection → webserver: the BFF consumes the shared TypeRTClientRemote contract, Gateway delegates transport to Connection, and Connection mounts on the HTTP server. Cordis service injection and Client module metadata preserve this order without importing the concrete Gateway from the Remotes Client entry.
Known Limitations and Deferred Work
- Connection and WebServer remain at
client/connectionandhost/webserver; a later package-only move can place them underapi/connectionandapi/webserverwithout changing their service contracts. - The legacy API Proxy remains at
host/apiproxyas the fallback for methods not yet migrated to Remote. It consumes the Host resolver owned byapi-remotesso migrated and legacy methods retain one Agent/Session identity policy.