Files
deepseek-harness/packages
Yichen Jiang e53f448650 fix(subagent): compose children from their parent's preset
Tool and prompt-section visibility is inherited along dsh-scope's parent
chain, and an agent's scope key is minted with no parent. Per-session agent
presets moved every model-facing row onto the agent plane and made
AgentPresets.mount() the one thing that binds that link, from the api-proxy's
session create, resume, and fork paths. The two in-process subagent drivers
installed only the per-child persona and tool filter, so a child's scope chain
had length one and its registry view resolved the global layer alone — which
is empty wherever a preset roster is composed. One-shot children reached the
model with no tools, continuable ones with only the host-plane `report`, and
neither carried its parent's persona, workspace context, or skill catalog.

AgentPresets.composeFrom() joins one agent to the standing composition another
already runs on. It is a bind, not a mount: the child gets its parent's exact
generation, so a composition edited since the parent started cannot fork it
onto another one, and it is synchronous, which is what lets a child creation
window use it. applyChildComposition() now takes the parent and performs the
join first, making a child composed without it unrepresentable at the call
sites. childSessionMeta() records the joined id so a cold read rebuilds the
composition the child actually ran under.

The audit that followed found two api-proxy readers on the wrong authority:
presenterScopeFor() and the live-agent branch of assertPresetUnchanged() both
read header.agentPreset, which goes stale the moment a blank session switches
preset. A switched session's cold transcript resolved presenters in the older
composition's layer and silently degraded to generic cards, and the gateway
refused to adopt a live session under the preset it actually runs while
accepting the one it left. Both now resolve through resolveSessionPreset(),
matching the resume branch fifteen lines above. The owning architecture Agent
Note carried the stale claim that the header records what a session runs; it
is corrected to name the header/log pair and its three readers.

Fixes #2165
2026-08-10 17:46:34 +08:00
..
2026-08-10 13:07:46 +08:00
2026-08-10 13:07:46 +08:00

Packages

English | 中文

npm scope: @deepseek-ai/dsh-*; Cordis Service subclasses and function plugins contribute through ctx.effect(), ctx.on(), or ctx.waterfall(). Rules: package, root.

Hierarchy

Groups hold packages/<group>/<pkg>/; names stay @deepseek-ai/dsh-<pkg>. Group READMEs own package/ctx-key maps.

Group Role Release expectation
core/ Product API spine: sessions, prompts, tools, agent services, and the concrete loop Product — stable surface
api/ Remote BFF assembly and TypeRT RPC gateway Product — stable surface
typert/ Type graph generation, artifact loading, and runtime registry Product — stable surface
goal/ Same-session goal persistence and lifecycle Product — stable surface
feedback/ Human feedback Product — stable surface
llm/ LLM capability family: the abstract service + provider adapters Product — stable surface
e2b/ E2B providers POC
subprocess/ Subprocess capability family: Service Definition + local process-tree provider Product — stable surface
bash/ Bash capability family: executor seam, local impl, model-facing tool Product — stable surface
pty/ Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools Product — stable surface
code-runtime/ Code-execution capability family: Service Definition + worker-thread provider + Code Mode Consumer Product — stable surface
sandbox/ Process-confinement seam; bwrap/Landlock/Seatbelt backends Product — stable surface
fs/ Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools Product — stable surface
lsp/ LSP capability family: seam, generic stdio provider, and the lsp tool Product — stable surface
skill/ Skill capability family: the provider registry, local provider, and model-facing catalog/loader Product — stable surface
compact/ Compaction capability family: Service Definition + basic provider + command Consumer Product — stable surface
context/ Model-visible request context, including workspace instructions and time context Product — stable surface
subagent/ Subagent capability family: the provider-registry contract and the model-facing delegation tool Product — stable surface
tasks/ Generic background-task runtime and model-facing task_* control tools Product — stable surface
workflow/ Workflow seam, worker-thread engine, and model-facing workflow/ralph tools Product — stable surface
web/ Web capability family: seam, search/fetch provider impls, and the model-facing web tools Product — stable surface
attachment/ Durable attachment identity, validation, local content-addressed storage Product — stable surface
spill/ Spill capability family: storage seam, local impl, tool-result spill policy Product — stable surface
todo/ The model-facing todo_write tool Product — stable surface
plan/ Plan collaboration state with a direct entry command and reviewed exit Product — stable surface
preset/ Per-session agent composition from preset cordis.yml files Product — stable surface
guard/ Loop-hygiene guards: advisory repeat-call reminders + the tools/execute deadline enforcer Product — stable surface
bundle/ Installable dsh --profile patch layers Product — stable surface
self-modification/ Agent runtime self-modification: live plugin/service inspection, model-written plugin mount/unmount (design), restricted repository Plugin loading Product — stable surface
hooks/ Hook bridges + the shared Claude Code / Codex wire-protocol library Product — stable surface
session/ Durable session data plane: persistence seam + JSONL/SQLite backends, projection seam, log-backed titles, session reporting Product — stable surface
session-query/ Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search Product — stable surface
settings/ User-settings seam + file-backed provider Product — stable surface
credentials/ Credential-reference seam + env-over-.env provider Product — stable surface
storage/ Non-session storage hub + backends + domain form Product — stable surface
workspace/ Workspace entity Product — stable surface
scaffold/ Create/launch/drive project tooling: helper, launcher, initializer, wire protocol with both ends, launcher telemetry Product — stable surface
acp/ Automation-only Agent Client Protocol server Product — stable surface
interaction/ Human-collaboration plane: approval/interaction seams, permission preset, commands, ask-user tool Product — stable surface
boot/ Shared app-bin boot glue Product — stable surface
host/ Web-GUI host half: API gateway + HTTP route server Product — stable surface
client/ Web-GUI browser half: shell, wire, object services, slots, ui-* plugins Product — stable surface
experimental/ Prototypes and internal plugins Unreleased
examples/ Demo bundles (agent-spine + CLI/ACP/JSON-RPC bins) leaves load Support — example infra
support/ Support infrastructure (testkits, invariants, replay, Loader smokes) Support — lower compatibility expectations
util/ Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) Support — small, stable, harness-dep-free

New packages join existing groups; new groups update their README and this table.

Dependencies

The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).

Extension plugins depend on Service Definitions, never concrete providers. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities separate Service Definition / Service provider / Consumer roles when they evolve independently; see capability seams.

Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.