Files
deepseek-harness/packages/client/modules
imccyu ec601ca13d build(vendor): rescope the vendored Cordis packages into @deepseek-ai
Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it
prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`,
`verify-translation-pairing --write` for the touched bilingual pairs,
`gen-doc-graphs`, and one typert snapshot whose ids embed character offsets.
`pnpm run rescope-vendor --check` verifies the result.

Renames nine vendored packages (cordis, cosmokit, schemastery and the six
@cordisjs plugins) and every reference that resolves them: manifest names and
dependency keys, module specifiers including declare-module merges, cordis.yml
plugin names, tsconfig paths, every Markdown fence, and `docs/` prose.
Directory names, upstream versions, and dependency ranges are unchanged, so
vendor/README.md still reads as an upstream snapshot; its manifest table gains
an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed
at each fork's origin.

The tutorial tier follows the rename end to end: its yaml fences named plugins
the Loader can no longer resolve, its `ts ignore-check` fences disagreed with
the compiled fences beside them, and its prose quoted both. The contracts that
told readers to keep upstream names — the root convention and the vendoring
cookbook's tree comment and manifest invariant — now say to rescope instead.

Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle
purity gate now names the vendored libraries a browser bundle inlines, and the
files where a bare `cordis` is an agent-preset id keep that product data.
2026-08-10 22:04:13 +08:00
..

@deepseek-ai/dsh-client-modules

English | 中文

Client module system: the browser peer of Node's internal ESM loader, built as a lazy CJS table. The web shell mounts the vendored cordis Loader for entry governance (fiber lifecycle, inject waiting, update/refresh) and injects this package's ClientModuleLoader through its internal contract — the vendored side's only consumption point is EntryTree.import, so replacing internal replaces exactly "how plugin code arrives" and nothing else.

Lazy CJS model (web2): executing a plugin bundle only REGISTERS its factory (window.__ModuleLoader__.load({id, factory})); every module body side effect — CSS injection included — lives in the factory closure and runs at materialization (factory(require) → export surface, memoized in loadCache), not at script execution. A factory that requires another registered-but-unmaterialized module materializes it recursively, so load order needs no external sequencing; require cycles throw (factory-form CJS cannot deliver partial exports). <id>/client and the bare id name the same surface (a plugin bundle IS its package's client half).

Resolution branch order (import(specifier)): platform seed word → shell instance; memoized record → surface; shell-own static registry (registerStatic, app-shell) → module; registered factory → materialize; graph row (window.__DSH_BOOT__) → load its external classic script + materialize; anything else throws — the runtime mirror of the build-time bundle purity gate. The synchronous require handed to factories walks the same order minus the asynchronous load branch and records observed edges into the module record. prefetch is the stage-one arrival hook (script load and factory registration only; concurrent calls share one in-flight task); invalidate drops the factory and materialized record so the next prefetch/import reloads the script (the HMR hook).

The Node half scans enabled Loader entries for web dsh.client packages, resolves each exports["./client"], hashes the built bundle into the boot graph, and serves it with its source map under /plugins. Source launch maps host imports to TypeScript source but still consumes this built client export; missing files share one build instruction followed by a package/path list, while unrelated filesystem errors remain separate failures.

Model Experience

None, as the module loader is browser-side kernel machinery; nothing here reaches a model request.

KV Cache effect

None; this package neither assembles nor sends a provider request.

Known Limitations and Deferred Work

  • Flat module graph by design — every bundle is one module node whose edges point only at table leaves; the interface (loadCache/edges/invalidate) already supports a general module graph, so the externalization granularity can change without an interface change.
  • No unload bookkeeping of its own — style removal and fiber teardown ordering live with the HMR driver (@deepseek-ai/dsh-client-hmr); the loader only inventories owned style tag ids per record.