Drop the recovery package/commands and related Schema/skill teaching so agents stop being steered at a dead surface, while keeping mono↔multi content QA work. Co-authored-by: Cursor <cursoragent@cursor.com>
6.3 KiB
Architecture
dws is a Go CLI with a versioned, static command surface for DingTalk MCP capabilities. Cobra help serves humans; runtime-assembled Schema (ResolveSchemaBuild) serves AI agents.
High-Level Flow
cmdis the CLI entrypoint, invokinginternal/appto build the root Cobra command tree.internal/appwires static utility commands (auth,audit,schema,completion), product helpers, and versioned plugin descriptors.internal/helperscontains the main command handlers for all product surfaces (dev,chat,calendar,contact,aitable, etc.).internal/executorandinternal/transportexecute MCP JSON-RPC calls;internal/outputformats responses.internal/authmanages login state, PAT tokens, and agent-code detection.- Schema assembly (
ResolveSchemaBuild) starts from the reviewedCommandRegistry, binds each identity to the exact current Cobra leaf, and then resolves typed constraints, sanitized MCP snapshots, and leaf ContractFinal / ProductDecl into oneSchemaRegistry. Startup and Schema queries do not call MCPtools/list. There is no generate-written Catalog delivery step. - Production Catalog /
ResolveMetaconsume the lazily assembled registry viaRegisterSchemaSourceRoot→ResolveSchemaBuild/deliverySchemaCatalog(声明即 Catalog; lazysync.Once).ResolveMetaprojects Identity/Safety/Selection from that assembly into an in-process map cache — not a committedschema_catalog/orschema_meta_index.*fixture. Flag-to-interface property delivery is owned by leafParamDecl.Property(native annotations).schema_parameter_mapping_ledger.goholds reviewedmapping_exclusions/removals(the emptyschema_parameter_bindings.jsonaudit table is retired). CLIrequiredand constraints come from the resolved typed contract, while MCPrequiredremains interface-only metadata. - Agent selection results are fixed in versioned review inputs. Every public tool has explicit use/avoid/example and interface disposition metadata; Skill references that are not current leaves require an explicit alias/group/stale/out-of-surface review instead of fuzzy runtime matching.
Repository Structure
cmd: CLI entrypointinternal/app: root command wiring, static utility commands, and plugin loadinginternal/helpers: product command handlers (dev, chat, calendar, contact, etc.)internal/plugin: versioned plugin manifest, hook, skill, and transport descriptor loadinginternal/cli: Schema assembly,dws schemaquery, and catalog contractsinternal/generator: CI/determinism tools (cmd_schema_catalogdump) and param-alias generateinternal/executor: invocation dispatch and result handlinginternal/transport: MCP HTTP client and request signinginternal/auth: login, token management, agent-code detection, identityinternal/audit: user operation audit log (JSONL, hash chain, forwarding)internal/errors: structured error model with categories and hintsinternal/keychain: OS keychain integration for credential storageinternal/security: endpoint allowlist and domain trustinternal/safety: runtime safety checks (confirm prompts, dry-run guards)internal/cobracmd: shared Cobra command buildersinternal/corecmd: dispatch-agnostic leaf-command base — flag registration, alias/env/default value resolution, required and cross-flag constraint validation, Risk write confirmation, toolArgs assembly, Runtime Schema projection. Distinct frominternal/cobracmd(generic tree helpers): it owns the declarative leaf contract (corecmd.Spec) that the LeafSpec framework is built on and that the Shortcut adapter projects into.internal/pat: PAT (Personal Access Token) authorization flowinternal/output: response formatting (json, table, raw, pretty)internal/logging: structured logging and argument sanitizationinternal/tui: terminal UI helperspkg/configmeta: environment variable registry and documentationpkg/config: configuration constants and pathspkg/edition: edition detection (oss vs enterprise)pkg/mcptypes: MCP protocol type definitionsinternal/syncdata: generated static endpoint and command-routing data synced from the Wukong baselineskills/: bundled agent skills (mono/ and multi/ layouts)test/: CLI, integration, contract, unit, and skill E2E testsscripts/: install scripts, policy checks, and CI helpers
Quality Pipeline
Quality enforcement is layered so a pull request receives fast, deterministic admission feedback without pretending that downstream integration has already run.
flowchart TB
PR["Pull request"] --> CLASSIFY["Fail-closed risk classification"]
CLASSIFY --> DOCS["Documentation-only<br/>asset/content validation"]
CLASSIFY --> STANDARD["Standard<br/>affected + reverse-dependent race<br/>scope-matched HEAD/base coverage"]
CLASSIFY --> HIGH["High-risk / main<br/>full race + native tests"]
DOCS --> CA["CI"]
STANDARD --> CA
HIGH --> CA
subgraph CA_CHECKS["Nine required contexts"]
L["Lint"]
T["Test"]
C["Coverage"]
P["Policy"]
E["Edition"]
I["Interface Integrity"]
A["AI Behavior"]
S["CLI Smoke"]
M["Mock MCP"]
end
CA --> CA_CHECKS
CA_CHECKS --> MAIN["Protected main"]
MAIN --> MP["Main Integration — 主干集成<br/>Multi-profile E2E"]
MAIN --> PLATFORM["Risk-selected / release native platform validation"]
MP --> RELEASE["Release delivery"]
PLATFORM --> RELEASE
All nine named contexts are produced for every tier. Domain-specific helpers
run when their owned surface is affected; otherwise the corresponding context
records an explicit unaffected success. Standard code changes still receive
representative Darwin/Windows compilation. High-risk PRs and protected main
run the complete race and native test suites, while platform-sensitive diffs
also receive native changed-code coverage.
Review orchestration is also base-owned: it requests one eligible peer without
executing PR code, re-routes an updated head when needed, and auto-merge
completes only after the latest push has peer approval plus the current
revision's nine strict contexts. Complete Multi-profile E2E remains downstream
of PR admission. See docs/ci-pr-gates.md for the exact
classification, context, reviewer, and ruleset contract.