Move every family manifest, the plugin scaffold and the shared workspace
package onto the 0.1.7-rc.2 cohort, together with the surfaces that state
the same fact:
- the dsh.engines.dsh floors and the matching @deepseek-ai/dsh host peers
- the release-age exclusion ledger and the two packageExtensions keys
- the root README badges, the CI/release mount-smoke pins and the
docs/publish-prep.md and docs/plugins.md prose
Two rc.2 facts were verified against the published artifacts rather than
inferred from the version number:
- the shell's frozen static module table is unchanged (the same nine
specifiers in the dsh-web-frontend rc.2 dist bundle), so
shared/web-platform.ts keeps its list and only its provenance comment
moves; the new dsh-client-shortcuts is an ordinary client plugin, not a
static module
- @deepseek-ai/dsh-client-ui-primitives@0.1.7-rc.2 imports a further
undeclared face, @deepseek-ai/dsh-util-code-language, so the
primitives packageExtensions patch gains that pin
The satellite peer floors in pnpm-lock.yaml still read >=0.1.7-rc.1: they
belong to the satellite packages and move when those repositories release
the aligned version.
The three developer skills described the pre-split layout: asset
directories under `packages/skins/skin-center`, `packages/dsh-pet` and
`packages/dsh-community-plugins`, plus commands such as
`pnpm skin-center:check` that exist only in the satellite repositories.
Each skill now names the owning repository, the commands that exist
there, and the side that stays here, and links the contracts instead of
restating them.
The same stale references are gone from the release and pre-push skills,
`docs/architecture.md` (which counted a fourth `lib/`-committing package
and listed `skins/skin-center` as a package directory), `docs/development.md`
(a skin-PR review lane for pull requests this repository rejects) and
`docs/plugins.md`; root `AGENTS.md` no longer mentions a skin registry
that lives elsewhere.
The skin, pet and community content repositories are now git submodules
under satellites/, so the commit a branch records for them is the pin the
market build reads. market-inputs.lock.json drops repo and sha and keeps
only what git cannot express: which submodule carries an input and where
its content sits inside it.
market-fetch-inputs.mjs resolves the repository URL from .gitmodules and
the commit from the gitlink, materializes the content directory from a
submodule working tree that sits on that commit, and otherwise downloads
that commit as a tarball, so a clone that never initializes the
submodules still builds the same content without fetching history.
The test-standards and emoji audits skip satellites/ the way they skip
.market-inputs/, the deploy lane also triggers when a gitlink moves, and
the owning note records that its rejection of submodules was about
mounting them as workspace packages.
The extraction moved the skin collection, the pet plugin and the
community plugin index into their own repositories, but the documents
that tell people where to submit those contributions still described
this repository's paths and scripts.
Skin, pet and community-index contributions now name the satellite
repository and its real entry points: skins/<id>/ with
scripts/dsh-skin-new.cjs and the skin-center catalog gate, assets/<id>/
with the pet CLI, and the community index's root community.json with
pnpm community:check. The gate lists in AGENTS.md, CONTRIBUTING.md,
docs/development.md and the architecture diagram no longer mention the
removed pnpm skin-center:check, and the artifact note now names the
three packages that still commit lib/.
The skin center, pet and community-index plugins now live in their own
repositories and are consumed as published npm packages, so this tree drops
them and everything that only existed to serve them in-repo.
Removed: packages/dsh-pet, packages/dsh-community-plugins and
packages/skins/skin-center (history stays in this repository), plus the root
scripts that moved with them (skin center catalog check, the reviewed-hooks
registry, the skin and pet authoring CLIs and their tests, community-index).
scripts/skins-montage.mjs stays: it renders the root README collage from
market/dist, which is this repository's tooling.
Decoupled:
- scripts/sync-shared.mjs no longer mirrors the settings trio, host helpers or
http/mount-once copies into the three packages (114 copies -> 99);
- lib-artifact-fingerprints.json tracks three committed lib/ packages now that
skin-center left;
- packages/dsh-usage drops an unused @linxin666/dsh-pet devDependency;
- the skin/pet/community gates leave ci.yml and the root scripts (they run in
the satellite repositories' own CI);
- scripts/i18n-audit.mjs no longer reads pet's client locale file, and the
test-standards and emoji audits skip .market-inputs (fetched content is not
ours to audit);
- the market build pins the community index in market-inputs.lock.json like the
skin and pet content, so the plugin list the site serves is reproducible from
a commit instead of following whatever npm resolves, and the catalog's skin
repo URLs point at dsh-skins;
- docs (root AGENTS.md, architecture, plugins, development, publish-prep) and
CONTRIBUTING point at the new repositories.
Gated by: aggregate:check, libs:check, runtime-deps:check, market:check,
sync-shared:check, test:standards, docs:check, i18n:check, emoji:check,
typecheck and 307/307 script tests.
Not yet safe to merge: the aggregate's three dependencies resolve from npm,
and the published 0.3.24 still injects the retired settingsScope service, so
the mount smoke stays red until the satellite repositories publish a build
containing the migration.
Move every consumed @deepseek-ai family specifier (272 across 23 manifests),
the dsh.engines.dsh floors and the matching @deepseek-ai/dsh host peers, the
plugin scaffold, the release-age ledger and the packageExtensions keys, the
desktop host payload pin with its regenerated hoisted lock, the root lock,
the CI and release mount pins, the README host badge, the cohort-version
source literals and the cohort prose in docs.
Regenerate the official token contract from the 0.1.7-rc.1 surfaces (293 to
299 names, additive, contractVersion stays 1) and verify the browser platform
seed against the rc.1 shell bundle. Harden the shell-isolation real-boot spec
so it only accepts an app-boot copy whose own non-optional peers resolve: this
cohort pulls an incomplete copy into the workspace for the first time, through
dsh-agent-preset-registry.
Record the cohort decision, the official release-notes and compare evidence,
the published-surface delta and the native-first overlap inventory in
.agents/notes/implemented/architecture/2026-09-23-sdk-cohort-0.1.7-rc.1.
The family stated which DSH host it needs only through dsh.engines.dsh, a
field the plugin manager reads; nothing in the npm manifest told a resolver
that the requirement existed. Every family package, the aggregate included,
and the plugin scaffold now also carry
peerDependencies["@deepseek-ai/dsh"] at the same >=<cohort> literal.
- scripts/family-dsh-engines.test.mjs covers both declarations over every
family package plus the scaffold: presence, the supported >=<semver> form,
and no declaration trailing the scaffold cohort floor.
- scripts/aggregate.mjs keeps the host peer when it rebuilds the aggregate
manifest, still dropping leftover child-plugin peers.
- docs/plugins.md and packages/AGENTS.md state the rule; the host-floor Agent
Note records the new surface and the extra cohort-bump move.
- The personal dsh-sdk-upgrade skill now names the host peer as the sixth
host-floor surface to move with every cohort (outside this repository).
family-dsh-engines.test.mjs asserted only that each family package declares a
supported >=<semver> dsh.engines.dsh form, so a package could silently drop
below the cohort the family is built against. It now also requires every
family floor to satisfy the scaffold cohort floor via rollout-verify's
satisfiesFloor, and pins that the family walker covers the aggregate package
packages/dsh-web-all, whose floor is the family's machine-readable statement.
docs/plugins.md records the aggregate coverage and the value check.
Both plugins are no longer useful and leave the family per owner direction.
The packages are deleted from the workspace; the aggregate drops their
patchFrom/deps rows and inactive entries, keeps one tombstone shell export
per removed id so old profiles degrade to an inert plugin instead of
ERR_PACKAGE_PATH_NOT_EXPORTED, and drops the stale retire block whose
target row the 0.1.7-alpha.2 host no longer mounts. The reference sweep
covers sync-shared targets and counts, the i18n audit, the ru dictionaries,
the web-settings allowlist, plugin-manager fixtures, the skin-center
semantic-attrs contract, the labeler, coverage baseline, lockfile, and
docs; desktop/runtime/profile-web stays pinned to the published 0.3.19
that still contains both packages.
Bump every @deepseek-ai family specifier (258 specifiers across 25
manifests), every dsh.engines.dsh floor (22 packages), cordis to ^4.0.4
and schemastery to ^3.18.4. Align the shared ledger, the desktop host
runtime seed (overrides, exclude list, regenerated lockfile) and the root
lockfile, plus the CI and release mount pins, the cohort-version docs and
the source literals that name the cohort.
The floors had been written as ">=>=0.1.7-alpha.2"; repair them to
">=0.1.7-alpha.2" so the family-engine regex gate passes again.
dsh-market/lib is rebuilt because its committed bundle embeds the resolved
cordis and schemastery paths; the Skin Center output is rebuilt in the
token-contract change that follows.
The official family published 0.1.7-alpha.1 while the alpha branch stood on
0.1.6-alpha.2, and the machine's DSH moved to the new cohort. Four changes in
the release reach this family:
- The settings subsystem is now keyed by the profile entry: ctx.settingsScope,
SettingsScope* and SettingsProvider.installSection/register are gone, replaced
by ctx.configForms, ConfigForm* and SettingsForms. Every family host half
carries its settings on its own Config with volatile fields, every browser
half binds through the webUiSettings service (which resolves a family
namespace to the owning profile entry id and then binds natively, with the
loopback bridge as the fallback), and the shared card/form layer speaks the
new contract including its boolean refusal answers.
- The agent-preset domain became declarative: directory discovery is gone, a
preset is a declaration a plugin registers at runtime. dsh-preset-center now
declares installed presets from its host half (install = declare) and
dsh-liangshen declares its own preset instead of syncing files into
~/.dsh/.agent-presets.
- Session V4 moved the tool-result failure flag to the message root; dsh-pet
read the removed content block and silently rendered failed turns as
successes.
- The client design system renamed its icons and reshaped SessionListState;
the affected call sites and fixtures follow.
Cohort: every consumed @deepseek-ai/dsh-* range, the scaffold, the README
badges, the CI and release mount-smoke pins, the desktop runtime pin and both
lockfiles, and the docs move together; the vendor pins follow the cohort's own
release (cordis 4.0.3, cosmokit 1.8.4, schemastery 3.18.3,
cordis-plugin-include 1.0.8, cordis-plugin-loader 1.0.4). The workspace
packageExtensions restore @deepseek-ai/dsh-util-workspace-path, which
dsh-client-ui-primitives now imports from its emitted lib while declaring no
dependencies.
scripts/e2e-mount.sh, scripts/e2e-mount-rewrite and its test, and
scripts/publish-legacy-aggregate.mjs pass GNU tar --force-local on the
Windows/MSYS lane, where a C:\ output path is otherwise read as a remote host.
The mount smoke does not pass on this workstation: the local dsh CLI is a
symlink into a DSH checkout whose built lib/ predates this cohort's own
multi-file dsh.bundle.patch support, so profile boot crashes on the official
dsh-web-app array before any family row is evaluated. That is host-side build
staleness outside this repository; the lane passes once the DSH checkout is
rebuilt. Recorded with the rest of the decision in
.agents/notes/implemented/architecture/2026-09-22-sdk-cohort-0.1.7-alpha.1.md.
The 0.1.6-alpha.2 cohort removed the official keyed seat
`settings.plugin.item` that `ui-settings-plugins` declared; the plugin
manager page now dispatches plugin configuration through
`plugins.item` / `plugins.bundle.config` / `plugins.row.config`.
The shared family card seat therefore had a dead fallback: a profile
installing one family plugin without `dsh-web-settings` registered into
a slot no host declares any more, and the refusal only reached the
console.
The fallback now targets `plugins.bundle.config`, keyed by the
contributing package's own bundle name (every family package ships its
own bundle patch, so a standalone install lists that package as the
bundle whose page renders the card). The family list seat
`web-ui.plugin.item` is unchanged. PluginCardSeat drops the
settings-namespace field for that bundle name, and the five consumers
(dsh-doctor, dsh-liangshen, dsh-remote-web-ui, dsh-task-board,
dsh-tool-describe-image) pass it.
Docs, seat tests and the committed aggregate bundle follow the same
rename.
Adapt dsh-web to the experimental @deepseek-ai/dsh-* 0.1.6-alpha.2 cohort in the
same isolated alpha worktree and DSH home, so the accepted 0.1.5-rc.1 stable
environment, its profile tree and the global dsh CLI stay untouched.
Cohort: every consumed range, the plugin scaffold, the root README badges, the
CI and release mount-smoke pins, the desktop runtime pin and its lockfile, both
release-age exclusion lists and the desktop overrides block move to
0.1.6-alpha.2; the declared host floor becomes dsh.engines.dsh >=0.1.6-alpha.2.
cordis, cosmokit and schemastery keep their independent support pins.
@deepseek-ai/dsh-client-ui-workspace joins the repository exclusion list and the
packages that navigate gained it as a devDependency, because the family now
consumes it directly.
Adaptation of the SDK delta - the multi-instance Client Session model:
- SessionListState.current/currentAddress and SessionSummary.completed are gone,
and ISessions.open()/openSubagent()/clear() are removed. View selection now
belongs to the workspace UI, which owns the main-area reference and publishes
it as retainedBy.mainView; navigation is ctx.uiWorkspace.openSession(target).
- shared/client/main-session.ts adds mainViewSessionId(byId), the catalog-level
reading of that marker, and sync-shared copies it into the seven consumers.
Ten call sites across eight packages read the removed faces; two of them
(git-graph auto-isolation, session-archive) type-checked against local
structural doubles and never appeared in the compiler's error list, so the
inventory was built by searching for the removed names rather than by
trusting tsc.
- dsh-task-board's framework-free controller port changes from a list snapshot
to { current(), open(), subscribe() }; the wiring resolves current() from the
marker. dsh-git-graph navigates new worktree sessions through the workspace UI.
dsh-pet, dsh-plugin-manager, dsh-doctor, dsh-liangshen, dsh-session-id and
dsh-session-archive read the marker instead of the removed selection.
Upstream packaging defect: dsh-client-ui-primitives@0.1.6-alpha.2 imports
simple-icons from its emitted lib/index.js while the published manifest still
declares no runtime dependencies; packageExtensions restores it at the exact pin
the official source resolves (16.31.0), beside the existing diff/shiki/micromark
restorations. No installed file is patched.
Native-first: no family row registers the new sidebar panel slots, and the
alpha.1 to alpha.2 slot-key comparison is additive only. dsh-plugin-manager
already extends the official Plugins section through settings.plugins.tab rather
than mounting a parallel page, and that stays the right native extension. The
aggregate declares no external npm plugin, so the new runtime plugin dependency
resolution has no external hard-binding to unmask. The inject contract records
dsh-client-ui-workspace as an approved inject module with its rationale.
Testing: pnpm typecheck, sync-shared:check, skin-center:check, community:check,
libs:check, build, test, test:scripts, test:desktop, runtime-deps:check,
aggregate:check, emoji:check, test:standards, docs:check, i18n:check and
market:check pass, and pnpm install --frozen-lockfile --ignore-scripts resolves
the lockfile. The alpha host in ~/.dsh-alpha is upgraded to 0.1.6-alpha.2 and
every profile @deepseek-ai copy is a symlink into it (235 ok, 0 warn, 0 fail);
dsh --profile alpha-web --dump-config composes the family rows with the retired
ui-settings-unarchive-sessions row.
The host range example in the plugin specification still named ^0.1.5-rc.1 after the family moved to the 0.1.6-alpha.1 cohort, while scripts/plugin-template already declares ^0.1.6-alpha.1. The line now matches the scaffold it illustrates.
The "Web 插件" section rendered its heading and zero cards: seat selection
asked whether the official keyed seat settings.plugin.item is declared, but
ui-settings-plugins declares it in every web bundle before any external
plugin applies, so every family card went to the official Plugins tab and the
group's own section stayed permanently empty.
installPluginCard now keys on the settings group being loaded
(ctx.get('webUiSettings')) and re-evaluates on slots/changed, so a group that
applies later still takes the cards. The move is guarded against the
registry's synchronous re-entrant change event, which otherwise registered the
card a second time into the seat it was leaving.
Five packages ship the regenerated shared copy; the aggregate bundle and its
lib fingerprint are refreshed, and the superseded #1589 seat rule is
cross-linked from its Agent Note.
The family's declared host floor now names the adapted cohort: all 21
family packages plus the plugin scaffold declare dsh.engines.dsh
>=0.1.2-alpha.3, the root README badge (zh/en) renders the requirement
statically instead of the live alpha dist-tag, and the CI/release
mount-smoke lanes pin @deepseek-ai/dsh@0.1.2-alpha.3. The scaffold's
SDK devDependencies align to ^0.1.2-alpha.3; docs/publish-prep.md and
docs/plugins.md state the same contract. Decision recorded in
2026-09-01-dsh-host-floor-tracks-cohort.
Add an optional subcategory to community.json entries, validated by community-index against a per-category enum, and passed through market-build into the plugin manifest. Both Workshop surfaces render the second level: dsh-market.com shows a second dashed pill row under the category pills when a category is selected, and the GUI Workshop card gains category and subcategory pill rows plus localized badges (raw ids replaced by labels). Assign the approved taxonomy to all 37 entries and both classification levels to the three previously uncategorized entries (gzip, approve-for-me, memories).
Display and source layers rename to dsh-web: GitHub slug, docs and prose,
aggregate package dir packages/dsh-web-all with npm name
@linxin666/dsh-web-all, settings package dir packages/dsh-web-settings,
private shared package dsh-web-shared, repo-local skill dirs, and the
docs banner asset.
Runtime, wire, and storage identifiers are frozen byte-identical so
installed profiles keep resolving with zero migration: web-ui-* bundle
ids, the dsh-web-ui-market settings section id, /api/dsh-web-ui-settings
and its proxy-token header, and the dsh-web-ui-telemetry-* storage keys.
Frozen history (docs/archive, docs/release-notes, archived notes), the
JAVA-LW fork reference, and local filesystem paths keep the old name.
npm migration: the next tag release dual-publishes @linxin666/dsh-web-all
alongside the final @linxin666/dsh-web-ui-all version, then the old name
is deprecated with a pointer; dual-publish lasts two releases.
Decision record: .agents/notes/implemented/architecture/2026-08-24-product-rename-dsh-web.md
The store is now the Workshop everywhere the name is user visible:
- GUI settings section: zh 创意工坊 / en Workshop (settings.title), with the
enable switch, hints and empty/offline copy following the new name - the
first-level nav label, section heading and store card all come from the
same key, so a refresh shows the new name immediately (client-only)
- market site (dsh-market.com): page title, meta description, brand title,
tab-list aria label and footer read 创意工坊; the domain stays
dsh-market.com and market/dist was regenerated by market-build
- package descriptions (dsh-market, dsh-community-plugins) and all
README pairs, docs/plugins.md (path now 设置 → 创意工坊 → 插件, the stale
hub 商店 step dropped), publish-prep.md, the semantic-attrs contract
and code comments updated; internal identities (package names, cordis
rows, /api/market/* routes, manifest URLs) are untouched
Verified in the live GUI (CDP, whale-song light): nav and section heading
show 创意工坊 with the store card intact; the regenerated site shows the
new brand in the header, title and footer.
READMEs, root repository layout, semantic-attrs contract and the community index flow now describe the store-only market; the community-plugins README documents the data-source role. Bundles the concurrent AGENTS.md wording from the running session.
- READMEs for market, skin-center, pet and community-plugins describe the
single DSH Market section with category tabs and the standalone fallback;
skin-center documents the on-demand skin plan (package ships blue-fantasy
only, market installs into /Users/zcl/.dsh/skins, default activation and the
upgrade fallback)
- semantic-attrs contract: dsh-market row and updated anchors for the
category cards (hub tabs vs standalone sections)
- root AGENTS.md layout and docs/plugins|publish-prep updated to the same
facts
- rebuild market and skin-center lib bundles; shared market-tab seat gains
the slots/settings devDeps for its own typecheck; sync-shared test covers
the new copy
dsh-live-stats (real-time token estimation and TPS projection) is no
longer supported. Delete the package, drop its tests and vitest config,
remove it from the web-ui-all aggregate manifest, the settings bridge
allowlist, sync-shared consumers, GitHub issue/PR templates, and all
docs; shrink the lockfile by exactly the removed importer. Update the
mount-once and sync-shared script tests to the reduced copy set.
Gates: typecheck, test, test:scripts, docs:check, aggregate:check,
gallery:check, skin-center:check, community:check, runtime-deps:check,
build all green.
Aggregate generator now rewrites child row ids to web-ui-* (stripping the
ui- prefix) and validates uniqueness, so installing the family bundle next
to a standalone plugin no longer trips the loader's duplicate-entry check.
A shared shared/host/mount-once.ts module (sync-shared synced into 12 family
packages) makes the host apply a no-op when the same plugin loads twice;
browser half is deduped by package name. Docs synced: root README FAQ,
web-ui-all README trio, plugins.md, packages/AGENTS.md; regenerated
dsh-skins and dsh-web-ui-all patches and skin-center lib; archived the
verification snapshot in docs/archive.
Rebased onto the rewritten docs; drops the host node-types and client
stub advice now covered by the layered AGENTS.md and tsconfig
conventions, keeping only the undocumented aggregate mount pitfall:
the loader fills schema defaults before apply, so eager load-time
validation of required fields fails the whole profile; ported plugins
must validate lazily unless the composition entry configures the key
fields.
- register the Skins card into web-ui.plugin.item (plugin config ->
Web UI Plugins) instead of the top-level settings.section seat, so the
skin center no longer occupies a level-1 settings nav entry
- convert SkinCenter from a full settings section to a disclosure plugin
card: header with name + installed-count badge + description, body with
the theme preview row and the skin list (try-on / light-dark / copy-apply
logic unchanged)
- drop the now-unused ui-settings module-table entry and the nav locale
key; add cardDescription / expand / collapse copy (en + zh)
- regenerate the embedded registry (refresh stale minecraft bundle text)
and rebuild lib
- update skin-center README, task-handoff doc and plugins.md
- keep the remote-web-ui api gate mounted while disabled so LAN /api stays paired
- revoke remote tokens/devices on disable and require fresh pairing on re-enable
- restore task-board cold-session failure detection through session history
- honor pet composition-level enabled and stop activity listeners when off
- wait through settings loading before mounting task-board/pet/remote UI
- declare settings/connection inject and peer deps consistently
- update vendored cordis platform tables and publish-prep inventory
- add dsh-client-ui-web-ui-settings, a browser-only plugin whose card
declares the web-ui.plugin.item child slot inside the plugin config page
- move the four family plugin settings cards into that group and add an
enabled switch to each namespace
- task-board hides its sidebar entry and board view, remote-web-ui drops its
pairing routes/gate/sidebar entry, pet hides the dock and API routes, and
live-stats stops its projection when disabled; all re-enable live
- register web-ui-settings in the web-ui-all aggregate and document the
group slot flow
- rename vendored cordis imports/aliases to @deepseek-ai/cordis across
packages, scripts, templates, and skin bundles; drop cordis package
declarations and keep tsdown node externals explicit
- add plugin configuration cards for remote-web-ui, task-board, live-stats,
and pet, backed by dsh-settings namespaces and client settingsScope
- make task-board system prompt announcement follow announceToAgent live
- make pet display persistence whole-pixel so drag state stays schema-valid
- remove working-activity, code-kline, and ui-code-kline packages and their
aggregate/docs references
- update README, plugins doc, and publish-prep snapshot
- README: provenance + license table for every family package (org-owned,
chimney's MIT working-activity, former in-source customizations, native)
- docs/plugins.md: admission rules — active third parties are forked or
referenced, not vendored; vendored code must keep LICENSE/attribution and
record its origin