Move every family manifest, the plugin scaffold and the shared workspace
package onto the 0.1.7-rc.2 cohort, together with the surfaces that state
the same fact:
- the dsh.engines.dsh floors and the matching @deepseek-ai/dsh host peers
- the release-age exclusion ledger and the two packageExtensions keys
- the root README badges, the CI/release mount-smoke pins and the
docs/publish-prep.md and docs/plugins.md prose
Two rc.2 facts were verified against the published artifacts rather than
inferred from the version number:
- the shell's frozen static module table is unchanged (the same nine
specifiers in the dsh-web-frontend rc.2 dist bundle), so
shared/web-platform.ts keeps its list and only its provenance comment
moves; the new dsh-client-shortcuts is an ordinary client plugin, not a
static module
- @deepseek-ai/dsh-client-ui-primitives@0.1.7-rc.2 imports a further
undeclared face, @deepseek-ai/dsh-util-code-language, so the
primitives packageExtensions patch gains that pin
The satellite peer floors in pnpm-lock.yaml still read >=0.1.7-rc.1: they
belong to the satellite packages and move when those repositories release
the aligned version.
Adds the Agent Note for the split (problem, decision, the external-row
trade, the commit-pinned market content, the release-order constraint, the
alternatives that lost and the consequences) as a bilingual triplet, and
updates the aggregate-positioning note, whose frozen-identifier list still
named the packages/skins/skin-center directory that no longer exists here.
Also clears the leftovers the split made stale: market-build's path comments
and its "no skins found" error now name .market-inputs and the fetch script,
the plugin template comment points at the dsh-skins repository, the labeler
routes skin/pet content changes to the lockfile instead of removed package
globs, the wallpaper/renderer review route keeps only its title matcher (its
paths moved to dsh-skins), the READMEs link the community index and the pet
notices on their new repositories, and the test-standards baseline drops the
entries for the removed packages' test files.
Move every consumed @deepseek-ai family specifier (272 across 23 manifests),
the dsh.engines.dsh floors and the matching @deepseek-ai/dsh host peers, the
plugin scaffold, the release-age ledger and the packageExtensions keys, the
desktop host payload pin with its regenerated hoisted lock, the root lock,
the CI and release mount pins, the README host badge, the cohort-version
source literals and the cohort prose in docs.
Regenerate the official token contract from the 0.1.7-rc.1 surfaces (293 to
299 names, additive, contractVersion stays 1) and verify the browser platform
seed against the rc.1 shell bundle. Harden the shell-isolation real-boot spec
so it only accepts an app-boot copy whose own non-optional peers resolve: this
cohort pulls an incomplete copy into the workspace for the first time, through
dsh-agent-preset-registry.
Record the cohort decision, the official release-notes and compare evidence,
the published-surface delta and the native-first overlap inventory in
.agents/notes/implemented/architecture/2026-09-23-sdk-cohort-0.1.7-rc.1.
The family stated which DSH host it needs only through dsh.engines.dsh, a
field the plugin manager reads; nothing in the npm manifest told a resolver
that the requirement existed. Every family package, the aggregate included,
and the plugin scaffold now also carry
peerDependencies["@deepseek-ai/dsh"] at the same >=<cohort> literal.
- scripts/family-dsh-engines.test.mjs covers both declarations over every
family package plus the scaffold: presence, the supported >=<semver> form,
and no declaration trailing the scaffold cohort floor.
- scripts/aggregate.mjs keeps the host peer when it rebuilds the aggregate
manifest, still dropping leftover child-plugin peers.
- docs/plugins.md and packages/AGENTS.md state the rule; the host-floor Agent
Note records the new surface and the extra cohort-bump move.
- The personal dsh-sdk-upgrade skill now names the host peer as the sixth
host-floor surface to move with every cohort (outside this repository).
Bump every @deepseek-ai family specifier (258 specifiers across 25
manifests), every dsh.engines.dsh floor (22 packages), cordis to ^4.0.4
and schemastery to ^3.18.4. Align the shared ledger, the desktop host
runtime seed (overrides, exclude list, regenerated lockfile) and the root
lockfile, plus the CI and release mount pins, the cohort-version docs and
the source literals that name the cohort.
The floors had been written as ">=>=0.1.7-alpha.2"; repair them to
">=0.1.7-alpha.2" so the family-engine regex gate passes again.
dsh-market/lib is rebuilt because its committed bundle embeds the resolved
cordis and schemastery paths; the Skin Center output is rebuilt in the
token-contract change that follows.
The official family published 0.1.7-alpha.1 while the alpha branch stood on
0.1.6-alpha.2, and the machine's DSH moved to the new cohort. Four changes in
the release reach this family:
- The settings subsystem is now keyed by the profile entry: ctx.settingsScope,
SettingsScope* and SettingsProvider.installSection/register are gone, replaced
by ctx.configForms, ConfigForm* and SettingsForms. Every family host half
carries its settings on its own Config with volatile fields, every browser
half binds through the webUiSettings service (which resolves a family
namespace to the owning profile entry id and then binds natively, with the
loopback bridge as the fallback), and the shared card/form layer speaks the
new contract including its boolean refusal answers.
- The agent-preset domain became declarative: directory discovery is gone, a
preset is a declaration a plugin registers at runtime. dsh-preset-center now
declares installed presets from its host half (install = declare) and
dsh-liangshen declares its own preset instead of syncing files into
~/.dsh/.agent-presets.
- Session V4 moved the tool-result failure flag to the message root; dsh-pet
read the removed content block and silently rendered failed turns as
successes.
- The client design system renamed its icons and reshaped SessionListState;
the affected call sites and fixtures follow.
Cohort: every consumed @deepseek-ai/dsh-* range, the scaffold, the README
badges, the CI and release mount-smoke pins, the desktop runtime pin and both
lockfiles, and the docs move together; the vendor pins follow the cohort's own
release (cordis 4.0.3, cosmokit 1.8.4, schemastery 3.18.3,
cordis-plugin-include 1.0.8, cordis-plugin-loader 1.0.4). The workspace
packageExtensions restore @deepseek-ai/dsh-util-workspace-path, which
dsh-client-ui-primitives now imports from its emitted lib while declaring no
dependencies.
scripts/e2e-mount.sh, scripts/e2e-mount-rewrite and its test, and
scripts/publish-legacy-aggregate.mjs pass GNU tar --force-local on the
Windows/MSYS lane, where a C:\ output path is otherwise read as a remote host.
The mount smoke does not pass on this workstation: the local dsh CLI is a
symlink into a DSH checkout whose built lib/ predates this cohort's own
multi-file dsh.bundle.patch support, so profile boot crashes on the official
dsh-web-app array before any family row is evaluated. That is host-side build
staleness outside this repository; the lane passes once the DSH checkout is
rebuilt. Recorded with the rest of the decision in
.agents/notes/implemented/architecture/2026-09-22-sdk-cohort-0.1.7-alpha.1.md.
Adapt dsh-web to the experimental @deepseek-ai/dsh-* 0.1.6-alpha.2 cohort in the
same isolated alpha worktree and DSH home, so the accepted 0.1.5-rc.1 stable
environment, its profile tree and the global dsh CLI stay untouched.
Cohort: every consumed range, the plugin scaffold, the root README badges, the
CI and release mount-smoke pins, the desktop runtime pin and its lockfile, both
release-age exclusion lists and the desktop overrides block move to
0.1.6-alpha.2; the declared host floor becomes dsh.engines.dsh >=0.1.6-alpha.2.
cordis, cosmokit and schemastery keep their independent support pins.
@deepseek-ai/dsh-client-ui-workspace joins the repository exclusion list and the
packages that navigate gained it as a devDependency, because the family now
consumes it directly.
Adaptation of the SDK delta - the multi-instance Client Session model:
- SessionListState.current/currentAddress and SessionSummary.completed are gone,
and ISessions.open()/openSubagent()/clear() are removed. View selection now
belongs to the workspace UI, which owns the main-area reference and publishes
it as retainedBy.mainView; navigation is ctx.uiWorkspace.openSession(target).
- shared/client/main-session.ts adds mainViewSessionId(byId), the catalog-level
reading of that marker, and sync-shared copies it into the seven consumers.
Ten call sites across eight packages read the removed faces; two of them
(git-graph auto-isolation, session-archive) type-checked against local
structural doubles and never appeared in the compiler's error list, so the
inventory was built by searching for the removed names rather than by
trusting tsc.
- dsh-task-board's framework-free controller port changes from a list snapshot
to { current(), open(), subscribe() }; the wiring resolves current() from the
marker. dsh-git-graph navigates new worktree sessions through the workspace UI.
dsh-pet, dsh-plugin-manager, dsh-doctor, dsh-liangshen, dsh-session-id and
dsh-session-archive read the marker instead of the removed selection.
Upstream packaging defect: dsh-client-ui-primitives@0.1.6-alpha.2 imports
simple-icons from its emitted lib/index.js while the published manifest still
declares no runtime dependencies; packageExtensions restores it at the exact pin
the official source resolves (16.31.0), beside the existing diff/shiki/micromark
restorations. No installed file is patched.
Native-first: no family row registers the new sidebar panel slots, and the
alpha.1 to alpha.2 slot-key comparison is additive only. dsh-plugin-manager
already extends the official Plugins section through settings.plugins.tab rather
than mounting a parallel page, and that stays the right native extension. The
aggregate declares no external npm plugin, so the new runtime plugin dependency
resolution has no external hard-binding to unmask. The inject contract records
dsh-client-ui-workspace as an approved inject module with its rationale.
Testing: pnpm typecheck, sync-shared:check, skin-center:check, community:check,
libs:check, build, test, test:scripts, test:desktop, runtime-deps:check,
aggregate:check, emoji:check, test:standards, docs:check, i18n:check and
market:check pass, and pnpm install --frozen-lockfile --ignore-scripts resolves
the lockfile. The alpha host in ~/.dsh-alpha is upgraded to 0.1.6-alpha.2 and
every profile @deepseek-ai copy is a symlink into it (235 ok, 0 warn, 0 fail);
dsh --profile alpha-web --dump-config composes the family rows with the retired
ui-settings-unarchive-sessions row.
Adapt dsh-web to the experimental @deepseek-ai/dsh-* 0.1.6-alpha.1 cohort on a
permanent alpha branch with its own worktree and DSH home, so the accepted
0.1.5-rc.1 environment, its profile tree and the global dsh CLI stay untouched.
Cohort: every consumed range, the plugin scaffold, the root README badge, the
CI and release mount-smoke pins, the desktop runtime pin and its lockfile all
move to 0.1.6-alpha.1; cordis, cosmokit and schemastery keep their independent
support pins. Both release-age exclusion lists and the desktop overrides block
follow, and stale rc-only entries are dropped rather than carried.
Adaptation of the SDK delta:
- agent/session-start was removed and agent/created became async serial.
dsh-tool-describe-image awaits its resting verdict inside the listener, so
the tool mask lands before the first request's toolset is assembled, and the
listener never rejects because a rejecting listener now aborts agent
creation. dsh-liangshen merges its two stale, mis-shaped registrations into
one correctly-shaped listener.
- ctx.codeRuntime was renamed to ctx.ptcRuntime; reading the old key would have
silently disabled PTC staging in the liangshen preset.
- dsh-tools now statically imports its new required peer dsh-sandbox, carried
as a root host face; dsh-client-ui-primitives imports diff, restored through
packageExtensions.
- The deprecated synchronous session readers still ship, so existing uses are
recorded rather than migrated.
Native-first: dsh-session-archive replaces its private requireState/setState
workaround with the new public workspace.unarchiveSession verb, while keeping
the inventory, batch operations, cascade physical delete and auto-maintenance
policies that the native archived-sessions page does not provide. The native
SSH remote-workspace provider is recorded as complementary to dsh-ssh, which
covers host management, SFTP, tunnels and cluster execution instead.
Validation: the full CI-equivalent gate sequence passes in the alpha worktree
(typecheck, sync-shared, skin-center, community, libs, build, test,
test:scripts, test:desktop, runtime-deps, aggregate, docs, i18n, market), and
dsh --profile alpha-web --dump-config composes the alpha host with the family
rows from the isolated home. Live GUI acceptance against a running alpha
instance remains open and is recorded in the Agent Note.
All @deepseek-ai/dsh-* ranges, the dsh.engines.dsh floors, the CI and
release mount-smoke pins, the README host badge, the publish-prep smoke
sentence, and both the root and desktop cohort pins move as one literal
to 0.1.5-rc.1, matching the installed DSH host. The
minimumReleaseAgeExclude lists follow at exact rc.1 versions; the
packageExtensions packaging-defect workarounds stay and are retargeted
to rc.1 (the rc.1 tarballs still omit the declared runtime deps,
verified 2026-09-10). Lockfiles regenerated through pnpm.
- devDependencies ^0.1.2-rc.1 -> ^0.1.5-alpha.2 across the family, exact
pins in shared/ and desktop runtime host included
- dsh.engines.dsh floors, README badges, CI mount-smoke CLI pins and the
publish-prep smoke-lane sentence move to >=0.1.5-alpha.2 in one change
- root and desktop runtime minimumReleaseAgeExclude rows re-verified
against the registry (every row has an alpha.2 release) and moved;
desktop overrides block re-pinned with the same evidence
- lockfiles regenerate in the following install commit
Manifest ranges move to ^0.1.2-alpha.4 across the family with minimumReleaseAgeExclude reconciled to the exact alpha.4 versions; the host floor moves with the cohort (dsh.engines.dsh >=0.1.2-alpha.4 across 21 family packages plus the plugin scaffold, the static README badge, and the @deepseek-ai/dsh@0.1.2-alpha.4 CI/release mount-smoke pins). The published delta brands session sequence numbers (SessionSeq / SessionLogOffset, Session.events replaced by eventAt/ownEvents, fork headers reshaped to isSeeded + inheritedEventCount), formalizes a v0-compatible browser wire header in dsh-api-session-controller, adds the keyed-hooks compartment to dsh-client-ui-slots, reworks the subagent continuation path, and removes the family-internal invariant helper. The only repository consumer is the dsh-pet test fixture, which now brands fixture sequence numbers through the exported SessionSeq() constructor.
The deprecated @morlay/better-session aggregate integration ships no more: the external row, its expanded sub-plugin rows and disabled overrides, the devDependency, the release-age exclusions, the patchedDependency with its patch file, and the scripts/dsh-better-session.mjs CLI are removed; the aggregate test flips to a negative guard. dsh-perf's Better Session card and native bsm core stay as the legacy-session migration surface.
The lockfile is regenerated once for both concerns. Full local gate sequence passes (typecheck, build, test, test:scripts, runtime-deps, aggregate, community, skin-center, docs, i18n). Notes: 2026-09-02-drop-deprecated-better-session-integration plus the cohort-note alpha.4 follow-up.
The family's declared host floor now names the adapted cohort: all 21
family packages plus the plugin scaffold declare dsh.engines.dsh
>=0.1.2-alpha.3, the root README badge (zh/en) renders the requirement
statically instead of the live alpha dist-tag, and the CI/release
mount-smoke lanes pin @deepseek-ai/dsh@0.1.2-alpha.3. The scaffold's
SDK devDependencies align to ^0.1.2-alpha.3; docs/publish-prep.md and
docs/plugins.md state the same contract. Decision recorded in
2026-09-01-dsh-host-floor-tracks-cohort.
Bump the whole @deepseek-ai cohort to the dsh-v0.1.2-alpha.2 preview:
rebuild the cohort tarball store from the upstream tag, realign cordis
to 4.0.2 per the trimmed peer set, migrate every settings consumer onto
the ctx.settings service seam (installSection), declare the severed
dsh-client-ui-session type-graph edge for git-graph, and refresh the
CI cohort cache, inject-contract pin, docs badges, and cohort-line
comments.
- doctor: settings scope via ui-settings/client, store engine via
dsh-client-store, sessions port via api-session-controller/client,
slots merge via client-ui-renderer/client; inject list follows the
runtime roster
- git-graph: same remap; SessionSnapshot.composerPhase is gone, the
blank empty-log mirror plus openState now drives the branch-selector
seat; worktree session launch moved to ISessions.create
- shared: platform table mirrors the 0.1.2 frozen module table (client-store
in, client-runtime out), preset drops RUNTIME_STORE_EXEMPTION and the
dead host-apiproxy branch; the platform contract spec becomes runnable
(renamed to *.spec.ts so the shared vitest include matches)
- aggregate: freeze dsh-aionui-panel for this cohort (discontinued,
unbuildable without client-runtime) pending the maintainer's final call
- sync-shared: settings-form shared source migrated, copies resynced
The 0.1.2-alpha.1 cohort is a developer preview that is not published to
npm, so every @deepseek-ai package is resolved from tarballs built from
the official source tag deepseek-harness@dsh-v0.1.2-alpha.1 (commit
cd5ef81) via a pnpm-workspace.yaml overrides block. Remove that block
once the cohort reaches registry.npmjs.org.
- bump every @deepseek-ai/dsh-* range to ^0.1.2-alpha.1 (shared pins exact)
- drop devDependencies on the two removed upstream packages:
dsh-client-runtime and dsh-host-apiproxy
- refresh minimumReleaseAgeExclude pins; drop the two dead entries
- bump dsh.engines to >=0.1.2-alpha.1 across plugin manifests
- pin packageManager to pnpm@11.24.0: 11.9.0 misapplies overrides for
transitive dependencies of file: tarballs and hits the registry
Display and source layers rename to dsh-web: GitHub slug, docs and prose,
aggregate package dir packages/dsh-web-all with npm name
@linxin666/dsh-web-all, settings package dir packages/dsh-web-settings,
private shared package dsh-web-shared, repo-local skill dirs, and the
docs banner asset.
Runtime, wire, and storage identifiers are frozen byte-identical so
installed profiles keep resolving with zero migration: web-ui-* bundle
ids, the dsh-web-ui-market settings section id, /api/dsh-web-ui-settings
and its proxy-token header, and the dsh-web-ui-telemetry-* storage keys.
Frozen history (docs/archive, docs/release-notes, archived notes), the
JAVA-LW fork reference, and local filesystem paths keep the old name.
npm migration: the next tag release dual-publishes @linxin666/dsh-web-all
alongside the final @linxin666/dsh-web-ui-all version, then the old name
is deprecated with a pointer; dual-publish lasts two releases.
Decision record: .agents/notes/implemented/architecture/2026-08-24-product-rename-dsh-web.md
Align every workspace @deepseek-ai/dsh-* dependency with the host runtime
line: devDependencies/peerDependencies move from ^0.1.1-rc.1 to ^0.1.1-rc.2
(shared/package.json exact pin included, plugin-template included), the
pnpm-workspace.yaml minimumReleaseAgeExclude list is reconciled to the
approved 0.1.1-rc.2 versions, and pnpm-lock.yaml is regenerated (43 SDK
packages at 0.1.1-rc.2, zero rc.1 entries; frozen-lockfile install passes).
Host runtime already upgraded to 0.1.1-rc.2 (dsh CLI + web profile tree).
- rename vendored cordis imports/aliases to @deepseek-ai/cordis across
packages, scripts, templates, and skin bundles; drop cordis package
declarations and keep tsdown node externals explicit
- add plugin configuration cards for remote-web-ui, task-board, live-stats,
and pet, backed by dsh-settings namespaces and client settingsScope
- make task-board system prompt announcement follow announceToAgent live
- make pet display persistence whole-pixel so drag state stays schema-valid
- remove working-activity, code-kline, and ui-code-kline packages and their
aggregate/docs references
- update README, plugins doc, and publish-prep snapshot
- packages/dsh-skins: skin family aggregate (all skins + skin-center as
workspace deps; skin enable remains dsh-skin use managed)
- packages/web-ui-all: full family aggregate (5 feature plugins + dsh-skins)
- scripts/aggregate.mjs: regenerates aggregate cordis.patch.yml from each
package's insert rows and syncs workspace:* deps (--check for CI)
- scripts/dsh-plugin-new + plugin-template: scaffold new plugins and wire
them into the family