Move every family manifest, the plugin scaffold and the shared workspace
package onto the 0.1.7-rc.2 cohort, together with the surfaces that state
the same fact:
- the dsh.engines.dsh floors and the matching @deepseek-ai/dsh host peers
- the release-age exclusion ledger and the two packageExtensions keys
- the root README badges, the CI/release mount-smoke pins and the
docs/publish-prep.md and docs/plugins.md prose
Two rc.2 facts were verified against the published artifacts rather than
inferred from the version number:
- the shell's frozen static module table is unchanged (the same nine
specifiers in the dsh-web-frontend rc.2 dist bundle), so
shared/web-platform.ts keeps its list and only its provenance comment
moves; the new dsh-client-shortcuts is an ordinary client plugin, not a
static module
- @deepseek-ai/dsh-client-ui-primitives@0.1.7-rc.2 imports a further
undeclared face, @deepseek-ai/dsh-util-code-language, so the
primitives packageExtensions patch gains that pin
The satellite peer floors in pnpm-lock.yaml still read >=0.1.7-rc.1: they
belong to the satellite packages and move when those repositories release
the aligned version.
Move every consumed @deepseek-ai family specifier (272 across 23 manifests),
the dsh.engines.dsh floors and the matching @deepseek-ai/dsh host peers, the
plugin scaffold, the release-age ledger and the packageExtensions keys, the
desktop host payload pin with its regenerated hoisted lock, the root lock,
the CI and release mount pins, the README host badge, the cohort-version
source literals and the cohort prose in docs.
Regenerate the official token contract from the 0.1.7-rc.1 surfaces (293 to
299 names, additive, contractVersion stays 1) and verify the browser platform
seed against the rc.1 shell bundle. Harden the shell-isolation real-boot spec
so it only accepts an app-boot copy whose own non-optional peers resolve: this
cohort pulls an incomplete copy into the workspace for the first time, through
dsh-agent-preset-registry.
Record the cohort decision, the official release-notes and compare evidence,
the published-surface delta and the native-first overlap inventory in
.agents/notes/implemented/architecture/2026-09-23-sdk-cohort-0.1.7-rc.1.
Bump every @deepseek-ai family specifier (258 specifiers across 25
manifests), every dsh.engines.dsh floor (22 packages), cordis to ^4.0.4
and schemastery to ^3.18.4. Align the shared ledger, the desktop host
runtime seed (overrides, exclude list, regenerated lockfile) and the root
lockfile, plus the CI and release mount pins, the cohort-version docs and
the source literals that name the cohort.
The floors had been written as ">=>=0.1.7-alpha.2"; repair them to
">=0.1.7-alpha.2" so the family-engine regex gate passes again.
dsh-market/lib is rebuilt because its committed bundle embeds the resolved
cordis and schemastery paths; the Skin Center output is rebuilt in the
token-contract change that follows.
The official family published 0.1.7-alpha.1 while the alpha branch stood on
0.1.6-alpha.2, and the machine's DSH moved to the new cohort. Four changes in
the release reach this family:
- The settings subsystem is now keyed by the profile entry: ctx.settingsScope,
SettingsScope* and SettingsProvider.installSection/register are gone, replaced
by ctx.configForms, ConfigForm* and SettingsForms. Every family host half
carries its settings on its own Config with volatile fields, every browser
half binds through the webUiSettings service (which resolves a family
namespace to the owning profile entry id and then binds natively, with the
loopback bridge as the fallback), and the shared card/form layer speaks the
new contract including its boolean refusal answers.
- The agent-preset domain became declarative: directory discovery is gone, a
preset is a declaration a plugin registers at runtime. dsh-preset-center now
declares installed presets from its host half (install = declare) and
dsh-liangshen declares its own preset instead of syncing files into
~/.dsh/.agent-presets.
- Session V4 moved the tool-result failure flag to the message root; dsh-pet
read the removed content block and silently rendered failed turns as
successes.
- The client design system renamed its icons and reshaped SessionListState;
the affected call sites and fixtures follow.
Cohort: every consumed @deepseek-ai/dsh-* range, the scaffold, the README
badges, the CI and release mount-smoke pins, the desktop runtime pin and both
lockfiles, and the docs move together; the vendor pins follow the cohort's own
release (cordis 4.0.3, cosmokit 1.8.4, schemastery 3.18.3,
cordis-plugin-include 1.0.8, cordis-plugin-loader 1.0.4). The workspace
packageExtensions restore @deepseek-ai/dsh-util-workspace-path, which
dsh-client-ui-primitives now imports from its emitted lib while declaring no
dependencies.
scripts/e2e-mount.sh, scripts/e2e-mount-rewrite and its test, and
scripts/publish-legacy-aggregate.mjs pass GNU tar --force-local on the
Windows/MSYS lane, where a C:\ output path is otherwise read as a remote host.
The mount smoke does not pass on this workstation: the local dsh CLI is a
symlink into a DSH checkout whose built lib/ predates this cohort's own
multi-file dsh.bundle.patch support, so profile boot crashes on the official
dsh-web-app array before any family row is evaluated. That is host-side build
staleness outside this repository; the lane passes once the DSH checkout is
rebuilt. Recorded with the rest of the decision in
.agents/notes/implemented/architecture/2026-09-22-sdk-cohort-0.1.7-alpha.1.md.
Adapt dsh-web to the experimental @deepseek-ai/dsh-* 0.1.6-alpha.2 cohort in the
same isolated alpha worktree and DSH home, so the accepted 0.1.5-rc.1 stable
environment, its profile tree and the global dsh CLI stay untouched.
Cohort: every consumed range, the plugin scaffold, the root README badges, the
CI and release mount-smoke pins, the desktop runtime pin and its lockfile, both
release-age exclusion lists and the desktop overrides block move to
0.1.6-alpha.2; the declared host floor becomes dsh.engines.dsh >=0.1.6-alpha.2.
cordis, cosmokit and schemastery keep their independent support pins.
@deepseek-ai/dsh-client-ui-workspace joins the repository exclusion list and the
packages that navigate gained it as a devDependency, because the family now
consumes it directly.
Adaptation of the SDK delta - the multi-instance Client Session model:
- SessionListState.current/currentAddress and SessionSummary.completed are gone,
and ISessions.open()/openSubagent()/clear() are removed. View selection now
belongs to the workspace UI, which owns the main-area reference and publishes
it as retainedBy.mainView; navigation is ctx.uiWorkspace.openSession(target).
- shared/client/main-session.ts adds mainViewSessionId(byId), the catalog-level
reading of that marker, and sync-shared copies it into the seven consumers.
Ten call sites across eight packages read the removed faces; two of them
(git-graph auto-isolation, session-archive) type-checked against local
structural doubles and never appeared in the compiler's error list, so the
inventory was built by searching for the removed names rather than by
trusting tsc.
- dsh-task-board's framework-free controller port changes from a list snapshot
to { current(), open(), subscribe() }; the wiring resolves current() from the
marker. dsh-git-graph navigates new worktree sessions through the workspace UI.
dsh-pet, dsh-plugin-manager, dsh-doctor, dsh-liangshen, dsh-session-id and
dsh-session-archive read the marker instead of the removed selection.
Upstream packaging defect: dsh-client-ui-primitives@0.1.6-alpha.2 imports
simple-icons from its emitted lib/index.js while the published manifest still
declares no runtime dependencies; packageExtensions restores it at the exact pin
the official source resolves (16.31.0), beside the existing diff/shiki/micromark
restorations. No installed file is patched.
Native-first: no family row registers the new sidebar panel slots, and the
alpha.1 to alpha.2 slot-key comparison is additive only. dsh-plugin-manager
already extends the official Plugins section through settings.plugins.tab rather
than mounting a parallel page, and that stays the right native extension. The
aggregate declares no external npm plugin, so the new runtime plugin dependency
resolution has no external hard-binding to unmask. The inject contract records
dsh-client-ui-workspace as an approved inject module with its rationale.
Testing: pnpm typecheck, sync-shared:check, skin-center:check, community:check,
libs:check, build, test, test:scripts, test:desktop, runtime-deps:check,
aggregate:check, emoji:check, test:standards, docs:check, i18n:check and
market:check pass, and pnpm install --frozen-lockfile --ignore-scripts resolves
the lockfile. The alpha host in ~/.dsh-alpha is upgraded to 0.1.6-alpha.2 and
every profile @deepseek-ai copy is a symlink into it (235 ok, 0 warn, 0 fail);
dsh --profile alpha-web --dump-config composes the family rows with the retired
ui-settings-unarchive-sessions row.
The plugin's 0.19.1 peers declare every consumed @deepseek-ai/dsh-* face
as ^0.1.5-rc.1, and a prerelease range only matches its own
[major,minor,patch] tuple, so the 0.1.6-alpha.1 cohort this branch
builds against satisfies none of them. The alpha branch therefore drops
the external right-panel plugin: aggregate.yml has no rows entry, the
aggregate package.json no longer depends on it, the release-age
exclusion goes away, and the regenerated cordis.patch.yml carries 20
rows / 19 workspace deps. The mount lane asserts the plugin is absent
instead of mounted, the mount tooling loses its better-sidebar tarball
override, and the READMEs, docs, publish-prep and the alpha Agent Note
record the standing divergence from dev. The isolated alpha home was
reinstalled and its stale links removed; dsh --profile alpha-web
--dump-config composes without a better-sidebar row.
The Better Session management surface only ever managed the removed
@morlay/better-session aggregate integration: its enable switch rewrote
managed overrides for aggregate rows that no longer exist, so the card
could only show the inactive posture. The whole surface goes away:
src/bsm (routes, service, migration core/runner, legacy-log codec,
profile managed blocks, import worker entry), the client card and its
bs-locales dictionaries, the perf settings card's nested section, the
./better-session-import export with its tsdown companion build, the
five bsm test files, and the 24 bsm.* keys in the central dsh-i18n ru
dictionary. The i18n audit's package table lists dsh-perf's single
dictionary module again, and the e2e mount comment states the
integration is removed rather than inactive.
The perf-settings-card.tsx hunks of this removal landed in the
concurrent eb2e13568 (shared index); this commit carries the rest.
Notes: 2026-09-02-remove-dsh-perf-better-session-card plus fact updates
in 2026-09-02-drop-deprecated-better-session-integration.
Gates: dsh-perf build/test 45/45/typecheck clean; workspace typecheck,
test, test:scripts 237/237, i18n:check (16 ns, 1278 zh = 1278 ru),
docs:check.
The alpha.2 cohort removal of @deepseek-ai/dsh-client-runtime took the
right panel out of the aggregate on 2026-08-30. Upstream shipped
0.18.0-alpha.0 (peers ^0.1.2-alpha.2, client inject renamed to
dsh-client-modules), so the aggregate row, package.json pin, and the
aggregate and mount-smoke assertions are restored at that exact version;
@mlgbnb/dsh-archive-manager stays excluded (latest 1.0.7 still imports
the removed face). Docs and the cohort notes are brought along.
alpha.2's dsh web prints the tokenized root URL (?token=<launch token>)
and fences / behind browser auth; scripts/e2e-mount.sh parsed the URL
with a port-only grep, dropping the token so Playwright landed on the
401 auth page and the frame wait timed out (eight straight red dev CI
runs after the alpha.2 CLI pin). Parse through the token boundary
instead; the smoke now carries the full printed URL.
Guard the smoke against the auth page directly: a 5s fast-fail on the
auth-page text names the failure instead of timing out on the frame
selector. Record the follow-up in the e2e mount anchor note and the
upgrade/compatibility skill lessons.
- dsh-web-all READMEs no longer claim the removed aionui-panel ships in
the aggregate; dsh-perf READMEs and renderDegrade copy stop advertising
the assistant-step shadow whose slot is gone upstream, and the orphaned
perf-assistant-shadow.tsx is deleted.
- pet and remote-web-ui notExposed copy adopts the corrected wording (the
dsh-host-apiproxy WEB_SETTINGS_NAMESPACES allowlist no longer exists).
- Dead libExternal entries for the deleted dsh-client-runtime are removed
(pet, git-graph, community-plugins), dead client-runtime mocks are
dropped (describe-image, remote-web-ui), skin-center's unused
api-workspace-controller inject is trimmed, and the mount e2e comment
matches the removal.
- shared/host/dsh-home.ts gains its final newline and the ten consumer
copies are resynced; leftover review debug output and stale aionui
comments are cleaned.
- Record the review evidence archive and the bug-fix Agent Note
(.agents/notes/implemented/bug-fix/2026-08-28-descriptor-faithful-wire-contracts).
Display and source layers rename to dsh-web: GitHub slug, docs and prose,
aggregate package dir packages/dsh-web-all with npm name
@linxin666/dsh-web-all, settings package dir packages/dsh-web-settings,
private shared package dsh-web-shared, repo-local skill dirs, and the
docs banner asset.
Runtime, wire, and storage identifiers are frozen byte-identical so
installed profiles keep resolving with zero migration: web-ui-* bundle
ids, the dsh-web-ui-market settings section id, /api/dsh-web-ui-settings
and its proxy-token header, and the dsh-web-ui-telemetry-* storage keys.
Frozen history (docs/archive, docs/release-notes, archived notes), the
JAVA-LW fork reference, and local filesystem paths keep the old name.
npm migration: the next tag release dual-publishes @linxin666/dsh-web-all
alongside the final @linxin666/dsh-web-ui-all version, then the old name
is deprecated with a pointer; dual-publish lasts two releases.
Decision record: .agents/notes/implemented/architecture/2026-08-24-product-rename-dsh-web.md
aionui-panel is no longer supported: drop its unit tests, vitest config,
test/typecheck gate scripts, and test-only devDeps (jsdom, vitest,
vite-tsconfig-paths); the package stays installed as a transitional
fallback but carries no gates anymore (packages/AGENTS.md testing-rule
exception recorded).
The mount e2e lane now asserts dsh-better-sidebar only (mount + no crash
markers); the aionui assertions are gone, so the plugin-mount CI lane no
longer depends on the published aionui-panel version and is green on main
without waiting for the family release.
Also scope the scratch profile's minimumReleaseAgeExclude in
e2e-mount.sh to dsh-better-sidebar@0.13.0 (matching #468).
Docs: root README pair, repo and packages AGENTS.md, and the package
README pair now mark aionui-panel as unsupported/transitional.
The aionui-panel settings card now chooses the right-panel provider instead of a
boolean switch: 'Use DSH-better-sidebar' (default; aionui is deprecated) or
'Use aionui-panel (deprecated)' (host schema + client gate + card select).
Mutual exclusion: better-sidebar >= 0.13.0 reads the aionui-panel namespace
and does not mount while aionui is selected (no changes needed here beyond
the dependency bump to ^0.13.0). aggregate.mjs supports external 'rows'
manifest entries only (the earlier config-patch mechanism is dropped).
Lockfile intentionally not updated yet: dsh-better-sidebar@0.13.0 must be
published first (PR omdsh-dev/DSH-better-sidebar#181), then pnpm install.