ds-review-bot round 1: boot() now throws `host preparation failed` when
prepare() rejects before any config-tree entry mounts (the plugin-tree label
overstated), and the new hygiene gate verify-vendored-links pins the
linkWorkspacePackages fix — every vendored package name in pnpm-lock.yaml
must resolve to a workspace link with no registry copy alongside.
- inline the collect() identity wrapper now that both streams use the
seam's diagnostic-tail shape
- resolve the packaged rg path lazily at the first call (memoized):
@vscode/ripgrep resolves its platform package at module evaluation, so a
static import turned a missing/corrupt platform package into a Loader
composition failure instead of the documented per-call SEARCH_FAILED
- classify synchronous spawn-creation throws (a NUL in argv, an abort
racing the pre-check, a rejected resolution) into SEARCH_FAILED /
SEARCH_ABORTED instead of leaking raw errors
- correct the stderrMaxBytes contract: the stderr excerpt is embedded in
SEARCH_* error messages, not hidden from the model
- export virtualManifest and pin its three acceptance paths (prefix hit,
pnpm-11 truncated-name content-scan fallback, both miss) with fixture
unit tests
Tests: rg-path.spec.ts (resolution failure + memoized rejection),
tools.spec.ts spawn-creation classification, notices spec virtualManifest.
The session-fixture-layout gate requires every session JSONL fixture in
the canonical packed layout (maximal delta runs per kind/block, as
migrate:packed-session-fixtures rewrites); the packChunks: false knob
violated that invariant and failed the snapshot job. Revert the knob and
canonicalize the recorded fixture instead: the live log's
eager-drain-packed rows migrate to the maximal-run layout a burst replay
reproduces, so the fixture stays replay-deterministic and canonical.
Merges master (default-workspace-write-ui, installer-adopt-checkout,
remove-scoped-bash, goal-clear-single-flight, frontend-plugin-loader,
install-interface-choice, …).
Conflict resolutions:
- apps/cli/tests/shipped-composition.e2e.ts: keep the fixed glob/grep
roster assertion; master's workspace-write composition now confines
tool-bash, so the escalation pair is pinned present (my earlier
absence pin is superseded) together with master's permission facts.
- even-out-shipped-tool-rosters note: both sides edited it; the merged
text keeps both sets of changes and the pair is re-recorded.
The scenario previously carried an authored fixture; W4 of #1119 review
requires a live transcript. Recording surfaced two composition bugs that
are fixed here alongside it:
- provider ids: the app and the replay catalog both named the old
'deepseek' provider, which no adapter registers; both now use
'deepseek-official'
- the live config lacked persistenceCompression: none, so record-mode
sessions were written zstd-compressed and could not be harvested
(the snapshot twin already forced plaintext)
Recorded logs also need deterministic replay:
- packChunks: false in both configs — the eager-drain batch boundaries
that split packed delta runs are timing-dependent, so a packed log of
a long reasoning stream cannot replay-match its live record
- the fixture's request/header config and request/context are normalized
to the replay-produced minimal shape (the live adapter logs model
capabilities llm-replay has no data for), and tool-result path
separators are canonicalized to '/' for the Linux golden
posixOnly is restored now that the fixture is recorded.
The scenario previously carried an authored fixture; W4 of #1119 review
requires a live transcript. Recording surfaced two composition bugs that
are fixed here alongside it:
- provider ids: the app and the replay catalog both named the old
'deepseek' provider, which no adapter registers; both now use
'deepseek-official'
- the live config lacked persistenceCompression: none, so record-mode
sessions were written zstd-compressed and could not be harvested
(the snapshot twin already forced plaintext)
Recorded logs also need deterministic replay:
- packChunks: false in both configs — the eager-drain batch boundaries
that split packed delta runs are timing-dependent, so a packed log of
a long reasoning stream cannot replay-match its live record
- the fixture's request/header config and request/context are normalized
to the replay-produced minimal shape (the live adapter logs model
capabilities llm-replay has no data for), and tool-result path
separators are canonicalized to '/' for the Linux golden
posixOnly is restored now that the fixture is recorded.
- delete the singleQuote shell-quoting helper and its bash-spawning tests
(no in-repo consumers; no shell layer exists anymore)
- drop spill from both collect streams: the tool never reads a raw spill
path, and a lossy stdout read is a pure SEARCH_RAW_OUTPUT_OVERFLOW error
- prepend --no-config so a host RIPGREP_CONFIG_PATH cannot inject a --pre
preprocessor into the unconfined spawn
- promote graceMs and stderrMaxBytes to validated Config fields (defaults
SEARCH_GRACE_MS / SEARCH_STDERR_MAX_BYTES) instead of inheriting
bash-local's config
- correct the grep tool's JSDoc seam reference (bash -> subprocess)
- drop the dead exit-127/command-not-found classification branch
- jscpd: the executor/tool mirror dsh-bash-local/dsh-tool-bash by design
(Agent Note), so the mirrored regions carry explicit ignore markers with
reasons instead of being flagged as duplication.
- pwsh-local: a self-terminated process reports SIGTERM or SIGKILL on
POSIX (PowerShell's Stop-Process choice), not only SIGTERM.
- gen-tool-catalog.spec: the shipped-tool completeness list gains 'pwsh'.