Commit Graph

5569 Commits

Author SHA1 Message Date
imccyu
1529be6fd4 feat(storage): json backend — one human-readable file per unit
Atomic whole-file replacement (same-dir temp + fsync + rename + parent
fsync); the in-memory unit state is authoritative and the file is always
the current net state, pretty-printed. Missing files open as empty units
and materialize on first write; foreign or unparsable files reject with
malformed-medium, stored-version drift with version-mismatch.
2026-07-25 11:08:04 +08:00
imccyu
e90b0d51df feat(storage): storage hub with named backend registry and data-form mounts
ctx.storage is a pure registration hub: multiple named backends stay
mounted side by side, data forms (domain first) mount via the
merge-extensible StorageForms map. src/backend.ts is the normative
KV-facet contract; tests/contract.ts is the shared conformance suite
every backend runs. Backends expose data-shape facets (kv now, an
append-log facet reserved for the future session-backend migration).
2026-07-25 11:08:04 +08:00
imccyu
2e27b8aeef chore(web): gate repairs for the config-tree boot round
Lint (bridge JSDoc params, service-class export shape, async invariant
listener form), regenerated doc catalogs/graphs with role classifications
for httpServer and clientModuleHost, catalog type-link exemptions for the
route/graph contracts, knip alignment (apps/cli composes via cordis.yml so
its yml-named deps are runtime edges knip cannot see; webserver's deleted
test dir), the zh side of the loading-model note brought along with its
pairing records, and coverage exclusions for the new web-transport halves
under the GUI test-lane TODO (real-composition harnesses land with that
lane).
2026-07-25 10:38:54 +08:00
imccyu
db59d32c9b docs(gui): agent notes for the config-tree boot and transport layering
New note records the dsh web composition decision (flat cordis.yml, the
AppCLIEntry/AppWebEntry class pair, one declaration place per config
source, the five-way transport split) with its rejected alternatives; the
client-plugin-loading note's roster endgame and HMR sections are brought
current with what shipped.
2026-07-25 10:25:02 +08:00
imccyu
5466a81474 feat(web): boot dsh web from a config tree via AppCLIEntry
apps/cli/cordis.yml holds the whole composition flat — the host runtime
rows, the api-gateway row, the webserver row, and the ten dshClient rows.
AppCLIEntry is the pre-cordis glue: layered env (ambient > cwd .env >
$DSH_HOME/.env, fixing DSH_HOME=... dsh web not finding its key), patch
composition from the three non-yml sources (profile json through the static
PROFILE_MAPPINGS table, CLI flags, the resolved frontend distIndex), the
Loader include boot (--dev appends the hmr row before the settle), and the
fail-loud triple (assertEntriesLoaded + installFailLoud + an all-ACTIVE
sweep for PENDING fibers). web.ts shrinks to argv parsing + the URL line.
2026-07-25 10:25:02 +08:00
imccyu
80cd8f54b5 refactor(web): collapse the shell boot into the AppWebEntry class
The four free functions in boot.tsx become one kernel class holding what
must exist before cordis: the parsed BootManifest, the ClientModuleSystem
instance, and the loading-page handles. Context/Loader setup runs in
parallel with the immediately-tier prefetch, but entry creation awaits the
prefetch: materialization is tree.import's synchronous require, so
cross-package require edges (i18n -> runtime/client) need every
immediately-tier factory registered first — unbarriered creation raced
10-25% of boots. The kernel adopts the modules entry (writes the
__DSH_MODULES__ slot pre-cordis, creates the entry first, skips its graph
row), and provide('modules') now lives in the adoption apply. apps/web
drops its host-package edges (composition is apps/cli's job).
2026-07-25 10:23:40 +08:00
imccyu
8d4aa73abe feat(web): grow real node halves in connection and hmr
connection binds the web transport: it injects httpServer + apiProxy and
registers toFetchHandler(ctx.apiProxy) under the /api prefix (the node:http
to fetch bridge moves in from the webserver, keeping the res-close disconnect
detection and drain/close backpressure waits). hmr owns dev reload: a
stat-poll watch per graph row driven by clientModuleHost.onGraphChanged,
rebuilt(id) on content change, and the /plugins/events SSE route (GET/HEAD
guarded); frame types are single-sourced in events.ts shared by both halves.
2026-07-25 10:23:40 +08:00
imccyu
c12277b4bb feat(web): make dsh-client-modules dual-face with an incremental host scan
The node half is ClientModuleHostService (ctx.clientModuleHost): it composes
the __DSH_BOOT__ graph by scanning loader entries for dshClient packages,
serves /plugins/<id>/client.js, taps the index render, and exposes
rebuilt/onRebuilt/onGraphChanged. Scanning is incremental per package — no
full-rescan path exists: internal/plugin marks the fiber's entry name dirty,
a flush reconciles each name against live entries, package metadata
(including negative verdicts) caches forever, and re-hashing is reachable
only through rebuilt(id). The browser half moves wholesale to the standard
./client export (ClientModuleSystem, parseBootManifest with the dual-view
BootManifest, and the adoption plugin face that reads the
window.__DSH_MODULES__ slot and provides ctx.modules).
2026-07-25 10:23:40 +08:00
imccyu
f499872cec refactor(web): rewrite webserver as a plain route-registration plugin
HttpServerService provides ctx.httpServer: register(route) -> disposer
(duplicate patterns throw), tapIndex transforms in registration order, and
the bound port; matching is exact > longest prefix > static dist fallback
(403/405/SPA semantics preserved). The server listens on activation, answers
per-request failures with 400 + a log line instead of exiting the process,
and knows no harness concepts — the boot graph, bundle routes, SSE channel,
and /api prefix all moved to their owning plugins.
2026-07-25 10:23:39 +08:00
imccyu
3cad7f6957 refactor(web): upgrade apiproxy to the api-gateway service plugin
createApiProxy moves from dsh-host-runtime into dsh-host-apiproxy (the
dependency direction already pointed this way); the package now
default-exports ApiProxyService (config {provider, model}, provides
ctx.apiProxy) while staying transport-agnostic — it registers no routes.
Runtime keeps bootHost/startHost for the headless path with its import
re-anchored, and drops the mountWebPlugins roster mounting helper.
2026-07-25 10:22:43 +08:00
Yichen Jiang
1bfca86128 feat(tui): select model reasoning effort 2026-07-25 08:32:38 +08:00
Yichen Jiang
83cccd7ffc feat(llm): add scriptable mock fault server 2026-07-25 08:20:51 +08:00
Yichen Jiang
1c66759235 Merge origin/master into worktree/llm-reasoning-effort 2026-07-25 07:59:21 +08:00
Yichen Jiang
8372340f9c feat(llm): add model-specific reasoning effort controls 2026-07-25 07:47:51 +08:00
Tianyi Cui
2beaa18f42 Merge remote-tracking branch 'origin/master' into worktree/acp-automation-protocol
# Conflicts:
#	packages/support/acp-snapshot/README.md
2026-07-25 02:07:28 +08:00
Tianyi Cui
9c4bc3e516 Merge remote-tracking branch 'origin/master' into web-e2e-lane 2026-07-25 02:00:05 +08:00
Tianyi Cui
05ee162723 Merge remote-tracking branch 'origin/master' into fix-webplugins-watch-flake
# Conflicts:
#	packages/host/webserver/src/web-plugins.ts
#	packages/host/webserver/tests/web-plugins.spec.ts
2026-07-25 01:58:59 +08:00
Tianyi Cui
16910475ef docs(i18n): mirror ACP-automation edits into the zh pairs from master
Master's i18n batches added Chinese counterparts to ~50 docs this PR
edits in English. Bring each zh side along with the minimal edits
covering the en diff (recorded-hash diffs, not re-translations),
reunite the stream-workflow-progress pair under rejected/ with its
manifest entry, re-record all pairing hashes, and regenerate the
event/persistence/tool catalogs and doc graphs over the merged tree.
2026-07-25 01:58:42 +08:00
Tianyi Cui
f7b36bd36d Merge pull request #618 from deepseek-harness/worktree/fix-master-ci-flakes
Stabilize master CI across platforms
2026-07-25 01:32:03 +08:00
Tianyi Cui
2096050824 fix(webserver): registry-owned stat poll replaces fs.watchFile baseline race
The dev bundle watch missed rebuilds that landed while the registry was
constructing: fs.watchFile captures its comparison baseline with an
ASYNCHRONOUS first stat, so a write racing that window is absorbed into
the baseline and never reported. Standalone repro missed 24/400 same-tick
rewrites; the CI flake in web-plugins.spec.ts ('watch mode: a bundle
content change re-hashes the row...') was exactly this — the spec writes
immediately after createHostWebPluginRegistry returns.

The watch now polls from one registry-owned setInterval against a stat
baseline the scan itself captures synchronously, stat-before-read: a
write landing between stat and read leaves the hash newer than the
baseline (next tick re-hashes to the same rev, no spurious notify); a
write landing after the read leaves the baseline older (next tick
detects and notifies). No blind window. The poll iterates the live
table, so rescans retarget the watch for free and dispose clears one
timer. Stress: real-registry same-tick rewrite 0/600 missed (was 1/300);
spec watch tests 0/50.

New regression test pins the same-tick-as-construction write. Its
rewrite deliberately differs in size from the seed: a same-millisecond
same-size rewrite is invisible to any mtime+size poll (coarse fs
timestamps) — a stat-polling limit, not this regression. Loading-model
Agent Note updated in both languages (pair re-recorded).
2026-07-25 01:22:46 +08:00
Chinesezjc
f09539581d docs(ci): record disabled forking as an explicit precondition of the self-hosted lane
The pool selector is defense-in-depth only — pull_request executes the
PR's own workflow definition, so YAML cannot enforce runner trust. Make
the actual enforcement boundary explicit in the decision record:
org-side disabled forking (the public release is an isolated read-only
mirror under a separate org), with migration to a repo-restricted
org-level runner group with base-branch workflow pinning as a hard
gate before forking could ever be enabled.
2026-07-25 00:54:35 +08:00
Chinesezjc
1a5d892ec5 ci: halve coverage workers on the shared self-hosted leg
The hosted 32-core runner is exclusive to one job, but the vm-backup
pool shares one 64-core VM across four runner instances; concurrent
PRs could stack 4×24 = 96 Vitest workers and re-trigger the documented
aggregate-contention failures in the timing-sensitive process suites.
Bound the self-hosted leg at 12 workers per job (48 host-wide fully
loaded) and keep 24 on the hosted leg, selected by the same expression
as the pool.
2026-07-25 00:45:31 +08:00
Chinesezjc
1f094ae076 fix(gui): todo row keeps running/stopped execution states visible
The row rendered a status only for error, so a call cancelled before
tool/result read as a completed plan update even though no todo/write
occurred. Non-ok states now ride the generic row's StateDot semantics
(ongoing dot while running, warning dot + 已中断 marker when interrupted);
the ok badge stays for settled successful updates.
2026-07-25 00:42:40 +08:00
Tianyi Cui
1d066e0f74 Fix remaining PTY and bundle watch races
Keep inherited child prompt markers bounded by the normal silence fallback. Stage web-plugin rescans atomically and retain missing watch state until a successful rebuild.
2026-07-25 00:33:33 +08:00
Tianyi Cui
f9a638b8a6 Stabilize master CI across platforms 2026-07-25 00:10:37 +08:00
Chinesezjc
34eef10f04 test(snapshot): re-record tool schemas for the todo item key tightening
additionalProperties: false on the todo_write item schema is model-visible
(tool schemas ride the request header and the code-mode prompt types), so
the pinned ACP/headless expected outputs re-record. Keyless refresh; the
two locally-failing scenarios are this machine's known environment issues
(HOME-symlink cwd normalization, SQLite ExperimentalWarning), not the diff.
2026-07-25 00:00:50 +08:00
Chinesezjc
8d53d44b60 docs(ci): reconcile every present-tense topology description with the coverage lane move
Sweep all remaining sources that still described coverage as an
enterprise 32-core job: the ci.yml jobs preamble, the three-job
paragraph of the larger-hosted-runners note, and the required-pool
sentence of the portable-recovery note — English and Chinese sides of
both notes, with their i18n pairing records re-recorded.
2026-07-24 23:49:58 +08:00
Tianyi Cui
440384fdb4 Merge remote-tracking branch 'origin/master' into worktree/acp-automation-protocol
# Conflicts:
#	.agents/notes/implemented/architecture/2026-06-14-session-persistence.md
#	.agents/notes/implemented/architecture/2026-06-20-package-hierarchy.md
#	.agents/notes/implemented/architecture/2026-07-02-tool-render-intent-union.md
#	.agents/notes/implemented/feature/2026-06-14-acp-agent-client-protocol.md
#	.agents/notes/implemented/feature/2026-06-14-acp-multi-session.md
#	.agents/notes/implemented/feature/2026-06-18-acp-terminal-and-tool-rendering.md
#	.agents/notes/implemented/feature/2026-07-19-model-facing-goal-tools.i18n.yaml
#	.agents/notes/implemented/feature/2026-07-19-model-facing-goal-tools.md
#	.agents/notes/implemented/feature/2026-07-19-model-facing-goal-tools.zh.md
#	.agents/notes/implemented/simplification/2026-07-04-trim-acp-bridge-unreachable-surface.md
#	docs/architecture.i18n.yaml
#	docs/cookbook/extension-cookbook.i18n.yaml
#	docs/cookbook/extension-cookbook.md
#	docs/cookbook/extension-cookbook.zh.md
#	docs/core-data-structures/approval.md
#	docs/core-data-structures/user-interaction.md
#	docs/event-producer-consumer.md
#	docs/persistence-catalog.md
#	docs/testing.md
#	docs/tool-catalog.md
#	examples/acp-agent/tests/fixtures/live-mode-switching-2026-07-07.session.jsonl
#	examples/acp-agent/tests/snapshots/cordis-inspect-jsdoc/stdout.expected.jsonl
#	examples/acp-agent/tests/snapshots/permission-switching/session.jsonl
#	packages/goal/tool-goal/README.md
#	packages/ui/acp/README.md
#	packages/ui/acp/acp-feature-support.md
#	packages/ui/acp/src/index.ts
#	packages/ui/acp/tests/bridge.spec.ts
#	packages/ui/acp/tests/dispose.spec.ts
#	packages/ui/acp/tests/edges.spec.ts
#	packages/ui/acp/tests/turns.spec.ts
2026-07-24 23:43:10 +08:00
Tianyi Cui
e4553deced docs(i18n): re-record testing.md pair after merging master's bilingual split
The merge added the web-browser-snapshot bullet to both sides of the now
bilingual docs/testing.md; the pair record needs the post-merge hashes.
2026-07-24 23:13:03 +08:00
Chinesezjc
e532c9ccc2 ci: restore pnpm cache on the hosted leg only
Keep the cache restore for the ephemeral hosted (untrusted-PR) leg where
it is a genuine speedup, gated by the same expression as the runs-on
pool selector; the self-hosted leg skips it and installs from the
persistent local store.
2026-07-24 23:12:20 +08:00
Tianyi Cui
8a7472d11d Merge remote-tracking branch 'origin/master' into web-e2e-lane
# Conflicts:
#	docs/testing.md
2026-07-24 23:11:00 +08:00
Chinesezjc
62bfc6b4fb docs(gui): bring the todo tool note's Chinese side along
master gave 2026-06-29-todo-write-tool a Chinese counterpart; the English
side's web-consumer sentences now translate across (in-body links keep
their .md targets per the pairing contract) and the pair is re-recorded.
The todo-panel fake gains the time/callTime fields ToolResultNode now
requires.
2026-07-24 23:10:19 +08:00
Tianyi Cui
1e78054a78 ci: retrigger workflows (push event for 7a4cd7857 was dropped by Actions) 2026-07-24 23:04:57 +08:00
Chinesezjc
5818fd6224 ci: address second review round — dependabot lane, drop dead restore, update topology note
- Route untrusted PRs (forks + Dependabot, same author test as e2e.yml)
  back to the hosted enterprise pool via a runs-on expression: Dependabot
  PRs are same-repo, so the previous head.repo guard admitted
  dependency-supplied code onto the persistent self-hosted VM. A single
  job with pool selection keeps all-checks-passed free of skips.
- Drop the pnpm-store cache restore from this lane: on self-hosted the
  hosted-path cache actually HIT (Linux key) and spent ~52 s pulling
  181 MB into a path pnpm never reads; the persistent local store
  already serves warm installs in seconds.
- Update the larger-hosted-runners Agent Note (en/zh + i18n pairing
  record) so the decision record describes the shipped topology:
  coverage on the in-house vm-backup pool for trusted PRs, hosted
  Ubuntu 24.04 32-core retained for untrusted PRs.
2026-07-24 23:00:56 +08:00
Chinesezjc
729dd3e1b7 docs(agents): correct the web todo note to the shipped mechanisms
The projection sentence prescribed resetting todos on window rebuild —
the implementation deliberately preserves the tail-page seed and lets
only in-window/live writes overwrite. The toolview section named a
nonexistent ctx.toolviews registry — the shipped seam is the keyed
conversation.chat.toolview slot via ctx.slots.register. Both sides of
the bilingual pair re-recorded.
2026-07-24 22:56:12 +08:00
Chinesezjc
ba75229638 fix(tool-todo): declare the unknown-key rejection in the item schema
additionalProperties stays true in the published schema while execute
rejected extra keys, so generated typings and validation disagreed with
runtime behavior. The item schema now declares additionalProperties:
false — the registry's arg validation rejects extra keys with a
path-qualified violation before execute runs — and the redundant manual
check is dropped (tool catalog regenerated).
2026-07-24 22:56:12 +08:00
Chinesezjc
c1ae98940c fix(gui): gap repair adopts the repull response's todos projection
repairGap installed the repulled window without the response projection;
a todo/write missed during the gap and already outside the new tail page
kept the stale list. The spec pins adoption through the repair path.
2026-07-24 22:56:12 +08:00
Chinesezjc
beb191d87f fix(gui): admit todos in the history wire schema
sessionHistoryValueSchema declared only events/hasMore, so the fetch
carrier's Zod parse stripped the tail page's todos projection — the
in-process and fixture paths carried it while a real WebApiClient lost it.
The fetch-carrier spec pins the field through the wire round trip.
2026-07-24 22:56:12 +08:00
Chinesezjc
1687c2c15c fix(gui): tail history page carries the full-log todo projection
The client's todos projection derived only from the paged display window,
so reopening a session whose last todo/write preceded the tail page showed
an empty plan until the user paged back — session-level state cannot be
reconstructed from an arbitrary window. The host owns the full log, so the
tail history response now attaches todos (latest todo/write backscan, the
same posture as the view pairing); installWindow seeds it, window rebuilds
preserve it, and any in-window or live write keeps overwriting it. The
fixture mirrors the host; docs and both Agent Notes record the mechanism.
2026-07-24 22:56:12 +08:00
Chinesezjc
356be9710a docs(gui): record the window-scoped todos gap and the web consumer
runtime README documents ConversationSnapshot.todos and its window-scoped
limitation; the todo tool README and Agent Note name the web client among
the event consumers; the web display note records the cold-load gap and
fix directions (bilingual pair re-recorded).
2026-07-24 22:56:12 +08:00
Chinesezjc
3b1ad3ee6c test(gui): keyless assembled todo-display pass in the fixture smoke
Eight real bundles through the DI chain in ?fixture mode: plan strip
content, dedicated row summary + details linkage, collapse hint, zero page
errors — the CI-gated assembled-surface coverage for the todo display.
2026-07-24 22:56:12 +08:00
Chinesezjc
f2a9c09429 fix(gui): fixture emits todo/write at the real tool boundary
The tool appends the snapshot mid-execution, between tool/call and
tool/result; the fixture spliced it after step/end with a post-turn
timestamp, so acceptance never exercised the production ordering. A spec
pins call → snapshot → result with monotonic times.
2026-07-24 22:56:12 +08:00
Chinesezjc
02abe3c821 fix(gui): todo-row guards valid-JSON invalid-shape args before dereferencing
null roots, non-object roots, and null array items (retained verbatim on a
rejected tool/call) now take the documented generic-summary fallback instead
of throwing into the row error boundary.
2026-07-24 22:56:12 +08:00
Chinesezjc
2d95a60ac9 fix(tool-todo): reject unknown item keys instead of silently dropping them
An item carrying keys beyond content/status (ids, children, priority) was
flattened to {content, status} on append, so the logged snapshot diverged
from what the model believed it wrote (model-visible must equal logged).
Reject loudly; the isError result lets the model self-correct.
2026-07-24 22:56:12 +08:00
Chinesezjc
0a3c7f2b39 docs(agents): web todo display Agent Note — side-effect channel + two surfaces 2026-07-24 22:56:12 +08:00
Chinesezjc
de4f818c80 test(gui): todo display fixture sample + browser acceptance script
fx-alpha gains turn 63: a todo_write call/result pair plus the todo/write
snapshot event, feeding both the TodoRow toolview and the TodoPanel strip
in ?fixture mode. verify-todo-display.mjs drives chromium through panel
visibility, content, row summary, details linkage, collapse and dark.
2026-07-24 22:56:12 +08:00
Chinesezjc
63109dab66 feat(gui): todo display — TodoPanel plan strip + todo_write toolview row
TodoPanel pins above the composer (776px card axis), hidden while empty,
collapsible with the active item as the collapsed hint; status glyphs
mirror the TUI plan panel. todo_write rows render a plan-flavored summary
(counts + active item) via the toolview registry, generic fallback on
malformed args. Existing fake snapshots gain the required todos field.
2026-07-24 22:56:12 +08:00
Chinesezjc
a0c269b0fb feat(gui): fold todo/write into ConversationSnapshot.todos
Session consumes the todo/write session event as a per-event side effect
(last write wins), rebuilds it on window replay/paging/resync, and exposes
snapshot.todos. TodoItem re-exported through the runtime surface.
2026-07-24 22:55:17 +08:00
Tianyi Cui
d01474d1d0 Merge pull request #616 from deepseek-harness/worktree/acp-automation-review-fixes
fix(acp): review fixes for the automation-only reduction
2026-07-24 22:54:13 +08:00
Tianyi Cui
13345fdadc docs(i18n): re-record web e2e note pair after the scaffold rename
The rename commit edited both sides of the bilingual pair but missed the
re-record; the pairing gate compares blob hashes and went red.
2026-07-24 22:46:04 +08:00