Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,8 @@ When a plugin prevents startup or frontend rendering, the recovery path collects

Safe Mode is non-destructive: it starts an isolated official-core profile, keeps the Agent and user data available, and allows the user to remove selected third-party plugins before returning to the normal profile.

Whether a profile plugin loads has one authority: the package switch in `profiles/web/.dsh-market/state.json#disabled`, read and written through `dsh-desktop-market-installer/plugin-state`. Harness boot skips a switched-off package before resolving it, and dsh-market, the official Plugin Manager (through the `profileBundlePackageBackend` `switched`/`removed` hooks), the workbench page, Recovery and Safe Mode all record their toggles there. `dsh.profile.bundles` is derived composability: launch projection and bundle healing may re-list an installed bundle without re-enabling it, except that a plugin with a pending removal is never re-listed and stays switched off until its removal commits. Every uninstall path forgets the switch so a reinstall starts enabled. Package ownership is separate: the generation registry owns plugins installed as generations; pnpm owns the shared-tree market and Profile-owned packages, so the generation backend declines those and Plugin Manager falls back to pnpm. Installing a generation over a Profile-owned directory completes at the next launch projection, because a loaded directory cannot be replaced in place.

After interrupted migration/restore gates, startup establishes the enabled market's compatible shared-tree baseline before migrating ordinary plugins. A deferred migration therefore cannot skip this baseline. Market installation keeps `.desktop-market-install-pending.json` until pnpm succeeds and the active package is verified; a partial install forces a retry even when its package version already looks current. The marker preserves the first pre-install manifest for diagnosis. Restoring that manifest on failure is not a rollback of the entire dependency tree.

For reused or deferred legacy trees, startup reads bundle manifests and YAML layers through Harness's own profile loader before launching. A bundle that is declared but no longer installed has its declaration removed once and the check retried, since disabling a plugin writes a patch row and cannot clear a manifest-level fault; this removes third-party declarations only, never core bundles, package files, user patch rows or plugin data. Inputs that are still invalid enter Safe Mode with plugin repair controls enabled, and the failing bundle is listed there. An incomplete migration/restore transaction still locks those controls; a newly rebuilt tree retains the existing real-launch/rollback verification. This preflight does not execute plugin code or prove successful activation. The native recovery manager is also opened if the recovery Harness fails, since shared settings can still affect both profiles.
Expand Down
2 changes: 1 addition & 1 deletion docs/development.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ This guide covers local development, validation, patch maintenance, and target-n
- npm
- macOS on Apple Silicon or Intel, or Windows x64

This baseline pins `@deepseek-ai/dsh@0.1.7-rc.2`. Windows packages bundle a target-native Node.js runtime for Harness, while macOS uses an Electron UtilityProcess. Both are independent of the Node.js version used to run development commands.
This baseline pins `@deepseek-ai/dsh@0.2.0-rc.2`. Windows packages bundle a target-native Node.js runtime for Harness, while macOS uses an Electron UtilityProcess. Both are independent of the Node.js version used to run development commands.

## Local setup

Expand Down
20 changes: 20 additions & 0 deletions docs/harness-0.2.0-rc.2-upgrade.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# Harness 0.2.0-rc.2 升级记录

仓库内所有 `@deepseek-ai/dsh-*` 依赖从 `0.1.7-rc.2` 固定到 `0.2.0-rc.2`。上游 `@deepseek-ai/dsh` 的依赖集只新增了 `dsh-experimental-schedule-bundle`,Cordis 系包版本不变。仓库内插件和 PPT 运行时的 dsh peer 区间追加 `^0.2.0-rc.1`。

## 补丁处理

- 13 个 dsh 补丁(另有 `cordis-plugin-loader`、`undici` 两个)可原样重放,只改文件名。
- 11 个补丁上下文失效,采用三方合并迁移:以旧版原始包为基准,把旧补丁的改动合入新版原始包,再用 `patch-package` 重新生成。`@deepseek-ai/dsh` 补丁要修改 `package.json`,需用 `--exclude '^$'` 覆盖默认排除规则。
- 需要人工处理的冲突:
- `dsh-client-ui-agent-preset`:上游移除了 `AgentPresetSection` 的 `useDeveloperTools`,导入/导出/搜索逻辑照旧追加。
- `dsh-client-ui-chat`:上游让 Desktop 默认使用 `standard` 记录视图,`openUploadedAttachment` 提供者接在新的构造之后。
- `dsh-client-ui-settings-models`:上游在编辑器提交时新增 `onSubmitCredential`,同步写入 Desktop 的 `footerProps`。
- `dsh-client-ui-workspace` 类型:采用上游新的 `forkSession(sessionId, onCreated?) => Promise<SessionId>` 签名,保留 Desktop 的 `deleteSession` 及注册接口。
- 删除 `dsh-client-ui-model-selection` 补丁及其测试:上游 0.2.0 已原生提供模型搜索(超过 4 个模型时显示,按名称排序,带清除按钮)。与旧补丁的区别:搜索不再匹配服务商名称,模型少于 5 个时不显示搜索框。

## 验证边界

已执行:全新 `npm ci` 重放 26 个补丁、`npm run typecheck`、`npm run ppt:build` 后完整 `vitest`(170 个文件、1539 个用例)、`npm run build`、`scripts/verify-harness-auth.mjs`。macOS 开发构建使用临时 userData 启动:Harness 就绪,客户端完成挂载,Agent 预设页的导入、Awesome preset 和搜索可用,模型选择器可以打开。

未执行:Windows 验证、安装包打包与安装、Safe Mode 真机启动、自定义预设导出、超过 4 个模型时的搜索交互,以及市场插件在 0.2.0 下的兼容性(启动时多个已安装市场插件报告 peer 区间不含 0.2.0-rc.2 的兼容性警告,但未阻止启动)。
Loading
Loading