Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
@deepseek-ai/dsh-jsonrpc-demo
English | 中文
Bin-only app that boots an external cordis.yml; its jsonrpc entry serves SDK clients over newline-delimited stdio. The config composes the spine, backends, and serving plugin. The published bin is dsh-jsonrpc-agent, and lib/bin.js also ships as the dsh-jsonrpc-agent-pkg single-executable runtime used by the Python SDK.
Config discovery
The first non-empty channel wins: $DSH_CORDIS_CONFIG, then positional argv[2]. If neither names an existing file, the bin prints one-line usage to stderr and exits 1; there is no working-directory or built-in fallback. dsh-app-boot makes plugin load failures fatal. This protocol does not use DSH_SNAPSHOT.
A config without dsh-jsonrpc is valid and serves nothing; the bin does not designate a server plugin.
Exit lifecycle
stdin EOF and SIGTERM dispose the root to quiescence and exit 0; SIGINT exits 130 after the same disposal. EOF may cut off an in-flight turn as documented in the distribution Agent Note. The jsonrpc plugin owns response-before-exit protocol shutdown; both paths are idempotent and safe to race.
stdout is the protocol
stdout carries only JSON-RPC frames. The bin and boot guards diagnose on stderr, and the config must omit stdout loggers.
Model Experience
Indirectly, through the plugins loaded from the external cordis.yml, which own every model-bound prompt, schema, message, and result; this bin adds none of its own.
KV Cache effect
No direct invalidation; the named consumer owns any request-prefix changes.
Known Limitations and Deferred Work
- The bin cannot prove that the config serves JSON-RPC — a valid config with no
dsh-jsonrpcentry boots successfully and serves nothing. - No built-in or default config exists — every launch must provide
DSH_CORDIS_CONFIGor a positional path, and deployment owns the complete plugin tree and stdout discipline. - stdin EOF cuts off in-flight work — client disappearance disposes the root immediately; callers that need orderly completion use the protocol-level
shutdownrequest.