gen-doc-graphs.ts 72 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623
  1. /**
  2. * Generate the relationship layer above the module, Cordis, and tool catalogs.
  3. * Enumerable facts come from source; hybrid graphs add manifests for policy the
  4. * source cannot infer, while curated graphs explain flow and ownership.
  5. * `--check` verifies the generated set.
  6. */
  7. import { existsSync, mkdirSync, readFileSync, writeFileSync } from 'node:fs'
  8. import { dirname, relative, resolve } from 'node:path'
  9. import ts from 'typescript'
  10. import { projectCordisCatalog } from '@deepseek-ai/dsh-typert-generator'
  11. import { CORDIS_CATALOG_POLICY } from './gen-cordis-catalog.ts'
  12. import type { EventEntry, ServiceEntry } from '@deepseek-ai/dsh-typert-generator'
  13. import {
  14. collectPackageGraph,
  15. escapeMermaidLabel as escLabel,
  16. graphNodeId as nodeId,
  17. type PackageGraphNode,
  18. } from './package-graph.ts'
  19. import { TypeScriptProject } from './ts-project.ts'
  20. const root = resolve(import.meta.dirname, '..')
  21. type Pkg = PackageGraphNode
  22. interface GraphDoc {
  23. rel: string
  24. content: string
  25. }
  26. interface ServiceRole {
  27. key: string
  28. pkg: string
  29. title: string
  30. mode: 'core' | 'seam' | 'bundle'
  31. implementations?: string[]
  32. consumers?: string[]
  33. companions?: string[]
  34. note: string
  35. }
  36. interface ExamplePlugin {
  37. id: string
  38. name: string
  39. }
  40. interface EventRelation {
  41. dispatchers: Map<string, Set<string>>
  42. listeners: Set<string>
  43. }
  44. /** One scanned package source file and its owning package short name. */
  45. export interface PackageSource {
  46. /** Repository-relative path. */
  47. rel: string
  48. /** Package short name from the `packages/<group>/<pkg>/src` path. */
  49. pkg: string
  50. /** The bound program source file. */
  51. sourceFile: ts.SourceFile
  52. }
  53. type EventReceiverKind = 'context' | 'agent-dispatch' | 'events-service'
  54. const GROUP_ORDER = [
  55. 'util',
  56. 'attachment',
  57. 'document',
  58. 'llm',
  59. 'core',
  60. 'typert',
  61. 'goal',
  62. 'experimental',
  63. 'process',
  64. 'bash',
  65. 'pty',
  66. 'sandbox',
  67. 'ssh',
  68. 'fs',
  69. 'skill',
  70. 'compact',
  71. 'subagent',
  72. 'tasks',
  73. 'workflow',
  74. 'web',
  75. 'webhook',
  76. 'spill',
  77. 'todo',
  78. 'plan',
  79. 'cordis',
  80. 'hooks',
  81. 'session-persistence',
  82. 'session-query',
  83. 'session-title',
  84. 'telemetry',
  85. 'storage',
  86. 'workspace',
  87. 'support',
  88. 'acp',
  89. 'ui',
  90. ]
  91. const SERVICE_ROLES: ServiceRole[] = [
  92. {
  93. key: 'hmr',
  94. pkg: 'hmr',
  95. title: 'Serialized module and configuration reloads',
  96. mode: 'core',
  97. consumers: ['app-boot'],
  98. note: 'Owns module and exact configuration watchers; application mutations share its queue and automatic reloads await the application file lock.',
  99. },
  100. {
  101. key: 'pluginManager',
  102. pkg: 'plugin-manager',
  103. title: 'Current-profile plugin and bundle management',
  104. mode: 'core',
  105. consumers: ['plugin-manager', 'ui-settings-plugin-inventory'],
  106. note: 'Shares profile package operations with the CLI and reports persisted and running state to Web and agent callers.',
  107. },
  108. {
  109. key: 'profileContext',
  110. pkg: 'app-boot',
  111. title: 'Launcher-owned profile data',
  112. mode: 'core',
  113. consumers: ['plugin-manager'],
  114. note: 'The dsh launcher supplies data-only profile locations and composition inputs; reload scheduling belongs to dsh-hmr.',
  115. },
  116. {
  117. key: 'mcpResources',
  118. pkg: 'mcp-resources',
  119. title: 'Scoped MCP resource access',
  120. mode: 'seam',
  121. implementations: ['mcp-client'],
  122. consumers: ['mcp-resources'],
  123. note: 'Connection-owned providers serve shared resource tools in the calling agent scope.',
  124. },
  125. {
  126. key: 'browserUse',
  127. pkg: 'browser-use',
  128. title: 'Browser-use provider registration',
  129. mode: 'seam',
  130. implementations: ['experimental-browser-use-playwright-mcp', 'experimental-browser-use-chrome-devtools-mcp', 'experimental-browser-use-stagehand-native'],
  131. consumers: ['experimental-browser-use-playwright-mcp', 'experimental-browser-use-chrome-devtools-mcp', 'experimental-browser-use-stagehand-native'],
  132. note: 'One provider-owned name per service instance. Providers own their tools and browser resources per live Session; the shared service has no browser operation API.',
  133. },
  134. {
  135. key: 'computerUse',
  136. pkg: 'computer-use',
  137. title: 'Computer-use provider registration',
  138. mode: 'seam',
  139. implementations: ['experimental-computer-use-cua-driver-mcp', 'experimental-computer-use-cua-driver-native'],
  140. consumers: ['experimental-computer-use-cua-driver-mcp', 'experimental-computer-use-cua-driver-native'],
  141. note: 'One provider-owned name per service instance. Each provider also owns its model tools; the service has no common action API, runtime selection, or Session workflow lock.',
  142. },
  143. {
  144. key: 'officeToPdf', pkg: 'office-to-pdf', title: 'Office to PDF conversion',
  145. mode: 'core', consumers: ['client-ui-sidebar-documentpreview'],
  146. note: 'Authorized Office bytes are converted on the Host using the declared native target engine, or Node WASM when no native target is declared.',
  147. },
  148. {
  149. key: 'attachments',
  150. pkg: 'attachment',
  151. title: 'Durable binary attachment storage',
  152. mode: 'seam',
  153. implementations: ['attachment-local'],
  154. consumers: ['api-session-controller', 'tool-fs', 'llm-pi-ai', 'llm-deepseek'],
  155. note: 'The host commits accepted images before session events; provider adapters resolve authorized durable references into provider-native content.',
  156. },
  157. {
  158. key: 'fileUploads',
  159. pkg: 'client-file-upload',
  160. title: 'Agent-scoped staged file uploads',
  161. mode: 'core',
  162. consumers: ['api-session-controller'],
  163. note: 'Owns streaming intake, durable storage, and staged receipt lifetime; the Session controller binds receipts to accepted submissions.',
  164. },
  165. {
  166. key: 'llm',
  167. pkg: 'llm',
  168. title: 'LLM adapter registry',
  169. mode: 'seam',
  170. implementations: ['llm-deepseek', 'llm-pi-ai', 'llm-replay'],
  171. consumers: ['agent-loop', 'compaction-basic'],
  172. note: 'Adapters register provider implementations; the loop and compaction call the provider-neutral stream service.',
  173. },
  174. {
  175. key: 'deepseekLlmApiExtensions',
  176. pkg: 'deepseek-llm-api-extensions',
  177. title: 'Official DeepSeek request extensions',
  178. mode: 'seam',
  179. implementations: ['session-log-deepseek', 'plugin-package-inventory-deepseek'],
  180. consumers: ['llm-deepseek'],
  181. note: 'Plugins prepare independent top-level fields; the official adapter merges them and commits their delivery state after HTTP acceptance.',
  182. },
  183. {
  184. key: 'tokenMeter',
  185. pkg: 'token-meter',
  186. title: 'Replay token measurement',
  187. mode: 'core',
  188. consumers: ['compaction-basic'],
  189. note: 'Owns isolated per-session replay folds; pressure consumers share immutable revisioned measurements.',
  190. },
  191. {
  192. key: 'toolResultPruner',
  193. pkg: 'compaction-tool-result-pruner',
  194. title: 'Model-free tool-result pruning',
  195. mode: 'core',
  196. consumers: ['compaction-basic'],
  197. note: 'Rewrites oversized current tool results through replayable single-node surface replacements before summary compaction.',
  198. },
  199. {
  200. key: 'sessions',
  201. pkg: 'session',
  202. title: 'In-memory session store',
  203. mode: 'core',
  204. consumers: ['agent-loop', 'agent', 'session-persistence', 'session-query', 'session-query-sqlite', 'subagent-in-process-driver', 'invariants', 'message-feedback'],
  205. note: 'Owns append-only Session instances and emits the durable session event feed.',
  206. },
  207. {
  208. key: 'sessionController',
  209. pkg: 'api-session-controller',
  210. title: 'Host Session Remote controller',
  211. mode: 'core',
  212. note: 'Owns Session commands, cold reads, durable-event following, live control state, model catalogs, workspace opening, and Agent activation policy.',
  213. },
  214. {
  215. key: 'sessionFileReferences',
  216. pkg: 'api-session-controller',
  217. title: 'Session-addressed file-reference Remote adapter',
  218. mode: 'core',
  219. note: 'Delegates file-reference discovery through the Session Controller\'s established Agent lookup policy.',
  220. },
  221. {
  222. key: 'sessionSkillCatalog',
  223. pkg: 'api-session-controller',
  224. title: 'Session-addressed skill Remote adapter',
  225. mode: 'core',
  226. note: 'Lists the Session composition\'s user-invocable skills without activating a cold Agent.',
  227. },
  228. {
  229. key: 'credentialsController',
  230. pkg: 'api-settings-controller',
  231. title: 'Host credential-surface Remote controller',
  232. mode: 'core',
  233. note: 'Projects the credential-reference seam onto the generated Remote namespace: batch fan-out, view projection, and refusal mapping live here, not on the seam Definition.',
  234. },
  235. {
  236. key: 'settingsController',
  237. pkg: 'api-settings-controller',
  238. title: 'Host settings-surface Remote controller',
  239. mode: 'core',
  240. note: 'Projects the user-settings seam onto the generated Remote namespace: the read is always redacted and every refusal is classified here, not on the seam Definition.',
  241. },
  242. {
  243. key: 'workspaceFiles',
  244. pkg: 'api-workspace-files',
  245. title: 'Host workspace file Remote service',
  246. mode: 'core',
  247. note: 'Serves stat, paged text, byte windows, directory listings, and the change feed for files inside a Session\'s workspace root, confined by lstat, containment, and a stat re-check.',
  248. },
  249. {
  250. key: 'workspaceChanges',
  251. pkg: 'workspace-changes',
  252. title: 'Host per-turn changed-file summaries',
  253. mode: 'core',
  254. note: 'Serves the summary each workspace/changes event announced and each listed file\'s turn-start and turn-end comparison, by Session and event sequence, until that Session is disposed; the log carries only the turn.',
  255. },
  256. {
  257. key: 'terminalController',
  258. pkg: 'api-terminal-controller',
  259. title: 'Session interactive terminal Remote controller',
  260. mode: 'core',
  261. note: 'Owns user terminal processes, default shell resolution and bounded screen recovery through the subprocess provider and typed Remote transport.',
  262. },
  263. {
  264. key: 'workspaceController',
  265. pkg: 'api-workspace-controller',
  266. title: 'Host Workspace Remote controller',
  267. mode: 'core',
  268. note: 'Owns Workspace commands and reconnect-safe Workspace state delivery through the generated Remote namespace.',
  269. },
  270. {
  271. key: 'directoryPickerController',
  272. pkg: 'api-workspace-controller',
  273. title: 'Host directory-picking Remote controller',
  274. mode: 'core',
  275. note: 'Carries the picking seam onto the wire: capability gating, cancellation, and the seam-coded failures a browser directory flow discriminates on.',
  276. },
  277. {
  278. key: 'invariants',
  279. pkg: 'invariants',
  280. title: 'Package-owned invariant registry',
  281. mode: 'core',
  282. consumers: ['session', 'agent', 'scope', 'agent-loop'],
  283. note: 'Companion subpaths register owner-local checks; the service owns selection, uniqueness, child fibers, and package-attributed failures.',
  284. },
  285. {
  286. key: 'typert',
  287. pkg: 'typert-registry',
  288. title: 'Runtime type registry',
  289. mode: 'core',
  290. consumers: ['typert-loader', 'api-gateway'],
  291. note: 'Plugins register live zod contributions directly or through dsh-typert-loader; the API gateway consumes invocation descriptors and providers, while other runtime consumers query schemas and reflection metadata at their own edges.',
  292. },
  293. {
  294. key: 'typertGateway',
  295. pkg: 'api-gateway',
  296. title: 'Typert Host invocation gateway',
  297. mode: 'core',
  298. note: 'Associates generated Remote descriptors with live Cordis services, resolves registered identities, and exposes unary calls through the shared Connection RPC carrier.',
  299. },
  300. {
  301. key: 'sessionPersistence',
  302. pkg: 'session-persistence',
  303. title: 'Durable session persistence seam',
  304. mode: 'seam',
  305. implementations: ['session-persistence-jsonl'],
  306. consumers: ['agent-loop', 'tool-bash', 'hooks-claude-code', 'hooks-codex', 'session-query', 'session-query-sqlite', 'message-feedback'],
  307. note: 'The JSONL backend persists the SessionEvent vocabulary as one artifact per Session.',
  308. },
  309. {
  310. key: 'settings',
  311. pkg: 'settings',
  312. title: 'User-settings seam',
  313. mode: 'seam',
  314. implementations: ['settings-file'],
  315. consumers: ['api-settings-controller', 'llm-deepseek', 'llm-pi-ai'],
  316. note: 'Plugins register namespace schemas and resolve layered values; providers store the raw document. The LLM adapters register their entry config as the composition base under the user section; the settings controller serves redacted layered descriptors and writes the user layer.',
  317. },
  318. {
  319. key: 'subagentModelSelection',
  320. pkg: 'tool-subagent',
  321. title: 'Subagent model-selection preference',
  322. mode: 'core',
  323. consumers: ['tool-subagent'],
  324. note: 'Owns the default-off settings namespace that Agent-scoped delegation tools sample when composing a new top-level Session.',
  325. },
  326. {
  327. key: 'credentials',
  328. pkg: 'credentials',
  329. title: 'Credential seam',
  330. mode: 'seam',
  331. implementations: ['credentials-local'],
  332. consumers: ['api-settings-controller', 'llm-deepseek', 'llm-pi-ai'],
  333. note: 'Configuration carries references to secrets; providers own the values. Consumers resolve per operation, so a rotated credential reaches the very next request; the settings controller exposes value-free views and write-only storage.',
  334. },
  335. {
  336. key: 'authorization',
  337. pkg: 'authorization',
  338. title: 'Authorization flow registry',
  339. mode: 'seam',
  340. implementations: [],
  341. consumers: ['llm-pi-ai'],
  342. note: 'Flows are registered by the plugin that knows how to obtain one credential and keyed by the record they write; the seam owns the conversation and the one-attempt-per-key lifecycle, never the protocol.',
  343. },
  344. {
  345. key: 'sessionTelemetry',
  346. pkg: 'session-telemetry',
  347. title: 'Session telemetry seam',
  348. mode: 'seam',
  349. implementations: ['session-telemetry-otel'],
  350. consumers: [],
  351. note: 'The seam captures, redacts, and hands session records to one backend; nothing else consumes the service — its output leaves the process.',
  352. },
  353. {
  354. key: 'storage',
  355. pkg: 'storage',
  356. title: 'Non-session storage hub',
  357. mode: 'seam',
  358. implementations: ['storage-json', 'storage-sqlite'],
  359. consumers: ['storage-domain'],
  360. note: 'Backends register side by side under names; data forms (domain first) mount on the hub and translate typed operations into opaque KV-unit primitives.',
  361. },
  362. {
  363. key: 'storageDomain',
  364. pkg: 'storage-domain',
  365. title: 'Domain data facility',
  366. mode: 'core',
  367. consumers: ['workspace'],
  368. note: 'Waits for every configured backend, then publishes the domain form as one lifecycle-bound service for typed durable state.',
  369. },
  370. {
  371. key: 'messageFeedback',
  372. pkg: 'message-feedback',
  373. title: 'Lifecycle-bound message feedback',
  374. mode: 'core',
  375. note: 'Owns per-assistant-message feedback in the canonical Session log, target validation, per-item compare-and-set, and the Host unary Remote contract. Feedback stays outside model history; log export follows the consumer policy.',
  376. },
  377. {
  378. key: 'sessionFeedback',
  379. pkg: 'command-feedback',
  380. title: 'Session-level feedback recorder',
  381. mode: 'core',
  382. note: 'Records one Session-level remark with its category as a log-only feedback/record event on a live Session through the Host unary Remote contract; the /feedback command shares the same producer.',
  383. },
  384. {
  385. key: 'workspaceRegistry',
  386. pkg: 'workspace',
  387. title: 'Workspace entity registry',
  388. mode: 'core',
  389. consumers: ['api-workspace-controller', 'api-session-controller'],
  390. note: 'Owns WorkspaceId-branded records over the domain facility; stable sessionIds accounts drive Host RPC and GUI projections.',
  391. },
  392. {
  393. key: 'sessionQuery',
  394. pkg: 'session-query',
  395. title: 'Session reads, traces, filters, and search',
  396. mode: 'seam',
  397. implementations: ['session-query-sqlite'],
  398. consumers: ['session-reference', 'tool-session-query'],
  399. note: 'The interface supplies exact reads, filters, and traces; its concrete backend adds full-text reconciliation, ranking, snippets, and cursor generations, while the model consumer owns workspace authority and cursor-free rendering.',
  400. },
  401. {
  402. key: 'fileReferences',
  403. pkg: 'file-reference',
  404. title: 'File reference discovery',
  405. mode: 'seam',
  406. implementations: ['file-reference-local'],
  407. consumers: ['api-session-controller'],
  408. note: 'The interface returns path-only completion candidates within an Agent cwd; providers own namespace access and ranking without reading file contents.',
  409. },
  410. {
  411. key: 'sessionReferenceResolver',
  412. pkg: 'session-reference',
  413. title: 'Cross-session snapshot preparation',
  414. mode: 'core',
  415. note: 'Projects bounded current-surface conversation snapshots into durable untrusted message context; host adapters own mention syntax.',
  416. },
  417. {
  418. key: 'sessionTitle',
  419. pkg: 'session-title',
  420. title: 'Log-backed session titles',
  421. mode: 'seam',
  422. implementations: ['session-title-first-prompt-llm', 'session-title-all-prompts-llm'],
  423. note: 'Owns the deterministic fallback, latest-title fold, and sole optional asynchronous provider registration.',
  424. },
  425. {
  426. key: 'systemPrompt',
  427. pkg: 'system-prompt',
  428. title: 'System prompt assembly registry',
  429. mode: 'core',
  430. consumers: ['agent-loop', 'tools', 'tool-fs', 'tool-terminal', 'tool-web'],
  431. note: 'Collects prompt sections and model-facing tool schemas for each step.',
  432. },
  433. {
  434. key: 'tools',
  435. pkg: 'tools',
  436. title: 'Tool registry and guarded execution pipeline',
  437. mode: 'core',
  438. consumers: ['agent-loop', 'tool-ask-user', 'tool-bash', 'tool-cordis', 'tool-fs', 'tool-terminal', 'tool-skill', 'tool-subagent', 'tool-todo', 'tool-web'],
  439. note: 'Registers capabilities, owns PTC mode transport, and routes calls through pre-policy, monotonic guards, around dispatch, post-policy, and final-result observation.',
  440. },
  441. {
  442. key: 'userQuestions',
  443. pkg: 'user-questions',
  444. title: 'Human question/answer seam',
  445. mode: 'seam',
  446. consumers: ['tool-ask-user'],
  447. note: 'UI front ends provide the active human-answer provider; tool-ask-user pauses a tool call on the provider-neutral ask() promise.',
  448. },
  449. {
  450. key: 'planMode',
  451. pkg: 'plan-mode',
  452. title: 'Plan collaboration state',
  453. mode: 'core',
  454. note: 'Folds logged plan/mode state, flushes user selections at turn boundaries, renders deployment-owned guidance, registers /plan, and keeps the plan-exit schema stable across transitions.',
  455. },
  456. {
  457. key: 'agentPresets',
  458. pkg: 'agent-presets',
  459. title: 'Per-session agent composition',
  460. mode: 'core',
  461. note: 'Discovers preset directories over trusted and user-authored roots and mounts one preset cordis.yml under an agent scope during creation, rejecting a row that never activates or that publishes into the root service realm.',
  462. },
  463. {
  464. key: 'commands',
  465. pkg: 'commands',
  466. title: 'Human command registry',
  467. mode: 'core',
  468. note: 'Plugins register direct human commands without sending invocations to the model.',
  469. },
  470. {
  471. key: 'sessionProjections',
  472. pkg: 'session-projection',
  473. title: 'Session projection units',
  474. mode: 'core',
  475. consumers: ['api-session-controller', 'tool-todo', 'session-title'],
  476. note: 'Domains register state-driven fold units; the eager drive keeps per-session watermark states and the Session controller serves baselines and pushes changed values.',
  477. },
  478. {
  479. key: 'sessionProjectionCache',
  480. pkg: 'session-projection-cache',
  481. title: 'Persisted projection cache',
  482. mode: 'core',
  483. consumers: ['api-session-controller', 'session-query', 'session-reference', 'subagent'],
  484. note: 'Durably checkpoints projection unit states per session (throttled + turn/end/detach mandatory points) and serves the cold-read ladder: cache row + persistence tail replay, so listings never load full logs.',
  485. },
  486. {
  487. key: 'skills',
  488. pkg: 'skill',
  489. title: 'Skill provider registry',
  490. mode: 'seam',
  491. implementations: ['skill-badge', 'skill-filesystem', 'skill-office'],
  492. consumers: ['tool-skill'],
  493. note: 'Merges provider skill catalogs; tool-skill renders the session-prefix catalog and loads complete skill bodies.',
  494. },
  495. {
  496. key: 'agents',
  497. pkg: 'agent',
  498. title: 'Agent service',
  499. mode: 'core',
  500. consumers: ['agent-loop', 'acp', 'subagent-in-process-driver'],
  501. note: 'Owns live Agent handles, the create/resume factory seam, and process-local initiator propagation.',
  502. },
  503. {
  504. key: 'agentDefaultModel',
  505. pkg: 'agent-default-model',
  506. title: 'Default Agent model selection',
  507. mode: 'core',
  508. consumers: ['api-session-controller', 'headless'],
  509. note: 'Layers the default ModelSelection through settings so direct and Host-backed Agent entry points share one state owner.',
  510. },
  511. {
  512. key: 'agentLoop',
  513. pkg: 'agent-loop',
  514. title: 'Concrete loop driver',
  515. mode: 'bundle',
  516. consumers: ['base', 'sdk-minimal'],
  517. note: 'The one concrete loop plugin; extension packages depend on dsh-agent events and services, not on this package.',
  518. },
  519. {
  520. key: 'goals',
  521. pkg: 'goal',
  522. title: 'Same-session goal domain',
  523. mode: 'core',
  524. note: 'Folds revisioned objective state from the session log and keeps live continuation activation process-local.',
  525. },
  526. {
  527. key: 'ssh',
  528. pkg: 'ssh',
  529. title: 'POSIX SSH connection owner',
  530. mode: 'core',
  531. consumers: ['fs-ssh', 'subprocess-ssh', 'sandbox-ssh'],
  532. note: 'Owns one authenticated OpenSSH connection, installed helper identity, independent program streams and disconnect cleanup for the paired remote providers.',
  533. },
  534. {
  535. key: 'subprocess',
  536. pkg: 'subprocess',
  537. title: 'Subprocess seam',
  538. mode: 'seam',
  539. implementations: ['subprocess-local', 'subprocess-ssh'],
  540. consumers: ['bash-local', 'bash-sandbox', 'terminal-bash', 'lsp-stdio', 'subagent-acp', 'subagent-codex', 'subagent-claude-code'],
  541. note: 'The bash executors, the PTY shell backend, the LSP host, and the out-of-process ACP, Codex, and Claude Code subagent backends spawn through ctx.subprocess; the service owns process coordinates, tree/session lifetime, stdio dispositions, terminal mechanics, and kill escalation.',
  542. },
  543. {
  544. key: 'shell',
  545. pkg: 'shell',
  546. title: 'Bash executor seam',
  547. mode: 'seam',
  548. implementations: ['bash-local', 'bash-sandbox', 'pwsh-local'],
  549. consumers: ['tool-bash', 'tool-pwsh', 'hooks-claude-code', 'hooks-codex'],
  550. note: 'The model-facing shell tools and hook bridges consume this seam; sandboxed, remote, or PowerShell executors replace bash-local without touching them.',
  551. },
  552. {
  553. key: 'shellEnv',
  554. pkg: 'shell-env',
  555. title: 'Managed bash environment registry',
  556. mode: 'core',
  557. consumers: ['tool-bash', 'tool-pwsh'],
  558. note: 'Plugins declare effect-scoped DSH_* facts; each shell tool collects one trusted snapshot per execution and its executor rebuilds the namespace.',
  559. },
  560. {
  561. key: 'terminals',
  562. pkg: 'terminal',
  563. title: 'Persistent PTY session registry',
  564. mode: 'seam',
  565. implementations: ['terminal-bash'],
  566. consumers: ['tool-terminal'],
  567. note: 'The registry owns exact-Agent session identity and cleanup; backends own terminal mechanics, while tool-terminal exposes the owner-scoped model tools.',
  568. },
  569. {
  570. key: 'sandbox',
  571. pkg: 'sandbox',
  572. title: 'Process-sandbox seam',
  573. mode: 'seam',
  574. implementations: ['sandbox-local', 'sandbox-ssh'],
  575. consumers: ['bash-sandbox', 'terminal-bash'],
  576. note: 'Consumers hand over the exact argv they are about to spawn; same-world backends wrap it under a per-call policy and report enforcement.',
  577. },
  578. {
  579. key: 'sandboxPolicy',
  580. pkg: 'sandbox-policy',
  581. title: 'Sandbox policy home',
  582. mode: 'core',
  583. implementations: [],
  584. consumers: ['bash-sandbox', 'fs-sandbox', 'terminal-bash'],
  585. note: 'The one home for the deployment default mode + workspace root; only the sandboxed executor and provider read the service (the tool layers use the pure `sandbox/mode` fold it also exports). Both enforcing families read it so bash and fs cannot confine to different roots.',
  586. },
  587. {
  588. key: 'approval',
  589. pkg: 'user-approval',
  590. title: 'Approval seam',
  591. mode: 'seam',
  592. implementations: [],
  593. consumers: ['tools', 'tool-bash', 'acp'],
  594. note: 'One-shot permission decisions dispatched over the `approval/request` waterfall; answerers are listeners (the ACP bridge for its own agents), absence fails closed to `unavailable`.',
  595. },
  596. {
  597. key: 'permissionPresets',
  598. pkg: 'permission-presets',
  599. title: 'Permission presets',
  600. mode: 'core',
  601. implementations: [],
  602. note: 'User-facing preset table (`workspace-write`/`danger-full-access`) bundling the sandbox-mode and approval-policy knobs; a switch writes one `permission/preset` event through to both knob events.',
  603. },
  604. {
  605. key: 'ptcRuntime',
  606. pkg: 'ptc-runtime',
  607. title: 'PTC execution seam',
  608. mode: 'seam',
  609. implementations: ['ptc-runtime-node', 'experimental-ptc-runtime-python'],
  610. consumers: ['tools', 'workflow-ptc'],
  611. note: 'Runs programs against host-provided async bindings; tools owns PTC presentation and workflow-ptc owns workflow orchestration.',
  612. },
  613. {
  614. key: 'fs',
  615. pkg: 'fs',
  616. title: 'Filesystem provider seam',
  617. mode: 'seam',
  618. implementations: ['fs-local', 'fs-sandbox', 'fs-ssh'],
  619. consumers: ['tool-fs'],
  620. companions: ['fs-observation-policy'],
  621. note: 'tool-fs executes read/write/edit through ctx.fs; fs-sandbox fences mutations by the shared sandbox mode; fs-observation-policy contributes observed-state checks through the fs/* event gate.',
  622. },
  623. {
  624. key: 'compaction',
  625. pkg: 'compaction',
  626. title: 'Compaction seam',
  627. mode: 'seam',
  628. implementations: ['compaction-basic'],
  629. consumers: ['compaction-basic'],
  630. note: 'The basic backend consumes post-step pressure and request-error recovery events; there is no model-facing compact tool.',
  631. },
  632. {
  633. key: 'subagents',
  634. pkg: 'subagent',
  635. title: 'Subagent provider and continuation service',
  636. mode: 'seam',
  637. implementations: ['subagent-spawn-in-process', 'subagent-fork-in-process', 'subagent-acp', 'subagent-codex', 'subagent-claude-code', 'subagent-dsh-sdk'],
  638. consumers: ['tool-subagent', 'tool-subagent-control', 'tool-ralph'],
  639. note: 'Providers implement transports; the service also owns optional Activation-based continuation orchestration, tool-subagent selects one-shot or continuable delegation, tool-subagent-control delivers follow-ups, and tool-ralph requires one fresh structured-output route.',
  640. },
  641. {
  642. key: 'agentTeams',
  643. pkg: 'experimental-agent-team',
  644. title: 'Agent Teams coordination domain',
  645. mode: 'core',
  646. consumers: ['experimental-tool-agent-team', 'experimental-client-ui-agent-team'],
  647. note: 'Owns the implicit-root roster, durable peer mailbox, shared task DAG, continuable-child lifecycle, and generated Team Remote methods; tool-agent-team contributes model controls and client-ui-agent-team mounts the browser contribution.',
  648. },
  649. {
  650. key: 'inspector',
  651. pkg: 'inspector',
  652. title: 'Cross-realm runtime inspection',
  653. mode: 'core',
  654. note: 'Owns the Worker-hosted CDP target and the transport-independent Host and Client observation and Cordis-tree query API.',
  655. },
  656. {
  657. key: 'jobs',
  658. pkg: 'jobs',
  659. title: 'Background job registry',
  660. mode: 'seam',
  661. implementations: ['jobs-local'],
  662. consumers: ['tool-bash', 'tool-terminal', 'tool-subagent', 'tool-jobs'],
  663. note: 'Producers (background bash, PTY sends, and subagent delegations) register running work; tool-jobs is the model-facing controller that reads, lists, and kills it; jobs-local is the process-local registry.',
  664. },
  665. {
  666. key: 'web',
  667. pkg: 'web',
  668. title: 'Web access provider registry',
  669. mode: 'seam',
  670. implementations: ['web-search-exa', 'web-search-perplexity', 'web-search-deepseek', 'web-fetch-http'],
  671. consumers: ['tool-web'],
  672. note: 'Search and fetch providers register into one ctx.web seam; tool-web owns the stable model-facing names.',
  673. },
  674. {
  675. key: 'spillStore',
  676. pkg: 'spill',
  677. title: 'Spill storage seam',
  678. mode: 'seam',
  679. implementations: ['spill-local'],
  680. consumers: ['spill-policy'],
  681. note: 'The backend saves oversized tool text and returns a model-facing locator plus retrieval hint; spill-policy is the tools/post-execute consumer that decides when to spill.',
  682. },
  683. {
  684. key: 'directoryPicker',
  685. pkg: 'host-directory-picker',
  686. title: 'Workspace-directory picking seam',
  687. mode: 'seam',
  688. implementations: ['host-directory-picker-native', 'host-directory-picker-browse'],
  689. consumers: ['api-workspace-controller'],
  690. note: 'Discriminated interaction capability: the native backend opens one OS chooser on the host display, the browse backend serves listing/creation primitives for the in-app browser; dual-face backends fill ui-workspace directory-flow slots from their browser halves (no wire advertisement).',
  691. },
  692. {
  693. key: 'webServer',
  694. pkg: 'host-webserver',
  695. title: 'HTTP route registration',
  696. mode: 'core',
  697. consumers: ['client-connection', 'client-modules', 'client-hmr'],
  698. note: 'Plain node:http carrier: named-route registry, index transform taps, and the static dist fallback; web-transport plugins register their own routes.',
  699. },
  700. {
  701. key: 'clientModules',
  702. pkg: 'client-modules',
  703. title: 'Client plugin graph host',
  704. mode: 'core',
  705. consumers: ['client-hmr'],
  706. note: 'Composes the __DSH_BOOT__ entry graph from an incremental dsh.client scan, serves plugin bundles, and notifies rebuilt/graph-changed subscribers.',
  707. },
  708. {
  709. key: 'workflowEngine',
  710. pkg: 'workflow',
  711. title: 'Workflow script engine',
  712. mode: 'seam',
  713. implementations: ['workflow-ptc'],
  714. consumers: ['tool-workflow', 'tool-ralph'],
  715. note: 'One engine per context, as in bash, with no named-provider registry; the general workflow and fixed Ralph consumers start runs whose agent() calls fan out through ctx.subagents.',
  716. },
  717. {
  718. key: 'webhookRuntime',
  719. pkg: 'webhook',
  720. title: 'Webhook rule runtime',
  721. mode: 'core',
  722. consumers: ['webhook-github'],
  723. note: 'Provider adapters dispatch authenticated deliveries; trusted plugins register independent process-local rules, and the runtime turns non-null results into ordinary Workspace-backed Sessions without delivery or completion state.',
  724. },
  725. {
  726. key: 'lsp',
  727. pkg: 'lsp',
  728. title: 'Language-server navigation seam',
  729. mode: 'seam',
  730. implementations: ['lsp-stdio'],
  731. consumers: ['tool-lsp'],
  732. note: 'Provider registration and selection plus normalized query execution over exactly four operations; the seam offers no protocol escape hatch, so a backend translates into the normalized request and result.',
  733. },
  734. {
  735. key: 'dynamicCordisRunner',
  736. pkg: 'cordis-host-runner',
  737. title: 'Dynamic Cordis package host runner',
  738. mode: 'core',
  739. consumers: ['tool-cordis'],
  740. note: 'Owns the in-memory definition registry, the vm sandbox for host halves, and the request-run round trip; browser pages reach the same service over the wire through its remote namespace.',
  741. },
  742. {
  743. key: 'cordisInspect',
  744. pkg: 'cordis-host-runner',
  745. title: 'Dynamic Cordis inspect registry',
  746. mode: 'core',
  747. consumers: ['tool-cordis'],
  748. note: 'Registers host inspect providers, mirrors the client provider manifest, and routes client queries through the dynamic Cordis transport.',
  749. },
  750. ]
  751. function generatedHeader(title: string): string[] {
  752. return [
  753. '<!-- Generated by scripts/gen-doc-graphs.ts - do not edit by hand.',
  754. ' Run `pnpm run gen-doc-graphs` to regenerate. -->',
  755. '',
  756. `# ${title}`,
  757. '',
  758. ]
  759. }
  760. function maintenanceFooter(source: string): string[] {
  761. return [`Maintenance mode: ${source}.`, '']
  762. }
  763. function graphIndexLink(rel: string): string {
  764. return relative('docs', rel).replaceAll('\\', '/')
  765. }
  766. function linkFromDoc(docRel: string, targetRel: string): string {
  767. return relative(dirname(docRel), targetRel).replaceAll('\\', '/')
  768. }
  769. function mermaidCode(value: string): string {
  770. return `<code>${value.replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;')}</code>`
  771. }
  772. function repoLink(path: string, label: string, up = '..'): string {
  773. return `[${label}](${up}/${path})`
  774. }
  775. function sourceLink(source: string, up = '..'): string {
  776. return repoLink(source.split(':')[0] ?? source, `\`${source}\``, up)
  777. }
  778. function pkgLink(pkg: Pkg | undefined, fallback: string, up = '..'): string {
  779. return pkg ? repoLink(pkg.rel, `\`${pkg.short}\``, up) : `\`${fallback}\``
  780. }
  781. function pkgList(names: string[] | undefined, pkgsByShort: Map<string, Pkg>): string {
  782. if (!names || names.length === 0) return '-'
  783. return names.map(name => pkgLink(pkgsByShort.get(name), name)).join(', ')
  784. }
  785. function tableCell(value: string): string {
  786. return value.replace(/\|/g, '\\|').replace(/\n/g, '<br>')
  787. }
  788. function assertServiceRolesComplete(services: readonly ServiceEntry[]): void {
  789. const discovered = new Set(services.map(service => service.key))
  790. const classified = new Set(SERVICE_ROLES.map(role => role.key))
  791. const missing = [...discovered].filter(key => !classified.has(key)).sort()
  792. const stale = [...classified].filter(key => !discovered.has(key)).sort()
  793. if (missing.length || stale.length) {
  794. throw new Error([
  795. missing.length ? `missing service role classification: ${missing.join(', ')}` : '',
  796. stale.length ? `stale service role classification: ${stale.join(', ')}` : '',
  797. ].filter(Boolean).join('; '))
  798. }
  799. }
  800. function renderCapabilitySeams(pkgs: Pkg[], services: readonly ServiceEntry[]): string {
  801. assertServiceRolesComplete(services)
  802. const pkgsByShort = new Map(pkgs.map(pkg => [pkg.short, pkg]))
  803. const maintenance = 'hybrid: services are discovered from Cordis declarations; interface/implementation/consumer roles are classified in `scripts/gen-doc-graphs.ts` with a completeness guard'
  804. const nodes = new Map<string, string>()
  805. const edges = new Set<string>()
  806. const companionEdges = new Set<string>()
  807. const addNode = (id: string, label: string): void => {
  808. if (!nodes.has(id)) nodes.set(id, ` ${id}["${escLabel(label)}"]`)
  809. }
  810. const addEdge = (from: string, to: string): void => { edges.add(` ${from} --> ${to}`) }
  811. const lines = generatedHeader('Capability Seams And Core Services')
  812. lines.push(
  813. 'A service can be a core spine service, a swappable capability seam, or a bundle/composition point. The graph shows the package that owns the service declaration, known implementation packages, and packages that consume the service directly.',
  814. '',
  815. '```mermaid',
  816. 'flowchart LR',
  817. )
  818. for (const role of SERVICE_ROLES) {
  819. const svc = nodeId('svc', role.key)
  820. const owner = nodeId('pkg', role.pkg)
  821. addNode(owner, role.pkg)
  822. addNode(svc, `ctx.${role.key}<br/>${role.title}`)
  823. addEdge(owner, svc)
  824. for (const impl of role.implementations ?? []) {
  825. addNode(nodeId('pkg', impl), impl)
  826. addEdge(nodeId('pkg', impl), svc)
  827. }
  828. for (const consumer of role.consumers ?? []) {
  829. addNode(nodeId('pkg', consumer), consumer)
  830. addEdge(svc, nodeId('pkg', consumer))
  831. }
  832. for (const companion of role.companions ?? []) {
  833. addNode(nodeId('pkg', companion), companion)
  834. companionEdges.add(` ${svc} -. event gate .-> ${nodeId('pkg', companion)}`)
  835. }
  836. }
  837. lines.push(...nodes.values(), ...[...edges].sort(), ...[...companionEdges].sort())
  838. lines.push('```', '', '| ctx key | Role | Owner | Implementations | Direct consumers | Companion plugins | Note |', '| --- | --- | --- | --- | --- | --- | --- |')
  839. for (const role of SERVICE_ROLES) {
  840. lines.push(`| \`ctx.${role.key}\` | \`${role.mode}\` | ${pkgLink(pkgsByShort.get(role.pkg), role.pkg)} | ${pkgList(role.implementations, pkgsByShort)} | ${pkgList(role.consumers, pkgsByShort)} | ${pkgList(role.companions, pkgsByShort)} | ${tableCell(role.note)} |`)
  841. }
  842. lines.push('', ...maintenanceFooter(maintenance))
  843. return lines.join('\n')
  844. }
  845. function parseExampleCordis(rel: string): ExamplePlugin[] {
  846. const text = readFileSync(resolve(root, rel), 'utf8')
  847. const plugins: ExamplePlugin[] = []
  848. let current: { id: string; name?: string } | null = null
  849. const flush = (): void => {
  850. if (current?.name) plugins.push({ id: current.id, name: current.name })
  851. }
  852. for (const line of text.split('\n')) {
  853. // Top-level rows (`- id:`) and bundle-patch insert rows (` - id:`).
  854. const id = /^\s*-\s+id:\s+(.+?)\s*$/.exec(line)
  855. if (id?.[1] !== undefined) {
  856. flush()
  857. current = { id: stripYamlScalar(id[1]) }
  858. continue
  859. }
  860. const name = /^\s+name:\s+(.+?)\s*$/.exec(line)
  861. if (name?.[1] !== undefined && current) current.name = stripYamlScalar(name[1])
  862. }
  863. flush()
  864. return plugins
  865. }
  866. function stripYamlScalar(value: string): string {
  867. return value.trim().replace(/^['"]|['"]$/g, '')
  868. }
  869. const APP_EXAMPLES = [
  870. {
  871. id: 'dsh_base',
  872. rel: 'apps/cli/composition.md',
  873. title: 'DSH Base Composition',
  874. label: 'packages/bundle/base/cordis.patch.yml',
  875. config: 'packages/bundle/base/cordis.patch.yml',
  876. summary: 'The dsh-base bundle patch shared by the web, headless, sdk, and acp profiles; their mode bundles and user layers patch over it, while sdk-minimal owns a separate standalone tree.',
  877. },
  878. ]
  879. type AppExample = typeof APP_EXAMPLES[number]
  880. function renderAppComposition(example: AppExample): string {
  881. const plugins = parseExampleCordis(example.config)
  882. const maintenance = 'hybrid: the patch row list is parsed from its `cordis.yml`; app package expansion is curated from package source'
  883. const lines = generatedHeader(example.title)
  884. lines.push(
  885. example.summary,
  886. '',
  887. '```mermaid',
  888. 'flowchart LR',
  889. ` cfg["${escLabel(example.label)}<br/>cordis.yml"]`,
  890. )
  891. for (const plugin of plugins) {
  892. const pluginNode = nodeId(`plugin_${example.id}`, plugin.id)
  893. lines.push(` ${pluginNode}["${escLabel(plugin.id)}<br/>${escLabel(plugin.name)}"]`)
  894. lines.push(` cfg --> ${pluginNode}`)
  895. }
  896. lines.push(
  897. '```',
  898. '',
  899. '| Plugin id | Package / module |',
  900. '| --- | --- |',
  901. ...plugins.map(plugin => `| \`${plugin.id}\` | \`${plugin.name}\` |`),
  902. '',
  903. `Source config: [\`${example.config}\`](${linkFromDoc(example.rel, example.config)}).`,
  904. )
  905. lines.push('', ...maintenanceFooter(maintenance))
  906. return lines.join('\n')
  907. }
  908. type CallSiteIndex = Map<ts.SignatureDeclaration | ts.JSDocSignature, ts.CallExpression[]>
  909. /**
  910. * The only method names visitSource classifies; receiver typing runs on these
  911. * alone. Obligation: every method name matched by a branch inside visitSource
  912. * must appear here — the prefilter drops non-members before any branch runs,
  913. * so a branch for an unlisted name is silently dead.
  914. */
  915. const EVENT_API_METHODS = new Set(['on', 'once', 'emit', 'parallel', 'serial', 'waterfall', 'dispatch'])
  916. /**
  917. * Collect event dispatch/listener relations from real cross-file receiver types.
  918. *
  919. * TODO: the program is seeded from the host aggregate alone (ts-project.ts
  920. * documents why: one program cannot hold both faces' Context merges), so a
  921. * Client package enters only when a host file imports it. Client-face
  922. * listeners on client-face events are therefore under-reported —
  923. * `connection/reset` omits `ui-skill`/`ui-agent-preset`. Closing it needs a
  924. * second Client program whose relations merge into these, not a wider seed.
  925. */
  926. export class EventRelationCollector {
  927. private readonly relations = new Map<string, EventRelation>()
  928. private readonly fileCallSites = new Map<ts.SourceFile, CallSiteIndex>()
  929. private readonly localCalleeProofs = new Map<ts.FunctionDeclaration, boolean>()
  930. private globalCallSites: CallSiteIndex | null = null
  931. private readonly contextType: ts.Type
  932. private readonly agentDispatchType: ts.Type
  933. private readonly eventsServiceType: ts.Type
  934. private readonly packageSourceFiles: ReadonlySet<ts.SourceFile>
  935. constructor(
  936. private readonly project: TypeScriptProject,
  937. private readonly sources: readonly PackageSource[],
  938. ) {
  939. this.contextType = this.declaredType('vendor/cordis/src/context.ts', 'Context')
  940. this.agentDispatchType = this.declaredType('packages/core/agent/src/dispatch.ts', 'AgentEventDispatch')
  941. this.eventsServiceType = this.declaredType('vendor/cordis/src/events.ts', 'EventsService')
  942. this.packageSourceFiles = new Set(sources.map(source => source.sourceFile))
  943. }
  944. /** Return all event relations discovered from the Program. */
  945. collect(): Map<string, EventRelation> {
  946. for (const source of this.sources) this.visitSource(source)
  947. return this.relations
  948. }
  949. /** Resolve one named class/interface declaration to its merged instance type. */
  950. private declaredType(relativePath: string, name: string): ts.Type {
  951. const sourceFile = this.project.sourceFile(relativePath)
  952. const declaration = sourceFile.statements.find((statement): statement is ts.ClassDeclaration | ts.InterfaceDeclaration => {
  953. return (ts.isClassDeclaration(statement) || ts.isInterfaceDeclaration(statement)) && statement.name?.text === name
  954. })
  955. const symbol = declaration?.name && this.project.checker.getSymbolAtLocation(declaration.name)
  956. if (!symbol) throw new Error(`cannot resolve TypeScript type ${name} from ${relativePath}`)
  957. return this.project.checker.getDeclaredTypeOfSymbol(symbol)
  958. }
  959. /** Index resolved function calls in the given files for narrow argument-flow recovery. */
  960. private buildCallSiteIndex(files: Iterable<ts.SourceFile>): CallSiteIndex {
  961. const index: CallSiteIndex = new Map()
  962. const visit = (node: ts.Node): void => {
  963. if (ts.isCallExpression(node)) {
  964. const declaration = this.project.checker.getResolvedSignature(node)?.declaration
  965. if (declaration) {
  966. const calls = index.get(declaration) ?? []
  967. calls.push(node)
  968. index.set(declaration, calls)
  969. }
  970. }
  971. ts.forEachChild(node, visit)
  972. }
  973. for (const file of files) visit(file)
  974. return index
  975. }
  976. /**
  977. * Return every indexed call resolving to one local helper declaration.
  978. * Fast path: when every same-file reference to the non-exported helper is
  979. * provably a direct callee, module scoping confines all of its calls to that
  980. * file, so only that file is indexed. Any other reference form may alias
  981. * the function value outward, so the original full package-source index
  982. * decides instead.
  983. */
  984. private callSitesFor(owner: ts.FunctionDeclaration): ts.CallExpression[] {
  985. if (!this.globalCallSites && !this.provenLocalCallee(owner)) {
  986. this.globalCallSites = this.buildCallSiteIndex(this.packageSourceFiles)
  987. }
  988. if (this.globalCallSites) return this.globalCallSites.get(owner) ?? []
  989. const file = owner.getSourceFile()
  990. let index = this.fileCallSites.get(file)
  991. if (!index) {
  992. index = this.buildCallSiteIndex([file])
  993. this.fileCallSites.set(file, index)
  994. }
  995. return index.get(owner) ?? []
  996. }
  997. /**
  998. * Prove every same-file reference to one helper is a direct callee. The
  999. * proof owns its premises: an exported helper or a helper in a global
  1000. * script file (no import/export means program-wide scope, callable from
  1001. * another file with no same-file reference at all) fails immediately.
  1002. * Alias escapes (re-export statements, default exports, value reads)
  1003. * resolve back to the owner symbol at a non-callee position and fail the
  1004. * proof, as does anything the scan cannot positively classify.
  1005. */
  1006. private provenLocalCallee(owner: ts.FunctionDeclaration): boolean {
  1007. const cached = this.localCalleeProofs.get(owner)
  1008. if (cached !== undefined) return cached
  1009. if (hasExportModifier(owner) || !ts.isExternalModule(owner.getSourceFile())) {
  1010. this.localCalleeProofs.set(owner, false)
  1011. return false
  1012. }
  1013. const name = owner.name
  1014. const ownerSymbol = name && this.project.checker.getSymbolAtLocation(name)
  1015. let proven = !!ownerSymbol
  1016. const refersToOwner = (identifier: ts.Identifier): boolean => {
  1017. // Shorthand properties resolve to the property symbol; ask for the value side.
  1018. const local = ts.isShorthandPropertyAssignment(identifier.parent)
  1019. ? this.project.checker.getShorthandAssignmentValueSymbol(identifier.parent)
  1020. : this.project.checker.getSymbolAtLocation(identifier)
  1021. if (!local) return false
  1022. const symbol = local.flags & ts.SymbolFlags.Alias
  1023. ? this.project.checker.getAliasedSymbol(local)
  1024. : local
  1025. return symbol === ownerSymbol
  1026. }
  1027. const visit = (node: ts.Node): void => {
  1028. if (!proven) return
  1029. if (ts.isIdentifier(node) && node !== name && node.text === name?.text
  1030. && !isDirectCallee(node) && refersToOwner(node)) {
  1031. proven = false
  1032. return
  1033. }
  1034. ts.forEachChild(node, visit)
  1035. }
  1036. visit(owner.getSourceFile())
  1037. this.localCalleeProofs.set(owner, proven)
  1038. return proven
  1039. }
  1040. /** Walk one package source file and classify event API calls by receiver type. */
  1041. private visitSource(source: PackageSource): void {
  1042. const visit = (node: ts.Node): void => {
  1043. if (ts.isCallExpression(node)) {
  1044. if (this.isAgentEventEmitter(node.expression)) {
  1045. const event = node.arguments[2]
  1046. if (event) {
  1047. for (const name of this.finiteStringValues(event) ?? []) {
  1048. this.addDispatcher(name, source.pkg, 'emitAgentEvent')
  1049. }
  1050. }
  1051. } else if (ts.isPropertyAccessExpression(node.expression) && EVENT_API_METHODS.has(node.expression.name.text)) {
  1052. const receiverKind = this.receiverKind(node.expression.expression)
  1053. const method = node.expression.name.text
  1054. if (receiverKind === 'events-service' && method === 'dispatch') {
  1055. const argumentList = node.arguments[1]
  1056. if (argumentList) {
  1057. for (const event of this.eventNamesFromArgumentList(argumentList, new Set())) {
  1058. this.addDispatcher(event, source.pkg, 'events.dispatch')
  1059. }
  1060. }
  1061. } else if (receiverKind === 'context' || receiverKind === 'agent-dispatch') {
  1062. const eventNames = this.eventNamesFromCall(node, receiverKind)
  1063. if (method === 'on' || method === 'once') {
  1064. for (const event of eventNames) this.ensure(event).listeners.add(source.pkg)
  1065. } else if (method === 'emit' || method === 'parallel' || method === 'serial' || method === 'waterfall') {
  1066. for (const event of eventNames) this.addDispatcher(event, source.pkg, method)
  1067. }
  1068. }
  1069. }
  1070. }
  1071. ts.forEachChild(node, visit)
  1072. }
  1073. visit(source.sourceFile)
  1074. }
  1075. /** Match the exported contained-notification helper by declaration identity. */
  1076. private isAgentEventEmitter(expression: ts.Expression): boolean {
  1077. if (!ts.isIdentifier(expression)) return false
  1078. const local = this.project.checker.getSymbolAtLocation(expression)
  1079. if (!local) return false
  1080. const symbol = local.flags & ts.SymbolFlags.Alias
  1081. ? this.project.checker.getAliasedSymbol(local)
  1082. : local
  1083. const declarations = symbol.declarations ?? []
  1084. return declarations.some((declaration) => {
  1085. return ts.isFunctionDeclaration(declaration)
  1086. && declaration.name?.text === 'emitAgentEvent'
  1087. && this.project.relativePath(declaration.getSourceFile()) === 'packages/core/agent/src/dispatch.ts'
  1088. })
  1089. }
  1090. /** Classify a receiver using assignability to the repository's actual event API types. */
  1091. private receiverKind(receiver: ts.Expression): EventReceiverKind | undefined {
  1092. const type = this.project.checker.getTypeAtLocation(receiver)
  1093. if (type.flags & (ts.TypeFlags.Any | ts.TypeFlags.Unknown | ts.TypeFlags.Never)) return undefined
  1094. if (this.project.checker.isTypeAssignableTo(type, this.eventsServiceType)) return 'events-service'
  1095. if (this.project.checker.isTypeAssignableTo(type, this.contextType)) return 'context'
  1096. if (this.project.checker.isTypeAssignableTo(type, this.agentDispatchType)) return 'agent-dispatch'
  1097. return undefined
  1098. }
  1099. /** Resolve the event-name argument for Context and fused agent dispatch calls. */
  1100. private eventNamesFromCall(call: ts.CallExpression, receiverKind: Exclude<EventReceiverKind, 'events-service'>): Set<string> {
  1101. const candidates = receiverKind === 'context' ? call.arguments.slice(0, 2) : call.arguments.slice(0, 1)
  1102. for (const candidate of candidates) {
  1103. const values = this.finiteStringValues(candidate)
  1104. if (values) return values
  1105. }
  1106. return new Set()
  1107. }
  1108. /** Recover the event slot from the argument array handed to EventsService.dispatch(). */
  1109. private eventNamesFromArgumentList(expression: ts.Expression, seen: Set<ts.Node>): Set<string> {
  1110. const current = unwrapExpression(expression)
  1111. if (seen.has(current)) return new Set()
  1112. seen.add(current)
  1113. if (ts.isArrayLiteralExpression(current)) {
  1114. for (const element of current.elements.slice(0, 2)) {
  1115. if (ts.isOmittedExpression(element) || ts.isSpreadElement(element)) continue
  1116. const values = this.finiteStringValues(element)
  1117. if (values) return values
  1118. }
  1119. return new Set()
  1120. }
  1121. if (ts.isConditionalExpression(current)) {
  1122. return unionSets(
  1123. this.eventNamesFromArgumentList(current.whenTrue, new Set(seen)),
  1124. this.eventNamesFromArgumentList(current.whenFalse, new Set(seen)),
  1125. )
  1126. }
  1127. if (!ts.isIdentifier(current)) return new Set()
  1128. const symbol = this.project.checker.getSymbolAtLocation(current)
  1129. if (!symbol) return new Set()
  1130. const events = new Set<string>()
  1131. for (const declaration of symbol.declarations ?? []) {
  1132. if (ts.isVariableDeclaration(declaration) && declaration.initializer && isConstDeclaration(declaration)) {
  1133. addAll(events, this.eventNamesFromArgumentList(declaration.initializer, new Set(seen)))
  1134. } else if (ts.isParameter(declaration)) {
  1135. addAll(events, this.eventNamesFromParameter(declaration, seen))
  1136. }
  1137. }
  1138. return events
  1139. }
  1140. /** Follow a non-exported local helper parameter back to every resolved call site. */
  1141. private eventNamesFromParameter(parameter: ts.ParameterDeclaration, seen: Set<ts.Node>): Set<string> {
  1142. const owner = parameter.parent
  1143. if (!ts.isFunctionDeclaration(owner) || hasExportModifier(owner)) return new Set()
  1144. const index = owner.parameters.indexOf(parameter)
  1145. if (index < 0) return new Set()
  1146. const events = new Set<string>()
  1147. for (const call of this.callSitesFor(owner)) {
  1148. const argument = call.arguments[index]
  1149. if (argument) addAll(events, this.eventNamesFromArgumentList(argument, new Set(seen)))
  1150. }
  1151. return events
  1152. }
  1153. /** Return a finite string-literal value set, rejecting widened and generic strings. */
  1154. private finiteStringValues(expression: ts.Expression): Set<string> | undefined {
  1155. const current = unwrapExpression(expression)
  1156. if (ts.isStringLiteralLike(current)) return new Set([current.text])
  1157. if (this.isForwardedAgentEventParameter(current)) return undefined
  1158. return finiteStringTypeValues(this.project.checker.getTypeAtLocation(current))
  1159. }
  1160. /** Reject the contextual parameter inside the AgentEventDispatch forwarding object. */
  1161. private isForwardedAgentEventParameter(expression: ts.Expression): boolean {
  1162. if (!ts.isIdentifier(expression)) return false
  1163. const declarations = this.project.checker.getSymbolAtLocation(expression)?.declarations ?? []
  1164. return declarations.some((declaration) => {
  1165. if (!ts.isParameter(declaration)) return false
  1166. const method = declaration.parent
  1167. if (!ts.isMethodDeclaration(method) || !ts.isObjectLiteralExpression(method.parent)) return false
  1168. const contextualType = this.project.checker.getContextualType(method.parent)
  1169. return contextualType !== undefined
  1170. && this.project.checker.isTypeAssignableTo(contextualType, this.agentDispatchType)
  1171. })
  1172. }
  1173. /** Get or create one relation row. */
  1174. private ensure(event: string): EventRelation {
  1175. const existing = this.relations.get(event)
  1176. if (existing) return existing
  1177. const relation = { dispatchers: new Map<string, Set<string>>(), listeners: new Set<string>() }
  1178. this.relations.set(event, relation)
  1179. return relation
  1180. }
  1181. /** Add one dispatcher method without duplicating package/method labels. */
  1182. private addDispatcher(event: string, pkg: string, method: string): void {
  1183. const relation = this.ensure(event)
  1184. const methods = relation.dispatchers.get(pkg) ?? new Set<string>()
  1185. methods.add(method)
  1186. relation.dispatchers.set(pkg, methods)
  1187. }
  1188. }
  1189. /** Return whether an identifier is the callee of a call, seen through value-preserving wrappers. */
  1190. function isDirectCallee(identifier: ts.Identifier): boolean {
  1191. let current: ts.Node = identifier
  1192. while (
  1193. ts.isParenthesizedExpression(current.parent)
  1194. || ts.isAsExpression(current.parent)
  1195. || ts.isTypeAssertionExpression(current.parent)
  1196. || ts.isNonNullExpression(current.parent)
  1197. || ts.isSatisfiesExpression(current.parent)
  1198. ) {
  1199. current = current.parent
  1200. }
  1201. return ts.isCallExpression(current.parent) && current.parent.expression === current
  1202. }
  1203. /** Peel syntax-only wrappers that do not change an expression's runtime value. */
  1204. function unwrapExpression(expression: ts.Expression): ts.Expression {
  1205. let current = expression
  1206. while (
  1207. ts.isParenthesizedExpression(current)
  1208. || ts.isAsExpression(current)
  1209. || ts.isTypeAssertionExpression(current)
  1210. || ts.isNonNullExpression(current)
  1211. || ts.isSatisfiesExpression(current)
  1212. ) {
  1213. current = current.expression
  1214. }
  1215. return current
  1216. }
  1217. /** Return every value only when a type is a closed string-literal union. */
  1218. function finiteStringTypeValues(type: ts.Type): Set<string> | undefined {
  1219. if (type.flags & ts.TypeFlags.StringLiteral) {
  1220. return new Set([(type as ts.StringLiteralType).value])
  1221. }
  1222. if (type.flags & ts.TypeFlags.Never) return new Set()
  1223. if (!type.isUnion()) return undefined
  1224. const values = new Set<string>()
  1225. for (const member of type.types) {
  1226. const memberValues = finiteStringTypeValues(member)
  1227. if (!memberValues) return undefined
  1228. addAll(values, memberValues)
  1229. }
  1230. return values
  1231. }
  1232. /** Return whether a variable declaration belongs to a const declaration list. */
  1233. function isConstDeclaration(declaration: ts.VariableDeclaration): boolean {
  1234. return (declaration.parent.flags & ts.NodeFlags.Const) !== 0
  1235. }
  1236. /** Return whether a declaration is visible to callers outside its source module. */
  1237. function hasExportModifier(node: ts.Node): boolean {
  1238. return ts.canHaveModifiers(node) && (ts.getModifiers(node)?.some((modifier) => {
  1239. return modifier.kind === ts.SyntaxKind.ExportKeyword || modifier.kind === ts.SyntaxKind.DefaultKeyword
  1240. }) ?? false)
  1241. }
  1242. /** Add every member of source to target. */
  1243. function addAll<T>(target: Set<T>, source: ReadonlySet<T>): void {
  1244. for (const value of source) target.add(value)
  1245. }
  1246. /** Return the union of two sets without mutating either input. */
  1247. function unionSets<T>(left: ReadonlySet<T>, right: ReadonlySet<T>): Set<T> {
  1248. const out = new Set(left)
  1249. addAll(out, right)
  1250. return out
  1251. }
  1252. /**
  1253. * Select the package source files of one project in deterministic order.
  1254. * @param project - the loaded repository TypeScript project.
  1255. * @returns `packages/<group>/<pkg>/src` files tagged with their package name.
  1256. */
  1257. export function collectPackageSources(project: TypeScriptProject): PackageSource[] {
  1258. return project.sourceFiles().flatMap((sourceFile): PackageSource[] => {
  1259. const rel = project.relativePath(sourceFile)
  1260. const match = /^packages\/[^/]+\/([^/]+)\/src\/.+\.ts$/.exec(rel)
  1261. return match?.[1] ? [{ rel, pkg: match[1], sourceFile }] : []
  1262. }).sort((left, right) => left.rel.localeCompare(right.rel))
  1263. }
  1264. function collectEventRelations(): Map<string, EventRelation> {
  1265. const project = new TypeScriptProject(root)
  1266. return new EventRelationCollector(project, collectPackageSources(project)).collect()
  1267. }
  1268. function relationPackages(map: Map<string, Set<string>>, pkgsByShort: Map<string, Pkg>): string {
  1269. if (map.size === 0) return '-'
  1270. return [...map.entries()]
  1271. .sort(([a], [b]) => a.localeCompare(b))
  1272. .map(([pkg, methods]) => `${pkgLink(pkgsByShort.get(pkg), pkg)} (${[...methods].sort().map(m => `\`${m}\``).join(', ')})`)
  1273. .join(', ')
  1274. }
  1275. function listenerPackages(listeners: Set<string>, pkgsByShort: Map<string, Pkg>): string {
  1276. if (listeners.size === 0) return '-'
  1277. return [...listeners].sort().map(pkg => pkgLink(pkgsByShort.get(pkg), pkg)).join(', ')
  1278. }
  1279. function renderEventRelations(pkgs: Pkg[], events: readonly EventEntry[]): string {
  1280. const relations = collectEventRelations()
  1281. const pkgsByShort = new Map(pkgs.map(pkg => [pkg.short, pkg]))
  1282. const maintenance = 'generated: Cordis event declarations and producer/listener edges are resolved from the repository TypeScript Program'
  1283. const lines = generatedHeader('Event Producer And Consumer Matrix')
  1284. lines.push(
  1285. 'This matrix shows which packages dispatch each harness-owned event and which packages listen to it. Events are many-to-many, so the dense relation data is presented as a table rather than one large graph. Receiver and event-name types also cover contained dispatch sites that deliberately bypass `ctx.emit`, such as subagent lifecycle containment.',
  1286. '',
  1287. '| Event | Mode | Declared in | Dispatchers | Listeners |',
  1288. '| --- | --- | --- | --- | --- |',
  1289. )
  1290. for (const event of [...events].sort((a, b) => a.name.localeCompare(b.name))) {
  1291. const relation = relations.get(event.name) ?? { dispatchers: new Map<string, Set<string>>(), listeners: new Set<string>() }
  1292. lines.push(`| \`${event.name}\` | \`${event.mode}\` | ${sourceLink(event.source)} | ${relationPackages(relation.dispatchers, pkgsByShort)} | ${listenerPackages(relation.listeners, pkgsByShort)} |`)
  1293. }
  1294. // Every declared event needs a dispatcher: zero means dead vocabulary or an
  1295. // unrecognized semantic dispatch form. Listener-free extension points remain
  1296. // valid. Client-declared events are exempt: the relation scan seeds the HOST
  1297. // aggregate program only (host+client cannot share one program — the cordis
  1298. // Context merges collide), so client dispatch sites are structurally
  1299. // invisible here; their rows stay in the table for the declarations' sake.
  1300. const undispatched = [...events]
  1301. .filter(event => !event.source.startsWith('packages/client/'))
  1302. .filter(event => (relations.get(event.name)?.dispatchers.size ?? 0) === 0)
  1303. .map(event => event.name)
  1304. .sort()
  1305. if (undispatched.length > 0) {
  1306. throw new Error(
  1307. `event-producer-consumer matrix: no dispatcher found for declared event${undispatched.length > 1 ? 's' : ''} `
  1308. + `${undispatched.map(name => `"${name}"`).join(', ')} — dead vocabulary, or a dispatch form the semantic scan misses `
  1309. + '(teach scripts/gen-doc-graphs.ts that form)',
  1310. )
  1311. }
  1312. const declared = new Set(events.map(event => event.name))
  1313. const extra = [...relations.keys()].filter(event => !declared.has(event)).sort()
  1314. if (extra.length > 0) {
  1315. lines.push('', '## Non-harness or undeclared event strings seen in package source', '', '| Event string | Dispatchers | Listeners |', '| --- | --- | --- |')
  1316. for (const event of extra) {
  1317. const relation = relations.get(event)
  1318. if (!relation) continue
  1319. lines.push(`| \`${event}\` | ${relationPackages(relation.dispatchers, pkgsByShort)} | ${listenerPackages(relation.listeners, pkgsByShort)} |`)
  1320. }
  1321. }
  1322. lines.push('', ...maintenanceFooter(maintenance))
  1323. return lines.join('\n')
  1324. }
  1325. function renderLifecycle(): string {
  1326. const maintenance = 'curated Mermaid sequence; exact event signatures live in the generated Cordis catalog'
  1327. return [
  1328. ...generatedHeader('Agent Turn And Step Lifecycle'),
  1329. 'This sequence is the visual companion to [architecture.md](architecture.md#turn-flow). It keeps durable replay facts on `session/event` and live control/status on `agent/*`.',
  1330. '',
  1331. '```mermaid',
  1332. 'sequenceDiagram',
  1333. ' participant User',
  1334. ' participant Agent',
  1335. ' participant Driver',
  1336. ' participant Hooks as hook listeners',
  1337. ' participant Prompt as ctx.systemPrompt',
  1338. ' participant LLM as ctx.llm',
  1339. ' participant Tools as ctx.tools',
  1340. ' participant Session',
  1341. ' participant SDK as UI or SDK listener',
  1342. ' User->>Agent: followup(content)',
  1343. ` Agent-->>SDK: ${mermaidCode('agent/inbox/spliced')}`,
  1344. ` Agent-->>SDK: ${mermaidCode('agent/inbox/inserted')} { message }`,
  1345. ' Agent->>Driver: queued work wakes driver',
  1346. ` Driver-->>SDK: ${mermaidCode('agent/status')} running`,
  1347. ` Driver->>Session: ${mermaidCode('turn/start')}`,
  1348. ' Note over Agent,Driver: claim pending next-step input plus one queued prompt',
  1349. ` Driver-->>SDK: ${mermaidCode('agent/inbox/spliced')} pure deletion`,
  1350. ` Driver-->>SDK: ${mermaidCode('agent/inbox/claimed')} { message, turn } per message`,
  1351. ` Driver->>Prompt: ${mermaidCode('system-prompt/assemble')} waterfall`,
  1352. ` Driver->>Hooks: ${mermaidCode('agent/pre-step')} waterfall`,
  1353. ' Hooks-->>Driver: authoritative reject or enter(messages)',
  1354. ' alt proposed step rejected, first batch empty, or pre-step failed',
  1355. ' Driver-->>Driver: claimed batch stays removed, the open turn spends no step',
  1356. ' else enter proposed step',
  1357. ` Driver->>Session: ${mermaidCode('step/start')}`,
  1358. ` Driver->>Hooks: ${mermaidCode('agent/request')} waterfall`,
  1359. ' Driver->>LLM: prepareCall(config, signal)',
  1360. ' Note over Driver,LLM: cancellation during either async phase commits neither system nor users',
  1361. ' Note over Driver,Session: synchronous admission using the prepared call capability',
  1362. ` Driver->>Session: ${mermaidCode('system/message')} ordered per-node reconciliation`,
  1363. ` Driver->>Session: ${mermaidCode('user/message')} per entered message`,
  1364. ` Driver->>Session: ${mermaidCode('request/header')} and ${mermaidCode('request/context')} as needed`,
  1365. ' Driver->>Driver: derive and freeze request from the log',
  1366. ` Driver->>LLM: bound prepared call through ${mermaidCode('llm/stream')} waterfall`,
  1367. ' LLM-->>Driver: StreamChunk*',
  1368. ` Driver-->>SDK: ${mermaidCode('agent/assistant-stream')} chunk*`,
  1369. ' alt final adapter or terminal in-band request failure',
  1370. ` Driver->>Session: ${mermaidCode('assistant/attempt')}`,
  1371. ` Driver-->>SDK: ${mermaidCode('agent/assistant-stream')} committed end`,
  1372. ` Driver->>Hooks: ${mermaidCode('agent/request-error')} waterfall`,
  1373. ' Hooks-->>Driver: return retry action or preserve the original error',
  1374. ' Note over Driver,LLM: retry in the open step: prepare and reconcile the same rendered assembly without repeating pre-step or users',
  1375. ' else model request succeeded',
  1376. ` Driver->>Session: ${mermaidCode('assistant/message')}`,
  1377. ` Driver-->>SDK: ${mermaidCode('agent/assistant-stream')} committed end`,
  1378. ' Driver->>Tools: classify pending call by executionMode',
  1379. ' loop barriers and bounded rolling pool, reclassify before start',
  1380. ' opt call starts',
  1381. ` Driver->>Session: ${mermaidCode('tool/call')}`,
  1382. ' Driver->>Tools: ordered pre, concurrent execute',
  1383. ' Tools-->>Session: tool-owned events when applicable',
  1384. ' end',
  1385. ' opt next model-order result ready',
  1386. ' Driver->>Tools: ordered post',
  1387. ` Driver->>Session: ${mermaidCode('tool/result')}`,
  1388. ' end',
  1389. ' end',
  1390. ` Driver->>Session: ${mermaidCode('step/end')}`,
  1391. ' opt natural stop and next-step inbox empty',
  1392. ` Driver->>Hooks: ${mermaidCode('agent/turn-stopping')} serial terminal checkpoint`,
  1393. ' end',
  1394. ' opt next-step input is pending',
  1395. ' Driver-->>Driver: claim pending next-step input',
  1396. ` Driver-->>SDK: ${mermaidCode('agent/inbox/claimed')} { message, turn } per message`,
  1397. ` Driver->>Hooks: ${mermaidCode('agent/pre-step')} waterfall`,
  1398. ' Hooks-->>Driver: authoritative reject or enter(messages)',
  1399. ' end',
  1400. ' end',
  1401. ' end',
  1402. ` Driver->>Session: ${mermaidCode('turn/end')}`,
  1403. ` Driver-->>SDK: ${mermaidCode('agent/status')} idle`,
  1404. '```',
  1405. '',
  1406. 'The `assistant/message` event records every successful provider call, including content-less and `max-tokens` finishes, and embeds the exact compact timed stream. Empty content stays out of derived history. A failed, retried, cancelled, or stream-error attempt that reaches settlement without a surface message records its stream as `assistant/attempt`. Live `agent/assistant-stream` chunk frames are transient; replay reads either durable settlement, and a hard process loss before settlement leaves no durable attempt stream.',
  1407. '',
  1408. '`dsh-compaction-basic` uses `agent/pre-step` for pressure before request derivation and `agent/request-error` only for canonical context overflow. Once either trigger qualifies, optional tool-result pruning runs before summary selection. Recovery runs within the open step and retries only when pruning or summarization advances the surface replacement generation; otherwise the original request error remains authoritative. Each retry prepares its call and reconciles the retained rendered assembly before request derivation, without repeating assembly, pre-step, or user admission.',
  1409. '',
  1410. 'The returned `agent/pre-step` decision is authoritative; listeners wrapping `next()` preserve downstream messages and `startsRequestSeries` unless replacement is intentional. Steering and injected context pass through the same waterfall after a later claim operation takes their next-step batch.',
  1411. '',
  1412. 'SDK users that need replayable transcript data should consume `session/event`; `agent/*` is the live coordination API for queue/status, prompt interception, request construction, steering, continuation, and errors.',
  1413. '',
  1414. ...maintenanceFooter(maintenance),
  1415. ].join('\n')
  1416. }
  1417. function renderToolPipeline(): string {
  1418. const maintenance = 'curated Mermaid flow; exact tool schemas and event signatures live in generated catalogs'
  1419. return [
  1420. ...generatedHeader('Tool Execution Pipeline'),
  1421. 'This graph shows where policy, hooks, sandboxing, filesystem guards, result rewriting, final-outcome observation, and UI rendering run without changing the loop. The `tools/pre-execute` waterfall runs first, monotonic guards run next, and the `tools/execute` and `tools/post-execute` waterfalls follow; the three waterfalls may transform a call. Definition-owned `finalizeContent` and `tools/result` run afterward.',
  1422. '',
  1423. '```mermaid',
  1424. 'flowchart TD',
  1425. ' model["Assistant message contains tool-call block"]',
  1426. ` toolCall["Session event: ${mermaidCode('tool/call')}<br/>logged before execution"]`,
  1427. ' presentCall["UI pending card<br/>presentCall(args)"]',
  1428. ` pre["${mermaidCode('tools/pre-execute')} waterfall<br/>hooks, permission, sandbox"]`,
  1429. ' guards["Registered monotonic guards<br/>deny or abstain; identity protected"]',
  1430. ' denied["denied or approval refused<br/>tool body skipped"]',
  1431. ` approval["${mermaidCode('ctx.approval')} one-shot prompt<br/>absent or unanswerable: deny"]`,
  1432. ` around["${mermaidCode('tools/execute')} waterfall<br/>timeout, retry, metrics (around dispatch)"]`,
  1433. ' toolBody["Registered tool execute() body"]',
  1434. ` fsGate["${mermaidCode('fs/write-intent')} or ${mermaidCode('fs/edit-intent')}<br/>tool-fs mutations only"]`,
  1435. ` owned["Tool-owned session events<br/>${mermaidCode('todo/write')}, ${mermaidCode('fs/observed')}, ${mermaidCode('hook/invoked')}, ${mermaidCode('hook/result')}, ${mermaidCode('tool/ptc-dispatch')}"]`,
  1436. ` post["${mermaidCode('tools/post-execute')} waterfall<br/>accept, block, replace, add context"]`,
  1437. ' normalized["Registry outer normalization<br/>pipeline/result snapshot throws become isError"]',
  1438. ' finalize["ToolDefinition.finalizeContent<br/>last content-only invariant"]',
  1439. ` final["${mermaidCode('tools/result')} synchronous notification<br/>frozen authoritative outcome"]`,
  1440. ' context["Active-batch additionalContexts FIFO<br/>injected user/message after recorded tool results"]',
  1441. ` toolResult["Session event: ${mermaidCode('tool/result')}<br/>single model-facing outcome"]`,
  1442. ' allResults["Tool batch settled<br/>recorded tool/result events complete"]',
  1443. ' presentResult["UI completed card<br/>presentResult(args, result)"]',
  1444. ' model --> toolCall',
  1445. ' toolCall --> presentCall',
  1446. ' toolCall --> pre',
  1447. ' pre -->|allow| guards',
  1448. ' guards -->|allow| around',
  1449. ' guards -->|deny| denied',
  1450. ' guards -.->|throw| normalized',
  1451. ' around --> toolBody',
  1452. ' pre -->|deny| denied',
  1453. ' pre -->|ask| approval',
  1454. ' approval -->|allowed-once| guards',
  1455. ' approval -->|rejected, cancelled, unavailable| denied',
  1456. ' approval -.->|throw| normalized',
  1457. ' denied --> post',
  1458. ' pre -.->|throw| normalized',
  1459. ' toolBody --> fsGate',
  1460. ' fsGate --> toolBody',
  1461. ' toolBody --> owned',
  1462. ' toolBody --> around',
  1463. ' around --> post',
  1464. ' around -.->|wrapper throws| normalized',
  1465. ' post -.->|throw| normalized',
  1466. ' post --> finalize',
  1467. ' normalized --> finalize',
  1468. ' finalize --> final',
  1469. ' final --> toolResult',
  1470. ' toolResult --> presentResult',
  1471. ' toolResult --> allResults',
  1472. ' allResults --> context',
  1473. '```',
  1474. '',
  1475. 'Filesystem read-before-edit checks stay below `tool-fs` on `fs/*` events. Generic pre/post waterfalls host hooks and approval policy; `ctx.approval` resolves asks before monotonic guards, and owner policy that must not be reordered remains a registered guard. Around-dispatch concerns such as timeouts wrap `tools/execute`. The registry losslessly snapshots the candidate result and normalizes a snapshot failure before the visible definition\'s snapshotted `finalizeContent` callback enforces its synchronous content-only invariant. `tools/result` then observes the immutable, lossless-JSON outcome. This lets hooks span tool families without coupling the tools to one policy service. PTC mode sends both the reserved `run_code` transport and its serialized sub-calls through the pipeline; sub-calls carry the parent token, log `tool/ptc-dispatch`, return denials as binding rejections, and omit `additionalContexts` to preserve call/result adjacency.',
  1476. '',
  1477. ...maintenanceFooter(maintenance),
  1478. ].join('\n')
  1479. }
  1480. function renderDocs(): GraphDoc[] {
  1481. const pkgs = collectPackageGraph(root, GROUP_ORDER, 'gen-doc-graphs')
  1482. const { model } = projectCordisCatalog(root, CORDIS_CATALOG_POLICY)
  1483. const docs: GraphDoc[] = [
  1484. { rel: 'docs/capability-seams.md', content: renderCapabilitySeams(pkgs, model.services) },
  1485. ...APP_EXAMPLES.map(example => ({ rel: example.rel, content: renderAppComposition(example) })),
  1486. { rel: 'docs/event-producer-consumer.md', content: renderEventRelations(pkgs, model.events) },
  1487. { rel: 'docs/agent-lifecycle.md', content: renderLifecycle() },
  1488. { rel: 'docs/tool-execution-pipeline.md', content: renderToolPipeline() },
  1489. ]
  1490. docs.unshift({ rel: 'docs/graph-atlas.md', content: renderIndex(docs) })
  1491. return docs
  1492. }
  1493. function renderIndex(docs: GraphDoc[]): string {
  1494. const labels: Record<string, string> = {
  1495. 'docs/capability-seams.md': 'capability seams and core services',
  1496. 'apps/cli/composition.md': 'dsh shared base composition',
  1497. 'docs/event-producer-consumer.md': 'event producer/consumer matrix',
  1498. 'docs/agent-lifecycle.md': 'agent turn and step lifecycle',
  1499. 'docs/tool-execution-pipeline.md': 'tool execution pipeline',
  1500. }
  1501. const modes: Record<string, string> = {
  1502. 'docs/capability-seams.md': 'hybrid generated',
  1503. 'apps/cli/composition.md': 'hybrid generated',
  1504. 'docs/event-producer-consumer.md': 'hybrid generated',
  1505. 'docs/agent-lifecycle.md': 'curated',
  1506. 'docs/tool-execution-pipeline.md': 'curated',
  1507. }
  1508. const rows = [
  1509. '| [module dependency graph](module-graph.md) | `generated` |',
  1510. '| [tool schema catalog and package map](tool-catalog.md) | `generated` |',
  1511. ...docs.map((doc) => {
  1512. const link = graphIndexLink(doc.rel)
  1513. return `| [${labels[doc.rel] ?? link}](${link}) | \`${modes[doc.rel] ?? 'generated'}\` |`
  1514. }),
  1515. ]
  1516. const maintenance = 'mixed: each linked page declares generated, hybrid, or curated mode'
  1517. return [
  1518. ...generatedHeader('Documentation Graph Index'),
  1519. 'These diagrams show relationships that the generated catalogs do not. Use them to find package relationships, capability seams, event flow, model-facing tools, app composition, and runtime lifecycle paths. Exact signatures and type definitions still live in the [subsystem pages](subsystems/core.md) (types + the generated Cordis API regions) and [tool-catalog.md](tool-catalog.md).',
  1520. '',
  1521. 'The process decision behind this index is recorded in [the documentation graph Agent Note](../.agents/notes/archived/process/2026-07-03-documentation-graph-atlas.md).',
  1522. '',
  1523. '| Graph | Mode |',
  1524. '| --- | --- |',
  1525. ...rows,
  1526. '',
  1527. 'Regenerate with `pnpm run gen-doc-graphs`; verify freshness with `pnpm run verify-doc-graphs`.',
  1528. '',
  1529. ...maintenanceFooter(maintenance),
  1530. ].join('\n')
  1531. }
  1532. function main(): void {
  1533. const docs = renderDocs()
  1534. if (process.argv.includes('--check')) {
  1535. const stale: string[] = []
  1536. for (const doc of docs) {
  1537. const abs = resolve(root, doc.rel)
  1538. const committed = existsSync(abs) ? readFileSync(abs, 'utf8') : null
  1539. if (committed !== doc.content) stale.push(doc.rel)
  1540. }
  1541. if (stale.length === 0) {
  1542. console.log(`gen-doc-graphs: ${docs.length} graph doc(s) are up to date.`)
  1543. return
  1544. }
  1545. console.error(`gen-doc-graphs: stale graph doc(s): ${stale.join(', ')}. Run \`pnpm run gen-doc-graphs\` and commit the result.`)
  1546. process.exit(1)
  1547. }
  1548. for (const doc of docs) {
  1549. mkdirSync(dirname(resolve(root, doc.rel)), { recursive: true })
  1550. writeFileSync(resolve(root, doc.rel), doc.content)
  1551. }
  1552. console.log(`gen-doc-graphs: wrote ${docs.length} graph doc(s).`)
  1553. }
  1554. if (process.argv[1] && import.meta.filename === resolve(process.argv[1])) {
  1555. main()
  1556. }