Releases: ccneedb/dsh-information-environment-governance
Release list
dsh-information-environment-governance v0.12.1 — Round 7 frozen baseline
The designated frozen baseline for the definitive behavioural evaluation. Supersedes v0.12.0 as the baseline: that tag points at a commit whose required compatibility job was red.
Fixed
- CI never installed pnpm, which
dsh plugin addforwards to, so every install step in the verification chain failed withdsh: pnpm was not found. The previouscontinue-on-errorhid it entirely; making the job required surfaced it on the first run. pnpm is now installed and pinned (12.9.1), like TypeScript (6.0.3).
Why the baseline moved
A frozen baseline must be a state that actually passed its checks. v0.12.0's required job was red, so the baseline is v0.12.1 and the record says why — corrected at the source rather than annotated.
Round 7 content in this baseline
- Glossary (
src/kernel/glossary.ts): nine fields, four statuses (PROVISIONAL | CONFIRMED | DEPRECATED | CONFLICTED), three sources, five-rung authority ladder. User authority is structural — an inferred entry can never reachCONFIRMED, and an inferred upsert of a confirmed entry is refused with its reason. Persistent project state on the existing ontology. - Three-tier behaviour via
resolveTerm():exact | alias | deprecated | ambiguous | conflicted | unknown. A harmless alias is the accept-silently case; no kind blocks work. - Compatibility baseline repaired: CI installs and exercises dsh 0.2.1-alpha.1, the release declared Verified, in a required job. The four states — Verified, Compatible, Unsupported, Unknown — are documented, and a peer range is explicitly not a tested-versions list.
Verification
- All five CI jobs green, including the required
full verification chain (verified host 0.2.1-alpha.1). node --test284/284 (17 terminology tests covering the ten required scenarios, each paired with its non-overreach counterpart);scripts/verify.sh23/23;check-docsgreen.- Tested versions: Node 20/22/24, TypeScript 6.0.3, pnpm 12.9.1, DSH 0.2.1-alpha.1,
PROMPT_VERSION0.5.0 at 2,806 bytes.
Not done, and not claimed
- Gates C and D remain unmeasured.
eval/seeds both arms and scores the filesystem, but its step 2 is "the subject is a real agent run", which the repository does not execute. No behavioural result is claimed for this revision. - Known limitations: agent-asserted
confirmedByUser; no cross-document contradiction detection;verify.shmisreports the test count on a non-TTY runner; the CI host job depends on an upstream npm package remaining installable.
dsh plugin --profile ieg-test add https://github.com/ccneedb/dsh-information-environment-governancedsh-information-environment-governance v0.12.0 — Round 7 frozen baseline
Round 7 — stabilization, terminology governance and validation preparation. This is the designated frozen baseline for the definitive behavioural evaluation.
Fixed — the declared compatibility baseline was never enforced
- CI installed
@deepseek-ai/dsh@0.2.0-rc.2, the release retired in the 0.8.0 re-baseline, while the package declared0.2.1-alpha.1as verified. The host job now installs exactly the verified release and is required: a compatibility failure is a CI failure, not a warning. - The same job ran
scripts/ieg-npm*.sh, deleted in Batch 5, hidden bycontinue-on-error. Dead step removed. - TypeScript was floating; pinned to
6.0.3.
Added — the project-local glossary
src/kernel/glossary.ts: nine fields, four statuses (PROVISIONAL | CONFIRMED | DEPRECATED | CONFLICTED), three sources, and a five-rung authority ladder. User authority is structural: an inferred entry can never reachCONFIRMED, an inferred upsert of a confirmed entry is refused with its reason, and persisted state that violates an invariant is dropped on load.- The glossary is persistent project state on the existing project ontology; the flat
terminologymap is now a derived, non-authoritative projection. record_orientationcapturesaliases,scope,confidenceand an explicitconfirmedByUser; unset means inferred, which always yieldsPROVISIONAL.resolveTerm()returnsexact | alias | deprecated | ambiguous | conflicted | unknown— semantic alignment, not language policing: a harmless alias is the accept-silently case and no kind blocks work.
Verification (fresh, after every change)
node --test284/284, including 17 terminology tests covering the ten required scenarios each paired with its non-overreach counterpart.scripts/verify.sh23/23;check-docsgreen; packaging verified from a fresh profile.- Tested versions: Node v24.21.0, TypeScript 6.0.3, DSH 0.2.1-alpha.1 (Verified),
PROMPT_VERSION0.5.0 at 2,806 bytes.
Intentionally not run, and not claimed
- Gates C and D remain unmeasured.
eval/seeds the two arms and scores the filesystem, but its step 2 is "the subject is a real agent run" — which this repository does not execute. No behavioural result is claimed for this revision.
Frozen baseline
v0.12.0. Any change to governance behaviour invalidates this baseline and requires re-freezing and re-running the evaluation.
Known limitations
Gates C/D unmeasured; confirmedByUser is asserted by the agent and cannot be independently verified; cross-document contradiction detection is not implemented; the CI host job depends on an upstream npm package remaining installable.
dsh plugin --profile ieg-test add https://github.com/ccneedb/dsh-information-environment-governancedsh-information-environment-governance v0.11.0
Batch 6 — the information environment maintenance round. IEG stops only governing actions and starts maintaining the environment, inside a capability boundary it states rather than assumes.
Added
maintain_environment— one manually triggerable, read-only maintenance round: inventory (8 classes), diagnosis (7 dimensions), proposed actions from a fixed vocabulary (KEEP | MERGE | UPDATE | REPLACE | DEPRECATE | REMOVE | LEAVE_UNCHANGED | REQUIRES_REVIEW), each with a reason and a confidence, plus unresolved-issue reporting. It proposes and never applies; destructive proposals need an explicit human decision.- Seven-instruction-batch trigger — counted through the host's own turn accounting (
agent/pre-stepturn+ inbox messages), so internal steps, tool calls and generated context are excluded by construction. At seven, maintenance is marked due; a completed round resets the counter. - Role-aware placement governance — duplication now requires the same functional role and that the information is not materially distinct. Lexical similarity alone no longer decides it.
- Change-impact reconciliation —
maintain_environment { changed }names affected artifacts, declared drift and unresolved inconsistencies. - Prompt
PROMPT_VERSION0.4.0 → 0.5.0: 2,806 bytes (from 2,677), inside the unchanged 2,945-byte ceiling.
Stated boundaries (not claims)
- Cross-document contradiction detection beyond declared state is not implemented; a free-text staleness scan was written, run against this repository, and removed after producing ten false positives on a healthy tree.
- Nothing is applied automatically.
- The full twenty-rule mapping to deterministic / heuristic / guidance is in
MAINTENANCE-HANDOFF.md§3.
Verification
- 19 new tests:
npm test267/267,scripts/verify.sh23/23,check-docsgreen. - A real round over this repository: 24 artifacts,
DEPRECATE=1 LEAVE_UNCHANGED=22 KEEP=1, unresolved = 0.
dsh plugin --profile ieg-test add https://github.com/ccneedb/dsh-information-environment-governancedsh-information-environment-governance v0.9.3
Documentation convergence and automated enforcement. No runtime behaviour changed; every change is documentation, tests or drift detection.
Documentation
TESTING.mdnow describes the two-command prompt CLI andenabled: falseas the way to turn governance off (ieg_statusfor state capture).docs/PACKAGE-REFERENCE.md: one prompt-CLI capability row; the whole surface stated; the control-record,prompt resetand npm-lifecycle sections replaced by the host-owned installation model; theieg.control_*codes removed from the vocabulary.ARCHITECTURE-SPEC-AGENT-REFERENCE.md§28.6 rewritten to the reduced surface, with the removed machinery recorded as removed rather than erased, and prompt resolution documented as per-assembly.MAINTENANCE-HANDOFF.mdnamesenabled: falseinstead of a per-agent pause that no longer exists;README.md,TYPESCRIPT-MIGRATION.mdanddocs/DOCUMENTATION-INDEX.mdmentions are explicitly historical.
Surviving mentions of the removed commands are negative or historical statements — which is what a changelog and a design record should carry.
Enforcement
- TypeScript-only is asserted by the suite:
src/**holds only.ts, no hand-written JavaScript at the repository root, no hand-written tooling in the build output. Exceptions:lib/**(generated),bin/ieg(host-mandated shim),scripts/,eval/,test/. - Release-metadata drift is asserted: one version agrees across
package.json,PLUGIN_VERSION, the newest changelog heading and every document'splugin_version, and the committed baseline names the declared peer baseline.
dsh plugin --profile ieg-test add https://github.com/ccneedb/dsh-information-environment-governanceVerified: npm test 248/248, scripts/verify.sh 23/23, check-docs.sh green. Prototype: Gates C and D remain unmeasured.
dsh-information-environment-governance v0.9.2
Batch 5 — architecture simplification, installation consolidation and source-language governance.
Removed
dsh-ieg install/update/uninstall, the profile-name validation, the npm wrapper scripts and their tests — a plugin cannot install itself.- The 0.6.0 control plane:
start/pause/restart/exit/status, the durable control record, its mtime cache, the generation counter, the ANSI menu,prompt reset, and the fiveieg.control_*diagnostics. Turning governance off isenabled: falsein the row config — one mechanism, not two.
Changed
dsh-iegis a prompt CLI:promptandprompt edit, plus--help/--version. No installation surface.- Exactly two official installation paths:
dsh-marketand DSH's native plugin installation (dsh plugin --profile <p> add <source>). Updates are deliberately "remove the old installation, install the new one". - The prompt file resolves from
$IEG_PROMPT_FILE, else<state-dir>/ieg/prompt.md.
Fixed (both caught by the release gate)
- Removing the control plane also removed the per-assembly re-read of
prompt.md; the section re-resolves it now, as before. ieg_statusreported the mount-time prompt source while the section emitted the live text; both now read one live resolution.
Added
- TypeScript is the only hand-written runtime language, stated in CONTRIBUTING and enforced by the packaging suite (
lib/**is generated;bin/iegis the host-mandated shim). - The gate proves the removed commands are gone rather than hidden.
External
- Submitted to the curated DSH plugin list: awesome-dsh-plugin PR #6521.
Install (the two official paths):
dsh plugin --profile ieg-test add https://github.com/ccneedb/dsh-information-environment-governance
# or through dsh-market, once listedVerified: npm test 246/246, scripts/verify.sh 23/23, check-docs.sh green. Prototype: Gates C and D remain unmeasured, and full documentation convergence is the next pass (README and TESTING are updated).
dsh-information-environment-governance v0.9.1
Prototype release for volunteer testing. Gates C and D remain unmeasured.
Batch 4 — distribution and installation-path repair.
- The bootstrap contradiction is fixed. The docs told users to run
dsh-ieg install …first, butdsh-iegships with the package, so a clean machine answersbash: dsh-ieg: command not found. Every first-install flow now uses the host's own installer:dsh plugin --profile <p> add <registry-name|path|git-url|tarball>. dsh-iegis post-install only, and its real invocation is documented:"$DSH_HOME/profiles/<profile>/node_modules/.bin/dsh-ieg"(pnpm installs it into the profile, not onto PATH).- The package is publishable:
privateremoved,publishConfig.access: public,dsh-pluginkeyword. Not published — the registry name is unclaimed and publication remains the gated release action. - Discovery uses the ecosystem's existing mechanism: npm keywords plus GitHub topics (
dsh-plugin,dsh,deepseek-harness,information-environment). - Release gate now packs the artifact, installs that tarball into a fresh profile through the DSH-native command and asserts composition, runtime, bundle patch and the profile-local CLI: 27 checks, up from 22.
Install (normal user path):
dsh plugin --profile ieg-test add https://github.com/ccneedb/dsh-information-environment-governanceVerified: npm test 272/272, scripts/verify.sh 27/27, check-docs.sh green. No runtime governance change; PROMPT_VERSION stays 0.4.0.
dsh-information-environment-governance v0.9.0
Prototype release for volunteer testing. Not production-ready: Gates C and D remain unmeasured and the package stays private: true.
Batch 3 — prompt optimization, positioning, and a read-only tool fix.
- Prompt re-baselined under the runtime/state/prompt division: 2,922 → 2,677 bytes (−8.4 %),
PROMPT_VERSION0.3.0 → 0.4.0. Each change is recorded inCHANGELOG.mdas change → reason → expected effect → regression check. Nouser-attentionguidance needed removing (it left in 0.7.0). No behavioural improvement is claimed. ieg_statusfixed: it declaredrender: () => [], so calls succeeded and showed the caller nothing. It now renders its canonical value; the wiring suite asserts the rendered content.- Positioning: the README answers what it is, what it governs, what it does not govern and who it is for, states the product message as an intended benefit (not a guarantee), and adds a concise Chinese section preserving 信息环境 / Information Environment.
- Live findings recorded: a delegated session has no approval channel, so the default
workspace.policy: askdenies its writes (fail-closed by design); the release gate no longer hardcodes versions.
Install from the attached tarball:
dsh-ieg install --profile ieg-test --from \
https://github.com/ccneedb/dsh-information-environment-governance/releases/download/v0.9.0/dsh-information-environment-governance-0.9.0.tgzOr from the repository root (the root is the package):
dsh plugin --profile ieg-test add https://github.com/ccneedb/dsh-information-environment-governanceVerified: npm test 272/272, scripts/verify.sh 22/22, check-docs.sh green, gate-precision unchanged (false_block_rate = 0).
dsh-information-environment-governance v0.8.0
Prototype release for volunteer testing. Not production-ready: Gates C and D remain unmeasured and the package stays private: true.
Batch 2 — install fix and DSH migration.
- Install fixed. The repository root is now the installable DSH component and declares
dsh.bundle.patch. Previously the package lived in aplugin/subdirectory and the repository root had no manifest, so DSH refused a Git install withnot-a-bundle("declares no dsh.bundle"). Verified end to end:dsh plugin add <git URL>installs 0.8.0 and the installed artifact mounts. - Baseline migrated to the single supported host baseline
dsh 0.2.1-alpha.1; the compatibility baseline was re-captured (identical section order, host prompt hashceb63ee5, required capabilities). No legacy compatibility layer. - Runtime migrated to TypeScript:
src/**/*.tsis the source of truth andlib/**is committed build output. - Structural regression added (
test/integration/packaging.test.js) plus thebounded-repair(OBJ-3) workspace-hygiene evaluation scenario.
Install from the attached tarball:
dsh-ieg install --profile ieg-test --from \
https://github.com/ccneedb/dsh-information-environment-governance/releases/download/v0.8.0/dsh-information-environment-governance-0.8.0.tgzOr from the Git repository:
dsh plugin --profile ieg-test add https://github.com/ccneedb/dsh-information-environment-governanceVerified: npm test 272/272, scripts/verify.sh 22/22, check-docs.sh green.
ABG v0.6.0 — terminal interface (breaking)
Breaking change. ABG is now driven from a Debian shell by abg; the Web GUI route and the in-harness feedback feature are removed.
The interface
abg # ANSI menu (the TUI)
abg start | pause | restart | exit
abg install | update | uninstall [--profile P] [--from <tarball|dir>]
abg prompt | abg prompt edit | abg prompt reset
abg status [--json]
pause takes effect from the next step without restarting the harness: the prompt section is withheld and the enforcement hooks pass through. exit stops governance for the profile and never uninstalls. The prompt text lives in a sibling prompt.md, validated with the same rules as before (no {{ }}, byte ceiling) — a refused edit changes nothing and says why. restart reloads configuration and re-reads prompt.md.
Removed
The Web client bundle, the /api/abg/* routes, the webServer seam, the gui configuration block, the feedback kernel, the abg_report_issue tool and the failure-report template. Deviation reports are ordinary GitHub issues again. The diagnostics ring and its opt-in mirror stay: the CLI is now the reader.
Fixed in this release
abg status | headdied with a stack trace and a non-zero status (EPIPE) — ordinary shell usage.--from <directory>crashed with EISDIR; a relative--homebypassed the live-home guard.npm run typecheckfailed on a missingAbgStats.size; the gate's generation-reload probe used a non-monotonic clock.
Gates: build ok, typecheck 0, 284 tests, verify.sh 22/22 (shipped-patch proof, CLI smoke, prompt-refusal round-trip, paused-suppression), check-docs ok, npm lifecycle 16/16.
ABG v0.5.1 — default installs fixed
Fixes a defect that made every default install of 0.4.0 and 0.5.0 inert.
The shipped cordis.patch.yml carries prompt.file: '' and diagnosticsExport.file: '' — documented values meaning "none"/"off" — but both were validated with a non-empty-string rule. buildGovernance() therefore threw on the shipped configuration, and because apply() must not throw (§26.2) ABG fell into its fault surface: no prompt section, no hooks, no tools, no GUI route, with nothing reported by the host. Since 0.4.0 a default install contributed nothing at all.
Also in this release:
- The panel needs a Web profile. A
headlessprofile composes no web app, sodsh --profile abg-test "<task>"can never show one;scripts/check-install.shtells the cases apart and names the Web-capable profiles. - The gate can see this bug class: the installed-artifact proof applies the shipped patch verbatim instead of
{}, with a negative control proving it bites. - npm-native lifecycle:
scripts/abg-npm.shplus a 16-assertion check. Verified host fact: plainnpm installdoes not registerdsh.profile.bundles, so the helper maintains it;dsh pluginitself forwards to pnpm. - First TypeScript slice: three kernel modules now have
.tssources with emitted JS and declarations as build artifacts. - Documentation: an index with one authoritative home per information kind, link and front-matter checking in CI, known-limitations collapsed to a single copy.
Gates: verify.sh 12/12 · npm lifecycle 16/16 · check-docs ok · 265 tests.