Skip to content

dsh-loopx-plugin 0.1.1-beta.6

Pre-release
Pre-release

Choose a tag to compare

@loopx-agent loopx-agent released this 05 Oct 12:56
5eee730

dsh-loopx-plugin 0.1.1-beta.6

An independently versioned DeepSeek Harness plugin release. This is a prerelease of the plugin; the current LoopX core release remains independently versioned.

Illustrated personal Feishu installation and upgrade guide · Versioned plugin documentation

Product changes

  • Qualify the DSH 0.2.0-rc.2 Host/Client boundary, retaining the qualified frozen 0.1.5 and 0.1.7-rc.2 ranges. Native Connection receives the SDK peer while business handlers receive their three business arguments. Driver reconciles newly created Agents; initialization uses its own typed message source.
  • Require the published LoopX 1.2.4+ CLI consistently for bootstrap, Driver and GoalBar. This carries the already released Windows peer-file fix into plugin setup; incompatible explicit CLI overrides fail with actionable guidance.
  • Repair source upgrades and qualify unversioned package-name installation/removal on Linux and Windows. Automatic initialization prepares private CLI/runtime and workflow skills before web readiness. Explicit /loopx-init retains its two notification turns.
  • Since beta.5: shared authenticated GoalBar transport, exact-Session binding and typed skill activation, private .loopx state, Python interpreter discovery without fixed minor lists, and per-Goal shadow diagnostic ledgers. Shadow observation remains opt-in and read-only.
  • Optional npm trusted publishing consumes the exact GitHub tarball without rebuilding. GitHub distribution works without an npm account through released Hub 1.4.14.

Community Contributors

Contributions are derived from the beta.5-to-beta.6 package/workflow Git range and merged PR metadata.

  • First-time external contributor @catwithtudou — isolated shadow diagnostic ledgers by exact Goal identity (#5441).
  • External community contributor @LIHUA919 — unified default local state under .loopx with explicit migration (#4915).
  • External community contributor @DJC1412 — corrected live package references to the canonical repository (#4776).
  • Community contributor @songoow — removed fixed Python-minor lists from interpreter discovery (#4482).

Compatibility and adoption

Node.js 22.19+, pnpm, Python 3.11+ and pip are required. Reproducible qualification uses pnpm 10.33.0. First CLI bootstrap needs network access unless a compatible CLI is already available; it uses a private runtime and respects PEP 668.

The live marketplace still points to beta.5 at publication; catalog PR #6633 updates its existing pinned asset row. Hub #98 must be merged and released to recognize installed GitHub packages correctly. Catalog adoption and upstream Hub release remain separate owner gates; use the pinned asset meanwhile.

Release Decision

Who should upgrade: DSH plugin users moving to DSH 0.2.0-rc.2, repairing source upgrades, or needing the Windows-safe LoopX CLI floor.

What this release solves: Published plugin bytes now match the qualified 0.2 API and enforce CLI 1.2.4+; GitHub distribution and recovery are usable while upstream market adoption is pending.

Breaking changes: Yes. Minimum LoopX CLI is now 1.2.4; automatic bootstrap upgrades compatible installs, but owners must upgrade an explicitly pinned outdated LOOPX_BIN. Existing legacy shadow ledgers require explicit offline migration, with no silent history rewrite.

How to verify: Restart DSH, verify beta.6 and four loaded components in the native plugin view, read the initialization result, then resolve the exact Session binding inside that Session. A global CLI version alone does not identify the managed runtime.

loopx --version
loopx --registry .loopx/registry.json --format json resolve-agent-thread \
  --host-surface deepseek-harness-native --thread-id "$DSH_SESSION_ID"

Contributors: @catwithtudou, @LIHUA919, @DJC1412, @songoow; concrete contributions are linked above.

Optional Capability Activation & Use

DSH LoopX plugin

Activation: Install the pinned package into the web profile and restart DSH. Invoke /loopx with your task in the exact Session; installation prepares skills but does not create a Goal binding or activate the Driver.

dsh plugin --profile web add "https://github.com/loopx-project/loopx/releases/download/dsh-loopx-plugin-v0.1.1-beta.6/dsh-loopx-plugin-0.1.1-beta.6.tgz"
dsh --profile web --port 0
loopx --version
loopx --registry .loopx/registry.json --format json resolve-agent-thread \
  --host-surface deepseek-harness-native --thread-id "$DSH_SESSION_ID"

Validation: Native plugin view reports beta.6; initializer verifies CLI 1.2.4+ and skill files. A unique bound pair admits GoalBar. Start resumes a stopped Goal and only evaluates an already skill-activated Session; Pause retires future continuation without aborting a running turn.

Disable / rollback: Close DSH, run dsh plugin --profile web remove dsh-loopx-plugin, then restart DSH. Native browser hot uninstall disconnected the server before dependency removal in qualification; that GUI path remains failed. Keep existing Goal/evidence data. To restore beta.5, install its fixed GitHub tgz only with a DSH version supported by beta.5; do not blindly downgrade on 0.2.

Authority boundary: No binding, model-tool grant, scheduler authority or remote access is created by installation. LoopX owns Goal/Agent/Todo/quota and durable bindings; the authenticated carrier enforces DSH trust fences. Explicit repair may issue its existing two model notifications.

Docs: Versioned installation, control and privacy contract.

DSH shadow observer

Activation: Default off. Before DSH starts, set all three variables with one exact Goal, Session and complete run identity; use your actual identities instead of the demo values.

export LOOPX_DSH_SHADOW_OBSERVER_GOAL_ID="my-goal"
export LOOPX_DSH_SHADOW_OBSERVER_SESSION_ID="$DSH_SESSION_ID"
export LOOPX_DSH_SHADOW_OBSERVER_RUN_IDENTITY_JSON='{"worker_id":"demo-worker","model_id":"demo-model","task_id":"demo-task","environment_id":"demo-env","tools_id":"demo-tools","budget_id":"demo-budget","adapter_revision":"beta.6","observer_revision":"beta.6"}'
loopx reliability-diagnostics receipt --goal-id my-goal --format json
loopx reliability-diagnostics status --goal-id my-goal --format json

Validation: Read the receipt/status for that Goal, inspect source coverage and count conservation. An existing legacy ledger blocks flush until the linked offline upgrade preserves history. C0/C1 fidelity and measured overhead are still separate acceptance work.

Disable / rollback: Unset LOOPX_DSH_SHADOW_OBSERVER_GOAL_ID, LOOPX_DSH_SHADOW_OBSERVER_SESSION_ID and LOOPX_DSH_SHADOW_OBSERVER_RUN_IDENTITY_JSON, then restart DSH; retain existing diagnostic data. Disable before rolling back older ledger readers.

Authority boundary: Read-only typed event metadata; no prompts, arguments, tool output or paths. No agent sends, scheduling, retries, stop/resume or CLI business calls; isolation is at module/hooks, not an OS process boundary.

Docs: Versioned observer setup and offline legacy-ledger upgrade.

npm trusted publishing

Activation: Optional maintainer route. The npm package owner must configure Trusted Publisher for loopx-project/loopx, workflow dsh-plugin-publish.yml, allowing npm publish; then dispatch on this published tag. No npm owner is currently configured by this release.

gh workflow run dsh-plugin-publish.yml --repo loopx-project/loopx \
  --ref dsh-loopx-plugin-v0.1.1-beta.6 \
  -f release_tag=dsh-loopx-plugin-v0.1.1-beta.6
npm view dsh-loopx-plugin version dist-tags dist.tarball --json

Validation: The workflow verifies merged-tag provenance, downloaded GitHub asset bytes, npm metadata, dist tag and repository discovery; it publishes the compiled tgz without rebuilding.

Disable / rollback: Do not dispatch the manual workflow, or remove its npm Trusted Publisher association as the npm owner. Use the GitHub asset channel. A previous npm dist tag can be restored only by the package owner after compatibility verification.

Authority boundary: GitHub identity does not create an npm account, establish package ownership, grant npm publish rights, or replace upstream marketplace merge/release authority.

Docs: Versioned optional npm handoff.

Validation and recovery

206 tests and the 0.2 Host/Client/test typechecks passed. Merged code CI passed on Linux and Windows for package-name install/remove. Packed real SDK/HTTP and VM Client lifecycle checks passed; those fixtures are not a mounted Windows desktop journey. Real macOS DSH 0.2 browser verification of the published URL loaded four beta.6 components, returned the initializer success result, and passed mounted Start/Pause with an isolated synthetic Goal and preconfigured unique binding. The released CLI 1.2.4 read back active/stopped; an unactivated Session added no model turn. A clean Linux container bootstrapped the released LoopX 1.2.4 wheel, skills, authentication and GoalBar readback under PEP 668. The original source-wheel Docker script did not pass unchanged because the Chat bundle was unbuilt; the release-wheel qualification used a private harness without cache-mount or bind-mount assumptions.

Native published beta.5-on-compatible-DSH-0.1.5 to beta.6-on-0.2 upgrade/removal and offline tgz install/removal passed. Released Hub 1.4.14 plus #98 candidate Client logic passed the proposed beta.6 catalog install/identity/pinned update/removal; it is not the live released market. Windows/DSH 0.2 full marketplace install, init, Start/Pause, upgrade and removal remain unverified on a real Windows desktop. Upstream #98 and catalog release are pending. The Windows desktop-host missing CLI module reported in #5671 occurs before plugin loading and remains an upstream/Windows packaging gate. Native browser hot uninstall failed with the Web service disconnected and package dependency retained; the passing removals above use CLI/backend fixture paths. Network timeouts remain external failure cases; retry the exact URL after connectivity recovers. An offline tgz covers only the plugin: compatible DSH/pnpm/Python/CLI or their caches must already be present.

dsh plugin --profile web add ./dsh-loopx-plugin-0.1.1-beta.6.tgz --offline --ignore-scripts

Asset SHA-256: 5c36776ded02ea330f560fa5395ed8deef144b59690ac15353df1c7263474a90. Canonical remaining acceptance tracking.

中文摘要

插件修复与升级

  • 独立插件 beta.6 对齐 DSH 0.2.0-rc.2 的 Host/Client API,并保留已资格验证的冻结旧版本范围;修复 Connection 参数传递、Agent 创建回读与初始化消息类型。
  • 初始化、Driver、GoalBar 统一要求已发布的 LoopX 1.2.4+,让 Windows peer 文件修复进入实际插件安装路径;显式指定的旧 CLI 需要其所有者升级。
  • 修复源升级,验证 Linux/Windows 包名安装与移除;自动初始化准备私有 CLI 和技能,显式 /loopx-init 保留两次通知 turn。
  • 从 beta.5 累计包含共享认证 GoalBar、精确会话绑定、技能激活、.loopx 默认状态、无固定小版本列表的 Python 发现与按 Goal 隔离的只读诊断账本。
  • GitHub 包分发不依赖 npm 账号;可选 npm trusted publishing 仍需要真实 npm 包所有权配置。市场目录仍是 beta.5,Hub #98 合入并发行前,前端已安装识别仍有遗漏。

社区贡献者

按 beta.5 到 beta.6 的插件及工作流范围与已合并 PR 元数据归因:

  • 首次贡献的外部社区贡献者 @catwithtudou:按精确 Goal 身份隔离诊断账本(#5441)。
  • 外部社区贡献者 @LIHUA919:统一 .loopx 默认本地状态与显式迁移(#4915)。
  • 外部社区贡献者 @DJC1412:修正插件公开入口中的官方仓库地址(#4776)。
  • 社区贡献者 @songoow:移除 Python 解释器发现的小版本硬编码列表(#4482)。

兼容与验收边界

需要 Node.js 22.19+、pnpm、Python 3.11+、pip;资格验证使用 pnpm 10.33.0。首次 CLI 下载需要网络,私有安装遵守 PEP 668。Windows CI 的安装移除通过不等于 Windows 桌面完整市场验收;真实 Windows 的初始化、Start/Pause、升级、卸载仍待验证。真实 macOS DSH 0.2 浏览器已对隔离合成 Goal 与预置唯一绑定完成 Start/Pause,用已发布 CLI 1.2.4 回读 active/stopped,未激活技能的会话未增加模型 turn。公开包的原生升级移除、离线 tgz 安装移除也通过;Hub 1.4.14 后端加 #98 候选逻辑验证通过不代表上游市场已发布。原始源 wheel 容器脚本受未构建 Chat 影响未原样通过,已发布 1.2.4 wheel 的隔离容器资格验证通过。网络恢复与离线依赖需单独满足。

升级决策

谁需要升级: 使用 DSH 0.2.0-rc.2、需要修复旧源升级或 Windows CLI 下限的插件用户。

解决了什么: beta.6 的发行包对应已验证 API 和 CLI 1.2.4 下限;提供不依赖 npm 的固定 GitHub 安装与恢复路径。

是否有破坏性变更: 有,CLI 下限提高到 1.2.4;自动初始化可升级兼容安装,显式旧 LOOPX_BIN 需所有者更新,旧诊断账本需显式离线迁移。

如何验证: 重启 DSH,在原生插件详情确认 beta.6 及四个加载组件,核对初始化结果,再在同一会话读取唯一绑定;全局 CLI 版本不能代替私有 runtime 回读。

loopx --version
loopx --registry .loopx/registry.json --format json resolve-agent-thread \
  --host-surface deepseek-harness-native --thread-id "$DSH_SESSION_ID"

贡献者: @catwithtudou、@LIHUA919、@DJC1412、@songoow,具体贡献见上方链接。

可选能力启用与使用

DSH LoopX plugin

启用: 安装固定 tgz,重启 web profile;在目标会话调用 /loopx 加任务,安装本身不创建绑定或激活 Driver。

dsh plugin --profile web add "https://github.com/loopx-project/loopx/releases/download/dsh-loopx-plugin-v0.1.1-beta.6/dsh-loopx-plugin-0.1.1-beta.6.tgz"
dsh --profile web --port 0
loopx --version
loopx --registry .loopx/registry.json --format json resolve-agent-thread \
  --host-surface deepseek-harness-native --thread-id "$DSH_SESSION_ID"

验证: 原生详情显示 beta.6;初始化验证 CLI 1.2.4+ 与技能。唯一绑定时显示 GoalBar;Start 仅恢复 Goal,并只评估已经调用技能的同一会话;Pause 不打断已运行 turn。

停用 / 回退: 先关闭 DSH,执行 dsh plugin --profile web remove dsh-loopx-plugin 后重启,保留 Goal 和证据。原生浏览器热卸载验证中 Web 服务中断且依赖保留,该 GUI 路径尚未通过。回装 beta.5 固定 tgz 前先确认其 DSH 兼容范围,0.2 不应盲目降级。

权限边界: 安装不授予绑定、模型工具、调度或远程访问权;LoopX 继续持有 Goal/Agent/Todo/配额及绑定 authority,DSH carrier 保持认证与信任边界。显式修复可能发出既有两次模型通知。

文档: 固定版本安装与权限说明。

DSH shadow observer

启用: 默认关闭;启动 DSH 前提供精确 Goal、会话与完整 run identity 的全部变量,用真实身份替换示例。

export LOOPX_DSH_SHADOW_OBSERVER_GOAL_ID="my-goal"
export LOOPX_DSH_SHADOW_OBSERVER_SESSION_ID="$DSH_SESSION_ID"
export LOOPX_DSH_SHADOW_OBSERVER_RUN_IDENTITY_JSON='{"worker_id":"demo-worker","model_id":"demo-model","task_id":"demo-task","environment_id":"demo-env","tools_id":"demo-tools","budget_id":"demo-budget","adapter_revision":"beta.6","observer_revision":"beta.6"}'
loopx reliability-diagnostics receipt --goal-id my-goal --format json
loopx reliability-diagnostics status --goal-id my-goal --format json

验证: 核对同一 Goal 的 receipt/status、覆盖范围与计数守恒;旧账本必须按离线升级文档保留历史。C0/C1 与开销验收仍独立未完成。

停用 / 回退: 清除 LOOPX_DSH_SHADOW_OBSERVER_GOAL_ID、LOOPX_DSH_SHADOW_OBSERVER_SESSION_ID、LOOPX_DSH_SHADOW_OBSERVER_RUN_IDENTITY_JSON 后重启,保留既有诊断数据;回退旧读取器前先关闭观察器。

权限边界: 只记录类型化事件元信息,不含提示词、参数、输出或路径;不发送 agent turn、不调度、不重试、不停止或恢复任务、不调用业务 CLI,属于模块与 hook 隔离。

文档: 固定版本 observer 说明 与 离线账本升级。

npm trusted publishing

启用: npm 包所有者先配置 loopx-project/loopx 的 dsh-plugin-publish.yml Trusted Publisher,允许 npm publish,再对已公开插件 tag 手动 dispatch。本次未创建 npm 所有权。

gh workflow run dsh-plugin-publish.yml --repo loopx-project/loopx \
  --ref dsh-loopx-plugin-v0.1.1-beta.6 \
  -f release_tag=dsh-loopx-plugin-v0.1.1-beta.6
npm view dsh-loopx-plugin version dist-tags dist.tarball --json

验证: 工作流核对合并 tag 来源、GitHub 资产、npm 元数据、dist tag 和仓库发现;不重建包。

停用 / 回退: 不 dispatch 手动工作流,或由 npm 所有者移除 Trusted Publisher;继续使用 GitHub 包。恢复旧 npm dist tag 需先验证兼容性。

权限边界: GitHub 登录不建立 npm 账号或包所有权,也不授予 npm 发布或上游市场合并发行权限。

文档: 固定版本 npm 与市场交接。

资产校验与后续

tgz SHA-256:5c36776ded02ea330f560fa5395ed8deef144b59690ac15353df1c7263474a90。原生浏览器热卸载失败(Web 中断且包依赖保留),请先关闭 DSH 再命令行移除。#5671 的 Windows 桌面宿主 CLI 模块缺失发生在插件加载前,仍需宿主打包修复与实机回读。恢复网络后重试固定 URL;离线 tgz 只提供插件本体,DSH/pnpm/Python/兼容 CLI 或其缓存仍要提前准备。完整图文升级指南。目录 #6633、Hub #98 采用与发行,以及 Windows 实机闭环,继续由 #5208 跟踪。