henryZhouLikeStudy
dsh-lattice-adapter-dsh
DSH Lattice adapter for DeepSeek Harness: capability detection and session mapping
- Stars
- 0
- Language
- TypeScript
- Created
- Aug 14, 2026
- Updated
- Aug 14, 2026
Introduction
@dsh-lattice/adapter-dsh
DSH Lattice V1 provider adapter for the DeepSeek Harness public seam.
This package is an independent community adapter, part of the
DSH Lattice facade project. It is not
affiliated with, endorsed by, or sponsored by DeepSeek AI, and it does not
import the upstream @deepseek-ai/dsh-root package.
What it provides
| Module | Responsibility |
|---|---|
capabilities | Capability detection: required-vs-observed comparison that fails loud (ECC-V1.0 §12, §22.2) |
session-mapping | Canonical agentId ↔ session mapping, identity kinds, explicit SessionLink lineage, compatibility fingerprints (§10, §16.3) |
events | Lattice/audit events with REQUIRED tenantId, secret redaction <redacted:kind/name>, leak scan (§19.3, §19.4) |
manifest | Adapter manifest validation; credentialRef references only — values are never inlined (§12, §19.3) |
adapter | DshAdapter implementing the Lattice adapter contract over a minimal SubagentsSeam |
Quick start
import { createDshAdapter } from "@dsh-lattice/adapter-dsh";
const adapter = createDshAdapter({
id: "dsh-sdk",
descriptor: {
name: "dsh-sdk",
package: "@dsh-lattice/adapter-dsh",
adapterVersion: "1.0.0",
requiredCapabilities: ["continuation", "directMessage", "structuredOutput", "progress"],
observedCapabilities: ["continuation", "directMessage", "structuredOutput", "progress", "oneShot"],
credentialRef: { kind: "env", name: "DSH_SDK_TOKEN" },
},
seam: harnessCtx.subagents, // the live ctx.subagents object
});
// Fail-loud gate before a run starts:
const preflight = adapter.preflight(["continuation", "artifacts"]);
if (!preflight.ok) {
// capability_mismatch: missing [artifacts]
}
const envelope = await adapter.runOneShot({
prompt: "review this diff",
tenantId: "tenant_1",
runId: "run_1",
taskId: "tsk_1",
assignmentId: "asn_1",
idempotencyKey: "idem_...",
});
Capability detection
requiredCapabilities come from the project config; observedCapabilities
come from the adapter manifest plus a runtime probe refreshed on every
startup. If observed ⊉ required the adapter emits
lattice/adapter/capability_mismatch and the run is rejected — never
silently degraded.
Session mapping (ECC-V1.0 §10)
| Provider kind | canonical agentId | lifetime |
|---|---|---|
| local in-process | canonical name + DSH sessionId | durable |
| ACP subprocess | adapter-assigned name + ACP session id | durable |
| A2A remote | cardId#a2aTaskId | durable |
| one-shot (Codex/Claude Code) | canonical name | ephemeral — run-scoped only |
Identity changes (fork/resume/handoff) are recorded only via explicit
SessionLink pointers — never implicit.
Security
See SECURITY.md. Highlights: no shell, capability
fail-loud, credentialRef indirection (presence-only resolution), secret
redaction on every event, explicit lineage.
Upstream compatibility evidence
Facts below were checked against the upstream repository checkout in this
workspace (deepseek-harness/, as of this writing):
- Upstream package is
@deepseek-ai/dsh-root0.1.0-rc.5,"type": "module", pnpm-managed, and is Cordis-based (scriptsverify-cordis-config,gen-cordis-catalog,gen-cordis-api;cordis.patch.ymlfiles inpackages/bundle/*). - The harness context exposes
ctx.subagentswithregisterProvider(...),start(providerId, options),startContinuable(...),interrupt(...), andlistChildren(...)(seepackages/sdk/server/tests/server.spec.ts,packages/subagent/subagent/README.md, and the subagent capability-seam notes).DshAdapterdepends only on this documented subset via theSubagentsSeaminterface, so it can be wired to a real harness context without a hard upstream dependency. send_message/interrupt_agentare parent-child limited. The tools live inpackages/subagent/tool-subagent-control/src/index.ts;list_agentsdocuments that only depth-1 direct children aresend_messagecandidates and deeper entries areinterrupt_agent-only. The Latticeagent_messageshim preserves this constraint (see the aggregator package).- The upstream SDK protocol client frames JSON-RPC 2.0 as one compact JSON
frame per
\n-terminated line (packages/sdk/protocol/README.md) — this is the framing the@dsh-lattice/transportsACP client mirrors. - Upstream ships an MCP client, not a public MCP server; the
exactly-one-tool MCP server in
@dsh-lattice/transportsis therefore a Lattice-owned boundary, not an upstream feature.
What is NOT verified
- No real DeepSeek Harness provider was launched in this workspace (no credentials, and upstream is developer preview). The seam contract is compile-time verified against the documented API subset, not executed against a live harness runtime.
- Protocol versions (MCP/ACP/A2A) are pinned per release manifest; re-verify before publishing (ECC-V1.0 §22.3).
Development
pnpm install # offline-capable from the pnpm store
pnpm build # tsc → dist/
pnpm typecheck
pnpm test # vitest
pnpm coverage