@dsh-lattice/adapter-dsh
DSH Lattice V1 provider adapter for the DeepSeek Harness public seam.
This package is an independent community adapter, part of the
DSH Lattice facade project. It is not
affiliated with, endorsed by, or sponsored by DeepSeek AI, and it does not
import the upstream @deepseek-ai/dsh-root package.
What it provides
| Module | Responsibility |
|---|---|
capabilities |
Capability detection: required-vs-observed comparison that fails loud (ECC-V1.0 §12, §22.2) |
session-mapping |
Canonical agentId ↔ session mapping, identity kinds, explicit SessionLink lineage, compatibility fingerprints (§10, §16.3) |
events |
Lattice/audit events with REQUIRED tenantId, secret redaction <redacted:kind/name>, leak scan (§19.3, §19.4) |
manifest |
Adapter manifest validation; credentialRef references only — values are never inlined (§12, §19.3) |
adapter |
DshAdapter implementing the Lattice adapter contract over a minimal SubagentsSeam |
Quick start
import { createDshAdapter } from "@dsh-lattice/adapter-dsh";
const adapter = createDshAdapter({
id: "dsh-sdk",
descriptor: {
name: "dsh-sdk",
package: "@dsh-lattice/adapter-dsh",
adapterVersion: "1.0.0",
requiredCapabilities: ["continuation", "directMessage", "structuredOutput", "progress"],
observedCapabilities: ["continuation", "directMessage", "structuredOutput", "progress", "oneShot"],
credentialRef: { kind: "env", name: "DSH_SDK_TOKEN" },
},
seam: harnessCtx.subagents, // the live ctx.subagents object
});
// Fail-loud gate before a run starts:
const preflight = adapter.preflight(["continuation", "artifacts"]);
if (!preflight.ok) {
// capability_mismatch: missing [artifacts]
}
const envelope = await adapter.runOneShot({
prompt: "review this diff",
tenantId: "tenant_1",
runId: "run_1",
taskId: "tsk_1",
assignmentId: "asn_1",
idempotencyKey: "idem_...",
});
Capability detection
requiredCapabilities come from the project config; observedCapabilities
come from the adapter manifest plus a runtime probe refreshed on every
startup. If observed ⊉ required the adapter emits
lattice/adapter/capability_mismatch and the run is rejected — never
silently degraded.
Session mapping (ECC-V1.0 §10)
| Provider kind | canonical agentId |
lifetime |
|---|---|---|
| local in-process | canonical name + DSH sessionId |
durable |
| ACP subprocess | adapter-assigned name + ACP session id | durable |
| A2A remote | cardId#a2aTaskId |
durable |
| one-shot (Codex/Claude Code) | canonical name | ephemeral — run-scoped only |
Identity changes (fork/resume/handoff) are recorded only via explicit
SessionLink pointers — never implicit.
Security
See SECURITY.md. Highlights: no shell, capability
fail-loud, credentialRef indirection (presence-only resolution), secret
redaction on every event, explicit lineage.
Upstream compatibility evidence
Facts below were checked against the upstream repository checkout in this
workspace (deepseek-harness/, as of this writing):
- Upstream package is
@deepseek-ai/dsh-root0.1.0-rc.5,"type": "module", pnpm-managed, and is Cordis-based (scriptsverify-cordis-config,
gen-cordis-catalog,gen-cordis-api;cordis.patch.ymlfiles in
packages/bundle/*). - The harness context exposes
ctx.subagentswith
registerProvider(...),start(providerId, options),
startContinuable(...),interrupt(...), andlistChildren(...)
(seepackages/sdk/server/tests/server.spec.ts,
packages/subagent/subagent/README.md, and the subagent capability-seam
notes).DshAdapterdepends only on this documented subset via the
SubagentsSeaminterface, so it can be wired to a real harness context
without a hard upstream dependency. send_message/interrupt_agentare parent-child limited. The tools
live inpackages/subagent/tool-subagent-control/src/index.ts;list_agents
documents that only depth-1 direct children aresend_messagecandidates
and deeper entries areinterrupt_agent-only. The Latticeagent_message
shim preserves this constraint (see the aggregator package).- The upstream SDK protocol client frames JSON-RPC 2.0 as one compact JSON
frame per\n-terminated line (packages/sdk/protocol/README.md) — this
is the framing the@dsh-lattice/transportsACP client mirrors. - Upstream ships an MCP client, not a public MCP server; the
exactly-one-tool MCP server in@dsh-lattice/transportsis therefore a
Lattice-owned boundary, not an upstream feature.
What is NOT verified
- No real DeepSeek Harness provider was launched in this workspace (no
credentials, and upstream is developer preview). The seam contract is
compile-time verified against the documented API subset, not executed
against a live harness runtime. - Protocol versions (MCP/ACP/A2A) are pinned per release manifest; re-verify
before publishing (ECC-V1.0 §22.3).
Development
pnpm install # offline-capable from the pnpm store
pnpm build # tsc → dist/
pnpm typecheck
pnpm test # vitest
pnpm coverage