Skip to content

fix(dsh): qualify 0.2 installs and require the Windows-safe CLI - #5589

Open
loopx-agent wants to merge 8 commits into
mainfrom
codex/dsh-install-repair
Open

loopx-agent wants to merge 8 commits into
mainfrom
codex/dsh-install-repair

Conversation

@loopx-agent

@loopx-agent loopx-agent commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

DSH Hub resolves this repository to its root Git URL when it cannot discover a published plugin package. The root has no plugin entry point, causing the repeated entry file missing index.js incidents. Older release artifacts also lack qualified 0.2 host support, and bootstrap previously accepted an outdated global LoopX CLI that predates the released Windows peer-file fix.

This change prepares a qualified dsh-loopx-plugin@0.1.1-beta.6 and its distribution path. It does not claim that the marketplace incidents are closed before publication and catalog adoption.

  • Pin development/host/Client packages to DSH 0.2.0-rc.2, retain the supported 0.1.5 and explicit 0.1.7 peer ranges, register the plugin's initialization message source, and reset Session state on agent/created while retaining the legacy lifecycle event. Initialization notices do not activate the Driver.
  • Share a LoopX 1.2.4 minimum across bootstrap, Driver and GoalBar. Default discovery skips older CLIs and installs a compatible isolated runtime when needed; an explicit outdated LOOPX_BIN fails with recovery guidance before pip or skill mutation. The Windows peer-file fix itself already shipped in 1.2.4 and is not duplicated here.
  • Add real DSH package-name installation/removal checks on Linux and Windows, npm discovery metadata, and readback that rejects incorrect latest, artifact integrity or repository search selection.
  • Prepare manual npm trusted publishing from a merged, already published GitHub release tag. Publish the downloaded release bytes without rebuilding, then verify npm bytes and marketplace discovery. Account ownership and trusted-publisher configuration remain required.
  • Link the proposed no-npm marketplace repair dsh-plugin-hub #93, which consumes the online catalog’s existing authoritative release command and preserves install/readback/update/removal identity.
  • Replace stale compatibility/checkpoint text and document native local-tarball recovery. The lockfile change follows the pinned 0.2 dependency graph.

The existing independently distributed DSH provider owns this repair (S4/S10 harness selection, #5208). /loopx-init and the existing DSH GoalBar/Driver use the same typed CLI owner; no new LoopX capability, configuration switch, or parallel Python decision owner is introduced. The future-facing pass keeps Connection Peer admission upstream and narrows the existing business callback instead of recreating transport authority. loopx-initialization extends upstream MessageSourceMap as a plugin-local notice kind. The semantic advisory does not scan this provider directory; its empty output is not equivalence evidence.

Validation on Node 24 / pnpm 10.33.0:

  • Type checks, peer-range qualification and 206 tests passed, including old-version, explicit-override, lifecycle and non-activation negative cases.
  • Packed artifact and profile checks passed. Real DSH web startup and shared carrier/service checks passed on 0.2.0-rc.2, 0.1.7-rc.2 and the original frozen 0.1.5 dependency graph. A fresh floating 0.1.5 graph fails upstream app-boot/HMR startup on both original and repaired artifacts; it is not reported as qualified.
  • Real package-name install loaded the exact bundles and all four plugin rows, rejected wrong tag/discovery/integrity, and removed the plugin successfully. Published beta.5 to candidate upgrade and incompatible-peer rejection passed.
  • Real isolated PyPI 1.2.4 bootstrap from an old global CLI, native workflow-skill installation/readback and idempotent reopening passed, without model calls or active goal mutation.
  • Refresh locked http-cache-semantics to compatible 4.3.0 (within the consumer’s ^4.2.0 range), with frozen installation, 206 tests and the real 0.2 runtime passing again. No vulnerability allow-list is added. GitHub’s advisory flags 4.2.0; the upstream maintainer disputes that report. This update does not claim the advisory was withdrawn. A raw policy reuse probe failed an assumption about non-storable entries; actual cacheable-request HTTP validation confirmed that private/no-store responses never enter reusable storage, including a subsequent max-stale request.
  • Full semantic validation, public-boundary scan of all 22 changed paths, DCO and diff checks passed.
  • The broad premerge canary was not green: DSH checks initially raced dependency preparation and passed sequential reruns; generic install/package checks lacked dashboard build prerequisites; the CLI lifecycle NoneType.todo_id failure was reproduced on the original baseline. These are distinguished from the focused passing checks above.

Remaining acceptance: final-head Linux/dependency/frontstage CI; final-head Windows packaging/install/removal and DCO passed; mounted-browser Start/Pause evidence and Docker checks are not claimed. Beta.6 GitHub release, the required personal release guide and verified marketplace adoption remain release gates. npm publication is needed for the current Hub’s npm route; Hub #93 proposes a direct release route and still needs upstream review/release/adoption; its fork CI is action_required with no executed jobs, awaiting upstream authorization. Its built backend passed a live-catalog/native-DSH HTTP installation, fixed-URL update and removal in a disposable profile; a mounted Hub browser interaction is untested. Source qualification alone does not restore live marketplace installation. Runtime changes require maintainer merge.

Related: #5580, #5545, #5530, #5505, #5443, #5510, #5428, #5427, #5511, #5208.

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
…acts

Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
Signed-off-by: LoopX Agent <337587101+loopx-agent@users.noreply.github.com>
@loopx-agent
loopx-agent force-pushed the codex/dsh-install-repair branch from 37312ef to 5b4a885 Compare October 4, 2026 15:28
@mikamikasuki

Copy link
Copy Markdown

The failed dependency-review check is explained by @deepseek-ai/libreoffice-kit@0.1.5 resolving fflate@0.8.2 in this lockfile. The lockfile also contains fflate@0.8.3 for another dependency path, but that does not remove the vulnerable 0.8.2 resolution. GitHub advisory GHSA-px8p-9vwx-vf98 lists 0.8.0–0.8.2 as affected and 0.8.3 as patched. Please update the affected transitive resolution (or its parent) to a patched version and rerun dependency review.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants