{"_id":"@chunsi-m/dsh-trajectory-governor","_rev":"2-e600da8524ee837ebb24cadbc9c3ffee","name":"@chunsi-m/dsh-trajectory-governor","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@chunsi-m/dsh-trajectory-governor","version":"0.1.0","license":"MIT","_id":"@chunsi-m/dsh-trajectory-governor@0.1.0","maintainers":[{"name":"chunsi-m","email":"chunsi-m@outlook.com"}],"homepage":"https://github.com/chunsi-w/dsh-trajectory-governor#readme","bugs":{"url":"https://github.com/chunsi-w/dsh-trajectory-governor/issues"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"dist":{"shasum":"1d6cc722f92bfdc73c5497134ad6629e0c05e892","tarball":"https://registry.npmjs.org/@chunsi-m/dsh-trajectory-governor/-/dsh-trajectory-governor-0.1.0.tgz","fileCount":16,"integrity":"sha512-4LZKXIv4XNW8YpFavKGKQdoH7H/ETwZV7pNU2LezaJdSalM3SJTlXrEulBJ4dfSp1z2nc3jNvleiJBxUCUQ+kQ==","signatures":[{"sig":"MEYCIQDGUTM7mIpC6Xrmo1M7eUV442SW2MFVobx6AYuiLrNkeQIhAK7kT3MRKNpNsEGoKvEyP6E7sr0ahxUm+MauaxHCmMNe","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101089},"main":"./lib/index.js","type":"module","types":"./lib/index.d.ts","engines":{"node":"^22.19.0 || >=24.0.0"},"exports":{".":{"types":"./lib/index.d.ts","default":"./lib/index.js"},"./core":{"types":"./lib/core.d.ts","default":"./lib/core.js"},"./package.json":"./package.json"},"gitHead":"e24c03b259b130e6d29fd8b6d4689cf2f9af23d9","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","check":"npm run build && npm test","pack:release":"npm run check && npm pack"},"_npmUser":{"name":"chunsi-m","email":"chunsi-m@outlook.com"},"repository":{"url":"git+https://github.com/chunsi-w/dsh-trajectory-governor.git","type":"git"},"_npmVersion":"11.17.0","description":"Closed-loop trajectory policy plane for DeepSeek Harness: task episodes, continuity, information gain, verification debt, adaptive effort, and scoped capability control.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"@deepseek-ai/schemastery":"^3.18.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.8","typescript":"^6.0.3","@types/node":"^22.20.0","@deepseek-ai/cordis":"4.0.1","@deepseek-ai/dsh-llm":"0.1.0-rc.6","@deepseek-ai/dsh-agent":"0.1.0-rc.6","@deepseek-ai/dsh-tools":"0.1.0-rc.6","@deepseek-ai/dsh-session":"0.1.0-rc.6","@deepseek-ai/schemastery":"3.18.1","@deepseek-ai/dsh-plan-mode":"0.1.0-rc.6","@deepseek-ai/dsh-agent-loop":"0.1.0-rc.6","@deepseek-ai/dsh-system-prompt":"0.1.0-rc.6","@deepseek-ai/dsh-code-runtime-worker-thread":"^0.1.0-rc.6"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-llm":">=0.1.0-rc.5 <0.2.0","@deepseek-ai/dsh-agent":">=0.1.0-rc.5 <0.2.0","@deepseek-ai/dsh-tools":">=0.1.0-rc.5 <0.2.0","@deepseek-ai/dsh-session":">=0.1.0-rc.5 <0.2.0","@deepseek-ai/dsh-system-prompt":">=0.1.0-rc.5 <0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/dsh-trajectory-governor_0.1.0_1786854850689_0.11800654948084688","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@chunsi-m/dsh-trajectory-governor","version":"0.2.0","description":"Closed-loop trajectory policy plane for DeepSeek Harness: task episodes, revision-aware verification debt, benchmark-aware stop control, adaptive effort, and scoped capability control.","type":"module","main":"./lib/index.js","types":"./lib/index.d.ts","exports":{".":{"types":"./lib/index.d.ts","default":"./lib/index.js"},"./core":{"types":"./lib/core.d.ts","default":"./lib/core.js"},"./package.json":"./package.json"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/chunsi-w/dsh-trajectory-governor.git"},"homepage":"https://github.com/chunsi-w/dsh-trajectory-governor#readme","bugs":{"url":"https://github.com/chunsi-w/dsh-trajectory-governor/issues"},"publishConfig":{"access":"public"},"engines":{"node":"^22.19.0 || >=24.0.0"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-agent":">=0.1.0-rc.5 <0.2.0","@deepseek-ai/dsh-llm":">=0.1.0-rc.5 <0.2.0","@deepseek-ai/dsh-session":">=0.1.0-rc.5 <0.2.0","@deepseek-ai/dsh-system-prompt":">=0.1.0-rc.5 <0.2.0","@deepseek-ai/dsh-tools":">=0.1.0-rc.5 <0.2.0"},"devDependencies":{"@deepseek-ai/cordis":"4.0.1","@deepseek-ai/dsh-agent":"0.1.0-rc.7","@deepseek-ai/dsh-agent-loop":"0.1.0-rc.7","@deepseek-ai/dsh-code-runtime-worker-thread":"0.1.0-rc.7","@deepseek-ai/dsh-llm":"0.1.0-rc.7","@deepseek-ai/dsh-plan-mode":"0.1.0-rc.7","@deepseek-ai/dsh-session":"0.1.0-rc.7","@deepseek-ai/dsh-system-prompt":"0.1.0-rc.7","@deepseek-ai/dsh-tools":"0.1.0-rc.7","@deepseek-ai/schemastery":"3.18.1","@types/node":"^22.20.0","typescript":"^6.0.3","vitest":"^4.1.8"},"scripts":{"build":"tsc -p tsconfig.json","test":"vitest run","check":"npm run build && npm test","pack:release":"npm run check && npm pack"},"dependencies":{"@deepseek-ai/schemastery":"^3.18.1"},"gitHead":"b5520e25ae6c9e088bfa379cc90ec7b474194b58","_id":"@chunsi-m/dsh-trajectory-governor@0.2.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-ndA74AJA4rXCR6JCo7ugtbc7TYzSAHm/KyrKRmgzZBB4N73UCLwpMFerNqA1LLINLItDSsqPzJ9mT9NmffSfGg==","shasum":"c4feb965b1c2c2e41ad873147f581f0903b3486d","tarball":"https://registry.npmjs.org/@chunsi-m/dsh-trajectory-governor/-/dsh-trajectory-governor-0.2.0.tgz","fileCount":16,"unpackedSize":171278,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFhbo4XQVat8LXiaMbXGTm9WjPpZLUPwx+OhWYHmJjOqAiAhuLW6S7NR+jgFg7mzHRurhXQTPBTzWYcjbq4V0ywZkw=="}]},"_npmUser":{"name":"chunsi-m","email":"chunsi-m@outlook.com"},"directories":{},"maintainers":[{"name":"chunsi-m","email":"chunsi-m@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dsh-trajectory-governor_0.2.0_1786991042966_0.3053618381511818"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-16T04:34:10.555Z","modified":"2026-08-17T18:24:03.707Z","0.1.0":"2026-08-16T04:34:10.820Z","0.2.0":"2026-08-17T18:24:03.114Z"},"bugs":{"url":"https://github.com/chunsi-w/dsh-trajectory-governor/issues"},"license":"MIT","homepage":"https://github.com/chunsi-w/dsh-trajectory-governor#readme","repository":{"type":"git","url":"git+https://github.com/chunsi-w/dsh-trajectory-governor.git"},"description":"Closed-loop trajectory policy plane for DeepSeek Harness: task episodes, revision-aware verification debt, benchmark-aware stop control, adaptive effort, and scoped capability control.","maintainers":[{"name":"chunsi-m","email":"chunsi-m@outlook.com"}],"readme":"# dsh-trajectory-governor\n\n### ！！！在 DeepSeek pro 模型使用比较好 \n\n面向 DeepSeek Harness 的**闭环 Agent 轨迹控制平面**。它不是继续增强一句 persona，也不是把会话永久分成 spec/react，而是围绕真实事件流维护：\n\n- Task Episode 与连续性关系；\n- 当前工作阶段；\n- 结构化信息增益；\n- 修改后的验证债务；\n- workspace revision 与完整 benchmark 证据；\n- 同规格、带容差的性能回归判断；\n- 重复调用与无新信息轨迹；\n- scoped 工具能力面；\n- 显式 `finish` 与自然结束的完成门；\n- 可选的自适应 reasoning effort；\n- 本地、非模型可见的决策账本。\n\n本项目是对 `dsh-mode-boost` 的 clean-sheet 重构，不依赖 preset fork，也不依赖 super-injector。\n\n## 已实现的闭环\n\n```text\n真人消息被 inbox claim\n  -> 在第一次 prompt assembly 前建立 Task Contract\n  -> 判断 new / continuation / extension / correction / review / conversation\n  -> 必要时通过 agent.ctx.tools.restrict() 暂时隐藏 write/edit\n  -> agent/pre-step 在同一个请求内追加可重建的近场 policy message\n  -> Native tool 或 Code Mode SDK 子调用产生 durable 事件\n  -> 计算 observation novelty / mutation / verification\n  -> 修改产生 Verification Debt\n  -> readback + test/build/check 清偿当前 revision 的债务\n  -> 可选 benchmark gate 只接受当前 revision 的完整、可解析结果\n  -> 同 query count / concurrency / warmup 才比较 QPS，容差内不误判噪声\n  -> finish guard 与 turn-stopping 阻止无证据结束\n  -> 有限续步耗尽后要求模型明确报告 blocker\n```\n## 安装\n\n要求：\n\n- Node.js `^22.19.0 || >=24.0.0`；\n- DeepSeek Harness `0.1.0-rc.7`（开发与集成测试基线）；peer range 兼容 `0.1.0-rc.5` 至 `<0.2.0`。\n\n从当前目录安装：\n\n```sh\nnpm run build\ndsh plugin --profile web add .\ndsh --profile web --dump-config\n```\n\n从 npm 安装（推荐）：\n\n```sh\ndsh plugin --profile web add @chunsi-m/dsh-trajectory-governor\ndsh --profile web --dump-config\n```\n\n如需固定版本：\n\n```sh\ndsh plugin --profile web add @chunsi-m/dsh-trajectory-governor@0.2.0\n```\n\n安装 tarball：\n\n```sh\nnpm run pack:release\ndsh plugin --profile web add ./chunsi-m-dsh-trajectory-governor-0.2.0.tgz\n```\n\n包已经声明正式的：\n\n```json\n{\n  \"dsh\": {\n    \"bundle\": {\n      \"patch\": \"./cordis.patch.yml\"\n    }\n  }\n}\n```\n\n所以 `dsh plugin --profile web add ...` 会把它加入 `web` profile 的 bundle 层，而不是只安装成无效普通依赖。\n\n## 配置\n\n`cordis.patch.yml` 默认配置：\n\n```yaml\n- insert:\n    - id: trajectory-governor\n      name: '@chunsi-m/dsh-trajectory-governor'\n      config:\n        mode: active\n        adaptiveReasoning: false\n        restrictBeforeEvidence: true\n        autoVerify: true\n        maxAutomaticContinuations: 1\n        exposeStatusTool: true\n        ledger: true\n        maxLedgerBytes: 10485760\n        benchmarkRequired: false\n        benchmarkToolNames: [run_benchmark]\n        verificationToolNames: [build_project, run_correctness_test]\n        finishToolNames: [finish]\n        fullBenchmarkMinQueries: 10000\n        fullBenchmarkMinRecall: 0.95\n        benchmarkScoreTolerancePercent: 2\n        maxActionsWithoutBenchmark: 8\n        maxStagnantFullBenchmarks: 2\n        stopRetryOnDeterministicErrors: true\n```\n\n| 字段 | 默认 | 说明 |\n|---|---:|---|\n| `mode` | `active` | `off` / `shadow` / `active`；shadow 只决策和记账，不改请求 |\n| `adaptiveReasoning` | `false` | inspect/design/recover 阶段选择模型声明的最深 effort；阶段结束后恢复 provider default |\n| `restrictBeforeEvidence` | `true` | fix/continuation 等任务在观察前临时隐藏已知专用写工具 |\n| `autoVerify` | `true` | 有完成 blocker 时允许 `agent/turn-stopping` 追加有限验证步骤 |\n| `maxAutomaticContinuations` | `1` | 每个 turn 的自动验证续步上限；耗尽后只追加一次 blocker-report 步 |\n| `noInformationLimit` | `3` | 重复且无新信息达到阈值后成为完成 blocker，取得新结果后解除 |\n| `exposeStatusTool` | `true` | 注册只读 `trajectory_policy_status` 工具 |\n| `ledger` | `true` | 写入本地 policy ledger，不进入模型历史 |\n| `ledgerPath` | `$DSH_HOME/trajectory-governor/decisions.jsonl` | 自定义账本路径 |\n| `maxLedgerBytes` | `10485760` | 活动 JSONL 达到大小前轮转；旧文件保留 |\n| `maxHintChars` | `1200` | 单条 model-visible policy hint 上限 |\n| `benchmarkRequired` | `false` | 为性能任务强制当前 revision 的完整 benchmark；普通任务保持关闭 |\n| `benchmarkToolNames` | `[run_benchmark]` | 视为 benchmark 的工具名，可按 harness 改写 |\n| `verificationToolNames` | `[build_project, run_correctness_test]` | 视为常规验证的工具名 |\n| `finishToolNames` | `[finish]` | 需要经过完成门的显式结束工具名 |\n| `fullBenchmarkMinQueries` | `10000` | 完整 benchmark 的最小 `total_queries` |\n| `fullBenchmarkMinRecall` | `0.95` | 完整 benchmark 的最小 `recall` |\n| `benchmarkScoreTolerancePercent` | `2` | 同规格 QPS 下降不超过此比例时视作噪声范围 |\n| `maxActionsWithoutBenchmark` | `8` | 缺当前完整 benchmark 时，多少成功动作后主动提醒补证据 |\n| `maxStagnantFullBenchmarks` | `2` | 同规格完整 benchmark 无实质提升后提示平台期 |\n| `stopRetryOnDeterministicErrors` | `true` | 对 HTTP 400 / `invalid_request_error` 不调用 DSH retry chain |\n| `maxTrackedResults` | `256` | 每 Agent 保留的 result fingerprint 与 benchmark best record 上限 |\n\n### 推荐上线顺序\n\n先使用 shadow mode：\n\n```yaml\nmode: shadow\nledger: true\n```\n\n确认 relation/phase 判断符合真实会话后，再切换：\n\n```yaml\nmode: active\n```\n\n`adaptiveReasoning` 默认关闭，因为改变 reasoning effort 会改变 request header 与缓存形状。应在具体 provider/model 上完成校准后再启用。\n\n## Task Episode\n\n当前确定性 relation：\n\n```text\nnew-objective\ncontinuation\nextension\ncorrection\nclarification\nreview\nconversation\n```\n\n它综合：\n\n- 指代与连续性词；\n- 文件名和 artifact 重合；\n- 与上一 objective 的词面相似度；\n- fix/build/review 语义；\n- 寒暄与短确认。\n\n第一条消息是“你好”不会永久关闭插件；下一条真实任务会建立新的 objective。\n\n## 能力面控制\n\n当前版本只把明确的 `write`、`edit` 视为专用 mutation 工具。`str_replace_editor` 是读写混合工具，只有在仍有独立 `read` 时才会被暂时隐藏。\n\n这使它不会把 Minimal preset 变成零观察能力，同时在 Code Mode 下 restriction 会自动改变生成的 TypeScript SDK，而不会删除保留 transport `run_code`。\n\n`bash`/`pwsh` 仍是混合读写工具。对 `apply_patch`、重定向、`sed -i`、`git apply`、包管理安装等常见写入签名，Governor 会保守地标记为 mutation risk：成功后递增 workspace revision 并创建需要命令验证的债务；无法确定 artifact 时不会伪造文件级 readback。Governor 仍是轨迹策略，不是安全边界；真正权限仍由官方 sandbox/approval 执行。\n\n## Verification Debt\n\n成功的 `write/edit/str_replace_editor mutation` 或高风险 shell 写入会创建验证债务。债务绑定创建它的 workspace revision，之后发生的修改会使旧 readback/test 证据失效：\n\n- 源代码：需要 readback + test/build/check；\n- 文档：需要 readback；\n- 未知 artifact：需要可执行验证。\n\n以下 shell 命令会被识别为 verification：\n\n```text\nnpm/pnpm/yarn/bun test|build|lint|typecheck|check\npytest / vitest / jest / mocha / tsc\ncargo test / go test / dotnet test / mvn test / gradle test / make test\n```\n\n`bash` 文本里出现非零 `[exit code: N]` 时也会被视为失败，即使工具层没有把它标为 `isError`。\n\n债务未清时，Governor 最多按配置追加有限验证步；到达上限后会追加一次仅用于报告 blocker 的步骤，不会无限循环，也不会静默放行。\n\n## Benchmark-aware Stop Controller\n\n实验型性能任务应显式打开 gate，而不是影响普通开发任务：\n\n```yaml\nbenchmarkRequired: true\nbenchmarkToolNames: [run_benchmark]\nverificationToolNames: [build_project, run_correctness_test]\nfinishToolNames: [finish]\nfullBenchmarkMinQueries: 10000\nfullBenchmarkMinRecall: 0.95\nbenchmarkScoreTolerancePercent: 2\n```\n\n配置的 benchmark 工具必须在 `meta` 或模型可见文本中返回完整命名指标；JSON 是最可靠的格式：\n\n```json\n{\n  \"total_queries\": 10000,\n  \"recall\": 0.98,\n  \"qps\": 1250.5,\n  \"concurrency\": 8,\n  \"warmup\": 500\n}\n```\n\n规则是确定性的：\n\n- 只有 `total_queries >= fullBenchmarkMinQueries` 且 `recall >= fullBenchmarkMinRecall` 才能通过当前 revision；无法解析的结果明确成为 blocker，绝不当作 pass。\n- QPS 只和相同 `total_queries`、`concurrency`、`warmup` 的 best record 比较；1K 与 10K 不会混比。\n- 同规格下降未超过 `benchmarkScoreTolerancePercent` 时保留为可接受噪声；超过容差时，当前 revision 不能结束，模型必须恢复已知好版本或提出并验证新假设。\n- 每次已识别 mutation 或高风险 shell 写入都会使先前 benchmark 失效；新的 current-revision full pass 才会重新打开 `finish`。\n- `agent.ctx.tools.guard()` 拦截已配置的显式 `finish`；自然结束由 `agent/turn-stopping` 以同一门槛处理。\n\nGovernor 只保留 benchmark best record 与状态，不直接写用户工作区。因此它不会伪造“自动 rollback”：外部 evaluator/harness 若需要真正自动恢复，必须自己提供可验证的 checkpoint/restore API。\n\n## Native 与 Code Mode\n\nGovernor 同时观察：\n\n- Native：`tool/call` / `tool/result`；\n- Code Mode：`tool/code-dispatch-start` / `tool/code-dispatch`。\n\n因此 `run_code` 内部的 read/write/edit 也会更新信息增益、释放 restriction、创建并清偿验证债务。\n\n## 状态工具\n\n```text\ntrajectory_policy_status\n```\n\n返回当前调用 Agent 自己的：\n\n- episode / human round；\n- relation / kind / phase / risk；\n- artifacts；\n- observed / mutated artifacts；\n- 当前 restriction；\n- no-information、recovery blocker 与 repeated-call 计数；\n- revision-aware open verification debt；\n- benchmark 当前 revision pass、最新结果、同规格 best record、平台期和 blocker；\n- ledger 轮转/失败状态；\n- 最终 assembly hash。\n\n实现严格使用 `exec.agent`，不会读取“最后组装请求的另一个会话”。\n\n## 决策账本与隐私\n\n默认路径：\n\n```text\n$DSH_HOME/trajectory-governor/decisions.jsonl\n```\n\n账本保存：\n\n- session/message id；\n- 原消息 SHA-256，不保存原文；\n- relation、phase、risk、complexity；\n- restriction；\n- tool effect、artifact、错误、novelty；\n- open verification debt；\n- request assembly hash；\n- turn stop reason。\n\n账本失败不会改变官方 Agent 执行流，但不再静默吞掉：首次写入失败会输出一条 `console.error`，`trajectory_policy_status` 的 `ledger.failed/error` 也会暴露原因，随后停止重试该账本。活动文件在 `maxLedgerBytes` 前轮转为带时间戳的 JSONL，历史记录不会被删除。\n\n## 构建与测试\n\n```sh\nnpm install\nnpm run check\n```\n\n当前测试覆盖：\n\n- Task Episode 关系；\n- 寒暄后真实任务；\n- correction / extension continuity；\n- artifact 提取；\n- tool semantics；\n- revision-aware verification debt 与 shell mutation risk；\n- benchmark 结构化解析、1K/10K 隔离、容差比较；\n- 显式 finish guard、自然结束 blocker-report、修改后 benchmark 失效；\n- no-information completion blocker；\n- JSONL rotation 与账本失败状态；\n- Minimal 防失能；\n- Code Mode restriction；\n- 首次请求前捕获输入；\n- 同请求近场 policy；\n- runtime context 保留；\n- 观察后释放写工具；\n- 自动验证续步上限；\n- adaptive reasoning 选择与恢复；\n- 多会话状态隔离；\n- shadow mode 请求不干预。\n\n## 当前限制\n\n- relation engine 是可解释规则基线，不是 learned classifier；\n- artifact graph 目前以路径和工具参数为主；\n- shell 命令语义只能保守识别；\n- benchmark 只能接受工具输出中明确命名的指标；不能从自由文本性能宣称推断 pass；\n- 没有官方 workspace checkpoint API，所以不执行自动 rollback；外部 evaluator 必须提供 restore 机制；\n- 没有自动 subagent evaluator；\n- 没有 contextual bandit；\n- 没有 workspace counterfactual fork runner；\n- 外部插件尚无官方 custom durable SessionEvent 注册面，所以研究决策存在 sidecar，而不是伪造未知 session event；\n- Governor 不替代测试、sandbox、approval 或人工评审。\n\n## 代码结构\n\n```text\nsrc/core.ts       Task Episode、PolicyPlan、工具语义、Verification Debt 纯逻辑\nsrc/index.ts      Harness runtime hooks 与闭环控制\nsrc/ledger.ts     本地 append-only sidecar\ncordis.patch.yml  官方 DSH bundle 层\ntests/            纯逻辑与真实 AgentLoop 集成测试\n```\n","readmeFilename":"README.md"}