@@ -11,10 +11,10 @@ separate Loader rows:
1111 Session successfully invokes the exact ` loopx ` skill. It then asks LoopX
1212 whether another turn may run and queues the authoritative heartbeat task
1313 into that live DSH Agent.
14- - the package-root Host registers a loopback-only ` /loopx ` Connection channel,
15- and its web Client contributes a compact GoalBar between DSH's native GoalBar
16- and Queue dock rows. It renders only for one exact live
17- ` (goalId, loopxAgentId) ` binding.
14+ - the package-root Host registers GoalBar at the authenticated
15+ ` /api/loopx.goalbar ` route required by DSH 0.1.5. Its web Client adds a compact
16+ GoalBar between DSH's native GoalBar and Queue dock rows, visible only for one
17+ exact live ` (goalId, loopxAgentId) ` binding.
1818
1919Installing the plugin and starting DSH load and prepare these capabilities;
2020neither creates a binding nor activates the Driver. The GoalBar
@@ -61,7 +61,12 @@ dsh plugin --profile web add \
6161 " https://github.com/huangruiteng/loopx/releases/download/dsh-loopx-plugin-v0.1.1-beta.5/dsh-loopx-plugin-0.1.1-beta.5.tgz"
6262```
6363
64- For a source checkout, the equivalent build-and-install path is:
64+ The prebuilt release above retains its original DSH compatibility. This source
65+ checkout targets DSH 0.1.5-rc.1 or newer within the 0.1.x line; it does not
66+ publish a new plugin release. The exported legacy RPC registration remains
67+ available to explicit callers, but plugin startup always uses the shared API.
68+
69+ For the DSH 0.1.5 source build, use:
6570
6671``` bash
6772cd packages/dsh-loopx-plugin
@@ -129,7 +134,7 @@ Start/Pause. Focused Client tests cover Session-generation replacement and old
129134request cancellation without duplicating that matrix in the packed smoke.
130135The Docker smoke packs the current plugin and builds the current LoopX
131136release-candidate wheel, then starts both in a clean Debian container with the
132- DSH 0.1.5 release candidate. It proves PEP 668-compatible private installation,
137+ DSH 0.1.5-rc.2 release candidate. It proves PEP 668-compatible private installation,
133138the managed launcher, startup readiness, installed ` loopx ` skill files, launch-
134139token authentication, and an authenticated GoalBar read through DSH's shared
135140API carrier. It requires Docker, ` uv ` , and network access for base images and
@@ -198,9 +203,10 @@ loopx reliability-diagnostics status --goal-id <goal-id> --format json
198203
199204Unless all required variables are valid, the independent observer row
200205registers no hook and writes no file. When enabled, it consumes only
201- ` session/created ` , ` session/event ` , and ` session/disposed ` ; it skips
202- ` assistant/chunk ` and records tool names, turn and step numbers, typed end
203- reasons, and ids only, never arguments, outputs, prompts, or paths. Events for
206+ ` session/created ` , ` session/event ` , and ` session/disposed ` ; it skips the retired
207+ token-level ` assistant/chunk ` rows older logs still replay, and records tool
208+ names, turn and step numbers, typed end reasons, and ids only, never arguments,
209+ outputs, prompts, or paths. Events for
204210any session other than the exact configured session are rejected as
205211` identity_invalid ` . The stats record pins worker/model/task/environment/tools/
206212budget plus adapter and observer revisions, declares source coverage, and
@@ -214,12 +220,17 @@ C1 run, and measured observer overhead remain separate evidence gates.
214220
215221## GoalBar authority and privacy boundary
216222
217- ` /loopx ` is registered with Connection authority ` loopback ` . Loopback is a
218- network reachability fence, not user authentication, and Phase 1 does not
219- support LAN or remote browsers. The browser supplies only its injected DSH
220- Session id and, for an action, the last validated Goal/Agent pair. The Host
221- re-derives cwd and thread identity from the live DSH Agent, freshly resolves
222- the binding, and executes only fixed LoopX argv.
223+ The GoalBar carrier uses Connection's authenticated ` /api/loopx.goalbar `
224+ Fetch route. Explicit callers of the deprecated RPC registration can still
225+ register ` /loopx ` ; plugin startup does not select it automatically. Both pass
226+ Connection's Host/Origin trust fence and browser authentication, and this
227+ package adds no second credential of its own. The deployment's reachability
228+ policy — loopback by default, or declared ` trustedHosts ` — decides which
229+ browsers can reach the host at all; Phase 1 does not support LAN or remote
230+ browsers. The browser supplies only its injected DSH Session id and, for an
231+ action, the last validated Goal/Agent pair. The Host re-derives cwd and thread
232+ identity from the live DSH Agent, freshly resolves the binding, and executes
233+ only fixed LoopX argv.
223234
224235The wire allowlist contains ids, activation, live Agent status, full-lane
225236counts, cursors, opaque source revisions, and fixed error codes. It excludes
0 commit comments