Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,10 @@ jobs:
repository: omdsh-dev/deepseek-harness
ref: dsh-v0.1.2-rc.1-a11y.5
path: .assembled/dsh
# This draft must stay blocked, not silently validate alpha against rc1.
# Replace the core ref only after its exact alpha source and patches exist.
- name: Verify assembled baseline before installing or building DSH
run: node scripts/verify-assembled-baseline.mjs .assembled/dsh .
- uses: pnpm/action-setup@v6
with:
version: 11.7.0
Expand Down
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@

## Unreleased

- Explicitly allow the reviewed `fs-ext@2.1.1` native build required by alpha.2 session ownership locks; preserve the first clean-install CI failure instead of disabling pnpm lifecycle approval.
- Prepare an unpublished, publication-blocked `0.1.1-alpha.0` development probe against the exact npm DSH `0.1.3-alpha.2` graph. Regenerate the lockfile from a clean dependency installation to remove stale rc1 auto-installed peers, and add a whole-DSH-lockfile regression check.
- Correct the remaining test-only import of the removed `dsh-client-runtime` contract and make the in-app compatibility message explicitly identify this as an unvalidated development target.
- Add an assembled-baseline preflight that rejects mismatched cores and the explicit development hold before installing/building the core or launching a companion lab. No alpha core, browser, or human-AT evidence is produced; beta.8, npm dist-tags, historical evidence, and the primary campaign remain unchanged. See [migration status](COMPATIBILITY-0.1.3-alpha.2.md).

## 0.1.0-beta.8 - 2026-09-07

- Advance the exact accessibility-core baseline to `dsh-v0.1.2-rc.1-a11y.5` after refreshing the semantic queue snapshots and making the queued-action dock assertion portable across classic-scrollbar runners.
Expand Down
56 changes: 56 additions & 0 deletions COMPATIBILITY-0.1.3-alpha.2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# DSH 0.1.3-alpha.2 migration status

English | [简体中文](COMPATIBILITY-0.1.3-alpha.2.zh.md)

Checked on 2026-09-07. Status: **development probe only; core integration and publication blocked**. The manifest's `0.1.1-alpha.0` is an unpublished development identifier, not a new support claim. `private: true` prevents npm publication, and the companion lab preflight rejects this held build even when the core's version string matches.

## Verified upstream state

- The [official npm metadata](https://registry.npmjs.org/@deepseek-ai%2fdsh) advertises `alpha: 0.1.3-alpha.2`; `latest` and `next` remain `0.1.2-rc.1`.
- The alpha package was published at `2026-09-07T13:11:36.213Z`. Its [version manifest](https://registry.npmjs.org/@deepseek-ai%2fdsh/0.1.3-alpha.2) contains neither `gitHead` nor a provenance attestation identifying the source commit. Its registry signature is not a source-revision mapping.
- The CLI tarball has SHA-1 `4f421920af35f1f9526eb0af2279bec36c304d3e` and integrity `sha512-rmf4xgzU9+abvaQ//slyBBhADtPu8fv+SZjxmh4GJwJMZipVa7hNU5m23HgVcB3LNmuGltuQ7jyypuhJ5yU69A==`.
- Public GitHub heads and tags resolve the newest source to [`dsh-v0.1.3-alpha.1`](https://github.com/deepseek-ai/deepseek-harness/releases/tag/dsh-v0.1.3-alpha.1), commit `d347e703908d0406b7a7ef80e3a0e594d86b2215`. An alpha.2 tag fetch fails; branches, matching refs, package-version commit history, and release queries do not identify the alpha.2 source. This is an observation at the check time, not a claim that no such source exists privately.

Do not substitute the alpha.1 source or rename an rc1 accessibility report to alpha.2.

## Prepared and checked locally

Local environment: macOS, Node `24.3.0`, pnpm `11.7.0`. These results are not a cross-OS CI result.

- All direct DSH development dependencies and client peers target exactly `0.1.3-alpha.2`. A regenerated lockfile contains 225 DSH packages, all at that version. The prior incremental install silently kept 23 incompatible rc1 peer packages; a clean dependency resolution removed them without peer overrides or disabling trust checks.
- `pnpm peers check`: no peer dependency issues.
- `pnpm run typecheck` and the companion build: pass against the published alpha package interfaces.
- `pnpm test`: 28 files, 229 tests pass, including the full-graph version guard and baseline/publication-hold rejection tests. The upstream `dsh-client-ui-primitives` artifact references an absent `index.js.map`; Vite emits a non-fatal warning. This has not been hidden or treated as an accessibility result.
- The only client-code change is an explicit development warning. The removed runtime type import in one test now points to `dsh-client-ui-conversation`.
- `npm pack --dry-run --ignore-scripts --json` after the build: 126 files; the baseline guard and bilingual migration status are included. This only checks package contents; no npm publication was attempted.

These are package/interface and isolated component checks. They do not demonstrate assembled alpha DSH behavior, core accessibility, spoken output, braille, or independent task completion.

The first [CI run](https://github.com/omdsh-dev/dsh-accessibility/actions/runs/34128713003) exposed an additional clean-install issue: pnpm rejected the unreviewed `fs-ext@2.1.1` build script on all six OS/Node validation jobs. The local install had initially used `--ignore-scripts`, so its follow-up install did not expose that clean-runner failure. Review confirmed that alpha.2 JSONL persistence imports this native module for session ownership locks; its install script is `node-gyp configure build`, compiling the shipped `fs-ext.cc` through `binding.gyp`. The explicit build allowlist now includes it. Do not disable build approval checks or classify this initial CI run as passing. The separate assembled preflight failure is intentional while the exact core source remains unavailable.

## Remaining gates

1. Identify a public, exact alpha.2 source revision with a trustworthy relationship to the npm release.
2. Port the rc1 core patches to that revision and review upstream changes, including attachments, history/session format, live updates, permissions, and focus/keyboard behavior.
3. Port the companion browser/AT templates from their current rc1 implementation; replace the CI core ref with an exact reviewed accessibility commit/tag. Remove the explicit development hold only as part of that reviewed transition. The assembled CI job currently **must fail preflight**, before building rc1; a skipped or rc1-only job is not an alpha pass.
4. Run focused core checks, all three browser engines, the external-plugin assembled scenario, disposable AT-lab smoke checks, and package-content verification. Archive fresh reports with exact clean revisions.
5. Review release metadata and the npm prerelease channel before publishing. This branch does not create a tag or release, move npm dist-tags, or replace beta.8.
6. Collect consented VoiceOver/NVDA and disabled-developer evidence separately. The current human ledger remains empty; no previous results or missing rows are promoted by this migration.

## Recheck and reproduce

Run the following from this companion checkout. The two local install commands use the reviewed lockfile; do not widen the exact recent-release exceptions in `pnpm-workspace.yaml`.

```sh
npm view @deepseek-ai/dsh dist-tags --json
npm view @deepseek-ai/dsh@0.1.3-alpha.2 gitHead dist.attestations --json
git ls-remote https://github.com/deepseek-ai/deepseek-harness.git 'refs/heads/*' 'refs/tags/*0.1.3*'
pnpm install --frozen-lockfile --ignore-scripts
pnpm install --frozen-lockfile
pnpm peers check
pnpm run typecheck
pnpm test
pnpm run build
```

For daily use, keep the released [`0.1.0-beta.8`](https://github.com/omdsh-dev/dsh-accessibility/releases/tag/v0.1.0-beta.8) companion with [`dsh-v0.1.2-rc.1-a11y.5`](https://github.com/omdsh-dev/deepseek-harness/releases/tag/dsh-v0.1.2-rc.1-a11y.5). Even that candidate is not a claim of complete screen-reader support.
39 changes: 39 additions & 0 deletions COMPATIBILITY-0.1.3-alpha.2.zh.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
# DSH 0.1.3-alpha.2 迁移状态

[English](COMPATIBILITY-0.1.3-alpha.2.md) | 简体中文

核验日期:2026-09-07。当前仅完成开发预检,核心整体验证与发布仍受阻。本分支的 `0.1.1-alpha.0` 是未发布的开发编号,已设置 `private: true`;即使核心版本号匹配,实验室入口也会拒绝这个仍处于阻止状态的构建。

## 上游状态

- [官方 npm 元数据](https://registry.npmjs.org/@deepseek-ai%2fdsh)中,`alpha` 指向 `0.1.3-alpha.2`,`latest` / `next` 仍指向 `0.1.2-rc.1`。
- alpha.2 于 `2026-09-07T13:11:36.213Z` 发布,但[版本元数据](https://registry.npmjs.org/@deepseek-ai%2fdsh/0.1.3-alpha.2)没有 `gitHead` 或可定位源码提交的 provenance。包签名不能代替源码映射。
- 公开分支、标签与发布记录只到 [`dsh-v0.1.3-alpha.1`](https://github.com/deepseek-ai/deepseek-harness/releases/tag/dsh-v0.1.3-alpha.1),对应 `d347e703908d0406b7a7ef80e3a0e594d86b2215`;获取 alpha.2 标签失败,版本提交记录中也未定位到对应源码。这是核验时的公开可见状态,不代表不存在未公开源码。

不能拿 alpha.1 源码当作 alpha.2,也不能将 rc1 报告更名后当作新版证据。完整包校验值和复查命令见[英文记录](COMPATIBILITY-0.1.3-alpha.2.md)。

## 已完成的预检

本地环境为 macOS、Node `24.3.0`、pnpm `11.7.0`;以下不是跨系统 CI 结果。

- 精确升级 DSH 开发依赖和客户端 peers 到 `0.1.3-alpha.2`。增量安装曾保留 23 个不兼容的 rc1 peer 包;重新解析干净依赖后已消除,未使用 peer 强制覆盖或关闭信任检查。
- 锁文件中 225 个 DSH 包均为 alpha.2;新增整个 DSH 锁文件版本一致性测试,防止再次混入旧版;`pnpm peers check` 无问题。
- 类型检查和插件构建通过;28 个测试文件、229 项测试通过。
- 修正一处仍指向已移除 runtime 包的测试类型导入;中英文界面明确提示本分支尚未完成兼容验证。
- 构建后的打包预检包含 126 个文件,确认基线检查器和中英文迁移记录均在包内;未尝试 npm 发布。
- 上游 `dsh-client-ui-primitives` 包引用了未附带的 `index.js.map`,Vite 会产生不影响当前测试退出结果的警告;没有隐藏该警告,也未将其当成无障碍结果。

这些只证明已发布接口与独立组件层面的检查,不证明 alpha.2 核心、完整 DSH、读屏语音、盲文或残障用户独立任务完成能力。

[首轮 CI](https://github.com/omdsh-dev/dsh-accessibility/actions/runs/34128713003)还暴露了干净安装问题:六个系统/Node 组合均被未审核的 `fs-ext@2.1.1` 构建脚本阻止。本地最初用过 `--ignore-scripts`,后续增量安装未暴露该问题。核对后确认它由 alpha.2 JSONL 会话持久化导入以实现会话所有权文件锁;安装脚本为 `node-gyp configure build`,通过 `binding.gyp` 编译随包的 `fs-ext.cc`,现已加入明确的构建清单。首轮失败记录保留,不关闭构建审核;核心源码缺失导致的 assembled 前置检查失败是另一项独立阻塞。

## 后续必须完成

1. 取得能可靠对应 npm alpha.2 的公开、精确源码提交。
2. 迁移核心补丁,逐项检查附件、会话格式与历史、实时更新、权限、焦点和键盘行为的变化。
3. 将仍基于 rc1 的浏览器/AT 模板迁移到新源码,固定新核心提交或 tag,再经审查解除开发阻止状态。当前 assembled CI 必须在构建 rc1 前失败,不能跳过或拿旧版通过充当新版通过。
4. 完成核心定向测试、三浏览器验证、插件与真实 DSH 组合测试、一次性 AT 实验室启动检查及打包检查,并绑定精确干净提交归档新报告。
5. 审查版本和 npm 预发布频道后再发布。本分支不创建 release/tag,不改 npm dist-tag,也不替换 beta.8。
6. 真人 VoiceOver/NVDA 和残障开发者证据继续单独收集,账本维持空白,不转移旧证据、不补写未发生的验证。

日常使用仍保持 [`0.1.0-beta.8`](https://github.com/omdsh-dev/dsh-accessibility/releases/tag/v0.1.0-beta.8) 插件与 [`dsh-v0.1.2-rc.1-a11y.5`](https://github.com/omdsh-dev/deepseek-harness/releases/tag/dsh-v0.1.2-rc.1-a11y.5) 核心配套。该候选组合也不代表已完全支持读屏软件。
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

English | [简体中文](README.zh.md)

> Development branch: the local `0.1.1-alpha.0` manifest probes DSH `0.1.3-alpha.2` and is deliberately `private: true`. It is not an install-ready or published release. Exact upstream source and integrated core validation are blocked; see the [migration status](COMPATIBILITY-0.1.3-alpha.2.md). Unless explicitly stated otherwise, the installation instructions and evidence below describe the released `0.1.0-beta.8` / DSH `0.1.2-rc.1` line, not this alpha branch.

An optional DeepSeek Harness companion for screen-reader guidance, semantic diagnostics, and an experimental user-loaded conversation reading view. It intentionally uses DSH slots and structured projections; it does not patch or observe hashed DOM classes.

This repository is also the public project hub of the [DSH Accessibility Working Group](https://github.com/omdsh-dev/community/blob/main/working-groups/accessibility.md). Its mission is to enable disabled developers to complete DSH's core tasks independently, effectively, and safely; help every developer produce more accessible digital content with DSH; and validate both goals with versioned standards, real assistive technology, and evidence from disabled users.
Expand Down Expand Up @@ -33,6 +35,8 @@ pnpm dsh web

## Install from a checkout

Use the released `v0.1.0-beta.8` checkout for these commands. Do not install this development branch into a working DSH profile.

```sh
pnpm install
pnpm run build
Expand Down
4 changes: 4 additions & 0 deletions README.zh.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@

[English](README.md) | 简体中文

> 开发分支提示:本地 `0.1.1-alpha.0` 仅用于预检 DSH `0.1.3-alpha.2`,已设置 `private: true` 阻止 npm 发布;它不是可供安装使用的已发布版本。对应上游源码和核心整体验证仍受阻,详见[迁移状态](COMPATIBILITY-0.1.3-alpha.2.zh.md)。除非另行注明,下方安装说明与证据均属于已发布的 `0.1.0-beta.8` / DSH `0.1.2-rc.1`,不代表本 alpha 分支通过验证。

这是 DeepSeek Harness 的可选无障碍 companion 插件:提供读屏操作说明、语义自检和实验性的用户主动加载会话阅读视图。它只使用 DSH 官方 slot 与结构化 projection,不修改或监听易变化的哈希 CSS 类名。

本仓库也是 [DSH 无障碍工作组](https://github.com/omdsh-dev/community/blob/main/working-groups/accessibility.zh-CN.md)的公开项目中心。项目使命是:让残障开发者能够独立、有效、安全地完成 DSH 的核心任务;让 DSH 帮助所有开发者产出更无障碍的数字内容;并用版本化标准、真实辅助技术和残障用户证据持续验证。
Expand Down Expand Up @@ -33,6 +35,8 @@ pnpm dsh web

## 从本地 checkout 安装

以下命令仅用于已发布的 `v0.1.0-beta.8` checkout。请勿把本开发分支安装进日常使用的 DSH profile。

```sh
pnpm install
pnpm run build
Expand Down
42 changes: 23 additions & 19 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@oh-my-dsh/dsh-accessibility",
"version": "0.1.0-beta.8",
"version": "0.1.1-alpha.0",
"description": "Screen-reader guidance and in-app accessibility diagnostics for DeepSeek Harness",
"type": "module",
"main": "lib/index.js",
Expand Down Expand Up @@ -29,6 +29,8 @@
"ACCESSIBILITY_STATEMENT.md",
"ACCESSIBILITY_STATEMENT.zh.md",
"CHANGELOG.md",
"COMPATIBILITY-0.1.3-alpha.2.md",
"COMPATIBILITY-0.1.3-alpha.2.zh.md",
"CONTRIBUTING.md",
"CONTRIBUTING.zh.md",
"GOVERNANCE.md",
Expand Down Expand Up @@ -88,6 +90,7 @@
"CLI-ACCESSIBILITY.md",
"CLI-ACCESSIBILITY.zh.md",
"scripts/run-assembled-browser.mjs",
"scripts/verify-assembled-baseline.mjs",
"scripts/assembled-browser.e2e.template.ts",
"scripts/browser-contract.e2e-helper.ts",
"scripts/run-at-lab.mjs",
Expand Down Expand Up @@ -197,27 +200,27 @@
},
"peerDependencies": {
"@deepseek-ai/cordis": ">=4.0.1 <5",
"@deepseek-ai/dsh-client-locale": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-chat": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-conversation": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-primitives": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-session": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-settings": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-slots": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-locale": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-chat": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-conversation": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-primitives": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-session": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-settings": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-slots": "0.1.3-alpha.2",
"react": "^18.2.0"
},
"devDependencies": {
"@deepseek-ai/cordis": "4.0.2",
"@deepseek-ai/dsh": "0.1.2-rc.1",
"@deepseek-ai/dsh-api-session-controller": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-locale": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-chat": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-conversation": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-primitives": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-renderer": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-session": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-settings": "0.1.2-rc.1",
"@deepseek-ai/dsh-client-ui-slots": "0.1.2-rc.1",
"@deepseek-ai/dsh": "0.1.3-alpha.2",
"@deepseek-ai/dsh-api-session-controller": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-locale": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-chat": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-conversation": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-primitives": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-renderer": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-session": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-settings": "0.1.3-alpha.2",
"@deepseek-ai/dsh-client-ui-slots": "0.1.3-alpha.2",
"@testing-library/react": "16.3.2",
"@types/node": "22.20.0",
"@types/react": "~18.3.1",
Expand All @@ -231,5 +234,6 @@
"tsdown": "0.22.2",
"typescript": "6.0.3",
"vitest": "4.1.8"
}
},
"private": true
}
Loading
Loading