返回源码地图

packages/bundle/web-app/cordis.patch.yml

main snapshot · da00f7f5358f · 正文引用章节 04 / 04;完整原文可核对,不声称全文件人工逐行审计

完整原文供逐行核对;页面收录不代表每行都经过人工语义审核。MIT 许可见 许可证。

1# The dsh-web-app bundle patch: the browser surface over the dsh-base layer.
2# Applied after dsh-base's insert; rows here override base rows by id, with
3# the profile's own cordis.patch.yml and any --patch overlays still to come.
4#
5# A patch replaces the targeted row's whole `config`, so each row below
6# restates every key it owns.
7#
8# The web-startup plugin injects `cmdlineArgs` and provides `webStartup` as an
9# ordinary Cordis service. Rows configured from flags inject that service, so
10# Loader resolves their expressions only after it exists. The web runtime then
11# provides bind-dependent `webRuntime` values to the trust fence.
12# `dsh --profile web --help` provides no `webStartup`, so no server binds.
13
14# ── surface-specific values the base deliberately omits ─────────────────────
15
16- id: system-prompt
17 config:
18 personaSuffix: Your working directory is {{cwd}}.
19 personaPrefix: >-
20 You are a coding agent powered by the {{model}} model.
21
22# Full-text session search is opt-in (the base row's `openAt: never`). This
23# restatement keeps the Web values on one ephemeral in-memory index; a
24# deployment enabling content search overrides `openAt` to `first-search` in a
25# later patch layer, which defers the node:sqlite import and in-memory handle
26# to the first search so Node 22 startup stays quiet.
27- id: session-query-sqlite
28 config:
29 path: ':memory:'
30 openAt: never
31
32- id: tools
33 config:
34 # TEMPORARY workaround: DSH_TOOLS_MODE (native|ptc|both) opts a whole dsh
35 # process into PTC mode while per-session tool-presentation selection is being
36 # designed; unset keeps the schema default (native). Remove the env seam
37 # once the web UI owns the choice per session.
38 mode: !!js process.env.DSH_TOOLS_MODE
39
40# ── web-only host rows, the transport layer, and the browser roster ─────────
41
42# `dsh.client` rows are the browser roster the modules node half scans into
43# window.__DSH_BOOT__; the modules row is simultaneously a host row.
44- insert:
45 - id: desktop-product-telemetry
46 name: '@deepseek-ai/dsh-host-product-telemetry-otel'
47 disabled: !!js "ctx.get('profileContext')?.name !== 'desktop'"
48 config:
49 scheduledDelayMillis: 30000
50 timeoutMillis: 15000
51 exportTimeoutMillis: 20000
52 shutdownTimeoutMillis: 2000
53 serviceName: deepseek-harness-desktop
54 serviceVersion: !!js process.env.DSH_CLIENT_VERSION
55 endpoint: !!js process.env.DSH_PRODUCT_ANALYTICS_OTLP_URL
56
57 - id: product-analytics
58 name: '@deepseek-ai/dsh-client-product-analytics'
59 disabled: !!js "ctx.get('profileContext')?.name !== 'desktop'"
60 config:
61 enabled: true
62 appVersion: !!js process.env.DSH_CLIENT_VERSION
63
64 # Host-owned opt-in sampled when a new Web session receives its preset
65 # delegation tools. The Plugins page edits this settings namespace.
66 - id: subagent-model-selection-settings
67 name: '@deepseek-ai/dsh-tool-subagent/model-selection-settings'
68
69 - id: message-feedback
70 name: '@deepseek-ai/dsh-message-feedback'
71 config:
72 maxNoteBytes: 8192
73
74 # Browser Session export: `/export` command plus the shared download dialog.
75 - id: session-log-download
76 name: '@deepseek-ai/dsh-session-log-export'
77
78 # Session-header "Open In..." split button over the host application
79 # resolution (macOS/Windows/Linux; a host with no resolved application
80 # renders no button). Two halves: the host routes and the browser surface.
81 - id: open-in-app
82 name: '@deepseek-ai/dsh-host-open-in-app'
83 config:
84 probeTimeoutMs: 10000
85 iconTimeoutMs: 10000
86 launchWatchMs: 1000
87
88 - id: ui-open-in-app
89 name: '@deepseek-ai/dsh-client-ui-open-in-app'
90
91 - id: workspace
92 name: '@deepseek-ai/dsh-workspace'
93
94 - id: session-reference
95 name: '@deepseek-ai/dsh-session-reference'
96
97 - id: file-reference-local
98 name: '@deepseek-ai/dsh-file-reference-local'
99
100 # Whole-log turn/step counts for the chat stats strip (the sessionStats
101 # projection key); the projection registry itself is a base-layer row.
102 - id: session-stats
103 name: '@deepseek-ai/dsh-session-stats'
104
105 # Whole-log turn outline for the chat turn rail (the turnOutline
106 # projection key): every turn stays navigable before its events page in.
107 - id: session-turn-outline
108 name: '@deepseek-ai/dsh-session-turn-outline'
109
110 # Resolve bind host, SSH launch, and display once at boot, then mount the
111 # matching dual-face directory picker. Mount -native or -browse directly in
112 # an overlay to pin the interaction.
113 - id: directory-picker
114 name: '@deepseek-ai/dsh-host-directory-picker-auto'
115
116 # Read-only projection of current Loader entries for trusted client RPCs.
117 - id: plugin-inventory
118 name: '@deepseek-ai/dsh-host-plugin-inventory'
119
120 # Session commands, cold reads, and live control over Typert Remote.
121 - id: session-controller
122 name: '@deepseek-ai/dsh-api-session-controller'
123
124 # One background job's observation record streamed over Typert Remote;
125 # the roster rides the session control stream above.
126 - id: job-controller
127 name: '@deepseek-ai/dsh-api-job-controller'
128 # Workspace file service: bounded read, directory listing, and the
129 # agent-write change feed inside the session workspace root.
130 - id: terminal-controller
131 name: '@deepseek-ai/dsh-api-terminal-controller'
132 - id: workspace-files
133 name: '@deepseek-ai/dsh-api-workspace-files'
134
135 # The Schedule service owns the task store and delivers each due occurrence
136 # as a follow-up in its original Session. The clock reading and the four
137 # reminder tools belong to the `standard`, `cordis`, and `ptc` presets,
138 # which declare them in their own scope.
139 - id: schedule
140 name: '@deepseek-ai/dsh-schedule'
141
142 # Configuration-surface reads and writes over Typert Remote. Each method
143 # reports an actionable error when its settings-domain provider is absent.
144 - id: ui-settings-account
145 name: '@deepseek-ai/dsh-client-ui-settings-account'
146
147 - id: account-controller
148 name: '@deepseek-ai/dsh-api-account-controller'
149
150 - id: settings-controller
151 name: '@deepseek-ai/dsh-api-settings-controller'
152
153 # Workspace commands and reconnect-safe projection over Typert Remote.
154 - id: workspace-controller
155 name: '@deepseek-ai/dsh-api-workspace-controller'
156
157 - id: cordis-host-runner
158 name: '@deepseek-ai/dsh-cordis-host-runner'
159
160 # The Host inspect providers are process-global: the registry rejects a
161 # duplicate id, so they register here once and every preset's `tool-cordis`
162 # row reads them.
163 - id: cordis-inspect-providers
164 name: '@deepseek-ai/dsh-tool-cordis/host'
165
166 # Ordinary provider for the parsed Web flags. Its plugin-level injection
167 # waits for cmdlineArgs; no launcher metadata or special row kind is needed.
168 - id: web-startup
169 name: '@deepseek-ai/dsh-web-app/startup'
170
171 # ── layer 2: transport/service ──────────────────────────────────────────────
172
173 # Plain route-registration carrier; host and port come from the app's
174 # webStartup provider, with these deployment fallbacks. The dist is served
175 # by the web-runtime row below through the fallback seat. Routing and
176 # browser-facing asset paths do not depend on the advertised URL, which the
177 # web-runtime row owns.
178 - id: webserver
179 name: '@deepseek-ai/dsh-host-webserver'
180 inject: [webStartup]
181 config:
182 host: !!js ctx.webStartup.host ?? '127.0.0.1'
183 port: !!js ctx.webStartup.port ?? 3080
184 compression: gzip
185 compressionLevel: 1
186 compressionThresholdBytes: 1024
187
188 # Web glue owned by this bundle: resolves the built frontend dist (an
189 # assembly fact of dsh-web-app, never user config), mounts the
190 # frontend-static fallback owner, registers the web-surface prompt
191 # section and the bash runtime variable, prints the URL line, and opens the
192 # canonical URL after the full Loader tree settles and the required-
193 # entry audit passes. Invocation-only values come from the webStartup
194 # provider; the advertised application URL is this row's `publicUrl` (the
195 # loopback URL when unset). After the server binds, this row samples LAN
196 # trust once and provides `webRuntime`. A complete agent-preset persona
197 # suppresses the prompt section for that agent while retaining the
198 # host-owned shell variable.
199 - id: web-runtime
200 name: '@deepseek-ai/dsh-web-app'
201 inject: [webStartup]
202 config:
203 openBrowser: !!js ctx.webStartup.openBrowser
204 printUrl: true
205 publicUrl: !!js ctx.webStartup.publicUrl
206 surfaceContext: true
207 trustedHosts: !!js ctx.webStartup.trustedHosts
208
209 # The client-plugin reload chain, always mounted: it is idle until a
210 # rebuild watcher (pnpm run dev:web) actually rewrites client bundles. It
211 # is a row rather than a child of web-runtime because its node half is a
212 # client-side package, which a host-side bundle cannot import.
213 - id: client-hmr
214 name: '@deepseek-ai/dsh-client-hmr'
215
216 # ── browser plugin roster (dsh.client rows; node halves are layer-2 hosts) ──
217
218 # Dual-face: the node half scans this tree, composes window.__DSH_BOOT__,
219 # and serves /plugins/<id>/client.js; the browser half is the module table
220 # the shell kernel constructs before cordis exists (adopted as a plugin
221 # entry by the kernel, never fetched).
222 - id: modules
223 name: '@deepseek-ai/dsh-client-modules'
224
225 # Owns both ends of the web transport: node half binds the gateway to the
226 # webserver under /api; browser half is the fetch/SSE client. Every API
227 # request and upgrade passes the loopback plus trustedHosts policy; an
228 # advertised public URL contributes nothing to it.
229 - id: connection
230 name: '@deepseek-ai/dsh-client-connection'
231 inject: [webRuntime]
232 config:
233 # LAN literals derived from the active bind plus --trusted-host extras.
234 # A deployment adding authorities keeps this expression and concatenates
235 # its literals, for example: ['app.internal', ...ctx.webRuntime.trustedHosts].
236 trustedHosts: !!js ctx.webRuntime.trustedHosts
237
238 # Raw Blob and ReadableStream uploads run independently of Connection's
239 # RPC and generation service.
240 - id: file-upload
241 name: '@deepseek-ai/dsh-client-file-upload'
242
243 - id: api-remotes
244 name: '@deepseek-ai/dsh-api-remotes'
245
246 - id: cordis-client-runner
247 name: '@deepseek-ai/dsh-cordis-client-runner'
248
249 - id: ui-theme
250 name: '@deepseek-ai/dsh-client-ui-theme'
251
252 - id: locale
253 name: '@deepseek-ai/dsh-client-locale'
254
255 - id: shortcuts
256 name: '@deepseek-ai/dsh-client-shortcuts'
257
258 - id: ui-shortcuts
259 name: '@deepseek-ai/dsh-client-ui-shortcuts'
260
261 - id: ui-layout
262 name: '@deepseek-ai/dsh-client-ui-layout'
263
264 - id: ui-renderer
265 name: '@deepseek-ai/dsh-client-ui-renderer'
266
267 - id: ui-session
268 name: '@deepseek-ai/dsh-client-ui-session'
269
270 # Unified resource model: protocol providers behind the useResource hook.
271 - id: resources
272 name: '@deepseek-ai/dsh-client-resources'
273
274 - id: ui-sidebar
275 name: '@deepseek-ai/dsh-client-ui-sidebar'
276
277 # The right Sidebar: one docking surface per session over ui-dockkit.
278 - id: ui-sidebar-right
279 name: '@deepseek-ai/dsh-client-ui-sidebar-right'
280
281
282 - id: office-to-pdf
283 name: '@deepseek-ai/dsh-office-to-pdf'
284
285 # The right Sidebar's document tab: bounded file reads with selectable
286 # Markdown, code, HTML, PDF, Office, and plain-text renderers.
287 - id: ui-sidebar-documentpreview
288 name: '@deepseek-ai/dsh-client-ui-sidebar-documentpreview'
289
290 # Web profiles opt in; Desktop retains sandboxed HTTP(S) Browser tabs.
291 - id: ui-sidebar-browser
292 name: '@deepseek-ai/dsh-client-ui-sidebar-browser'
293 disabled: !!js "ctx.get('profileContext')?.name !== 'desktop'"
294
295 - id: ui-sidebar-terminal
296 name: '@deepseek-ai/dsh-client-ui-sidebar-terminal'
297 # The right Sidebar's workspace file tree tab type.
298 - id: ui-sidebar-files
299 name: '@deepseek-ai/dsh-client-ui-sidebar-files'
300
301 - id: ui-settings
302 name: '@deepseek-ai/dsh-client-ui-settings'
303
304 - id: ui-settings-general
305 name: '@deepseek-ai/dsh-client-ui-settings-general'
306
307 - id: ui-settings-models
308 name: '@deepseek-ai/dsh-client-ui-settings-models'
309
310 # Plugin management: the sidebar Plugins page installs, enables, disables,
311 # and removes the profile's bundles through the `pluginManager` Remote.
312 # Without a profile-backed Host it reports itself unavailable.
313 - id: ui-plugin-manager
314 name: '@deepseek-ai/dsh-client-ui-plugin-manager'
315
316 # Read-only Plugin list tab in the Settings Plugins section; the built-in
317 # bundles the sidebar page leaves out are inspected here.
318 - id: ui-settings-plugin-inventory
319 name: '@deepseek-ai/dsh-client-ui-settings-plugin-inventory'
320
321 - id: ui-conversation
322 name: '@deepseek-ai/dsh-client-ui-conversation'
323
324 - id: ui-approval
325 name: '@deepseek-ai/dsh-client-ui-approval'
326
327 - id: ui-chat
328 name: '@deepseek-ai/dsh-client-ui-chat'
329
330 # Official occupants for the generic sidebar and conversation brand slots.
331 - id: ui-brand-official
332 name: '@deepseek-ai/dsh-client-ui-brand-official'
333
334 - id: ui-attachment
335 name: '@deepseek-ai/dsh-client-ui-attachment'
336
337 # Tool call tree, generic fallback, and keyed business Tool views.
338 - id: ui-tool
339 name: '@deepseek-ai/dsh-client-ui-tool'
340
341 - id: ui-cordis
342 name: '@deepseek-ai/dsh-client-ui-cordis'
343
344 # Turn tail: the changed-files card and delivery cards under each closing
345 # assistant message. Remove this entry to turn the surface off; the tail
346 # hole renders empty.
347 - id: ui-deliverables
348 name: '@deepseek-ai/dsh-client-ui-deliverables'
349
350 # Records each top-level turn's changed files from git working-tree
351 # snapshots; the changed-files card above renders its events.
352 - id: workspace-changes
353 name: '@deepseek-ai/dsh-workspace-changes'
354
355
356 - id: ui-workspace
357 name: '@deepseek-ai/dsh-client-ui-workspace'
358
359 # Durable workflow lifecycle as an independent Chat node after the
360 # existing generic workflow tool row.
361 - id: ui-workflow-run
362 name: '@deepseek-ai/dsh-client-ui-workflow-run'
363
364 # Input triggers: the '/' | '@' pipeline (ui-input-trigger), the command surface over
365 # it (ui-commands), and the reference sources (ui-skill / ui-reference).
366 - id: ui-input-trigger
367 name: '@deepseek-ai/dsh-client-ui-input-trigger'
368
369 - id: ui-commands
370 name: '@deepseek-ai/dsh-client-ui-commands'
371
372 - id: ui-skill
373 name: '@deepseek-ai/dsh-client-ui-skill'
374
375 - id: ui-subagent
376 name: '@deepseek-ai/dsh-client-ui-subagent'
377
378 - id: ui-reference
379 name: '@deepseek-ai/dsh-client-ui-reference'
380
381
382 # Background jobs: the session-header roster with on-demand streaming
383 # record panels over the session job-output service.
384 - id: ui-jobs
385 name: '@deepseek-ai/dsh-client-ui-jobs'
386
387 # Task management and Session reminder catalog over the Host Schedule
388 # service mounted above.
389 - id: ui-schedule
390 name: '@deepseek-ai/dsh-client-ui-schedule'
391
392 # Goal surface: GoalBar in the input dock over the goal session projection.
393 - id: ui-goal
394 name: '@deepseek-ai/dsh-client-ui-goal'
395
396 # The feedback surface: Like/Dislike in the assistant-message action
397 # strip, the feedback dialog behind Dislike and /feedback with its
398 # acknowledgement toast, over the messageFeedback and sessionFeedback Remotes.
399 - id: ui-message-feedback
400 name: '@deepseek-ai/dsh-client-ui-message-feedback'
401
402 # Model selection: the /model popupSelect + composer seat over session.models.
403 - id: ui-model-selection
404 name: '@deepseek-ai/dsh-client-ui-model-selection'
405
406 - id: ui-permission
407 name: '@deepseek-ai/dsh-client-ui-permission-presets'
408
409 # The agent-preset row in General settings: the default preset for
410 # sessions created later. Absent a roster it renders nothing.
411 - id: ui-agent-preset
412 name: '@deepseek-ai/dsh-client-ui-agent-preset'
413
414 - id: ui-settings-session-log
415 name: '@deepseek-ai/dsh-client-ui-settings-session-log'
416
417 # The Built-in plugins settings section: the navigation entry and the tab
418 # row the inventory tab registers into. The official configuration pages
419 # are the companion rows below.
420 - id: ui-settings-plugins
421 name: '@deepseek-ai/dsh-client-ui-settings-plugins'
422
423 # The official settings pages: one companion package per host-plane
424 # namespace, each registering its page into the Plugins page while the
425 # Host serves the namespace.
426 - id: ui-settings-shell
427 name: '@deepseek-ai/dsh-client-ui-settings-shell'
428
429 - id: ui-settings-agent-loop
430 name: '@deepseek-ai/dsh-client-ui-settings-agent-loop'
431
432 - id: ui-settings-subagent
433 name: '@deepseek-ai/dsh-client-ui-settings-subagent'
434
435 - id: ui-settings-web-search
436 name: '@deepseek-ai/dsh-client-ui-settings-web-search'
437
438 # Plan control: the composer plan seat over the plan projection + /plan channel.
439 - id: ui-plan
440 name: '@deepseek-ai/dsh-client-ui-plan'
441
442 - id: ui-user-questions
443 name: '@deepseek-ai/dsh-client-ui-user-questions'
444
445 - id: ui-trajectory
446 name: '@deepseek-ai/dsh-client-ui-trajectory'
447
448# ── the agent plane moves behind agent presets ─────────────────────────────
449#
450# Every row below composes what ONE agent contributes to the host registries:
451# its tools, its prompt sections, its delegation backends. The base keeps them
452# for the TUI, which is single-session and composes its agent process-wide; the
453# Web surface disables them here and lets each session mount a preset instead.
454#
455# Disabling rather than deleting is deliberate: the base is shared, and a row
456# absent from a surface overlay would silently reappear the day someone reorders
457# the composition.
458
459# `shell-env` STAYS in the host plane: `apps/cli/src/web.ts` injects it to
460# publish `DSH_WEB_URL`/`DSH_WEB_MODE`, and a host row that injects a service is
461# the criterion for host-plane ownership — injection resolves before any session
462# exists, so there is no agent to key by. Behind a preset realm those variables
463# would never reach the model's shell at all.
464
465- id: tool-plugin-manager
466 disabled: true
467
468- id: tool-bash
469 disabled: true
470
471- id: tool-pwsh
472 disabled: true
473
474# The background-job REGISTRY stays on the host plane; only the model-facing
475# `job_*` controls move. Its producers — `tool-bash` here, `tool-terminal` and a
476# non-continuable `tool-subagent` elsewhere — are preset rows that resolve it
477# with `ctx.get`, and an entry-local realm around the registry is invisible to
478# every sibling row outside that realm, so `run_in_background` answered
479# "background jobs unavailable" while the controls sat in the catalog. That is
480# the `goals` criterion read from inside the preset: a Service a row outside its
481# realm READS belongs to the plane both can see. The registry is keyed by owning
482# agent, so one host instance serves every session exactly as before presets.
483
484- id: tool-jobs
485 disabled: true
486
487- id: tool-fs
488 disabled: true
489
490- id: tool-fs-search
491 disabled: true
492
493# The `skill` REGISTRY stays in the host plane. It is host+per-scope layered
494# (the tools-registry shape): deployment-level providers — repository plugins,
495# a host skill-filesystem row — register into its global layer, while a preset's
496# `skill-filesystem` registers into that preset's layer, and each agent reads the
497# merged catalog its scope chain selects. Only the per-agent rows move behind
498# presets: the base host `skill-filesystem` row is disabled here (presets own local
499# discovery), and `tool-skill` is what a preset mounts to give its agent the
500# catalog and loader at all.
501
502- id: skill-filesystem
503 disabled: true
504
505- id: tool-skill
506 disabled: true
507
508# The goal service and session driver stay on the host plane, where Gateway
509# remotes resolve them. Presets own the human command and model-facing tool.
510
511- id: command-goal
512 disabled: true
513
514- id: tool-goal
515 disabled: true
516
517- id: plan-mode
518 disabled: true
519
520# The token METER stays on the host plane; only the compaction backend that
521# reads it moves. It owns the context-meter projection units, and that table is
522# process-wide, so preset ownership would make the meter a function of which
523# presets happen to be mounted rather than a per-session fact. Same criterion as
524# `tasks` and `goals`; the reasoning has one home in
525# `.agents/notes/implemented/architecture/2026-08-10-host-plane-ownership-after-presets.md`.
526
527- id: compaction-basic
528 disabled: true
529
530- id: command-compact
531 disabled: true
532
533- id: tool-result-pruner
534 disabled: true
535
536# The subagent registry and its backends STAY in the host plane. `subagents` is
537# a process singleton with a cross-session query surface (`listChildren`,
538# `followup`) that the host api-proxy serves to the browser, and a provider
539# registers under a globally unique name, so a per-session copy would both
540# starve that host row and collide on the second session. What a preset
541# chooses is which delegation TOOLS its agent sees, below.
542
543- id: tool-subagent-control
544 disabled: true
545
546- id: tool-subagent-list-agents
547 disabled: true
548
549- id: tool-subagent
550 disabled: true
551
552- id: tool-subagent-fork
553 disabled: true
554
555- id: workflow-ptc
556 disabled: true
557
558- id: tool-workflow
559 disabled: true
560
561# `base` ships this row disabled; the preset-plane gate reads declared row ids
562# without regard to `disabled`, so this row must stay to keep `tool-ralph` off
563# the host plane and out of collision with every preset's row.
564- id: tool-ralph
565 disabled: true
566
567- id: agent-instructions
568 disabled: true
569
570- id: tool-todo
571 disabled: true
572
573- id: tool-web
574 disabled: true
575
576# The preset selection registry. The shipped preset declarations follow as
577# separate patch files under `presets/`, listed after this file in
578# `package.json` `dsh.bundle.patch`.
579- insert:
580 - id: agent-preset-registry
581 name: '@deepseek-ai/dsh-agent-preset-registry'
582 config:
583 default: standard