cordis.patch.yml 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433
  1. # The dsh-base bundle patch: the shared core of every dsh profile, applied as
  2. # ONE insert over the empty profile root. Later bundle patches and the user's
  3. # profile cordis.patch.yml address these rows by id, with the last write
  4. # winning per row.
  5. #
  6. # A patch replaces the targeted row's whole `config` rather than merging into
  7. # it, so a row whose value differs by mode does NOT live here: it belongs to
  8. # each mode bundle, keeping any single row down to one bundle layer plus the
  9. # user's. Mode-specific rows appear below only with shared plugin identity and
  10. # neutral defaults; each mode bundle restates its complete configuration.
  11. #
  12. # Row order carries no load semantics (activation is service-availability
  13. # driven); the grouping is for readers.
  14. - insert:
  15. - id: timer
  16. name: '@cordisjs/plugin-timer'
  17. - id: hmr
  18. name: '@cordisjs/plugin-hmr'
  19. config:
  20. root: ['.']
  21. # The profile's cordis.patch.yml replaces this row's config to select exact GitHub
  22. # repository Plugin generations. The app registers the DSH-owned runtime even
  23. # when the list is empty so a later personal-config edit can load
  24. # transactionally; one-shot headless runs consume the startup value only.
  25. - id: repository-plugins
  26. name: '@deepseek-ai/dsh-repository-plugin'
  27. - id: llm
  28. name: '@deepseek-ai/dsh-llm'
  29. - id: session
  30. name: '@deepseek-ai/dsh-session'
  31. - id: typert
  32. name: '@deepseek-ai/dsh-typert-registry'
  33. - id: typert-loader
  34. name: '@deepseek-ai/dsh-typert-loader'
  35. - id: typert-gateway
  36. name: '@deepseek-ai/dsh-api-gateway'
  37. - id: session-title
  38. name: '@deepseek-ai/dsh-session-title'
  39. config:
  40. fallbackMaxWords: 5
  41. fallbackMaxBytes: 40
  42. maxTitleBytes: 80
  43. - id: session-title-llm
  44. name: '@deepseek-ai/dsh-session-title-first-message-llm'
  45. config:
  46. targetWords: 5
  47. targetCjkCharacters: 10
  48. maxInputBytes: 4096
  49. maxOutputTokens: 64
  50. timeoutMs: 60000
  51. - id: user-interaction
  52. name: '@deepseek-ai/dsh-user-interaction'
  53. - id: agent
  54. name: '@deepseek-ai/dsh-agent'
  55. # The transport-independent default for Agents created by front doors.
  56. # Settings may supply a saved selection; consumers read it at creation time.
  57. - id: agent-default-model
  58. name: '@deepseek-ai/dsh-agent-default-model'
  59. config:
  60. provider: deepseek-official
  61. model: deepseek-v4-flash
  62. - id: tasks
  63. name: '@deepseek-ai/dsh-tasks-local'
  64. - id: llm-retry
  65. name: '@deepseek-ai/dsh-llm-retry'
  66. # User-settings document (`$DSH_HOME/settings.yaml`, hot-reloaded): a
  67. # `llm-deepseek:` or `llm-pi-ai:` section there overrides the adapter entries
  68. # below without a restart, and is what the web Models page writes.
  69. - id: settings
  70. name: '@deepseek-ai/dsh-settings-local'
  71. # Credential sources: inherited environment over the managed
  72. # `$DSH_HOME/.credentials.yaml`, with project and user `.env` fallbacks.
  73. # Adapters resolve references per request; the Models page writes only the
  74. # managed document, which is never materialized into the process environment.
  75. - id: credentials
  76. name: '@deepseek-ai/dsh-credentials-local'
  77. # The pi-ai multi-provider twin, mounted dormant: zero routes (and no extra
  78. # models in the picker) until a `llm-pi-ai:` settings section supplies provider
  79. # profiles — then those routes register live, keys resolving per request
  80. # through their apiKeyEnv references, and drop again when the section empties.
  81. # Supplying those profiles is exactly what the web Models page does. Which
  82. # adapters exist is composition; which providers run is the user's settings
  83. # document.
  84. - id: llm-pi-ai
  85. name: '@deepseek-ai/dsh-llm-pi-ai'
  86. - id: session-persistence-jsonl
  87. name: '@deepseek-ai/dsh-session-persistence-jsonl'
  88. config:
  89. root: !!js dshHomePath('sessions')
  90. # Raw configs can supply a process-local path or disable this shared session
  91. # capability. The neutral default is process-local and opens only when used.
  92. - id: session-query-sqlite
  93. name: '@deepseek-ai/dsh-session-query-sqlite'
  94. config:
  95. path: ':memory:'
  96. openAt: first-search
  97. # Shared projection registry: subagent catalog identity (mode/label) folds
  98. # through its registered units, so the `list_agents` surface below fails
  99. # loud without it; web layers reuse this same mount for list rows.
  100. - id: session-projection
  101. name: '@deepseek-ai/dsh-session-projection'
  102. # Session telemetry, on for every dsh mode: mirrors every session-log
  103. # event (assistant/chunk projected to first-of-step) plus ops markers onto
  104. # OTLP/HTTP log records, streaming on the batch processor's cadence
  105. # (10s/batch here) — not at exit; a crash loses at most the last unexported
  106. # interval. No telemetry/record redaction rule is mounted yet, so exports
  107. # are the raw captured copy; the deployment stance, env seams, and
  108. # follow-ups are pinned in the web-telemetry-default-mount Agent Note.
  109. # DSH_TELEMETRY_OTLP_URL overrides the production endpoint, and a non-empty
  110. # DSH_TELEMETRY_DISABLED — any value, including '0'/'false' — opts the
  111. # process out (the launchers patch the row disabled; config cannot disable
  112. # a row). Exports carry the harness home's anonymous user id ($DSH_HOME/.userid,
  113. # random UUID; delete the file to reset the identity) as the Resource's
  114. # user.id. The exporter/processor values normally bound the shutdown drain
  115. # to ~1s against an unreachable collector: exporter.timeoutMillis is both
  116. # the per-attempt socket timeout and the retry deadline (1s effectively
  117. # disables the SDK's 5-try backoff), while maxExportBatchSize == maxQueueSize
  118. # (both explicit) makes the drain a single batch. The SDK awaits
  119. # exporter.forceFlush() outside exportTimeoutMillis, so the backend's 3s
  120. # shutdownTimeoutMillis is the load-bearing outer bound when a transport
  121. # promise never settles. Every CLI exit path drains it by disposing the root
  122. # on SIGINT/SIGTERM.
  123. - id: telemetry-otel
  124. name: '@deepseek-ai/dsh-session-telemetry-otel'
  125. config:
  126. shutdownTimeoutMillis: 3000
  127. exporter:
  128. url: !!js process.env.DSH_TELEMETRY_OTLP_URL ?? 'https://harness-telemetry.deepseeksvc.com/v1/logs'
  129. compression: gzip
  130. timeoutMillis: 1000
  131. processor:
  132. scheduledDelayMillis: 10000
  133. maxQueueSize: 2048
  134. maxExportBatchSize: 2048
  135. exportTimeoutMillis: 1500
  136. - id: subprocess
  137. name: '@deepseek-ai/dsh-subprocess-local'
  138. # Every shipped CLI mode starts with the same file-effect boundary.
  139. # The environment remains an explicit deployment override; otherwise fresh
  140. # sessions pin workspace-write + ask through the permission service below.
  141. - id: sandbox
  142. name: '@deepseek-ai/dsh-sandbox-local'
  143. - id: sandbox-policy
  144. name: '@deepseek-ai/dsh-sandbox-policy'
  145. config:
  146. mode: !!js process.env.DSH_PERMISSION_MODE ?? 'workspace-write'
  147. workspaceRoot: !!js process.cwd()
  148. - id: bash-sandbox
  149. name: '@deepseek-ai/dsh-bash-sandbox'
  150. config:
  151. timeoutMs: 60000
  152. - id: approval
  153. name: '@deepseek-ai/dsh-user-approval'
  154. config:
  155. policy: !!js "(process.env.DSH_PERMISSION_MODE ?? 'workspace-write') === 'danger-full-access' ? 'never' : 'ask'"
  156. - id: permission
  157. name: '@deepseek-ai/dsh-permission'
  158. config:
  159. presets:
  160. read-only:
  161. sandbox: read-only
  162. approval: ask
  163. workspace-write:
  164. sandbox: workspace-write
  165. approval: ask
  166. danger-full-access:
  167. sandbox: danger-full-access
  168. approval: never
  169. - id: bash-env
  170. name: '@deepseek-ai/dsh-bash-env'
  171. - id: tool-bash
  172. name: '@deepseek-ai/dsh-tool-bash'
  173. - id: tool-tasks
  174. name: '@deepseek-ai/dsh-tool-tasks'
  175. - id: fs-policy
  176. name: '@deepseek-ai/dsh-fs-policy'
  177. - id: tool-fs
  178. name: '@deepseek-ai/dsh-tool-fs'
  179. - id: tool-fs-search
  180. name: '@deepseek-ai/dsh-tool-fs-search'
  181. config:
  182. sampleOverCapGlobResults: false
  183. - id: workspace-context
  184. name: '@deepseek-ai/dsh-workspace-context'
  185. config:
  186. maxBytes: 65536
  187. - id: skill
  188. name: '@deepseek-ai/dsh-skill'
  189. - id: skill-local
  190. name: '@deepseek-ai/dsh-skill-local'
  191. - id: skill-badge
  192. name: '@deepseek-ai/dsh-skill-badge'
  193. disabled: true
  194. - id: tool-skill
  195. name: '@deepseek-ai/dsh-tool-skill'
  196. - id: commands
  197. name: '@deepseek-ai/dsh-commands'
  198. - id: command-feedback
  199. name: '@deepseek-ai/dsh-command-feedback'
  200. - id: goal
  201. name: '@deepseek-ai/dsh-goal'
  202. - id: goal-session
  203. name: '@deepseek-ai/dsh-goal-session'
  204. - id: command-goal
  205. name: '@deepseek-ai/dsh-command-goal'
  206. - id: plan-mode
  207. name: '@deepseek-ai/dsh-plan-mode'
  208. config:
  209. section: |
  210. You are in plan mode. Stay in plan mode until exit_plan_mode succeeds or the user switches the session mode. Imperative language to implement changes means plan the implementation, not execute it. A user's conversational agreement — including an answer confirming something you asked — approves nothing and does not end plan mode; fold the confirmed decision into the plan and submit it through exit_plan_mode.
  211. Explore first. Use non-mutating reads, searches, static analysis, and checks to ground the plan in the actual repository. Do not edit or write files, change configuration, run formatters or code generation that rewrites tracked files, commit, or otherwise carry out the plan. Prefer existing functions and patterns over new machinery.
  212. The tool catalog stays the same across modes for request-cache stability. These plan-mode rules override any later tool description or guidance that suggests using mutation tools; those tools remain listed only to keep the request shape stable. Do not use todo_write to track this planning phase: it tracks implementation after an approved plan, while the plan itself belongs in exit_plan_mode.
  213. Resolve discoverable facts by inspection. Use ask_user_question only for user-owned choices or material ambiguity that inspection cannot answer. Do not ask the user where code lives or how current behavior works when you can find out.
  214. Make the plan decision-complete: state the goal and success criteria; group implementation changes by subsystem; identify public API, schema, and data-flow changes; cover edge cases, failure modes, tests, acceptance criteria, and explicit assumptions. Keep it concise enough to review but detailed enough that another engineer can implement it without making design decisions.
  215. When ready, call exit_plan_mode with the complete plan markdown, starting with a # title. Make exit_plan_mode the only and final tool call in that assistant response: it presents the plan for approval, and implementation begins only in a later step after approval. Do not paste the final plan as a plain reply or ask "should I proceed?" through prose or ask_user_question. If review rejects it, incorporate the feedback and present again. If the review channel is unavailable or aborted, stay in plan mode and ask the user to switch modes manually; do not proceed with implementation.
  216. - id: token-meter
  217. name: '@deepseek-ai/dsh-token-meter'
  218. - id: compact-basic
  219. name: '@deepseek-ai/dsh-compact-basic'
  220. # Human `/compact`: one useful reduction below the automatic threshold. Backend
  221. # independent, so it follows whichever compaction service this leaf mounts.
  222. - id: command-compact
  223. name: '@deepseek-ai/dsh-command-compact'
  224. - id: subagent
  225. name: '@deepseek-ai/dsh-subagent'
  226. - id: subagent-spawn
  227. name: '@deepseek-ai/dsh-subagent-spawn'
  228. config:
  229. providerName: spawn
  230. - id: subagent-fork
  231. name: '@deepseek-ai/dsh-subagent-fork'
  232. config:
  233. providerName: fork
  234. # Continuable background children are selected per delegation tool. The
  235. # separately loaded follow-up tool registers the one global `send_message`.
  236. - id: tool-subagent-control
  237. name: '@deepseek-ai/dsh-tool-subagent-control'
  238. - id: tool-subagent-list-agents
  239. name: '@deepseek-ai/dsh-tool-subagent-control/list-agents'
  240. - id: tool-subagent
  241. name: '@deepseek-ai/dsh-tool-subagent'
  242. config:
  243. provider: spawn
  244. toolName: subagent
  245. backgroundMode: continuable
  246. - id: tool-subagent-fork
  247. name: '@deepseek-ai/dsh-tool-subagent'
  248. config:
  249. provider: fork
  250. toolName: subagent_fork
  251. backgroundMode: continuable
  252. # Optional direct-child return channel; absent from roots and one-shot agents.
  253. - id: tool-subagent-report
  254. name: '@deepseek-ai/dsh-tool-subagent-report'
  255. - id: workflow-workerthread
  256. name: '@deepseek-ai/dsh-workflow-workerthread'
  257. config:
  258. provider: spawn
  259. - id: tool-workflow
  260. name: '@deepseek-ai/dsh-tool-workflow'
  261. - id: timeout-policy
  262. name: '@deepseek-ai/dsh-timeout-policy'
  263. - id: spill-local
  264. name: '@deepseek-ai/dsh-spill-local'
  265. - id: spill-policy
  266. name: '@deepseek-ai/dsh-spill-policy'
  267. config:
  268. maxInlineBytes: 50000
  269. # Durability checkpoints before each model request and top-level dispatch.
  270. - id: session-checkpoint-policy
  271. name: '@deepseek-ai/dsh-session-checkpoint-policy'
  272. # Compacts oversized tool results before the broader conversation compactor
  273. # runs, preserving the model-visible result within the configured budget.
  274. - id: tool-result-prune
  275. name: '@deepseek-ai/dsh-compact-tool-result-prune'
  276. config:
  277. thresholdChars: 8192
  278. headChars: 4096
  279. tailChars: 1024
  280. - id: tool-todo
  281. name: '@deepseek-ai/dsh-tool-todo'
  282. config:
  283. allowParallelInProgress: true
  284. # Persisted same-session goals reach the model and the slash menu here; the
  285. # domain, driver, and `/goal` command are above.
  286. - id: tool-goal
  287. name: '@deepseek-ai/dsh-tool-goal'
  288. # Fresh-agent Ralph iteration over a build-time-fixed script.
  289. - id: tool-ralph
  290. name: '@deepseek-ai/dsh-tool-ralph'
  291. config:
  292. subagentProvider: spawn
  293. maxRounds: 64
  294. - id: tool-str-replace-editor
  295. name: '@deepseek-ai/dsh-tool-str-replace-editor'
  296. config:
  297. maxOutputChars: 16000
  298. # Consecutive-repeat reminders on the tool chain.
  299. - id: repeat-tool-guard
  300. name: '@deepseek-ai/dsh-repeat-tool-guard'
  301. config:
  302. thresholds: [3, 5, 8]
  303. argumentsPreviewChars: 500
  304. # Every mode enables the stable web_search model surface. DeepSeek search
  305. # resolves the same DEEPSEEK_API_KEY credential the Models page manages for
  306. # chat, at each search; its Messages endpoint is separate from the
  307. # chat-completions endpoint, so it takes its own base-URL override. Fetch stays
  308. # disabled and no fetch provider is mounted: that provider defers SSRF
  309. # protection and the model would choose the request target. Search is a full
  310. # auxiliary model request with server-side retrieval, so this shipped DeepSeek
  311. # route gets 60s while the provider-neutral tool default remains 30s.
  312. - id: web
  313. name: '@deepseek-ai/dsh-web'
  314. config:
  315. searchProvider: deepseek-official
  316. - id: web-search-deepseek
  317. name: '@deepseek-ai/dsh-web-search-deepseek'
  318. config:
  319. apiKeyEnv: DEEPSEEK_API_KEY
  320. - id: tool-web
  321. name: '@deepseek-ai/dsh-tool-web'
  322. config:
  323. fetch: false
  324. searchTimeoutMs: 60000
  325. # ── rows every mode mounts, whose values each overlay may state ──────────────
  326. # The tool registry. Presentation mode is a deployment choice; omitting it here
  327. # keeps the schema default (native).
  328. - id: tools
  329. name: '@deepseek-ai/dsh-tools'
  330. # The deployment persona is a deployment choice; plan-mode and tool plugins own
  331. # their own prompt sections.
  332. - id: system-prompt
  333. name: '@deepseek-ai/dsh-system-prompt'
  334. config:
  335. persona: ''
  336. # Agents created at startup. The base stays empty; raw overlays may create
  337. # agents, while Web creates sessions on client request.
  338. - id: agent-loop
  339. name: '@deepseek-ai/dsh-agent-loop'
  340. config:
  341. agents: []
  342. # The sandboxed filesystem provider. `cwd` defaults to `process.cwd()`; an
  343. # overlay can pin another workspace.
  344. - id: fs-sandbox
  345. name: '@deepseek-ai/dsh-fs-sandbox'
  346. # The native DeepSeek adapter. No key or endpoint is inlined: both resolve per
  347. # request from the `llm-deepseek:` settings section over this entry, with the
  348. # key coming from the credential store below. Thinking defaults are a deployment
  349. # choice.
  350. - id: llm-deepseek
  351. name: '@deepseek-ai/dsh-llm-deepseek'