cordis.patch.yml 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460
  1. # The dsh-base bundle patch: the shared core of every dsh profile, applied as
  2. # ONE insert over the empty profile root. Later bundle patches and the user's
  3. # profile cordis.patch.yml address these rows by id, with the last write
  4. # winning per row.
  5. #
  6. # A patch replaces the targeted row's whole `config` rather than merging into
  7. # it, so a row whose value differs by mode does NOT live here: it belongs to
  8. # each mode bundle, keeping any single row down to one bundle layer plus the
  9. # user's. Mode-specific rows appear below only with shared plugin identity and
  10. # neutral defaults; each mode bundle restates its complete configuration.
  11. #
  12. # Row order carries no load semantics (activation is service-availability
  13. # driven); the grouping is for readers.
  14. - insert:
  15. - id: timer
  16. name: '@deepseek-ai/cordis-plugin-timer'
  17. - id: hmr
  18. name: '@deepseek-ai/cordis-plugin-hmr'
  19. config:
  20. root: ['.']
  21. - id: llm
  22. name: '@deepseek-ai/dsh-llm'
  23. - id: deepseek-llm-api-extensions
  24. name: '@deepseek-ai/dsh-deepseek-llm-api-extensions'
  25. - id: session
  26. name: '@deepseek-ai/dsh-session'
  27. - id: session-log-deepseek
  28. name: '@deepseek-ai/dsh-session-log-deepseek'
  29. - id: typert
  30. name: '@deepseek-ai/dsh-typert-registry'
  31. - id: typert-loader
  32. name: '@deepseek-ai/dsh-typert-loader'
  33. - id: typert-gateway
  34. name: '@deepseek-ai/dsh-api-gateway'
  35. - id: session-title
  36. name: '@deepseek-ai/dsh-session-title'
  37. config:
  38. fallbackMaxWords: 5
  39. fallbackMaxBytes: 40
  40. maxTitleBytes: 80
  41. - id: session-title-llm
  42. name: '@deepseek-ai/dsh-session-title-first-prompt-llm'
  43. config:
  44. targetWords: 5
  45. targetCjkCharacters: 10
  46. maxInputBytes: 4096
  47. maxOutputTokens: 64
  48. timeoutMs: 60000
  49. - id: user-questions
  50. name: '@deepseek-ai/dsh-user-questions'
  51. - id: agent
  52. name: '@deepseek-ai/dsh-agent'
  53. - id: plugin-package-inventory-deepseek
  54. name: '@deepseek-ai/dsh-plugin-package-inventory-deepseek'
  55. # The transport-independent default for Agents created by entry points.
  56. # Settings may supply a saved selection; consumers read it at creation time.
  57. - id: agent-default-model
  58. name: '@deepseek-ai/dsh-agent-default-model'
  59. config:
  60. provider: deepseek-official
  61. model: deepseek-v4-flash
  62. - id: jobs
  63. name: '@deepseek-ai/dsh-jobs-local'
  64. - id: llm-retry
  65. name: '@deepseek-ai/dsh-llm-retry'
  66. # User-settings document (`$DSH_HOME/settings.yaml`, hot-reloaded): a
  67. # `llm-deepseek:` or `llm-pi-ai:` section there overrides the adapter entries
  68. # below without a restart, and is what the web Models page writes.
  69. - id: settings
  70. name: '@deepseek-ai/dsh-settings-file'
  71. # Credential sources: inherited environment over the managed
  72. # `$DSH_HOME/.credentials.yaml`, with project and user `.env` fallbacks.
  73. # Adapters resolve references per request; the Models page writes only the
  74. # managed document, which is never materialized into the process environment.
  75. - id: credentials
  76. name: '@deepseek-ai/dsh-credentials-local'
  77. # The pi-ai multi-provider twin, mounted dormant: zero routes (and no extra
  78. # models in the picker) until a `llm-pi-ai:` settings section supplies provider
  79. # profiles — then those routes register live, keys resolving per request
  80. # through their apiKeyEnv references, and drop again when the section empties.
  81. # Supplying those profiles is exactly what the web Models page does. Which
  82. # adapters exist is composition; which providers run is the user's settings
  83. # document.
  84. - id: llm-pi-ai
  85. name: '@deepseek-ai/dsh-llm-pi-ai'
  86. - id: session-persistence-jsonl
  87. name: '@deepseek-ai/dsh-session-persistence-jsonl'
  88. config:
  89. root: !!js dshHomePath('sessions')
  90. # Durable image bytes live outside the append-only session log. Messages
  91. # keep content-addressed references that this shared backend resolves for
  92. # provider requests and authorized history reads.
  93. - id: attachment-local
  94. name: '@deepseek-ai/dsh-attachment-local'
  95. # Full-text session search is opt-in. `openAt: never` keeps
  96. # ctx.sessionQuery mounted — exact reads, titles, and lineage traces
  97. # (session export, subagent-fork Workspace inheritance) stay available —
  98. # while search calls fail with SESSION_QUERY_SEARCH_DISABLED and SQLite is
  99. # never opened; the Web sidebar search matches titles and workspace names
  100. # only. Deployments enabling content search override `openAt` to
  101. # `first-search` or `startup` in a later patch layer (profile
  102. # cordis.patch.yml or a --patch overlay), typically with a durable `path`.
  103. - id: session-query-sqlite
  104. name: '@deepseek-ai/dsh-session-query-sqlite'
  105. config:
  106. path: ':memory:'
  107. openAt: never
  108. # Shared projection registry: subagent catalog identity (mode/label) folds
  109. # through its registered units, so the `list_agents` surface below fails
  110. # loud without it; web layers reuse this same mount for list rows.
  111. - id: session-projection
  112. name: '@deepseek-ai/dsh-session-projection'
  113. # Session telemetry is mounted but disabled by default. DSH_TELEMETRY_MODE
  114. # explicitly opts into FULL or FEEDBACK_ONLY reporting; uploading mirrors
  115. # session-log records onto OTLP/HTTP logs with no session-telemetry/record redaction
  116. # rule, so exports are the raw captured copy. The deployment stance, env
  117. # seams, and follow-ups are pinned in the default-off Agent Note.
  118. # DSH_TELEMETRY_OTLP_URL overrides the production endpoint. A non-empty
  119. # DSH_TELEMETRY_DISABLED — any value, including '0'/'false' — opts the
  120. # process out (the launchers patch the row disabled; config cannot disable
  121. # a row). Exports carry the harness home's anonymous user id ($DSH_HOME/.anonymous-user-id,
  122. # random UUID; delete the file to reset the identity) as the Resource's
  123. # user.id. The exporter/processor values normally bound the shutdown drain
  124. # to ~1s against an unreachable collector: exporter.timeoutMillis is both
  125. # the per-attempt socket timeout and the retry deadline (1s effectively
  126. # disables the SDK's 5-try backoff), while maxExportBatchSize == maxQueueSize
  127. # (both explicit) makes the drain a single batch. The SDK awaits
  128. # exporter.forceFlush() outside exportTimeoutMillis, so the backend's 3s
  129. # shutdownTimeoutMillis is the load-bearing outer bound when a transport
  130. # promise never settles. Every CLI exit path drains it by disposing the root
  131. # on SIGINT/SIGTERM.
  132. - id: session-telemetry-otel
  133. name: '@deepseek-ai/dsh-session-telemetry-otel'
  134. config:
  135. mode: !!js process.env.DSH_TELEMETRY_MODE || 'DISABLED'
  136. shutdownTimeoutMillis: 3000
  137. exporter:
  138. url: !!js process.env.DSH_TELEMETRY_OTLP_URL ?? 'https://harness-telemetry.deepseeksvc.com/v1/logs'
  139. compression: gzip
  140. timeoutMillis: 1000
  141. processor:
  142. scheduledDelayMillis: 10000
  143. maxQueueSize: 2048
  144. maxExportBatchSize: 2048
  145. exportTimeoutMillis: 1500
  146. - id: subprocess
  147. name: '@deepseek-ai/dsh-subprocess-local'
  148. # Every shipped CLI mode starts with the same file-effect boundary.
  149. # The environment remains an explicit deployment override; otherwise fresh
  150. # sessions pin workspace-write + ask through the permission service below.
  151. - id: sandbox
  152. name: '@deepseek-ai/dsh-sandbox-local'
  153. - id: sandbox-policy
  154. name: '@deepseek-ai/dsh-sandbox-policy'
  155. config:
  156. mode: !!js process.env.DSH_PERMISSION_MODE ?? 'workspace-write'
  157. workspaceRoot: !!js process.cwd()
  158. - id: bash-sandbox
  159. name: '@deepseek-ai/dsh-bash-sandbox'
  160. disabled: !!js process.platform === 'win32'
  161. config:
  162. timeoutMs: 60000
  163. - id: pwsh-sandbox
  164. name: '@deepseek-ai/dsh-pwsh-sandbox'
  165. disabled: !!js process.platform !== 'win32'
  166. - id: approval
  167. name: '@deepseek-ai/dsh-user-approval'
  168. config:
  169. policy: !!js "(process.env.DSH_PERMISSION_MODE ?? 'workspace-write') === 'danger-full-access' ? 'never' : 'ask'"
  170. - id: permission
  171. name: '@deepseek-ai/dsh-permission-presets'
  172. config:
  173. presets:
  174. read-only:
  175. sandbox: read-only
  176. approval: ask
  177. workspace-write:
  178. sandbox: workspace-write
  179. approval: ask
  180. danger-full-access:
  181. sandbox: danger-full-access
  182. approval: never
  183. - id: shell-env
  184. name: '@deepseek-ai/dsh-shell-env'
  185. - id: tool-bash
  186. name: '@deepseek-ai/dsh-tool-bash'
  187. disabled: !!js process.platform === 'win32'
  188. - id: tool-pwsh
  189. name: '@deepseek-ai/dsh-tool-pwsh'
  190. disabled: !!js process.platform !== 'win32'
  191. - id: tool-jobs
  192. name: '@deepseek-ai/dsh-tool-jobs'
  193. - id: fs-observation-policy
  194. name: '@deepseek-ai/dsh-fs-observation-policy'
  195. - id: tool-fs
  196. name: '@deepseek-ai/dsh-tool-fs'
  197. - id: tool-fs-search
  198. name: '@deepseek-ai/dsh-tool-fs-search'
  199. config:
  200. sampleOverCapGlobResults: false
  201. - id: agent-instructions
  202. name: '@deepseek-ai/dsh-agent-instructions'
  203. config:
  204. maxBytes: 65536
  205. - id: skill
  206. name: '@deepseek-ai/dsh-skill'
  207. - id: skill-filesystem
  208. name: '@deepseek-ai/dsh-skill-filesystem'
  209. - id: skill-badge
  210. name: '@deepseek-ai/dsh-skill-badge'
  211. disabled: true
  212. - id: tool-skill
  213. name: '@deepseek-ai/dsh-tool-skill'
  214. - id: commands
  215. name: '@deepseek-ai/dsh-commands'
  216. - id: command-feedback
  217. name: '@deepseek-ai/dsh-command-feedback'
  218. - id: goal
  219. name: '@deepseek-ai/dsh-goal'
  220. - id: goal-round-driver
  221. name: '@deepseek-ai/dsh-goal-round-driver'
  222. - id: command-goal
  223. name: '@deepseek-ai/dsh-command-goal'
  224. - id: plan-mode
  225. name: '@deepseek-ai/dsh-plan-mode'
  226. config:
  227. section: |
  228. You are in plan mode. Stay in plan mode until exit_plan_mode succeeds or the user switches the session mode. Imperative language to implement changes means plan the implementation, not execute it. A user's conversational agreement — including an answer confirming something you asked — approves nothing and does not end plan mode; fold the confirmed decision into the plan and submit it through exit_plan_mode.
  229. Explore first. Use non-mutating reads, searches, static analysis, and checks to ground the plan in the actual repository. Do not edit or write files, change configuration, run formatters or code generation that rewrites tracked files, commit, or otherwise carry out the plan. Prefer existing functions and patterns over new machinery.
  230. The tool catalog stays the same across modes for request-cache stability. These plan-mode rules override any later tool description or guidance that suggests using mutation tools; those tools remain listed only to keep the request shape stable. Do not use todo_write to track this planning phase: it tracks implementation after an approved plan, while the plan itself belongs in exit_plan_mode.
  231. Resolve discoverable facts by inspection. Use ask_user_question only for user-owned choices or material ambiguity that inspection cannot answer. Do not ask the user where code lives or how current behavior works when you can find out.
  232. Make the plan decision-complete: state the goal and success criteria; group implementation changes by subsystem; identify public API, schema, and data-flow changes; cover edge cases, failure modes, tests, acceptance criteria, and explicit assumptions. Keep it concise enough to review but detailed enough that another engineer can implement it without making design decisions.
  233. When ready, call exit_plan_mode with the complete plan markdown, starting with a # title. Make exit_plan_mode the only and final tool call in that assistant response: it presents the plan for approval, and implementation begins only in a later step after approval. Do not paste the final plan as a plain reply or ask "should I proceed?" through prose or ask_user_question. If review rejects it, incorporate the feedback and present again. If the review channel is unavailable or aborted, stay in plan mode and ask the user to switch modes manually; do not proceed with implementation.
  234. - id: token-meter
  235. name: '@deepseek-ai/dsh-token-meter'
  236. - id: compaction-basic
  237. name: '@deepseek-ai/dsh-compaction-basic'
  238. # Human `/compact`: one useful reduction below the automatic threshold. Backend
  239. # independent, so it follows whichever compaction service this leaf mounts.
  240. - id: command-compact
  241. name: '@deepseek-ai/dsh-command-compact'
  242. - id: subagent
  243. name: '@deepseek-ai/dsh-subagent'
  244. - id: subagent-spawn-in-process
  245. name: '@deepseek-ai/dsh-subagent-spawn-in-process'
  246. config:
  247. providerName: spawn
  248. - id: subagent-fork-in-process
  249. name: '@deepseek-ai/dsh-subagent-fork-in-process'
  250. config:
  251. providerName: fork
  252. # Continuable background children are selected per delegation tool. The
  253. # separately loaded follow-up tool registers the one global `send_message`.
  254. - id: tool-subagent-control
  255. name: '@deepseek-ai/dsh-tool-subagent-control'
  256. - id: tool-subagent-list-agents
  257. name: '@deepseek-ai/dsh-tool-subagent-control/list-agents'
  258. - id: tool-subagent
  259. name: '@deepseek-ai/dsh-tool-subagent'
  260. config:
  261. provider: spawn
  262. toolName: subagent
  263. backgroundMode: continuable
  264. # Fork stays one-shot: a continuable child's `report` tool and prompt
  265. # section precede the inherited history a fork exists to reuse; one-shot
  266. # fork children install neither, keeping the parent's request prefix.
  267. # See .agents/notes/implemented/architecture/2026-08-10-fork-children-stay-one-shot.md.
  268. - id: tool-subagent-fork
  269. name: '@deepseek-ai/dsh-tool-subagent'
  270. config:
  271. provider: fork
  272. toolName: subagent_fork
  273. backgroundMode: one-shot
  274. # Optional direct-child return channel; absent from roots and one-shot agents.
  275. - id: tool-subagent-report
  276. name: '@deepseek-ai/dsh-tool-subagent-report'
  277. - id: workflow-worker-thread
  278. name: '@deepseek-ai/dsh-workflow-worker-thread'
  279. config:
  280. provider: spawn
  281. - id: tool-workflow
  282. name: '@deepseek-ai/dsh-tool-workflow'
  283. - id: timeout-policy
  284. name: '@deepseek-ai/dsh-tool-call-timeout-policy'
  285. - id: spill-local
  286. name: '@deepseek-ai/dsh-spill-local'
  287. - id: spill-policy
  288. name: '@deepseek-ai/dsh-spill-policy'
  289. config:
  290. maxInlineBytes: 50000
  291. # Durability checkpoints before each model request and top-level dispatch.
  292. - id: session-checkpoint-policy
  293. name: '@deepseek-ai/dsh-session-checkpoint-policy'
  294. # Compacts oversized tool results before the broader conversation compactor
  295. # runs, preserving the model-visible result within the configured budget.
  296. - id: tool-result-pruner
  297. name: '@deepseek-ai/dsh-compaction-tool-result-pruner'
  298. config:
  299. thresholdChars: 8192
  300. headChars: 4096
  301. tailChars: 1024
  302. - id: tool-todo
  303. name: '@deepseek-ai/dsh-tool-todo'
  304. config:
  305. allowParallelInProgress: true
  306. # Persisted same-session goals reach the model and the slash menu here; the
  307. # domain, driver, and `/goal` command are above.
  308. - id: tool-goal
  309. name: '@deepseek-ai/dsh-tool-goal'
  310. # Fresh-agent Ralph iteration over a build-time-fixed script.
  311. - id: tool-ralph
  312. name: '@deepseek-ai/dsh-tool-ralph'
  313. config:
  314. subagentProvider: spawn
  315. maxRounds: 64
  316. - id: tool-str-replace-editor
  317. name: '@deepseek-ai/dsh-tool-str-replace-editor'
  318. config:
  319. maxOutputChars: 16000
  320. # Consecutive-repeat reminders on the tool chain.
  321. - id: repeat-tool-reminder
  322. name: '@deepseek-ai/dsh-repeat-tool-reminder'
  323. config:
  324. thresholds: [3, 5, 8]
  325. argumentsPreviewChars: 500
  326. # Every mode enables the stable model-facing web_search tool. DeepSeek search
  327. # resolves the same DEEPSEEK_API_KEY credential the Models page manages for
  328. # chat, at each search; its Messages endpoint is separate from the
  329. # chat-completions endpoint, so it takes its own base-URL override. Fetch stays
  330. # disabled and no fetch provider is mounted: that provider defers SSRF
  331. # protection and the model would choose the request target. Search is a full
  332. # auxiliary model request with server-side retrieval, so this shipped DeepSeek
  333. # route gets 60s while the provider-neutral tool default remains 30s.
  334. - id: web
  335. name: '@deepseek-ai/dsh-web'
  336. config:
  337. searchProvider: deepseek-official
  338. - id: web-search-deepseek
  339. name: '@deepseek-ai/dsh-web-search-deepseek'
  340. config:
  341. apiKeyEnv: DEEPSEEK_API_KEY
  342. - id: tool-web
  343. name: '@deepseek-ai/dsh-tool-web'
  344. config:
  345. fetch: false
  346. searchTimeoutMs: 60000
  347. # ── rows every mode mounts, whose values each overlay may state ──────────────
  348. # The tool registry. Presentation mode is a deployment choice; omitting it here
  349. # keeps the schema default (native).
  350. - id: tools
  351. name: '@deepseek-ai/dsh-tools'
  352. # The deployment persona is a deployment choice; plan-mode and tool plugins own
  353. # their own prompt sections.
  354. - id: system-prompt
  355. name: '@deepseek-ai/dsh-system-prompt'
  356. config:
  357. persona: ''
  358. # Agents created at startup. The base stays empty; raw overlays may create
  359. # agents, while Web creates sessions on client request.
  360. - id: agent-loop
  361. name: '@deepseek-ai/dsh-agent-loop'
  362. config:
  363. agents: []
  364. # The sandboxed filesystem provider. `cwd` defaults to `process.cwd()`; an
  365. # overlay can pin another workspace.
  366. - id: fs-sandbox
  367. name: '@deepseek-ai/dsh-fs-sandbox'
  368. # The native DeepSeek adapter. No key or endpoint is inlined: both resolve per
  369. # request from the `llm-deepseek:` settings section over this entry, with the
  370. # key coming from the credential store below. Thinking defaults are a deployment
  371. # choice.
  372. - id: llm-deepseek
  373. name: '@deepseek-ai/dsh-llm-deepseek'