cordis.patch.yml 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369
  1. # The dsh-web-app bundle patch: the browser surface over the dsh-base layer.
  2. # Applied after dsh-base's insert; rows here override base rows by id, with
  3. # the profile's own cordis.patch.yml and any --patch overlays still to come.
  4. #
  5. # A patch replaces the targeted row's whole `config`, so each row below
  6. # restates every key it owns.
  7. #
  8. # The web-startup plugin injects `cmdlineArgs` and provides `webStartup` as an
  9. # ordinary Cordis service. Rows configured from flags inject that service, so
  10. # Loader resolves their expressions only after it exists. The web runtime then
  11. # provides bind-dependent `webRuntime` values to the trust fence and client
  12. # roster. `dsh --profile web --help` provides neither service, so no server binds.
  13. # ── surface-specific values the base deliberately omits ─────────────────────
  14. - id: system-prompt
  15. config:
  16. persona: >-
  17. You are a coding agent powered by the {{model}} model. Your working directory is {{cwd}}.
  18. # TODO: Re-enable shared HMR for Web after its reload lifecycle is tested.
  19. - id: hmr
  20. disabled: true
  21. # Web content search runs on an ephemeral in-memory index. The service
  22. # activates at boot, while first-search defers the node:sqlite import and
  23. # in-memory handle so Node 22 startup stays quiet until content search
  24. # actually uses SQLite. That search then reconciles this boot's sources.
  25. - id: session-query-sqlite
  26. config:
  27. path: ':memory:'
  28. openAt: first-search
  29. - id: tools
  30. config:
  31. # TEMPORARY workaround: DSH_TOOLS_MODE (native|code|both) opts a whole dsh
  32. # process into Code Mode while per-session tool-mode selection is being
  33. # designed; unset keeps the schema default (native). Remove the env seam
  34. # once the web UI owns the choice per session.
  35. mode: !!js process.env.DSH_TOOLS_MODE
  36. # ── web-only host rows, the transport layer, and the browser roster ─────────
  37. # `dsh.client` rows are the browser roster the modules node half scans into
  38. # window.__DSH_BOOT__; the modules row is simultaneously a host row.
  39. - insert:
  40. - id: code-runtime
  41. name: '@deepseek-ai/dsh-code-runtime-worker'
  42. - id: storage
  43. name: '@deepseek-ai/dsh-storage'
  44. - id: storage-json
  45. name: '@deepseek-ai/dsh-storage-json'
  46. config:
  47. root: !!js dshHomePath('storages')
  48. - id: storage-domain
  49. name: '@deepseek-ai/dsh-storage-domain'
  50. config:
  51. backend: json
  52. - id: workspace
  53. name: '@deepseek-ai/dsh-workspace'
  54. - id: session-projection-cache
  55. name: '@deepseek-ai/dsh-session-projection-cache'
  56. config:
  57. writeEveryEvents: 200
  58. writeIntervalMs: 5000
  59. # Resolve bind host, SSH launch, and display once at boot, then mount the
  60. # matching dual-face directory picker. Mount -native or -browse directly in
  61. # an overlay to pin the interaction.
  62. - id: directory-picker
  63. name: '@deepseek-ai/dsh-host-directory-picker-auto'
  64. # The API gateway: the transport-agnostic dispatch face every client shape
  65. # shares. The base layer's agent-default-model service owns the default model.
  66. - id: api-gateway
  67. name: '@deepseek-ai/dsh-host-apiproxy'
  68. # Ordinary provider for the parsed Web flags. Its plugin-level injection
  69. # waits for cmdlineArgs; no launcher metadata or special row kind is needed.
  70. - id: web-startup
  71. name: '@deepseek-ai/dsh-web-app/startup'
  72. # ── layer 2: transport/service ──────────────────────────────────────────────
  73. # Plain route-registration carrier; host and port come from the app's
  74. # webStartup provider, with these deployment fallbacks. The dist is served by
  75. # the web-runtime row below through the fallback seat.
  76. - id: webserver
  77. name: '@deepseek-ai/dsh-host-webserver'
  78. inject: [webStartup]
  79. config:
  80. host: !!js ctx.webStartup.host ?? '127.0.0.1'
  81. port: !!js ctx.webStartup.port ?? 3080
  82. # Web glue owned by this bundle: resolves the built frontend dist (an
  83. # assembly fact of dsh-web-app, never user config), mounts the
  84. # frontend-static fallback owner, registers the web-surface prompt
  85. # section and bash runtime variables, and prints the URL line. The webStartup
  86. # provider supplies invocation-only values; after the server binds, this row
  87. # samples LAN trust once and provides `webRuntime`. A complete agent-preset
  88. # persona suppresses the prompt section for that agent while retaining
  89. # these host-owned shell variables.
  90. - id: web-runtime
  91. name: '@deepseek-ai/dsh-web-app'
  92. inject: [webStartup]
  93. config:
  94. mode: !!js ctx.webStartup.mode
  95. printUrl: true
  96. surfaceContext: true
  97. trustedHosts: !!js ctx.webStartup.trustedHosts
  98. # The client-plugin reload chain: a dev-only row this bundle ships off,
  99. # which the runtime row turns on before client discovery. It is a row rather
  100. # than a child of web-runtime because its node half is a client-side package,
  101. # which a host-side bundle cannot import.
  102. - id: client-hmr
  103. name: '@deepseek-ai/dsh-client-hmr'
  104. inject: [webStartup]
  105. disabled: true
  106. # ── browser plugin roster (dsh.client rows; node halves are layer-2 hosts) ──
  107. # Dual-face: this waits for the runtime row to decide whether HMR belongs
  108. # in the first graph. The node half then scans this tree, composes
  109. # window.__DSH_BOOT__, and serves /plugins/<id>/client.js; the browser half
  110. # is the module table the shell kernel constructs before cordis exists
  111. # (adopted as a plugin entry by the kernel, never fetched).
  112. - id: modules
  113. name: '@deepseek-ai/dsh-client-modules'
  114. inject: [webRuntime]
  115. # Owns both ends of the web transport: node half binds the gateway to the
  116. # webserver under /api; browser half is the fetch/SSE client.
  117. - id: connection
  118. name: '@deepseek-ai/dsh-client-connection'
  119. inject: [webRuntime]
  120. config:
  121. # LAN literals derived from the active bind plus --trusted-host extras.
  122. # A deployment adding authorities keeps this expression and concatenates
  123. # its literals, for example: ['app.internal', ...ctx.webRuntime.trustedHosts].
  124. trustedHosts: !!js ctx.webRuntime.trustedHosts
  125. - id: api-remotes
  126. name: '@deepseek-ai/dsh-api-remotes'
  127. - id: client-runtime
  128. name: '@deepseek-ai/dsh-client-runtime'
  129. - id: ui-theme
  130. name: '@deepseek-ai/dsh-client-ui-theme'
  131. - id: locale
  132. name: '@deepseek-ai/dsh-client-locale'
  133. - id: ui-layout
  134. name: '@deepseek-ai/dsh-client-ui-layout'
  135. - id: ui-sidebar
  136. name: '@deepseek-ai/dsh-client-ui-sidebar'
  137. - id: ui-settings
  138. name: '@deepseek-ai/dsh-client-ui-settings'
  139. - id: ui-settings-general
  140. name: '@deepseek-ai/dsh-client-ui-settings-general'
  141. - id: ui-models
  142. name: '@deepseek-ai/dsh-client-ui-models'
  143. - id: ui-conversation
  144. name: '@deepseek-ai/dsh-client-ui-conversation'
  145. # Tool call tree, generic fallback, and keyed business Tool views.
  146. - id: ui-tool
  147. name: '@deepseek-ai/dsh-client-ui-tool'
  148. # Turn tail: the produced-files row under each closing assistant message.
  149. # Remove this entry to turn the surface off; the tail hole renders empty.
  150. - id: ui-deliverables
  151. name: '@deepseek-ai/dsh-client-ui-deliverables'
  152. - id: ui-workspace
  153. name: '@deepseek-ai/dsh-client-ui-workspace'
  154. # Input triggers: the '/' | '@' pipeline (ui-slash), the command surface over
  155. # it (ui-command), and the two reference sources (ui-skill / ui-subagent).
  156. - id: ui-slash
  157. name: '@deepseek-ai/dsh-client-ui-slash'
  158. - id: ui-command
  159. name: '@deepseek-ai/dsh-client-ui-command'
  160. - id: ui-skill
  161. name: '@deepseek-ai/dsh-client-ui-skill'
  162. - id: ui-subagent
  163. name: '@deepseek-ai/dsh-client-ui-subagent'
  164. # Goal surface: GoalBar in the input dock over the goal session projection.
  165. - id: ui-goal
  166. name: '@deepseek-ai/dsh-client-ui-goal'
  167. # Model selection: the /model popupSelect + composer seat over session.models.
  168. - id: ui-model
  169. name: '@deepseek-ai/dsh-client-ui-model'
  170. - id: ui-permission
  171. name: '@deepseek-ai/dsh-client-ui-permission'
  172. # The agent-preset row in General settings: the default preset for
  173. # sessions created later. Absent a roster it renders nothing.
  174. - id: ui-agent-preset
  175. name: '@deepseek-ai/dsh-client-ui-agent-preset'
  176. # Plan control: the composer plan seat over the plan projection + /plan channel.
  177. - id: ui-plan
  178. name: '@deepseek-ai/dsh-client-ui-plan'
  179. - id: ui-question
  180. name: '@deepseek-ai/dsh-client-ui-question'
  181. - id: ui-trajectory
  182. name: '@deepseek-ai/dsh-client-ui-trajectory'
  183. # ── the agent plane moves behind agent presets ─────────────────────────────
  184. #
  185. # Every row below composes what ONE agent contributes to the host registries:
  186. # its tools, its prompt sections, its delegation backends. The base keeps them
  187. # for the TUI, which is single-session and composes its agent process-wide; the
  188. # Web surface disables them here and lets each session mount a preset instead.
  189. #
  190. # Disabling rather than deleting is deliberate: the base is shared, and a row
  191. # absent from a surface overlay would silently reappear the day someone reorders
  192. # the composition.
  193. # `bash-env` STAYS in the host plane: `apps/cli/src/web.ts` injects it to
  194. # publish `DSH_WEB_URL`/`DSH_WEB_MODE`, and a host row that injects a service is
  195. # the criterion for host-plane ownership — injection resolves before any session
  196. # exists, so there is no agent to key by. Behind a preset realm those variables
  197. # would never reach the model's shell at all.
  198. - id: tool-bash
  199. disabled: true
  200. # The background-task REGISTRY stays on the host plane; only the model-facing
  201. # `task_*` controls move. Its producers — `tool-bash` here, `tool-pty` and a
  202. # non-continuable `tool-subagent` elsewhere — are preset rows that resolve it
  203. # with `ctx.get`, and an entry-local realm around the registry is invisible to
  204. # every sibling row outside that realm, so `run_in_background` answered
  205. # "background tasks unavailable" while the controls sat in the catalog. That is
  206. # the `goals` criterion read from inside the preset: a Service a row outside its
  207. # realm READS belongs to the plane both can see. The registry is keyed by owning
  208. # agent, so one host instance serves every session exactly as before presets.
  209. - id: tool-tasks
  210. disabled: true
  211. - id: tool-fs
  212. disabled: true
  213. - id: tool-fs-search
  214. disabled: true
  215. - id: tool-str-replace-editor
  216. disabled: true
  217. # The `skill` REGISTRY stays in the host plane. It is host+per-scope layered
  218. # (the tools-registry shape): deployment-level providers — repository plugins,
  219. # a host skill-local row — register into its global layer, while a preset's
  220. # `skill-local` registers into that preset's layer, and each agent reads the
  221. # merged catalog its scope chain selects. Only the per-agent rows move behind
  222. # presets: the base host `skill-local` row is disabled here (presets own local
  223. # discovery), and `tool-skill` is what a preset mounts to give its agent the
  224. # catalog and loader at all.
  225. - id: skill-local
  226. disabled: true
  227. - id: tool-skill
  228. disabled: true
  229. # The goal SERVICE, its session driver, and the `/goal` command STAY on the
  230. # host plane; only the model-facing tool moves. The Gateway serves the goal
  231. # domain as Remote endpoints, and a Remote method picks its receiver Service
  232. # from a generated descriptor — it resolves `goals` on the host, so a
  233. # per-session realm would answer `service-unavailable` for every browser call.
  234. # That is the `bash-env` criterion read from the other side: injection is not
  235. # the only host relationship a Service can have. The registry is keyed by
  236. # session, so one host instance serves every session exactly as before presets.
  237. - id: tool-goal
  238. disabled: true
  239. - id: plan-mode
  240. disabled: true
  241. - id: token-meter
  242. disabled: true
  243. - id: compact-basic
  244. disabled: true
  245. - id: command-compact
  246. disabled: true
  247. - id: tool-result-prune
  248. disabled: true
  249. # The subagent registry and its backends STAY in the host plane. `subagents` is
  250. # a process singleton with a cross-session query surface (`listChildren`,
  251. # `followup`) that the host api-proxy serves to the browser, and a provider
  252. # registers under a globally unique name, so a per-session copy would both
  253. # starve that host row and collide on the second session. What a preset
  254. # chooses is which delegation TOOLS its agent sees, below.
  255. - id: tool-subagent-control
  256. disabled: true
  257. - id: tool-subagent-list-agents
  258. disabled: true
  259. - id: tool-subagent
  260. disabled: true
  261. - id: tool-subagent-fork
  262. disabled: true
  263. # `tool-subagent-report` is host-plane for the same reason as the registry, not
  264. # because a preset may not want it: it registers a CONTINUABLE SETUP on that
  265. # singleton rather than a tool this agent calls, and the setup list is not
  266. # scope-aware — one copy per mounted preset means every child gets `report`
  267. # registered once per live session, which throws on the second.
  268. - id: workflow-workerthread
  269. disabled: true
  270. - id: tool-workflow
  271. disabled: true
  272. - id: tool-ralph
  273. disabled: true
  274. - id: workspace-context
  275. disabled: true
  276. - id: tool-todo
  277. disabled: true
  278. - id: tool-web
  279. disabled: true
  280. # The preset roster. `config/agent-presets/` ships with the deployment and is
  281. # read-only (its entries carry `system` trust);
  282. # `$DSH_HOME/.agent-presets` is where a person — or an agent — authors their own, and
  283. # carries the same trust as shell access because a preset IS a composition.
  284. # `roots` is an assembly fact, not user config: the shipped preset directory
  285. # ships beside this file, so AppCLIEntry resolves it and patches it in — the
  286. # same treatment `distIndex` gets on the webserver row.
  287. - insert:
  288. - id: agent-presets
  289. name: '@deepseek-ai/dsh-agent-presets'
  290. config:
  291. default: standard