Files
deepseek-harness/packages/host/directory-picker-auto
imccyu 9b2925e50f fix: restore the credential-rejected branch and admit SRC absence by key
Review follow-ups that are logic rather than documentation:

- rpc.schema.ts had lost the credential-rejected branch while api-proxy.ts
  still returns that code, so a legitimate business error failed the
  client's response parse. Restore the branch and assert it.
- rpc-schemas.spec.ts had lost the workspace list, archiveSession and
  insertSessionBefore cases along with the command schemas; those routes
  still ship, so restore their coverage.
- An omitted SRC field is now recognized by an absent key instead of an
  undefined value, which makes the allowance assertExactArguments already
  granted reachable; an explicitly undefined field stays invalid input. A
  weak descriptor's undefined result rides the wire as an absent value,
  matching the envelope removal.
- The chooser unmounts an already-created backend when the surface entry
  fails to load, and no longer reverses the captured id array in place.
2026-08-11 23:33:18 +08:00
..
2026-08-10 16:34:20 +08:00

@deepseek-ai/dsh-host-directory-picker-auto

English | 中文

The adaptive chooser of the directory-picker seam: a node-half-only plugin that resolves the host's situation once at boot and mounts the matching dual-face backend — -native or -browse — as a real Loader entry in the in-memory root tree (never persisted to a config file; the root tree's write() is a no-op). Because the backend arrives as an ordinary entry, its browser half is discovered by the client module table exactly as a config-row's would be, so the seam's one-row-swaps-both-faces invariant holds for the resolved choice. Unloading the chooser removes the entry again, unloading both faces with it.

Resolution is one pure boot-time sample (resolveDirectoryPickerBackend), exported for reuse. native requires every signal that the operator can see the host display and the native backend can serve it: a loopback-only bind (read from the injected httpServer; an all-interfaces bind admits remote browsers no OS chooser can reach), no SSH launch (SSH_CONNECTION/SSH_TTY unset or blank — under SSH port-forwarding the chooser would open on the unattended server), and a servable display session — assumed on darwin/win32; on linux DISPLAY/WAYLAND_DISPLAY plus a zenity or kdialog binary on PATH (the probe is one more boot-time fact); never on any other platform, since the native backend drives exactly darwin/win32/linux. Anything ambiguous resolves to browse, which works everywhere. The sample happens exactly once per boot so the mounted capability stays stable for the service lifetime, as the seam requires. Pinning an interaction is not a config field here — compose the -native or -browse row directly instead of this one, the seam's documented swap point; mounting the chooser and a backend row together fails loud (duplicate directoryPicker service, duplicate client flow in the single holes).

Model Experience

None, as the chooser only composes the GUI host's directory selection; nothing here reaches a model request.

KV Cache effect

None; this package neither assembles nor sends a provider request.

Known Limitations and Deferred Work

  • Detection infers operator location from launch context, which no launch-side signal can prove — a tmux session detached from its SSH launch loses the SSH_* markers; a Darwin process outside an Aqua session still counts as displayed; and a workstation-local launch later reached through ssh -L arrives from 127.0.0.1, resolves native, and opens the chooser on the unattended workstation. A wrong native choice degrades to the backend's existing retryable failure dialog, and composing -browse directly selects the safe interaction for such deployments.
  • The Linux chooser probe reads PATH only — a zenity/kdialog reachable some other way (shell alias, non-PATH install) still resolves browse; installing either binary on PATH restores native eligibility at the next boot.
  • Boot-time only — one resolution serves every client of the boot; per-connection adaptivity (native for a local browser, browse for a remote one, same server) would need a per-client capability and the wire advertisement the seam deliberately deleted, and waits for a deployment that serves both at once.