Files
deepseek-harness/apps/cli
Yichen Jiang 715baae6c1 fix(agent-presets): let the invariant follow the roster it actually scans
The service moved its "is a roster composed" reads to the derived root set;
the invariant companion still read `config.roots`. In the shape this change
exists for — an app configures nothing and the roster is the harness home
alone — that made the advisory warning fire while the fail-loud invariant
stayed silent, so an agent could address a model against an empty global
layer unchecked.

Both now read one source: `roots` exposes the resolved set, and the invariant
asks it. That decides the behavior deliberately rather than by omission — a
composition that mounts the roster now fails an unjoined agent whether its
roots were configured or derived, and `includeUserRoot: false` with no
configured roots is how a deployment keeps its agents on the host plane. Both
shapes are pinned; the derived-only case fails against the old predicate.

Three pieces of prose went stale with the first commit: the web-app bundle
comment still called the writable root an assembly fact patched in by
AppCLIEntry (removed in the profile-plugin-bundles refactor — `composeProfile`
owns it now, and only for the shipped root), and the shipped skill and its
Agent Note still called both roots "configuration". The README gains the
resolved-roster reader and the discoverable-but-undeletable preset a second
writable root produces.
2026-08-11 21:13:41 +08:00
..
2026-08-10 22:20:59 +08:00
2026-08-11 11:22:08 +08:00
2026-08-11 11:22:08 +08:00

@deepseek-ai/dsh

English | 中文

The dsh command is the product launcher for profiles: ordered stacks of plugin-bundle patch layers under the user's own overrides. src/args.ts owns the command grammar, and src/bin.ts loads only the selected runner. Invalid commands, options from another mode, configuration errors, and boot failures exit nonzero.

Entry modes

Command Purpose
dsh --profile <name> Boot the named profile under $DSH_HOME/profiles/<name>.
dsh --profile headless "task" Run one fresh persisted session, print the final answer, and exit.
dsh web Alias of --profile web.
dsh plugin --profile <name> <pnpm args> Manage a profile's plugins by forwarding to pnpm in the profile directory.

The invoking directory is the default workspace root. The web and headless profiles auto-initialize on first use from shipped templates; any other profile must be created through dsh plugin.

App arguments

The launcher parses only its own flags and hands everything after them to the booted profile, where any injected app plugin may parse the shared immutable snapshot (dsh-cmdline). Launcher flags therefore come first, and the first token the launcher does not recognize starts the app's arguments:

dsh --profile web --port 8080       # --port belongs to the web app
dsh --profile tui --resume <id>     # --resume belongs to the terminal app
dsh --profile headless "run the tests"
dsh --profile web --help            # the web app's flags, not the launcher's
dsh --help                          # the launcher's own help

Profiles

A profile directory holds a package.json (out-of-tree plugin dependencies plus the profile manifest dsh.profile with its ordered bundles list) and a cordis.patch.yml (the user's own patch layer, hot-reloaded on long-lived surfaces). The tree composes over an empty root: each bundle's patch in dsh.profile.bundles order, then the profile's cordis.patch.yml, then the home-level $DSH_HOME/cordis.patch.yml, then --patch overlays. Bundles named in dsh.profile.bundles resolve from the dsh installation first (@deepseek-ai/dsh-base, @deepseek-ai/dsh-web-app, @deepseek-ai/dsh-headless), then from the profile's own node_modules, where pnpm installs out-of-tree plugins. Use --dump-default-config and --dump-config to inspect the composed tree without booting it.

The CLI behavior reference owns exact layer precedence, flags, shutdown behavior, deployment defaults, and source execution.

Development

Production runs require built package and frontend artifacts. From the repository root, pnpm dsh <args...> builds those artifacts, runs the TypeScript entry, and forwards every argument; the source-execution reference owns the module-resolution contract.