mirror of
https://github.com/deepseek-ai/deepseek-harness
synced 2026-08-15 21:04:50 +00:00
The service moved its "is a roster composed" reads to the derived root set; the invariant companion still read `config.roots`. In the shape this change exists for — an app configures nothing and the roster is the harness home alone — that made the advisory warning fire while the fail-loud invariant stayed silent, so an agent could address a model against an empty global layer unchecked. Both now read one source: `roots` exposes the resolved set, and the invariant asks it. That decides the behavior deliberately rather than by omission — a composition that mounts the roster now fails an unjoined agent whether its roots were configured or derived, and `includeUserRoot: false` with no configured roots is how a deployment keeps its agents on the host plane. Both shapes are pinned; the derived-only case fails against the old predicate. Three pieces of prose went stale with the first commit: the web-app bundle comment still called the writable root an assembly fact patched in by AppCLIEntry (removed in the profile-plugin-bundles refactor — `composeProfile` owns it now, and only for the shipped root), and the shipped skill and its Agent Note still called both roots "configuration". The README gains the resolved-roster reader and the discoverable-but-undeletable preset a second writable root produces.
bundle/ — profile plugin bundles
English | 中文
Profile bundles: npm packages whose manifest declares "dsh": { "bundle": { "patch": "./cordis.patch.yml" } }, making them installable patch layers for dsh --profile compositions (profile contract). A bundle's substance is its patch list; some also ship runtime glue plugins their patch mounts.
| Package | Role | ctx key |
|---|---|---|
base/ |
The shared dsh core every profile applies first | — (patch only) |
web-app/ |
Browser surface: web patch layer + runtime glue plugin | mounts rows |
headless/ |
Direct one-shot task mode over base, with no Host or Web layer | mounts headless-runner |
In-box bundles resolve from the dsh installation; out-of-tree bundles install into a profile through dsh plugin --profile <name> add <package>.