The shipped host composition moved: `base.cordis.yml` and `web.cordis.yml` are the dsh-base and dsh-web-app patch layers now. The gate still opened the old paths and crashed on ENOENT — a gate that cannot read its inputs proves nothing, loudly or otherwise. Retargeting it also surfaced what the move implies for ownership: the web bundle carries the roster and its browser plugin rows now, so the bundle's own manifest is what must declare them. The gate's existing bare-plugin check said so as soon as it could parse the file again.
@deepseek-ai/dsh-web-app
English | 中文
The dsh browser-surface bundle. cordis.patch.yml rides over dsh-base: it sets the coding persona, inserts the Web host rows (webserver, API gateway, workspace, projection, storage) and the browser plugin roster, and mounts this package's own web-runtime glue plugin (config {mode, printUrl, lanAddresses}). That plugin owns what used to be launcher code: it resolves the built frontend dist through @deepseek-ai/dsh-frontend's exports (workspace knowledge of this bundle, never user config), mounts the frontend-static fallback owner over it, registers the web-surface prompt section and the bash-visible DSH_WEB_URL/DSH_WEB_MODE runtime variables, and prints the dsh web: URL line when printUrl is true. The dsh web launcher alias patches mode/lanAddresses/printUrl and the flag family over these rows; dsh-headless layers on top and silences the URL line.
Model Experience
Web-surface prompt section and bash runtime variables
What the model sees
The app:web-surface global section (order −98) orients the model to the GUI: the canonical local URL, the "this page" referent, the HMR/rebuild update contract for the active mode, and the instruction not to start replacement servers. DSH_WEB_URL and DSH_WEB_MODE additionally appear in the managed bash environment with their descriptions, resolved per invocation from the live server.
Token effect
One prompt paragraph per session plus two managed-environment variable lines; constant per process.
KV Cache effect
The prompt section sits near the system prompt's head and is stable for the life of the process (port and mode are boot facts), so it does not invalidate the cache across turns.
Known Limitations and Deferred Work
- The frontend dist must be built —
require.resolveof the dist fails loud at activation with a build hint; there is no source-serving fallback. lanAddressesis a boot-time snapshot — interface changes after boot are not re-advertised; the printed LAN URL always matches the configured trust fence.