Files
deepseek-harness/apps/cli/README.md
T
Tianyi Cui 3b33ca058f chore(repo): enforce dsh as the only Node application launcher
Add verify-application-entrypoints to the top-level gate graph. It inventories executable sources and package bins across apps, packages, and examples; rejects unclassified launchers including root-level js/mjs/cjs/ts files; and permits only the dsh CLI plus the explicitly private Python runtime carrier exception.

Update repository, architecture, CLI, and naming records to state the same rule: Node consumers select a dsh profile instead of invoking application-package bins, and no compatibility aliases remain. Fixtures prove both allowed classifications and representative escape attempts, making the architectural rule mechanically enforceable.
2026-08-23 10:59:01 +08:00

3.4 KiB

@deepseek-ai/dsh

English | 中文

The dsh command is the sole supported Node application launcher: profiles are ordered stacks of plugin-bundle patch layers under the user's own overrides. SDK and ACP are profiles, not separate public bins. src/args.ts owns the command grammar, and src/bin.ts loads only the selected runner. Invalid commands, options from another mode, configuration errors, and boot failures exit nonzero.

Entry modes

Command Purpose
dsh --profile <name> Boot the named profile under $DSH_HOME/profiles/<name>.
dsh --profile acp Serve automation clients over ACP stdio until disconnect.
dsh --profile headless "job" Run one fresh persisted session, print the final answer, and exit.
dsh --profile sdk Serve SDK clients over JSON-RPC stdio until shutdown or disconnect.
dsh web Alias of --profile web.
dsh plugin --profile <name> <pnpm args> Manage a profile's plugins by forwarding to pnpm in the profile directory.

The invoking directory is the default workspace root. The web, headless, sdk, and acp profiles auto-initialize on first use from shipped templates; any other profile must be created through dsh plugin.

App arguments

The launcher parses only its own flags and hands everything after them to the booted profile, where any injected app plugin may parse the shared immutable snapshot (dsh-cmdline). Launcher flags therefore come first, and the first token the launcher does not recognize starts the app's arguments:

dsh --profile web --port 8080       # --port belongs to the web app
dsh --profile tui --resume <id>     # example, assuming the tui profile is installed; --resume belongs to the terminal app
dsh --profile headless "run the tests"
dsh --profile web --help            # the web app's flags, not the launcher's
dsh --help                          # the launcher's own help

Profiles

A profile directory holds a package.json (out-of-tree plugin dependencies plus the profile manifest dsh.profile with its ordered bundles list and patchReload lifecycle) and a cordis.patch.yml (the user's own patch layer). patchReload: live watches the profile and home-level patch files; startup applies them once.

The tree composes over an empty root:

  • each bundle's patch in dsh.profile.bundles order
  • then the profile's cordis.patch.yml, then the home-level $DSH_HOME/cordis.patch.yml
  • then --patch overlays

Bundles named in dsh.profile.bundles resolve from the dsh installation first (@deepseek-ai/dsh-base, @deepseek-ai/dsh-web-app, @deepseek-ai/dsh-headless, @deepseek-ai/dsh-sdk-app, @deepseek-ai/dsh-acp-app), then from the profile's own node_modules, where pnpm installs out-of-tree plugins.

Use --dump-default-config and --dump-config to inspect the composed tree without booting it.

The CLI behavior reference owns exact layer precedence, flags, shutdown behavior, deployment defaults, and source execution.

Development

Production runs require built package and frontend artifacts. From the repository root, run pnpm run build separately, then use pnpm dsh <args...> to run the TypeScript entry and forward every argument; the source-execution reference owns the module-resolution contract.