deepseek-harness/docs
Yichen Jiang 2dd4b8e78d fix(host): pin model discovery to loopback and drop its unread wire field
llm.discoverModels was reachable from any declared trusted host. The
method takes a caller-supplied baseURL and makes the host issue a GET to
it, then reports the status or the parsed body — so on a LAN deployment
an anonymous caller had a probe for whatever the host can reach and the
browser cannot, plus a path that carries a draft credential. The
PRIVILEGED_METHODS doc already states the rule this broke: trustedHosts
is a DNS-rebinding fence, not authentication, so the configuration plane
stays loopback-same-origin. It is in that set now, asserted both against
the hand-built fence and over real HTTP beside the catalog reads that
deliberately stay reachable.

supportsDiscovery and listModelDiscoveryNamespaces are gone. The field
was required on the wire and read by nobody: its own contract said a
surface should offer the action "instead of naming an adapter family it
would have to hardcode", while the surface hardcodes llm-pi-ai in two
places and gates the button on whether there is anything to probe. Its
shape did not fit the second caller either — the create card has no row
to read a per-row field from. Keeping a required field alive for a
consumer that may never arrive costs every producer and fixture a value
nobody consults, which is exactly how the fixtures drifted. The registry
that fed it had no other production consumer, so registration and
disposal are now observed through the offer itself.

The Agent Note claimed the key is never logged, which the wire schema
beside it already contradicts, and predated both the provider field and
the catalog-answer path. The two new public types pointed at core.md
without a type-equiv block or manifest entry, so the generated service
catalog named documentation that did not exist.
2026-08-05 19:51:11 +08:00
..
cookbook docs: finish hierarchy rescan after rebase 2026-08-05 16:18:58 +08:00
cordis-catalog fix(host): pin model discovery to loopback and drop its unread wire field 2026-08-05 19:51:11 +08:00
cordis-tutorial docs(i18n): proofread active Chinese documentation 2026-08-04 17:36:14 +08:00
core-data-structures fix(host): pin model discovery to loopback and drop its unread wire field 2026-08-05 19:51:11 +08:00
i18n docs: apply hierarchy across the corpus 2026-08-05 16:13:28 +08:00
postmortem docs: finish hierarchy rescan after rebase 2026-08-05 16:18:58 +08:00
user docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
agent-lifecycle.md refactor(agent): return request retry action 2026-07-27 21:17:49 +08:00
AGENTS.md docs: define hierarchy and document forms 2026-08-05 16:13:27 +08:00
architecture.i18n.yaml docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
architecture.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
architecture.zh.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
capability-seams.md Merge remote-tracking branch 'origin/master' into feat/pwsh-tool 2026-08-04 17:54:45 +08:00
config-catalog.md fix(llm): size unknown models and refuse a section that cannot be served 2026-08-05 18:54:23 +08:00
cordis-paper.pdf docs: add cordis paper 2026-07-31 15:54:36 +08:00
cordis-primer.i18n.yaml docs(i18n): proofread active Chinese documentation 2026-08-04 17:36:14 +08:00
cordis-primer.md Merge remote-tracking branch 'origin/master' into worktree/pr343-retarget-latest-master 2026-07-23 13:40:29 +08:00
cordis-primer.zh.md docs(i18n): proofread active Chinese documentation 2026-08-04 17:36:14 +08:00
defensive-patterns.i18n.yaml docs: finish hierarchy rescan after rebase 2026-08-05 16:18:58 +08:00
defensive-patterns.md docs: finish hierarchy rescan after rebase 2026-08-05 16:18:58 +08:00
defensive-patterns.zh.md docs: finish hierarchy rescan after rebase 2026-08-05 16:18:58 +08:00
development.i18n.yaml docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
development.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
development.zh.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
event-producer-consumer.md feat(llm): interrogate a draft provider endpoint for its models 2026-08-05 19:50:11 +08:00
glossary.i18n.yaml docs(i18n): address proofreading review findings 2026-08-04 18:42:13 +08:00
glossary.md docs: align Goal Round step cardinality 2026-07-24 12:10:40 +08:00
glossary.zh.md docs(i18n): address proofreading review findings 2026-08-04 18:42:13 +08:00
graph-atlas.md cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
module-graph.md Merge remote-tracking branch 'origin/master' into feat/pwsh-tool 2026-08-04 17:54:45 +08:00
persistence-catalog.md chore(docs): refresh the descriptor catalog pointer 2026-08-02 20:34:43 +08:00
testing.i18n.yaml docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
testing.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
testing.zh.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
tool-catalog.md docs(pwsh): scope the encoding claim, document the PATH probe and preamble limitation, and fix catalog requires lists 2026-08-02 19:37:45 +08:00
tool-execution-pipeline.md Merge remote-tracking branch 'origin/master' into feat/send-unify 2026-07-23 22:41:45 +08:00
web-styling.i18n.yaml docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
web-styling.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
web-styling.zh.md docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00