deepseek-harness/scripts
Yichen Jiang 2dd4b8e78d fix(host): pin model discovery to loopback and drop its unread wire field
llm.discoverModels was reachable from any declared trusted host. The
method takes a caller-supplied baseURL and makes the host issue a GET to
it, then reports the status or the parsed body — so on a LAN deployment
an anonymous caller had a probe for whatever the host can reach and the
browser cannot, plus a path that carries a draft credential. The
PRIVILEGED_METHODS doc already states the rule this broke: trustedHosts
is a DNS-rebinding fence, not authentication, so the configuration plane
stays loopback-same-origin. It is in that set now, asserted both against
the hand-built fence and over real HTTP beside the catalog reads that
deliberately stay reachable.

supportsDiscovery and listModelDiscoveryNamespaces are gone. The field
was required on the wire and read by nobody: its own contract said a
surface should offer the action "instead of naming an adapter family it
would have to hardcode", while the surface hardcodes llm-pi-ai in two
places and gates the button on whether there is anything to probe. Its
shape did not fit the second caller either — the create card has no row
to read a per-row field from. Keeping a required field alive for a
consumer that may never arrive costs every producer and fixture a value
nobody consults, which is exactly how the fixtures drifted. The registry
that fed it had no other production consumer, so registration and
disposal are now observed through the offer itself.

The Agent Note claimed the key is never logged, which the wire schema
beside it already contradicts, and predated both the provider field and
the catalog-answer path. The two new public types pointed at core.md
without a type-equiv block or manifest entry, so the generated service
catalog named documentation that did not exist.
2026-08-05 19:51:11 +08:00
..
fixtures/translation-prompt fix(i18n): harden prompt response handling 2026-07-23 23:12:56 +08:00
snapshots docs: finish hierarchy rescan after rebase 2026-08-05 16:18:58 +08:00
agent-note-tree.ts fix(notes): keep archive helpers internal 2026-07-26 23:29:46 +08:00
AGENTS.md docs(windows): clarify portability rules 2026-07-18 13:03:44 +08:00
archived-agent-notes.spec.ts Merge remote-tracking branch 'origin/master' into worktree/archive-agent-notes-20260726 2026-07-27 00:53:07 +08:00
archived-agent-notes.ts fix(notes): anchor archive seals to prior Git state 2026-07-27 00:01:39 +08:00
build-exe-for-python-sdk.ts cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
build-python-release.py cleanup(build): minimize native payload handling 2026-07-30 01:29:18 +08:00
change-scope.spec.ts refactor(dev-infra): narrow change scope report 2026-07-28 01:02:43 +08:00
change-scope.ts refactor(dev-infra): narrow change scope report 2026-07-28 01:02:43 +08:00
check-expected-filenames.sh ci: reject golden filenames on matching PRs 2026-07-19 21:24:42 +08:00
check-vendor-manifest.sh Add lefthook git hooks with a vendor-manifest guard 2026-06-11 15:07:55 +08:00
check-workspace-constraints.ts fix(packages): omit source publication payloads 2026-08-05 01:15:19 +08:00
ci-workflow.spec.ts fix(ci): isolate pnpm setup per runner 2026-07-29 00:45:52 +08:00
clean.spec.ts fix(build): contain clean targets within repository 2026-07-26 02:51:58 +08:00
clean.ts fix(build): contain clean targets within repository 2026-07-26 02:51:58 +08:00
client-bundle-css.spec.ts feat(ui): complete trajectory request inspection 2026-07-28 09:53:32 +08:00
client-bundle-purity.spec.ts fix(client): load plugin bundles as external scripts 2026-08-04 14:18:47 +08:00
client-tsconfig.spec.ts fix(ci): make local Wine gate portable on macOS 2026-07-27 18:43:00 +08:00
cordis-config-files.spec.ts Stabilize master CI across platforms 2026-07-25 00:10:37 +08:00
cordis-config-files.ts fix(ci): ignore translation records in Cordis config scan 2026-07-23 00:39:55 +08:00
cordis-core-api.spec.ts docs: restore generated Cordis core API 2026-07-20 16:33:44 +08:00
cordis-core-api.ts docs: restore generated Cordis core API 2026-07-20 16:33:44 +08:00
cordis-walk.ts refactor(cordis): generate catalogs from Typert models 2026-07-29 23:55:12 +08:00
coverage-exempt.spec.ts fix(ci): review follow-ups for the coverage lane split 2026-07-31 02:55:37 +08:00
coverage-exempt.ts ci: run coverage-exempt heavy suites uninstrumented in parallel 2026-07-31 02:55:37 +08:00
demo-code-mode.mjs fix(cli): close shared config review gaps 2026-07-30 14:56:39 +08:00
demo-cordis.mjs refactor(cli)!: one shared base config with per-surface overlays 2026-07-29 21:15:42 +08:00
dev-web.spec.ts fix(web): verify current GUI updates end to end 2026-07-29 11:22:48 +08:00
dev-web.ts fix(web): verify current GUI updates end to end 2026-07-29 11:22:48 +08:00
doc-budgets.manifest.json docs: define hierarchy and document forms 2026-08-05 16:13:27 +08:00
doc-typecheck-paths.spec.ts fix(docs): map exact source aliases in built checks 2026-07-19 19:26:38 +08:00
doc-typecheck-paths.ts feat(gui): step1 skeleton — dsc web serves built web UI over booted harness host 2026-07-22 16:24:44 +08:00
doc-typecheck.ts Merge remote-tracking branch 'origin/master' into nih-imp-gates 2026-07-27 06:21:53 +08:00
gen-config-catalog.ts Rename RFCs to Agent Notes 2026-07-19 22:52:03 +08:00
gen-cordis-api.ts refactor(cordis): generate catalogs from Typert models 2026-07-29 23:55:12 +08:00
gen-cordis-catalog.ts feat(llm): interrogate a draft provider endpoint for its models 2026-08-05 19:50:11 +08:00
gen-doc-graphs.spec.ts fix(scripts): share package-source selection to clear the jscpd clone 2026-07-30 19:57:17 +08:00
gen-doc-graphs.ts Merge remote-tracking branch 'origin/master' into feat/pwsh-tool 2026-08-04 17:54:45 +08:00
gen-module-graph.ts refactor(acp): reduce bridge to automation protocol 2026-07-24 01:40:25 +08:00
gen-persistence-catalog.ts docs(notes): aggressive archive sweep of low-value decision records 2026-07-28 00:00:51 +08:00
gen-scoped-events.ts refactor(tsconfig): single root solution graph over host/client aggregates 2026-07-23 03:59:05 +08:00
gen-third-party-notices.spec.ts fix(fs-search): address the second-round #1119 review 2026-08-02 01:11:08 +08:00
gen-third-party-notices.ts docs: rescan rebased documentation hierarchy 2026-08-05 16:16:57 +08:00
gen-tool-catalog.ts docs(pwsh): scope the encoding claim, document the PATH probe and preamble limitation, and fix catalog requires lists 2026-08-02 19:37:45 +08:00
gen-translation-brief.ts feat(i18n): unit-mapped briefings with mechanical --apply, adopting the #684 planner mechanics 2026-07-27 02:31:07 +08:00
hero-composer-dom-continuity.mjs docs(web): the composer bar is one session-maybe slot, not a swapped pair 2026-07-30 15:18:06 +08:00
install-lefthook.mjs fix(ci): tolerate initializing Lefthook lock 2026-07-30 20:17:04 -07:00
install-lefthook.spec.ts fix(ci): stabilize merged coverage gates 2026-07-30 20:52:35 -07:00
install.sh cleanup: remove TUI package and legacy dsh entrypoints 2026-08-04 13:20:28 +08:00
jsdoc.ts feat: slash system / input service / agent scope 2026-07-27 03:28:39 +08:00
lint-rule-fingerprint.spec.ts test: make lint profile fingerprint honest 2026-07-29 23:26:16 +08:00
markdown.ts fix(scripts): address review findings on the gate consolidation 2026-07-27 12:02:39 +08:00
migrate-packed-session-fixtures.ts feat(session): default JSONL writes to packed rows 2026-07-26 23:44:52 +08:00
oxlint-contract.spec.ts fix: allow ignored-only staged lint 2026-07-29 23:36:08 +08:00
package-graph.ts fix: normalize glob paths with split(sep).join('/') on Windows 2026-07-15 19:11:20 +08:00
package-invariants.spec.ts fix(packages): omit source publication payloads 2026-08-05 01:15:19 +08:00
package-invariants.ts fix(invariants): harden runtime contracts and gates 2026-07-21 00:25:38 +08:00
paired-markdown-derivatives.spec.ts docs: deduplicate paired code-block checks 2026-07-26 02:52:48 +08:00
paired-markdown-derivatives.ts docs: deduplicate paired code-block checks 2026-07-26 02:52:48 +08:00
prepare-ci-bubblewrap.sh docs: record final larger-runner evidence 2026-07-22 16:55:39 +08:00
project-doc-site.spec.ts fix(docs): index the full persistence outline 2026-07-31 13:47:51 +08:00
project-doc-site.ts fix(docs): index persistence events in page outline 2026-07-31 13:43:03 +08:00
publication-payload.spec.ts fix(packages): omit source publication payloads 2026-08-05 01:15:19 +08:00
publication-payload.ts fix(packages): omit source publication payloads 2026-08-05 01:15:19 +08:00
publint-all.spec.ts feat(dev-infra): make gate plans inspectable and replayable 2026-07-27 21:27:42 +08:00
publint-all.ts fix(scripts): address review findings on the gate consolidation 2026-07-27 12:02:39 +08:00
publish-npm-baseline.ts fix(npm): promote dsh after baseline publication 2026-08-05 01:44:13 +08:00
repo-files.ts Merge remote-tracking branch 'origin/master' into worktree/archive-agent-notes-20260726 2026-07-27 00:53:07 +08:00
run-gates.spec.ts Merge remote-tracking branch 'origin/master' into fix/node26-vitest-webstorage 2026-07-31 10:26:05 +08:00
run-gates.ts fix(picker): correct crash-isolation and DPI claims, wire the built-worker guard, and tidy round-four nits 2026-08-05 00:31:43 +08:00
run-oxlint.spec.ts refactor: centralize Oxlint worker bounds 2026-07-29 23:39:49 +08:00
run-oxlint.ts refactor: centralize Oxlint worker bounds 2026-07-29 23:39:49 +08:00
session-fixture-layout.snapshot.ts feat(session): default JSONL writes to packed rows 2026-07-26 23:44:52 +08:00
session-fixture-layout.spec.ts fix(scripts): complete fixture migration diagnostics 2026-07-27 03:54:33 +08:00
session-fixture-layout.ts fix(scripts): complete fixture migration diagnostics 2026-07-27 03:54:33 +08:00
smoke-python-runtime.py Merge branch 'worktree-llm-dynamic-config' into worktree-llm-web-config 2026-07-30 20:15:40 +08:00
test-invariants.spec.ts fix(test): preserve invariant config failures 2026-07-31 10:41:44 +08:00
test-invariants.ts fix(test): preserve invariant config failures 2026-07-31 10:41:44 +08:00
translation-brief.spec.ts feat(i18n): unit-mapped briefings with mechanical --apply, adopting the #684 planner mechanics 2026-07-27 02:31:07 +08:00
translation-brief.ts feat(i18n): unit-mapped briefings with mechanical --apply, adopting the #684 planner mechanics 2026-07-27 02:31:07 +08:00
translation-pairing-git.ts fix(i18n): pin translation snapshots against gc 2026-07-28 10:28:49 -07:00
translation-pairing.manifest.json docs(subprocess): bilingual pair for the consumer-migration Agent Note 2026-07-26 15:51:24 +08:00
translation-pairing.spec.ts fix(i18n): pin translation snapshots against gc 2026-07-28 10:28:49 -07:00
translation-pairing.ts Merge remote-tracking branch 'origin/master' into worktree-i18n-update-workflow 2026-07-27 09:39:54 +08:00
translation-prompt.snapshot.ts fix(i18n): complete prompt v4 pipeline path 2026-07-23 22:41:53 +08:00
translation-prompt.spec.ts docs(i18n): proofread active Chinese documentation 2026-08-04 17:36:14 +08:00
translation-prompt.ts fix(i18n): harden prompt response handling 2026-07-23 23:12:56 +08:00
ts-project.ts fix(build): reuse TypeScript config host 2026-07-26 00:30:20 +08:00
type-equiv.manifest.json fix(host): pin model discovery to loopback and drop its unread wire field 2026-08-05 19:51:11 +08:00
verify-agent-note-classification.ts Remove generated Agent Note index 2026-07-19 23:15:23 +08:00
verify-agent-note-format.ts Remove generated Agent Note index 2026-07-19 23:15:23 +08:00
verify-archived-agent-notes.ts fix(notes): anchor archive seals to prior Git state 2026-07-27 00:01:39 +08:00
verify-built-package-invariants.mjs refactor(scripts): consolidate gate scripts on mdast fences, parseArgs, and globSync 2026-07-26 23:14:28 +08:00
verify-built-package-invariants.spec.ts ci: enforce bounded build lanes 2026-07-21 20:15:09 +08:00
verify-client-domain-graph.ts refactor(scripts): consolidate gate scripts on mdast fences, parseArgs, and globSync 2026-07-26 23:14:28 +08:00
verify-cordis-config.ts feat(examples): add generic memory MCP overlays 2026-07-31 02:00:14 -07:00
verify-doc-budgets.ts docs: rebalance prose cleanup and add trimming skill 2026-07-13 23:27:00 +08:00
verify-doc-refs.ts Rename RFCs to Agent Notes 2026-07-19 22:52:03 +08:00
verify-export-jsdoc.ts refactor: migrate linting to Oxlint 2026-07-29 14:32:11 +08:00
verify-md-links.ts feat(skills): bundle and harden personal maintenance workflows 2026-07-27 18:53:30 +08:00
verify-md-wrap.ts docs(notes): archive low-value decision records 2026-07-26 23:06:00 +08:00
verify-mermaid.ts feat(skills): bundle and harden personal maintenance workflows 2026-07-27 18:53:30 +08:00
verify-node-next-types.ts fix(scripts): run publint/tsc via node JS entry, not a shell .cmd shim 2026-07-15 16:38:22 +08:00
verify-package-invariants.ts feat(invariants): implement package runtime checks 2026-07-20 00:38:37 +08:00
verify-package-paths.ts Merge remote-tracking branch 'origin/master' into nih-imp-gates 2026-07-27 06:21:53 +08:00
verify-package-readme-limitations.ts Rename RFCs to Agent Notes 2026-07-19 22:52:03 +08:00
verify-package-readme-model-experience.ts feat(bash-env): extract the shared DSH_* environment registry into its own package 2026-08-02 14:17:46 +08:00
verify-runtime-closure.ts refactor(scripts): consolidate gate scripts on mdast fences, parseArgs, and globSync 2026-07-26 23:14:28 +08:00
verify-translation-pairing.ts fix(i18n): persist uncommitted translation snapshots 2026-07-28 04:34:05 -07:00
verify-translation-prompt.ts fix(i18n): harden prompt response handling 2026-07-23 23:12:56 +08:00
verify-type-equiv.ts fix(scripts): address review findings on the gate consolidation 2026-07-27 12:02:39 +08:00
verify-vendored-links.ts fix(review): label host-preparation failures and gate vendored lockfile links 2026-08-02 01:25:01 +08:00
vitest-environment.compat.spec.ts fix(test): isolate jsdom storage on Node 26 2026-07-30 21:49:33 +08:00
wine-windows-gates.sh fix(ci): retry the Wine lane's pnpm install on the hoisted-linker rename race 2026-07-28 16:16:10 +08:00