Summary
Installing @perrylink/dsh-github from the market breaks the DSH web UI on the
next host restart. The published lib/client.js is the plain tsc ESM
compile of src/client.ts — top-level import/export, no
window.__ModuleLoader__.load({ id, factory }) registration. The shell installs
that file as a classic script, so the browser throws
SyntaxError: Cannot use import statement outside a module; because the host
concatenates the batch into one combo script, that single parse error aborts the
whole batch and the UI reports Failed to load plugins.
This is the defect PR #11 describes and fixes. It is still unreleased: I checked
the current npm latest (0.7.14) and the main / v0.7.15 trees and all three
still ship the unbundled artifact.
Environment
- host
@deepseek-ai/dsh 0.1.5-rc.3, web profile
- plugin
@perrylink/dsh-github@0.7.13, installed through the market
(market logged the install as hot=false)
- Windows 10, Node 22
Reproduction
- install the plugin — it is appended to
dsh.profile.bundles
- DSH keeps working. Expected:
hot=false, so the running host still serves
the bundle it already has in memory
- restart the host (
dsh web stop + dsh web) — the first host restart since
the install
- the UI never comes up
The failure is therefore latent: any later restart (a reboot, dsh web restart)
triggers it, and nothing at install time warns.
Observed
UI / host side:
Failed to load plugins
failed to import loader entry <id> (@deepseek-ai/dsh-client-hmr):
client-modules: bundle /plugins/??... loaded without registering
'@deepseek-ai/dsh-client-hmr' via __ModuleLoader__.load
Browser console:
Uncaught SyntaxError: Cannot use import statement outside a module
@ plugins/??…,@perrylink/dsh-github/client.js,…
The entry named in the host error (@deepseek-ai/dsh-client-hmr) is a red
herring — it is simply the first non-preset row of the manifest. The parse error
is caused by this package's artifact.
Artifact evidence
lib/client.js, same shape in every published and in-tree revision:
| ref |
bytes |
top-level import/export |
__ModuleLoader__ |
0.7.13 (installed here) |
12463 |
12 |
0 |
0.7.14 (npm latest) |
12473 |
12 |
0 |
main / v0.7.15 |
12473 |
12 |
0 |
Line 23 of the file is import { createElement, useState } from 'react';.
Why CI stays green — node --check cannot catch this, because the package is
"type": "module" and Node parses the file as ESM, where the import is legal:
$ node --check lib/client.js
# exit 0 ← looks fine
$ node -e "require('vm').runInThisContext(
require('fs').readFileSync('lib/client.js','utf8'), {filename:'client.js'})"
client.js:23
import { createElement, useState } from 'react';
^^^^^^
SyntaxError: Cannot use import statement outside a module
For contrast, a correctly bundled plugin in the same profile has
__ModuleLoader__ ×1 and 0 top-level import/export.
Impact
Not scoped to this plugin. Any profile that lists it in bundles loses every
client plugin in its batch. Recovery has to be done by hand — the UI is
unreachable, so the market cannot be used to uninstall the offending package.
I worked around it by removing the entry from dsh.profile.bundles and
restarting the host.
Request
PR #11 already implements the right fix (scripts/client-bundle.mjs for the
artifact contract + a guard that executes the shipped file as a classic script,
so a 0.7.12-shaped artifact fails the build instead of the browser). Could it be
merged and released? Until an artifact with the registration wrapper is
published, this package cannot be installed safely by anyone using the market.
Secondary observation from the same install, unrelated to this crash: the market
flagged @perrylink/dsh-github: introduced host-compatibility risks — @deepseek-ai/cordis@^4.0.4 vs 4.0.2, i.e. the package declares a host line this
host does not satisfy.
Summary
Installing
@perrylink/dsh-githubfrom the market breaks the DSH web UI on thenext host restart. The published
lib/client.jsis the plaintscESMcompile of
src/client.ts— top-levelimport/export, nowindow.__ModuleLoader__.load({ id, factory })registration. The shell installsthat file as a classic script, so the browser throws
SyntaxError: Cannot use import statement outside a module; because the hostconcatenates the batch into one combo script, that single parse error aborts the
whole batch and the UI reports
Failed to load plugins.This is the defect PR #11 describes and fixes. It is still unreleased: I checked
the current npm
latest(0.7.14) and themain/v0.7.15trees and all threestill ship the unbundled artifact.
Environment
@deepseek-ai/dsh0.1.5-rc.3,webprofile@perrylink/dsh-github@0.7.13, installed through the market(market logged the install as
hot=false)Reproduction
dsh.profile.bundleshot=false, so the running host still servesthe bundle it already has in memory
dsh web stop+dsh web) — the first host restart sincethe install
The failure is therefore latent: any later restart (a reboot,
dsh web restart)triggers it, and nothing at install time warns.
Observed
UI / host side:
Browser console:
The entry named in the host error (
@deepseek-ai/dsh-client-hmr) is a redherring — it is simply the first non-preset row of the manifest. The parse error
is caused by this package's artifact.
Artifact evidence
lib/client.js, same shape in every published and in-tree revision:import/export__ModuleLoader__0.7.13(installed here)0.7.14(npmlatest)main/v0.7.15Line 23 of the file is
import { createElement, useState } from 'react';.Why CI stays green —
node --checkcannot catch this, because the package is"type": "module"and Node parses the file as ESM, where theimportis legal:For contrast, a correctly bundled plugin in the same profile has
__ModuleLoader__×1 and 0 top-levelimport/export.Impact
Not scoped to this plugin. Any profile that lists it in
bundlesloses everyclient plugin in its batch. Recovery has to be done by hand — the UI is
unreachable, so the market cannot be used to uninstall the offending package.
I worked around it by removing the entry from
dsh.profile.bundlesandrestarting the host.
Request
PR #11 already implements the right fix (
scripts/client-bundle.mjsfor theartifact contract + a guard that executes the shipped file as a classic script,
so a 0.7.12-shaped artifact fails the build instead of the browser). Could it be
merged and released? Until an artifact with the registration wrapper is
published, this package cannot be installed safely by anyone using the market.
Secondary observation from the same install, unrelated to this crash: the market
flagged
@perrylink/dsh-github: introduced host-compatibility risks — @deepseek-ai/cordis@^4.0.4 vs 4.0.2, i.e. the package declares a host line thishost does not satisfy.