Skip to content

0.7.13/0.7.14: lib/client.js ships as unbundled ESM — the next host restart fails every client plugin in the batch ("Failed to load plugins") #12

Description

@airunahead

Summary

Installing @perrylink/dsh-github from the market breaks the DSH web UI on the
next host restart. The published lib/client.js is the plain tsc ESM
compile of src/client.ts — top-level import/export, no
window.__ModuleLoader__.load({ id, factory }) registration. The shell installs
that file as a classic script, so the browser throws
SyntaxError: Cannot use import statement outside a module; because the host
concatenates the batch into one combo script, that single parse error aborts the
whole batch and the UI reports Failed to load plugins.

This is the defect PR #11 describes and fixes. It is still unreleased: I checked
the current npm latest (0.7.14) and the main / v0.7.15 trees and all three
still ship the unbundled artifact
.

Environment

  • host @deepseek-ai/dsh 0.1.5-rc.3, web profile
  • plugin @perrylink/dsh-github@0.7.13, installed through the market
    (market logged the install as hot=false)
  • Windows 10, Node 22

Reproduction

  1. install the plugin — it is appended to dsh.profile.bundles
  2. DSH keeps working. Expected: hot=false, so the running host still serves
    the bundle it already has in memory
  3. restart the host (dsh web stop + dsh web) — the first host restart since
    the install
  4. the UI never comes up

The failure is therefore latent: any later restart (a reboot, dsh web restart)
triggers it, and nothing at install time warns.

Observed

UI / host side:

Failed to load plugins
failed to import loader entry <id> (@deepseek-ai/dsh-client-hmr):
  client-modules: bundle /plugins/??... loaded without registering
  '@deepseek-ai/dsh-client-hmr' via __ModuleLoader__.load

Browser console:

Uncaught SyntaxError: Cannot use import statement outside a module
  @ plugins/??…,@perrylink/dsh-github/client.js,…

The entry named in the host error (@deepseek-ai/dsh-client-hmr) is a red
herring — it is simply the first non-preset row of the manifest. The parse error
is caused by this package's artifact.

Artifact evidence

lib/client.js, same shape in every published and in-tree revision:

ref bytes top-level import/export __ModuleLoader__
0.7.13 (installed here) 12463 12 0
0.7.14 (npm latest) 12473 12 0
main / v0.7.15 12473 12 0

Line 23 of the file is import { createElement, useState } from 'react';.

Why CI stays green — node --check cannot catch this, because the package is
"type": "module" and Node parses the file as ESM, where the import is legal:

$ node --check lib/client.js
# exit 0  ← looks fine

$ node -e "require('vm').runInThisContext(
    require('fs').readFileSync('lib/client.js','utf8'), {filename:'client.js'})"
client.js:23
import { createElement, useState } from 'react';
^^^^^^
SyntaxError: Cannot use import statement outside a module

For contrast, a correctly bundled plugin in the same profile has
__ModuleLoader__ ×1 and 0 top-level import/export.

Impact

Not scoped to this plugin. Any profile that lists it in bundles loses every
client plugin in its batch. Recovery has to be done by hand — the UI is
unreachable, so the market cannot be used to uninstall the offending package.
I worked around it by removing the entry from dsh.profile.bundles and
restarting the host.

Request

PR #11 already implements the right fix (scripts/client-bundle.mjs for the
artifact contract + a guard that executes the shipped file as a classic script,
so a 0.7.12-shaped artifact fails the build instead of the browser). Could it be
merged and released? Until an artifact with the registration wrapper is
published, this package cannot be installed safely by anyone using the market.

Secondary observation from the same install, unrelated to this crash: the market
flagged @perrylink/dsh-github: introduced host-compatibility risks — @deepseek-ai/cordis@^4.0.4 vs 4.0.2, i.e. the package declares a host line this
host does not satisfy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions