Stale. the latest tag points at 1.3.1, while this report covers 1.2.0
Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.
sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==
| name | dsh-plugin-wallpaper-engine |
|---|---|
| version | 1.2.0 |
| integrity | sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA== |
| repository | git+https://github.com/elysia395/dsh-wallpaper-engine.git |
| declared bundle patch | "./cordis.patch.yml" |
| declared engines.dsh | >=0.2.0-rc.1 — declarative and unenforced |
| DSH | 0.2.0-rc.2 |
|---|---|
| Node | v24.21.0 |
| OS / arch | linux 6.17.0-1022-azure x64 |
| verifier | dsh-verified 0.1.0 ec8d77c8d74d |
| generated | 2026-10-03T16:28:41.376Z |
| status | summary | evidence | |
|---|---|---|---|
L0 |
pass | declares dsh.bundle.patch and every declared patch path exists (47 files, 3662488 bytes unpacked)
dsh.manifestVersion is not declared; the reader does not infer a default tarball ships no src/ paths, so capability findings are limited to build output metrics{
"fileCount": 47,
"unpackedBytes": 3662488,
"patchPaths": [
"./cordis.patch.yml"
],
"declaredEnginesDsh": ">=0.2.0-rc.1",
"shipsSource": false
} |
e-resolve, e-tarball, e-l0 |
L1 |
pass | installed
the CLI completed the install with exit code 0 no dependency build script was approved by the verifier; approval permits commands with the host user permissions metrics{
"durationMs": 2036,
"exitCode": 0,
"declaredPeers": null,
"bundlesAfterInstall": [
"@deepseek-ai/dsh-base",
"dsh-plugin-wallpaper-engine"
],
"pendingBuildScripts": [],
"buildScriptsApproved": 0,
"diagnosticsLog": null
} |
e-l1-install |
L2 |
pass | booted, mounted and stayed alive
the process was still running when the wall-clock bound reached it and reported no failure diagnostics, so the bundle was neither skipped nor rejected the fiber phase is not read directly: an early exit with diagnostics is the load-failure signal, and a boot that settles and waits is the success signal metrics{
"bootBoundMs": 25000,
"durationMs": 25065,
"signal": null
} |
e-l2-boot |
L3 |
pass | a session completed with no credential
the model call was served by the official replay adapter from a fixture authored in this repository; no provider was contacted and no credential was present probe task, stated verbatim: "reply with any text" metrics{
"replayAdapter": "@deepseek-ai/dsh-llm-replay@0.2.0-rc.2",
"probeTask": "reply with any text",
"events": {
"session": "session-98ade1c0-7be9-40e8-b816-e099bf909a10",
"turnEndReason": {
"kind": "completed"
},
"finalText": "Replay fixture: no provider was called.",
"textEventCount": 1,
"error": null,
"exitCode": 0,
"durationMs": 1253,
"eventCount": 7
}
} |
e-l3-session |
L4 |
pass | 4 capability signal(s) present across 31 scanned file(s)
the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency static analysis cannot see dynamically constructed code or prove intent metrics{
"scannedFiles": 31,
"scannedBytes": 3348335,
"skippedFiles": 0
} |
e-l4, e-patch |
L5 |
pass | no significant delta across 6 sampled run(s)
no metric moved beyond the significance thresholds; that is the finding differential attribution: baseline profile first, then the subject activated, same container and order thresholds are coarse on purpose — order-of-magnitude watcher changes, RSS growth beyond 100 MiB, steady state more than 2 s later metrics{
"samples": 6,
"baseline": {
"atMs": 8042,
"rss": 199413760,
"heapUsed": 68444568,
"external": 5188103,
"activeTotal": 10,
"watchers": 7,
"timers": 0,
"libuvHandles": 22,
"libuvActiveHandles": 17,
"fds": 20
},
"activated": {
"atMs": 8039,
"rss": 200183808,
"heapUsed": 71759872,
"external": 5271558,
"activeTotal": 11,
"watchers": 8,
"timers": 0,
"libuvHandles": 23,
"libuvActiveHandles": 18,
"fds": 20
},
"delta": {
"atMs": -3,
"rss": 770048,
"heapUsed": 3315304,
"external": 83455,
"activeTotal": 1,
"watchers": 1,
"timers": 0,
"libuvHandles": 1,
"libuvActiveHandles": 1,
"fds": 0
}
} |
e-l5-overhead |
L6 |
pass | removed without residue
the profile retains no bundle selection, dependency entry or files for the subject metrics{
"residue": [],
"durationMs": 263
} |
e-l6-remove |
| capability | confidence | attribution | first evidence |
|---|---|---|---|
eval_or_dynamic_code | low | build-output | package/lib/webwallgl/assets/renderer-DTLW1Gf0.js:261 |
listens_on_port | medium | unknown | package/lib/index.js:3417 |
network_egress | medium | unknown | package/lib/routes/github-stars.js:41 |
spawns_process | medium | unknown | package/lib/index.js:67 |
Capability is not intent. A signature records what the code can reach for, not what it does.
{
"status": "no-significant-delta",
"samples": 6,
"baseline": {
"atMs": 8042,
"rss": 199413760,
"heapUsed": 68444568,
"external": 5188103,
"activeTotal": 10,
"watchers": 7,
"timers": 0,
"libuvHandles": 22,
"libuvActiveHandles": 17,
"fds": 20
},
"activated": {
"atMs": 8039,
"rss": 200183808,
"heapUsed": 71759872,
"external": 5271558,
"activeTotal": 11,
"watchers": 8,
"timers": 0,
"libuvHandles": 23,
"libuvActiveHandles": 18,
"fds": 20
},
"delta": {
"atMs": -3,
"rss": 770048,
"heapUsed": 3315304,
"external": 83455,
"activeTotal": 1,
"watchers": 1,
"timers": 0,
"libuvHandles": 1,
"libuvActiveHandles": 1,
"fds": 0
},
"significant": []
}
| id | kind | artifact |
|---|---|---|
e-resolve |
command exit 0 177 ms | resolve dsh-plugin-wallpaper-engine@1.2.0 -> dsh-plugin-wallpaper-engine@1.2.0
{
"name": "dsh-plugin-wallpaper-engine",
"version": "1.2.0",
"registry": "https://registry.npmjs.org",
"tarball": "https://registry.npmjs.org/dsh-plugin-wallpaper-engine/-/dsh-plugin-wallpaper-engine-1.2.0.tgz",
"advertisedIntegrity": "sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==",
"publishedAt": "2026-10-02T00:29:42.919Z"
}
|
e-tarball |
artifact exit 0 66 ms | fetch https://registry.npmjs.org/dsh-plugin-wallpaper-engine/-/dsh-plugin-wallpaper-engine-1.2.0.tgz
{
"bytes": 1585336,
"resolvedIntegrity": "sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==",
"advertisedIntegrity": "sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==",
"integrityMatchesRegistry": true,
"sha256": "5562b2f99702a0b54cd8c683b2a3996d99dcdbf2a0571a2c7e9bd3839ef2c49e"
}
|
e-l0 |
static | read published package.json and verify declared dsh.bundle.patch paths exist
{
"status": "pass",
"reasons": [],
"declared": {
"manifestVersion": null,
"bundlePatch": [
"./cordis.patch.yml"
],
"clientPlatform": "web",
"enginesDsh": ">=0.2.0-rc.1",
"enginesNode": ">=18"
},
"missingPatchPaths": [],
"fileCount": 47,
"unpackedBytes": 3662488,
"shipsSource": false
}
|
e-patch |
static | read cordis.patch.yml
# dsh-plugin-wallpaper-engine bundle patch.
#
# Applied over the dsh-web-app layer. This bundle contributes ONE host row
# (the plugin that scans Wallpaper Engine and serves its media) and relies on
# its `dsh.client` manifest (in package.json) to load the browser half that
# draws the wallpaper behind the DSH GUI and adds the settings UI.
#
# A patch replaces the targeted row's whole `config`, so only additive
# `insert` rows appear here (we never override an existing shipped row).
- insert:
# Host half: discovers the local Wallpaper Engine install (Steam app 431960),
# enumerates Scene/Video/Web wallpapers from the Workshop + default projects
# (Application wallpapers are listed but never rendered),
# and serves their media + a JSON inventory over same-origin HTTP routes
# the browser half fetches directly (GET /wallpaper-engine/inventory, /media,
# /preview, …; docs/ROUTE-INDEX.md is the authoritative table — it is generated
# and machine-checked, so the route count is deliberately not repeated here).
- id: wallpaper-engine
name: 'dsh-plugin-wallpaper-engine'
# webServer is a hard dependency (`inject = ['webServer']` in lib/index.js):
# the Loader waits for the HTTP server to mount, so a headless/TUI profile
# without one does not load this bundle at all.
|
e-l4 |
static | scan 31 shipped source file(s) for capability signatures
{
"present": [
{
"id": "eval_or_dynamic_code",
"confidence": "low",
"attribution": "build-output",
"firstEvidence": {
"file": "package/lib/webwallgl/assets/renderer-DTLW1Gf0.js",
"line": 261,
"snippet": "`);for(const k of l)u.push(...o(k));let d=!1;if(e.limitrows&&e.maxrows>0&&u.length>e.maxrows&&(u=u.slice(0,e.maxrows),d=!0,e.limituseellipsis)){let k=u[e.maxrows-1];for(;k.length>0&&n(k+\"…\")>c;)k=k.sl…"
}
},
{
"id": "listens_on_port",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/lib/index.js",
"line": 3417,
"snippet": "server = createServer((req, res) => {"
}
},
{
"id": "network_egress",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/lib/routes/github-stars.js",
"line": 41,
"snippet": "const res = await fetch(url, {"
}
},
{
"id": "spawns_process",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/lib/index.js",
"line": 67,
"snippet": "import { execFile, execFileSync, spawn } from 'node:child_process';"
}
}
],
"scannedFiles": 31,
"skippedFiles": 0,
"limits": [
"the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
"static analysis cannot see dynamically constructed code or prove intent"
]
}
|
e-l1-install |
command exit 0 2036 ms | dsh plugin --profile verify add dsh-plugin-wallpaper-engine@1.2.0
Progress: resolved 1, reused 0, downloaded 0, added 0 Packages are hard linked from the content-addressable store to the virtual store. Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11 Virtual store is at: node_modules/.pnpm Packages: +1 + Progress: resolved 1, reused 0, downloaded 1, added 1, done [WARN] Issues with peer dependencies found. Run "pnpm peers check" to list them. dependencies: + dsh-plugin-wallpaper-engine 1.2.0 Done in 269ms using pnpm v12.8.1 dsh: initialized profile verify at /work/dsh-home/profiles/verify |
e-l2-boot |
command exit 0 25065 ms | dsh --profile verify
dsh: warning: 1 entry did not activate wallpaper-engine (dsh-plugin-wallpaper-engine): pending (waiting for service: webServer) |
e-l6-remove |
command exit 0 263 ms | dsh plugin --profile verify remove dsh-plugin-wallpaper-engine
Packages: -1 - dependencies: - dsh-plugin-wallpaper-engine 1.2.0 Done in 10ms using pnpm v12.8.1 |
e-l5-overhead |
sample | dsh --profile <baseline|activated> with the host sampler injected via NODE_OPTIONS=--import
{
"method": "differential",
"status": "no-significant-delta",
"samples": 6,
"baselineMedian": {
"atMs": 8042,
"rss": 199413760,
"heapUsed": 68444568,
"external": 5188103,
"activeTotal": 10,
"watchers": 7,
"timers": 0,
"libuvHandles": 22,
"libuvActiveHandles": 17,
"fds": 20
},
"activatedMedian": {
"atMs": 8039,
"rss": 200183808,
"heapUsed": 71759872,
"external": 5271558,
"activeTotal": 11,
"watchers": 8,
"timers": 0,
"libuvHandles": 23,
"libuvActiveHandles": 18,
"fds": 20
},
"delta": {
"atMs": -3,
"rss": 770048,
"heapUsed": 3315304,
"external": 83455,
"activeTotal": 1,
"watchers": 1,
"timers": 0,
"libuvHandles": 1,
"libuvActiveHandles": 1,
"fds": 0
},
"significant": []
}
|
e-l3-session |
command exit 0 1253 ms | dsh --profile l3 --patch /work/fixtures/replay/l3-overlay.yml --json reply with any text
{"type":"session","sessionId":"session-98ade1c0-7be9-40e8-b816-e099bf909a10","cwd":"/work"}
{"type":"status","phase":"turn_start","turn":1}
{"type":"status","phase":"step_start","turn":1,"step":1}
{"type":"text","text":"Replay fixture: no provider was called."}
{"type":"status","phase":"step_end","turn":1,"step":1}
{"type":"status","phase":"turn_end","turn":1,"reason":{"kind":"completed"}}
{"type":"final","text":"Replay fixture: no provider was called."}
dsh: warning: 1 entry did not activate
wallpaper-engine (dsh-plugin-wallpaper-engine): pending (waiting for service: webServer)
|