Start with the smallest proof.Run one exact-version dsh --version probe. It removes Web startup from the diagnosis while preserving the same npm resolution path.

Route the last visible phase.

Install question

Use --yes before the package; this resolves only hidden confirmation.

Metadata wait

Capture registry, npm ping, proxy requirement, and exact npm view.

Fetch or script

Use HTTP log level, timing, and foreground lifecycle output.

Fresh-cache A/B

Use a temporary cache; keep the shared cache and evidence intact.

One ladder proves ownership.

Registrynpm view

Metadata path responds.

Packagedsh --version

Fetch, extraction, bin, and Node entrypoint work.

Runtimedsh web

Profile and Host boot begin; a printed URL proves listen.

Do not clear everything.

npm documents its cache as content-addressed and self-verifying. Run npm cache verify, preserve logs, and isolate the A/B before any deletion.

Primary evidence.

Find the boundary without destroying it.

The complete runbook includes exact commands, phase routing, safe cache isolation, PowerShell coverage, logging and secret handling, a DSH-entry proof ladder, and fifteen acceptance gates.

Read the complete runbook