12410 Commits

Author SHA1 Message Date
Tianyi Cui
c7ea0f6468 Merge worktree/ci-native-windows-coverage-20260808 into worktree/ci-native-windows-multicore-20260809 2026-08-09 13:01:37 +08:00
Tianyi Cui
cbba728f03 Merge worktree/ci-native-windows-20260808 into worktree/ci-native-windows-coverage-20260808 2026-08-09 13:01:04 +08:00
Tianyi Cui
f157719690 Merge origin/master into worktree/ci-native-windows-20260808
# Conflicts:
#	vendor/README.md
2026-08-09 13:00:19 +08:00
Tianyi Cui
461f2aaaf2 ci: use multicore native Windows runner 2026-08-09 12:43:45 +08:00
xjt
17360907f6 docs(i18n): address terminology review findings 2026-08-09 12:35:06 +08:00
Huanqi Cao
01a3b454f6 fix(sandbox): extend the restricted token's default DACL with a write-SID ACE
New objects created without an explicit security descriptor take
their DACL from the token's default DACL, which CreateRestrictedToken
builds from the user's ambient SIDs — none of them a restricting SID.
Confined children therefore failed the write pass-2 check when
creating anonymous pipes (CreatePipe: ERROR_ACCESS_DENIED, surfaced
as Node EPERM), breaking PowerShell pipelines and other CreatePipe
consumers. Merge a full-access write-SID ACE (Everyone under
read-only) into the token default DACL at init via
SetTokenInformation(TokenDefaultDacl).

Named pipes are EXEMPT: their default security descriptor is the
kernel's PUBLIC template (owner/SYSTEM/Admins full, Everyone
read-only), which no token change influences, so libuv's piped stdio
capture stays denied for confined grandchildren — the POC-documented
boundary, now pinned by the runner suite (inherit/ignore OK, pipe
DENIED) and documented in the README pair. The NUL paragraph is
corrected to the measured matrix (Everyone has 0x1201BF on the
device: cmd/node writes land; Set-Content fails at the PS layer).
2026-08-09 12:34:48 +08:00
xjt
9087be1a2a fix(docs): address generated translation review findings 2026-08-09 12:21:57 +08:00
xjt
acf75a8af3 Merge origin/master into xjt/incremental-proofreading-275-apply 2026-08-09 12:17:59 +08:00
Tianyi Cui
03258467bf Merge pull request #2062 from deepseek-harness/worktree/ci-github-repository-plugin-e2e-20260808
feat(repository-plugin): run trusted Git repository packages
2026-08-09 12:03:40 +08:00
Yichen Jiang
30923a7a0a Merge remote-tracking branch 'origin/stack/agent-profiles-5-web-ui' into stack/agent-profiles-8-authoring
# Conflicts:
#	packages/core/tools/README.i18n.yaml
#	packages/core/tools/README.md
#	packages/core/tools/README.zh.md
2026-08-09 11:55:11 +08:00
Yichen Jiang
53e30d7652 Merge remote-tracking branch 'origin/stack/agent-profiles-3-wire' into stack/agent-profiles-5-web-ui 2026-08-09 11:52:23 +08:00
Yichen Jiang
62f8eecbba Merge remote-tracking branch 'origin/stack/agent-profiles-1-seam' into stack/agent-profiles-3-wire 2026-08-09 11:51:13 +08:00
Yichen Jiang
cb442eb31d Merge remote-tracking branch 'origin/master' into stack/agent-profiles-1-seam 2026-08-09 11:47:41 +08:00
xjt
aad0030fe0 Merge remote-tracking branch 'origin/master' into xjt/generated-docs-zh-translation-apply
# Conflicts:
#	packages/boot/app-boot/README.i18n.yaml
#	packages/boot/app-boot/README.zh.md
2026-08-09 11:45:58 +08:00
xjt
0c3354e582 Merge origin/master into xjt/incremental-proofreading-275-apply 2026-08-09 11:44:26 +08:00
Tianyi Cui
c8e0b0f3a7 test(repository-plugin): update keyless prepare fixture 2026-08-09 11:41:40 +08:00
Tianyi Cui
a208bc1a92 docs(config-catalog): refresh repository source 2026-08-09 11:41:40 +08:00
Tianyi Cui
fc20194733 fix(repository-plugin): follow package regrouping 2026-08-09 11:41:40 +08:00
Tianyi Cui
8d76ddaa6c fix(repository-plugin): enforce published prepare dependency 2026-08-09 11:41:40 +08:00
Tianyi Cui
690fc798a5 test(repository-plugin): isolate simulated npm release 2026-08-09 11:41:40 +08:00
Tianyi Cui
e00ec8e2aa test(repository-plugin): refresh prepared wrapper fixture 2026-08-09 11:41:40 +08:00
Tianyi Cui
cc7bd4948d fix(repository-plugin): reject incomplete MCP publication 2026-08-09 11:41:40 +08:00
Tianyi Cui
29b3e3fa84 fix(repository-plugin): require published prepare dependency 2026-08-09 11:41:40 +08:00
Tianyi Cui
e91ff6d499 test(repository-plugin): cover MCP activation cleanup 2026-08-09 11:41:40 +08:00
Tianyi Cui
913ecf5f1d fix(mcp-client): await Cordis startup discovery 2026-08-09 11:41:40 +08:00
Tianyi Cui
67b9e9b1d6 test(repository-plugin): isolate agent mock sequence 2026-08-09 11:41:40 +08:00
Tianyi Cui
c750d5a908 test(repository-plugin): resolve published Cordis types 2026-08-09 11:41:40 +08:00
Tianyi Cui
a7832cbfbf fix(repository-cache): isolate Git package dependencies 2026-08-09 11:41:40 +08:00
Tianyi Cui
033fa4b0b1 feat(repository-plugin): load trusted package code 2026-08-09 11:41:40 +08:00
Tianyi Cui
a0c64f4906 ci(repository-plugin): authenticate private GitHub source 2026-08-09 11:41:40 +08:00
Tianyi Cui
a9af1a33f0 test(repository-plugin): update prepared fixture metadata 2026-08-09 11:41:40 +08:00
Tianyi Cui
778b9585d4 docs: refresh repository Plugin config source 2026-08-09 11:41:40 +08:00
Tianyi Cui
b91b1fdefe fix(repository-plugin): make GitHub source preparation self-contained 2026-08-09 11:41:40 +08:00
Tianyi Cui
da2179dd2b test(fixtures): prepare repository Plugin at prepack 2026-08-09 11:41:40 +08:00
Tianyi Cui
b995b12261 test(fixtures): add private GitHub repository Plugin 2026-08-09 11:41:40 +08:00
Tianyi Cui
27159ed21b Merge pull request #2080 from deepseek-harness/docs/prose-conciseness-pass
docs,feat(doc-gates): fix 15 dead anchor fragments; verify-md-links now validates fragments
2026-08-09 11:37:55 +08:00
xjt
a7af54a8d3 docs(i18n): standardize contract terminology 2026-08-09 11:33:14 +08:00
xjt
90a876cbad test: refresh translation prompt snapshot 2026-08-09 11:21:20 +08:00
Yichen Jiang
ca7326e17e Merge remote-tracking branch 'origin/stack/agent-profiles-5-web-ui' into stack/agent-profiles-8-authoring
# Conflicts:
#	docs/module-graph.md
2026-08-09 11:09:53 +08:00
Yichen Jiang
83a957647b Merge remote-tracking branch 'origin/stack/agent-profiles-3-wire' into stack/agent-profiles-5-web-ui
# Conflicts:
#	docs/module-graph.md
2026-08-09 11:09:01 +08:00
Yichen Jiang
5fc2a81fbe Merge remote-tracking branch 'origin/stack/agent-profiles-1-seam' into stack/agent-profiles-3-wire
# Conflicts:
#	docs/module-graph.md
2026-08-09 11:07:48 +08:00
xjt
7ff0cbcb7e docs: complete Chinese proofreading and generated reference pairing 2026-08-09 11:02:16 +08:00
Huanqi Cao
bb50783002 test(sandbox): cover the temp-grant cleanup-failure AggregateError path 2026-08-09 10:57:01 +08:00
Tianyi Cui
dad5963484 fix(doc-gates): review findings — GitHub-slugger parity and the surviving old-rule prose
ds-review-bot round: slugs now come from RENDERED heading text (links,
inline code, emphasis) with underscores kept and GitHub's occupied-set
repeat suffixes; explicit <a id> anchors register only from real HTML flow
(fences, inline code, and comments no longer produce phantoms); fragment
matching is exact-case since element ids are. anchorCache is exported and
the spec reuses it. The contradicting 'gate checks file existence, not
#anchor validity' sentence in docs/AGENTS.md is gone; the dsh-doc-standards
residual caveat names the real TS-string anchor homes; the 2026-06-18
cross-link note is updated to shipped behavior and cross-linked with the
fragment-gate note.
2026-08-09 10:56:43 +08:00
Tianyi Cui
10ef3d4924 docs,feat(doc-gates): fix 15 dead anchor fragments; verify-md-links now validates fragments
A corpus sweep under the doc/prose standards found 15 links whose #fragment
named no anchor in its target — reworded headings, one relocated contract
(tool-fs → the group README's no-timeout rule), and zh sides citing English
slugs their Chinese headings never produce. Fixed all 15 (zh sides get the
conventional explicit <a id> + English fragment), fixed the one generator-owned
instance at its source (gen-doc-graphs), and extended verify-md-links to
resolve fragments onto Markdown targets — same-file anchors included — against
heading slugs and explicit <a id>, so the class is gated instead of manually
grepped. Remaining probes (narrated history, duplication shingles, comment
transcripts, budgets) came back clean; sibling-adapter README symmetry and
implemented-note contrasts are deliberate keeps.
2026-08-09 10:56:42 +08:00
Tianyi Cui
80019566f2 chore(doc-gates): keep cordisModuleBodies module-local — knip flags the unused export 2026-08-09 10:56:05 +08:00
Huanqi Cao
8119bc3401 test(sandbox): fix grant-count and dispose-warning assertions
The reparse case reuses the standing workspace grant of the preceding
case (same workspace -> map hit), so the failed temp grant is the third
grant, not the fourth; the dispose-warning text carries 'failure(s)'.
2026-08-09 10:51:02 +08:00
Huanqi Cao
5fea4b7c4b feat(sandbox): derive the windows-acl write SID per workspace, not per session
The per-session random write SID forced a full tree propagation per
session per server lifetime (minutes on large workspaces). The write
SID is now the per-workspace identity derived from the canonical
workspace path (workspaceWriteSid: sha256 -> S-1-4-x-y), stored
nowhere: the workspace-root ACE materializes once per workspace per
machine and every later provision hits the exact-ACE skip.

- workspace ACEs are STANDING (never revoked - the reuse cache); temp
  ACEs stay revocable (disposed with the provider), so an inheritable
  ACE never outlives its session's temp dir on the ambient temp root
- AclSandbox requires the write SID under workspace-write; read-only
  parses/grants nothing; the runner derives the SID itself (the
  --write-sid flag's presence still marks the seam-managed contract)
- the acl-session record drops writeSid (sessionId/workspace/tempDir
  remain): the SID-tamper surface and its validation are gone
- sandbox-local holds two grant maps: standing workspace grants and
  revocable per-session temp grants

Docs (README pair, design note pair, catalogs, type-equiv) and the
acl-session/grant/acl/probe/runner suites updated; workspace-sid.spec
pins the derivation contract.
2026-08-09 10:44:35 +08:00
Tianyi Cui
c9205901ec fix(doc-gates): review findings — scan every merge block, any quote style, .tsx too; self-check the scan
ds-review-bot round: the backstop stopped at a file's first declare-module
block while the projection it guards reads them all; the textual prefilter
matched only single quotes; .tsx sources escaped the glob. All three are the
silent-vanish class the scan exists to prevent. contextMergeFiles now yields
one entry per block (quote-agnostic prefilter, ts+tsx patterns), and a third
partition direction requires everything rendered to be scan-visible, so a
future scan regression is a hard error. Spec fixture made projection-
consistent; the partially superseded 2026-07-28 regions note is rewritten to
the current mechanism and cross-linked both ways.
2026-08-09 10:29:13 +08:00
xjt
5d46c11784 docs(i18n): reconcile source-drifted translations 2026-08-09 10:24:11 +08:00