Commit Graph

1122 Commits

Author SHA1 Message Date
Yichen Jiang
1f6b67269e Merge branch 'master' into agent-request-messages 2026-07-09 09:52:33 +08:00
Tianyi Cui
e0e4203263 Merge pull request #208 from deepseek-harness/code-runtime-worker
feat: contained worker-thread code runtime (dsh-code-runtime-worker)
2026-07-09 01:05:48 +08:00
Tianyi Cui
43de115173 Merge branch 'master' into code-runtime-worker 2026-07-09 01:04:01 +08:00
Yichen Jiang
ca71834776 Merge remote-tracking branch 'origin/agent-request-messages' into agent-request-messages 2026-07-09 00:42:05 +08:00
Yichen Jiang
f2c333e510 docs(rfc): record the session-prefix decision
The seam shipped without its own RFC — the reconstructable-requests RFC
was amended with the mechanics, but the decision record (why a
compose-once frozen prefix, and what the per-request before/after shape,
a system-prompt section, a durable history opener, per-turn composition,
and a dedicated session event each lost to) had no home. Implemented
lifecycle, feature class, dated to the first commit of the work.
2026-07-09 00:40:57 +08:00
Tianyi Cui
064d1c4ce1 docs: state advisory typing in the worker row (review)
A reviewer read "TypeScript via host-side type-strip" and reasonably
asked what typing buys if nothing checks it — the group README never
said the annotations are advisory by design. The row now states it; the
rationale stays in the RFC and the enforcement story (per-dispatch
validateArgs) in the dsh-tools README.
2026-07-09 00:38:21 +08:00
Tianyi Cui
46187ec3b6 Merge branch 'master' into agent-request-messages 2026-07-09 00:21:05 +08:00
Tianyi Cui
d014e7eaa6 Merge pull request #221 from deepseek-harness/codex/fix-bash-local-process-tests
test(bash-local): wait for process readiness
2026-07-09 00:02:54 +08:00
Tianyi Cui
75ae8e38af Merge branch 'master' into codex/fix-bash-local-process-tests 2026-07-09 00:01:28 +08:00
Yichen Jiang
fd1071392c docs(compact): sync the compactIfNeeded prose signature with the sessionPrefix parameter
The seam gained sessionPrefix between fullSystemPrompt and signal in
18d478bc, but the compact README member table and the compaction
core-data-structures page still showed the 3-arg form and listed only
agent/system/signal as what pre-step supplies. The generated service
catalog was already correct; only these two prose homes drifted.
2026-07-08 22:40:38 +08:00
Yichen Jiang
0d023b9aaa Merge remote-tracking branch 'origin/master' into agent-request-messages 2026-07-08 22:26:25 +08:00
Wenlu Wang
970971fd53 Merge pull request #213 from deepseek-harness/feat/repeat-tool-guard
feat(guard): repeat-tool-guard plugin (implements the RFC)
2026-07-08 22:14:53 +08:00
Tianyi Cui
90547f283b fix: byte-exact value/error caps + write-callback contract (agent review)
Two [P1] review findings on the worker runtime:

- maxValueBytes gated and sliced the rendered fallback by UTF-16 code
  units, so a multibyte string ("€€€€" under a 4-byte cap) crossed whole
  and a truncated multibyte rendering could still run ~3x over budget.
  New truncateUtf8Bytes cuts at code-point boundaries under a real byte
  budget; prepareValue's fallback and the host's forged-error-text bound
  both use it, and the VALUE_RENDER_SLACK comment drops its now-obsolete
  "sliced by characters" wrinkle.

- The patched stream write dropped Node's optional encoding/callback
  arguments, so a program awaiting flush completion
  (write(chunk, resolve)) hung to the wall ceiling and misreported as a
  timeout. The shim now fires the callback asynchronously once the chunk
  is admitted — including for writes the exhausted budget drops.
2026-07-08 21:56:28 +08:00
Yichen Jiang
959a3c3a8b fix(agent-loop): discard an interrupted prefix composition instead of caching it
A cancel/dispose landing inside the first agent/session-prefix waterfall
used to commit the listener chain's return value to the instance cache
before the interruption check dropped the turn; an abort-aware listener's
degraded fallback would then ship on every later request of the instance.
The commit now happens only after the composition survives the
interruption check — the cache only ever holds a fully composed prefix,
and the next turn recomposes under a live signal.
2026-07-08 21:46:03 +08:00
Yichen Jiang
9c133c644d test(bash-local): wait for process readiness 2026-07-08 21:45:10 +08:00
Yichen Jiang
765052a7d1 fix(agent-loop): compose the session prefix before pre-step; hand it to the pressure gate
ds-review-bot critical (follow-up): on the first step of a resumed or
seeded/forked instance, auto-compaction ran before runStep composed
this instance's prefix, so the gate read the PREVIOUS instance's logged
prefix from the header fold — a contributor that grew across
resume/fork (skills added, AGENTS.md grown: exactly the
environment-dependent case) could under-gate and ship an over-window
first request.

The loop now composes agent/session-prefix before the instance's first
agent/pre-step (still once per instance; runStep just reads the cache),
and agent/pre-step carries the composed prefix to its listeners.
CompactService.compactIfNeeded gains the sessionPrefix parameter;
BasicCompactService.estimatePressure gates on the handed value — the
header-fold read is gone, so the estimate is exact at every step
including a resumed/forked instance's first. Composition moving before
the boundary snapshot also means a composing listener's session append
now joins the CURRENT request (documented on the seam).

New coverage: composition precedes pre-step and the seam receives the
composed prefix; cancel and disposal landing inside the composition
window drop the step cleanly; the compact gate test hands the prefix
directly.
2026-07-08 20:30:10 +08:00
Yichen Jiang
e6bd6cc9be fix(compact): count the logged session prefix toward token pressure
ds-review-bot critical: compactIfNeeded estimated pressure from the
derived history + system prompt only, but every loop-built request also
carries EpochHeader.messagePrefix in front of the history — a
deployment at the window edge would under-estimate by exactly the
prefix, skip compaction, and ship an over-window request.

BasicCompactService now gates on estimatePressure(): the session prefix
read from the log's folded header + the derived history + the system
prompt. The fold is exact from the instance's second request on (and
from a resumed instance's first — the previous instance logged its
prefix); it is absent only before a fresh session's first request,
where the history is a single prompt and compaction is moot. Compaction
itself still shrinks history only — a prefix that alone approaches the
window is a configuration error no compactor fixes, same as the
documented single-unit-overflow stance.
2026-07-08 19:32:42 +08:00
Yichen Jiang
77333c0a19 fix(agent): correct session-prefix composition-order docs; scrub messagePrefix in snapshots
Two ds-review-bot findings:

The seam JSDoc claimed extending 'await next()' composes in
registration order — false for the append form: the waterfall unwinds
innermost-first, so appending places later-registered contributions
first. The canonical contribution is now documented as the PREPEND
'[mine, ...await next()]' (registration order on the wire), with the
append form's reverse-order behavior stated explicitly; the ordering
test now uses the canonical pattern in both listeners.

scrubRequestHeaders tokenized only system/tools, so a fixture recording
a composed session prefix would carry its raw text (workspace-specific
churn/leak). The scrubber now maps each header/delta messagePrefix
entry to a {{messagePrefix}} token — count stays a structural fact,
absence stays absent, the empty-array transition stays visible — with
normalize.spec coverage for the header, delta, absence, and odd-shape
paths.
2026-07-08 16:16:08 +08:00
Yichen Jiang
b04cfe3a41 Merge remote-tracking branch 'origin/master' into agent-request-messages 2026-07-08 15:54:36 +08:00
Yichen Jiang
ea4c10d753 refactor(agent): replace the per-step advice seam with agent/session-prefix
Review discussion converged on the industry shape (Claude Code caches
user context per conversation; Codex separates initial context from
diffs; Kimi appends at continuation boundaries to protect prompt
caching): stable openers belong in a compose-once prefix, mid-session
changes belong in append-only history — not in a per-request slot.

agent/session-prefix fires ONCE per loop instance, lazily on its first
request-building step: the composed Message[] is deep-frozen, cached on
the transmission bookkeeping, recorded as EpochHeader.messagePrefix on
the anchoring 'initial'/'resume' snapshot, and reused verbatim for
every request the instance sends — prefix stability is structural, not
a producer discipline, and a resume recomposes with attributable drift.
The request is messagePrefix + boundary snapshot.

The per-step RequestAdvice/RequestAdviceContext surface and the
messageSuffix header field are dropped: the tail slot had no consumer,
and every current update pattern (new AGENTS.md discovered, memory
update, skills change) routes through the existing append-only history
channels — inject(), tools/post-execute additionalContext,
prompt-submit additionalContext — each paid once and prefix-cached
thereafter. The messagePrefix delta arm stays for codec totality; the
loop never produces one in practice.
2026-07-08 15:44:30 +08:00
kingwl
232c1957e2 Merge remote-tracking branch 'origin/master' into feat/repeat-tool-guard 2026-07-08 14:52:12 +08:00
Tianyi Cui
030eebb634 Merge remote-tracking branch 'origin/master' into code-runtime-worker 2026-07-08 14:44:23 +08:00
Tianyi Cui
dabc5e6225 Merge pull request #205 from deepseek-harness/code-runtime-pkg
feat: add the code-execution capability seam (ctx.codeRuntime)
2026-07-08 14:44:04 +08:00
kingwl
e491759f30 fix review finding: cap the detailed reminder's argument payload 2026-07-08 14:40:08 +08:00
Tianyi Cui
d0314736de Merge remote-tracking branch 'origin/master' into code-runtime-pkg 2026-07-08 14:38:54 +08:00
Tianyi Cui
4398daa62b Merge pull request #203 from deepseek-harness/code-mode-rfc
docs: rewrite the Code Mode RFC — registry-native mode over a worker-thread code-runtime seam
2026-07-08 14:38:34 +08:00
Tianyi Cui
89941c0b42 Merge remote-tracking branch 'origin/master' into code-mode-rfc 2026-07-08 14:29:50 +08:00
kingwl
a581963070 docs(rfc): promote the repeat-tool-guard RFC to implemented 2026-07-08 14:24:20 +08:00
kingwl
a0e39db3b6 test(acp-snapshot): add the repeat-tool-guard reminder scenario 2026-07-08 14:24:20 +08:00
kingwl
93d5e4c560 test(acp-snapshot): replace the authored-implies-override guard with an explicit overridden flag 2026-07-08 14:24:20 +08:00
kingwl
db26ef479d feat(guard): add the repeat-tool-guard plugin 2026-07-08 14:24:20 +08:00
Wenlu Wang
2f162308fe Merge pull request #209 from deepseek-harness/repeat-tool-guard-rfc
docs(rfc): propose the repeat-tool-guard plugin
2026-07-08 13:48:12 +08:00
kingwl
36d93b4ad3 docs(rfc): propose the repeat-tool-guard plugin 2026-07-08 13:44:50 +08:00
Tianyi Cui
d6363d3d27 Merge pull request #207 from deepseek-harness/all-checks-passed-gate
ci: add all-checks-passed aggregate job for branch protection
2026-07-08 13:42:44 +08:00
Tianyi Cui
e20ce35ffb fix: self-contained built bundles + wire-size value cap (bot review)
Two findings from the GitHub review bot on the ready PR:

The tsdown two-entry build emitted the shared bootstrap module as a
lib/bootstrap-*.js chunk imported by both bundles, which the package.json
files whitelist (deliberately exact) omitted — a packed install had
dangling imports. The package now runs two single-entry builds, so each
bundle inlines its own bootstrap copy and every shipped file is
self-contained.

prepareValue admitted any cloneable value whose BOUNDED inspect rendering
fit maxValueBytes, so a huge container with a compact rendering (a
50k-element array renders as '... N more items') crossed the port raw,
bypassing the cap on both sides. The cap now measures the value's real
cross-boundary size — exact bytes for strings, the structured-clone wire
size (v8.serialize) for everything else — and oversized containers cross
as their bounded rendering instead.
2026-07-08 12:55:14 +08:00
Tianyi Cui
aa2a7f9a8a fix: validate and re-cap all inbound worker-port traffic (Codex round 1)
The host's message listener trusted the compile-time WorkerToHost shape on
traffic from a peer that runs model code: postMessage(null) threw in the
listener and crashed the host process; forged log/done messages bypassed
maxLogBytes/maxValueBytes (the worker-side LogBuffer and prepareValue cap
only honest flows); and the error-reply renegotiation re-echoed a forged
non-cloneable call id, throwing outside any catch.

Every inbound message now passes a runtime shape gate that validates and
REBUILDS it field by field (junk drops without a throw; call ids must be
numbers, so replies are always clone-plain; forged extra fields never ride
along). One host-side ledger bounds everything landing in logs — honest
port entries, forged ones, and stray pipe bytes — at the single documented
maxLogBytes, with the shared in-band truncation marker emitted host-side
when the ledger trips first; the completion value is re-capped host-side
through the same prepareValue (with exactly the truncation suffix as slack
so honest worker-capped values pass unchanged), and done error text is
bounded. Also folds the stray-capture budget into that shared ledger
(round-1 finding B: it was a second maxLogBytes on top of the documented
shared cap).
2026-07-08 11:42:59 +08:00
Tianyi Cui
ae1845fea0 Merge branch 'master' into all-checks-passed-gate 2026-07-08 11:09:32 +08:00
Tianyi Cui
466a052159 Merge branch 'code-runtime-pkg' into code-runtime-worker 2026-07-08 11:07:14 +08:00
Tianyi Cui
583704ac1d feat: add the worker-thread code runtime (dsh-code-runtime-worker)
The shipped backend of the code-execution seam, per the Code Mode RFC's
worker-thread section: one fresh Node worker per run, executing the
model's TypeScript after a host-side type-strip (wrapped in an
async-function shell so top-level return/await parse, sliced back out
position-preserved), bindings bridged over the message port under
hostile-peer rules (own-property name lookup, at-most-once replies,
post-settlement drops, null-prototype namespaces), logs streamed eagerly
with an in-band truncation marker, and two independent budgets — measured
event-loop busy time (computeMs) plus a never-pausing wall ceiling
(maxWallMs) — funneling into worker.terminate(). env: {} and execArgv: []
keep the isolate hermetic; disposal aborts in-flight runs and awaits
worker exits.

The worker entry loads unbuilt via Node's native type stripping
(src/worker.ts, erasable-only) and ships built as a sibling tsdown bundle
(lib/worker.js); tests/built-lib.e2e.ts pins the built load path under
plain node and joins the built-artifact smoke gate. Unit suites cover the
bootstrap in-process (fake port) and the runtime over real workers,
per-file 100%.
2026-07-08 11:07:14 +08:00
Wenlu Wang
a7e8ac04d8 Merge pull request #204 from deepseek-harness/feat/shared-acp-snapshot
Extract the ACP snapshot suite into a support package (dsh-acp-snapshot)
2026-07-08 11:02:21 +08:00
Tianyi Cui
2be0b9266c ci: add all-checks-passed aggregate job for branch protection
A single stable required check that needs every other job in ci.yml, so
branch protection no longer enumerates matrix leg names that change as
lanes and node versions evolve. if: always() keeps the job running when
a dependency fails (a skipped required check would count as passing);
any non-success result — failure, cancelled, or skipped — fails it.
2026-07-08 10:57:25 +08:00
Wenlu Wang
987f9c00eb Merge branch 'master' into feat/shared-acp-snapshot 2026-07-08 10:51:08 +08:00
Tianyi Cui
b16fb37f89 Merge pull request #200 from deepseek-harness/rfc-subagent-claude-codex
docs(rfc): propose Claude Code and Codex subagent backends
2026-07-08 10:50:34 +08:00
Tianyi Cui
d7cc90a04c Merge branch 'master' into rfc-subagent-claude-codex 2026-07-08 10:49:17 +08:00
Tianyi Cui
d10761a577 Merge branch 'code-mode-rfc' into code-runtime-pkg 2026-07-08 10:44:35 +08:00
Tianyi Cui
e94c3b9015 docs: pin JSON normalization at the dispatch bridge (review finding)
The seam's structured-clone boundary admits values JSON does not (BigInt,
Map, circulars), while tool/code-dispatch events must be JSON-appendable —
left unhandled, a sub-call could execute and then fail at logging time.
The bridge now JSON-normalizes binding arguments BEFORE dispatch (a value
that does not survive rejects that one call), so the dispatched form and
the logged form are the same JSON value by construction.
2026-07-08 10:42:14 +08:00
Yichen Jiang
2cbdeb0872 Merge remote-tracking branch 'origin/master' into agent-request-messages
docs/core-data-structures/core.md: combined master's canonical tool-order
wording (#196) with this branch's request-advice envelope + wire-order
paragraphs.
2026-07-08 10:24:35 +08:00
Yichen Jiang
e97fffeab7 refactor(agent): rename agent/request-messages to agent/request-advice
tianyicui's review: the seam name did not say what the event or its
types do. 'advice' reads both ways — advisory content for the model,
and AOP before/after advice woven around a join point (here the
derived history) without modifying it — so RequestAdvice.before/after
are self-describing. Types follow: RequestAdvice / RequestAdviceContext;
the logged EpochHeader fields keep their positional names
(messagePrefix/messageSuffix).

Also sharpens the core.md wording the review flagged as ambiguous:
before-advice sits in front of the ENTIRE derived history, directly
after the system slot (the conventional home for session-stable openers
— an AGENTS.md digest, a skills catalog), after-advice follows the
history's last message. Catalogs and doc graphs regenerated.
2026-07-08 10:05:34 +08:00
kingwl
1097fa3507 fix review finding: an impossible scripted permission click rejects the run
A client-callback throw only becomes a JSON-RPC error RESPONSE to the
agent's session/request_permission — runScenario itself kept going, so a
tolerant agent could treat the error as a denial and the scenario would
pass, or worse, record: the impossible click baked into fixture and
golden, green on every replay. The mismatch is now captured as a harness
error while the agent is answered plain cancelled (a well-defined path
it cannot reinterpret), and the step loop rejects the run on it as soon
as the in-flight step settles. The spec asserts the rejection instead of
the agent-side error echo.
2026-07-08 02:46:23 +08:00
Tianyi Cui
15a3431913 docs: catalog the code-runtime seam vocabulary (Codex review finding)
Adds the missing core-data-structures coverage the catalog policy
requires for non-spine seam vocabulary: the code-runtime.md sub-page
with drift-checked type-equiv blocks for all six seam types, the core.md
sub-page row, the type-equiv manifest entries, and LINK_MAP entries so
the generated service signature links CodeRunRequest/CodeRunResult;
cordis/config catalogs regenerated.
2026-07-08 02:38:47 +08:00