Files
deepseek-harness/packages/spill/README.md
Dudu-0223 463b72ce96 feat(spill): add tool-output spill seam, local backend, and policy
Oversized plain-text tool results now spill to a session-scoped file and
return a bounded preview plus the spill path, so a verbose result stays
readable via `read` without consuming the next model request in full.

- dsh-spill: minimal SpillFiles seam (saveText → session-scoped SpillPath)
- dsh-spill-local: private 0700 session dirs, traversal-safe names, exclusive
  owner-only writes
- dsh-spill-policy: tools/post-execute transformer; no-op unless maxInlineBytes
  is set; skips read; best-effort on save failure (never turns a success into
  an isError)

web_fetch is the showcase — no tool-specific spill code. The coding-agent
example loads the stack so its keyless Loader smoke guards the namespace-plugin
export shape. Snapshot gap for a transcript-visible web_fetch spill is recorded
in the RFC's Consequences (ACP replay is keyless and cannot hit the web).
2026-07-08 20:41:55 +08:00

1.3 KiB

spill/ - spill storage capability family

The tool-output spill capability seam: an abstract storage interface, a local filesystem implementation, and the tool-result policy that uses it. All product packages.

Package Role ctx key
spill/ Abstract spill storage seam (saveText — persist oversized tool text to a session-scoped path) ctx.spillFiles
spill-local/ Local-filesystem backend: private, session-scoped files with traversal-safe names (registers on ctx.spillFiles)
spill-policy/ tools/post-execute policy: replaces oversized plain-text results with a preview + spill path (no service surface)

The interface lives at spill/spill/. The split mirrors bash/fs: the seam owns storage only, spill-local owns the filesystem mechanics, and spill-policy owns WHEN to spill and the model-facing notice. Preview mechanics stay in util/retention — the policy composes the two without either owning the other's job.

See the tool output spill RFC for the design rationale, including why final-result spill is separate from tool-owned early spill (bash streams, subagent rollouts) and why creation belongs to the runtime spill seam rather than the model-facing write tool.