Files
deepseek-harness/packages/spill
Dudu-0223 d0c2f0916d fix: address codex review round 1
- spill-policy validates maxInlineBytes as a non-negative integer at LOAD, so a
  bad config fails the deployment instead of letting a negative value reach
  TextRetainer and turn every oversized-result call into an isError.
- Document the spill seam vocabulary in docs/core-data-structures/spill.md
  (SaveTextSpill/SpillOwner/SpillSource/SpillRef/SpillPath, verbatim + type-equiv
  gated) and index it from core.md, matching the other capability seams.
2026-07-08 22:54:26 +08:00
..

spill/ - spill storage capability family

The tool-output spill capability seam: an abstract storage interface, a local filesystem implementation, and the tool-result policy that uses it. All product packages.

Package Role ctx key
spill/ Abstract spill storage seam (saveText — persist oversized tool text to a session-scoped path) ctx.spillFiles
spill-local/ Local-filesystem backend: private, session-scoped files with traversal-safe names (registers on ctx.spillFiles)
spill-policy/ tools/post-execute policy: replaces oversized plain-text results with a preview + spill path (no service surface)

The interface lives at spill/spill/. The split mirrors bash/fs: the seam owns storage only, spill-local owns the filesystem mechanics, and spill-policy owns WHEN to spill and the model-facing notice. Preview mechanics stay in util/retention — the policy composes the two without either owning the other's job.

See the tool output spill RFC for the design rationale, including why final-result spill is separate from tool-owned early spill (bash streams, subagent rollouts) and why creation belongs to the runtime spill seam rather than the model-facing write tool.