2026-07-28 13:55:59 +08:00
|
|
|
import { createUserMessage } from '@deepseek-ai/dsh-llm'
|
2026-07-12 15:41:42 +08:00
|
|
|
import { afterEach, describe, expect, it, vi } from 'vitest'
|
build(vendor): rescope the vendored Cordis packages into @deepseek-ai
Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it
prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`,
`verify-translation-pairing --write` for the touched bilingual pairs,
`gen-doc-graphs`, and one typert snapshot whose ids embed character offsets.
`pnpm run rescope-vendor --check` verifies the result.
Renames nine vendored packages (cordis, cosmokit, schemastery and the six
@cordisjs plugins) and every reference that resolves them: manifest names and
dependency keys, module specifiers including declare-module merges, cordis.yml
plugin names, tsconfig paths, every Markdown fence, and `docs/` prose.
Directory names, upstream versions, and dependency ranges are unchanged, so
vendor/README.md still reads as an upstream snapshot; its manifest table gains
an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed
at each fork's origin.
The tutorial tier follows the rename end to end: its yaml fences named plugins
the Loader can no longer resolve, its `ts ignore-check` fences disagreed with
the compiled fences beside them, and its prose quoted both. The contracts that
told readers to keep upstream names — the root convention and the vendoring
cookbook's tree comment and manifest invariant — now say to rescope instead.
Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle
purity gate now names the vendored libraries a browser bundle inlines, and the
files where a bare `cordis` is an agent-preset id keep that product data.
2026-08-10 22:04:06 +08:00
|
|
|
import { Context } from '@deepseek-ai/cordis'
|
2026-08-11 20:39:04 +08:00
|
|
|
import { existsSync, mkdtempSync, readFileSync, rmSync, writeFileSync } from 'node:fs'
|
2026-07-10 20:52:27 +08:00
|
|
|
import { tmpdir } from 'node:os'
|
|
|
|
|
import { join } from 'node:path'
|
2026-07-17 20:17:27 +08:00
|
|
|
import { SessionId, type SessionEvent } from '@deepseek-ai/dsh-session'
|
2026-08-13 00:36:22 +08:00
|
|
|
import JsonlSessionPersistence from '@deepseek-ai/dsh-session-persistence-jsonl'
|
2026-07-18 12:33:49 +08:00
|
|
|
import type { Agent } from '@deepseek-ai/dsh-agent'
|
2026-07-14 02:32:35 +08:00
|
|
|
import AgentLoop from '@deepseek-ai/dsh-agent-loop'
|
2026-07-16 17:39:53 +08:00
|
|
|
import { mountAgentLoopTestDependencies } from '@deepseek-ai/dsh-agent-loop-testkit'
|
2026-08-13 00:36:22 +08:00
|
|
|
import LocalJobRegistry from '@deepseek-ai/dsh-jobs-local'
|
|
|
|
|
import * as ToolTasks from '@deepseek-ai/dsh-tool-jobs'
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
import { LocalBashExecutor } from '@deepseek-ai/dsh-bash-local'
|
2026-08-13 00:36:22 +08:00
|
|
|
import LocalSubprocessRuntime from '@deepseek-ai/dsh-subprocess-local'
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
import * as ToolBash from '@deepseek-ai/dsh-tool-bash'
|
2026-08-13 00:36:22 +08:00
|
|
|
import * as BashEnvPlugin from '@deepseek-ai/dsh-shell-env'
|
Reorganize packages into a modular hierarchy
Move the 18 flat packages/<name> packages into role-grouped dirs:
core/, llm/, bash/, session-persistence/, ui/, support/. Group dirs are
pure containers; each package keeps its @deepseek-ai/dsh-* name.
Collapse the per-package tsconfig paths maps (base + typecheck) into one
@deepseek-ai/dsh-* wildcard with a candidate per group, and derive the
publint list from the hierarchy. Update all depth-coupled globs/configs
(workspace, tsdown, vitest, eslint, knip, tsconfig includes/refs,
per-package tsconfigs, generators, doc-script scopes, type-equiv manifest)
and the cross-package/script relative imports in tests.
Fix doc-typecheck's workspacePaths() to parse tsconfig JSONC via the
TypeScript API instead of a regex comment-strip, which corrupted the
new wildcard `/*/` path candidates.
WIP: doc cross-links and package/RFC docs still to update.
2026-06-20 22:55:20 +08:00
|
|
|
import { MockAdapter, textResponse, toolCallResponse } from '../../../core/agent-loop/tests/mock-adapter.ts'
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Full-loop integration: a scripted mock model drives the REAL bash tool
|
2026-08-09 15:34:32 +08:00
|
|
|
* through the agent loop, exercising the same execution paths a live model would
|
2026-08-13 00:36:22 +08:00
|
|
|
* (tool/call + tool/result session events, the generic `ctx.jobs` runtime,
|
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
|
|
|
* agent.inject completion notices).
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
*/
|
2026-07-12 15:41:42 +08:00
|
|
|
async function harness(adapter: MockAdapter, sessionRoot?: string, dshHome?: string) {
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
const ctx = new Context()
|
2026-07-16 17:39:53 +08:00
|
|
|
await mountAgentLoopTestDependencies(ctx)
|
2026-07-20 00:06:21 +08:00
|
|
|
if (sessionRoot !== undefined) {
|
2026-08-13 00:36:22 +08:00
|
|
|
await ctx.plugin(JsonlSessionPersistence, { root: sessionRoot, compression: 'none' })
|
2026-07-20 00:06:21 +08:00
|
|
|
}
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
await ctx.plugin(AgentLoop, { agents: [] })
|
2026-08-13 00:36:22 +08:00
|
|
|
await ctx.plugin(LocalJobRegistry)
|
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
|
|
|
await ctx.plugin(ToolTasks)
|
2026-08-13 00:36:22 +08:00
|
|
|
await ctx.plugin(LocalSubprocessRuntime)
|
2026-08-02 14:18:01 +08:00
|
|
|
await ctx.plugin(BashEnvPlugin, dshHome === undefined ? {} : { dshHome })
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
await ctx.plugin(LocalBashExecutor, { timeoutMs: 10_000 })
|
2026-08-02 14:18:01 +08:00
|
|
|
await ctx.plugin(ToolBash)
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
ctx.llm.registerAdapter(['mock'], adapter)
|
|
|
|
|
return ctx
|
|
|
|
|
}
|
|
|
|
|
|
2026-07-10 20:52:27 +08:00
|
|
|
const dirs: string[] = []
|
2026-07-12 15:41:42 +08:00
|
|
|
afterEach(() => {
|
|
|
|
|
vi.unstubAllEnvs()
|
|
|
|
|
for (const dir of dirs.splice(0)) rmSync(dir, { recursive: true, force: true })
|
|
|
|
|
})
|
2026-07-10 20:52:27 +08:00
|
|
|
|
2026-07-14 02:32:35 +08:00
|
|
|
function waitForIdle(ctx: Context, agent: Agent): Promise<void> {
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
return new Promise((resolve) => {
|
2026-08-06 12:13:14 +08:00
|
|
|
const dispose = ctx.on('agent/status', ({ agent: subject, status }) => {
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
if (subject === agent && status === 'idle') {
|
|
|
|
|
dispose()
|
|
|
|
|
resolve()
|
|
|
|
|
}
|
|
|
|
|
})
|
|
|
|
|
})
|
|
|
|
|
}
|
|
|
|
|
|
2026-07-14 02:32:35 +08:00
|
|
|
function events(agent: Agent): SessionEvent[] {
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
return [...agent.session.events]
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/** Find a session event by type, narrowed; throws when absent. */
|
|
|
|
|
function findEvent<T extends SessionEvent['type']>(
|
|
|
|
|
log: SessionEvent[],
|
|
|
|
|
type: T,
|
|
|
|
|
position: 'first' | 'last' = 'first',
|
|
|
|
|
): Extract<SessionEvent, { type: T }> {
|
|
|
|
|
const found = position === 'first'
|
|
|
|
|
? log.find(event => event.type === type)
|
|
|
|
|
: log.findLast(event => event.type === type)
|
|
|
|
|
if (!found) throw new Error(`no ${type} event in the session log`)
|
|
|
|
|
return found as Extract<SessionEvent, { type: T }>
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
function resultText(event: SessionEvent): string {
|
|
|
|
|
if (event.type !== 'tool/result') return ''
|
2026-07-28 13:55:59 +08:00
|
|
|
return event.data.message.content[0].content
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
.filter(block => block.type === 'text')
|
|
|
|
|
.map(block => block.text)
|
|
|
|
|
.join('')
|
|
|
|
|
}
|
|
|
|
|
|
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
|
|
|
/** Poll until `predicate` holds (background settlement races turn end). */
|
|
|
|
|
async function pollUntil(predicate: () => boolean, timeoutMs = 5_000): Promise<void> {
|
|
|
|
|
const deadline = Date.now() + timeoutMs
|
|
|
|
|
while (Date.now() < deadline) {
|
|
|
|
|
if (predicate()) return
|
|
|
|
|
await new Promise(resolve => setTimeout(resolve, 20))
|
|
|
|
|
}
|
|
|
|
|
throw new Error(`condition not met within ${timeoutMs}ms`)
|
|
|
|
|
}
|
|
|
|
|
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
describe('bash tool through the agent loop', () => {
|
2026-07-10 20:52:27 +08:00
|
|
|
it('first-turn bash receives session identity before the lazy JSONL file materializes', async () => {
|
|
|
|
|
const root = mkdtempSync(join(tmpdir(), 'dsh-bash-session-env-'))
|
|
|
|
|
dirs.push(root)
|
2026-07-12 15:41:42 +08:00
|
|
|
const dshHome = join(root, 'dsh-home')
|
|
|
|
|
vi.stubEnv('DSH_STALE_PARENT', 'stale')
|
2026-07-10 20:52:27 +08:00
|
|
|
const adapter = new MockAdapter([
|
|
|
|
|
toolCallResponse('call-1', 'bash', {
|
2026-07-12 15:41:42 +08:00
|
|
|
command: 'printf \'%s\\n%s\\n%s\\n%s\\n%s\\n\' "$DSH_HOME" "$DSH_SHELL" "$DSH_SESSION_ID" "$DSH_SESSION_JSONL" "${DSH_STALE_PARENT-unset}"; if [ -e "$DSH_SESSION_JSONL" ]; then printf \'present\\n\'; else printf \'absent\\n\'; fi',
|
2026-07-10 20:52:27 +08:00
|
|
|
description: 'inspect session environment',
|
|
|
|
|
}),
|
|
|
|
|
textResponse('Session environment inspected.'),
|
|
|
|
|
])
|
2026-07-12 15:41:42 +08:00
|
|
|
const ctx = await harness(adapter, root, dshHome)
|
2026-07-13 16:18:44 +08:00
|
|
|
const handle = await ctx.agents.create({
|
2026-07-10 20:52:27 +08:00
|
|
|
sessionId: SessionId('session-env-id'),
|
2026-07-17 21:56:10 +08:00
|
|
|
agentOptions: { provider: 'mock', model: 'mock' },
|
2026-07-10 20:52:27 +08:00
|
|
|
})
|
2026-07-18 12:33:49 +08:00
|
|
|
const agent = handle.agent
|
2026-07-10 20:52:27 +08:00
|
|
|
const location = ctx.sessionPersistence.locate(agent.session.header)
|
|
|
|
|
expect(location?.kind).toBe('jsonl')
|
|
|
|
|
|
2026-07-28 13:55:59 +08:00
|
|
|
agent.followup(createUserMessage({ content: [{ type: 'text', text: 'inspect the current session' }], source: { kind: 'user' } }))
|
2026-07-10 20:52:27 +08:00
|
|
|
await waitForIdle(ctx, agent)
|
|
|
|
|
|
|
|
|
|
const result = findEvent(events(agent), 'tool/result')
|
2026-07-12 15:41:42 +08:00
|
|
|
expect(resultText(result)).toBe(`${dshHome}\n1\nsession-env-id\n${location?.path}\nunset\nabsent\n`)
|
2026-07-24 21:58:07 +08:00
|
|
|
await ctx.sessions.flush(agent.session)
|
|
|
|
|
expect(existsSync(location!.path)).toBe(true)
|
2026-07-10 20:52:27 +08:00
|
|
|
const header = JSON.parse(readFileSync(location!.path, 'utf8').split('\n')[0]!) as { type: string; id: string }
|
|
|
|
|
expect(header).toMatchObject({ type: 'session', id: 'session-env-id' })
|
|
|
|
|
await handle.dispose()
|
|
|
|
|
})
|
|
|
|
|
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
it('foreground: model calls bash, sees the result, replies', async () => {
|
|
|
|
|
const adapter = new MockAdapter([
|
|
|
|
|
toolCallResponse('call-1', 'bash', { command: 'echo integration-ok', description: 'test command' }, 'Running it.'),
|
|
|
|
|
textResponse('The command printed integration-ok.'),
|
|
|
|
|
])
|
|
|
|
|
const ctx = await harness(adapter)
|
2026-07-18 12:21:15 +08:00
|
|
|
const agent = ctx.agentLoop.create(SessionId('it-fg'), { provider: 'mock', model: 'mock' })
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
|
2026-07-28 13:55:59 +08:00
|
|
|
agent.followup(createUserMessage({ content: [{ type: 'text', text: 'run echo integration-ok' }], source: { kind: 'user' } }))
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
await waitForIdle(ctx, agent)
|
|
|
|
|
|
|
|
|
|
const log = events(agent)
|
|
|
|
|
const toolCall = findEvent(log, 'tool/call')
|
|
|
|
|
expect(toolCall.data.name).toBe('bash')
|
|
|
|
|
|
|
|
|
|
const toolResult = findEvent(log, 'tool/result')
|
2026-07-28 13:55:59 +08:00
|
|
|
expect(toolResult.data.message.content[0].isError).toBe(false)
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
expect(resultText(toolResult)).toBe('integration-ok\n')
|
|
|
|
|
|
|
|
|
|
// The second model call saw the tool result in its derived history.
|
|
|
|
|
const lastRequest = adapter.requests.at(-1)
|
|
|
|
|
const toolResultBlocks = (lastRequest?.messages ?? [])
|
|
|
|
|
.flatMap(message => message.content)
|
|
|
|
|
.filter(block => block.type === 'tool-result')
|
|
|
|
|
expect(toolResultBlocks).toHaveLength(1)
|
|
|
|
|
|
|
|
|
|
const finalMessage = findEvent(log, 'assistant/message', 'last')
|
2026-07-28 13:55:59 +08:00
|
|
|
expect(finalMessage.data.message.content.some(
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
block => block.type === 'text' && block.text.includes('integration-ok'),
|
|
|
|
|
)).toBe(true)
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
it('foreground: non-zero exit is reported in the result text, not as isError', async () => {
|
|
|
|
|
const adapter = new MockAdapter([
|
|
|
|
|
toolCallResponse('call-1', 'bash', { command: 'exit 9', description: 'test command' }),
|
|
|
|
|
textResponse('It failed with code 9.'),
|
|
|
|
|
])
|
|
|
|
|
const ctx = await harness(adapter)
|
2026-07-18 12:21:15 +08:00
|
|
|
const agent = ctx.agentLoop.create(SessionId('it-exit'), { provider: 'mock', model: 'mock' })
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
|
2026-07-28 13:55:59 +08:00
|
|
|
agent.followup(createUserMessage({ content: [{ type: 'text', text: 'run exit 9' }], source: { kind: 'user' } }))
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
await waitForIdle(ctx, agent)
|
|
|
|
|
|
|
|
|
|
const toolResult = findEvent(events(agent), 'tool/result')
|
2026-07-28 13:55:59 +08:00
|
|
|
expect(toolResult.data.message.content[0].isError).toBe(false)
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
expect(resultText(toolResult)).toContain('[exit code: 9]')
|
|
|
|
|
})
|
|
|
|
|
|
2026-08-13 00:36:22 +08:00
|
|
|
it('background: start ack → completion wakes the idle agent → job_output collects it', async () => {
|
2026-08-11 20:39:04 +08:00
|
|
|
// The command blocks on a sentinel this test creates only after the agent
|
|
|
|
|
// has gone idle, so settlement cannot fold into the still-running turn.
|
|
|
|
|
// Without that fence a fast command can settle before step 2's pre-step
|
|
|
|
|
// claim, which folds the notice into a turn whose scripted reply is final:
|
|
|
|
|
// the turn then closes with an empty next-step inbox and the collection
|
|
|
|
|
// entries are never reached.
|
|
|
|
|
const dir = mkdtempSync(join(tmpdir(), 'dsh-bg-'))
|
|
|
|
|
dirs.push(dir)
|
|
|
|
|
const sentinel = join(dir, 'release')
|
2026-08-13 00:36:22 +08:00
|
|
|
// The job id is deterministic (a fresh LocalJobRegistry counts per kind from 1),
|
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
|
|
|
// so the script can name `bash-1` without threading a generated id.
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
const adapter = new MockAdapter([
|
2026-08-11 20:39:04 +08:00
|
|
|
toolCallResponse('call-1', 'bash', {
|
|
|
|
|
command: `while [ ! -f ${JSON.stringify(sentinel)} ]; do sleep 0.02; done; echo bg-ok`,
|
|
|
|
|
description: 'test command',
|
|
|
|
|
run_in_background: true,
|
|
|
|
|
}),
|
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
|
|
|
textResponse('Started it in the background.'),
|
2026-08-13 00:36:22 +08:00
|
|
|
toolCallResponse('call-2', 'job_output', { job_id: 'bash-1' }),
|
|
|
|
|
textResponse('Background job finished.'),
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
])
|
|
|
|
|
const ctx = await harness(adapter)
|
2026-07-18 12:21:15 +08:00
|
|
|
const agent = ctx.agentLoop.create(SessionId('it-bg'), { provider: 'mock', model: 'mock' })
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
|
2026-07-28 13:55:59 +08:00
|
|
|
agent.followup(createUserMessage({ content: [{ type: 'text', text: 'run echo bg-ok in the background' }], source: { kind: 'user' } }))
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
await waitForIdle(ctx, agent)
|
|
|
|
|
|
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
|
|
|
const firstResult = findEvent(events(agent), 'tool/result')
|
2026-07-28 13:55:59 +08:00
|
|
|
expect(firstResult.data.message.content[0].isError).toBe(false)
|
2026-08-13 00:36:22 +08:00
|
|
|
expect(resultText(firstResult)).toBe('started background job bash-1')
|
2026-08-11 20:39:04 +08:00
|
|
|
// The turn closed with the task still running, so the notice cannot exist yet.
|
2026-07-23 19:15:45 +08:00
|
|
|
const isNotice = (e: SessionEvent): e is SessionEvent<'user/message'> =>
|
|
|
|
|
e.type === 'user/message' && e.data.source.kind === 'plugin'
|
2026-08-11 20:39:04 +08:00
|
|
|
expect(events(agent).some(isNotice)).toBe(false)
|
|
|
|
|
|
|
|
|
|
// Releasing the command now settles it against a provably idle owner. No
|
|
|
|
|
// second user message: the wake alone opens the turn that collects it.
|
|
|
|
|
writeFileSync(sentinel, '')
|
2026-08-11 19:36:49 +08:00
|
|
|
const lastResultText = (): string => {
|
|
|
|
|
const found = events(agent).findLast(event => event.type === 'tool/result')
|
|
|
|
|
return found === undefined ? '' : resultText(found)
|
|
|
|
|
}
|
|
|
|
|
await pollUntil(() => events(agent).some(isNotice) && lastResultText().includes('bg-ok'))
|
2026-08-11 20:39:04 +08:00
|
|
|
// Two turns: the user's, then the one the completion opened by itself.
|
|
|
|
|
expect(events(agent).filter(event => event.type === 'turn/start')).toHaveLength(2)
|
2026-08-11 19:36:49 +08:00
|
|
|
|
2026-08-11 20:39:04 +08:00
|
|
|
// The notice carries the gated command as its label, so this pins the id,
|
|
|
|
|
// the terminal status, and the producer identity; the verbatim notice text
|
2026-08-13 00:36:22 +08:00
|
|
|
// and its bounding are pinned in the tool-jobs unit tests.
|
2026-08-11 19:36:49 +08:00
|
|
|
const notice = events(agent).find(isNotice)!
|
2026-08-11 20:39:04 +08:00
|
|
|
const noticeText = notice.data.content
|
|
|
|
|
.filter(block => block.type === 'text').map(block => block.text).join('')
|
2026-08-13 00:36:22 +08:00
|
|
|
expect(noticeText).toContain('background job bash-1 (bash: ')
|
2026-08-11 20:39:04 +08:00
|
|
|
expect(noticeText).toContain('finished [status: completed, exit code: 0]')
|
|
|
|
|
expect(notice.data.source).toMatchObject({
|
feat(web): declare the remaining context forms on every shipped producer
Four values complete the vocabulary, so the opaque body is reached only by
producers that genuinely promise no shape.
`snapshot` — current state a later snapshot supersedes. system-prompt now
exposes `renderContextSections()`, the named contributions
`renderContextSnapshot()` already joins for the model, so the body attributes
each part to the subsystem that produced it instead of re-splitting joined
prose. The runtime snapshot, time-context, and tmux-context declare it.
`notice` — a one-off account of what just happened, declared by tool-tasks,
goal state changes, tool-goal wrap-up, plan-mode switches, and
repeat-tool-guard. Its `summary` rides the COLLAPSED row: these five are the
majority of shipped producers and none of them needs expanding to be read.
The task summary bounds itself because its inputs are unbounded caller text.
`relay` — a message another agent addressed to this one; both subagent
sources declare it and the body names the sender above what it said.
`recall` — material lifted from another session's log. session-reference
needed no new field: its references already record retained and omitted
counts and the truncation flag, which the body shows first, because recalled
context is bounded on the way in.
`ContextFormed` is now discriminated by `form`, so a producer cannot declare
a shape without the facts that shape is presented from — a notice without its
summary, or a snapshot without its sections, fails to compile.
Only the two hook bridges stay opaque, by design: their content is whatever
an external program printed, so no shape can be promised for it. Unknown
kinds and unreadable records land there too.
2026-08-05 16:07:04 +08:00
|
|
|
kind: 'plugin',
|
2026-08-13 00:36:22 +08:00
|
|
|
plugin: 'tool-jobs',
|
feat(web): declare the remaining context forms on every shipped producer
Four values complete the vocabulary, so the opaque body is reached only by
producers that genuinely promise no shape.
`snapshot` — current state a later snapshot supersedes. system-prompt now
exposes `renderContextSections()`, the named contributions
`renderContextSnapshot()` already joins for the model, so the body attributes
each part to the subsystem that produced it instead of re-splitting joined
prose. The runtime snapshot, time-context, and tmux-context declare it.
`notice` — a one-off account of what just happened, declared by tool-tasks,
goal state changes, tool-goal wrap-up, plan-mode switches, and
repeat-tool-guard. Its `summary` rides the COLLAPSED row: these five are the
majority of shipped producers and none of them needs expanding to be read.
The task summary bounds itself because its inputs are unbounded caller text.
`relay` — a message another agent addressed to this one; both subagent
sources declare it and the body names the sender above what it said.
`recall` — material lifted from another session's log. session-reference
needed no new field: its references already record retained and omitted
counts and the truncation flag, which the body shows first, because recalled
context is bounded on the way in.
`ContextFormed` is now discriminated by `form`, so a producer cannot declare
a shape without the facts that shape is presented from — a notice without its
summary, or a snapshot without its sections, fails to compile.
Only the two hook bridges stay opaque, by design: their content is whatever
an external program printed, so no shape can be promised for it. Unknown
kinds and unreadable records land there too.
2026-08-05 16:07:04 +08:00
|
|
|
form: 'notice',
|
|
|
|
|
})
|
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
|
|
|
const readResult = findEvent(events(agent), 'tool/result', 'last')
|
2026-07-28 13:55:59 +08:00
|
|
|
expect(readResult.data.message.content[0].isError).toBe(false)
|
feat(tasks): background task runtime, generic task_* control tools, bash/subagent producers
One shared ctx.tasks registry (branded <kind>-N ids, owner-fenced
read/kill/wait/list, attachSurface misconfiguration fence, reported-flag
notice dedup, atomic register) + dsh-tool-tasks (task_output/task_list/
task_kill, completion-notice injection, background prompt habit).
Producers opt in via their own enableRunInBackground config: bash
(stream kind; seam slimmed to resolve/run/start returning a BashProcess
handle, bash_output/bash_kill deleted) and subagent (final-output kind;
done settles after run.dispose()). Owner disposal drains tasks through
the new awaited ctx.agents.onCleanup seam in the loop's disposal chain.
Both RFCs moved to implemented/; docs, catalogs, snapshots re-pinned.
2026-07-09 21:22:54 +08:00
|
|
|
expect(resultText(readResult)).toContain('bg-ok')
|
|
|
|
|
expect(resultText(readResult)).toContain('[status: completed, exit code: 0]')
|
Add bash execution: dsh-bash seam, dsh-bash-local impl, dsh-tool-bash tools
Three packages following the new capability-seam pattern (interface /
implementation / consumer, now documented in docs/architecture.md):
- dsh-bash: abstract BashExecutor service (ctx.bash) + vocabulary types.
- dsh-bash-local: local subprocesses — bash -c per call in a detached
process group, SIGTERM→SIGKILL group kills, tail-keep truncation with
full-stream spill files, model-friendly env, background task registry.
- dsh-tool-bash: the bash / bash_output / bash_kill tool schemas with
runtime arg validation and background completion notices via
agent.inject(). Non-zero exits are reported, not errored.
Design surveyed against the bash tools of Claude Code, OpenCode, Codex,
and pi (notes in the package READMEs). Permissions/sandbox stay TODO on
the tools/execute waterfall seam; stateful-shell alternatives recorded
in run.ts.
2026-06-12 23:28:44 +08:00
|
|
|
})
|
|
|
|
|
})
|