deepseek-harness/scripts
Tianyi Cui 3c1c6a89b1 test(python): gate installed runtime wheels across release targets (#2953)
* test(python): exercise installed wheels as black boxes

Add an installed-wheel mode that refuses source/editable imports, repository working directories, mismatched SDK/runtime versions, unpinned runtime dependencies, and executables outside the installed runtime distribution. The mode resolves the wheel-owned executable itself, so callers cannot accidentally prove an explicit checkout artifact.

Add a real-API scenario that drives two tool-using turns through the public synchronous SDK, verifies the file bytes outside the agent, checks completed turn/tool events and persistence, and projects provider failures without retaining credential-bearing error text. The existing deterministic scenario set remains the keyless behavior oracle.

Refs #2952.

* ci(python): require installed-wheel checks on every release target

Move the complete deterministic runtime scenarios behind construction and clean installation of the SDK and matching runtime wheels. Each native leg runs outside the checkout with source-resolution environment variables removed; Linux manylinux smokes assert the same installed provenance.

Expand the required pull-request call from Linux x64 to Linux x64, Linux arm64, and macOS arm64. Trusted heads receive only DEEPSEEK_API_KEY_EXTERNAL for a fail-loud live two-turn smoke on each carrier, while fork and Dependabot heads retain the full keyless path without exposing secrets.

Pin the reusable secret declaration, matrix call, aggregate dependency, untrusted-head condition, and live/keyless commands in the workflow contract test.

Refs #2952.

* docs(testing): make installed wheels the Python CI authority

Record the clean-wheel provenance boundary, complete keyless scenario set, trusted real-API contract, secret handling, and three-target required topology in a new implemented testing decision. Update the SEA distribution and portable-CI authorities plus the Python contributor reference to describe the same current state.

Archive the fully superseded Linux-x64-only decision after consolidating its rationale and alternatives into the new owner. Preserve its bilingual triplet as a sealed historical snapshot and redirect every active current-state reference.

Refs #2952.
2026-08-23 16:53:55 +08:00
..
fixtures/translation-prompt test: make the product translation fixture generic 2026-08-13 13:58:03 +08:00
release docs: remove implementation narration from prose 2026-08-21 22:22:23 +08:00
snapshots test(python): gate installed runtime wheels across release targets (#2953) 2026-08-23 16:53:55 +08:00
types/client-build-environment feat(client): inject public build environment 2026-08-19 18:21:26 +08:00
agent-note-tree.ts fix(notes): keep archive helpers internal 2026-07-26 23:29:46 +08:00
AGENTS.md docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
archived-agent-notes.spec.ts Merge remote-tracking branch 'origin/master' into worktree/archive-agent-notes-20260726 2026-07-27 00:53:07 +08:00
archived-agent-notes.ts docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
attribute-chunk-bytes.mjs build(web): react-free vendor list for the incremental markdown pipeline, npmPackageOf scoped guard, chunk audit script 2026-08-06 16:38:25 +08:00
build-exe-for-python-sdk-native-pty.spec.ts fix(python-runtime): fall back to node-pty prebuild 2026-08-13 18:12:36 +08:00
build-exe-for-python-sdk-native-pty.ts fix(python-runtime): fall back to node-pty prebuild 2026-08-13 18:12:36 +08:00
build-exe-for-python-sdk.ts chore(repo): wire profile apps and the renamed runtime through builds 2026-08-23 10:59:01 +08:00
build-python-release.py feat(python-sdk): support bundled preset runtime dependencies 2026-08-14 13:06:21 +08:00
build.ts fix(build): support standalone pnpm entrypoints 2026-08-21 11:09:25 +08:00
change-scope.spec.ts test(windows): budget instrumented integration waits 2026-08-09 16:39:41 +08:00
change-scope.ts refactor(dev-infra): narrow change scope report 2026-07-28 01:02:43 +08:00
check-expected-filenames.sh
check-macos-deployment-target.py fix: address Python release review feedback 2026-08-11 20:09:33 +08:00
check-vendor-manifest.sh
check-workspace-constraints.spec.ts chore(repo): wire profile apps and the renamed runtime through builds 2026-08-23 10:59:01 +08:00
check-workspace-constraints.ts chore(repo): wire profile apps and the renamed runtime through builds 2026-08-23 10:59:01 +08:00
ci-workflow.spec.ts test(python): gate installed runtime wheels across release targets (#2953) 2026-08-23 16:53:55 +08:00
clean.spec.ts feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
clean.ts feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
client-build-environment.client.spec.ts fix(cic): cover release-publish in client-build gate and correct group wording 2026-08-20 15:59:40 +08:00
client-build-environment.ts feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
client-bundle-css.spec.ts refactor(client): move web rendering into a dynamic plugin 2026-08-18 01:34:21 +08:00
client-bundle-purity.spec.ts chore(client): align split package graph 2026-08-23 16:28:18 +08:00
client-tsconfig.spec.ts fix: rebase 3 2026-08-13 02:29:17 +08:00
cordis-config-files.spec.ts Stabilize master CI across platforms 2026-07-25 00:10:37 +08:00
cordis-config-files.ts
cordis-core-api.spec.ts docs: generate each subsystem's cordis surface into its own page; delete the flat catalogs 2026-08-09 01:31:57 +08:00
cordis-core-api.ts refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
cordis-walk.ts build(vendor): rescope the vendored Cordis packages into @deepseek-ai 2026-08-10 22:04:13 +08:00
cordis-yaml.ts fix(python-sdk): harden packaged runtime behavior 2026-08-18 14:38:42 +08:00
coverage-exempt.spec.ts fix(ci): review follow-ups for the coverage lane split 2026-07-31 02:55:37 +08:00
coverage-exempt.ts perf(ci): isolate the transform corpus from coverage 2026-08-22 20:10:54 +08:00
coverage-partitions.spec.ts test(ci): deduplicate coverage command setup 2026-08-21 11:36:57 +08:00
coverage-partitions.ts fix(build): support standalone pnpm entrypoints 2026-08-21 11:09:25 +08:00
coverage-uncovered-locations.cjs ci: print exact uncovered locations when the coverage gate fails 2026-08-06 03:18:17 +08:00
demo-code-mode.mjs refactor(acp): launch automation through the dsh acp profile 2026-08-23 10:59:00 +08:00
demo-cordis.mjs refactor(acp): launch automation through the dsh acp profile 2026-08-23 10:59:00 +08:00
dev-web.spec.ts build(client): enforce client package boundaries 2026-08-18 01:34:53 +08:00
dev-web.ts build(client): enforce client package boundaries 2026-08-18 01:34:53 +08:00
doc-budgets.manifest.json test(python): pin the minimal composition's model-visible surface 2026-08-17 16:49:14 +08:00
doc-typecheck-paths.spec.ts refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
doc-typecheck-paths.ts refactor(client): merge React bindings into UI renderer 2026-08-18 01:34:23 +08:00
doc-typecheck.ts docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
gen-client-catalog.spec.ts fix: ci 2026-08-13 01:33:31 +08:00
gen-client-catalog.ts docs: purge residual chain-of-thought leakage 2026-08-22 13:10:23 +08:00
gen-config-catalog.ts docs: remove implementation narration from prose 2026-08-21 22:22:23 +08:00
gen-cordis-api.ts refactor(cordis): generate catalogs from Typert models 2026-07-29 23:55:12 +08:00
gen-cordis-catalog-partition.spec.ts build(vendor): rescope the vendored Cordis packages into @deepseek-ai 2026-08-10 22:04:13 +08:00
gen-cordis-catalog-record.spec.ts fix(i18n): bind localized links to active pairs 2026-08-19 02:26:57 +08:00
gen-cordis-catalog.ts fix(client): align domain split with repository gates 2026-08-23 16:28:19 +08:00
gen-cordis-inspect-catalog.ts • feat(self-modification): add dynamic Cordis plugin runtime and UI 2026-08-13 01:29:36 +08:00
gen-doc-graphs.spec.ts fix(scripts): share package-source selection to clear the jscpd clone 2026-07-30 19:57:17 +08:00
gen-doc-graphs.ts docs: synchronize controller transport documentation 2026-08-23 16:16:04 +08:00
gen-module-graph.ts
gen-persistence-catalog.ts docs(todo): add the owning subsystem reference 2026-08-22 22:22:43 +08:00
gen-scoped-events.ts build(vendor): rescope the vendored Cordis packages into @deepseek-ai 2026-08-10 22:04:13 +08:00
gen-third-party-notices.spec.ts refactor(infra): keep Codex notices direct 2026-08-15 05:26:12 +08:00
gen-third-party-notices.ts docs: remove implementation narration from prose 2026-08-21 22:22:23 +08:00
gen-tool-catalog.ts docs: purge residual chain-of-thought leakage 2026-08-22 13:10:23 +08:00
gen-translation-brief.ts fix(i18n): bind localized links to active pairs 2026-08-19 02:26:57 +08:00
install-lefthook.mjs fix(ci): stabilize latest-master acceptance gates 2026-08-12 19:41:06 +08:00
install-lefthook.spec.ts perf(ci): parallelize coverage and web snapshots in-job 2026-08-18 21:15:20 +08:00
jsdoc.ts refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
lint-rule-fingerprint.spec.ts feat(util): mint UUIDs without crypto.randomUUID in every context 2026-08-21 20:35:34 +08:00
locale-dictionary-parity.spec.ts fix(locale): tighten parity gate and correct copy-source wording 2026-08-18 17:56:49 +08:00
markdown.ts fix(i18n): share Markdown link parsing 2026-08-18 19:37:53 +08:00
merge-translation-pairing-driver.sh fix(i18n): preserve merge conflicts without runtime 2026-08-09 00:37:46 +08:00
merge-translation-pairing.ts fix(i18n): bind localized links to active pairs 2026-08-19 02:26:57 +08:00
migrate-packed-session-fixtures.ts test: omit persistence envelopes from session snapshots 2026-08-18 18:27:01 +08:00
oxlint-contract.spec.ts fix(test): publish lint probes atomically 2026-08-22 20:10:55 +08:00
package-graph.spec.ts fix(client): align domain split with repository gates 2026-08-23 16:28:19 +08:00
package-graph.ts fix(client): align domain split with repository gates 2026-08-23 16:28:19 +08:00
package-invariants.spec.ts refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
package-invariants.ts refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
paired-markdown-derivatives.spec.ts docs: deduplicate paired code-block checks 2026-07-26 02:52:48 +08:00
paired-markdown-derivatives.ts docs: deduplicate paired code-block checks 2026-07-26 02:52:48 +08:00
pnpm-invocation.spec.ts fix(build): support standalone pnpm entrypoints 2026-08-21 11:09:25 +08:00
pnpm-invocation.ts fix(build): support standalone pnpm entrypoints 2026-08-21 11:09:25 +08:00
prepare-ci-bubblewrap.sh fix(sandbox): isolate bwrap PID namespace 2026-08-20 10:05:16 +08:00
project-doc-site.spec.ts docs(notes): localize zh note links and widen the closure walk timeout 2026-08-20 22:29:32 +08:00
project-doc-site.ts docs(website): serve index routes at their clean-URL .md addresses 2026-08-20 22:10:35 +08:00
project-reference-faces.spec.ts build: enforce split project reference faces 2026-08-08 12:25:41 +08:00
project-reference-faces.ts build: enforce split project reference faces 2026-08-08 12:25:41 +08:00
publication-payload.spec.ts refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
publication-payload.ts refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
publint-all.spec.ts build(client): enforce client package boundaries 2026-08-18 01:34:53 +08:00
publint-all.ts feat(webworker): browser worker host runtime and the vfs image packer 2026-08-21 20:35:32 +08:00
publish-npm-baseline.ts feat(web,cli): open the ready Web UI by default 2026-08-19 15:42:12 +08:00
repo-files.ts Merge remote-tracking branch 'origin/master' into worktree/archive-agent-notes-20260726 2026-07-27 00:53:07 +08:00
rescope-vendor.spec.ts build(vendor): add the @deepseek-ai rescope codemod, its mapping doc, and its Agent Note 2026-08-10 22:04:10 +08:00
rescope-vendor.ts chore(client): align split package graph 2026-08-23 16:28:18 +08:00
run-coverage-partitions.ts perf(ci): parallelize coverage and web snapshots in-job 2026-08-18 21:15:20 +08:00
run-gates.spec.ts Merge origin/master into worktree/gate-package-subsystem-pages 2026-08-23 15:47:32 +08:00
run-gates.ts Merge origin/master into worktree/gate-package-subsystem-pages 2026-08-23 15:47:32 +08:00
run-oxlint.spec.ts fix(client): align domain split with repository gates 2026-08-23 16:28:19 +08:00
run-oxlint.ts fix(client): align domain split with repository gates 2026-08-23 16:28:19 +08:00
run-web-snapshots.ts fix(build): support standalone pnpm entrypoints 2026-08-21 11:09:25 +08:00
session-fixture-layout.snapshot.ts test: omit persistence envelopes from session snapshots 2026-08-18 18:27:01 +08:00
session-fixture-layout.spec.ts refactor(test): keep session fixture projection local 2026-08-19 13:41:42 +08:00
session-fixture-layout.ts refactor(test): keep session fixture projection local 2026-08-19 13:41:42 +08:00
slot-walk.ts • feat(self-modification): add dynamic Cordis plugin runtime and UI 2026-08-13 01:29:36 +08:00
smoke-python-runtime.py test(python): gate installed runtime wheels across release targets (#2953) 2026-08-23 16:53:55 +08:00
test-fixture-cleanup.ts fix(scripts): widen fixture-cleanup EPERM retry window 2026-08-13 15:16:12 +08:00
test-invariants.spec.ts refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
test-invariants.ts refactor(attachment): normalize image storage API 2026-08-21 15:06:24 +08:00
translation-brief.spec.ts fix(i18n): align translation briefing link rules 2026-08-19 03:01:11 +08:00
translation-brief.ts fix(i18n): align translation briefing link rules 2026-08-19 03:01:11 +08:00
translation-links.spec.ts test(i18n): model reserved paths portably 2026-08-19 04:08:47 +08:00
translation-links.ts fix(i18n): encode exact link paths safely 2026-08-19 03:56:17 +08:00
translation-pairing-git.ts docs: remove implementation narration from prose 2026-08-21 22:22:23 +08:00
translation-pairing-merge.spec.ts fix(i18n): resolve merge and Markdown edge cases 2026-08-19 03:47:00 +08:00
translation-pairing-merge.ts fix(i18n): resolve merge and Markdown edge cases 2026-08-19 03:47:00 +08:00
translation-pairing-record.ts feat(i18n): compose pairing records during merges 2026-08-08 21:11:59 +08:00
translation-pairing.manifest.json docs: complete Chinese proofreading and generated reference pairing 2026-08-09 11:02:16 +08:00
translation-pairing.spec.ts Merge pull request #2560 from deepseek-harness/codex/add-security-policy 2026-08-23 11:10:52 +08:00
translation-pairing.ts Merge pull request #2560 from deepseek-harness/codex/add-security-policy 2026-08-23 11:10:52 +08:00
translation-prompt.snapshot.ts
translation-prompt.spec.ts fix(i18n): bind localized links to active pairs 2026-08-19 02:26:57 +08:00
translation-prompt.ts docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
ts-project.ts feat(release): reject a module-scope load of an optional dependency 2026-08-14 16:10:06 +08:00
type-equiv.manifest.json fix(client): align domain split with repository gates 2026-08-23 16:28:19 +08:00
verify-agent-note-classification.ts docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
verify-agent-note-format.ts docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
verify-application-entrypoints.spec.ts chore(repo): enforce dsh as the only Node application launcher 2026-08-23 10:59:01 +08:00
verify-application-entrypoints.ts chore(repo): enforce dsh as the only Node application launcher 2026-08-23 10:59:01 +08:00
verify-archived-agent-notes.ts docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
verify-built-package-invariants.mjs refactor(scripts): consolidate gate scripts on mdast fences, parseArgs, and globSync 2026-07-26 23:14:28 +08:00
verify-built-package-invariants.spec.ts
verify-client-domain-graph.spec.ts fix(client): tighten UI ownership boundaries 2026-08-18 01:34:25 +08:00
verify-client-domain-graph.ts fix(client): tighten UI ownership boundaries 2026-08-18 01:34:25 +08:00
verify-client-packages.spec.ts chore(client): align split package graph 2026-08-23 16:28:18 +08:00
verify-client-packages.ts docs: remove implementation narration from prose 2026-08-21 22:22:23 +08:00
verify-config-source-ownership.spec.ts feat(subagent): make Claude Code provider directly installable 2026-08-14 16:05:48 +08:00
verify-config-source-ownership.ts feat(subagent): make product providers directly installable 2026-08-12 19:28:31 +08:00
verify-cordis-config.spec.ts feat(subagent): make Codex provider directly installable 2026-08-15 03:25:43 +08:00
verify-cordis-config.ts test(webhook): resolve the real CLI rule from examples 2026-08-23 01:48:55 +08:00
verify-doc-budgets.ts
verify-doc-refs.ts
verify-doc-site-fragments.spec.ts docs(website): serve every page as raw Markdown with an llms.txt index 2026-08-20 22:10:15 +08:00
verify-doc-site-fragments.ts docs(website): serve index routes at their clean-URL .md addresses 2026-08-20 22:10:35 +08:00
verify-dsh-package-licenses.spec.ts Adopt MIT for DSH packages 2026-08-13 13:07:24 +08:00
verify-dsh-package-licenses.ts Adopt MIT for DSH packages 2026-08-13 13:07:24 +08:00
verify-export-jsdoc.ts docs: remove implementation narration from prose 2026-08-21 22:22:23 +08:00
verify-md-links.spec.ts fix(doc-gates): review findings — GitHub-slugger parity and the surviving old-rule prose 2026-08-09 10:56:43 +08:00
verify-md-links.ts docs: remove implementation narration from prose 2026-08-21 22:22:23 +08:00
verify-md-wrap.ts docs(notes): archive low-value decision records 2026-07-26 23:06:00 +08:00
verify-mermaid.ts Merge origin/master into worktree/web-plugin-config, adapting to ctx.remote.$on 2026-08-11 19:52:34 +08:00
verify-node-next-types.ts refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
verify-optional-dependency-imports.spec.ts feat(release): reject a module-scope load of an optional dependency 2026-08-14 16:10:06 +08:00
verify-optional-dependency-imports.ts docs: remove implementation narration from prose 2026-08-21 22:22:23 +08:00
verify-package-invariants.ts docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
verify-package-paths.ts chore: remove remaining SDK toolchain residue 2026-08-11 16:37:29 +08:00
verify-package-readme-limitations.ts
verify-package-readme-model-experience.ts chore(client): align split package graph 2026-08-23 16:28:18 +08:00
verify-public-repository-links.spec.ts docs: replace nonexistent repository references 2026-08-11 12:35:38 +08:00
verify-public-repository-links.ts docs: replace nonexistent repository references 2026-08-11 12:35:38 +08:00
verify-runtime-closure.spec.ts fix(python-sdk): make runtime readiness explicit 2026-08-18 17:36:59 +08:00
verify-runtime-closure.ts fix(python-sdk): make runtime readiness explicit 2026-08-18 17:36:59 +08:00
verify-skill-invocation-metadata.spec.ts fix(skill): enforce manual invocation policy 2026-08-10 18:04:26 +08:00
verify-skill-invocation-metadata.ts fix(skill): enforce manual invocation policy 2026-08-10 18:04:26 +08:00
verify-subsystem-pages.spec.ts test(docs): use a block cleanup callback 2026-08-23 16:02:32 +08:00
verify-subsystem-pages.ts Merge origin/master into worktree/gate-package-subsystem-pages 2026-08-23 15:47:32 +08:00
verify-translation-pairing.ts fix(i18n): bind localized links to active pairs 2026-08-19 02:26:57 +08:00
verify-translation-prompt.ts test: decouple the translation prompt snapshot from live documents 2026-08-13 13:07:57 +08:00
verify-type-equiv.ts docs: synchronize controller transport documentation 2026-08-23 16:16:04 +08:00
verify-vendored-links.ts fix(review): label host-preparation failures and gate vendored lockfile links 2026-08-02 01:25:01 +08:00
vitest-environment.compat.spec.ts fix(test): isolate jsdom storage on Node 26 2026-07-30 21:49:33 +08:00
wine-windows-gates.sh fix(ci): give Wine Host compiler sufficient heap 2026-08-23 01:48:35 +08:00