deepseek-harness/packages
Yichen Jiang 43f3324a7b fix(tools): restrict what a scope inherits, not just the global layer
A restriction was compiled against the global tool layer alone: only
global-layer tools were tested against `admits()`, and every chain-layer
tool was overlaid unfiltered afterward. That read the exempt set as "the
global layer" when what it means is "what this scope registers itself" —
two descriptions of the same set only while every model-facing tool sat in
the host composition.

Moving those rows onto the agent plane separated them. A preset's tools are
an ANCESTOR contribution to a joined agent, so a subagent's `toolFilter`
stopped constraining anything it was given; and with the global layer empty
`restrict()` rejected every name it received as unknown, failing the child
outright. With the same tools in the global layer the filter still admits
and applies normally, which is what makes this a regression of the move
rather than a standing limitation.

`view()` now filters everything a scope inherits — the global layer and
every ancestor layer on its chain — and exempts only the layer the scope
owns. That exemption is load-bearing rather than incidental: the delegation
runtime registers a child's `report` and structured-output tools into the
child's own layer, and a filter naming the capabilities the child may use
must not strip the machinery it answers through. Tool order, and with it
prefix-cache reuse, is unchanged: inherited names keep their global-then-
ancestor position and own-layer names still come last.

The diagnostic said "unknown global tool" while listing what is really the
inherited surface; it now names the surface it checks and says why an
own-layer name is not restrictable.

Fixes #2185
2026-08-10 20:34:45 +08:00
..
acp Merge remote-tracking branch 'origin/master' into worktree/web-multimodal-image-input 2026-08-09 23:33:35 +08:00
api Merge remote-tracking branch 'origin/stack/agent-profiles-3-wire' into stack/agent-profiles-5-web-ui 2026-08-09 13:18:22 +08:00
attachment test(attachment): exclude POSIX fsync on Windows 2026-08-10 12:06:01 +08:00
bash Merge remote-tracking branch 'origin/master' into fix/preset-host-plane-task-registry 2026-08-10 16:53:03 +08:00
boot docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
bundle Merge remote-tracking branch 'origin/master' into fix/preset-host-plane-task-registry 2026-08-10 16:17:44 +08:00
client fix(web): pin preset before subagent header action 2026-08-10 19:54:08 +08:00
code-runtime docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
compact Merge remote-tracking branch 'origin/master' into worktree/web-multimodal-image-input 2026-08-09 23:33:35 +08:00
context Merge remote-tracking branch 'upstream/master' into fix/workspace-context-rendered-change-proof 2026-08-10 05:10:39 -07:00
core fix(tools): restrict what a scope inherits, not just the global layer 2026-08-10 20:34:45 +08:00
credentials docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
e2b docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
examples docs: replace front door terminology 2026-08-10 13:07:46 +08:00
experimental docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
feedback fix(feedback): report shared anonymous user id 2026-08-10 16:23:05 +08:00
fs Merge latest master into PR branch 2026-08-10 02:10:57 -07:00
goal docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
guard docs: purge chain-of-thought leakage from prose 2026-08-09 21:10:59 +08:00
hooks docs: replace front door terminology 2026-08-10 13:07:46 +08:00
host Merge remote-tracking branch 'origin/master' into worktree/subagent-missing-tools-fb2359 2026-08-10 20:32:58 +08:00
interaction docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
llm docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
lsp Merge branch 'worktree/ci-native-windows-20260808' into worktree/ci-native-windows-coverage-20260808 2026-08-09 21:52:02 +08:00
mcp docs: purge chain-of-thought leakage from prose 2026-08-09 21:10:59 +08:00
plan docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
preset Merge remote-tracking branch 'origin/master' into worktree/subagent-missing-tools-fb2359 2026-08-10 20:32:58 +08:00
pty Merge branch 'merge/1829-master' into merge/1990-1829 2026-08-10 11:24:58 +08:00
sandbox docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
scaffold docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
self-modification fix(apiproxy): echo the preset a created session runs, not its header 2026-08-10 19:28:40 +08:00
session docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
session-query docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
settings docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
skill Merge pull request #1543 from deepseek-harness/stack/agent-profiles-8-authoring 2026-08-10 11:55:58 +08:00
spill docs: reserve seam for complete capabilities 2026-08-09 17:26:57 +08:00
storage docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
subagent fix(tools): restrict what a scope inherits, not just the global layer 2026-08-10 20:34:45 +08:00
subprocess docs: purge chain-of-thought leakage from prose 2026-08-09 21:10:59 +08:00
support Merge latest master into PR branch 2026-08-10 02:10:57 -07:00
tasks Merge remote-tracking branch 'origin/master' into fix/preset-host-plane-task-registry 2026-08-10 16:53:03 +08:00
todo docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
typert docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
util docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
web docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
workflow docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
workspace Merge remote-tracking branch 'origin/master' into worktree/drop-create-by-name 2026-08-10 15:49:34 +08:00
AGENTS.md docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
CLAUDE.md
README.i18n.yaml Merge remote-tracking branch 'origin/master' into codex/pr-555-ci-fix 2026-08-10 12:33:36 +08:00
README.md Merge remote-tracking branch 'origin/master' into codex/pr-555-ci-fix 2026-08-10 12:33:36 +08:00
README.zh.md Merge remote-tracking branch 'origin/master' into codex/pr-555-ci-fix 2026-08-10 12:33:36 +08:00

Packages

English | 中文

npm scope: @deepseek-ai/dsh-*; Cordis Service subclasses and function plugins contribute through ctx.effect(), ctx.on(), or ctx.waterfall(). Rules: package, root.

Hierarchy

Groups hold packages/<group>/<pkg>/; names stay @deepseek-ai/dsh-<pkg>. Group READMEs own package/ctx-key maps.

Group Role Release expectation
core/ Product API spine: sessions, prompts, tools, agent services, and the concrete loop Product — stable surface
api/ Remote BFF assembly and TypeRT RPC gateway Product — stable surface
typert/ Type graph generation, artifact loading, and runtime registry Product — stable surface
goal/ Same-session goal persistence and lifecycle Product — stable surface
feedback/ Human feedback Product — stable surface
llm/ LLM capability family: the abstract service + provider adapters Product — stable surface
e2b/ E2B providers POC
subprocess/ Subprocess capability family: Service Definition + local process-tree provider Product — stable surface
bash/ Bash capability family: executor seam, local impl, model-facing tool Product — stable surface
pty/ Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools Product — stable surface
code-runtime/ Code-execution capability family: Service Definition + worker-thread provider + Code Mode Consumer Product — stable surface
sandbox/ Process-confinement seam; bwrap/Landlock/Seatbelt backends Product — stable surface
fs/ Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools Product — stable surface
lsp/ LSP capability family: seam, generic stdio provider, and the lsp tool Product — stable surface
skill/ Skill capability family: the provider registry, local provider, and model-facing catalog/loader Product — stable surface
compact/ Compaction capability family: Service Definition + basic provider + command Consumer Product — stable surface
context/ Model-visible request context, including workspace instructions and time context Product — stable surface
subagent/ Subagent capability family: the provider-registry contract and the model-facing delegation tool Product — stable surface
tasks/ Generic background-task runtime and model-facing task_* control tools Product — stable surface
workflow/ Workflow seam, worker-thread engine, and model-facing workflow/ralph tools Product — stable surface
web/ Web capability family: seam, search/fetch provider impls, and the model-facing web tools Product — stable surface
attachment/ Durable attachment identity, validation, local content-addressed storage Product — stable surface
spill/ Spill capability family: storage seam, local impl, tool-result spill policy Product — stable surface
todo/ The model-facing todo_write tool Product — stable surface
plan/ Plan collaboration state with a direct entry command and reviewed exit Product — stable surface
preset/ Per-session agent composition from preset cordis.yml files Product — stable surface
guard/ Loop-hygiene guards: advisory repeat-call reminders + the tools/execute deadline enforcer Product — stable surface
bundle/ Installable dsh --profile patch layers Product — stable surface
self-modification/ Agent runtime self-modification: live plugin/service inspection, model-written plugin mount/unmount (design), restricted repository Plugin loading Product — stable surface
hooks/ Hook bridges + the shared Claude Code / Codex wire-protocol library Product — stable surface
session/ Durable session data plane: persistence seam + JSONL/SQLite backends, projection seam, log-backed titles, session reporting Product — stable surface
session-query/ Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search Product — stable surface
settings/ User-settings seam + file-backed provider Product — stable surface
credentials/ Credential-reference seam + env-over-.env provider Product — stable surface
storage/ Non-session storage hub + backends + domain form Product — stable surface
workspace/ Workspace entity Product — stable surface
scaffold/ Create/launch/drive project tooling: helper, launcher, initializer, wire protocol with both ends, launcher telemetry Product — stable surface
acp/ Automation-only Agent Client Protocol server Product — stable surface
interaction/ Human-collaboration plane: approval/interaction seams, permission preset, commands, ask-user tool Product — stable surface
boot/ Shared app-bin boot glue Product — stable surface
host/ Web-GUI host half: API gateway + HTTP route server Product — stable surface
client/ Web-GUI browser half: shell, wire, object services, slots, ui-* plugins Product — stable surface
experimental/ Prototypes and internal plugins Unreleased
examples/ Demo bundles (agent-spine + CLI/ACP/JSON-RPC bins) leaves load Support — example infra
support/ Support infrastructure (testkits, invariants, replay, Loader smokes) Support — lower compatibility expectations
util/ Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) Support — small, stable, harness-dep-free

New packages join existing groups; new groups update their README and this table.

Dependencies

The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).

Extension plugins depend on Service Definitions, never concrete providers. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities separate Service Definition / Service provider / Consumer roles when they evolve independently; see capability seams.

Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.