The review's critical: the open-merge branch re-joined and re-walked the whole held text per frame, so k tiny open frames cost O(k * budget) (thousands of 1-byte frames against a near-64 MiB budget would re-traverse hundreds of GB and block the host event loop). The host now holds a fragment ARRAY with an incrementally billed cost — each fragment's jsonStringCostUpTo walks only its own text — and the closing frame bills only its own content, so the merged entry's wire cost is charged exactly once, split across the fragments. The child bills symmetrically: the first open fragment pays quotes+separator, each continuation pays only its content, matching the host ledger (the review's warning: per-fragment full billing truncated a 16-char merged entry under maxLogBytes: 64 that costs only 19 bytes as one entry). Regression cases: 16 single-character flushes merge to one whole entry; a closing frame that overflows the remaining budget truncates to the marker; a closing frame after an open flood already truncated the ledger is a no-op; and a forged open-frame flood stays bounded by the ledger. The closing-frame post-truncation guard is an invariant-false branch (an open frame that would trip the ledger resets openParts, so a non-empty hold implies no truncation) and carries a v8 ignore with that reason. |
||
|---|---|---|
| .agents | ||
| .claude | ||
| .github | ||
| apps | ||
| docs | ||
| native | ||
| packages | ||
| patches | ||
| python | ||
| scripts | ||
| snapshots | ||
| vendor | ||
| website | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .gitlab-ci.yml | ||
| .jscpd.json | ||
| .oxlintrc.json | ||
| .oxlintrc.staged.json | ||
| .rgignore | ||
| AGENTS.md | ||
| BENCHMARK.md | ||
| BRAND_GUIDELINES.i18n.yaml | ||
| BRAND_GUIDELINES.md | ||
| BRAND_GUIDELINES.zh.md | ||
| CLAUDE.md | ||
| CONTRIBUTING.i18n.yaml | ||
| CONTRIBUTING.md | ||
| CONTRIBUTING.zh.md | ||
| lefthook.yml | ||
| LICENSE | ||
| package.json | ||
| pnpm-lock.yaml | ||
| pnpm-workspace.yaml | ||
| pytest.ini | ||
| README.i18n.yaml | ||
| README.md | ||
| README.zh.md | ||
| SAFETY.i18n.yaml | ||
| SAFETY.md | ||
| SAFETY.zh.md | ||
| THIRD_PARTY_NOTICES.md | ||
| tsconfig.base.client.json | ||
| tsconfig.base.json | ||
| tsconfig.client.json | ||
| tsconfig.host.json | ||
| tsconfig.json | ||
| tsdown.config.ts | ||
| vitest.config.ts | ||
| vitest.e2e.config.ts | ||
| vitest.expected.config.ts | ||
| vitest.shared.ts | ||
| vitest.snapshot.config.ts | ||
| vitest.web-stress.config.ts | ||
| vitest.web.config.ts | ||
| vitest.web.perf.config.ts | ||
DeepSeek Harness
English | 中文
DeepSeek Harness (dsh) is an open-source agent harness developed by DeepSeek AI.
It is built on an everything-is-a-plugin architecture and powered by Cordis, whose design is described in A Programming Paradigm for Spatiotemporal Composability.
Documentation: https://deepseek-harness.github.io/deepseek-harness/
Developer preview
DeepSeek Harness is in developer preview and iterating rapidly. THERE WILL BE COMPATIBILITY-BREAKING CHANGES.
Review the safety notice before running the project.
Run
Run from npm
Install Node.js, then run:
npx @deepseek-ai/dsh web
The command starts the Web UI at http://127.0.0.1:3080 by default and opens it in the default browser for a local launch. An SSH launch only prints the host URL because the SSH client or editor owns the local forwarded address. Pass --no-open to run the server without opening a browser. See Web UI guide.
Run from source
To run from a repository checkout:
git clone https://github.com/deepseek-ai/deepseek-harness.git
cd deepseek-harness
pnpm install
pnpm run build
pnpm dsh web
pnpm run build prepares the repository artifacts. pnpm dsh web uses those built artifacts without rebuilding.
Community and support
- Submit feedback or bug reports through GitHub Discussions.
- Add the
dsh-plugintopic to your plugin repository for discoverability. - Join DeepSeek Harness Discord community.
Contributing
See CONTRIBUTING.md.
Development
Start with the development guide and architecture documentation.
For agents, follow AGENTS.md.
License
Third-party dependencies and their licenses are disclosed in THIRD_PARTY_NOTICES.md.