deepseek-harness/docs
Tianyi Cui 7234d41b91 workflow: hook promises and hook failures are realm-built too
Codex code-review round 5: agent()/parallel()/pipeline() returned HOST Promise
objects into the script realm — Object.getPrototypeOf(agent('x')) reached host
Promise.prototype, contradicting the realm contract (correctness containment,
not the accepted sandbox stance). The rejection channel had the same leak one
hop away: a caught hook failure was a host WorkflowError (host Error.prototype
chain), and phase()/log() threw host errors synchronously.

All three surfaces are realm-built now:
- hook promises: the realm's own Promise.resolve (bound at context setup)
  assimilates the host promise, so the script-visible promise carries realm
  prototypes; the realm promise gets the same no-op rejection consumer as the
  host one (a script may drop it).
- hook failures: rejections and phase/log sync throws are translated at the
  boundary into realm-built clones (name/code/message/fatal via an in-realm
  factory); non-WorkflowError host failures become generic realm Errors
  carrying their describeThrown rendering.
- the combinators recognize FATAL clones structurally
  (isFatalWorkflowErrorClone: proxy-guarded descriptor reads), preserving the
  fatal-vs-null discipline across the boundary; a script forging the shape
  kills only its own run. drive() maps any post-cancel failure to 'cancelled'
  by run state (a CANCELLED clone deliberately fails the host instanceof).

Tests: realm-promise identity for all three hooks + host Promise.prototype
pollution unreachable; clone shape (instanceof realm Error, name/code/fatal/
message) with prototype-chain mutation staying realm-side; a rejecting
provider result crossing as a generic clone; phase/log sync-throw clones;
combinator catch branches (string throw, proxy throw, shape-miss forgery →
null; forged fatal → kills own run); existing fatal-propagation, cancellation,
and unhandled-rejection tests as canaries.
2026-07-05 21:24:30 +08:00
..
cookbook Merge branch 'simpl-a2-vocab' into simpl-a3-knobs 2026-07-04 21:20:55 +08:00
cordis-catalog workflow, subagent: fix Codex code-review round-1 blockers 2026-07-05 19:04:38 +08:00
core-data-structures workflow, subagent: fix Codex code-review round-1 blockers 2026-07-05 19:04:38 +08:00
i18n docs: equal-authority pairing with sidecar consistency records 2026-07-03 07:41:24 -07:00
persistence-catalog Split the cordis catalog into separate events and services documents 2026-07-05 00:45:06 +08:00
postmortem fix(docs): address Codex review round 3 — last three moved-policy citations 2026-07-04 16:02:39 +08:00
rfc workflow: hook promises and hook failures are realm-built too 2026-07-05 21:24:30 +08:00
tool-catalog workflow: dynamic workflows — script-driven multi-agent orchestration 2026-07-05 13:29:35 +08:00
AGENTS.md Split the cordis catalog into separate events and services documents 2026-07-05 00:45:06 +08:00
architecture.md workflow: dynamic workflows — script-driven multi-agent orchestration 2026-07-05 13:29:35 +08:00
defensive-patterns.md docs(AGENTS): rewrite the root standing orders to the 1,500-word budget 2026-07-04 14:22:47 +08:00
development.i18n.yaml Split the cordis catalog into separate events and services documents 2026-07-05 00:45:06 +08:00
development.md Split the cordis catalog into separate events and services documents 2026-07-05 00:45:06 +08:00
development.zh.md Split the cordis catalog into separate events and services documents 2026-07-05 00:45:06 +08:00
module-graph.md workflow: dynamic workflows — script-driven multi-agent orchestration 2026-07-05 13:29:35 +08:00
testing.md fix(docs): address ds-review-bot — the e2e tier is not DeepSeek-only 2026-07-04 16:43:23 +08:00