2nd dokployH
Find a file
Chinesezjc 8e9d5467b0 fix(code-runtime-python): bound reply and call backlogs, snapshot binding metadata, and compact the reply queue
Review findings on the CPython backend: a child that never reads fd 3 leaves
the reply pipe full forever, so the drain loop waits on 'drain' while every
call frame it keeps sending resolves a binding and queues another reply —
the backlog (and the binding results it pins) would grow until the wall
clock. sendReply now caps the pending backlog at MAX_PENDING_REPLIES and
settles the run as worker-exit past it, mirroring the frame cap; a child
flooding calls against a binding that never settles would otherwise bypass
that cap (pendingReplies grows only after the await), so the dispatcher
counts in-flight binding calls before dispatch and releases the slot in the
async body's finally, capping outstanding closures at the same bound. The
drain also compacts its consumed prefix (replyQueue.splice(0, head)) once
head reaches the bound, so a drain that stays alive without emptying cannot
grow the backing store linearly with cumulative throughput.

The completion-value meter counted lone surrogates with
_SURROGATE.findall(folded), materializing one single-character string per
surrogate: a surrogate-dense value near the budget (millions of surrogates,
each serializing to six bytes) allocated millions of objects before the meter
returned, defeating the meter's counting-without-building contract. The count
is now the length difference between folded and the without string the meter
already computes; a standalone equivalence check confirms it matches findall
across lone-high, lone-low, paired, astral, and mixed cases.

validateBindings read namespace.global/errorClass.name/memberNameProperty
several times and retained the original errorClass object for the boot
frame, whose JSON.stringify re-read it after validation: a stateful getter
could throw or change between the two stages, turning the seam-misuse
rejection into a worker-exit or injecting an unvalidated name. Each field is
now read once into a plain value and the bindings map stores a plain
{ name, memberNameProperty } copy, so validation and the boot frame see
identical values.

Regression tests: a hostile child floods 5000 sequential valid calls without
reading fd 3 and the run settles worker-exit with the reply-queue message
before maxWallMs; a 3,000,000-surrogate completion succeeds at an
18,000,002-byte budget and reports output-limit one byte under; a 5000-call
flood against a never-settling binding settles worker-exit with the
call-backlog message; getter-backed namespace metadata that throws or
changes on a second read boots and runs with each field read exactly once; a
two-wave flood whose replies exceed the writable high-water mark drives the
drain past the compaction bound mid-delivery and verifies all 1524 replies
arrive. README Known Limitations gains the reply-backlog and call-backlog
bounds (en/zh, pairing re-recorded); a new Agent Note registers the findings.
2026-08-31 15:25:26 +08:00
.agents fix(code-runtime-python): bound reply and call backlogs, snapshot binding metadata, and compact the reply queue 2026-08-31 15:25:26 +08:00
.claude docs: accuracy sweep, architecture restructure, two ADRs, review skill 2026-06-13 22:05:34 +08:00
.github refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
apps test(loader): budget production profile startup 2026-08-31 11:23:46 +08:00
docs docs(doc-graphs): list the experimental Python backend as a codeRuntime implementation 2026-08-31 15:25:26 +08:00
native docs: trim CoT leakage from post-purge prose 2026-08-22 20:35:11 +08:00
packages fix(code-runtime-python): bound reply and call backlogs, snapshot binding metadata, and compact the reply queue 2026-08-31 15:25:26 +08:00
patches chore(subprocess-local): bump node-pty beta 2026-08-13 17:58:13 +08:00
python chore(sdk-runtime): adopt master's manifest (drop the code-runtime-python peer) 2026-08-31 14:56:11 +08:00
scripts docs(doc-graphs): list the experimental Python backend as a codeRuntime implementation 2026-08-31 15:25:26 +08:00
snapshots refactor(bundle): remove the agent spine demo 2026-08-31 11:23:30 +08:00
vendor release(vendor): cordis 4.0.2, cosmokit 1.8.3, group 1.0.2, hmr 1.0.17, include 1.0.7, loader 1.0.3, logger-console 1.0.2, schemastery 3.18.2, timer 1.1.4 2026-08-30 11:04:50 +08:00
website fix(docs): harden build output cleanup 2026-08-26 14:33:17 +08:00
.editorconfig Declare LF and final-newline conventions in .editorconfig 2026-07-15 16:09:12 +08:00
.gitattributes feat(i18n): compose pairing records during merges 2026-08-08 21:11:59 +08:00
.gitignore fix(code-runtime-python): bound three child-side walks by depth, not width 2026-08-31 14:24:59 +08:00
.gitlab-ci.yml fix(python): make Windows release paths native 2026-08-24 19:09:40 +08:00
.jscpd.json chore(lint): bring .tsx files into the eslint, lefthook, and jscpd lanes 2026-07-27 21:42:08 +08:00
.oxlintrc.json feat(util): mint UUIDs without crypto.randomUUID in every context 2026-08-21 20:35:34 +08:00
.oxlintrc.staged.json refactor: make lint workflows Oxlint-only 2026-08-09 14:55:15 +08:00
.rgignore chore: exclude archived Agent Notes from rg 2026-08-10 14:49:30 +08:00
AGENTS.md refactor(bundle): remove the agent spine demo 2026-08-31 11:23:30 +08:00
BENCHMARK.md docs: make Web UI the primary onboarding path 2026-08-12 11:44:33 +08:00
BRAND_GUIDELINES.i18n.yaml docs: split brand guidelines into bilingual pair 2026-08-19 21:01:18 +08:00
BRAND_GUIDELINES.md docs: split brand guidelines into bilingual pair 2026-08-19 21:01:18 +08:00
BRAND_GUIDELINES.zh.md docs: split brand guidelines into bilingual pair 2026-08-19 21:01:18 +08:00
CLAUDE.md Initialize repo with README, AGENTS.md, and CLAUDE.md symlink 2026-06-10 22:58:56 +08:00
CONTRIBUTING.i18n.yaml docs(i18n): polish contribution greeting 2026-08-12 14:40:32 +08:00
CONTRIBUTING.md docs(i18n): refine contribution guide wording 2026-08-12 14:24:44 +08:00
CONTRIBUTING.zh.md docs(i18n): polish contribution greeting 2026-08-12 14:40:32 +08:00
lefthook.yml Revert "fix(client): declare browser-only externals as devDependencies" 2026-08-15 02:19:09 +08:00
LICENSE Adopt MIT for DSH packages 2026-08-13 13:07:24 +08:00
package.json release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
pnpm-lock.yaml refactor(code-runtime-python): move the package into packages/experimental 2026-08-31 15:13:55 +08:00
pnpm-workspace.yaml Merge commit '80d68a54120fc87e6b354e41562a9fbfd6874e48' into codex/product-subagent-runtime-refresh-codex 2026-08-25 19:42:47 +08:00
pytest.ini Merge remote-tracking branch 'origin/master' into codex/trim-ai-prose 2026-07-14 00:40:36 +08:00
README.i18n.yaml docs: link Cordis paper on arXiv 2026-08-27 17:45:31 +08:00
README.md docs: link Cordis paper on arXiv 2026-08-27 17:45:31 +08:00
README.zh.md docs: link Cordis paper on arXiv 2026-08-27 17:45:31 +08:00
SAFETY.i18n.yaml Merge pull request #2560 from deepseek-harness/codex/add-security-policy 2026-08-23 11:10:52 +08:00
SAFETY.md Merge pull request #2560 from deepseek-harness/codex/add-security-policy 2026-08-23 11:10:52 +08:00
SAFETY.zh.md Merge pull request #2560 from deepseek-harness/codex/add-security-policy 2026-08-23 11:10:52 +08:00
THIRD_PARTY_NOTICES.md chore: commit the master third-party notices (SDK 0.3.241) 2026-08-31 14:59:01 +08:00
tsconfig.base.client.json feat(client): inject public build environment 2026-08-19 18:21:26 +08:00
tsconfig.base.json fix(code-runtime-python): finish the experimental move — invariant name and tsconfig aliases 2026-08-31 15:13:55 +08:00
tsconfig.client.json Merge commit 'bc954280ae67e349291e51e5787c6987e767fa40' into schedule-web-catalog 2026-08-28 07:24:24 +08:00
tsconfig.host.json refactor(code-runtime-python): move the package into packages/experimental 2026-08-31 15:13:55 +08:00
tsconfig.json refactor(repo): retire top-level examples 2026-08-24 22:02:44 +08:00
tsdown.config.ts refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
vitest.config.ts fix(code-runtime-python): complete the experimental move across configs and docs 2026-08-31 15:15:08 +08:00
vitest.e2e.config.ts feat(inspector): define shared protocol foundation 2026-08-27 16:15:17 +08:00
vitest.expected.config.ts refactor(repo): retire top-level examples 2026-08-24 22:02:44 +08:00
vitest.shared.ts fix(typert): close remote gateway review gaps 2026-08-07 21:47:15 +08:00
vitest.snapshot.config.ts fix(test): use expected-output naming 2026-08-24 21:37:14 +08:00
vitest.web-stress.config.ts test(web): add opt-in reasoning chunk stress lane 2026-08-04 14:37:31 +08:00
vitest.web.config.ts feat(inspector): define shared protocol foundation 2026-08-27 16:15:17 +08:00
vitest.web.perf.config.ts fix(history): adapt packed pages to session journal 2026-08-25 20:10:43 +08:00

DeepSeek Harness

English | 中文

DeepSeek Harness (dsh) is an open-source agent harness developed by DeepSeek AI.

It is built on an everything-is-a-plugin architecture and powered by Cordis, whose design is described in A Programming Paradigm for Spatiotemporal Composability.

Documentation: https://deepseek-harness.github.io/deepseek-harness/

Developer preview

DeepSeek Harness is in developer preview and iterating rapidly. THERE WILL BE COMPATIBILITY-BREAKING CHANGES.

Review the safety notice before running the project.

Run

Run from npm

Install Node.js, then run:

npx @deepseek-ai/dsh web

The command starts the Web UI at http://127.0.0.1:3080 by default and opens it in the default browser for a local launch. An SSH launch only prints the host URL because the SSH client or editor owns the local forwarded address. Pass --no-open to run the server without opening a browser. See Web UI guide.

Run from source

To run from a repository checkout:

git clone https://github.com/deepseek-ai/deepseek-harness.git
cd deepseek-harness
pnpm install
pnpm run build
pnpm dsh web

pnpm run build prepares the repository artifacts. pnpm dsh web uses those built artifacts without rebuilding.

Community and support

Contributing

See CONTRIBUTING.md.

Development

Start with the development guide and architecture documentation.

For agents, follow AGENTS.md.

License

MIT

Third-party dependencies and their licenses are disclosed in THIRD_PARTY_NOTICES.md.