deepseek-harness/packages
Chinesezjc 8f7d9121d1 fix(code-runtime-python): bound three child-side walks by depth, not width
Three separate paths in the CPython child allocated state proportional to a
value's width or a string's length, so a legitimate input the byte budgets
admit could die as the program's own MemoryError.

`_lossless_json_violation` enqueued one traversal tuple per member while
running, in `dispatch`, over MODEL-CONSTRUCTED binding arguments that no
child-side byte budget bounds first. It now uses the same (kind, container,
iterator) cursor the other two walks already had, checking dict keys as the
cursor pulls each entry. Measured over `[0] * 6_000_000` (~17 MB of JSON):
459.1 MiB of traversal tuples before, 0.0 MiB after.

`_decode_json_plain` matched JSON strings with a `(?:[^"\\]|\\.)*` repetition,
which makes CPython's engine retain backtracking state proportional to the
string's width: 146 MiB for a 1 MiB string, 557.8 MiB for 4 MiB. A legitimate
multi-megabyte binding reply raised MemoryError inside `_pump_replies`, and
because that pump is the only settler of the call's future, the run stranded
until the wall clock reported `timeout`. Strings now scan chunk-to-chunk over a
character class, which the engine matches without backtracking state; the same
4 MiB decode peaks at the 4.0 MiB result.

`_check_done_value` charged strings and dict keys what
`_dump_string(...).encode()` returned, building the escaped copy plus its
encode to MEASURE it -- ~6x the original each for control-heavy text, so
metering a value the budget then rejects could itself breach RLIMIT_AS and
report `exception` where the seam promises `output-limit`. The new
`_json_str_cost` counts instead, reusing `_json_string_cost`'s C-level passes
and reproducing `_dump_string`'s exact surrogate rules (fold spelled-out pairs,
charge six ASCII bytes per lone surrogate). Identical values, 228.9 MiB -> 19.1
MiB of peak on a 20M-NUL string.

Each fix ships a regression test. The two RLIMIT_AS repros are Linux-only:
Darwin does not apply the limit, so the peaks above are measured directly and
recorded in the test comments.
2026-08-31 14:24:59 +08:00
..
acp release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
api Merge origin/master into worktree/steer-followup-images 2026-08-31 10:37:39 +08:00
attachment Merge origin/master into worktree/steer-followup-images 2026-08-31 10:37:39 +08:00
boot release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
bundle refactor(bundle): remove the agent spine demo 2026-08-31 11:23:30 +08:00
client Merge origin/master into worktree/steer-followup-images 2026-08-31 10:37:39 +08:00
code-runtime fix(code-runtime-python): bound three child-side walks by depth, not width 2026-08-31 14:24:59 +08:00
compaction release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
context refactor(bundle): remove the agent spine demo 2026-08-31 11:23:30 +08:00
core refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
credentials release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
e2b release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
experimental refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
extensions refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
feedback release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
fs Merge remote-tracking branch 'origin/master' into worktree/fix-3269-read-image 2026-08-31 10:00:53 +08:00
goal test(goal): cover projection teardown access 2026-08-31 11:23:46 +08:00
guard release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
hooks release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
host release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
identity release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
interaction release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
jobs release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
llm refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
lsp release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
mcp release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
plan release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
preset release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
runtime-diagnostics refactor(bundle): remove the agent spine demo 2026-08-31 11:23:30 +08:00
sandbox release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
schedule release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
sdk test(sdk): mount session projections in loop fixtures 2026-08-31 11:23:46 +08:00
session refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
session-query refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
settings release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
shell release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
skill refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
spill release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
storage refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
subagent test(loader): budget production profile startup 2026-08-31 11:23:46 +08:00
subprocess release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
terminal release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
test-support refactor(session)!: remove SQLite persistence backend 2026-08-31 13:23:07 +08:00
todo release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
typert release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
util release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
web release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
webhook release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
workflow release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
workspace release(dsh): 0.1.2-alpha.2 2026-08-30 21:19:29 +08:00
AGENTS.md docs(testing): state the concurrent execution model where tests are written 2026-08-29 15:31:12 +08:00
CLAUDE.md
README.i18n.yaml refactor(bundle): remove the agent spine demo 2026-08-31 11:23:30 +08:00
README.md refactor(bundle): remove the agent spine demo 2026-08-31 11:23:30 +08:00
README.zh.md refactor(bundle): remove the agent spine demo 2026-08-31 11:23:30 +08:00

description kind
The DeepSeek Harness package workspace: how the npm packages under packages/ are grouped, what each group owns, and the conventions that bind them. package-group

Packages

English | 中文

Summary

The harness is assembled from npm packages under packages/, grouped by capability family: sessions and the agent loop, model-facing tools, shell and filesystem execution, web access, subagents, and the rest. Use this page as the top-level map: find the owning group, then open its README for the package list. Every package is scoped @deepseek-ai/dsh-* and lives in exactly one group; each group README is the authoritative package map for its family.

Table of Contents


Package groups

Every package lives in exactly one group; new packages join existing groups, and a new group updates its own README and this table.

Group Role
core/ Product API spine: sessions, prompts, tools, agent services, and the concrete loop
api/ Remote BFF assembly and Typert RPC gateway
typert/ Type graph generation, artifact loading, and runtime registry
goal/ Same-session goal persistence and lifecycle
schedule/ Session-local scheduled follow-ups
feedback/ Human feedback capture and command
identity/ Shared anonymous identity
llm/ LLM capability family: abstract service + provider adapters
e2b/ E2B remote-runtime providers
subprocess/ Subprocess capability family: Service Definition + local process-tree provider
shell/ Bash capability family: executor seam, local impl, model-facing tools
terminal/ Persistent PTY capability family: owner-scoped sessions, local implementation, model-facing tools
code-runtime/ Code-execution capability family: Service Definition + worker-thread provider + PTC mode Consumer
sandbox/ Process-confinement seam; bwrap/Landlock/Seatbelt backends
fs/ Filesystem capability family: seam, local impl, model-facing file tools, discovery tools
lsp/ LSP capability family: seam, generic stdio provider, and the lsp tool
skill/ Skill capability family: provider registry, local provider, model-facing catalog/loader
compaction/ Compaction capability family: Service Definition + basic provider + command Consumer
context/ Model-visible request context: workspace instructions, time context, references
subagent/ Subagent capability family: provider-registry contract and model-facing delegation tools
jobs/ Generic background-job runtime and model-facing job control tools
experimental/ Private prototypes and internal-only plugins
workflow/ Workflow seam, worker-thread engine, and model-facing workflow/ralph tools
webhook/ Verified external events, trusted rules, and fire-and-forget Workspace Sessions
web/ Web capability family: seam, search/fetch providers, model-facing web tools
attachment/ Durable attachment identity, validation, local content-addressed storage
spill/ Spill capability family: storage seam, local impl, tool-result spill policy
todo/ The model-facing todo_write tool
plan/ Plan collaboration state with a direct entry command and reviewed exit
preset/ Per-session agent composition from preset cordis.yml files
guard/ Loop-hygiene guards: advisory repeat-call reminders + the tools/execute deadline enforcer
bundle/ Installable dsh --profile patch layers
extensions/ Agent runtime self-modification: live plugin/service inspection and model-written mount/unmount
hooks/ Hook bridges + the shared Claude Code / Codex wire-protocol library
session/ Durable session data plane: persistence seam + backends, projection seam, log-backed titles, session reporting
session-query/ Session retrieval family: logical corpus, bounded reads, lineage, semantic filtering, SQLite full-text search
settings/ User-settings seam + file-backed provider
credentials/ Credential-reference and credential-record seam + env-over-.env provider + authorization flows that ask a human
storage/ Non-session storage hub + backends + domain form
workspace/ Workspace entity
sdk/ Out-of-process SDK: JSON-RPC protocol and TypeScript client/server
acp/ Automation-only Agent Client Protocol server
interaction/ Human-collaboration plane: approval/interaction seams, permission preset, commands, ask-user tool
boot/ Shared app-bin boot glue
host/ Web-GUI host half: API gateway + HTTP route server
client/ Web-GUI browser half: shell, wire, object services, slots, ui-* plugins
test-support/ Support infrastructure (testkits, invariants, replay, Loader smokes)
runtime-diagnostics/ Runtime diagnostics: package-owned invariant checks and reports
util/ Low-level zero-dependency utilities shared across groups (Branded<B>, home/path helpers, timeout, retention)

Release expectations

Most groups are product — stable API. The exceptions: e2b/ is a POC, experimental/ is unreleased, and test-support/, runtime-diagnostics/, and util/ are support with lower compatibility expectations.


Dependencies

The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).

Extension plugins depend on Service Definitions, never concrete providers. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles may depend on spine plugins. Capabilities separate Service Definition / Service Provider / Consumer roles when they evolve independently; see capability seams.


Package README contracts

Every package README covers purpose, configuration, extension points, and Model Experience unless the model-agnostic omission allowlist exempts it. It also carries ## Known Limitations and Deferred Work or uses its allowlist. Package conventions — exports, service access, invariants, tests — live in packages/AGENTS.md.


Dev Note

Working context for maintainers — click to expand

None.