deepseek-harness/packages
Yichen Jiang a90ccc4453 revert(sandbox): withdraw the credential-document read denial
The `readDenyPaths` policy field shipped in the previous commit broke Linux
confinement outright. bwrap has to create the `/dev/null` bind's mount point
inside a tree its own profile has already made read-only, so it refused the
entire confinement whenever the parent directory was absent — every host that
has not stored a credential yet, including a fresh install:

  bwrap: Can't mkdir parents for /home/runner/.dsh/.env: Read-only file system

which the executor correctly classifies as SANDBOX_UNAVAILABLE, so every
confined bash call failed closed. Landlock cannot subtract from its own `/`
read grant, so it reported `partial` enforcement on every confined call for a
file it never hid, with no way to switch the denial off (schemastery fills an
omitted array with `[]`, so empty and omitted were indistinguishable).

A protection that breaks confinement where it works and misreports it where it
does not is worse than a documented absence. Revert the field, both expressible
backends, the enforcement downgrade, and the policy default; state the residue
plainly in the credentials-local READMEs — file mode stops other OS users, not
the model — and keep the OS-keychain provider recorded as the real answer.

The narrower discipline stands: no surface hoists the credential document into
`process.env`, and the model is never handed a resolved path to it.
2026-07-30 17:09:42 +08:00
..
acp Merge remote-tracking branch 'origin/master' into codex/web-queue-actions 2026-07-30 00:30:38 +08:00
bash revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
client Merge remote-tracking branch 'origin/master' into mergebot/pr937 2026-07-30 11:59:59 +08:00
code-runtime Merge commit 'ecbf75a5e70f662b6420375140cf12eb6bac7860' into worktree/retarget-pr885-20260729 2026-07-29 21:37:43 +08:00
compact Merge commit '90bc53cc64dc684dc3d741f45ae6a8d548c188f9' into worktree/retarget-pr885-20260729 2026-07-29 21:40:13 +08:00
context Merge branch 'master' into fix/workspace-instruction-frame-metadata 2026-07-30 12:16:41 +08:00
cordis revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
core Merge remote-tracking branch 'origin/master' into codex/web-queue-actions 2026-07-30 03:33:41 +08:00
credentials revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
examples Merge latest master into codex/migrate-to-oxlint 2026-07-30 00:13:30 +08:00
experimental docs: implement experimental and internal package group 2026-07-28 22:30:12 +08:00
fs revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
goal Merge remote-tracking branch 'origin/master' into codex/web-queue-actions 2026-07-30 03:33:41 +08:00
guard docs(i18n): standardize reviewed README headings 2026-07-29 20:16:45 +08:00
hooks fix(hooks): remove speculative regex runtime 2026-07-29 23:15:15 +08:00
host fix(web): address queue review feedback 2026-07-30 04:12:38 +08:00
llm docs(credentials): record the third-review contracts across READMEs, catalogs, and a new Agent Note 2026-07-30 16:37:28 +08:00
lsp Merge master into fix/subprocess-password-scrub 2026-07-29 21:38:24 +08:00
mcp docs(i18n): record proofread README pairs 2026-07-29 15:30:44 +08:00
plan Merge remote-tracking branch 'origin/master' into xjt/readme-proofreading-batch-1 2026-07-29 15:47:00 +08:00
pty Merge remote-tracking branch 'origin/master' into codex/web-queue-actions 2026-07-30 01:04:25 +08:00
sandbox revert(sandbox): withdraw the credential-document read denial 2026-07-30 17:09:42 +08:00
sdk Merge master into fix/subprocess-password-scrub 2026-07-29 21:38:24 +08:00
session-persistence docs(i18n): standardize reviewed README headings 2026-07-29 20:16:45 +08:00
session-projection refactor(session-projection): compact checkpoint row fields to ver/seq/val 2026-07-28 22:45:35 +08:00
session-query Merge commit 'ecbf75a5e70f662b6420375140cf12eb6bac7860' into worktree/retarget-pr885-20260729 2026-07-29 21:37:43 +08:00
session-title Merge latest master into codex/migrate-to-oxlint 2026-07-29 22:39:06 +08:00
settings fix(settings): keep installSettingsSection quiet when its consumer unloads 2026-07-30 15:52:51 +08:00
skill Merge branch 'master' into fix/workspace-instruction-frame-metadata 2026-07-30 12:16:41 +08:00
spill docs(i18n): standardize reviewed README headings 2026-07-29 20:16:45 +08:00
storage Merge commit 'refs/codex/pr885/master-20260730' into worktree/retarget-pr885-20260729 2026-07-30 01:18:28 +08:00
subagent Merge commit 'ecbf75a5e70f662b6420375140cf12eb6bac7860' into worktree/retarget-pr885-20260729 2026-07-29 21:37:43 +08:00
subprocess Merge master into fix/subprocess-password-scrub 2026-07-29 21:38:24 +08:00
support Merge branch 'worktree-config-settings-seam' into worktree-llm-dynamic-config 2026-07-30 14:33:36 +08:00
tasks Merge remote-tracking branch 'origin/master' into codex/web-queue-actions 2026-07-30 00:30:38 +08:00
telemetry docs(i18n): record proofread README pairs 2026-07-29 15:30:44 +08:00
timeout docs(i18n): standardize reviewed README headings 2026-07-29 20:16:45 +08:00
todo docs(i18n): standardize reviewed README headings 2026-07-29 20:16:45 +08:00
typert Merge commit 'refs/codex/pr885/master-20260730' into worktree/retarget-pr885-20260729 2026-07-30 01:18:28 +08:00
ui docs(credentials): record the third-review contracts across READMEs, catalogs, and a new Agent Note 2026-07-30 16:37:28 +08:00
util fix(credentials-local): one operation chain, read-modify-write under the shared writer lock, and a quote-aware line editor 2026-07-30 15:40:09 +08:00
web docs(i18n): resolve follow-up review findings 2026-07-29 18:38:56 +08:00
workflow Merge commit 'ecbf75a5e70f662b6420375140cf12eb6bac7860' into worktree/retarget-pr885-20260729 2026-07-29 21:37:43 +08:00
workspace docs(i18n): standardize reviewed README headings 2026-07-29 20:16:45 +08:00
AGENTS.md refactor(tools): shapeDispatchLog off the public registry surface 2026-07-26 22:52:15 +08:00
CLAUDE.md
README.i18n.yaml Merge branch 'worktree-config-settings-seam' into worktree-llm-dynamic-config 2026-07-30 14:33:36 +08:00
README.md Merge branch 'worktree-config-settings-seam' into worktree-llm-dynamic-config 2026-07-30 14:33:36 +08:00
README.zh.md Merge branch 'worktree-config-settings-seam' into worktree-llm-dynamic-config 2026-07-30 14:33:36 +08:00

Packages

English | 中文

Packages use the @deepseek-ai/dsh-* scope. Each is a Cordis Service subclass or function plugin; contributions use ctx.effect(), ctx.on(), or ctx.waterfall(). Authoring rules: package and root.

Hierarchy

Packages live at packages/<group>/<pkg>/; groups are containers, while names remain @deepseek-ai/dsh-<pkg>. Each group README is the canonical package/ctx-key map.

Group Role Release expectation
core/ Product API spine: sessions, prompts, tools, agent services, and the concrete loop Product — stable surface
typert/ Type graph generation, artifact loading, and runtime registry Product — stable surface
goal/ Persisted same-session goal state and lifecycle Product — stable surface
llm/ LLM capability family: the abstract service + provider adapters Product — stable surface
subprocess/ Subprocess capability family: spawn seam + local process-tree implementation Product — stable surface
bash/ Bash capability family: executor seam, local impl, model-facing tool Product — stable surface
pty/ Persistent PTY capability family: owner-scoped sessions, local implementation, and model-facing tools Product — stable surface
code-runtime/ Code-execution capability family: the runtime seam for model-written programs + a worker-thread backend Product — stable surface
sandbox/ Process-confinement seam; bwrap/Landlock/Seatbelt backends Product — stable surface
fs/ Filesystem capability family: seam, local impl, model-facing file tools, bash-backed discovery tools Product — stable surface
lsp/ LSP capability family: seam, generic stdio provider, and the lsp tool Product — stable surface
skill/ Skill capability family: the provider registry, local provider, and model-facing catalog/loader Product — stable surface
compact/ Compaction capability family: the abstract seam + a basic backend (tool deferred) Product — stable surface
context/ Model-visible request context, including workspace instructions and time context Product — stable surface
subagent/ Subagent capability family: the provider-registry seam and the model-facing delegation tool Product — stable surface
tasks/ Generic background-task runtime and model-facing task_* control tools Product — stable surface
workflow/ Workflow capability family: the script-engine seam, worker-thread engine, and model-facing workflow and fresh-agent ralph tools Product — stable surface
web/ Web capability family: seam, search/fetch provider impls, and the model-facing web tools Product — stable surface
spill/ Spill capability family: storage seam, local impl, tool-result spill policy Product — stable surface
todo/ The model-facing todo_write tool Product — stable surface
plan/ Plan collaboration state with a direct entry command and reviewed exit Product — stable surface
timeout/ Tool-call timeout policy: the tools/execute deadline enforcer Product — stable surface
guard/ Loop-hygiene guards: advisory repeat-call reminders Product — stable surface
cordis/ Self-referential runtime toolset: inspect the live runtime's plugins and services, mount/unmount model-written plugins (design) Product — stable surface
hooks/ Hook bridges + the shared Claude Code / Codex wire-protocol library Product — stable surface
session-persistence/ Persistence seam + JSONL/SQLite backends Product — stable surface
session-projection/ Projection seam: domain fold units serve whole values Product — stable surface
session-query/ Session retrieval family: logical corpus, bounded reads, lineage, event relationships, semantic filtering, and SQLite full-text search Product — stable surface
session-title/ Log-backed session titles: fallback service and opt-in LLM providers Product — stable surface
settings/ User-settings seam + file-backed provider Product — stable surface
credentials/ Credential-reference seam + env-over-.env provider Product — stable surface
telemetry/ Session reporting: capture/redact seam, OTel backend Product — stable surface
storage/ Non-session storage hub + backends + domain form Product — stable surface
workspace/ Workspace entity Product — stable surface
sdk/ Project SDK tooling Product — stable surface
acp/ Automation-only Agent Client Protocol server Product — stable surface
ui/ TUI and JSON-RPC integrations, approval/interaction seams, ask-user tool Product — stable surface
host/ Web-GUI host half: API gateway + HTTP route server Product — stable surface
client/ Web-GUI browser half: shell, wire, object services, slots, ui-* plugins Product — stable surface
experimental/ Prototypes and internal plugins Unreleased
examples/ Demo bundles (agent-spine + TUI/CLI/ACP/JSON-RPC bins) leaves load Support — example infra
support/ Support infrastructure (testkits, invariants, replay, Loader smokes) Support — lower compatibility expectations
util/ Low-level zero-dependency utilities shared across groups (Branded<B>, Harness home/path helpers, timeout, retention) Support — small, stable, harness-dep-free

New packages join existing groups; new groups update their README and this table.

Dependencies

The dependency graph is generated: docs/module-graph.md (pnpm run gen-module-graph, freshness-gated in CI).

Extension plugins depend on interfaces, never the concrete loop. dsh-agent-loop is swappable; UI, hook, and tool plugins use dsh-agent. Composition bundles, including dsh-agent-spine-demo, may depend on spine plugins. Capabilities split into interface / implementation / consumer packages; see capability seams.

Package READMEs cover purpose, APIs, extension points, and Model Experience unless on the model-agnostic omission allowlist. They also carry ## Known Limitations and Deferred Work or use its allowlist.