2nd dokployH
Find a file
Tianyi Cui aa2a7f9a8a fix: validate and re-cap all inbound worker-port traffic (Codex round 1)
The host's message listener trusted the compile-time WorkerToHost shape on
traffic from a peer that runs model code: postMessage(null) threw in the
listener and crashed the host process; forged log/done messages bypassed
maxLogBytes/maxValueBytes (the worker-side LogBuffer and prepareValue cap
only honest flows); and the error-reply renegotiation re-echoed a forged
non-cloneable call id, throwing outside any catch.

Every inbound message now passes a runtime shape gate that validates and
REBUILDS it field by field (junk drops without a throw; call ids must be
numbers, so replies are always clone-plain; forged extra fields never ride
along). One host-side ledger bounds everything landing in logs — honest
port entries, forged ones, and stray pipe bytes — at the single documented
maxLogBytes, with the shared in-band truncation marker emitted host-side
when the ledger trips first; the completion value is re-capped host-side
through the same prepareValue (with exactly the truncation suffix as slack
so honest worker-capped values pass unchanged), and done error text is
bounded. Also folds the stray-capture budget into that shared ledger
(round-1 finding B: it was a second maxLogBytes on top of the documented
shared cap).
2026-07-08 11:42:59 +08:00
.agents/skills simplify pre-push skill guidance 2026-07-07 19:17:16 +08:00
.claude docs: accuracy sweep, architecture restructure, two ADRs, review skill 2026-06-13 22:05:34 +08:00
.github/workflows build: upgrade to 22.19 for deps 2026-07-07 17:39:04 +08:00
docs fix: validate and re-cap all inbound worker-port traffic (Codex round 1) 2026-07-08 11:42:59 +08:00
examples Merge branch 'master' into worktree-llm-tool-order 2026-07-07 17:01:32 +08:00
packages fix: validate and re-cap all inbound worker-port traffic (Codex round 1) 2026-07-08 11:42:59 +08:00
scripts feat: add the worker-thread code runtime (dsh-code-runtime-worker) 2026-07-08 11:07:14 +08:00
vendor Use explicit ts specifiers for declarations 2026-06-22 06:11:00 +08:00
.gitignore ci: cache eslint lane 2026-07-06 03:07:35 +08:00
AGENTS.md feat: add the worker-thread code runtime (dsh-code-runtime-worker) 2026-07-08 11:07:14 +08:00
CLAUDE.md Initialize repo with README, AGENTS.md, and CLAUDE.md symlink 2026-06-10 22:58:56 +08:00
eslint.config.mjs ci: ignore doc-typecheck temp dirs during lint 2026-07-06 02:04:32 +08:00
knip.json feat: add the worker-thread code runtime (dsh-code-runtime-worker) 2026-07-08 11:07:14 +08:00
lefthook.yml Merge parallel pre-push gates into CI scheduler 2026-07-06 01:47:13 +08:00
LICENSE Initialize repo with README, AGENTS.md, and CLAUDE.md symlink 2026-06-10 22:58:56 +08:00
package.json Merge remote-tracking branch 'origin/master' into worktree-node-22-18-compat 2026-07-07 21:33:40 +08:00
pnpm-lock.yaml feat: add the worker-thread code runtime (dsh-code-runtime-worker) 2026-07-08 11:07:14 +08:00
pnpm-workspace.yaml Reorganize packages into a modular hierarchy 2026-06-20 22:55:20 +08:00
README.i18n.yaml docs: revise graph docs from review 2026-07-05 01:25:58 +08:00
README.md docs: revise graph docs from review 2026-07-05 01:25:58 +08:00
README.zh.md docs: revise graph docs from review 2026-07-05 01:25:58 +08:00
tsconfig.base.json feat: add the code-execution capability seam (ctx.codeRuntime) 2026-07-08 02:17:24 +08:00
tsconfig.build.json feat: add the worker-thread code runtime (dsh-code-runtime-worker) 2026-07-08 11:07:14 +08:00
tsconfig.json feat: add the worker-thread code runtime (dsh-code-runtime-worker) 2026-07-08 11:07:14 +08:00
tsdown.config.ts Merge remote-tracking branch 'origin/master' into feat/adr0016-type-build-check 2026-06-22 00:35:51 +08:00
vitest.config.ts feat: add the worker-thread code runtime (dsh-code-runtime-worker) 2026-07-08 11:07:14 +08:00
vitest.e2e.config.ts Merge parallel pre-push gates into CI scheduler 2026-07-06 01:47:13 +08:00
vitest.snapshot.config.ts feat: one tsconfig.json and different rules 2026-06-19 23:35:47 +08:00

DeepSeek Harness

English | 中文

The DeepSeek Harness SDK is a plugin-based SDK for building agent harnesses.

Development

This monorepo is built on the Cordis framework (vendored as source under vendor/), microkernel-style: everything is a plugin.

pnpm install
pnpm run test          # vitest
pnpm run demo:repl     # REPL agent demo (needs DEEPSEEK_API_KEY)
pnpm run demo:acp      # ACP server agent demo (needs DEEPSEEK_API_KEY)

For humans, start with the development guide for local setup, hooks, environment variables, and quality gates, then read the architecture design and documentation graph index before package work. Local context lives in packages/ and vendor/.

For agents, follow AGENTS.md.