Commit Graph

9398 Commits

Author SHA1 Message Date
Yichen Jiang
a90ccc4453 revert(sandbox): withdraw the credential-document read denial
The `readDenyPaths` policy field shipped in the previous commit broke Linux
confinement outright. bwrap has to create the `/dev/null` bind's mount point
inside a tree its own profile has already made read-only, so it refused the
entire confinement whenever the parent directory was absent — every host that
has not stored a credential yet, including a fresh install:

  bwrap: Can't mkdir parents for /home/runner/.dsh/.env: Read-only file system

which the executor correctly classifies as SANDBOX_UNAVAILABLE, so every
confined bash call failed closed. Landlock cannot subtract from its own `/`
read grant, so it reported `partial` enforcement on every confined call for a
file it never hid, with no way to switch the denial off (schemastery fills an
omitted array with `[]`, so empty and omitted were indistinguishable).

A protection that breaks confinement where it works and misreports it where it
does not is worse than a documented absence. Revert the field, both expressible
backends, the enforcement downgrade, and the policy default; state the residue
plainly in the credentials-local READMEs — file mode stops other OS users, not
the model — and keep the OS-keychain provider recorded as the real answer.

The narrower discipline stands: no surface hoists the credential document into
`process.env`, and the model is never handed a resolved path to it.
2026-07-30 17:09:42 +08:00
Yichen Jiang
52ae578982 test(tui): pin the personal overlay to the environment layers the CLI loads
The personal-config smoke asserted that `$DSH_HOME/.env` feeds a `!!js`
expression in the personal `config.yaml` — the hoist this branch removed so
`credentials-local` can own that document and keep stored keys rotatable.

Seed both layers instead and let one expression separate them: the welcome
prefers the personal variable, so it can only render the invoking directory's
value while the harness home's `.env` stays out of `process.env`. The negative
that made the removal worth doing is now asserted in the assembled
application, not just in the provider's unit tests.
2026-07-30 17:09:29 +08:00
Tianyi Cui
abd7d57358 Merge branch 'master' into feature/shared-cli-config-foundation 2026-07-30 17:08:42 +08:00
ZiyaZhang
61803f1a46 fix(ui-workspace): expose session status accessibly 2026-07-30 02:07:36 -07:00
Tianyi Cui
07e3d15d42 docs(settings): mark deferred review follow-ups 2026-07-30 17:07:29 +08:00
imccyu
6686f47945 Merge pull request #883 from deepseek-harness/feat/ask-question-gui
feat(web): answerable ask_user_question flow & workspace tooltips & hero layout & plan button
2026-07-30 17:07:18 +08:00
creatixchu
893a1a8d51 Merge remote-tracking branch 'origin/feat/directory-picker-show-hidden' into feat/directory-picker-quiet-navigation 2026-07-30 17:06:07 +08:00
Chinesezjc
ba0757223d feat(web): add a web render-intent card for web_search and web_fetch results
web_search and web_fetch returned only model-facing text, whose markdown source
list is lossy (title-or-hostname label, snippet and date concatenated), so a
client could not recover the structured sources. Add a card:'web' result view
with a kind discriminant ('search' carrying structured sources + answer +
truncated, 'fetch' carrying url + statusCode + truncated), projected through
each tool's output.presentationMeta and read back in presentResult. A UI
without the web card falls back to content; the TUI is unchanged. The web
consumer is a follow-up.
2026-07-30 17:04:09 +08:00
Chinesezjc
3e22adab28 feat(fs): add a search render-intent card for grep and glob results
grep and glob returned only model-facing text; the structured matches/paths
never reached the client. Add a card:'search' result view with a kind
discriminant ('matches' grouped by file for grep, 'paths' for glob), projected
through each tool's output.presentationMeta and read back in presentResult. The
projections re-apply the same inline cap and per-line budget as the render text
and report total + truncated, so a UI never presents a capped page as complete.
A UI without the search card falls back to content; the TUI is unchanged. The
web consumer is a follow-up.
2026-07-30 17:03:54 +08:00
Chinesezjc
eb4cc8efc5 feat(fs): add a read render-intent card for the read tool result
The read tool's result carries structured numbered lines, but only the
model-facing envelope text reached the client. Add a card:'read' result view
(ReadResultView) projecting {path, lines, totalLines, lang} through the tool's
output.presentationMeta so presentResult reproduces it on live and replay
paths; the pending call stays a generic read card. A UI without the read
capability falls back to the envelope-stripped content, so the TUI is
unchanged. The web consumer that renders the line-numbered view is a follow-up.
2026-07-30 17:03:05 +08:00
creatixchu
3809795fd5 Merge remote-tracking branch 'origin/master' into feat/directory-picker-show-hidden 2026-07-30 17:02:33 +08:00
_Kerman
997932ffd6 feat(ui): refine trajectory timeline interaction 2026-07-30 17:00:58 +08:00
ZiyaZhang
01ff68636a Merge remote-tracking branch 'upstream/master' into fix/session-waiting-approval 2026-07-30 01:57:54 -07:00
imccyu
34d5f8f2e2 Merge branch 'master' into feat/ask-question-gui 2026-07-30 16:55:54 +08:00
imccyu
f87692a5c3 test(web): anchor the group section above the HoverCard wrapper
The workspace header row is now wrapped by its HoverCard anchor span
(0b4a6196f), so the row's immediate parent no longer holds the session
subtree; the delete scenario anchors on the groupSection ancestor
instead. The flat-view and dwell failures were downstream of this one
(shared page state).
2026-07-30 16:54:43 +08:00
Turtle
3c620a0cb6 Merge remote-tracking branch 'origin/master' into feature/shared-cli-config-foundation
# Conflicts:
#	docs/cordis-catalog/services.md
#	packages/host/apiproxy/README.i18n.yaml
2026-07-30 16:53:55 +08:00
Turtle
7bcf5e3fb0 feat(cli): enable Node environment proxy in launcher 2026-07-30 16:53:35 +08:00
Turtle
9c5a515501 fix(example): drop the never-activated bash stack from the inheritance fixture
dsh-bash-local injects `subprocess`, which this tree never mounted, so the bash
chain sat PENDING and the bundle's tool-bash waited with it. The shared boot()
all-ACTIVE assertion now surfaces that as a load failure.

The scenario probes filesystem confinement only, so the rows are removed and the
bundle opts out with `toolBash: false`. The recorded transcript is unchanged
because bash never reached the model.
2026-07-30 16:52:14 +08:00
Tianyi Cui
b987ec664a Merge pull request #941 from deepseek-harness/feat/session-inherited-boundary
feat(session): add the end-seed log boundary
2026-07-30 16:51:20 +08:00
_Kerman
a6baddaaac refactor: remove per-followup result attribution 2026-07-30 16:48:28 +08:00
NI0317
4d3e324467 docs: preserve established README voice 2026-07-30 16:47:27 +08:00
imccyu
34c124585a fix: test 2026-07-30 16:46:50 +08:00
Chinesezjc
d7e46bea35 test(web): update chat-apply keyed-entry assertion for the file-mutation rows
The diff card registers edit and write into the keyed toolview hole, so the
mounted-entry set is now ['bash', 'edit', 'write', 'todo_write'].
2026-07-30 16:45:00 +08:00
Hypatia May
86b95a3856 Merge PR #941 dependency into manual compaction stack
# Conflicts:
#	docs/cordis-catalog/services.md
#	docs/core-data-structures/session.i18n.yaml
#	packages/host/apiproxy/README.i18n.yaml
#	packages/host/apiproxy/src/api-proxy.ts
#	packages/ui/tui/src/index.ts
2026-07-30 16:42:24 +08:00
kingwl
0a25c0d237 feat(web): add queue collapse control 2026-07-30 16:41:55 +08:00
Yichen Jiang
8707f324c6 refactor(ui-models): render the curated fields from a narrowed adapter family
The effort field's existence check was unreachable — EFFORT_FIELD is
total over the two known families — and a coverage exemption was papering
over the branch, which the merged toolchain no longer honored. Taking the
narrowed family as a parameter makes the lookup total at the type level,
so the check and its exemption both disappear. The rendered output is
unchanged: the browser goldens replay byte-identical.
2026-07-30 16:41:44 +08:00
Yichen Jiang
e7894f4152 docs(credentials): record the third-review contracts across READMEs, catalogs, and a new Agent Note
Both provider READMEs state what actually holds: credentials-local now
documents the physical-line editor, the read-modify-write under the
writer lock, and a Security boundary section saying plainly that the file
mode stops other OS users and not the model. sandbox-policy documents
readDenyPaths and its per-backend enforcement. The llm READMEs carry the
registration handle, pi-ai's credential-miss semantics, and DeepSeek's
same-generation snapshot; app-boot and the CLI README stop describing
$DSH_HOME/.env as an environment layer.

A new Agent Note records the round (and the prior seam note cross-links
it); the sandbox and core catalog pages gain readDenyPaths and
AdapterRegistrationHandle with their manifest entries. The headless
missing-credential snapshot re-records for the reworded guidance, pi-ai
gains the Loader-composition guard its twin already had, and the
deliberate provider symmetry is marked for the clone detector.
2026-07-30 16:37:28 +08:00
Hypatia May
3b3d5579cb Merge remote-tracking branch 'origin/fix/human-transcript-projection' into fix/web-transcript-projection
# Conflicts:
#	apps/web/tests/snapshots/seeded-history/ui.expected.md
#	packages/client/runtime/README.i18n.yaml
#	packages/client/runtime/README.md
#	packages/client/runtime/src/client/index.ts
#	packages/client/runtime/src/client/sessions/fold-adapter.ts
#	packages/client/runtime/tests/fold-adapter.spec.ts
#	packages/client/ui-trajectory/src/client/layout.ts
#	packages/client/ui-trajectory/src/client/spans.ts
#	packages/compact/compact/README.i18n.yaml
2026-07-30 16:37:22 +08:00
Tianyi Cui
9e679c89b6 Merge branch 'master' into feat/session-inherited-boundary 2026-07-30 16:30:42 +08:00
kingwl
d7641ec028 Merge origin/master into codex/figma-context-injection-row 2026-07-30 16:20:47 +08:00
kingwl
17893c503e feat(web): match context injection disclosure design 2026-07-30 16:20:34 +08:00
creatixchu
bfbab9d2ab Merge remote-tracking branch 'origin/feat/directory-picker-quiet-navigation' into feat/dir-selector-adaptive-default
# Conflicts:
#	.agents/notes/implemented/architecture/2026-07-28-directory-picker-capability-seam.i18n.yaml
2026-07-30 16:20:22 +08:00
creatixchu
6bf2661640 Merge remote-tracking branch 'origin/feat/directory-picker-show-hidden' into feat/directory-picker-quiet-navigation 2026-07-30 16:16:09 +08:00
ZiyaZhang
7401587ac2 fix(ui-workspace): show approval-waiting sessions 2026-07-30 01:12:48 -07:00
creatixchu
380b215287 Merge remote-tracking branch 'origin/master' into feat/directory-picker-show-hidden 2026-07-30 16:12:35 +08:00
Chinesezjc
d2582b8dc1 feat(web): render write/edit tool output as a diff card
The write/edit tools already declare card:'diff' with applied hunks on
callView/resultView, but the Web client discarded it: a mutation landed on
GenericToolCard and the details panel flattened the result to a <pre>. Add
DiffBlock (ui-primitives), diff-card-model (the single callView/resultView
derivation), and FileMutationRow (keyed under write and edit), and make the
generic fallback row and the details panel diff-aware. The +/- block form,
per-file path header, same-file gap, and footer mirror the TUI diff card;
the chat row caps at CHAT_DIFF_MAX_LINES against the panel's full height.
2026-07-30 16:11:59 +08:00
Turtle
674c25a6a2 Merge remote-tracking branch 'origin/master' into feature/shared-cli-config-foundation
# Conflicts:
#	docs/tool-catalog.md
#	examples/package.json
#	packages/examples/agent-spine-demo/README.i18n.yaml
#	packages/examples/agent-spine-demo/README.zh.md
#	pnpm-lock.yaml
2026-07-30 16:11:21 +08:00
Yichen Jiang
9626c15c6b test(sandbox): carry the resolved read denials through consumer policy assertions
The policy home's resolve() now stamps readDenyPaths, so every consumer
that pins the resolved shape (bash-sandbox hand-off, tool-fs stamps)
carries it, and three uncovered branches gained real tests: landlock
reporting partial enforcement for a denial it cannot express, the
policy's default under programmatic construction, and both ambient
credential paths in llm-deepseek without a mounted seam.
2026-07-30 16:11:21 +08:00
NI0317
254ead9871 docs: add candid preview note 2026-07-30 16:10:35 +08:00
Yichen Jiang
7606a99813 feat(sandbox): deny confined executions read access to the credential document
The credential store is 0600 under a 0700 directory, which stops other OS
users but not the model: tool processes run as the same user, so under
the shipped danger-full-access default they read it like any other file.

SandboxExecutionPolicy grows readDenyPaths, and sandbox-policy defaults
it to $DSH_HOME/.env — the exact file rather than the harness home, so
the model keeps its documented access to its own session log. Seatbelt
appends a trailing deny (last matching rule wins) and bwrap maps
/dev/null over each path after any workspace bind; Landlock grants are a
pure allow-list that cannot subtract from its own / read grant, so
confine() reports partial enforcement there instead of claiming a
boundary the process does not have.

A real-kernel Seatbelt e2e proves the shape: the same read succeeds
unconfined and fails under the denial, while a sibling file in the same
directory stays readable. Both READMEs state the residual boundary
plainly — no confining mode means no boundary — and record the OS
keychain provider as the real answer.
2026-07-30 16:02:13 +08:00
NI0317
96540c3242 Merge origin/master into codex/sandbox-policy-context 2026-07-30 15:53:48 +08:00
_Kerman
f6db60b52c Merge remote-tracking branch 'origin/master' into xtr/react-loop-simplification 2026-07-30 15:53:46 +08:00
Hypatia May
07760e577a Merge origin/master into codex/status-bar-token-metrics 2026-07-30 15:53:06 +08:00
imccyu
f88d324f01 Merge branch 'master' into codex/details-default-closed 2026-07-30 15:53:01 +08:00
Yichen Jiang
d91f0227e6 fix(settings): keep installSettingsSection quiet when its consumer unloads
The helper's cleanup ran the same fallback for two different events. A
settings provider detaching leaves the consumer running, so falling back
to the composition entry and re-judging derived facts is right. The
consumer's own unload ran it too — re-registering routes and touching
resources the teardown was releasing. The disposer now checks the
consumer fiber's own state and returns when it is unloading or disposed.
2026-07-30 15:52:51 +08:00
NI0317
4ee2b61dbc Merge remote-tracking branch 'origin/master' into feature/readme-current-capabilities 2026-07-30 15:52:28 +08:00
NI0317
544d3f8267 docs: refresh root README for current capabilities 2026-07-30 15:52:20 +08:00
Hypatia May
8fdd01e4ae Merge remote-tracking branch 'origin/master' into fix/human-transcript-projection 2026-07-30 15:52:09 +08:00
Yichen Jiang
54f95d7669 fix(llm): atomic route replacement, whole-snapshot requests, and loud credential misses
Four review findings across the seam and both adapters.

registerAdapter now returns a handle carrying replace(providers): the
candidate route set is validated in full before anything moves, so a
route another adapter owns leaves the previous registration intact, and
the swap itself is one synchronous section with no observable gap. pi-ai
uses it instead of dispose-then-register — the old shape dropped every
route when the new set conflicted, and its facts cache could then equal
the registry's, so reverting to a working configuration never re-applied.
Its registration facts are also sorted by provider, so a settings
document that merely reorders keys no longer triggers a swap.

DeepSeek's per-request snapshot now carries the credential facts, and
resolveApiKey receives it instead of re-reading the raw config: a
settings generation the resolver rejects can no longer contribute its
literal key to a request the previous generation's endpoint serves.

pi-ai only defers to the SDK's provider-native discovery when a profile
names no credential at all; a configured apiKeyEnv that misses now fails
with MISSING_CREDENTIAL naming the route and the reference, instead of
handing pi-ai undefined and letting it authenticate with an unrelated
ambient key.

The eager boot-time credential probe is gone: it could run before the
credentials service mounted and reported every failure as a missing key.
The route stays registered and browsable; the first request gives the
accurate error, whose guidance now leads with the credential store and
mentions a literal apiKey last.
2026-07-30 15:51:35 +08:00
NI0317
4a72beacf2 test(web): keep policy acceptance portable 2026-07-30 15:51:03 +08:00