Commit Graph

11538 Commits

Author SHA1 Message Date
Tianyi Cui
5931afaf87 docs(session-persistence): bind raw capability to its reader
The abstract capability flag forces every backend to state whether it owns per-session raw artifacts, but TypeScript cannot express that a true flag requires replacing the concrete unsupported default. Without an implementer-facing obligation, a backend could advertise support and then fail with a contradictory unsupported diagnostic on first use.\n\nDocument the required pairing at the capability declaration. Keep readRaw concrete so backends that correctly report false inherit one fail-loud implementation instead of duplicating rejection code.
2026-08-11 18:10:28 +08:00
Tianyi Cui
b52ddb2887 fix(apiproxy): omit an unresolved compression option
ApiProxyDefaults uses an exact optional property, so passing config.sessionExportCompressionLevel directly made the service object carry an explicit undefined that is not assignable to the resolved request shape. The full host build caught this distinction after the redundant fallback was removed.\n\nConditionally omit the property when Cordis has not supplied a value. Direct createApiProxy callers still receive the implementation-owned default, while configured plugin values pass through without introducing another defaulting site.
2026-08-11 17:59:07 +08:00
Tianyi Cui
544a17f604 Merge origin/master into worktree/pr2177-export-fixes-20260811
Master advanced again after the first merge-forward checkpoint, adding the web human-transcript command-input change. Preserve the earlier checkpoint and merge the new exact e03b51d7 base as a separate commit instead of rebasing or rewriting this merge-heavy stack.\n\nThe incremental merge is conflict-free and keeps the session-export review fixes based on the repository's current integration state.
2026-08-11 17:53:13 +08:00
Tianyi Cui
c10d74ba95 fix(apiproxy): cancel attachment reads during export
Response-consumer cancellation already stopped lineage reads, persistence reads, and ZIP production, but the final attachment phase called readImage without the producer signal. A slow or stalled attachment backend could therefore keep working after the browser abandoned the download and prevent the producer from settling.\n\nExtend the attachment read seam with optional cancellation, forward it through the local backend into Node's filesystem read, and preserve the abort reason rather than wrapping it as a storage failure. The exporter now passes its combined request/consumer signal to every attachment read.\n\nCover both ownership boundaries: the local-store test proves filesystem forwarding and cancellation identity, while the assembled export test cancels a reader during a pending attachment provider call. Regenerate the Cordis API catalog and paired documentation so implementers can rely on the new contract.
2026-08-11 17:52:24 +08:00
Tianyi Cui
5e067fa7fe docs(apiproxy): state the export queue bound exactly
The response stream uses a fixed 64 KiB byte high-water mark; no deployment setting controls it. Calling that queue configured incorrectly suggested another tuning surface and obscured the concrete memory bound.\n\nName the fixed capacity directly while preserving the separate bound of one synchronous fflate push beyond the queued bytes.
2026-08-11 17:47:29 +08:00
Tianyi Cui
8d63728584 fix(apiproxy): name root export preparation failures
The pre-stream error boundary covers both the live-session flush barrier and the persistence read, but its response attributed every failure to reading storage. A flush failure therefore produced a misleading diagnostic even though the response correctly withheld private backend details.\n\nUse preparation as the shared operation name and cover the flush-failure path explicitly. Both preparation stages now retain one stable, path-safe HTTP 500 without pretending to identify the failing stage.
2026-08-11 17:47:13 +08:00
Tianyi Cui
5703ae356e refactor(apiproxy): resolve export compression once
The Cordis schema supplies the normal plugin default, while createApiProxy also owns the fallback required by direct programmatic callers. Repeating the same nullish fallback in ApiProxyService created a third defaulting site without adding a distinct invariant.\n\nPass the validated config value through unchanged and leave createApiProxy as the single implementation boundary that turns an optional request value into the required compression specification.
2026-08-11 17:46:40 +08:00
Tianyi Cui
d1aae98895 docs(connection): describe native export handoff accurately
The fixture comment still said the Trajectory action used window.fetch after the implementation moved to a temporary download anchor. That wording implied client-side response handling and buffering which the browser-download design deliberately avoids.\n\nDescribe the actual native download-manager handoff while retaining the important contract: the fixture download stub only satisfies the host type and is unreachable through fixture dispatch.
2026-08-11 17:46:25 +08:00
Terra
2d2b89825e Merge pull request #1115 from deepseek-harness/codex/gui-goal-user-message
feat(web): show /goal input in the human transcript
2026-08-11 17:43:45 +08:00
Tianyi Cui
c626d5f53c Merge origin/master into worktree/pr2177-export-fixes-20260811
Refresh PR #2258 onto master at 5427cbcc19 so the session-log export fixes are evaluated and mergeable against the current repository.\n\nPreserve master's SDK-toolchain removal, client theme bootstrap, and Python finish-reason changes intact. The only textual overlap is the generated config-catalog pairing record: both English and Chinese catalogs merge cleanly with the PR's compression setting and master's package moves, so regenerate that sidecar from the merged owners instead of choosing either stale hash.
2026-08-11 17:39:19 +08:00
NI0317
d06a7e07e5 feat(web): show command inputs in the human transcript 2026-08-11 17:19:51 +08:00
Tianyi Cui
1d12ae62e7 Merge pull request #2242 from deepseek-harness/worktree/remove-sdk-project-toolchain
Remove the unreleased SDK project toolchain
2026-08-11 17:09:21 +08:00
Tianyi Cui
f9e8375f66 Merge remote-tracking branch 'origin/master' into worktree/remove-sdk-project-toolchain 2026-08-11 17:00:05 +08:00
_Kerman
a661eeeba0 Merge pull request #2257 from deepseek-harness/xtr/python-sdk-finish-reason
fix(python): report run finish reason
2026-08-11 16:56:51 +08:00
Tianyi Cui
4d6dc77a1f Merge remote-tracking branch 'origin/master' into worktree/remove-sdk-project-toolchain 2026-08-11 16:54:34 +08:00
_Kerman
dbbe55fdb1 fix(python): reject malformed finish reasons 2026-08-11 16:48:41 +08:00
imccyu
ea574b5fca Merge pull request #2180 from deepseek-harness/worktree-dark
fix(client): apply theme before plugin loading
2026-08-11 16:41:50 +08:00
Tianyi Cui
175d252f77 chore: remove remaining SDK toolchain residue 2026-08-11 16:37:29 +08:00
_Kerman
6896fd1545 fix(python): report run finish reason 2026-08-11 16:25:59 +08:00
Tianyi Cui
f21977383b Merge remote-tracking branch 'origin/master' into worktree/pr2177-export-fixes-20260811
# Conflicts:
#	docs/config-catalog.i18n.yaml
#	docs/subsystems/persistence.i18n.yaml
#	packages/session/session-persistence-jsonl/README.i18n.yaml
#	packages/session/session-persistence/README.i18n.yaml
2026-08-11 16:18:28 +08:00
Tianyi Cui
af8a8e1384 Merge remote-tracking branch 'origin/master' into worktree/pr2177-export-fixes-20260811
# Conflicts:
#	docs/config-catalog.i18n.yaml
2026-08-11 16:11:30 +08:00
Tianyi Cui
8a2a22db84 fix(apiproxy): configure session export compression
Session-log ZIP entries always used DEFLATE level 6 even though compression level is a deployment tradeoff: CPU-constrained hosts may prefer low latency while bandwidth-constrained hosts may prefer smaller archives. A hardcoded level also violated the repository rule that deployment-varying plugin choices live in validated Config.

Add sessionExportCompressionLevel to ApiProxyService.Config as an integer 0-9 with default 6, resolve the same default once for direct createApiProxy callers, and pass the required level into the streaming module. Tests prove schema defaulting and rejection as well as a level-0 versus level-9 archive-size difference with identical extracted content. The generated config catalog, bilingual gateway README, and feature note document the knob and its tradeoff.
2026-08-11 16:11:09 +08:00
Tianyi Cui
1419671f3f fix(session-export): wait for response pull capacity
The ZIP loop checked desiredSize only after a push and responded to an overfull queue with setTimeout(0). A timer turn does not mean the consumer drained anything, so a slow or disconnected client still allowed the producer to enqueue the complete compressed archive while later artifact and attachment reads ran eagerly.

Give the ReadableStream a 64 KiB byte queuing strategy and block the single producer on a pull-released capacity gate whenever desiredSize is non-positive. Cancellation wakes that gate through the existing producer signal; synchronous fflate output is therefore bounded to the queue high-water mark plus one input push. A regression test exhausts timer turns without consuming and proves the next media entry remains unread until response pulling begins, and the bilingual contracts now describe the real bound.
2026-08-11 16:09:50 +08:00
Tianyi Cui
192840e198 fix(session-export): propagate download cancellation
Only the root raw-artifact read received the request signal. Lineage discovery and descendant reads could continue after disconnect, response-body cancellation did not stop the producer, and the root error boundary converted an abort rejection into an ordinary HTTP 500.

Combine request and response-consumer cancellation into the ZIP producer signal, forward it through every cancellable read, check it around the attachment seam, and terminate fflate exactly once when production stops. The pre-stream boundary now rethrows the original abort instead of translating it. Regression tests cover signal propagation, exact cancellation identity at the HTTP boundary, and a reader cancellation interrupting an in-flight descendant read; the bilingual host contract records these lifecycle semantics.
2026-08-11 16:09:27 +08:00
Tianyi Cui
52f0b09e76 fix(session-export): flush live logs before raw reads
The exporter read persistence artifacts directly even when the requested root or a descendant was still live. Buffered session events could therefore be omitted from a successful download, so the advertised verbatim-artifact guarantee described storage accurately but captured an arbitrarily stale durability boundary.

Resolve each id against SessionStore and cross its authoritative flush barrier immediately before readRaw. Cold sessions remain a no-op, while live roots and descendants are made durable independently; this intentionally yields a per-session read-boundary snapshot rather than claiming an atomic lineage snapshot. A host-path regression test proves both artifacts change from stale to durable only through flush, and the bilingual host contract and Agent Note document the boundary.
2026-08-11 16:08:47 +08:00
Tianyi Cui
454e06c8c1 Merge origin/master into worktree/remove-sdk-project-toolchain
# Conflicts:
#	.agents/notes/implemented/architecture/2026-07-10-single-file-executable-sdk-runtime-distribution.i18n.yaml
#	.agents/notes/implemented/architecture/2026-07-10-single-file-executable-sdk-runtime-distribution.md
#	.agents/notes/implemented/feature/2026-07-21-continuable-background-subagents.i18n.yaml
#	.agents/notes/implemented/feature/2026-07-21-continuable-background-subagents.md
#	.agents/notes/implemented/feature/2026-07-21-continuable-background-subagents.zh.md
#	.agents/notes/proposed/architecture/2026-07-15-sdk-project-editing-architecture.i18n.yaml
#	.agents/notes/proposed/architecture/2026-07-15-sdk-project-editing-architecture.md
#	.agents/notes/proposed/feature/2026-07-14-sdk-developer-projects.i18n.yaml
#	.agents/notes/proposed/feature/2026-07-14-sdk-developer-projects.md
#	.agents/notes/proposed/feature/2026-07-14-sdk-developer-projects.zh.md
#	packages/README.i18n.yaml
#	packages/README.md
#	packages/scaffold/create-sdk/README.md
#	packages/scaffold/create-sdk/src/args.ts
#	packages/scaffold/scripts/src/args.ts
#	packages/sdk/README.i18n.yaml
#	scripts/verify-package-readme-model-experience.ts
2026-08-11 15:56:06 +08:00
imccyu
f0a6c25291 fix(client): apply theme before plugin loading 2026-08-11 15:35:32 +08:00
Turtle
5d591e55c1 Merge pull request #610 from deepseek-harness/codex/replace-surface-terminology
Replace overloaded surface terminology
2026-08-11 15:34:34 +08:00
Yichen Jiang
9c06f682c4 Merge pull request #2207 from deepseek-harness/worktree/custom-provider-edit-parity-f8c160
fix(web): 自定义提供方的显示名称与 API 协议可编辑
2026-08-11 15:33:50 +08:00
Tianyi Cui
c1590faac7 Merge origin/master into worktree/remove-sdk-project-toolchain 2026-08-11 15:23:42 +08:00
Turtle
096586886a fix(review): address terminology feedback 2026-08-11 15:23:05 +08:00
Turtle
c6f3870b51 test: refresh terminology snapshots 2026-08-11 15:23:05 +08:00
Turtle
0c708cb10d refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
Yichen Jiang
63a294fa1b Merge remote-tracking branch 'origin/master' into worktree/custom-provider-edit-parity-f8c160 2026-08-11 15:16:23 +08:00
hypatiamay
c172faed37 Merge pull request #1836 from deepseek-harness/feat/subagent-list-agents-vocabulary
fix(subagent): report resumable children as ready
2026-08-11 15:15:15 +08:00
Tianyi Cui
5f947e1d94 Merge origin/master into worktree/remove-sdk-project-toolchain
# Conflicts:
#	THIRD_PARTY_NOTICES.md
2026-08-11 15:08:18 +08:00
Tianyi Cui
904c3f2c35 fix(session-persistence-jsonl): reject empty zstd artifacts
A present zero-byte .jsonl.zstd file was treated as though no artifact existed because readRaw returned undefined when frame scanning found nothing. That contradicted both the plaintext path and the logical zstd reader, and it made the export endpoint answer 404 for on-disk corruption.

Treat a present artifact without a complete header frame as corruption and reuse the zstd reader's existing diagnostic. The regression test now distinguishes an existing empty file from an absent path, and the bilingual JSONL storage contract records that zero-frame artifacts reject alongside other header and frame failures.
2026-08-11 15:05:54 +08:00
Tianyi Cui
e58cc13de4 fix(session-export): distinguish unsupported raw artifacts
SessionPersistence.readRaw previously used undefined for two unrelated states: a supported backend could not find the requested session, or the backend had no per-session artifact concept at all. The export endpoint consequently reported an existing SQLite-backed session as HTTP 404, which falsely diagnosed storage capability as session absence.

Make raw-artifact support an explicit backend capability. Unsupported backends now fail their inherited readRaw path loudly and the host answers 501 before reading, while undefined retains the single meaning of an absent artifact on a supporting backend. First-party backends, test providers, generated API catalogs, bilingual persistence docs, and export error contracts now state that distinction; focused tests cover both the 501 and the inherited rejection.
2026-08-11 15:04:35 +08:00
Hypatia May
6e94bfd366 Merge branch 'feat/subagent-settlement-delivery' into feat/subagent-list-agents-vocabulary 2026-08-11 14:59:18 +08:00
Hypatia May
9f4159d0be Merge branch 'feat/subagent-report-semantics' into feat/subagent-settlement-delivery 2026-08-11 14:59:00 +08:00
Hypatia May
3f9c7077f9 Merge commit '5e1b3dd6536cbf4796164e7676e13c68300bb52d' into feat/subagent-report-semantics 2026-08-11 14:58:58 +08:00
_Kerman
b6cd817aca Merge pull request #2131 from deepseek-harness/fix/web-favicon-dark-mode
fix(web): make the favicon follow the color scheme
2026-08-11 14:58:43 +08:00
Tianyi Cui
7f14c7e165 refactor(web): hand session exports to browser downloads
The export endpoint already streams a ZIP response, but the web client immediately converted that response into a Blob. That forced the complete archive through JavaScript memory before a download could start and coupled transport, buffering, object-URL lifetime, and filename handling to the trajectory view.

Navigate a temporary download anchor directly to the export endpoint instead. The browser now owns streaming and HTTP failure presentation, while a standalone delivery module owns URL construction and filename sanitization. Focused tests cover the handoff, rejection behavior, and the assembled session view; the package README and feature note record the new ownership boundary.
2026-08-11 14:57:38 +08:00
Tianyi Cui
e063fc1a89 Merge pull request #2162 from deepseek-harness/worktree/windows-acl-hardening-followup
fix(sandbox): keep Windows ACL temp authority session-private
2026-08-11 14:57:22 +08:00
Hypatia May
6a604aaa85 Merge branch 'feat/subagent-settlement-delivery' into feat/subagent-list-agents-vocabulary 2026-08-11 14:53:11 +08:00
Hypatia May
ef8637f864 Merge branch 'feat/subagent-report-semantics' into feat/subagent-settlement-delivery
# Conflicts:
#	docs/event-producer-consumer.i18n.yaml
#	docs/event-producer-consumer.md
2026-08-11 14:52:49 +08:00
Hypatia May
fafb10eecb Merge commit '38d82c497765ce0344800e3d5af9f1ee073f4bb5' into feat/subagent-report-semantics 2026-08-11 14:50:35 +08:00
Chinesezjc
b7ea33ecde Merge pull request #2202 from deepseek-harness/ci/selfhosted-windows-runners
ci: unify Windows CI on native self-hosted runners
2026-08-11 14:49:48 +08:00
Hypatia May
6c4ed5e036 test(snapshot): refresh pins after master merge 2026-08-11 14:45:14 +08:00
Tianyi Cui
a8db48429a Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-11 14:43:23 +08:00