Files
deepseek-harness/packages/core
Yichen Jiang 43f3324a7b fix(tools): restrict what a scope inherits, not just the global layer
A restriction was compiled against the global tool layer alone: only
global-layer tools were tested against `admits()`, and every chain-layer
tool was overlaid unfiltered afterward. That read the exempt set as "the
global layer" when what it means is "what this scope registers itself" —
two descriptions of the same set only while every model-facing tool sat in
the host composition.

Moving those rows onto the agent plane separated them. A preset's tools are
an ANCESTOR contribution to a joined agent, so a subagent's `toolFilter`
stopped constraining anything it was given; and with the global layer empty
`restrict()` rejected every name it received as unknown, failing the child
outright. With the same tools in the global layer the filter still admits
and applies normally, which is what makes this a regression of the move
rather than a standing limitation.

`view()` now filters everything a scope inherits — the global layer and
every ancestor layer on its chain — and exempts only the layer the scope
owns. That exemption is load-bearing rather than incidental: the delegation
runtime registers a child's `report` and structured-output tools into the
child's own layer, and a filter naming the capabilities the child may use
must not strip the machinery it answers through. Tool order, and with it
prefix-cache reuse, is unchanged: inherited names keep their global-then-
ancestor position and own-layer names still come last.

The diagnostic said "unknown global tool" while listing what is really the
inherited surface; it now names the surface it checks and says why an
own-layer name is not restrictable.

Fixes #2185
2026-08-10 20:34:45 +08:00
..
2026-08-10 13:07:46 +08:00

core/ — product API spine

English | 中文

The session log, system-prompt assembly, tool registry, agent vocabulary, deployment-default model selection, and concrete loop that form the harness's default control spine. These are product packages — the stable surface plugins and consumers build against.

Package Role ctx key
scope/ Scoped-context registration primitive library — no ctx key
session/ Event-sourced session log and in-memory store ctx.sessions
system-prompt/ Prompt and tool-schema assembly registry ctx.systemPrompt
tools/ Scoped tool registry and execution pipeline ctx.tools
agent/ Agent interface, registry, and event vocabulary ctx.agents
agent-default-model/ Default model selection shared by Agent entry points ctx.agentDefaultModel
agent-loop/ Default concrete agent driver ctx.agentLoop

scope supplies the shared scoping primitive. agent owns the public contract, while agent-loop is its default implementation; extension plugins depend on the seam so the driver remains swappable. agent-default-model owns the deployment selection an Agent entry point uses only when a session has no selection of its own.

Runnable compositions belong to examples/agent-spine-demo; this group owns only the swappable spine pieces.

The subsystem reference — the package-by-package loop map, the Agent handle and its delivery/interception contracts — is docs/subsystems/core.md; the default runnable composition is examples/agent-spine-demo.