mirror of
https://github.com/deepseek-ai/deepseek-harness
synced 2026-08-15 21:04:50 +00:00
Apply the accepted pre-release package, service, type, directory, and role renames as one repository-wide change.
193 lines
7.6 KiB
YAML
193 lines
7.6 KiB
YAML
# ACP automation server and backend snapshot-record composition. With
|
|
# `DSH_SNAPSHOT=record`, the app bin runs the real DeepSeek adapter and the
|
|
# harness harvests its persisted log. The bin loads the gitignored root `.env`
|
|
# before this config. This tree has no stdout logger or HMR because stdout
|
|
# carries ACP JSON-RPC.
|
|
|
|
# The DeepSeek adapter. Shipped default: full thinking at max effort on every
|
|
# request; exact-model resolution materializes request defaults before logging.
|
|
- id: llm-deepseek
|
|
name: '@deepseek-ai/dsh-llm-deepseek'
|
|
config:
|
|
thinking: enabled
|
|
reasoningEffort: max
|
|
models:
|
|
- id: deepseek-v4-flash
|
|
- id: deepseek-v4-pro
|
|
|
|
# The default composition confines bash AND the filesystem tools to the
|
|
# workspace and asks before a wider retry. Snapshot runs select
|
|
# danger-full-access so the established scenarios remain runner-independent;
|
|
# DSH_PERMISSION_MODE provides the same explicit deployment/test override
|
|
# outside the snapshot harness. The sandbox default + fallback root live on
|
|
# ctx.sandboxPolicy; agent calls resolve both families against the session cwd.
|
|
- id: sandbox
|
|
name: '@deepseek-ai/dsh-sandbox-local'
|
|
|
|
- id: sandbox-policy
|
|
name: '@deepseek-ai/dsh-sandbox-policy'
|
|
config:
|
|
mode: !!js "process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')"
|
|
workspaceRoot: !!js process.cwd()
|
|
|
|
# Managed child-process groups for the bash executor (spawn/kill/output plumbing).
|
|
- id: subprocess
|
|
name: '@deepseek-ai/dsh-subprocess-local'
|
|
|
|
- id: bash
|
|
name: '@deepseek-ai/dsh-bash-sandbox'
|
|
config:
|
|
timeoutMs: 60000
|
|
|
|
- id: approval
|
|
name: '@deepseek-ai/dsh-user-approval'
|
|
config:
|
|
policy: !!js "(process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')) === 'danger-full-access' ? 'never' : 'ask'"
|
|
|
|
# The ACP automation app: agent spine + JSONL persistence + protocol bridge.
|
|
# Persistence root: $DSH_SNAPSHOT_SESSIONS_ROOT when the snapshot harness sets it
|
|
# (so it can harvest / isolate the log), else ./.sessions for the demo.
|
|
# Snapshot modes use raw JSONL fixtures; ordinary runs keep the compressed default.
|
|
- id: acp-agent
|
|
name: '@deepseek-ai/dsh-acp-demo'
|
|
config:
|
|
provider: deepseek-official
|
|
model: deepseek-v4-pro
|
|
persistenceRoot: !!js process.env.DSH_SNAPSHOT_SESSIONS_ROOT ?? './.sessions'
|
|
persistenceCompression: !!js "process.env.DSH_SNAPSHOT === undefined ? 'zstd' : 'none'"
|
|
workspaceContext:
|
|
maxBytes: 65536
|
|
# Keep the persona to identity and behavior; tool plugins own tool guidance.
|
|
# The loop resolves {{model}} and each ACP session's client-supplied {{cwd}}.
|
|
persona: |
|
|
You are a coding assistant powered by the {{model}} model. Your working directory is {{cwd}}. Your bash tool runs under a file sandbox — a `[sandbox: file access denied …]` result is policy, not a command bug.
|
|
|
|
Verify your work by running the code or tests. Keep answers brief and factual.
|
|
|
|
# Replay-aware request pressure; the routed adapter supplies model capacity.
|
|
- id: token-meter
|
|
name: '@deepseek-ai/dsh-token-meter'
|
|
|
|
# Summarize an older range after measured pressure or a canonical provider overflow.
|
|
# Ratios scale against the routed model's context window.
|
|
- id: compaction-basic
|
|
name: '@deepseek-ai/dsh-compaction-basic'
|
|
config:
|
|
thresholdRatio: 0.8
|
|
retainRatio: 0.08
|
|
maxTokens: 8192
|
|
compactionRetries: 1
|
|
|
|
# Projection registry: subagent catalog identity (mode/label) folds through
|
|
# its registered units; the catalog surfaces (`list_agents`, subagent listing)
|
|
# fail loud without the capability.
|
|
- id: session-projection
|
|
name: '@deepseek-ai/dsh-session-projection'
|
|
|
|
# Expose fresh-child `spawn` and completed-prefix `fork` through separate tool
|
|
# names so multi-child scenarios exercise both transports. These leaves follow
|
|
# the app because it provides `ctx.agents` and `ctx.tools`.
|
|
- id: subagent
|
|
name: '@deepseek-ai/dsh-subagent'
|
|
|
|
- id: subagent-spawn-in-process
|
|
name: '@deepseek-ai/dsh-subagent-spawn-in-process'
|
|
config:
|
|
providerName: spawn
|
|
|
|
- id: subagent-fork-in-process
|
|
name: '@deepseek-ai/dsh-subagent-fork-in-process'
|
|
config:
|
|
providerName: fork
|
|
|
|
# Continuable background children are selected per delegation tool. The
|
|
# separately loaded control package registers the global `send_message`; its
|
|
# list plugin registers `list_agents`, served through the sessionProjections
|
|
# registry mounted above. `report` is installed only in continuable child scopes.
|
|
- id: tool-subagent-control
|
|
name: '@deepseek-ai/dsh-tool-subagent-control'
|
|
|
|
- id: tool-subagent-list-agents
|
|
name: '@deepseek-ai/dsh-tool-subagent-control/list-agents'
|
|
|
|
- id: tool-subagent-report
|
|
name: '@deepseek-ai/dsh-tool-subagent-report'
|
|
|
|
- id: tool-subagent
|
|
name: '@deepseek-ai/dsh-tool-subagent'
|
|
config:
|
|
provider: spawn
|
|
toolName: subagent
|
|
backgroundMode: continuable
|
|
maxDepth: 1
|
|
|
|
# Fork stays one-shot because a continuable child's `report` tool and prompt
|
|
# section precede the inherited history a fork reuses; `run_in_background` is off
|
|
# because this example mounts no task service. See .agents/notes/implemented/architecture/2026-08-10-fork-children-stay-one-shot.md.
|
|
- id: tool-subagent-fork
|
|
name: '@deepseek-ai/dsh-tool-subagent'
|
|
config:
|
|
provider: fork
|
|
toolName: subagent_fork
|
|
backgroundMode: one-shot
|
|
enableRunInBackground: false
|
|
maxDepth: 1
|
|
|
|
|
|
# The worker-thread workflow engine fans a model-written JavaScript script's
|
|
# `agent()` calls out through the spawn backend; the adjacent tool exposes it to the model.
|
|
- id: workflow-worker-thread
|
|
name: '@deepseek-ai/dsh-workflow-worker-thread'
|
|
config:
|
|
provider: spawn
|
|
|
|
- id: tool-workflow
|
|
name: '@deepseek-ai/dsh-tool-workflow'
|
|
|
|
- id: tool-ralph
|
|
name: '@deepseek-ai/dsh-tool-ralph'
|
|
# `todo_write` replaces the logged whole list for later model requests.
|
|
- id: tool-todo
|
|
name: '@deepseek-ai/dsh-tool-todo'
|
|
config:
|
|
allowParallelInProgress: true
|
|
|
|
# Identical repeat calls trigger advisory context, never a block, at the default
|
|
# thresholds [3, 5, 8]. Only the repeat-tool-reminder snapshot scenario reaches them.
|
|
- id: repeat-tool-reminder
|
|
name: '@deepseek-ai/dsh-repeat-tool-reminder'
|
|
|
|
# The filesystem stack rides the SAME sandbox policy as bash: dsh-fs-sandbox
|
|
# replaces dsh-fs-local behind ctx.fs and fences write/edit by the effective
|
|
# mode (read-only denies, workspace-write contains to the workspace + temp
|
|
# roots, danger-full-access passes through), so read/write/edit are available
|
|
# under every mode. fs-observation-policy (read-before-edit) composes orthogonally on top.
|
|
- id: fs-sandbox
|
|
name: '@deepseek-ai/dsh-fs-sandbox'
|
|
config:
|
|
cwd: !!js process.cwd()
|
|
|
|
- id: fs-observation-policy
|
|
name: '@deepseek-ai/dsh-fs-observation-policy'
|
|
|
|
- id: tool-fs
|
|
name: '@deepseek-ai/dsh-tool-fs'
|
|
|
|
# `configPath` is read once at load and resolves from the server launch cwd, not
|
|
# `session/new.cwd`; one `hooks.json` therefore applies to every session and a
|
|
# project-local file is not discovered. Missing config registers nothing. Hook
|
|
# commands still run in the session cwd. Warnings use `ctx.logger`, never stdout;
|
|
# see packages/hooks/hooks-claude-code/README.md for the deferred per-session design.
|
|
- id: hooks-claude-code
|
|
name: '@deepseek-ai/dsh-hooks-claude-code'
|
|
config:
|
|
configPath: ./hooks.json
|
|
|
|
# Codex uses its own `codex-hooks.json` and snake_case five-event dialect; it
|
|
# cannot share Claude's file. It has the same process-level, read-once, missing-is-no-op,
|
|
# logger-only contract. Shipping both bridges lets a scenario seed and exercise either dialect.
|
|
- id: hooks-codex
|
|
name: '@deepseek-ai/dsh-hooks-codex'
|
|
config:
|
|
configPath: ./codex-hooks.json
|