Four values complete the vocabulary, so the opaque body is reached only by producers that genuinely promise no shape. `snapshot` — current state a later snapshot supersedes. system-prompt now exposes `renderContextSections()`, the named contributions `renderContextSnapshot()` already joins for the model, so the body attributes each part to the subsystem that produced it instead of re-splitting joined prose. The runtime snapshot, time-context, and tmux-context declare it. `notice` — a one-off account of what just happened, declared by tool-tasks, goal state changes, tool-goal wrap-up, plan-mode switches, and repeat-tool-guard. Its `summary` rides the COLLAPSED row: these five are the majority of shipped producers and none of them needs expanding to be read. The task summary bounds itself because its inputs are unbounded caller text. `relay` — a message another agent addressed to this one; both subagent sources declare it and the body names the sender above what it said. `recall` — material lifted from another session's log. session-reference needed no new field: its references already record retained and omitted counts and the truncation flag, which the body shows first, because recalled context is bounded on the way in. `ContextFormed` is now discriminated by `form`, so a producer cannot declare a shape without the facts that shape is presented from — a notice without its summary, or a snapshot without its sections, fails to compile. Only the two hook bridges stay opaque, by design: their content is whatever an external program printed, so no shape can be promised for it. Unknown kinds and unreadable records land there too.
jsonrpc-agent
English | 中文
The unattended coding-agent composition for the Python SDK's bundled JSON-RPC runtime. It intentionally loads no terminal UI, console logger, approval surface, or user-interaction tool because stdout belongs to the SDK protocol and turns are driven by the SDK.
The model-facing tools are:
bash, foreground onlyread,write, andeditsubagent, using one foreground in-process spawn providertodo_write
The surrounding runtime also loads JSONL session persistence and automatic context compaction. maxTokensAsSuccess keeps a token-limited model turn as an accepted evaluation result while preserving its max-tokens reason.
Runtime environment
| Variable | Purpose |
|---|---|
DEEPSEEK_API_KEY |
Credential passed to the OpenAI-compatible host endpoint |
DEEPSEEK_BASE_URL |
Host endpoint used by dsh-llm-deepseek |
DSH_CWD |
Agent workspace for bash and filesystem tools |
DSH_MAX_TOKENS_AS_SUCCESS |
true (default) accepts token-limited results; false reports them as errors |
DSH_SESSION_ROOT |
JSONL trajectory directory |
DSH_SYSTEM_PROMPT |
Deployment-provided coding persona |
Pass the config path through the Python SDK's cordis option or DSH_CORDIS_CONFIG. The bundled executable already carries every plugin named by this file; the target machine does not need Node.js.
Persistent tools variant
persistent-tools.cordis.yml is a minimal runnable variant whose model-facing surface is exactly:
- owner-scoped persistent
bash str_replace_editorwithview,create,str_replace, andinsert
It composes the real local PTY, filesystem intent policy, and session sandbox policy. The keyless SDK snapshot drives the shipped JSON-RPC runtime through both tools, proves that shell cwd/environment survive across calls, and pins the notification stream, turn result, and persisted JSONL:
pnpm exec vitest run --config vitest.snapshot.config.ts -t persistent-tools