Commit Graph
100 Commits
Author SHA1 Message Date
Tianyi Cui 137c3c9254 Merge pull request #2428 from deepseek-harness/fix/run-code-description-contract
让 run_code 的模型面说明点名必填的 description 参数
2026-08-13 11:17:48 +08:00
Tianyi Cui 64fbab25d1 Merge pull request #2427 from deepseek-harness/worktree/minimal-no-runtime-context
fix: suppress runtime context in minimal profiles
2026-08-13 11:16:55 +08:00
Tianyi Cui eec7f2ec74 Merge pull request #2302 from deepseek-harness/worktree/repository-rename-proof-a9cbb8
refactor: apply repository naming contract
2026-08-13 01:21:20 +08:00
Tianyi Cui a2d0f7f411 refactor: apply repository naming contract
Apply the accepted pre-release package, service, type, directory, and role renames as one repository-wide change.
2026-08-13 00:54:38 +08:00
Tianyi Cui 564a853a04 Merge pull request #2277 from deepseek-harness/codex/background-first-continuable-subagents
feat(subagent): default continuable delegation to background
2026-08-11 22:21:02 +08:00
Tianyi Cui cb235da37f Merge pull request #2282 from deepseek-harness/worktree/deny-deepseek-base-urls-519
fix(boot): deny DeepSeek endpoint env overrides
2026-08-11 21:55:26 +08:00
Tianyi Cui 4c9c6c8217 test(cli): align endpoint fixture with boot trust 2026-08-11 21:33:06 +08:00
Tianyi Cui a767cd357f Merge pull request #2280 from deepseek-harness/worktree/naming-contract-proposal
docs: propose repository naming contract and rename ledger
2026-08-11 21:28:54 +08:00
Tianyi Cui b735af91fa Merge remote-tracking branch 'origin/master' into worktree/naming-contract-proposal 2026-08-11 21:16:36 +08:00
Tianyi Cui bf6800d972 Merge origin/master into naming contract proposal 2026-08-11 21:07:21 +08:00
Tianyi Cui 32454ba589 docs: address naming ledger review 2026-08-11 21:07:09 +08:00
Tianyi Cui ac266ed2de Merge pull request #2109 from deepseek-harness/worktree/schedule-fixed-rate
feat(schedule): add bounded fixed-rate reminders
2026-08-11 20:53:47 +08:00
Tianyi Cui 2310a23743 fix(boot): deny DeepSeek endpoint env overrides 2026-08-11 20:53:04 +08:00
Tianyi Cui 01033361c1 Merge branch 'worktree/schedule-explicit-at' into worktree/schedule-fixed-rate 2026-08-11 20:34:42 +08:00
Tianyi Cui 7583778fbd Merge branch 'worktree/schedule-conversational-after' into worktree/schedule-explicit-at
# Conflicts:
#	packages/client/runtime/README.i18n.yaml
#	packages/client/runtime/README.md
#	packages/client/runtime/README.zh.md
2026-08-11 20:34:34 +08:00
Tianyi Cui 9dc4af386d Merge branch 'master' into worktree/schedule-conversational-after 2026-08-11 20:31:49 +08:00
Tianyi Cui 869b5c7bf2 docs: propose repository naming contract 2026-08-11 20:26:18 +08:00
Tianyi Cui d991327507 Merge branch 'worktree/schedule-explicit-at' into worktree/schedule-fixed-rate 2026-08-11 20:07:51 +08:00
Tianyi Cui 3e131befb5 Merge branch 'worktree/schedule-conversational-after' into worktree/schedule-explicit-at 2026-08-11 20:06:58 +08:00
Tianyi Cui 466854a1d6 Merge remote-tracking branch 'origin/master' into worktree/schedule-conversational-after 2026-08-11 20:03:21 +08:00
Tianyi Cui ac9ba8ce28 Merge branch 'worktree/schedule-explicit-at' into worktree/schedule-fixed-rate 2026-08-11 20:00:32 +08:00
Tianyi Cui e4fdd4b1e9 Merge branch 'worktree/schedule-conversational-after' into worktree/schedule-explicit-at 2026-08-11 19:57:55 +08:00
Tianyi Cui 5f64b6815c Merge remote-tracking branch 'origin/master' into worktree/schedule-conversational-after
# Conflicts:
#	docs/event-producer-consumer.i18n.yaml
#	docs/event-producer-consumer.md
#	docs/event-producer-consumer.zh.md
2026-08-11 19:54:39 +08:00
Tianyi Cui bfef1648aa Merge branch 'worktree/schedule-explicit-at' into worktree/schedule-fixed-rate 2026-08-11 19:43:34 +08:00
Tianyi Cui 97fe09e2c2 Merge branch 'worktree/schedule-conversational-after' into worktree/schedule-explicit-at 2026-08-11 19:34:38 +08:00
Tianyi Cui 4e74c2e056 Merge remote-tracking branch 'origin/master' into worktree/schedule-conversational-after 2026-08-11 19:33:25 +08:00
Tianyi Cui 7028df46e4 Merge worktree/schedule-explicit-at into worktree/schedule-fixed-rate 2026-08-11 19:23:20 +08:00
Tianyi Cui 035f3e5a65 Merge worktree/schedule-conversational-after into worktree/schedule-explicit-at 2026-08-11 19:20:38 +08:00
Tianyi Cui 32a9a0ac61 Merge remote-tracking branch 'origin/master' into worktree/schedule-conversational-after 2026-08-11 19:10:26 +08:00
Tianyi Cui 274c3c13c4 Merge remote-tracking branch 'origin/master' into worktree/schedule-conversational-after 2026-08-11 19:06:02 +08:00
Tianyi Cui 3f01ff8291 Merge remote-tracking branch 'origin/master' into worktree/schedule-conversational-after 2026-08-11 19:05:13 +08:00
Tianyi Cui eb83e0c615 Merge pull request #2258 from deepseek-harness/worktree/pr2177-export-fixes-20260811
fix(web): harden session-log downloads
2026-08-11 18:43:05 +08:00
Tianyi Cui d29a8261e0 fix(vendor): realign the rescope log anchor
PR #2239 removed the old in-memory activation entry and renumbered the local-modification log so Cordis source publication is item 16 and the rescope is item 17. It updated vendor/README.md but left this exact edit expecting the rescope before an item 18, so the current master post-state matched neither side and pnpm run hygiene failed.

Treat item 16 as the pre-rescope anchor and append item 17 in the replacement. The forward edit now produces the checked-in ordering, while reversing it removes only the rescope entry and preserves the independent Cordis publication note.

Verified with the rescope-vendor unit suite, pnpm run rescope-vendor:check, pnpm run hygiene, and git diff --cached --check.
2026-08-11 18:24:17 +08:00
Tianyi Cui 7df8bad6a0 merge(master): checkpoint post-review base movement
Master advanced from e03b51d7db to ee223e6545 after bot-thread resolution and the PR-body policy fix. Merge-forward preserves the reviewed issue commits and explicit checkpoint history instead of rewriting the branch.

The only textual conflict was the generated translation-pairing record for docs/config-catalog. Regenerate the English catalog from the combined source tree and re-record the bilingual hashes so current-master command-line changes and this PR's compression configuration coexist.

Verified with pnpm run verify-config-catalog, pnpm run verify-translation-pairing docs/config-catalog.md, and git diff --cached --check.
2026-08-11 18:19:35 +08:00
Tianyi Cui 5931afaf87 docs(session-persistence): bind raw capability to its reader
The abstract capability flag forces every backend to state whether it owns per-session raw artifacts, but TypeScript cannot express that a true flag requires replacing the concrete unsupported default. Without an implementer-facing obligation, a backend could advertise support and then fail with a contradictory unsupported diagnostic on first use.\n\nDocument the required pairing at the capability declaration. Keep readRaw concrete so backends that correctly report false inherit one fail-loud implementation instead of duplicating rejection code.
2026-08-11 18:10:28 +08:00
Tianyi Cui b52ddb2887 fix(apiproxy): omit an unresolved compression option
ApiProxyDefaults uses an exact optional property, so passing config.sessionExportCompressionLevel directly made the service object carry an explicit undefined that is not assignable to the resolved request shape. The full host build caught this distinction after the redundant fallback was removed.\n\nConditionally omit the property when Cordis has not supplied a value. Direct createApiProxy callers still receive the implementation-owned default, while configured plugin values pass through without introducing another defaulting site.
2026-08-11 17:59:07 +08:00
Tianyi Cui 544a17f604 Merge origin/master into worktree/pr2177-export-fixes-20260811
Master advanced again after the first merge-forward checkpoint, adding the web human-transcript command-input change. Preserve the earlier checkpoint and merge the new exact e03b51d7 base as a separate commit instead of rebasing or rewriting this merge-heavy stack.\n\nThe incremental merge is conflict-free and keeps the session-export review fixes based on the repository's current integration state.
2026-08-11 17:53:13 +08:00
Tianyi Cui c10d74ba95 fix(apiproxy): cancel attachment reads during export
Response-consumer cancellation already stopped lineage reads, persistence reads, and ZIP production, but the final attachment phase called readImage without the producer signal. A slow or stalled attachment backend could therefore keep working after the browser abandoned the download and prevent the producer from settling.\n\nExtend the attachment read seam with optional cancellation, forward it through the local backend into Node's filesystem read, and preserve the abort reason rather than wrapping it as a storage failure. The exporter now passes its combined request/consumer signal to every attachment read.\n\nCover both ownership boundaries: the local-store test proves filesystem forwarding and cancellation identity, while the assembled export test cancels a reader during a pending attachment provider call. Regenerate the Cordis API catalog and paired documentation so implementers can rely on the new contract.
2026-08-11 17:52:24 +08:00
Tianyi Cui 5e067fa7fe docs(apiproxy): state the export queue bound exactly
The response stream uses a fixed 64 KiB byte high-water mark; no deployment setting controls it. Calling that queue configured incorrectly suggested another tuning surface and obscured the concrete memory bound.\n\nName the fixed capacity directly while preserving the separate bound of one synchronous fflate push beyond the queued bytes.
2026-08-11 17:47:29 +08:00
Tianyi Cui 8d63728584 fix(apiproxy): name root export preparation failures
The pre-stream error boundary covers both the live-session flush barrier and the persistence read, but its response attributed every failure to reading storage. A flush failure therefore produced a misleading diagnostic even though the response correctly withheld private backend details.\n\nUse preparation as the shared operation name and cover the flush-failure path explicitly. Both preparation stages now retain one stable, path-safe HTTP 500 without pretending to identify the failing stage.
2026-08-11 17:47:13 +08:00
Tianyi Cui 5703ae356e refactor(apiproxy): resolve export compression once
The Cordis schema supplies the normal plugin default, while createApiProxy also owns the fallback required by direct programmatic callers. Repeating the same nullish fallback in ApiProxyService created a third defaulting site without adding a distinct invariant.\n\nPass the validated config value through unchanged and leave createApiProxy as the single implementation boundary that turns an optional request value into the required compression specification.
2026-08-11 17:46:40 +08:00
Tianyi Cui d1aae98895 docs(connection): describe native export handoff accurately
The fixture comment still said the Trajectory action used window.fetch after the implementation moved to a temporary download anchor. That wording implied client-side response handling and buffering which the browser-download design deliberately avoids.\n\nDescribe the actual native download-manager handoff while retaining the important contract: the fixture download stub only satisfies the host type and is unreachable through fixture dispatch.
2026-08-11 17:46:25 +08:00
Tianyi Cui c626d5f53c Merge origin/master into worktree/pr2177-export-fixes-20260811
Refresh PR #2258 onto master at 5427cbcc19 so the session-log export fixes are evaluated and mergeable against the current repository.\n\nPreserve master's SDK-toolchain removal, client theme bootstrap, and Python finish-reason changes intact. The only textual overlap is the generated config-catalog pairing record: both English and Chinese catalogs merge cleanly with the PR's compression setting and master's package moves, so regenerate that sidecar from the merged owners instead of choosing either stale hash.
2026-08-11 17:39:19 +08:00
Tianyi Cui 1d12ae62e7 Merge pull request #2242 from deepseek-harness/worktree/remove-sdk-project-toolchain
Remove the unreleased SDK project toolchain
2026-08-11 17:09:21 +08:00
Tianyi Cui f9e8375f66 Merge remote-tracking branch 'origin/master' into worktree/remove-sdk-project-toolchain 2026-08-11 17:00:05 +08:00
Tianyi Cui 4d6dc77a1f Merge remote-tracking branch 'origin/master' into worktree/remove-sdk-project-toolchain 2026-08-11 16:54:34 +08:00
Tianyi Cui 175d252f77 chore: remove remaining SDK toolchain residue 2026-08-11 16:37:29 +08:00
Tianyi Cui f21977383b Merge remote-tracking branch 'origin/master' into worktree/pr2177-export-fixes-20260811
# Conflicts:
#	docs/config-catalog.i18n.yaml
#	docs/subsystems/persistence.i18n.yaml
#	packages/session/session-persistence-jsonl/README.i18n.yaml
#	packages/session/session-persistence/README.i18n.yaml
2026-08-11 16:18:28 +08:00
Tianyi Cui af8a8e1384 Merge remote-tracking branch 'origin/master' into worktree/pr2177-export-fixes-20260811
# Conflicts:
#	docs/config-catalog.i18n.yaml
2026-08-11 16:11:30 +08:00
Tianyi Cui 8a2a22db84 fix(apiproxy): configure session export compression
Session-log ZIP entries always used DEFLATE level 6 even though compression level is a deployment tradeoff: CPU-constrained hosts may prefer low latency while bandwidth-constrained hosts may prefer smaller archives. A hardcoded level also violated the repository rule that deployment-varying plugin choices live in validated Config.

Add sessionExportCompressionLevel to ApiProxyService.Config as an integer 0-9 with default 6, resolve the same default once for direct createApiProxy callers, and pass the required level into the streaming module. Tests prove schema defaulting and rejection as well as a level-0 versus level-9 archive-size difference with identical extracted content. The generated config catalog, bilingual gateway README, and feature note document the knob and its tradeoff.
2026-08-11 16:11:09 +08:00
Tianyi Cui 1419671f3f fix(session-export): wait for response pull capacity
The ZIP loop checked desiredSize only after a push and responded to an overfull queue with setTimeout(0). A timer turn does not mean the consumer drained anything, so a slow or disconnected client still allowed the producer to enqueue the complete compressed archive while later artifact and attachment reads ran eagerly.

Give the ReadableStream a 64 KiB byte queuing strategy and block the single producer on a pull-released capacity gate whenever desiredSize is non-positive. Cancellation wakes that gate through the existing producer signal; synchronous fflate output is therefore bounded to the queue high-water mark plus one input push. A regression test exhausts timer turns without consuming and proves the next media entry remains unread until response pulling begins, and the bilingual contracts now describe the real bound.
2026-08-11 16:09:50 +08:00
Tianyi Cui 192840e198 fix(session-export): propagate download cancellation
Only the root raw-artifact read received the request signal. Lineage discovery and descendant reads could continue after disconnect, response-body cancellation did not stop the producer, and the root error boundary converted an abort rejection into an ordinary HTTP 500.

Combine request and response-consumer cancellation into the ZIP producer signal, forward it through every cancellable read, check it around the attachment seam, and terminate fflate exactly once when production stops. The pre-stream boundary now rethrows the original abort instead of translating it. Regression tests cover signal propagation, exact cancellation identity at the HTTP boundary, and a reader cancellation interrupting an in-flight descendant read; the bilingual host contract records these lifecycle semantics.
2026-08-11 16:09:27 +08:00
Tianyi Cui 52f0b09e76 fix(session-export): flush live logs before raw reads
The exporter read persistence artifacts directly even when the requested root or a descendant was still live. Buffered session events could therefore be omitted from a successful download, so the advertised verbatim-artifact guarantee described storage accurately but captured an arbitrarily stale durability boundary.

Resolve each id against SessionStore and cross its authoritative flush barrier immediately before readRaw. Cold sessions remain a no-op, while live roots and descendants are made durable independently; this intentionally yields a per-session read-boundary snapshot rather than claiming an atomic lineage snapshot. A host-path regression test proves both artifacts change from stale to durable only through flush, and the bilingual host contract and Agent Note document the boundary.
2026-08-11 16:08:47 +08:00
Tianyi Cui 454e06c8c1 Merge origin/master into worktree/remove-sdk-project-toolchain
# Conflicts:
#	.agents/notes/implemented/architecture/2026-07-10-single-file-executable-sdk-runtime-distribution.i18n.yaml
#	.agents/notes/implemented/architecture/2026-07-10-single-file-executable-sdk-runtime-distribution.md
#	.agents/notes/implemented/feature/2026-07-21-continuable-background-subagents.i18n.yaml
#	.agents/notes/implemented/feature/2026-07-21-continuable-background-subagents.md
#	.agents/notes/implemented/feature/2026-07-21-continuable-background-subagents.zh.md
#	.agents/notes/proposed/architecture/2026-07-15-sdk-project-editing-architecture.i18n.yaml
#	.agents/notes/proposed/architecture/2026-07-15-sdk-project-editing-architecture.md
#	.agents/notes/proposed/feature/2026-07-14-sdk-developer-projects.i18n.yaml
#	.agents/notes/proposed/feature/2026-07-14-sdk-developer-projects.md
#	.agents/notes/proposed/feature/2026-07-14-sdk-developer-projects.zh.md
#	packages/README.i18n.yaml
#	packages/README.md
#	packages/scaffold/create-sdk/README.md
#	packages/scaffold/create-sdk/src/args.ts
#	packages/scaffold/scripts/src/args.ts
#	packages/sdk/README.i18n.yaml
#	scripts/verify-package-readme-model-experience.ts
2026-08-11 15:56:06 +08:00
Tianyi Cui c1590faac7 Merge origin/master into worktree/remove-sdk-project-toolchain 2026-08-11 15:23:42 +08:00
Tianyi Cui 5f947e1d94 Merge origin/master into worktree/remove-sdk-project-toolchain
# Conflicts:
#	THIRD_PARTY_NOTICES.md
2026-08-11 15:08:18 +08:00
Tianyi Cui 904c3f2c35 fix(session-persistence-jsonl): reject empty zstd artifacts
A present zero-byte .jsonl.zstd file was treated as though no artifact existed because readRaw returned undefined when frame scanning found nothing. That contradicted both the plaintext path and the logical zstd reader, and it made the export endpoint answer 404 for on-disk corruption.

Treat a present artifact without a complete header frame as corruption and reuse the zstd reader's existing diagnostic. The regression test now distinguishes an existing empty file from an absent path, and the bilingual JSONL storage contract records that zero-frame artifacts reject alongside other header and frame failures.
2026-08-11 15:05:54 +08:00
Tianyi Cui e58cc13de4 fix(session-export): distinguish unsupported raw artifacts
SessionPersistence.readRaw previously used undefined for two unrelated states: a supported backend could not find the requested session, or the backend had no per-session artifact concept at all. The export endpoint consequently reported an existing SQLite-backed session as HTTP 404, which falsely diagnosed storage capability as session absence.

Make raw-artifact support an explicit backend capability. Unsupported backends now fail their inherited readRaw path loudly and the host answers 501 before reading, while undefined retains the single meaning of an absent artifact on a supporting backend. First-party backends, test providers, generated API catalogs, bilingual persistence docs, and export error contracts now state that distinction; focused tests cover both the 501 and the inherited rejection.
2026-08-11 15:04:35 +08:00
Tianyi Cui 7f14c7e165 refactor(web): hand session exports to browser downloads
The export endpoint already streams a ZIP response, but the web client immediately converted that response into a Blob. That forced the complete archive through JavaScript memory before a download could start and coupled transport, buffering, object-URL lifetime, and filename handling to the trajectory view.

Navigate a temporary download anchor directly to the export endpoint instead. The browser now owns streaming and HTTP failure presentation, while a standalone delivery module owns URL construction and filename sanitization. Focused tests cover the handoff, rejection behavior, and the assembled session view; the package README and feature note record the new ownership boundary.
2026-08-11 14:57:38 +08:00
Tianyi Cui e063fc1a89 Merge pull request #2162 from deepseek-harness/worktree/windows-acl-hardening-followup
fix(sandbox): keep Windows ACL temp authority session-private
2026-08-11 14:57:22 +08:00
Tianyi Cui a8db48429a Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-11 14:43:23 +08:00
Tianyi Cui a3ca7f09b2 Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup
# Conflicts:
#	packages/sandbox/sandbox-windows-acl/package.json
2026-08-11 14:32:26 +08:00
Tianyi Cui c4e7b453eb Merge pull request #2177 from deepseek-harness/feat/web-session-log-export
feat(web): export the session log from the trajectory toolbar
2026-08-11 14:27:52 +08:00
Tianyi Cui daf90bda7e refactor(sdk): remove unreleased project toolchain 2026-08-11 14:20:53 +08:00
Tianyi Cui f2b3a7382e Merge pull request #2187 from deepseek-harness/feat/mcp-auto-reconnect
feat(mcp-client): auto-reconnect mcp client
2026-08-11 11:52:32 +08:00
Tianyi Cui b52154da52 Merge current master into feat/mcp-auto-reconnect
Master advanced from 1ac6ee70bb24a566cca74d99bdfe5b1bbc092940 to cb7b5af91e9f23bb300a1b7d4fb64b64abbdea01 while the prior retarget's fresh CI was finishing. Preserve both already validated merge checkpoints and incorporate the new live tip with another forward merge instead of rewriting history.

The newer base adds session-log format guards and benchmark documentation. It merges automatically, including the generated config-catalog overlap, so no MCP feature resolution is required; this checkpoint makes GitHub evaluate PR #2187 against the master tip current at the final push.
2026-08-11 11:44:20 +08:00
Tianyi Cui 4952db971a Merge advancing master into feat/mcp-auto-reconnect
Master advanced from c757901957abdfd87f1cd7b11ecab16f3050e65d to 1ac6ee70bb24a566cca74d99bdfe5b1bbc092940 while retarget verification was running. Preserve the already validated c757901957 checkpoint and merge the new tip forward instead of rewriting that checkpoint.

The newer master changes subagent output selection and removes the empty experimental package group. It merges cleanly with PR #2187, so no feature-resolution changes are required; this commit makes final mergeability and CI evaluate the branch against the live master tip.
2026-08-11 11:26:58 +08:00
Tianyi Cui 6d87182099 Merge latest master into feat/mcp-auto-reconnect
Retarget PR #2187 from master 8a763b34645fc9371c0c21595ac65438d603d9bf to c757901957abdfd87f1cd7b11ecab16f3050e65d so the reconnect changes are evaluated against the current release and package metadata.

Resolve the mcp-client package.json conflict by preserving master's publishable-package metadata and workspace peer ranges while retaining the PR's direct @deepseek-ai/dsh-timeout peer and development dependency. The reconnect implementation therefore keeps its explicit runtime contract without discarding current-master release configuration.
2026-08-11 11:24:07 +08:00
Tianyi Cui 8521bfe606 Merge pull request #2211 from deepseek-harness/worktree/event-driven-issue-review-status-20260810
feat: direct Issue status from PR review events
2026-08-11 11:15:16 +08:00
Tianyi Cui 580d85d2a8 fix(ci): await token stats before aria snapshot 2026-08-11 00:28:00 +08:00
Tianyi Cui fc763a1c08 Merge origin/master into feat/mcp-auto-reconnect 2026-08-11 00:15:23 +08:00
Tianyi Cui e5b9ce93a9 Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-11 00:12:11 +08:00
Tianyi Cui e2556c51bf fix(mcp-client): distinguish failure from loss
The reconnect supervisor used connection lost for every transition into backoff, including an initial startup attempt that never established a connection and later retry attempts that also failed. That wording implied a previously healthy generation and obscured whether any tools had ever been registered.

Capture whether the generation had reached the established state before scheduling recovery. Established disconnects retain connection lost/reconnecting; startup and retry failures now report connection failed/retrying. The reconnect-disabled diagnostic uses the same distinction while preserving its concrete manual-recovery guidance.

Unit assertions cover established loss, initial failure, retry failure, and both reconnect-disabled branches. Focused package coverage remains 100%, and the bilingual Agent Note records the observable state vocabulary.
2026-08-11 00:05:06 +08:00
Tianyi Cui dd5c9dc3df Merge remote-tracking branch 'origin/master' into worktree/event-driven-issue-review-status-20260810 2026-08-11 00:03:28 +08:00
Tianyi Cui 0e01036a2a test(mcp-client): preserve startup error cause
Strict startup intentionally wraps connection and synchronization failures with the server-qualified activation diagnostic while retaining the original error in Error.cause. The prior assertion checked only the wrapper text, so the causal chain could regress unnoticed and erase the actionable transport failure.

Assert the full wrapper message and object identity of the original connection error in cause. This keeps operator-facing context and the underlying SDK diagnostic independently stable without changing production behavior.
2026-08-11 00:02:13 +08:00
Tianyi Cui bdd0e6a709 test(mcp-client): pin give-up cleanup ordering
The failure-cap path already appends tool disposal to syncChain, but the existing tests only covered give-up after settled discovery. They could not detect a future change that disposed the old set immediately and then allowed a blocked re-sync to publish a new leaked generation.

Hold a list_changed fetch open, drive the reconnect budget to exhaustion, then release a different tool list. The test proves final cleanup runs after that in-flight swap and removes both the previous and late-published tool names while creating no attempt beyond the configured cap.
2026-08-11 00:01:31 +08:00
Tianyi Cui 442f0ef839 fix(mcp-client): bind strict sync to activation
The supervisor selected strict startup registration with a shared isFirstSync flag. Because the MCP SDK may deliver tools/list_changed before connect() resolves, that notification could enter the sync queue first, consume the strict option inside its contained handler, and leave the actual activation sync non-fatal.

Pass startup intent explicitly to connectGeneration(). Only the plugin activation attempt receives the failOnStartupError registration policy; notification-driven syncs and later reconnect generations always use contained runtime semantics. Queue arrival order can no longer redefine startup behavior.

A regression test injects list_changed from inside connect(), keeps a foreign namespace squatter in place, and proves activation still rejects after the notification's contained sync. Focused package coverage remains 100%, and the bilingual reconnect note records the ownership rule.
2026-08-11 00:00:27 +08:00
Tianyi Cui 6147f02386 fix(mcp-client): await failed generation shutdown
The MCP SDK starts a fire-and-forget close when initialization fails. Its stdio transport clears its process field before that close finishes, so our second Client.close() could return immediately and the reconnect timer could launch a replacement while the original child was still alive.

Track the transport onclose signal for every client generation and gate failed-attempt backoff on both Client.close() settlement and that signal. Use the same barrier during plugin disposal. If the SDK's bounded stdio termination window expires without onclose, fail closed and report incomplete shutdown instead of risking overlapping server processes.

Regression coverage models the SDK's early-returning second close, delayed and missing close signals, pending-connect disposal, close rejection, and the terminal timeout path. The reconnect Agent Note and Chinese counterpart now record the quiescence contract.
2026-08-10 23:57:44 +08:00
Tianyi Cui 93628d5647 Merge pull request #2112 from deepseek-harness/feat/cmdline-args-service-continue
feat(cmdline): let apps own profile command lines
2026-08-10 23:57:21 +08:00
Tianyi Cui 23b1cf47d2 Merge remote-tracking branch 'origin/master' into worktree/event-driven-issue-review-status-20260810 2026-08-10 23:56:42 +08:00
Tianyi Cui d7e8d0d7bd Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-10 23:55:34 +08:00
Tianyi Cui e9a3a38873 fix(ci): type workflow fixture search safely 2026-08-10 23:55:27 +08:00
Tianyi Cui bdc9bbdf9d Merge origin/master into feat/mcp-auto-reconnect
Integrate master at 8b4ef532 before addressing review feedback so each bot issue remains isolated in its own descendant commit. Resolve the vendor package rescope by moving the PR's new MCP supervisor imports to @deepseek-ai/cordis and @deepseek-ai/schemastery, preserve the reconnect implementation and e2e coverage, and regenerate the merged config and module catalogs with fresh bilingual pairing records.
2026-08-10 23:44:58 +08:00
Tianyi Cui 3716459223 fix(ci): narrow issue lifecycle review events 2026-08-10 23:35:05 +08:00
Tianyi Cui 7e4202d4f7 Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-10 23:29:15 +08:00
Tianyi Cui e475984706 test(sandbox): close Windows ACL coverage gaps 2026-08-10 23:16:34 +08:00
Tianyi Cui 19ee8a767d merge: update origin/master checkpoint 2026-08-10 23:14:14 +08:00
Tianyi Cui 00708b950b feat: direct issue status from PR review events 2026-08-10 23:13:32 +08:00
Tianyi Cui 4a9d72818f Merge pull request #2132 from deepseek-harness/fix/continuable-subagent-policy-inheritance
fix(subagent): inherit the parent sandbox scope and pin child approvals to never
2026-08-10 22:44:59 +08:00
Tianyi Cui d3715052ea Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-10 22:25:37 +08:00
Tianyi Cui 64cd78a564 Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-10 21:55:38 +08:00
Tianyi Cui f5b12d12d4 Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup
# Conflicts:
#	packages/sandbox/sandbox-windows-acl/src/index.ts
2026-08-10 21:50:09 +08:00
Tianyi Cui 138d513a9a Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-10 21:19:13 +08:00
Tianyi Cui 6db5abb110 Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-10 20:43:17 +08:00
Tianyi Cui ad37ee33c5 Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup
# Conflicts:
#	docs/config-catalog.i18n.yaml
2026-08-10 20:24:28 +08:00
Tianyi Cui 6da5b1ed6d Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-10 19:33:40 +08:00
Tianyi Cui 8ea27971e3 Merge remote-tracking branch 'origin/master' into worktree/windows-acl-hardening-followup 2026-08-10 19:09:06 +08:00
Tianyi Cui 8143f01678 test(sandbox): satisfy path boundary lint 2026-08-10 18:57:29 +08:00
Tianyi Cui ee21d593b6 test(sandbox): isolate temp cleanup failures 2026-08-10 18:08:22 +08:00
Tianyi Cui 6f21d00169 docs(sandbox): align capability SID terminology 2026-08-10 18:08:22 +08:00