An awaited waitForExit()/dispose() must hold the event loop open until the tree really exits: with the liveness tick and the escalation timer unref'd, a parent with no other live handles could exit claiming quiescence and orphan the survivors it promised to reap. The escalation's pending SIGKILL is a commitment; it self-bounds at graceMs. Module graph picks up the subprocess-local -> timeout edge.
subprocess/ — subprocess capability family
The shared home for spawning managed child-process trees: fully-specified spawn specs with Node-shaped per-stream stdio dispositions (raw pipes, inherit, bounded tail-keep collection with spill files), the one credential scrub every harness spawner uses, offset-based incremental reads, tree-scoped signalling with SIGTERM→grace→SIGKILL escalation, and the cooperative dispose ladder. Command defaulting, shell semantics, deadlines, protocol framing, and presentation stay with consumers — the bash executors, the LSP host, and the ACP subagent backend. See the subprocess seam Agent Note.
| Package | ctx key | Role |
|---|---|---|
subprocess (@deepseek-ai/dsh-subprocess) |
ctx.subprocess |
The seam: abstract SubprocessService.spawn(spec), the fully-explicit SubprocessSpawnSpec with per-stream stdio dispositions, SubprocessHandle (streams, offset-based readers, kill/terminate/waitForExit/dispose), and the shared scrub + DSH_*/CollectedOutput vocabulary |
subprocess-local (@deepseek-ai/dsh-subprocess-local) |
— | The local implementation: detached process trees, per-disposition stream wiring, tail-keep truncation with bounded private spill files, the DSH_* merge order, tree signalling with escalation, the dispose ladder, and terminate-and-join disposal |
The service owns process lifetime across consumer reloads; consumers own what a process means (a bash command, a future non-shell runner) and every default that shapes one.