Implements the turndown Agent Note from the NIH dependency audit (full variant, not the minimal entities-only fallback): dsh-tool-web's fetch rendering now converts HTML through turndown + @joplin/turndown-plugin-gfm (atx headings, fenced code, dash bullets, GFM tables/strikethrough) over the real domino DOM, with script/style/noscript removed wholesale. The hand-rolled ~86-line regex converter html.ts and its entity tables are deleted; renderBody wraps the conversion in try/catch falling back to the raw HTML body, because turndown's recursive DOM walk overflows with a RangeError on pathological nesting (measured: 4k levels on the main thread, 8k in a worker) where the regex version could never throw. Closure weight, measured: tool-web IS in the single-exe runtime closure, and the exe asset globs would pack ~7.9 MB of the three new packages — but ~6 MB of that is domino's test corpus, with runtime lib/ at ~550 KB against a ~174 MB artifact (<0.5% either way), so the swap wins. Per testing policy the previously-missing keyless web_fetch snapshot ships in the same change: the acp-agent `web-fetch` scenario boots a new web.cordis.yml overlay (web seam + real dsh-web-fetch-local provider + tool-web fetch-only + a loopback HTTP fixture server on a fixed port serving deterministic HTML with entities, a GFM table, and nesting), so recording and keyless replay both drive the real HTTP fetch and real conversion end to end; the scenario pins the new `web` header class. The Agent Note moves proposed -> implemented and is rewritten per the lifecycle contract (Decision/Consequences/Testing, closure verdict and alternatives recorded); tool-web and acp-agent READMEs updated in both languages and pairs re-recorded.
3.1 KiB
acp-agent 示例
English | 中文
通过 JSON-RPC stdio 提供的自动化导向 Agent Client Protocol 服务器。它面向父 agent(智能体)、subagent 提供方和其他程序化客户端,而非产品 UI。
pnpm run demo:acp # needs DEEPSEEK_API_KEY (repo-root .env or env)
pnpm run demo:code-mode acp # same protocol with the Code Mode tool transport
该叶节点加载 ACP 应用、DeepSeek 适配器、受沙箱限制的 bash 与文件系统栈、一次性批准策略、压缩(compaction)、subagent、工作流、钩子、派生会话查询索引和重复守卫。应用为每次 session/new 创建一个新 agent,将会话持久化到 JSONL,并保持 stdout 只含协议内容。session-query.cordis.yml 为其专用快照显式选用 workspace 授权的查询工具和通用超时/溢出策略;fs.cordis.yml 为文件系统场景添加溢出存储,code-mode.cordis.yml 添加 run_code 及其生成的 TypeScript SDK,web.cordis.yml 则为 web-fetch 快照添加 web seam、本地抓取提供方、web_fetch 与一个回环 HTML fixture 服务器。
协议通道
Stdout 只携带以换行分隔的 ACP JSON-RPC。@deepseek-ai/dsh-acp-demo 不安装 stdout logger;叶节点的附加项必须使用 stderr 输出诊断信息。
自动化契约(支持的方法、基线提示词内容、已提交文本输出,以及有意缺少的 UI 界面)位于 @deepseek-ai/dsh-acp。
会话 workspace 与权限
每次 session/new 都提供一个绝对 cwd。受沙箱限制的 bash 与文件系统变更会根据该会话 cwd 解析 workspace-write,因此并发会话可以使用不同的项目根目录;平台临时根目录仍是共享可写暂存空间(参见沙箱契约)。DSH_PERMISSION_MODE 在部署和测试中选择 workspace-write 或 danger-full-access。
在 workspace-write 下,模型请求扩大沙箱权限的重试会触发 session/request_permission,选项为 allow_once 和 reject_once。客户端以程序方式决策;解除对话框或答案不可用时会失败闭合。选定结果仅适用于该次重试,并通过常规工具结果/审计路径记录。服务器绝不公开权限选择器,也不持久化客户端策略。
快照测试
此示例拥有 ACP 快照套件。它会启动真实自动化服务器,通过 dsh-llm-replay 回放已提交的模型流,并比较规范化后的协议输出与重新持久化的会话日志。录制使用真实模型;刷新会复用已提交的回放输入。覆盖场景包括抛出/挂起行为,可选 workspace/ fixture(测试前置数据)则为外部状态检查预置环境。
大多数场景锁定后端行为,而非 ACP 专用行为;仅面向自动化的 ACP 决策说明了为何该覆盖仍与传输层耦合。