Files
deepseek-harness/packages/subagent
Dudu-0223 7428cdf41e fix(subagent): address codex review round 3
- Make host-user authority unforgeable. `{ kind: 'user' }` was a bare
  discriminant, so any plugin holding `ctx.subagents` — including
  model-generated cordis_mount code, which the advanced ACP composition ships
  alongside continuable subagents — could construct it and skip the
  direct-parent check for any known child id. It now carries an opaque grant
  that only SubagentService.userAuthority() mints, which composition hands to
  trusted host adapters; a model-facing tool uses parent authority from its own
  execution context.
- Reconcile a delivery discarded inside its own admission window. An enqueue
  listener that cancels fires the discard before followup() returns, so the
  discard listener could not clear an id it had not seen; submit() retained it
  and residency stayed `running` until an explicit drain.
- Recheck the caller signal after materialization. An abort landing between
  publication and inbox acceptance still submitted the prompt and returned both
  ids; it now rolls the child back.
- Stop promising the model transcript access that no shipped continuable config
  mounts. The tools now state only that a background child does not report back.
- Restate the implemented note as shipped state rather than a proposal, so it
  works as current authority.
2026-08-02 12:51:08 +08:00
..

subagent/ — subagent capability family

English | 中文

The subagent seam: an agent delegating work to a child agent. Like the bash and llm families this is a capability seam (see capability seams) — but with one defining difference: multiple provider implementations coexist in one context, registered by name, rather than the single-implementation bash shape. The registry mirrors the LLM adapter registry.

Package Role ctx key
subagent/ Subagent service: named-provider registry, vocabulary, durable descriptor, and continuable-child orchestration ctx.subagents
subagent-inprocess/ Shared in-process run driver (no provider; one cleanup effect per run)
subagent-spawn/ In-process backend: a fresh child agent, with cold resume (registers on ctx.subagents)
subagent-fork/ In-process backend: a child seeded with the parent's completed-turn prefix, with cold resume (registers on ctx.subagents)
subagent-acp/ Out-of-process backend: a child agent in a spawned subprocess, driven over ACP (one-shot) (registers on ctx.subagents)
subagent-dsh-sdk/ Out-of-process backend: a child harness runtime in a spawned subprocess, driven over stdio JSON-RPC through the TypeScript SDK client (registers on ctx.subagents)
tool-subagent/ Model-facing subagent delegation tool over ctx.subagents (registers on ctx.tools)
tool-subagent-control/ The optional, globally named send_message follow-up tool over ctx.subagents (registers on ctx.tools)

The interface and continuation orchestration live at subagent/subagent/. One-shot provider start dispatch stays independent of persistence; an internal continuation manager owns each durable continuable child as one Session plus at most one process-local Activation, binding no Task, and exists only while the Agent service is present, resolving persistence per continuation operation. The in-process subagent-spawn / subagent-fork backends share the subagent-inprocess driver (a library with no provider of its own — both depend on it, neither on the other), and the out-of-process subagent-acp / subagent-dsh-sdk backends spawn their children through the subprocess/ seam (the shared credential scrub, tree-scoped teardown, and dispose ladder). Tests replace only the child boundary with package-local fixtures.

The design rationale: .agents/notes/implemented/feature/2026-06-21-subagent-capability-seam.md, .agents/notes/implemented/feature/2026-07-21-continuable-background-subagents.md, and .agents/notes/implemented/simplification/2026-07-26-merge-subagent-control-service.md.