Files
deepseek-harness/packages/web
Dudu-0223 a1624530ee fix: address codex review round 3
Resource-lifecycle and error-classification fixes in the local fetch provider:

- Classify a timeout that fires DURING the body read as WEB_FETCH_TIMEOUT, not
  WEB_ABORTED: thread the controller signal into the body-read translate path
  and recover the timeout WebError from signal.reason, honoring the public
  WEB_FETCH_TIMEOUT contract for a stalled response body.
- Cancel the response body before every blocked-redirect throw path
  (cross-origin, invalid target, missing Location), so a rejected redirect with
  a large or streaming body does not leak the socket after the tool returns
  WEB_REDIRECT_BLOCKED.
- Cancel the body when charset validation fails, matching the
  unsupported-content-type and over-size paths (the round-1 charset check threw
  before readCapped owned the stream).
2026-06-26 19:14:30 +08:00
..

web/ - web capability family

The web access capability seam: an abstract web interface, search/fetch provider implementations, and the model-facing web tools. All product packages.

Package Role ctx key
web/ Abstract web seam (search/fetch provider registries + selection + vocabulary + WebError) ctx.web
web-search-exa/ Exa-backed WebSearchProvider (registers on ctx.web)
web-search-perplexity/ Perplexity-backed WebSearchProvider (registers on ctx.web)
web-fetch-local/ Anonymous public HTTP(S) WebFetchProvider (registers on ctx.web)
tool-web/ Model-facing web_search/web_fetch tool schemas (registers on ctx.tools)

The interface lives at web/web/. Unlike bash/fs, the seam spans two capabilities (search and fetch) with potentially multiple providers each: ctx.web is one web-access middle layer with one provider-selection policy, one abort/error vocabulary, and one product-facing "how this harness reaches the web" config surface. Providers register capabilities, not tools; tool-web is the only owner of model-facing names, schemas, prompt guidance, and presentation. A search provider swap does not change how the model asks for a query, and a fetch implementation swap does not change how the model asks for a URL.

See the web capability seam RFC for the design rationale, including why search and fetch are deliberately one seam and why web_fetch's SSRF protection is deferred.