cordis.yml 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159
  1. # ACP server and snapshot-record composition. With `DSH_SNAPSHOT=record`, the
  2. # app bin runs the real DeepSeek adapter and the harness harvests its persisted
  3. # log. The bin loads the gitignored root `.env` before this config. This tree has
  4. # no stdout logger or HMR because stdout carries ACP JSON-RPC.
  5. # The DeepSeek adapter.
  6. - id: llm-deepseek
  7. name: '@deepseek-ai/dsh-llm-deepseek'
  8. config:
  9. apiKey: !!js process.env.DEEPSEEK_API_KEY
  10. baseURL: !!js process.env.DEEPSEEK_BASE_URL
  11. # The default composition confines bash AND the filesystem tools to the
  12. # workspace and asks before a wider retry. Snapshot runs select
  13. # danger-full-access so the established scenarios remain runner-independent;
  14. # DSH_PERMISSION_MODE provides the same explicit deployment/test override
  15. # outside the snapshot harness. The sandbox mode + workspace root live on
  16. # ctx.sandboxPolicy — the one home both enforcing families (bash, fs) read.
  17. - id: sandbox
  18. name: '@deepseek-ai/dsh-sandbox-local'
  19. - id: sandbox-policy
  20. name: '@deepseek-ai/dsh-sandbox-policy'
  21. config:
  22. mode: !!js "process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')"
  23. workspaceRoot: !!js process.cwd()
  24. - id: bash
  25. name: '@deepseek-ai/dsh-bash-sandbox'
  26. config:
  27. timeoutMs: 60000
  28. - id: approval
  29. name: '@deepseek-ai/dsh-user-approval'
  30. config:
  31. policy: !!js "(process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')) === 'danger-full-access' ? 'never' : 'ask'"
  32. - id: permission
  33. name: '@deepseek-ai/dsh-permission'
  34. # The ACP server app: the agent-spine-demo spine + JSONL persistence + the ACP bridge.
  35. # Persistence root: $DSH_SNAPSHOT_SESSIONS_ROOT when the snapshot harness sets it
  36. # (so it can harvest / isolate the log), else ./.sessions for the demo.
  37. # Snapshot modes use raw JSONL fixtures; ordinary runs keep the compressed default.
  38. - id: acp-agent
  39. name: '@deepseek-ai/dsh-acp-demo'
  40. config:
  41. provider: deepseek
  42. model: deepseek-v4-flash
  43. persistenceRoot: !!js process.env.DSH_SNAPSHOT_SESSIONS_ROOT ?? './.sessions'
  44. persistenceCompression: !!js "process.env.DSH_SNAPSHOT === undefined ? 'zstd' : 'none'"
  45. workspaceContext:
  46. maxBytes: 65536
  47. # Keep the persona to identity and behavior; tool plugins own tool guidance.
  48. # The loop resolves {{model}} and each ACP session's client-supplied {{cwd}}.
  49. persona: |
  50. You are a coding assistant powered by the {{model}} model. Your working directory is {{cwd}}. Your bash tool runs under a file sandbox — a `[sandbox: file access denied …]` result is policy, not a command bug.
  51. Verify your work by running the code or tests. Keep answers brief and factual.
  52. # Replay-aware request pressure with one service-wide context window.
  53. - id: token-meter
  54. name: '@deepseek-ai/dsh-token-meter'
  55. config:
  56. # FIXME: Resolve compaction config per model; this capacity assumes a 256k context window.
  57. contextWindow: 256000
  58. # Summarize an older range after measured pressure or a canonical provider overflow.
  59. # Service-wide policy provides pressure, retention, and one overflow-retry default.
  60. - id: compact-basic
  61. name: '@deepseek-ai/dsh-compact-basic'
  62. config:
  63. thresholdRatio: 0.8
  64. retainTokens: 20480
  65. maxTokens: 8192
  66. compactionRetries: 1
  67. # Expose fresh-child `spawn` and completed-prefix `fork` through separate tool
  68. # names so multi-child scenarios exercise both transports. These leaves follow
  69. # the app because it provides `ctx.agents` and `ctx.tools`.
  70. - id: subagent
  71. name: '@deepseek-ai/dsh-subagent'
  72. - id: subagent-spawn
  73. name: '@deepseek-ai/dsh-subagent-spawn'
  74. config:
  75. providerName: spawn
  76. - id: subagent-fork
  77. name: '@deepseek-ai/dsh-subagent-fork'
  78. config:
  79. providerName: fork
  80. - id: tool-subagent
  81. name: '@deepseek-ai/dsh-tool-subagent'
  82. config:
  83. provider: spawn
  84. toolName: subagent
  85. maxDepth: 1
  86. - id: tool-subagent-fork
  87. name: '@deepseek-ai/dsh-tool-subagent'
  88. config:
  89. provider: fork
  90. toolName: subagent_fork
  91. maxDepth: 1
  92. # The worker-thread workflow engine fans a model-written JavaScript script's
  93. # `agent()` calls out through the spawn backend; the adjacent tool exposes it to the model.
  94. - id: workflow-workerthread
  95. name: '@deepseek-ai/dsh-workflow-workerthread'
  96. config:
  97. provider: spawn
  98. - id: tool-workflow
  99. name: '@deepseek-ai/dsh-tool-workflow'
  100. # `todo_write` replaces the logged whole list and surfaces an ACP `plan` update.
  101. - id: tool-todo
  102. name: '@deepseek-ai/dsh-tool-todo'
  103. # Identical repeat calls trigger advisory context, never a block, at the default
  104. # thresholds [3, 5, 8]. Only the repeat-tool-guard snapshot scenario reaches them.
  105. - id: repeat-tool-guard
  106. name: '@deepseek-ai/dsh-repeat-tool-guard'
  107. # The filesystem stack rides the SAME sandbox policy as bash: dsh-fs-sandbox
  108. # replaces dsh-fs-local behind ctx.fs and fences write/edit by the effective
  109. # mode (read-only denies, workspace-write contains to the workspace + temp
  110. # roots, danger-full-access passes through), so read/write/edit are available
  111. # under every mode. fs-policy (read-before-edit) composes orthogonally on top.
  112. - id: fs-sandbox
  113. name: '@deepseek-ai/dsh-fs-sandbox'
  114. config:
  115. cwd: !!js process.cwd()
  116. - id: fs-policy
  117. name: '@deepseek-ai/dsh-fs-policy'
  118. - id: tool-fs
  119. name: '@deepseek-ai/dsh-tool-fs'
  120. # `configPath` is read once at load and resolves from the server launch cwd, not
  121. # `session/new.cwd`; one `hooks.json` therefore applies to every session and a
  122. # project-local file is not discovered. Missing config registers nothing. Hook
  123. # commands still run in the session cwd. Warnings use `ctx.logger`, never stdout;
  124. # see packages/hooks/hooks-claude/README.md for the deferred per-session design.
  125. - id: hooks-claude
  126. name: '@deepseek-ai/dsh-hooks-claude'
  127. config:
  128. configPath: ./hooks.json
  129. # Codex uses its own `codex-hooks.json` and snake_case five-event dialect; it
  130. # cannot share Claude's file. It has the same process-level, read-once, missing-is-no-op,
  131. # logger-only contract. Shipping both bridges lets a scenario seed and exercise either dialect.
  132. - id: hooks-codex
  133. name: '@deepseek-ai/dsh-hooks-codex'
  134. config:
  135. configPath: ./codex-hooks.json