index.ts 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333
  1. /**
  2. * Local Service Provider for the bash capability seam over the subprocess
  3. * capability seam. Public commands run as `bash -c` in a managed process group spawned
  4. * through `ctx.subprocess`; subclasses may reuse the same mechanics with an
  5. * explicit argv. This executor owns command defaulting, deadlines and cause
  6. * classification, the model-friendly terminal environment, and the model-facing
  7. * stdout/stderr merge for background reads. Execution policy belongs in
  8. * `tools/pre-execute` or a sandboxing executor.
  9. * @module @deepseek-ai/dsh-bash-local
  10. */
  11. import { Context } from '@deepseek-ai/cordis'
  12. import z from '@deepseek-ai/schemastery'
  13. import { SHELL_SETTINGS_NAMESPACE, ShellExecutor } from '@deepseek-ai/dsh-shell'
  14. import type { ShellExecRequest, ShellExecSpec, ShellProcess, ShellProcessRead, ShellRunResult, CollectedOutput } from '@deepseek-ai/dsh-shell'
  15. import type { SubprocessCollect, SubprocessHandle, SubprocessOutputReader, SubprocessSpawnSpec } from '@deepseek-ai/dsh-subprocess'
  16. import { installSettingsSection } from '@deepseek-ai/dsh-settings'
  17. import { clampTimeout, deadline, MAX_TIMER_DELAY_MS, timeoutOf } from '@deepseek-ai/dsh-timeout'
  18. /**
  19. * Model-friendly environment overrides: disable colors, pagers, and
  20. * interactive terminal features that would garble tool output (the same set
  21. * Codex hardcodes; Claude Code achieves it via TERM=dumb). Bash-tool policy —
  22. * merged first into the spawn's explicit env, so a trusted caller's own entry
  23. * still wins; the subprocess service applies its credential scrub independently.
  24. */
  25. export const ENV_OVERRIDES = {
  26. NO_COLOR: '1',
  27. TERM: 'dumb',
  28. PAGER: 'cat',
  29. GIT_PAGER: 'cat',
  30. } as const
  31. /** Default SIGTERM→SIGKILL grace period (the `graceMs` config; matches OpenCode's 3s). */
  32. const DEFAULT_GRACE_MS = 3_000
  33. /** Default per-stream spill cap (the `maxSpillBytes` config). */
  34. const DEFAULT_MAX_SPILL_BYTES = 64 * 1024 * 1024
  35. /** Plugin config (all optional — `static Config` supplies the defaults). */
  36. export interface Config {
  37. /** Default working directory for commands (default: process.cwd()). */
  38. cwd?: string
  39. /** Default foreground timeout in milliseconds. */
  40. timeoutMs?: number
  41. /** Upper bound for per-call timeout overrides. */
  42. maxTimeoutMs?: number
  43. /** Per-stream in-memory output cap; overflow spills to a temp file. */
  44. maxOutputBytes?: number
  45. /** Per-stream spill-file cap; larger streams retain only their in-memory tail. */
  46. maxSpillBytes?: number
  47. /** Grace period for kill escalation and inherited pipes; at most `MAX_TIMER_DELAY_MS`. */
  48. graceMs?: number
  49. }
  50. /** The shape after schemastery applied the defaults (cwd has none). */
  51. type ResolvedConfig = Required<Omit<Config, 'cwd'>> & Pick<Config, 'cwd'>
  52. /** Project a settled collect-mode reader into the final CollectedOutput shape. */
  53. function finalOutput(reader: SubprocessOutputReader): CollectedOutput {
  54. const read = reader.readFrom(0)
  55. return {
  56. text: read.text,
  57. truncated: read.lossy,
  58. ...read.spillPath !== undefined ? { spillPath: read.spillPath } : {},
  59. }
  60. }
  61. function assertPositiveFinite(name: string, value: number): void {
  62. if (!Number.isFinite(value) || value <= 0) {
  63. throw new Error(`bash-local: ${name} must be a positive finite number`)
  64. }
  65. }
  66. /**
  67. * Reject a resolved section this executor could not run with. The schema
  68. * expresses neither "positive and finite" nor the timer bound `graceMs` has to
  69. * fit, so a stored value is refused where it is written instead of failing at
  70. * the next command.
  71. * @param config - the resolved section, schema-valid by construction.
  72. * @throws Error naming the field that cannot be used.
  73. */
  74. export function assertServiceableBashConfig(config: Config): void {
  75. const resolved = config as ResolvedConfig
  76. assertPositiveFinite('timeoutMs', resolved.timeoutMs)
  77. assertPositiveFinite('maxTimeoutMs', resolved.maxTimeoutMs)
  78. assertPositiveFinite('maxOutputBytes', resolved.maxOutputBytes)
  79. assertPositiveFinite('maxSpillBytes', resolved.maxSpillBytes)
  80. assertPositiveFinite('graceMs', resolved.graceMs)
  81. if (resolved.graceMs > MAX_TIMER_DELAY_MS) {
  82. throw new Error(`bash-local: graceMs must be no greater than ${MAX_TIMER_DELAY_MS}`)
  83. }
  84. }
  85. /**
  86. * Local bash executor over `ctx.subprocess`. Bounded output, spill files, and
  87. * process-group SIGTERM→SIGKILL escalation are the subprocess service's
  88. * mechanics; this executor supplies their configured budgets per spawn, so a
  89. * still-running background process stays managed (killed and joined at
  90. * composition teardown) even across an executor reload.
  91. */
  92. export class LocalBashExecutor extends ShellExecutor {
  93. static inject = ['subprocess']
  94. static Config: z<Config> = z.object({
  95. cwd: z.string(),
  96. timeoutMs: z.number().default(120_000),
  97. maxTimeoutMs: z.number().default(600_000),
  98. maxOutputBytes: z.number().default(64_000),
  99. maxSpillBytes: z.number().default(DEFAULT_MAX_SPILL_BYTES),
  100. graceMs: z.number().default(DEFAULT_GRACE_MS),
  101. })
  102. /** The currently authoritative config: the settings section, or the composition entry. */
  103. private source: () => ResolvedConfig
  104. /** Validated config (schemastery applied the defaults before construction). */
  105. get config(): ResolvedConfig {
  106. return this.source()
  107. }
  108. constructor(ctx: Context, config: Config) {
  109. super(ctx)
  110. // Schemastery fills these fields before construction; the type does not encode that step.
  111. const entry = config as ResolvedConfig
  112. assertServiceableBashConfig(entry)
  113. this.source = () => entry
  114. installSettingsSection(ctx, SHELL_SETTINGS_NAMESPACE, LocalBashExecutor.Config, entry, {
  115. validate: assertServiceableBashConfig,
  116. setSource: (current) => {
  117. this.source = current as () => ResolvedConfig
  118. },
  119. // Every field is read through the getter at each command, so nothing
  120. // derived from the source needs rebuilding when the document changes.
  121. onChange: () => {},
  122. })
  123. }
  124. /**
  125. * Resolve a request into a fully-specified spec: fill `workdir` from
  126. * `config.cwd` (else `process.cwd()`), and `timeoutMs` from
  127. * `config.timeoutMs`, capped at `config.maxTimeoutMs`. The tool layer calls
  128. * this before {@link run}/{@link start}, so those methods receive explicit
  129. * values and never re-default.
  130. */
  131. resolve(request: ShellExecRequest): ShellExecSpec {
  132. const timeoutMs = clampTimeout(
  133. request.timeoutMs,
  134. this.config.timeoutMs,
  135. this.config.maxTimeoutMs,
  136. 'bash-local: request.timeoutMs',
  137. )
  138. const stdoutMaxBytes = request.stdoutMaxBytes ?? this.config.maxOutputBytes
  139. assertPositiveFinite('request.stdoutMaxBytes', stdoutMaxBytes)
  140. return {
  141. command: request.command,
  142. workdir: request.workdir ?? this.config.cwd ?? process.cwd(),
  143. timeoutMs,
  144. stdoutMaxBytes,
  145. ...request.signal ? { signal: request.signal } : {},
  146. // Carry stdin/ordinary env/trusted dshEnv through verbatim — optional,
  147. // no config default. The subprocess service owns the scrub and merge order.
  148. ...request.stdin !== undefined ? { stdin: request.stdin } : {},
  149. ...request.env !== undefined ? { env: request.env } : {},
  150. ...request.dshEnv !== undefined ? { dshEnv: request.dshEnv } : {},
  151. // Carry a sandbox policy through verbatim: this executor never
  152. // confines, so the field is inert here (the seam contract) — a
  153. // sandboxing subclass overrides resolve() to stamp its default instead.
  154. sandboxPolicy: request.sandboxPolicy,
  155. }
  156. }
  157. /** Map one resolved bash spec and explicit argv onto a fully-specified subprocess spawn. */
  158. // XXX(stateful-shell): evaluate persistent cwd or PTY sessions when workflows require shell state.
  159. private spawnSpec(
  160. spec: ShellExecSpec,
  161. argv: readonly string[],
  162. stdoutMaxBytes: number,
  163. signal: AbortSignal | undefined,
  164. ): SubprocessSpawnSpec {
  165. const collect = (maxBytes: number): SubprocessCollect =>
  166. ({ maxBytes, spill: { maxBytes: this.config.maxSpillBytes } })
  167. return {
  168. argv,
  169. cwd: spec.workdir,
  170. stdio: {
  171. stdin: spec.stdin !== undefined ? { data: spec.stdin } : 'ignore',
  172. stdout: collect(stdoutMaxBytes),
  173. stderr: collect(this.config.maxOutputBytes),
  174. },
  175. graceMs: this.config.graceMs,
  176. signal,
  177. // One explicit env map for the seam, layered so the trusted dshEnv
  178. // snapshot beats both the caller's env and the terminal overrides; the
  179. // subprocess service merges the whole map after its ambient scrub.
  180. env: { ...ENV_OVERRIDES, ...spec.env, ...spec.dshEnv },
  181. }
  182. }
  183. /** The collect-mode readers the executor itself requested (present by construction). */
  184. private static collected(handle: SubprocessHandle): { stdout: SubprocessOutputReader; stderr: SubprocessOutputReader } {
  185. const { stdout, stderr } = handle.collected
  186. /* v8 ignore start -- collect dispositions expose both readers by the seam contract; defensive. */
  187. if (stdout === undefined || stderr === undefined) {
  188. throw new Error('bash-local: subprocess implementation dropped a requested collect stream')
  189. }
  190. /* v8 ignore stop */
  191. return { stdout, stderr }
  192. }
  193. async run(spec: ShellExecSpec): Promise<ShellRunResult> {
  194. return this.runArgv(spec, ['bash', '-c', spec.command])
  195. }
  196. /**
  197. * Run an explicit argv with the foreground lifecycle, environment, output,
  198. * timeout, and cancellation semantics of this executor. Subclasses use this
  199. * after replacing the public command's shell argv at an execution boundary.
  200. * @param spec - resolved execution settings and caller-owned command metadata.
  201. * @param argv - exact executable and arguments to hand to `ctx.subprocess`.
  202. * @returns the settled foreground result with collected output and cause facts.
  203. */
  204. protected async runArgv(spec: ShellExecSpec, argv: readonly string[]): Promise<ShellRunResult> {
  205. // One deadline combines timeout and upstream cancellation; disposal clears its timer.
  206. using d = deadline(spec.signal, spec.timeoutMs, 'BASH_TIMEOUT')
  207. const handle = this.ctx.subprocess.spawn(this.spawnSpec(spec, argv, spec.stdoutMaxBytes, d.signal))
  208. const outcome = await handle.done
  209. const collected = LocalBashExecutor.collected(handle)
  210. // Only this executor's timeout reason counts as timedOut; outer deadlines count as aborts.
  211. const timedOut = timeoutOf(d.signal, 'BASH_TIMEOUT') !== undefined
  212. const aborted = d.signal.aborted && !timedOut
  213. return {
  214. ...outcome,
  215. timedOut,
  216. aborted,
  217. timeoutMs: spec.timeoutMs,
  218. stdout: finalOutput(collected.stdout),
  219. stderr: finalOutput(collected.stderr),
  220. }
  221. }
  222. start(spec: ShellExecSpec): ShellProcess {
  223. return this.startArgv(spec, ['bash', '-c', spec.command])
  224. }
  225. /**
  226. * Start an explicit argv with the background lifecycle, environment, output,
  227. * cancellation, and process-tree ownership semantics of this executor.
  228. * Subclasses use this after replacing the public command's shell argv at an
  229. * execution boundary.
  230. * @param spec - resolved execution settings and caller-owned command metadata.
  231. * @param argv - exact executable and arguments to hand to `ctx.subprocess`.
  232. * @returns the live background handle; spawn rejection settles it as killed.
  233. */
  234. protected startArgv(spec: ShellExecSpec, argv: readonly string[]): ShellProcess {
  235. // Background runs ignore timeoutMs; callers stop them through kill() or spec.signal.
  236. const running = this.ctx.subprocess.spawn(this.spawnSpec(spec, argv, this.config.maxOutputBytes, spec.signal))
  237. const collected = LocalBashExecutor.collected(running)
  238. // A spawn failure produces no process output, so the subprocess service has nothing
  239. // to buffer; the note is delivered exactly once through the read path.
  240. let spawnFailureNote: string | undefined
  241. const consumeSpawnFailure = (): string => {
  242. const note = spawnFailureNote ?? ''
  243. spawnFailureNote = undefined
  244. return note
  245. }
  246. let stdoutOffset = 0
  247. let stderrOffset = 0
  248. const proc: ShellProcess = {
  249. status: 'running',
  250. exitCode: null,
  251. signal: null,
  252. done: running.done.then((outcome) => {
  253. // Any signal termination is killed, including a command signaling itself.
  254. if (proc.status === 'running') {
  255. proc.status = spec.signal?.aborted === true || outcome.signal !== null ? 'killed' : 'completed'
  256. }
  257. proc.exitCode = outcome.exitCode
  258. proc.signal = outcome.signal
  259. this.onProcessDone(proc, collected.stderr.readFrom(0).text, false)
  260. }, (error: unknown) => {
  261. // Background spawn failures settle as killed and surface through the read path.
  262. proc.status = 'killed'
  263. spawnFailureNote = `spawn failed: ${String(error)}`
  264. this.onProcessDone(proc, spawnFailureNote, true, error)
  265. }),
  266. readOutput: (): ShellProcessRead => {
  267. const out = collected.stdout.readFrom(stdoutOffset)
  268. const err = collected.stderr.readFrom(stderrOffset)
  269. stdoutOffset = out.nextOffset
  270. stderrOffset = err.nextOffset
  271. // A failed spawn never produced process output, so the note and real
  272. // stderr text are mutually exclusive.
  273. const errText = err.text.length > 0 ? err.text : consumeSpawnFailure()
  274. // Single newline between sections: stdout chunks usually end with one
  275. // already; add it only when missing.
  276. const separator = out.text.length > 0 && !out.text.endsWith('\n') ? '\n' : ''
  277. const delta = out.text
  278. + (errText.length > 0 ? `${separator}[stderr]\n${errText}` : '')
  279. return {
  280. delta,
  281. lossy: out.lossy || err.lossy,
  282. ...out.spillPath !== undefined ? { stdoutSpillPath: out.spillPath } : {},
  283. ...err.spillPath !== undefined ? { stderrSpillPath: err.spillPath } : {},
  284. }
  285. },
  286. kill: (): boolean => {
  287. if (proc.status !== 'running') return false
  288. proc.status = 'killed'
  289. running.terminate()
  290. return true
  291. },
  292. }
  293. return proc
  294. }
  295. /**
  296. * Settlement hook for subclasses that attach execution facts to a process.
  297. * Called after exit facts or spawn-failure output are stamped and before
  298. * {@link ShellProcess.done} resolves. The base implementation is intentionally
  299. * empty.
  300. * @param _proc - the settled process handle.
  301. * @param _stderr - the process's retained stderr tail used by subclasses for settlement classification.
  302. * @param _spawnFailed - whether the subprocess promise rejected before a process started.
  303. * @param _spawnError - the original spawn rejection reason, which may itself be undefined.
  304. */
  305. protected onProcessDone(_proc: ShellProcess, _stderr: string, _spawnFailed: boolean, _spawnError?: unknown): void {}
  306. }
  307. export default LocalBashExecutor