cordis.yml 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168
  1. # ACP automation server and backend snapshot-record composition. With
  2. # `DSH_SNAPSHOT=record`, the app bin runs the real DeepSeek adapter and the
  3. # harness harvests its persisted log. The bin loads the gitignored root `.env`
  4. # before this config. This tree has no stdout logger or HMR because stdout
  5. # carries ACP JSON-RPC.
  6. # The DeepSeek adapter. Shipped default: full thinking at max effort on every
  7. # request (wire-only defaults; they never enter the request header).
  8. - id: llm-deepseek
  9. name: '@deepseek-ai/dsh-llm-deepseek'
  10. config:
  11. apiKey: !!js process.env.DEEPSEEK_API_KEY
  12. baseURL: !!js process.env.DEEPSEEK_BASE_URL
  13. thinking: enabled
  14. reasoningEffort: max
  15. defaultContextWindow: 256000
  16. models:
  17. - id: deepseek-v4-flash
  18. - id: deepseek-v4-pro
  19. # The default composition confines bash AND the filesystem tools to the
  20. # workspace and asks before a wider retry. Snapshot runs select
  21. # danger-full-access so the established scenarios remain runner-independent;
  22. # DSH_PERMISSION_MODE provides the same explicit deployment/test override
  23. # outside the snapshot harness. The sandbox default + fallback root live on
  24. # ctx.sandboxPolicy; agent calls resolve both families against the session cwd.
  25. - id: sandbox
  26. name: '@deepseek-ai/dsh-sandbox-local'
  27. - id: sandbox-policy
  28. name: '@deepseek-ai/dsh-sandbox-policy'
  29. config:
  30. mode: !!js "process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')"
  31. workspaceRoot: !!js process.cwd()
  32. # Managed child-process groups for the bash executor (spawn/kill/output plumbing).
  33. - id: subprocess
  34. name: '@deepseek-ai/dsh-subprocess-local'
  35. - id: bash
  36. name: '@deepseek-ai/dsh-bash-sandbox'
  37. config:
  38. timeoutMs: 60000
  39. - id: approval
  40. name: '@deepseek-ai/dsh-user-approval'
  41. config:
  42. policy: !!js "(process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')) === 'danger-full-access' ? 'never' : 'ask'"
  43. # The ACP automation app: agent spine + JSONL persistence + protocol bridge.
  44. # Persistence root: $DSH_SNAPSHOT_SESSIONS_ROOT when the snapshot harness sets it
  45. # (so it can harvest / isolate the log), else ./.sessions for the demo.
  46. # Snapshot modes use raw JSONL fixtures; ordinary runs keep the compressed default.
  47. - id: acp-agent
  48. name: '@deepseek-ai/dsh-acp-demo'
  49. config:
  50. provider: deepseek
  51. model: deepseek-v4-pro
  52. persistenceRoot: !!js process.env.DSH_SNAPSHOT_SESSIONS_ROOT ?? './.sessions'
  53. persistenceCompression: !!js "process.env.DSH_SNAPSHOT === undefined ? 'zstd' : 'none'"
  54. workspaceContext:
  55. maxBytes: 65536
  56. # Keep the persona to identity and behavior; tool plugins own tool guidance.
  57. # The loop resolves {{model}} and each ACP session's client-supplied {{cwd}}.
  58. persona: |
  59. You are a coding assistant powered by the {{model}} model. Your working directory is {{cwd}}. Your bash tool runs under a file sandbox — a `[sandbox: file access denied …]` result is policy, not a command bug.
  60. Verify your work by running the code or tests. Keep answers brief and factual.
  61. # Replay-aware request pressure; the routed adapter supplies model capacity.
  62. - id: token-meter
  63. name: '@deepseek-ai/dsh-token-meter'
  64. # Summarize an older range after measured pressure or a canonical provider overflow.
  65. # Ratios scale against the routed model's context window.
  66. - id: compact-basic
  67. name: '@deepseek-ai/dsh-compact-basic'
  68. config:
  69. thresholdRatio: 0.8
  70. retainRatio: 0.08
  71. maxTokens: 8192
  72. compactionRetries: 1
  73. # Expose fresh-child `spawn` and completed-prefix `fork` through separate tool
  74. # names so multi-child scenarios exercise both transports. These leaves follow
  75. # the app because it provides `ctx.agents` and `ctx.tools`.
  76. - id: subagent
  77. name: '@deepseek-ai/dsh-subagent'
  78. - id: subagent-spawn
  79. name: '@deepseek-ai/dsh-subagent-spawn'
  80. config:
  81. providerName: spawn
  82. - id: subagent-fork
  83. name: '@deepseek-ai/dsh-subagent-fork'
  84. config:
  85. providerName: fork
  86. - id: tool-subagent
  87. name: '@deepseek-ai/dsh-tool-subagent'
  88. config:
  89. provider: spawn
  90. toolName: subagent
  91. maxDepth: 1
  92. - id: tool-subagent-fork
  93. name: '@deepseek-ai/dsh-tool-subagent'
  94. config:
  95. provider: fork
  96. toolName: subagent_fork
  97. maxDepth: 1
  98. # The worker-thread workflow engine fans a model-written JavaScript script's
  99. # `agent()` calls out through the spawn backend; the adjacent tool exposes it to the model.
  100. - id: workflow-workerthread
  101. name: '@deepseek-ai/dsh-workflow-workerthread'
  102. config:
  103. provider: spawn
  104. - id: tool-workflow
  105. name: '@deepseek-ai/dsh-tool-workflow'
  106. - id: tool-ralph
  107. name: '@deepseek-ai/dsh-tool-ralph'
  108. # `todo_write` replaces the logged whole list for later model requests.
  109. - id: tool-todo
  110. name: '@deepseek-ai/dsh-tool-todo'
  111. # Identical repeat calls trigger advisory context, never a block, at the default
  112. # thresholds [3, 5, 8]. Only the repeat-tool-guard snapshot scenario reaches them.
  113. - id: repeat-tool-guard
  114. name: '@deepseek-ai/dsh-repeat-tool-guard'
  115. # The filesystem stack rides the SAME sandbox policy as bash: dsh-fs-sandbox
  116. # replaces dsh-fs-local behind ctx.fs and fences write/edit by the effective
  117. # mode (read-only denies, workspace-write contains to the workspace + temp
  118. # roots, danger-full-access passes through), so read/write/edit are available
  119. # under every mode. fs-policy (read-before-edit) composes orthogonally on top.
  120. - id: fs-sandbox
  121. name: '@deepseek-ai/dsh-fs-sandbox'
  122. config:
  123. cwd: !!js process.cwd()
  124. - id: fs-policy
  125. name: '@deepseek-ai/dsh-fs-policy'
  126. - id: tool-fs
  127. name: '@deepseek-ai/dsh-tool-fs'
  128. # `configPath` is read once at load and resolves from the server launch cwd, not
  129. # `session/new.cwd`; one `hooks.json` therefore applies to every session and a
  130. # project-local file is not discovered. Missing config registers nothing. Hook
  131. # commands still run in the session cwd. Warnings use `ctx.logger`, never stdout;
  132. # see packages/hooks/hooks-claude/README.md for the deferred per-session design.
  133. - id: hooks-claude
  134. name: '@deepseek-ai/dsh-hooks-claude'
  135. config:
  136. configPath: ./hooks.json
  137. # Codex uses its own `codex-hooks.json` and snake_case five-event dialect; it
  138. # cannot share Claude's file. It has the same process-level, read-once, missing-is-no-op,
  139. # logger-only contract. Shipping both bridges lets a scenario seed and exercise either dialect.
  140. - id: hooks-codex
  141. name: '@deepseek-ai/dsh-hooks-codex'
  142. config:
  143. configPath: ./codex-hooks.json