70 lines
1.9 KiB
YAML
70 lines
1.9 KiB
YAML
|
|
# Keyless real-Loader composition for the parent-only override inheritance
|
||
|
|
# snapshot. The deployment default stays WIDE (workspace-write) while the
|
||
|
|
# seeded parent session carries a session-scoped read-only override; the
|
||
|
|
# resumed parent delegates, and only the inheritance capture can confine the
|
||
|
|
# child — remove it and the child writes successfully under the deployment
|
||
|
|
# default, so this scenario is the assembled-app red/green anchor for the
|
||
|
|
# delegation bypass.
|
||
|
|
|
||
|
|
- id: persistence
|
||
|
|
name: '@deepseek-ai/dsh-session-persistence-jsonl'
|
||
|
|
config:
|
||
|
|
root: './.sessions'
|
||
|
|
compression: none
|
||
|
|
|
||
|
|
# file/override/childFiles all default to their DSH_SNAPSHOT_* env vars.
|
||
|
|
- id: replay
|
||
|
|
name: '@deepseek-ai/dsh-llm-replay'
|
||
|
|
|
||
|
|
- id: bash
|
||
|
|
name: '@deepseek-ai/dsh-bash-local'
|
||
|
|
config:
|
||
|
|
timeoutMs: 60000
|
||
|
|
|
||
|
|
# The confining filesystem stack: the wide deployment default lives on the
|
||
|
|
# shared policy home; the seeded parent's read-only override must beat it
|
||
|
|
# INSIDE the child for the scenario to deny.
|
||
|
|
- id: sandbox-policy
|
||
|
|
name: '@deepseek-ai/dsh-sandbox-policy'
|
||
|
|
config:
|
||
|
|
mode: workspace-write
|
||
|
|
workspaceRoot: !!js process.cwd()
|
||
|
|
|
||
|
|
- id: fs-sandbox
|
||
|
|
name: '@deepseek-ai/dsh-fs-sandbox'
|
||
|
|
|
||
|
|
- id: fs-policy
|
||
|
|
name: '@deepseek-ai/dsh-fs-policy'
|
||
|
|
|
||
|
|
- id: tool-fs
|
||
|
|
name: '@deepseek-ai/dsh-tool-fs'
|
||
|
|
|
||
|
|
- id: agent
|
||
|
|
name: '@deepseek-ai/dsh-agent-spine-demo'
|
||
|
|
config:
|
||
|
|
agents: []
|
||
|
|
workspaceContext: false
|
||
|
|
skills:
|
||
|
|
enabled: false
|
||
|
|
toolTasks: false
|
||
|
|
goals: false
|
||
|
|
|
||
|
|
- id: subagent
|
||
|
|
name: '@deepseek-ai/dsh-subagent'
|
||
|
|
|
||
|
|
- id: subagent-spawn
|
||
|
|
name: '@deepseek-ai/dsh-subagent-spawn'
|
||
|
|
config:
|
||
|
|
providerName: spawn
|
||
|
|
|
||
|
|
- id: tool-subagent
|
||
|
|
name: '@deepseek-ai/dsh-tool-subagent'
|
||
|
|
config:
|
||
|
|
provider: spawn
|
||
|
|
toolName: subagent
|
||
|
|
maxDepth: 1
|
||
|
|
|
||
|
|
# Await the persisted resume before the headless driver inspects root agents.
|
||
|
|
- id: resumed-agent
|
||
|
|
name: './tests/fixtures/subagent-inheritance-agent.ts'
|