[Bug]: tools/pre-execute 等 waterfall 被坏监听器短路后,所有工具返回 Cannot read properties of undefined (reading 'kind')——需要一个消费侧防护与不变式 #4906
Replies: 3 comments
|
I documented the operator-side failure boundary in the handbook tool execution pipeline guide: when a tools/pre-execute waterfall listener does not call next(), the shared gate can resolve undefined and make every tool fail. The guide includes a minimal-profile A/B and fail-closed diagnosis: https://github.com/sandbaseai/deepseek-harness-handbook/blob/main/docs/en/architecture/tool-execution-pipeline.md\n\nLatest release: https://github.com/sandbaseai/deepseek-harness-handbook/releases/tag/v0.5.263 |
|
Correction: the canonical source link is https://github.com/sandbaseai/deepseek-harness-handbook/blob/main/docs/en/architecture/tool-execution-pipeline.md . The Pages site does not currently expose a dedicated HTML route for this architecture page. |
|
Follow-up: v0.5.298 refines the Tool Execution Pipeline guide with the waterfall short-circuit evidence and a fail-closed pre-execute decision contract. It keeps plugin compatibility failures visible instead of flattening them into generic gate.kind errors: https://github.com/sandbaseai/deepseek-harness-handbook/releases/tag/v0.5.298 |
Uh oh!
There was an error while loading. Please reload this page.
问题及现象:
在 web profile 安装 dshmarketplace-plugin@0.1.5 插件后,dsh 调用任何工具都显示

Error: Cannot read properties of undefined (reading 'kind');此问题只发生在包含 dshmarketplace-plugin 的 web profile;纯 dsh-base + dsh-headless 的 headless profile 不受影响。:根因
dshmarketplace-plugin@0.1.5(实测 0.1.6 同样存在,逐字节对比确认)注册了一个全局
tools/pre-execute瀑布监听器(lib/index.js):tools/pre-execute的payload是ToolExecution,只有name/arguments/agent/signal等,没有.tool属性,导致t?.tool?.name !== 'dshmarketplace_install'对任何调用恒为真,进而,监听器对每个工具都直接return undefined。next()。而waterfall语义是 "不调next()即否决整条链"(vendor/cordis/src/events.ts 内代码注释: "A listener that does not call next() vetoes the rest of the chain, including the built-in behavior")。所以内置的默认handler({ kind: 'allow' })永远轮不到执行,瀑布最终返回undefined。packages/core/tools/src/index.ts的prepareExecution中读取返回值:TypeError被外层 catch 捕获并变成该工具的错误结果,于是每次调用都返回同样的错误结果。影响面:一个插件坏,全产品工具失灵
tools/pre-execute是全产品工具执行的必经点。任何非 scoped、且不调next()就返回的监听器,都是对所有 agent 的所有工具的单点故障。这暴露了工具管线对第三方插件监听器的零防御。建议 DeepSeek Harness 侧做的防护
虽然问题是第三方插件引入的,但也暴露了
tools/pre-execute的容错性低的问题,因此建议 DeepSeek Harness 做防护性修改:prepareExecution中校验瀑布返回值。gate 必须是一个合法 PreToolDecision(allow/deny/ask);若为 undefined 或形状非法,应当:reading 'kind'。当前行为 把 TypeError 当工具错误结果返回 虽然进程不崩,但对模型不可恢复、且掩盖真实的出错方。
PreToolDecision。这样同类短路会在不变式诊断中直接显现。All reactions