feat(my-deepagent): v0.1.0 Step 0~5 — scaffolding through deepagent + OpenRouter

Python rewrite of the agent harness on top of deepagents 0.6.1 + langchain 1.x,
replacing the abandoned TS attempt in packages/. 388 unit/integration tests pass.

Steps
-----
0. Scaffolding — uv workspace, ruff/mypy/pre-commit/alembic, src/tests/docs
   trees with docs/schemas/ seeded from my-deepagent-seed/.
1. Core — config (pydantic-settings with MYDEEPAGENT_ env prefix and TOML
   source), enums (Backend, Capability, RiskLevel, ApprovalDecisionAction,
   ApprovalState, RunState, RunPhaseState, SessionState, ErrorClass),
   errors (MyDeepAgentError + BudgetExhaustedError with PEP-3134 cause +
   context suppression), hash (canonical JSON + sha256).
2. Persona/Workflow/Binding — pydantic v2 schemas with tuple-based deep
   immutability (post-construction hash drift prevented), YAML loaders,
   deterministic auto-select (preferred_backends → version → name → hash),
   override resolution with ineligibility diagnostics, PersonaConsentStore
   with fcntl.flock + tmp+fsync+rename atomic write.
3. Artifact schema registry — Draft202012Validator, multi-root resolution,
   structured ValidationFinding output.
4. Persistence — 18 SQLAlchemy 2.0 async ORM models with FK CASCADE/RESTRICT,
   WAL + busy_timeout + foreign_keys PRAGMA, alembic baseline +
   ux_active_run_repo_base partial unique index, LangGraph SqliteSaver as
   context manager only (lifecycle safety).
5. DeepAgent session — build_agent wires Persona → create_deep_agent with
   LocalShellBackend / FilesystemBackend / StateBackend / CompositeBackend,
   ChatOpenAI(base_url=openrouter) for openrouter: model strings, and 4
   middleware classes (cost / audit-tool / safety-shell / fallback-model).

Critical workarounds
--------------------
- deepagents 0.6.1 rejects FilesystemPermission together with backends that
  implement SandboxBackendProtocol (LocalShellBackend). SafetyShellMiddleware
  enforces destructive-command and secret-path policy at the tool layer
  instead, and build_agent strips the permissions kwarg when the persona's
  deepagents_backend is local_shell.
- FilesystemOperation in deepagents is Literal['read', 'write'] only;
  _map_operations collapses our richer schema (read/write/edit/ls) safely.

Real OpenRouter smoke
---------------------
test_openrouter_deepagents_local_shell_smoke calls DeepSeek via deepagents +
LocalShellBackend + SafetyShellMiddleware end-to-end. PASS, ~$0.000001 cost,
input=9 / output=1 tokens with content "OK".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
chungyeong
2026-05-15 19:40:02 +09:00
parent 1fe59d16ca
commit 17ba5d723b
100 changed files with 12408 additions and 0 deletions

View File

@@ -0,0 +1,92 @@
"""All closed-set enums used across the codebase."""
from enum import StrEnum
class Backend(StrEnum):
OPENROUTER = "openrouter"
ANTHROPIC = "anthropic"
OPENAI = "openai"
GOOGLE = "google"
FAKE = "fake"
class Capability(StrEnum):
SPEC_WRITE = "spec_write"
PHASE_PLANNING = "phase_planning"
TASK_DAG_PLANNING = "task_dag_planning"
CODE_EDIT = "code_edit"
TEST_FIRST_DEVELOPMENT = "test_first_development"
CODE_REVIEW = "code_review"
EVIDENCE_CHECK = "evidence_check"
COMMAND_EXECUTE = "command_execute"
BACKTEST_RUN = "backtest_run"
METRIC_EXTRACT = "metric_extract"
FAILURE_MINING = "failure_mining"
OBJECTIVE_EVAL = "objective_eval"
FINAL_REPORT_COMPOSE = "final_report_compose"
class RiskLevel(StrEnum):
LOW = "low"
MEDIUM = "medium"
HIGH = "high"
class ApprovalDecisionAction(StrEnum):
APPROVE = "approve"
REJECT = "reject"
REQUEST_CHANGES = "request_changes"
ABORT = "abort"
class ApprovalState(StrEnum):
PENDING = "pending"
APPROVED = "approved"
REJECTED = "rejected"
CHANGES_REQUESTED = "changes_requested"
ABORTED = "aborted"
PAUSED = "paused"
class RunState(StrEnum):
CREATED = "created"
BOUND = "bound"
PLANNING = "planning"
AWAITING_APPROVAL = "awaiting_approval"
EXECUTING = "executing"
PAUSED = "paused"
COMPLETED = "completed"
FAILED = "failed"
ABORTED = "aborted"
class RunPhaseState(StrEnum):
PENDING = "pending"
RUNNING = "running"
AWAITING_ARTIFACT = "awaiting_artifact"
VALIDATING = "validating"
AWAITING_APPROVAL = "awaiting_approval"
COMPLETED = "completed"
FAILED = "failed"
SKIPPED = "skipped"
class SessionState(StrEnum):
CREATED = "CREATED"
BOOTSTRAPPING = "BOOTSTRAPPING"
READY = "READY"
BUSY = "BUSY"
WAITING_FOR_APPROVAL = "WAITING_FOR_APPROVAL"
ARTIFACT_TIMEOUT = "ARTIFACT_TIMEOUT"
HUNG = "HUNG"
CRASHED = "CRASHED"
RESUMING = "RESUMING"
REBOOTSTRAPPED = "REBOOTSTRAPPED"
FAILED_NEEDS_HUMAN = "FAILED_NEEDS_HUMAN"
class ErrorClass(StrEnum):
RECOVERABLE = "recoverable"
HUMAN_REQUIRED = "human_required"
FATAL = "fatal"