An R process that keeps variables and loaded packages between calls in one
agent's conversation. Register $tools() on the agent to give the model a
run_r_code tool that uses it. Calls run in order and return promises, so
other conversations aren't blocked.
The process runs with your user account's access to files and the network;
it is not an OS sandbox. The default permissions deny the tool; allow it
with r_code = TRUE in Permissions(). $run() runs code directly,
without permission checks. See vignette("code-execution").
The process doesn't inherit your environment variables, and R there doesn't
read .Renviron. It gets the variables that locate programs, libraries,
locales and temporary files, such as PATH, HOME, LANG and TMPDIR,
plus the ones you name in env.
This keeps keys out of what the code is given, not out of its reach: code
running as your user account can still read your R session's starting
environment through the operating system, and any file your account can
read, .Renviron included. To keep keys from the code, run it under an
account that can't read them, or in a sandbox.
Working directory and resets
Each call starts in the agent's working directory; setwd() lasts until
the next call. $cancel() and timeouts kill the R process and discard its
variables and queued calls; the next call starts fresh and says so. Effects
outside R, such as written files, are not undone. The session belongs to one
agent and stops accepting calls if the agent's session changes. Call
$close() when the conversation ends.
Results and saved conversations
Each result holds ellmer text and image content, HTML for display, and an
extra$deputy_r record of the call. Saved turns keep the code, output and
plots but not the variables, which must be recreated after a restart. Agent
snapshots keep only the current model context, so with compaction, store the
full display history yourself. Base, ggplot2, grid and patchwork plots are
captured; htmlwidgets and rich HTML tables report unsupported_output, so
print the data instead.
Calling agent tools from R
With tools = c("name"), code run through the agent's run_r_code tool can
call tools$name(...). The calls go through the agent's permissions, hooks
and usage limits, and their events carry parent_tool_call_id. Selected
tools must already be registered on the agent, use convert = FALSE and
validate their raw JSON arguments; run_r_code itself can't be selected. R
gets the tool's original return value, even if a PostToolUse hook sets
updated_tool_output. A call must finish within the remaining timeout,
or the session resets.
With selected tools, $run() is unavailable and the agent can't have an
approval_dir. Requests are limited to 256 KiB and results to 8 MiB
serialized. The tool functions run in your main R process; selecting them
doesn't limit what the R code can do.
Methods
RSession$new()
Create a session. The R process starts on the first call.
Arguments
agentThe agent that owns the session.
timeoutMaximum seconds for each call. A call that takes longer resets the session.
startup_timeoutMaximum seconds for the R process to start.
queue_limitMaximum number of calls waiting behind the running one.
max_output_bytesMaximum bytes of output kept per call. This limits captured output, not memory use.
plot_width, plot_heightPNG plot size in pixels, at most 4096.
toolsNames of tools registered on
agentthat R code may call astools$<name>(...). None by default.envThe names of other environment variables the R code may read, such as
c("HTTPS_PROXY", "NO_PROXY")behind a proxy."inherit"passes your whole environment, including every key it holds.libpathThe library directories the R process loads packages from, searched in order.
NULLuses your session's.libPaths()each time a process starts.
RSession$run()
Run code directly, without the agent's permissions or
hooks. Errors at once if code is invalid or the queue is full.
Returns
A promise for an ellmer::ContentToolResult. R errors, crashes
and cancelled calls resolve to a result that describes them.