Documentation
¶
Index ¶
- Constants
- func Digest(b []byte) string
- func DirectoryIdentity(path string) (string, error)
- func LaunchableExecutable(path string) ([]byte, os.FileMode, error)
- func Leader(ctx context.Context, dir, hash string) error
- func ObservedClaudeSession(raw []byte) string
- func ObservedClaudeUsage(raw []byte) (uint64, uint64, bool)
- func ObservedOpenCodeSession(raw []byte) string
- func ObservedOpenCodeUsage(raw []byte) (uint64, uint64, bool)
- func ObservedSession(raw []byte) string
- func ObservedUsage(raw []byte) (uint64, uint64, bool)
- func ProcessIdentity(pid int) (string, error)
- func Publish(dir, name string, v any) error
- func ReadBounded(path string, max int) ([]byte, error)
- func Recover(boot Boot) bool
- func RecoverHost(dir string, boot Boot) bool
- func ValidateCapsule(c Capsule) error
- type Ack
- type Boot
- type Capsule
- type HostResult
- type Journal
- type Outcome
- type PrelaunchError
- type Vocabulary
Constants ¶
const ( HostCodex = "codex" HostClaudeCode = "claude-code" HostOpenCode = "opencode" )
Supervised host names (CAL-V0-074, CAL-V0-076). A capsule, config or policy without a host is Codex, so Codex bytes stay unchanged.
const MaxCapsule = 1 << 20
const MaxHostOutput = 16 << 10
const MaxRuntime = 256 << 20
MaxRuntime bounds a pinned runtime's bytes.
Variables ¶
This section is empty.
Functions ¶
func DirectoryIdentity ¶
func LaunchableExecutable ¶
LaunchableExecutable is the launch-time check on a pinned runtime path: an absolute path naming a regular file with an execute bit, never a symlink, whose bounded bytes and permission bits it returns. The type, mode and bytes all come from one descriptor opened without following a final symlink, so no second path lookup can substitute another file. Admission and ValidateCapsule share it, so an admitted program is never refused at launch for the executable's type (CAL-V0-074).
func Leader ¶
Leader may run the runtime only after the exact immutable acknowledgment. It executes the object it verified: a root-protected runtime by its path, otherwise a private copy of the verified bytes written before boot into the private protocol directory, so replacing or rewriting the pinned path while the supervisor acknowledges cannot change what runs (CAL-V0-074).
func ObservedClaudeSession ¶
ObservedClaudeSession is the bounded session of a Claude Code result object, or "" when the output is not one.
func ObservedClaudeUsage ¶
ObservedClaudeUsage admits integer input and output counters from the result object's usage. Input adds the cache creation and cache read counters when present, so it counts all input as Codex's counter does. A missing or non-integer counter, or an overflow, leaves usage unobserved.
func ObservedOpenCodeSession ¶
ObservedOpenCodeSession is the one bounded session an OpenCode stream names, or "" when the output is not a qualified stream.
func ObservedOpenCodeUsage ¶
ObservedOpenCodeUsage sums the token counters of every finished step. The counters are disjoint, so input is input plus cache read and cache write, and output is output plus reasoning. Usage is known only when accounting is complete: a stream with a host error (whose failed step reports no tokens), a step started but never finished (an interrupted or truncated run), a last step that did not finish with "stop", a missing or non-integer counter, an overflow, or output that fills the retained bound (the host may have written more than was kept, even if the kept prefix ends on a stop step) leaves usage unobserved. Only the retained bytes decide, so the store and the native transition derive the same usage.
func ObservedSession ¶
func ObservedUsage ¶
ObservedUsage admits only complete integer usage counters from the qualified turn-completed event. Missing dimensions remain unobserved.
func ProcessIdentity ¶
func Publish ¶
Publish links a synced private temporary inode into an absent final name. A collision never authorizes overwriting a boot or acknowledgment.
func Recover ¶
Recover drains only a retained leader/start binding. Absence is checked at the kernel group boundary; a reused or escaped identity remains uncertain.
func RecoverHost ¶
RecoverHost drains a prior run's retained leader group (CAL-V0-077). A detached host's recovery is never proved: an escape started after the discovery snapshot, or orphaned before it, has no link to the retained group, and no witness that survives the supervisor's crash (the host output pipes are gone with it) proves its absence. Recovery still drains every escape it can observe, then reports quiescence uncertain.
func ValidateCapsule ¶
Types ¶
type Boot ¶
type Capsule ¶
type Capsule struct {
Profile string `json:"profile"`
Effect string `json:"effect"`
Executable string `json:"executable"`
ExecutableSHA256 string `json:"executableSha256"`
Argv []string `json:"argv"`
Env []string `json:"env"`
Directory string `json:"directory"`
Prompt string `json:"prompt"`
// Host selects the result vocabulary (CAL-V0-074); absent is Codex, so
// Codex capsule bytes are unchanged.
Host string `json:"host,omitempty"`
}
type HostResult ¶
type HostResult struct {
Accepted bool `json:"accepted,omitempty"`
Claims []string `json:"claims,omitempty"`
Question string `json:"question,omitempty"`
Kind string `json:"kind"`
Summary string `json:"summary"`
NextAction string `json:"nextAction"`
}
func DecodeClaudeResult ¶
func DecodeClaudeResult(raw []byte) (string, HostResult, error)
DecodeClaudeResult decodes the Claude Code result object (CAL-V0-075): a successful, non-error result carrying a bounded session and a result string that strictly decodes to the minimum handoff.
func DecodeEvents ¶
func DecodeEvents(raw []byte) (string, HostResult, error)
func DecodeOpenCodeEvents ¶
func DecodeOpenCodeEvents(raw []byte) (string, HostResult, error)
DecodeOpenCodeEvents decodes an OpenCode run (CAL-V0-077): one constant bounded session, no host error, a final step that finished with reason "stop", and a last text part, inside a finished step, that strictly decodes to the minimum handoff.
type Outcome ¶
type Outcome struct {
Result HostResult
Class, SessionID, OutputSHA256 string
Clean bool
Stdout, Stderr []byte
Boot Boot
}
func Run ¶
func Run(ctx context.Context, self, dir string, c Capsule, journal Journal) (out Outcome, err error)
Run commits SPAWNING before fork and RUNNING before immutable ack:true. A refusal before the fork is a *PrelaunchError with an empty outcome; any later error, including one with an empty class, may follow a spawn.
type PrelaunchError ¶
type PrelaunchError struct{ Err error }
PrelaunchError is a Run refusal made before the lane leader is forked: no host process exists or can exist for it. Every other Run error may follow a spawn, so only this one lets a caller settle the stage as NO_EXEC (CAL-V0-074).
func (*PrelaunchError) Error ¶
func (e *PrelaunchError) Error() string
func (*PrelaunchError) Unwrap ¶
func (e *PrelaunchError) Unwrap() error
type Vocabulary ¶
type Vocabulary struct {
Decode func([]byte) (string, HostResult, error)
Session func([]byte) string
Usage func([]byte) (uint64, uint64, bool)
Detached bool
DetachedEnv []string
InterruptedSession bool
}
Vocabulary reads one supervised host's retained standard output: the handoff result of a zero exit, the host session, and token usage.
A Detached host starts helper processes in process groups of their own, outside the supervisor-owned group (CAL-V0-077). Its capsule must carry every DetachedEnv entry, and Run discovers, drains and proves gone those groups before it reports a clean stop.
An InterruptedSession host reports its session as its run starts, so a stage stopped at its wall still names the session a checkpointed continuation resumes (CAL-V0-089). A host that reports its session only in its final result cannot continue an interrupted stage.
func HostVocabulary ¶
func HostVocabulary(host string) (Vocabulary, bool)
HostVocabulary returns the vocabulary of host; "" is Codex. An unknown host has none.