supervisor

package
v1.0.0-rc.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: AGPL-3.0, AGPL-3.0-or-later Imports: 17 Imported by: 0

Documentation

Index

Constants

View Source
const (
	HostCodex      = "codex"
	HostClaudeCode = "claude-code"
	HostOpenCode   = "opencode"
)

Supervised host names (CAL-V0-074, CAL-V0-076). A capsule, config or policy without a host is Codex, so Codex bytes stay unchanged.

View Source
const MaxCapsule = 1 << 20
View Source
const MaxHostOutput = 16 << 10
View Source
const MaxRuntime = 256 << 20

MaxRuntime bounds a pinned runtime's bytes.

Variables

This section is empty.

Functions

func Digest

func Digest(b []byte) string

func DirectoryIdentity

func DirectoryIdentity(path string) (string, error)

func LaunchableExecutable

func LaunchableExecutable(path string) ([]byte, os.FileMode, error)

LaunchableExecutable is the launch-time check on a pinned runtime path: an absolute path naming a regular file with an execute bit, never a symlink, whose bounded bytes and permission bits it returns. The type, mode and bytes all come from one descriptor opened without following a final symlink, so no second path lookup can substitute another file. Admission and ValidateCapsule share it, so an admitted program is never refused at launch for the executable's type (CAL-V0-074).

func Leader

func Leader(ctx context.Context, dir, hash string) error

Leader may run the runtime only after the exact immutable acknowledgment. It executes the object it verified: a root-protected runtime by its path, otherwise a private copy of the verified bytes written before boot into the private protocol directory, so replacing or rewriting the pinned path while the supervisor acknowledges cannot change what runs (CAL-V0-074).

func ObservedClaudeSession

func ObservedClaudeSession(raw []byte) string

ObservedClaudeSession is the bounded session of a Claude Code result object, or "" when the output is not one.

func ObservedClaudeUsage

func ObservedClaudeUsage(raw []byte) (uint64, uint64, bool)

ObservedClaudeUsage admits integer input and output counters from the result object's usage. Input adds the cache creation and cache read counters when present, so it counts all input as Codex's counter does. A missing or non-integer counter, or an overflow, leaves usage unobserved.

func ObservedOpenCodeSession

func ObservedOpenCodeSession(raw []byte) string

ObservedOpenCodeSession is the one bounded session an OpenCode stream names, or "" when the output is not a qualified stream.

func ObservedOpenCodeUsage

func ObservedOpenCodeUsage(raw []byte) (uint64, uint64, bool)

ObservedOpenCodeUsage sums the token counters of every finished step. The counters are disjoint, so input is input plus cache read and cache write, and output is output plus reasoning. Usage is known only when accounting is complete: a stream with a host error (whose failed step reports no tokens), a step started but never finished (an interrupted or truncated run), a last step that did not finish with "stop", a missing or non-integer counter, an overflow, or output that fills the retained bound (the host may have written more than was kept, even if the kept prefix ends on a stop step) leaves usage unobserved. Only the retained bytes decide, so the store and the native transition derive the same usage.

func ObservedSession

func ObservedSession(raw []byte) string

func ObservedUsage

func ObservedUsage(raw []byte) (uint64, uint64, bool)

ObservedUsage admits only complete integer usage counters from the qualified turn-completed event. Missing dimensions remain unobserved.

func ProcessIdentity

func ProcessIdentity(pid int) (string, error)

func Publish

func Publish(dir, name string, v any) error

Publish links a synced private temporary inode into an absent final name. A collision never authorizes overwriting a boot or acknowledgment.

func ReadBounded

func ReadBounded(path string, max int) ([]byte, error)

func Recover

func Recover(boot Boot) bool

Recover drains only a retained leader/start binding. Absence is checked at the kernel group boundary; a reused or escaped identity remains uncertain.

func RecoverHost

func RecoverHost(dir string, boot Boot) bool

RecoverHost drains a prior run's retained leader group (CAL-V0-077). A detached host's recovery is never proved: an escape started after the discovery snapshot, or orphaned before it, has no link to the retained group, and no witness that survives the supervisor's crash (the host output pipes are gone with it) proves its absence. Recovery still drains every escape it can observe, then reports quiescence uncertain.

func ValidateCapsule

func ValidateCapsule(c Capsule) error

Types

type Ack

type Ack struct {
	Boot     Boot `json:"boot"`
	Accepted bool `json:"accepted"`
}

type Boot

type Boot struct {
	Effect  string `json:"effect"`
	PID     int    `json:"pid"`
	Started string `json:"started"`
}

func RecoveryBoot

func RecoveryBoot(dir, effect string, retained Boot) (Boot, error)

type Capsule

type Capsule struct {
	Profile          string   `json:"profile"`
	Effect           string   `json:"effect"`
	Executable       string   `json:"executable"`
	ExecutableSHA256 string   `json:"executableSha256"`
	Argv             []string `json:"argv"`
	Env              []string `json:"env"`
	Directory        string   `json:"directory"`
	Prompt           string   `json:"prompt"`
	// Host selects the result vocabulary (CAL-V0-074); absent is Codex, so
	// Codex capsule bytes are unchanged.
	Host string `json:"host,omitempty"`
}

type HostResult

type HostResult struct {
	Accepted   bool     `json:"accepted,omitempty"`
	Claims     []string `json:"claims,omitempty"`
	Question   string   `json:"question,omitempty"`
	Kind       string   `json:"kind"`
	Summary    string   `json:"summary"`
	NextAction string   `json:"nextAction"`
}

func DecodeClaudeResult

func DecodeClaudeResult(raw []byte) (string, HostResult, error)

DecodeClaudeResult decodes the Claude Code result object (CAL-V0-075): a successful, non-error result carrying a bounded session and a result string that strictly decodes to the minimum handoff.

func DecodeEvents

func DecodeEvents(raw []byte) (string, HostResult, error)

func DecodeOpenCodeEvents

func DecodeOpenCodeEvents(raw []byte) (string, HostResult, error)

DecodeOpenCodeEvents decodes an OpenCode run (CAL-V0-077): one constant bounded session, no host error, a final step that finished with reason "stop", and a last text part, inside a finished step, that strictly decodes to the minimum handoff.

type Journal

type Journal func(phase string, boot Boot, out *Outcome) error

type Outcome

type Outcome struct {
	Result                         HostResult
	Class, SessionID, OutputSHA256 string
	Clean                          bool
	Stdout, Stderr                 []byte
	Boot                           Boot
}

func Run

func Run(ctx context.Context, self, dir string, c Capsule, journal Journal) (out Outcome, err error)

Run commits SPAWNING before fork and RUNNING before immutable ack:true. A refusal before the fork is a *PrelaunchError with an empty outcome; any later error, including one with an empty class, may follow a spawn.

type PrelaunchError

type PrelaunchError struct{ Err error }

PrelaunchError is a Run refusal made before the lane leader is forked: no host process exists or can exist for it. Every other Run error may follow a spawn, so only this one lets a caller settle the stage as NO_EXEC (CAL-V0-074).

func (*PrelaunchError) Error

func (e *PrelaunchError) Error() string

func (*PrelaunchError) Unwrap

func (e *PrelaunchError) Unwrap() error

type Vocabulary

type Vocabulary struct {
	Decode             func([]byte) (string, HostResult, error)
	Session            func([]byte) string
	Usage              func([]byte) (uint64, uint64, bool)
	Detached           bool
	DetachedEnv        []string
	InterruptedSession bool
}

Vocabulary reads one supervised host's retained standard output: the handoff result of a zero exit, the host session, and token usage.

A Detached host starts helper processes in process groups of their own, outside the supervisor-owned group (CAL-V0-077). Its capsule must carry every DetachedEnv entry, and Run discovers, drains and proves gone those groups before it reports a clean stop.

An InterruptedSession host reports its session as its run starts, so a stage stopped at its wall still names the session a checkpointed continuation resumes (CAL-V0-089). A host that reports its session only in its final result cannot continue an interrupted stage.

func HostVocabulary

func HostVocabulary(host string) (Vocabulary, bool)

HostVocabulary returns the vocabulary of host; "" is Codex. An unknown host has none.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL