prototype: incubate content-addressed catalog admission - #55
Conversation
agent-session-id: cdd15622-c01a-4731-bbfe-ab8cce0cad54 agent-tool: Codex CLI agent-tool-version: 0.145.0 agent-model: unknown agent-runtime-profile: /nix/store/ph8rlhdj25mg71v81jsfzy6dq4xpcs9m-coding-agent-runtime-profile/share/coding-agents/profile.json agent-skills-manifest: /nix/store/lsykz8x5481xrpbgk280xh3pypk1c5jy-agent-skills-corpus/share/agent-skills/manifest.json tooling-profile: dotfiles@3649b53
|
@schickling-assistant — owner handoff for the existing fork branch only
Please keep PR #55 DRAFT. No merge or adoption is authorized. |
|
Two questions before starting items 1 and 2, because current To find out what the refresh actually involves, I rebased the existing fork branch onto current The conflict set against current
Question 1 — Should item 2 be understood to include that port for Question 2 — Resolving that hunk toward the branch would remove those call sites, and because the retained-directory path resolves through How would you like Happy to proceed on items 1 and 2 as soon as these two are settled. The remaining three conflicts ( Posted on behalf of @schickling
|
|
Superseded by current transactional publication, desired-input digest, mediated authoring, and authoritative graph validation. The prototype's second catalog/CAS authority is no longer applicable. Posted on behalf of @schickling
|
Why
The recursive mutable
agent.kdlcatalog has no transaction boundary for afleet assembled by independent static and dynamic publishers. Per-seat file
swaps cannot express an atomic multi-seat change, and declaration provenance is
currently coupled to mutable message/context/status state.
This draft incubates the smallest executable slice of #52. It is a prototype,
not an accepted storage or lifecycle contract.
What
manager fencing, and operation replay;
SeatAdmissionjoins;AgentSpec.pathfrom stable mutableAgentSpec.agent_dir;catalog prepare|stage|admit|publish|head|inspect;Static and dynamic publishers can update their own seats through the same root
protocol. A root transaction records its actor but does not take custody of
foreign seats.
Safety properties exercised
traversal, cross-seat joins, duplicate/reserved/symlinked state roots, and
corrupt selected objects fail closed;
Validation
nix flake check --print-build-logscargo test --lib catalog_store::tests: 8 passedcargo test --test catalog_cli: 1 passed-D warnings8/0
Deliberate limits
This slice does not integrate the experimental root with resident discovery or
reconciliation. It does not provide a content-addressed render-input bundle,
typed resource contracts, authenticated managers, realization/replacement,
power-loss durability proof, GC, replication, or a daemon control API.
Content-addressed custody assumes the repository's trusted same-user model;
single-FD verify/use sealing remains follow-up hardening.
Companion eval PR: compoundingtech/evals#39.
Closes no issue; incubates #52 and refines #41.
Plain-folder portability target (currently RED)
The acceptance boundary is an ordinary recursively copied or file-synced
catalog folder. That folder alone must support offline inspection and recovery
of the last complete valid activation. Authoring stays as ordinary KDL and
catalog resources; CAS data is additive under the single catalog-owned
.st2/catalog-v1directory, never under per-agent.st2directories.The current prototype does not meet this target. Its mutable
.st2/catalog-v1/rootcan arrive before its referenced object closure, andinspectthen fails on missing or corrupt selected objects instead of fallingback to the previous complete activation. The current head is therefore
incubation evidence, not an accepted LKG or portability implementation.
The smallest next slice is read-only inspection/activation fallback: publish
immutable versioned activation records, select the newest complete valid
closure, and fall back to an older complete valid activation. It must not
broaden resident discovery or reconciliation.
Pre-registered adversarial gates
These model-free gates are RED requirements before code is broadened:
the complete new closure is valid, then selects it without a mixed view.
The slice cannot depend on a database, daemon, reachable peer, consensus,
online service, or special copy order. It includes no physical GC or remote
delete propagation. Future GC must preserve selected/fallback closures and
leave a standalone ordinary folder.
Posted on behalf of @schickling
agent_nameagent_session_idagent_toolagent_tool_versionagent_runtimeagent_modelruntime_profileskills_manifestworktreemachinetooling_profile