Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion crates/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -125,7 +125,7 @@ Boundary rule: if you need an upstream crate in a low-level crate, stop and chec
| `ironclaw_conversations` | `ironclaw_conversations/AGENTS.md`, `ironclaw_conversations/CLAUDE.md` | Conversation binding, session thread contracts, inbound/state store, libSQL/Postgres conversation persistence. | Capability runtime internals or UI transport. |
| `ironclaw_agent_loop` | `ironclaw_agent_loop/AGENTS.md`, `ironclaw_agent_loop/CLAUDE.md` | Agent-loop framework state, planner/executor, strategy/family contracts, test support. | Product adapters, transport, concrete provider auth. |
| `ironclaw_loop_host` | `ironclaw_loop_host/AGENTS.md`, `ironclaw_loop_host/CLAUDE.md` | Loop host support services: capability/input ports, allow sets, input queue, identity/skill context, cancellation. | Owning core loop strategy or runtime lane execution. |
| `ironclaw_capabilities` | `ironclaw_capabilities/AGENTS.md`, `ironclaw_capabilities/CLAUDE.md` | Caller-facing `CapabilityHost` invoke/resume/spawn workflow, obligation seams, conformance helpers. | Process lifecycle APIs, direct concrete runtime dependencies. |
| `ironclaw_capabilities` | `ironclaw_capabilities/AGENTS.md`, `ironclaw_capabilities/CLAUDE.md` | Caller-facing `CapabilityHost` invoke/resume/spawn workflow, obligation seams, conformance helpers, and the host-private `ReplayPayloadStore` (raw gate/auth resume replay payload, never model-visible). | Process lifecycle APIs, direct concrete runtime dependencies. |
| `ironclaw_engine` | `ironclaw_engine/AGENTS.md`, `ironclaw_engine/CLAUDE.md`, `ironclaw_engine/MONTY.md` | **v1-only (legacy — retires with the monolith).** The root crate's engine v2 (thread/capability/CodeAct: runtime manager, executor, gates, leases). Reborn crates are boundary-test-forbidden from importing it. | **Any new Reborn behavior.** Maintenance of existing v1 behavior only. |

### Product, adapters, Reborn binary
Expand Down
1 change: 1 addition & 0 deletions crates/ironclaw_capabilities/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@
- `CapabilityHost` (`host`) and the invoke/resume/spawn requests/results: `CapabilityInvocationRequest`/`CapabilityInvocationResult`, `CapabilityResumeRequest`, `CapabilitySpawnRequest`/`CapabilitySpawnResult` (`requests`); `CapabilityInvocationError`/`ResumeContextMismatchKind` (`error`).
- The obligation seam (`obligations`): `CapabilityObligationHandler`, `CapabilityObligationRequest`/`CapabilityObligationOutcome`, abort/completion requests, `CapabilityObligationPhase`/`CapabilityObligationFailureKind`/`CapabilityObligationError`.
- Capability-profile conformance evaluation (`conformance`): `CapabilityProfileClaim`/`CapabilityProfileClaimedOperation`, the conformance report/findings, and `evaluate_profile_conformance`.
- The host-private replay-payload store (`replay_payload`): `ReplayPayload`, the `ReplayPayloadStore` port, `FilesystemReplayPayloadStore`, and `ReplayPayloadStoreError`. Persists the raw replay payload a gate/auth resume re-dispatches from, keyed by `InvocationId`, behind a `ScopedFilesystem` CAS lane. Never model-visible (no `SafeSummary`) — see `CLAUDE.md`.
- Crate-local public API, tests, and fixtures needed to prove that ownership.

## Do Not Move In Here
Expand Down
1 change: 1 addition & 0 deletions crates/ironclaw_capabilities/CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,3 +8,4 @@
- Approval resume must validate and claim the matching fingerprinted lease before dispatch.
- Authorization denial or unsupported/failed obligations must fail before runtime dispatch, process start, or approval lease claim.
- Keep obligation handling behind a seam; built-in obligation implementations belong in later host-runtime/obligation slices.
- The `ReplayPayloadStore` (`replay_payload`) persists the **host-private** raw replay payload (tool `input`, `estimate`, prior-approval identity, input ref, correlation id) a gate/auth resume re-dispatches from, keyed by `InvocationId`. It is the opposite of a model-visible `GateRecord`: it carries no `SafeSummary` and must never reach the model, an event, an error, a snapshot, or a log — the record exists only for host-side re-dispatch. It lives here (not `ironclaw_run_state`, whose charter forbids raw replay input, nor `ironclaw_turns`, whose charter forbids raw tool input in turn state/events) because capabilities owns the invoke/resume workflow this payload serves. The `ironclaw_filesystem` / `ironclaw_turns` dependencies exist for this store: it persists behind a `ScopedFilesystem` over the shared `cas_update` lane (fail-closed on non-CAS backends) and embeds the resume-payload field types owned by `ironclaw_turns` (`CapabilityInputRef`, `AuthResumeApprovalIdentity`) rather than re-typing them. Write-once; no removal method until an explicit retention contract adds one.
9 changes: 8 additions & 1 deletion crates/ironclaw_capabilities/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -14,11 +14,19 @@ async-trait = "0.1"
chrono = "0.4"
ironclaw_authorization = { path = "../ironclaw_authorization" }
ironclaw_extensions = { path = "../ironclaw_extensions" }
# Storage substrate: the host-private ReplayPayloadStore persists behind a
# ScopedFilesystem over the shared CAS lane (mirrors run_state's Filesystem*Store).
ironclaw_filesystem = { path = "../ironclaw_filesystem" }
ironclaw_host_api = { path = "../ironclaw_host_api" }
ironclaw_processes = { path = "../ironclaw_processes" }
ironclaw_run_state = { path = "../ironclaw_run_state" }
ironclaw_safety = { path = "../ironclaw_safety" }
ironclaw_trust = { path = "../ironclaw_trust" }
# Resume-payload vocabulary owner: ReplayPayload embeds CapabilityInputRef and
# AuthResumeApprovalIdentity from turns (the CapabilityApprovalResume/AuthResume
# field types) rather than re-typing them.
ironclaw_turns = { path = "../ironclaw_turns" }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
thiserror = "2"
tracing = "0.1"
Expand All @@ -33,6 +41,5 @@ ironclaw_processes = { path = "../ironclaw_processes", features = ["test-support
ironclaw_run_state = { path = "../ironclaw_run_state", features = ["test-support"] }
ironclaw_dispatcher = { path = "../ironclaw_dispatcher" }
ironclaw_events = { path = "../ironclaw_events" }
ironclaw_filesystem = { path = "../ironclaw_filesystem" }
ironclaw_resources = { path = "../ironclaw_resources" }
tokio = { version = "1", features = ["macros", "rt"] }
18 changes: 10 additions & 8 deletions crates/ironclaw_capabilities/src/host.rs
Original file line number Diff line number Diff line change
Expand Up @@ -7,9 +7,9 @@ use ironclaw_host_api::{
ActivityId, AuthorizeResult, Authorized, Blocked, CapabilityAuthorizer, CapabilityDescriptor,
CapabilityDispatchRequest, CapabilityDispatchResult, CapabilityDispatcher, CapabilityGrantId,
CapabilityId, Decision, DenyReason, DenyRef, DispatchError, ExecutionContext, GateRef,
Invocation, InvocationFingerprint, InvocationId, InvocationOrigin, Obligation, ProcessId,
ProductKind, ResourceEstimate, ResourceReservation, ResourceReservationId, ResourceScope,
RuntimeLane,
GateWaypoint, Invocation, InvocationFingerprint, InvocationId, InvocationOrigin, Obligation,
ProcessId, ProductKind, ResourceEstimate, ResourceReservation, ResourceReservationId,
ResourceScope, RuntimeLane,
};
use ironclaw_processes::{ProcessManager, ProcessStart};
use ironclaw_run_state::{
Expand Down Expand Up @@ -729,8 +729,8 @@ where
}
}
Ok(AuthorizeFold::Blocked {
result: AuthorizeResult::Blocked(Blocked::Approval(GateRef::from_uuid(
approval_request_id.as_uuid(),
result: AuthorizeResult::Blocked(Blocked::Approval(GateWaypoint::new(
GateRef::from_uuid(approval_request_id.as_uuid()),
))),
})
}
Expand Down Expand Up @@ -2035,8 +2035,8 @@ where
}
}
Ok(AuthorizeFold::Blocked {
result: AuthorizeResult::Blocked(Blocked::Approval(GateRef::from_uuid(
approval_request_id.as_uuid(),
result: AuthorizeResult::Blocked(Blocked::Approval(GateWaypoint::new(
GateRef::from_uuid(approval_request_id.as_uuid()),
))),
})
}
Expand Down Expand Up @@ -2154,7 +2154,9 @@ where
// `AuthorizationRequiresApproval` with no persisted gate, so the
// forward-looking Blocked witness carries a fresh correlation id.
Ok(AuthorizeFold::Blocked {
result: AuthorizeResult::Blocked(Blocked::Approval(GateRef::new())),
result: AuthorizeResult::Blocked(Blocked::Approval(GateWaypoint::new(
GateRef::new(),
))),
})
}
}
Expand Down
4 changes: 4 additions & 0 deletions crates/ironclaw_capabilities/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ mod error;
mod helpers;
mod host;
mod obligations;
mod replay_payload;
mod requests;

pub use conformance::{
Expand All @@ -24,6 +25,9 @@ pub use obligations::{
CapabilityObligationError, CapabilityObligationFailureKind, CapabilityObligationHandler,
CapabilityObligationOutcome, CapabilityObligationPhase, CapabilityObligationRequest,
};
pub use replay_payload::{
FilesystemReplayPayloadStore, ReplayPayload, ReplayPayloadStore, ReplayPayloadStoreError,
};
pub use requests::{
CapabilityAuthResumeRequest, CapabilityInvocationRequest, CapabilityInvocationResult,
CapabilityResumeRequest, CapabilitySpawnRequest, CapabilitySpawnResult,
Expand Down
Loading
Loading