Repository navigation
feat(gateway): bind kernel capabilities to Capability Kits and list a kit's live hosts (kits K3a) - #598
Draft
LamaSu wants to merge 3 commits into
Draft
feat(gateway): bind kernel capabilities to Capability Kits and list a kit's live hosts (kits K3a)#598LamaSu wants to merge 3 commits into
LamaSu wants to merge 3 commits into
Conversation
… kit's live hosts (kits K3a) Operator binding, first slice (ledger R8 and R41; vision criteria 3 and 1). - POST /api/kits/:digest/bindings binds a kernel capability the caller owns to a CSD of a published kit version. Append-only and idempotent per tuple. - POST /api/kits/:digest/bindings/:bindingId/withdraw writes a second immutable record. The kernel's current owner withdraws. - GET /api/kits/:digest/operators lists a kit's hosts, with presence (a 5-minute heartbeat), the AvailabilitySummary shape, the recorded list price and the identity tier. It carries no operator address or principal. - GET /api/operators/me/binding serves OperatorBindingDTO v0. payee is null (no payout-destination store yet); moneyAuthority is "none". - Bindings live in the kit registry's write-once file store: no DDL. - services/operator-identity.ts holds the identity tiers and the kernel-owner rule. capability-availability.ts imports its helpers from there, unchanged. Code written by GPT-6.1 Sol (codex 0.159.1, effort ultra) from the lane's brief. Reviewed by the kits lane. Review fixes follow in the next commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RkdS4kBJNfFzaDBUCX8kQg
…ic bind, DTO-safe unmapped capacity The kits lane's review of the K3a slice: - A self_asserted principal owns a kernel only on exact string equality with its operatorAddress (no trimming), as the kernel upsert compares when it assigns ownership. Empty, blank and zero-address owners stay refused. - The idempotency check, the quota claim and the create run in one queued registry step (createBindingIfAbsent). Two concurrent identical binds now return the same binding, and spend one claim. - /api/operators/me/binding omits capability rows whose type can't be a legacyType (1-120 characters), so one such row can't make the projection fail. - Binding scans keep their own skipped list (skippedBindings). The kit listing's skipped is unchanged. - Quota claims for bindings record the kit digest being bound. Code written by GPT-6.1 Sol (codex 0.159.1, effort ultra). Each new test failed on the unfixed code. Lane checks at this head: full gateway suite 5145 passed, 13 skipped, 3 todo; tsc clean; lane mutation run 34/34 killed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RkdS4kBJNfFzaDBUCX8kQg
…operator-binding-k3 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RkdS4kBJNfFzaDBUCX8kQg
LamaSu
had a problem deploying
to
trusted-checks
October 7, 2026 00:13 — with
GitHub Actions
Failure
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Kits K3a: operator binding. Vision criterion 3 (an operator binds capacity and advertises capacity and pricing) and criterion 1 (a buyer searches kits and the live operators hosting them). Ledger rows R8 (binding grants no money authority) and R41 (a payment destination is not execution authority).
Stacked on #511 (the durable Capability Kit registry). Base is
feat/kits-registry-k1. Retarget to master after #511 merges; CI runs on PRs into master only.What it adds (gateway only; no DDL;
packages/specuntouched)POST /api/kits/:digest/bindings, body{csdUrl, kernelId, capabilityId}:POST /api/kits/:digest/bindings/:bindingId/withdraw: the kernel's current owner writes an immutable withdrawal. The first withdrawal wins.GET /api/kits/:digest/operators?presence=online|any: the buyer view of a kit's active hosts. Each host shows:presence, which is online only with a heartbeat 5 minutes old or newer;lastSeenAt;availability, in the AvailabilitySummary shape only;listPrice: the capability's recorded pricing,basis: "capability_record";assuranceTierCap: 0;identityStatus.It shows no operator address, principal or principal hash.
GET /api/operators/me/binding: OperatorBindingDTO v0, exactly as merged in feat(spec): Capability Kit manifest identity, OperatorBindingDTO and OpportunityDTO v0 contracts (interface-only; not before wave D) #397.payeeis null until N21 has a store, andmoneyAuthorityis "none".Storage: new areas in the kit registry's write-once file store (
bindings/,binding-withdrawals/,binding-quota/). They reuse its exclusive-create, no-symlink and canonical-verification primitives. The operator chose file storage for kits (R6, option a).Identity (
services/operator-identity.ts), recorded on every binding:proven: WP-A'sprovenWallet, or a SIWE session with no API key;self_asserted: an API key whose operator id equals the kernel'soperatorAddressexactly. That is the same compare the kernel upsert uses when it assigns ownership.Not in this PR (named exposures)
listPriceis the recorded price. The A2A and paid-job quote paths don't use it yet; the next slice, K3b, connects them.assuranceTierCapis 0, because the server keeps no proven per-kernel tier.Provenance and review
k3a-r1-operator-binding-9b5822e4is with the orchestrator for a fresh Claude Opus 5.5 review, under the operator's 10/06 15:09 rule. The verdict is pending.git merge-tree --write-tree 9b5822e4 41864713.server.tsadds the same two lines at moved offsets.Checks at 15970be (run by the lane)
tsc --noEmit🤖 Generated with Claude Code
https://claude.ai/code/session_01RkdS4kBJNfFzaDBUCX8kQg