You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: Makefile
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -56,7 +56,7 @@ check-go:
56
56
check-runtime-contract:
57
57
go test ./internal/agentdaemon/proto ./internal/agentdaemon/gateway ./apps/parsar-daemon/internal/transport ./apps/parsar-daemon/internal/dispatch ./apps/parsar-daemon/internal/contracttest -count=1
58
58
go test ./services/agents-api/internal/execution -run '^TestRuntimeProtocol' -count=1
59
-
go test ./apps/parsar-daemon/internal/agent/... -run '^TestSharedTextLifecycle$$' -count=1
59
+
go test ./apps/parsar-daemon/internal/agent/... -run '^(TestSharedTextLifecycle|TestPublicHarnessContractDeclarations|TestRegistryRejectsEveryOmittedCapabilityBeforeReplacement|TestUnsupportedExtensionsHaveNoNativeEffects)$$' -count=1
the shared model configuration contract (declarations and preparation).
16
16
-[`agent/harness.go`](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/apps/parsar-daemon/internal/agent/harness.go): the
17
-
execution lifecycle, optional interfaces and registration methods.
17
+
execution lifecycle, explicit extension contracts and registration methods.
18
18
19
19
20
20
## Ownership
@@ -77,11 +77,15 @@ model communication configuration, not Turn scheduling or native process ownersh
77
77
[Harness integration](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/contracts/agents-api/harnesses.md#acceptance-checklist). Record results in
78
78
the [qualification table](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/contracts/agents-api/harnesses.md#current-qualified-operations).
79
79
80
-
Start with the mandatory text lifecycle, then qualify optional operations one at
81
-
a time. Call the reusable `agent/contracttest.TextLifecycle` assertions with the
80
+
Implement the mandatory text lifecycle and explicitly handle every extension.
81
+
Qualify supported extensions one at a time; an unqualified extension returns
82
+
`agent.ErrUnsupportedOperation` without native effects. Call the reusable `agent/contracttest.TextLifecycle` assertions with the
82
83
adapter's prepared Executor and deterministic native fixture. These assertions
83
-
cover healthy reuse, durable input and cancellation; keep native fault and live
84
-
acceptance separate. Name the entry test `TestSharedTextLifecycle` so
84
+
cover healthy reuse, durable input and cancellation for adapters whose native
85
+
owner remains reusable. A native cancellation may instead require retirement:
86
+
`Reusable=false` carries a reason and the caller must confirm `Executor.Close`.
87
+
Do not force reuse to fit a test helper. Keep native fault and live acceptance
88
+
separate. Name the entry test `TestSharedTextLifecycle` so
85
89
`make check-runtime-contract` includes it. Do not copy an adapter's native
86
90
limitations into the shared Core protocol.
87
91
@@ -94,15 +98,16 @@ limitations into the shared Core protocol.
94
98
- A new engine supplies an adapter, a qualified profile, registration and an
95
99
independently verified deployment. It adds no engine-name branches to API
96
100
handlers, persistence, dispatch, scheduling or Environment providers.
97
-
- Keep required lifecycle declarations, optional interfaces and registration
101
+
- Keep required lifecycle declarations, extension interfaces and registration
98
102
methods in `agent/harness.go`. Result types, errors and Registry storage may
99
103
stay in focused files. Keep this guide linked to that entry point.
100
104
- Use the existing `proto.SupportedAgentKind` and `AgentKindCapabilities`
101
105
schema. Do not add a second capability descriptor or a combined optional
102
106
interface.
103
107
- Onboarding does not require feature equality. Verify common lifecycle
104
108
obligations and use the same public assertions for each declared operation.
105
-
Optional native differences are separate capability work, not onboarding blockers.
109
+
Native differences do not block onboarding, but an omitted declaration or
110
+
missing extension implementation does.
106
111
- Never equate accepted parameters with applied native behavior.
107
112
108
113
## Native model configuration
@@ -156,9 +161,11 @@ ownership are in the [unified model configuration design](https://github.com/Min
156
161
157
162
[`agent/harness.go`](https://github.com/MiniMax-AI/parsar-core/blob/f6d258735fc601c521dd990e6f9e1ed261f4ef2d/apps/parsar-daemon/internal/agent/harness.go) is the
158
163
canonical interface entry point. Its required lifecycle is `ExecutorFactory`,
159
-
`Executor`, `Turn` and `TurnSettlement`. Optional Turn and workspace interfaces
160
-
remain separate; their result types and error values stay in the corresponding
161
-
operation files in the same package. All use the existing neutral protocol types.
164
+
`Executor`, `Turn` (including `DurableSteerer`) and `TurnSettlement`. Required
165
+
methods must perform their native obligations; returning Unsupported is not an
166
+
implementation of cancellation, receipts, settlement or cleanup. Turn and workspace
167
+
extension interfaces remain small and separate, but every public adapter implements
168
+
each explicitly. Their result types and errors stay in focused operation files. All use the existing neutral protocol types.
162
169
163
170
The [Core–Runtime lifecycle contract](/runtime-protocol#executor-and-turn-lifetimes)
@@ -175,7 +182,7 @@ native Session. Their implementations expose the same Executor and Turn contract
175
182
Implement cancellation on the exact Turn through `agent.Session`. Follow the
176
183
[lifecycle and settlement rules](/runtime-protocol#executor-and-turn-lifetimes);
177
184
the adapter must supply native completion evidence to the shared Runtime.
178
-
Permission and user-choice responses use the optional interfaces below.
185
+
Permission and user-choice responses use the explicit extension interfaces below.
179
186
180
187
## Events, inputs and optional capabilities
181
188
@@ -194,20 +201,50 @@ before consuming a pending interaction. Do not map answers by header or position
194
201
Resume only the exact history bound to the Session; missing or ambiguous required
195
202
history fails before new model input.
196
203
197
-
| Interface or contract |When required| Obligation |
204
+
| Interface or contract |Required handling| Obligation |
198
205
| --- | --- | --- |
199
-
|`agent.DurableSteerer`| Current public text execution | Distinguish write and application receipts; preserve retry identity; independent of the optional non-durable `Steerer`|
200
-
|`agent.FunctionResultSubmitter`| Public function tools | Match call/result identity and acknowledge native application |
201
-
|`agent.PermissionResponder`, `agent.UserChoiceResponder`| When emitting these interactions | Route exact identities and settle receipts |
202
-
|`agent.WorkspaceReader`, `agent.WorkspaceDirectoryLister`, `agent.WorkspaceWriter`| Qualified workspace operations | Use the fixed authorized workspace and retain accepted operations through close |
203
-
| Neutral message, image, MCP, structured-output and Subagent observations | Only when qualified and advertised | Preserve the operation-specific contract and reject unsupported combinations |
204
-
205
-
Optional features need not match another harness. The service profile qualifies
206
-
public combinations; the Runtime advertises this installation's available support.
207
-
Neither replaces schema validation or tenant authorization. Declaring a capability
208
-
without implementing its semantics is an error. Workspace reads may use separate
209
-
read-only preparations; those do not start model work or provide another execution
210
-
lifecycle.
206
+
|`ExecutorFactory`, `Executor.StartTurn`, `Executor.Close`| Real implementation | Prepare without model input; keep failed or uncertain resource ownership; confirm cleanup |
207
+
|`Turn`, `Session.Cancel`, `CancellationOutcome`, `AwaitSettlement`| Real implementation | Cancel the exact Turn, preserve observed results and confirm settlement independently of cancellation requests |
208
+
|`DurableSteerer`| Real implementation on every Turn | Distinguish complete write from native application receipt; preserve retry identity |
|`FunctionResultSubmitter`| Explicit implementation or Unsupported | Match native call/result identity and acknowledge application |
211
+
|`PermissionResponder`, `UserChoiceResponder`| Explicit implementation or Unsupported | Respond to exact emitted identities; unknown/expired interactions remain distinct from Unsupported |
212
+
|`WorkspaceReader`, `WorkspaceDirectoryLister`, `WorkspaceWriter`| Explicit on Turn, Executor and Prepared owners | Use the authorized workspace, confirm access/commit/close, or return the operation's Unsupported error |
213
+
|`Prepared`, `PreparedCancellation`| Real implementation for an executable preparation | Preserve resource and output ownership across Start, cancellation and unused cleanup |
214
+
| Neutral messages, images, MCP, structured output and Subagent observations | Explicit capability decisions | Preserve each operation's protocol semantics; reject unsupported input before submission |
215
+
216
+
Each adapter's `contracts.go` contains individual compile-time assertions for these
217
+
small interfaces. Do not embed a default implementation that makes future
218
+
interfaces appear implemented. Adding a contract also requires classification in
219
+
the common completeness check and an explicit assertion for every public adapter;
220
+
the check follows the authored Harness catalog.
221
+
222
+
For a design-level refusal, implement the method directly, for example:
native failures and uncertain outcomes keep their existing errors and ownership.
234
+
A nil `Turn` still means no input was submitted and output remains with the caller;
235
+
it must not be repurposed as an Unsupported marker.
236
+
237
+
Workspace capability describes the actual Runtime/resource-owner combination.
238
+
Codex and MiniMax resource objects explicitly reject native workspace access while
239
+
the common authorized `localworkspace` owner provides it. Claude can expose native
240
+
read/list access; writes are provided by the common owner. Interface presence alone
241
+
must never select a resource or advertise support.
242
+
243
+
The service profile qualifies public combinations; the Runtime advertises the
244
+
installed combination. Neither replaces schema validation or tenant authorization.
245
+
Native behavior tests must agree with supported declarations. An advertised
246
+
operation returning Unsupported is a contract violation, never success or grounds
247
+
for automatic replay.
211
248
212
249
## Register the adapter
213
250
@@ -224,8 +261,29 @@ from [`cli/agent_registration.go`](https://github.com/MiniMax-AI/parsar-core/blo
224
261
| 3 |`RegisterPreparation(kind, workspaceRead, agent.PreparationFactory)`| Optional. Separate read-only workspace preparation when qualified workspace operations need it. |
225
262
226
263
The direct-call `agent.Factory` should delegate to the same Executor
227
-
implementation. Every other capability declaration must match behavior verified
228
-
for that installation. Runtime registration does not grant Core qualification;
264
+
implementation. Every `proto.AgentKindCapabilities` field must be explicitly
265
+
`proto.CapabilitySupported` or `proto.CapabilityUnsupported`.
266
+
`proto.CapabilityUnspecified` is invalid: zero values and omitted fields do not mean
267
+
Unsupported. Installation probes may use `proto.CapabilityFromBool` for an
268
+
individual field; they must not populate all unmentioned or future fields.
269
+
Availability remains separate in `SupportedAgentKind.Available`.
270
+
271
+
Registration and wire decoding validate the complete declaration. The wire carries
272
+
an explicit boolean for every field; omitted and null fields are invalid. A new
273
+
field requires a decision by every production declaration. Runtime consumers use
274
+
`IsSupported()` and reject unsupported requests before native operations; an
275
+
interface assertion only verifies implementation, never support. Every declaration
276
+
must match behavior verified for that installation.
277
+
278
+
The admission mapping is explicit: `Steering` controls non-durable `Steerer` input;
279
+
`DurableInputReceipts` controls `DurableSteerer` input and also requires the Turn
280
+
settlement contract. Neither implies the other. Core's current public text profile
281
+
requires both advertised capabilities. `Permissions` qualifies permission and
282
+
user-choice responses together; a supported declaration requires both native
283
+
response paths. Workspace declarations describe the selected authorized resource
284
+
owner, including the common Runtime workspace implementation.
285
+
286
+
Runtime registration does not grant Core qualification;
229
287
that belongs to the service profile.
230
288
231
289
The runnable test-only example is
@@ -276,7 +334,7 @@ The [Harness selection contract](https://github.com/MiniMax-AI/parsar-core/blob/
276
334
deployment enablement, defaults and immutable Session binding. This guide adds no
277
335
second selector or fallback rule.
278
336
279
-
## Required versus optional operations
337
+
## Required versus extension operations
280
338
281
339
The current public text path requires durable turns, applied input receipts,
282
340
ordered observations, cancellation and enforcement of disabled execution controls.
@@ -287,7 +345,7 @@ of enforcement.
287
345
288
346
MCP, public function calls, deferred function discovery, structured output, image inputs, verbosity controls and other optional
289
347
operations do not need to match another engine. Reject unqualified combinations
290
-
explicitly and record the gap. Never advertise a capability to bypass selection.
348
+
with Unsupported and record the gap. Never advertise a capability to bypass selection.
291
349
292
350
Structured-output adapters consume `ExecutionControls.OutputFormat` and publish
293
351
confirmed native output through the existing Message contract. Register public
@@ -334,6 +392,26 @@ not add routes, storage branches or a harness-specific Core scheduler. Report
334
392
unsupported native facts explicitly; completing a child task is not closing its
335
393
Subagent. Native background work must remain owned through settlement and cancel.
336
394
395
+
## Contract verification
396
+
397
+
Run `make check-runtime-contract`, the three adapter test packages and `make check`.
398
+
The common completeness gate covers capability omissions and interface assertions;
399
+
adapter tests must cover actual native semantics, not only method presence.
400
+
401
+
| Boundary | Existing focused evidence |
402
+
| --- | --- |
403
+
| Codex reuse, cancellation and unconfirmed cleanup |`codex/executor_test.go`, `terminal_cleanup_test.go`, `prepared_cancel_test.go`|
0 commit comments