Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
21 commits
Select commit Hold shift + click to select a range
3de649e
code: connect explicit native editor tasks to local core
erikleblansch Oct 1, 2026
41a4320
test: add isolated native editor UI trial
erikleblansch Oct 1, 2026
4263b8b
test: wait for actual editor readiness before command palette
erikleblansch Oct 2, 2026
ed1209b
code: migrate to OpenCode with core-backed cooperative tasks
erikleblansch Oct 2, 2026
6ddd75d
test: add isolated OpenCode real-model coding trial
erikleblansch Oct 2, 2026
364cbd7
test: retain VM failure causes and isolate fresh-checkout fixture
erikleblansch Oct 2, 2026
aeb6b82
test: restore verified headless VM boot configuration
erikleblansch Oct 2, 2026
b3a4cfe
code: connect native cooperation trial to an external public core
erikleblansch Oct 2, 2026
ac96993
code: capture exact inputs for the cooperative peer topology
erikleblansch Oct 2, 2026
0282ffe
code: preserve primary task failures and closed provider diagnostics
erikleblansch Oct 2, 2026
9fdca1e
code: distinguish terminal peer responses from complete answers
erikleblansch Oct 2, 2026
11a7063
code: stop regenerating terminal model failures and confirm cleanup s…
erikleblansch Oct 2, 2026
afdb284
code: align OpenCode agent prompts with the single-tool core protocol
erikleblansch Oct 2, 2026
e021e5c
ci: add explicit source-bound OpenCode Qwen KVM trial
erikleblansch Oct 2, 2026
9435c84
Merge main and retain OpenCode integration status
erikleblansch Oct 2, 2026
8685bd0
test: compare exact guest source across Python versions
erikleblansch Oct 2, 2026
4447964
opencode: retain closed native tool lifecycle diagnostics
erikleblansch Oct 2, 2026
d6ec314
fix: bind OpenCode zero temperature to negotiated core generation policy
erikleblansch Oct 2, 2026
8e571e0
feat: continue OpenCode tasks after owner-selected verification
erikleblansch Oct 2, 2026
9c5b41d
fix: retain ordinary verifier errors within wire bounds
erikleblansch Oct 2, 2026
40d8901
test: exercise owner verification in real OpenCode trial
erikleblansch Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/opencode-inference.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: VOLPAROSSA/volparossa
ref: 708bcdd2960ae019579b1c4ce6991ed57653050c
ref: 845cc84d0d0b766ab1c5227231dbf6c8eaeb8cc3
path: build/ci-core
persist-credentials: false
- name: Require exact clean source and explicit hosted runner
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/source-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,8 @@ jobs:
run: npm test
- name: Check offline source-build contract
run: python3 -B -m unittest discover -s tests -p 'test_build_codex_runtime.py'
- name: Check OpenCode source-build and namespace contracts
run: python3 -B -m unittest discover -s tests -p 'test_*opencode*.py'

# No dependency installation, Codex/model download, real inference, editor
# No dependency installation, runtime/model download, real inference, editor
# installation or privileged service startup. These are source/protocol checks.
6 changes: 3 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
# VOLPAROSSA Code

- Build an independent GPL-3.0-only editor extension on the open Codex CLI/app-server, not a copy of the proprietary OpenAI IDE extension.
- Build on the open-source OpenCode runtime and reuse suitable upstream apps/clients/editor integrations (user revision 2026-10-02). Original integration code is GPL-3.0-only; preserve upstream MIT notices. Codex experiments are historical, not the selected runtime.
- VOLPAROSSA owns model selection, peer scheduling, cancellation and contribution accounting. Do not add a competing peer coordinator here.
- Private source, prompts, credentials, tool results and repository history must not be silently published to peers, cache or training. Public work requires explicit scope and consent.
- Network cooperation and collective improvement are the default architectural goal, including protected execution of private work on other nodes. Local inference is a fallback/development executor, not completion of that requirement. Do not replace real peer collaboration with local subagents or claim that TLS, fragmenting tasks or a peer signature protects inputs from the executing host.
- No OpenAI authentication, cloud inference fallback, telemetry, automatic runtime/model downloads or global configuration changes.
- Opening a workspace must not start models, commands or network participation. Honor editor workspace trust and explicit per-operation input selection.
- Codex tool actions remain subject to local workspace/approval boundaries; a model response is not authority to run a command.
- OpenCode tool actions remain subject to local workspace/approval boundaries; a model response is not authority to run a command. Core owns immune-policy decisions and executor admission; frontend labels are not an implemented immune system.
- Keep the README honest about the difference between transport tests, actual inference, native editor tests and complete coding-agent behavior.
- Use targeted checks while integrating executable slices. Preserve upstream notices and pin any reused runtime exactly.

237 changes: 121 additions & 116 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,134 +1,139 @@
# Project VOLPAROSSA Code

**An open editor companion for the VOLPAROSSA cooperative network.**
**OpenCode tools. VOLPAROSSA intelligence. Cooperative development.**

The selected direction is a coding assistant built on **OpenCode**, with
VOLPAROSSA supplying intelligence and organizing network cooperation. Reusing
suitable upstream apps, clients and editor integrations is part of that direction.
Original integration code is GPL-3.0-only; upstream licenses and notices remain
intact. This is not an OpenAI-backed service or a copy of its proprietary IDE extension.
VOLPAROSSA Code connects the open-source **OpenCode** coding runtime to the
VOLPAROSSA core. The goal is a network-native assistant that can read, change
and check code, distribute useful work, combine agent results and improve its
working methods—without making the power of one device the limit.

**What is on `main`?** The executable baseline below still contains the earlier
Codex-based experiments and direct private-core commands. The OpenCode runtime
and cooperative-tool integration are being developed in
[PR #5](https://github.com/VOLPAROSSA/volparossa-code/pull/5), which has not yet
been merged. This README update does not install that runtime or change the
working commands on `main`.
OpenCode replaces the earlier Codex CLI/app-server foundation. Suitable upstream
apps, clients and editor integrations can share the same core connection. The
first integration is a development extension for VS Code/VSCodium on Linux;
cross-platform applications and packaging are not yet complete.

## Who does what?
This README describes the OpenCode development candidate tracked in
[PR #5](https://github.com/VOLPAROSSA/volparossa-code/pull/5), not a completed
coding assistant. Original integration code is GPL-3.0-only; upstream licenses
and notices remain intact. This is not an OpenAI-backed service or a copy of
its proprietary IDE extension.

## One coordinator, multiple cooperating agents

```mermaid
flowchart LR
Editor["VOLPAROSSA Code\nUser intent, selection, approvals"] --> Runtime["OpenCode\nAgent and workspace tool loop"]
Runtime --> Core["VOLPAROSSA core\nModels, task coordination, cancellation"]
Core --> Private["Owner-local inference\nCurrent development executor / fallback"]
Core -.-> Cooperative["Network cooperation by default\nProtected private execution required"]
Runtime --> Tools["Approved local workspace tools"]
flowchart TD
UI["Editor / OpenCode client<br/>Intent, project scope, approvals"] --> Runtime["OpenCode runtime<br/>Tools and subagent sessions"]
Runtime --> Core["VOLPAROSSA core<br/>Placement, models, cancellation, accounting"]
Core --> A["Network agent A<br/>Suitable authorized work"]
Core --> B["Network agent B<br/>Parallel work and review"]
Core --> C["Protected network execution<br/>Private work · required, not implemented"]
Core --> Local["Local executor<br/>Fallback and development"]
A --> Core
B --> Core
C --> Core
Runtime --> Tools["Workspace-scoped tools<br/>Explicit edit / command authority"]
Immune["Immune system<br/>Admission, behavior, results"] -.-> Core
```

This diagram describes the **target integration**, not an already completed
coding datapath. The core owns peer selection and cooperation; the editor must
not create a separate peer scheduler or treat model output as permission to run
commands. Private prompts, code, tool output and repository history are not
automatically public training or cache material.
This is the **target architecture**, not a claim that every arrow works today.
Network cooperation and collective improvement are the default design, including
private projects. Core owns peer scheduling; OpenCode's local subagents do not
themselves provide a decentralized network or confidential remote execution.

Cooperation is the default architectural goal, not an optional replacement for
an otherwise local-only product. Private work must also be able to use suitable
Privacy belongs inside cooperation. Private work must also be able to use suitable
network executors without exposing source or tool data to their operators. That
protected execution is **not implemented by the current local executor**: TLS,
task fragmentation and peer signatures alone do not hide inputs from an ordinary
executing host. Explicitly public task sharing is a separate capability, not proof
of private distributed coding.

## First executable slice — current `main`

The extension implements two explicit commands:

- **VOLPAROSSA: Ask About Selected Code (Private, Local)** sends only a confirmed
question and selection to an existing same-owner `compute private-serve` socket.
Responses appear as untrusted plaintext; no changes are applied automatically.
- **VOLPAROSSA: Show Compute Capabilities** queries that service without sending
code or claiming that a model has successfully executed.

The current core interface permits **512 UTF-8 bytes for the question and 4096
for the selection**, subject to the selected model's smaller token budget.
Over-limit inputs fail instead of being silently shortened. Partial model output
remains labeled partial. Cancellation is forwarded; uncertain cleanup is not
reported as success. There is no public-peer or OpenAI fallback.

These first commands use the core directly. They are **not yet routed through
Codex**. The separate app-server client implements the pinned NDJSON handshake,
thread/turn requests, notifications and interruption, and declines tool approvals
by default. An explicit caller can supply a narrowly scoped per-command approval
policy; the normal extension does not enable it. Its focused protocol tests are
now complemented by a **real, source-built app-server lifecycle trial**:
initialization, an ephemeral VOLPAROSSA-provider thread, exact unsubscribe and
clean shutdown pass in disposable namespaces without OpenAI credentials or
network access. This trial does not send a model turn or execute tools.

Separately, the [real core/model trial](https://github.com/VOLPAROSSA/volparossa/actions/runs/36738995292)
passes with this repository's pinned private client and the 360M model: a small
synthetic-code question produces a complete answer containing its identifier,
with cancellation, isolation and cleanup checks. This is an adapter proof, not
a native-editor test or a measure of general coding quality.

See the [explicit runtime build and native trial](docs/RUNTIME_BUILD.md). Nothing
is downloaded or started merely by installing or activating the extension.

The next [local Responses adapter](docs/RESPONSES_PROVIDER.md) now connects a
bounded text/tool subset to the core's separate conversation interface. It retains
call/result identities and waits for confirmed core cleanup before returning a
completed turn. Its real HTTP/Unix-socket tests use synthetic model responses;
the actual Codex/model/tool loop is **not proved yet**. The new Qwen conversation
profile is a larger-context candidate, not evidence of reliable coding performance.

An explicit [native coding trial](docs/NATIVE_CODING_TRIAL.md) now supplies the
missing model catalog and disposable read/edit/test harness. It uses the full
pinned Codex prompt, actual core inference and native tools, with approvals limited
to one synthetic project. The harness is implemented and its offline checks pass;
the actual model-driven coding trial is still pending.

## Try the development extension

On Linux, explicitly prepare and start the core's private service following its
[IPC contract](https://github.com/VOLPAROSSA/volparossa/blob/main/crates/volparossa/src/compute/private_serve/WIRE.md).
The extension does not install runtimes/models, start participation, change
network settings or read your existing Codex credentials/configuration.

Open this repository as an **extension development directory** in VS Code or
VSCodium. In the development instance's user settings, set
`volparossaCode.privateSocket` to the service's absolute Unix-socket path. Use a
trusted, local workspace, select a short snippet, then invoke the command from
the command palette. No npm dependencies are required. Do not treat this as a
packaged or native-editor-tested release yet.

With Node 22 or newer, the focused checks are:
of private distributed coding. Code, prompts, tool output and history are not
automatically public cache or training data. A local-only assistant does not
fulfill the goal of the shared VOLPAROSSA brain.

## Current executable integration

**VOLPAROSSA: Run OpenCode Task (Development)** selects the new OpenCode launcher,
not Codex. It joins these implemented components:

- Pinned OpenCode **v1.18.34**, authenticated HTTP sessions and SSE events.
- A Chat Completions provider translating text and function-tool history into
the core's typed conversation interface.
- One-shot command/edit approvals, correlated root and child sessions,
cancellation, session deletion and owned-process cleanup.
- An explicit Linux launcher with a selected writable project, temporary state,
no inherited account credentials and no external network interface.

**Current proof:** the pinned OpenCode source builds and the actual runtime
completes a tool loop through the production launcher and adapters: one approved
command changes a disposable file, its tool result returns to the core interface,
and the session shuts down cleanly. A second native trial invokes the cooperative
tool, preserves complete and incomplete core results, and confirms that only the
enrolled public snapshot crosses the bridge. Both trials use **synthetic core/model
replies**, not real inference or peer execution. Focused checks additionally cover
adapter, editor and lifecycle behavior. Model-driven coding, native editor UI
operation, protected peer execution and a finished immune-policy path remain unproved.

The available conversation executor is still **private and local**. Its scope is
shown honestly; the adapter does not disguise it as network compute or export
private input through the public peer interface.

**VOLPAROSSA: Run OpenCode Task with Enrolled Public Work** additionally connects
one explicitly reviewed public question and selected excerpt to the core's
cooperative task interface. The model can invoke this task once; it cannot append
private files or history to it. A limited owner-side proxy keeps the raw public
core socket outside the coding sandbox. Core owns peer placement, execution and
cancellation; original task results and incomplete-answer flags are retained.
This interface currently requires the separate core cooperative-compute candidate,
not stock `main`. The joined path with actual peer inference remains to be proved.

This public-only development step is **not** the intended limit of cooperation:
default collaboration, shared learning and protected private execution across
the network remain required functionality.

The existing **Ask About Selected Code (Private, Local)** and **Show Compute
Capabilities** commands remain available. Selected-code advice sends only the
confirmed question and excerpt to the same-owner core socket. It does not change
files or execute tools. The direct Q&A interface allows **512 UTF-8 bytes for the
question and 4096 for the selection**, subject to the selected model's smaller
token budget. Oversized input is refused, not silently shortened; partial output
and uncertain cancellation or cleanup are not presented as success.

The separate [real core/model Q&A trial](https://github.com/VOLPAROSSA/volparossa/actions/runs/36738995292)
passes with the pinned private client and 360M model, including cancellation,
isolation and cleanup checks. That remains evidence for the direct Q&A adapter,
not the OpenCode read/edit/test loop, native editor UI or general coding quality.

## Development setup

See [OpenCode setup, isolation and proof boundaries](docs/OPENCODE.md).
Use a trusted local workspace and explicitly provision the pinned runtime and
core/model service. Opening the extension or a project starts no model, runtime
or network participation. No OpenAI login or automatic cloud fallback is used.

Run focused checks with Node 22 or newer:

```sh
npm test
npm run check
node --test tests/opencode-*.test.cjs tests/cooperative-*.test.cjs tests/chat-completions-provider.test.cjs tests/extension.test.cjs
```

## Remaining integration work

- Integrate the OpenCode candidate into `main`, preserving isolated configuration,
upstream notices and the existing private Q&A command. Retain the Codex evidence
as history, not as the selected future runtime.
- Prove an actual OpenCode/model read-edit-test task with reviewable changes,
explicit local approvals and independently checked results. Protocol tests or
synthetic replies alone do not prove real model-driven coding.
- Make network cooperation standard through the core's scheduler, with protected
private execution, resource accounting, cancellation, result provenance and
core immune-policy oversight; do not substitute public sharing for private execution.
- Run native editor tests against the real core/model and prepare suitable upstream
app/client integrations and packaging.

The small models currently supported by the core are not a claim of Codex-class
coding performance. Installing this frontend alone does not supply a stronger
model, private distributed inference or a completed cooperative coding agent.

See [upstream provenance for the current baseline](THIRD_PARTY_LICENSES.md) and
the [OpenCode migration PR](https://github.com/VOLPAROSSA/volparossa-code/pull/5).
The [Codex app-server documentation](https://learn.chatgpt.com/docs/app-server)
and [open-source boundary](https://learn.chatgpt.com/docs/open-source) describe the
historical foundation retained on `main`, not the newly selected runtime.
Original integration code is GPL-3.0-only. OpenCode is MIT-licensed; its original
notice and source pin are preserved in [third-party provenance](THIRD_PARTY_LICENSES.md).

## Remaining work

- Exercise the source-built OpenCode runtime with actual core inference and a
model-driven read/edit/test task with explicit local approvals and independently
checked results, then verify native editor operation.
- Prove the connected cooperative tool with actual core/peer execution, then
integrate its core dependency; retain original results, cancellation and provenance.
- Implement remote conversation execution and actual protected private work,
with suitable model capacity, measured performance and core-owned resource
accounting. Public sharing is not a substitute for private execution.
- Join immune-policy admission, result review and approved shared learning to
those paths; local approval dialogs alone do not provide that system.
- Reuse suitable upstream clients on additional platforms and package verified
integrations without silently downloading runtimes or changing host settings.

Earlier [Codex runtime](docs/RUNTIME_BUILD.md), [Responses adapter](docs/RESPONSES_PROVIDER.md)
and [native-editor](docs/NATIVE_EDITOR.md) records remain **historical evidence**.
Their checks do not prove OpenCode operation. Small provisioned models do not
establish competitive coding quality or the capacity of the eventual shared brain.
14 changes: 14 additions & 0 deletions THIRD_PARTY_LICENSES.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,20 @@

Original code in this repository is GPL-3.0-only; see [LICENSE](LICENSE).

## OpenCode — selected foundation

OpenCode v1.18.34 is pinned to
[`aec0b9a6d8898f68f923aaf08b7306d931fd9d76`](https://github.com/anomalyco/opencode/tree/aec0b9a6d8898f68f923aaf08b7306d931fd9d76).
Its [original MIT license](third_party/opencode-LICENSE.txt) is retained unchanged.
[The source record](third_party/opencode.json) binds the upstream license, Bun
lockfile, config source and compatible provider version. The recorded
[patch](patches/opencode-no-runtime-installs.patch) disables implicit config-loader
dependency installation in explicit VOLPAROSSA mode. No upstream binaries,
generated SDK or dependency tree are committed. Redistribution must retain all
upstream/dependency notices. A pin does not prove model quality or peer privacy.

## Codex — historical experiment

The **open Codex CLI/app-server** is an Apache-2.0 project. This independent
protocol client was checked against commit
[`67727e7cf114cf3e1b71db368d74b24e32f6cb12`](https://github.com/openai/codex/tree/67727e7cf114cf3e1b71db368d74b24e32f6cb12).
Expand Down
Loading
Loading