feat: ship open runtime with durable recovery, contextual tools and SDK - #7
Merged
Merged
Conversation
HZP1995
marked this pull request as ready for review
September 28, 2026 06:32
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and behavior
The public repository exposed private-kernel contracts without an independently buildable runtime or complete installed SDK. This change supplies a bounded C++17 reference runtime, CLI and SDK. Exact-phrase skills run first; optional HTTP model output may select one validated tool. Explicit SQLite storage persists receipts and history across restarts.
A request repeated after completion returns its recorded result. If a tool may have committed before its response was lost, the request remains UNKNOWN and is not automatically retried. Context-aware adapters receive a stable scoped idempotency key, deadline and cancellation token, and return a typed committed/failed/unknown outcome. Legacy tool callbacks remain source-compatible.
The runnable inventory example uses a separate HTTP service and SQLite database. It deliberately commits a stock reservation and drops the response. The runtime records UNKNOWN; external receipt verification and reconciliation recover the result, and service-side atomic idempotency prevents another stock decrement after process restarts.
Implementation
MasterAgent::Coreand optionalMasterAgent::HttpCMake targets; CLI, external consumer and inventory integration examples in verified SDK archives.ExecutionContext,RunOptions, cooperative cancellation andToolOutcome. Check stopping before dispatch/invocation; preserve authoritative results even if cancellation arrives during execution.Validation
Local macOS arm64, 0.4.0-alpha.3:
GitHub CI passed for
842121ead24d49c30ad4f1021fae40e0f42a0a36on both Linux x64 and macOS arm64: all 17 tests, 5 evaluations, relocated consumers and the packaged inventory contract. Blocking static analysis, 7 sanitizer contracts and 13 dependency-disabled tests also passed. Both push and PR runs succeeded. Final CI results. Loopback fixtures explicitly avoid reverse DNS so their startup does not depend on runner DNS configuration.Boundaries
This is a single-process, one-tool-per-turn open reference implementation, not the proprietary kernel or a distributed exactly-once/DAG system. Storage is unencrypted. Cancellation is cooperative and cannot undo an external effect; custom model handlers own their I/O deadlines. Idempotency keys are scoped by the host application and do not provide tenant authorization. The unauthenticated inventory service binds to loopback for local integration only. Rebuild SDK consumers: alpha binary ABI stability is not promised. Real GGUF models, third-party business systems, Qualcomm NPU and Android remain unvalidated. Experimental mesh/learning/speculation modules are not wired into the reference CLI.