Skip to content

feat: ship open runtime with durable recovery, contextual tools and SDK - #7

Merged
HZP1995 merged 4 commits into
mainfrom
codex/oss-runtime-foundation
Sep 28, 2026
Merged

HZP1995 merged 4 commits into
mainfrom
codex/oss-runtime-foundation

Conversation

@HZP1995

@HZP1995 HZP1995 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Problem and behavior

The public repository exposed private-kernel contracts without an independently buildable runtime or complete installed SDK. This change supplies a bounded C++17 reference runtime, CLI and SDK. Exact-phrase skills run first; optional HTTP model output may select one validated tool. Explicit SQLite storage persists receipts and history across restarts.

A request repeated after completion returns its recorded result. If a tool may have committed before its response was lost, the request remains UNKNOWN and is not automatically retried. Context-aware adapters receive a stable scoped idempotency key, deadline and cancellation token, and return a typed committed/failed/unknown outcome. Legacy tool callbacks remain source-compatible.

The runnable inventory example uses a separate HTTP service and SQLite database. It deliberately commits a stock reservation and drops the response. The runtime records UNKNOWN; external receipt verification and reconciliation recover the result, and service-side atomic idempotency prevents another stock decrement after process restarts.

Implementation

  • Installable MasterAgent::Core and optional MasterAgent::Http CMake targets; CLI, external consumer and inventory integration examples in verified SDK archives.
  • Strict supported-schema validation, bounded sessions/history/output, request conflicts, explicit synchronous concurrency and error contracts.
  • SQLite WAL receipts with exclusive ownership, fail-closed persistence, dispatch-before-callback ordering, conservative recovery and auditable reconciliation.
  • ExecutionContext, RunOptions, cooperative cancellation and ToolOutcome. Check stopping before dispatch/invocation; preserve authoritative results even if cancellation arrives during execution.
  • Bounded HTTP transport and opt-in endpoints; corrected experimental harness future lifetime/deadline behavior, active Release test checks and evaluation failure reporting.
  • Blocking static analysis of the public runtime, sanitizer/network/recovery CI, optional-dependency-disabled builds, Linux/macOS package verification, build provenance and checksums.

Validation

Local macOS arm64, 0.4.0-alpha.3:

  • Release CTest: 17/17 passed.
  • ASan/UBSan: 7/7 critical runtime, harness, HTTP and recovery tests passed.
  • HTTP/storage-disabled build: 13/13 tests passed.
  • Synthetic evaluations: 5/5 passed.
  • SDK archive unpacked in a new location: 2/2 external consumer tests plus the complete inventory integration contract passed.
  • Subprocess crash after an external fsync, SQLite start/dispatch/completion write-failure injection, context cancellation/deadlines and external HTTP receipt loss/reconciliation are covered.

GitHub CI passed for 842121ead24d49c30ad4f1021fae40e0f42a0a36 on both Linux x64 and macOS arm64: all 17 tests, 5 evaluations, relocated consumers and the packaged inventory contract. Blocking static analysis, 7 sanitizer contracts and 13 dependency-disabled tests also passed. Both push and PR runs succeeded. Final CI results. Loopback fixtures explicitly avoid reverse DNS so their startup does not depend on runner DNS configuration.

Boundaries

This is a single-process, one-tool-per-turn open reference implementation, not the proprietary kernel or a distributed exactly-once/DAG system. Storage is unencrypted. Cancellation is cooperative and cannot undo an external effect; custom model handlers own their I/O deadlines. Idempotency keys are scoped by the host application and do not provide tenant authorization. The unauthenticated inventory service binds to loopback for local integration only. Rebuild SDK consumers: alpha binary ABI stability is not promised. Real GGUF models, third-party business systems, Qualcomm NPU and Android remain unvalidated. Experimental mesh/learning/speculation modules are not wired into the reference CLI.

@HZP1995
HZP1995 marked this pull request as ready for review September 28, 2026 06:32
@HZP1995 HZP1995 changed the title feat: ship open reference runtime with durable recovery and installable SDK feat: ship open runtime with durable recovery, contextual tools and SDK Sep 28, 2026
@HZP1995
HZP1995 merged commit 432189c into main Sep 28, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants