Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
f67bde6
feat(serve): implement generic Broker provider controls
wenshao Sep 27, 2026
1b179d3
Merge branch 'main' into codex/broker-provider-control-12765
wenshao Sep 28, 2026
f0f217d
fix(runtime): preserve broker provider validation errors
wenshao Sep 28, 2026
ac0b6cf
chore: merge main into broker provider control
wenshao Sep 28, 2026
cc06ee0
fix(runtime): restore admission and unknown observation semantics
wenshao Sep 28, 2026
ecacbfe
fix(serve): keep oversized provider results observable and tighten th…
wenshao Sep 28, 2026
29a2ae6
fix(cli): narrow the status binding before progress eviction
wenshao Sep 28, 2026
803761a
fix(runtime): keep terminal cancellation receipts answerable without …
wenshao Sep 28, 2026
fe7895d
fix(runtime): fail a prepared-provider cancel non-retryably when it c…
wenshao Sep 28, 2026
17a8360
fix(serve): admit path-safe opaque Session ids on the provider envelope
wenshao Sep 28, 2026
42a059a
Merge remote-tracking branch 'origin/main' into codex/broker-provider…
wenshao Sep 28, 2026
5c0c9bf
fix(serve): address the round-3 review of the Broker provider controls
wenshao Sep 28, 2026
e94f781
fix(serve): address the round-4 review of the Broker provider controls
wenshao Sep 29, 2026
a4849e2
Merge remote-tracking branch 'origin/main' into codex/broker-provider…
wenshao Sep 29, 2026
174f974
docs(runtime-broker): count every fault gate the profile runs
wenshao Sep 29, 2026
50fb283
fix(serve): keep main's input rules on the provider path
wenshao Sep 29, 2026
9cb9dc8
fix(serve): reconcile lost provider answers over Broker HTTP
wenshao Sep 29, 2026
7601740
fix(serve): fit provider artifacts and pin the retention bound
wenshao Sep 29, 2026
ebea694
fix(runtime-broker): cancel a lost provider dispatch at its worker
wenshao Sep 29, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 19 additions & 8 deletions docs/design/2026-09-24-managed-runtime-tool-contract.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,8 @@
[English](2026-09-24-managed-runtime-tool-contract.md) | [简体中文](2026-09-24-managed-runtime-tool-contract.zh-CN.md)

Status: contract, worker handlers, and Java tool transport implemented;
Broker transport wiring remains follow-up work
Broker transport wired through `managed-runtime-provider/1` (see
Comment thread
wenshao marked this conversation as resolved.
[2026-09-27-broker-provider-control.md](2026-09-27-broker-provider-control.md))

Related: #12380 (Managed Agent staged delivery), the attestation contract in
[2026-09-22-managed-runtime-attestation-contract.md](2026-09-22-managed-runtime-attestation-contract.md),
Expand All @@ -30,10 +31,14 @@ In scope: route manifest declarations, the shared schema and conformance
fixtures, and the worker handlers with their raw HTTP gate admission.
TypeScript contract tests and the Java fixture consumer share the contract;
the worker tests exercise the mounted handlers. The Java `HttpRuntimeTransport`
implements `execute`, `status`, and `cancel` against this contract.

Out of scope: wiring `HttpRuntimeTransport` into `RuntimeTransport`,
Harness-side tool wiring, and a
implements `execute`, `status`, and `cancel` against this contract. A
seven-field prepared reference, the Session verbs and the provider controls
use `managed-runtime-provider/1` instead: `acquire` answers Broker-local, and
`release` and each control go through the provider control route (see
[2026-09-27-broker-provider-control.md](2026-09-27-broker-provider-control.md)).

Out of scope: ~~wiring `HttpRuntimeTransport` into `RuntimeTransport`~~
(landed through `managed-runtime-provider/1`), Harness-side tool wiring, and a
`not_started_proven` outcome, which needs the durable receipt store.

## 3. Design
Expand Down Expand Up @@ -170,9 +175,15 @@ The worker handlers described below serve these routes.

## 5. Follow-up work

- Complete the session verbs and wire `HttpRuntimeTransport` into
`RuntimeTransport`. Supply `toolName`/`input` separately from the stored
reference as described in §4.1, and cover real Broker dispatch end to end.
- ~~Complete the session verbs and wire `HttpRuntimeTransport` into
`RuntimeTransport`.~~ Landed via the `managed-runtime-provider/1` protocol;
see
[2026-09-27-broker-provider-control.md](2026-09-27-broker-provider-control.md).
The remaining gap from §4.1: the immediate `POST /executions` route still
reads `toolName`/`input` from the stored reference, so its callers must
persist tool arguments in `reference_json`; use the deferred reserve/start
path or the provider protocol instead. Giving the immediate route the same
payload separation remains open.
- The `UNKNOWN` execution reconciler shipped in #12655. Its transport must
validate the status wire envelope, then project it to `{state, result}`
(`result` only for `settled`). Strip `protocolVersion` and `lastSequence`;
Expand Down
8 changes: 4 additions & 4 deletions docs/design/2026-09-24-managed-runtime-tool-contract.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

[English](2026-09-24-managed-runtime-tool-contract.md) | [简体中文](2026-09-24-managed-runtime-tool-contract.zh-CN.md)

状态:契约、worker 处理器与 Java 工具 transport 已实现;Broker transport 接入仍为后续工作
状态:契约、worker 处理器与 Java 工具 transport 已实现;Broker transport 经 `managed-runtime-provider/1` 接入(见 [2026-09-27-broker-provider-control.zh-CN.md](2026-09-27-broker-provider-control.zh-CN.md))

相关:#12380(Managed Agent 分阶段交付)、[2026-09-22-managed-runtime-attestation-contract.md](2026-09-22-managed-runtime-attestation-contract.md) 的 attestation 契约,以及 #12380 上本契约所答复的对账讨论。

Expand All @@ -16,9 +16,9 @@ owned Managed Runtime worker 在 attestation 之外增加三个工具操作—

## 2. 范围

范围内:路由清单声明、共享 schema 与 conformance fixtures,以及 worker 处理器和对应的 raw HTTP gate 放行。TypeScript 契约测试与 Java fixture 消费方共享契约;worker 测试覆盖已挂载的处理器。Java `HttpRuntimeTransport` 按本契约实现 `execute`、`status`、`cancel`。
范围内:路由清单声明、共享 schema 与 conformance fixtures,以及 worker 处理器和对应的 raw HTTP gate 放行。TypeScript 契约测试与 Java fixture 消费方共享契约;worker 测试覆盖已挂载的处理器。Java `HttpRuntimeTransport` 按本契约实现 `execute`、`status`、`cancel`。七字段的已准备 reference、会话动词和 provider 控制则改走 `managed-runtime-provider/1`:`acquire` 在 Broker 本地应答,`release` 和各项控制经 provider control 路由发送(见 [2026-09-27-broker-provider-control.zh-CN.md](2026-09-27-broker-provider-control.zh-CN.md))。

范围外:将 `HttpRuntimeTransport` 接为 `RuntimeTransport`、Harness 侧工具接线,以及 `not_started_proven` 结果(需要持久回执存储)。
范围外:~~将 `HttpRuntimeTransport` 接为 `RuntimeTransport`~~(已经由 `managed-runtime-provider/1` 落地)、Harness 侧工具接线,以及 `not_started_proven` 结果(需要持久回执存储)。

## 3. 设计

Expand Down Expand Up @@ -76,7 +76,7 @@ reference 是 harness 分配的原始调用身份;Runtime 不会得知任何 B

## 5. 后续工作

- 完成会话操作并将 `HttpRuntimeTransport` 接为 `RuntimeTransport`。按 §4.1 所述从已保存的 reference 之外单独提供 `toolName`/`input`,并端到端覆盖真实 Broker 分发。
- ~~完成会话操作并将 `HttpRuntimeTransport` 接为 `RuntimeTransport`。~~ 已经由 `managed-runtime-provider/1` 协议落地,见 [2026-09-27-broker-provider-control.zh-CN.md](2026-09-27-broker-provider-control.zh-CN.md)。§4.1 仍存的缺口:immediate `POST /executions` 路由仍然从已保存的 reference 读取 `toolName`/`input`,其调用方必须把工具参数持久化进 `reference_json`;请改用 deferred reserve/start 路径或 provider 协议。为 immediate 路由提供同样的负载分离仍为后续工作。
- `UNKNOWN` 执行对账器已在 #12655 落地。其 transport 必须先校验 status 线上信封,再投影为 `{state, result}`(仅 `settled` 携带 `result`)。去掉 `protocolVersion` 与 `lastSequence`;Broker 拒绝额外字段,目前没有游标消费方。
- 对 Runtime 报告仍在运行的执行是否发送物理取消,有意推迟。

Expand Down
2 changes: 2 additions & 0 deletions docs/design/2026-09-25-managed-context-envelope.md
Original file line number Diff line number Diff line change
Expand Up @@ -110,6 +110,8 @@ One request installs one Session's context on a Runtime and returns a receipt. W
| `binding` | an object closed to the seven `ContextBinding` fields, each with its W0a rule, as W0a's wire strings |
| `contextDigest` | a string matching `sha256:[0-9a-f]{64}` |

The Broker acquires only the narrower Runtime Session IDs that [Broker Provider Control](2026-09-27-broker-provider-control.md) admits.

The worker checks the request in this order and stops at the first failure:

1. A request that breaks the shape is 400 `managed_runtime_attestation_invalid`.
Expand Down
2 changes: 2 additions & 0 deletions docs/design/2026-09-25-managed-context-envelope.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -110,6 +110,8 @@ Attestation v3 保留 v2 的 gate,只改变身份字段。
| `binding` | 封闭为七个 `ContextBinding` 字段的对象,每个字段适用 W0a 的规则,取 W0a 的线上字符串形式 |
| `contextDigest` | 匹配 `sha256:[0-9a-f]{64}` 的字符串 |

Broker 只获取 [Broker Provider 控制](2026-09-27-broker-provider-control.zh-CN.md)所允许的更窄的 Runtime Session ID。

worker 按以下顺序检查请求,遇到第一个失败就停止:

1. 不符合形状的请求返回 400 `managed_runtime_attestation_invalid`。
Expand Down
16 changes: 8 additions & 8 deletions docs/design/2026-09-26-managed-context-worker.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,7 @@ Under boot v1 there is no gate, and every call runs in `workspaceCwd`, as before

### Retention

A Runtime keeps its installations for its lifetime, as it keeps its tool journal. Nothing is evicted, so step 5 keeps protecting a live Session, and an `operationId` reused with other values is always refused. The Broker bounds that lifetime when it reclaims the Runtime. Each entry holds only bounded fields, a few kilobytes at most. Tool configurations are not kept: each call builds its own, in its Session's context so that core does not keep it for its debug log, and core compiles only once each parameter schema that JSON text describes exactly and that compiles the first time, so rebuilding adds no compiled validators. Each Session also keeps three small entries under its key for the Runtime's lifetime, as its installation is kept: its project directory, and core's record of its model and model identity. Releasing a Session's entries earlier needs a signal that the Session has ended. The Broker's `release` session verb is that signal, and it has no worker route yet.
A Runtime keeps its installations for its lifetime, as it keeps its tool journal. Nothing is evicted, so step 5 keeps protecting a live Session, and an `operationId` reused with other values is always refused. The Broker bounds that lifetime when it reclaims the Runtime. Each entry holds only bounded fields, a few kilobytes at most. Tool configurations are not kept: each call builds its own, in its Session's context so that core does not keep it for its debug log, and core compiles only once each parameter schema that JSON text describes exactly and that compiles the first time, so rebuilding adds no compiled validators. Each Session also keeps three small entries under its key for the Runtime's lifetime, as its installation is kept: its project directory, and core's record of its model and model identity. Releasing a Session's entries earlier needs a signal that the Session has ended. The Broker's `release` session verb is that signal, and it now reaches the worker through the provider control route (see [Broker Provider Control](2026-09-27-broker-provider-control.md)). That release permanently closes the Session's admission, but it drops neither its installation, which a Workspace activation release that follows still reads, nor these three entries. It drops only the entries that core keeps under the Runtime Session ID itself, which exist for a Session acquired through that route.

### Errors

Expand All @@ -119,7 +119,7 @@ The envelope left four questions to W0c. The worker answers them as follows:
1. **Refusal line.** The worker writes none. A worker that implements only v1 cannot write one, so the Broker could never rely on it. Instead, W0c-2 bounds boot v2 retries and never retries as v1.
2. **Configuration installation.** Still open. This slice installs no configuration, and the route keeps its v3 shape. Whether the installation request carries it, or a later version of the route does, is undecided.
3. **Control characters in `cwdRelative`.** The worker applies the W0a rule unchanged, which refuses every Cc character. If W0a narrows the rule, the worker follows it.
4. **Retention.** A Runtime's lifetime, as above. Releasing entries earlier waits for the session verbs.
4. **Retention.** A Runtime's lifetime, as above. The session verbs have landed, but `release` keeps a Session's installation and its entries (see [Retention](#retention)), so releasing them earlier is still open.

## Security

Expand Down Expand Up @@ -184,9 +184,9 @@ The envelope left four questions to W0c. The worker answers them as follows:

## Follow-up work

| Slice | Scope |
| ------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| W0c-2 | The provisioner writes boot v2 and checks ready v2; the v3 attestation and installation clients; no downgrade, and a retry bound for boot v2; identifier and Session ID checks tightened to the envelope's rules; a test that the Broker's JSON writer leaves non-ASCII characters unescaped; `managed_context_unavailable` from installation and `execute`. |
| W0c-3 | Session and storage resolvers in `managed-agent-server` instead of one startup directory, and the Workspace turn lease for shared Workspaces. |
| Session verbs | A worker route for `release`, which drops the released Session's installation. |
| Configuration | Installing configuration from `contextConfigRef`, in the installation request or in a later version of the route (open question 2). |
| Slice | Scope |
| ------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| W0c-2 | The provisioner writes boot v2 and checks ready v2; the v3 attestation and installation clients; no downgrade, and a retry bound for boot v2; identifier and Session ID checks tightened to the envelope's rules; a test that the Broker's JSON writer leaves non-ASCII characters unescaped; `managed_context_unavailable` from installation and `execute`. |
| W0c-3 | Session and storage resolvers in `managed-agent-server` instead of one startup directory, and the Workspace turn lease for shared Workspaces. |
| Session verbs | Landed with a difference via the provider control route (`managed-runtime-provider/1`): `release` permanently closes the Session's admission and deliberately does _not_ drop the installation, which a Workspace activation release that follows still reads. The activation release does not drop it either, so installations are still kept for the Runtime's lifetime (see [Retention](#retention)). See [2026-09-27-broker-provider-control.md](2026-09-27-broker-provider-control.md). |
| Configuration | Installing configuration from `contextConfigRef`, in the installation request or in a later version of the route (open question 2). |
Loading
Loading