Skip to content

Separate world ownership from clients and expose authored source inspection - #8

Merged
everettVT merged 3 commits into
mainfrom
codex/observer-runtime-boundaries
Sep 19, 2026
Merged

everettVT merged 3 commits into
mainfrom
codex/observer-runtime-boundaries

Conversation

@everettVT

Copy link
Copy Markdown
Owner

The observer previously owned its runtime through a stdin connection, so closing an HTTP process could stop every world. Add an explicit private Unix attachment endpoint whose native owner outlives clients, with bounded framing, owner/request identities and mutation preconditions. Add parser-backed source inspection so saved definitions can expose authored logic without execution.

Includes the previously published module grouping and lowering-v2 commit that has not yet reached main. Existing stdio remains supported.

Validation: locked workspace tests, formatting, Clippy (MCP features), native worlds acceptance; observer attachment tests for bad frames, stale identities, timeouts and HTTP replacement; two fresh native HHMM worlds retained PID/generation/revision/rows across two HTTP incarnations and were stopped with children reaped. Optional all-features Iceberg validation requires Rust 1.95; this host has 1.94.1.

everettVT and others added 2 commits September 14, 2026 22:33
…ansport

A composed program used to reach the observer as thousands of flat operators
with no structure. Three changes give it a block diagram and cut it in half:

- Module blocks (A13): a world built from a composition synthesizes one
  authored group per composition node from the resolution's generated relation
  prefixes, plus Inputs and Outputs blocks, with child names taken from the
  library association. Groups carry `kind: "module"` and resolve at snapshot
  time by debug pattern followed by neighbour propagation (majority vote over
  channel neighbours, bounded rounds), so they never pin build-specific
  operator ids. Blocks skip the box layout invariants, nest by containment,
  and report `mapping_report` counts including unattributed operators.
  The Inputs and Outputs blocks match the external operators themselves and do
  not propagate, so aliased bindings cannot pull module internals out of their
  block.
- Lean composition lowering (A14): `LoweringOptions { explain, export_internal,
  alias_bindings }` with a version 2 that omits Evidence relations, exports only
  external outputs, and aliases bound inputs to their single source. Public
  relation contents are identical at every revision, proven natively under both
  lowerings. Records verify under their own recorded `lowering_version`, so
  registered compositions stay valid; managed worlds build under version 2.
  Measured on the X0 composed agent: 260 relations and 2,495 native operators
  become 101 relations and 1,095 operators.
- Direct provider transport: the inference worker's `ProviderClient` gains
  `transport: "direct"` with `api_key_env`, sending the bearer token from the
  named environment variable at call time. The key never enters the config, its
  hash, or any result. Modal configs keep their bound hashes unchanged.

Tests: fake-driver module-group synthesis, propagation, nesting, precedence and
report counts; lowering version 2 text, registry round-trips and a native
equivalence test; provider transport unit tests. Docs in docs/worlds.md,
docs/inspection.md and docs/operations.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@everettVT
everettVT merged commit 1f9f417 into main Sep 19, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant