Repository navigation
feat(spec): bridge protocol v0.1 — ops, capabilities, transports, security - #68
Merged
Merged
Conversation
…urity JSON-RPC 2.0 contract (LSP-for-extensions): protocolVersion + spec-version handshake, 8-op closed set, capability model for host env slots, stdio / HTTP-loopback / in-process transports, caller identity + per-caller op scoping, loopback auth + threat boundaries.
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
4 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
Draft of the AnyHarness bridge protocol v0.1 — the versioned JSON-RPC contract ("LSP-for-extensions") that lets any agent harness adopt the registry + install + trust layer by implementing the client side once, instead of building a plugin system. Part of the v2 foundation plan (
.agents/plans/2026-10-07-v2-foundation.md, W3).Changes
Adds
spec/bridge/:protocol.md— JSON-RPC 2.0 envelope (NDJSON framing, no batches),protocolVersionhandshake + sibling-spec version negotiation (specsmap referencingspec/manifest.md's versioning policy by name), error model (standard codes +-32001…-32012bridge codes +-32800cancel), ordering/streaming rules (streamId-correlatedevents.notifyfor hook progress/deltas), session lifecycle.operations.md— the exact 8-op set:capabilities.negotiate,extensions.list,extensions.get,hooks.invoke,commands.resolve,skills.materialize,tools.call(MCP passthrough),events.notify. Each op: params, result, error codes, and when the harness calls it.capabilities.md—Capabilities= declaredExtensionKinds + canonical hook events + host env slots (storage|secrets|exec|skills|mcp); graceful-degradation-by-filtering rules; feature-vs-permission split.transports.md— stdio (primary;harness serve, NDJSON), HTTP loopback (daemon + browser contexts; bearer token,serve.jsonport/token discovery, SSE notifications), in-process (@any-harness/sdkcreateBridge()); caller-identity model + per-callerallow/denyop scoping for daemon mode.messages.schema.json— JSON Schema draft 2020-12 for the envelope and every op's params/result.security.md— trust boundaries (adopting the bridge = adopting the trust layer), per-context loopback threat model (file perms vs bearer/CORS/Host-header rules), script-policy surfacing through capabilities, non-goals.Interface pins kept verbatim:
Extension,ExtensionKind,ManifestRef,Capabilities. Store layout and manifest fields are referenced by name (spec/store-layout.md,spec/manifest.md,spec/lockfile.md,spec/trust.md), never redefined.Test plan
pnpm testpasses — n/a, docs-only change, no code touchedpnpm -r exec tsc --noEmitpasses — n/a, no TS changesmessages.schema.jsonparses as valid JSONNotes
Content-Lengthheaders (matches MCP stdio); cancellation routed throughevents.notify/request.cancelledto keep the op set closed at 8;auth-failed/forbidden/capability-unsupportedkept as three distinct failure axes (401/403/feature-grant); TLS off on loopback, justified insecurity.md§2.Link to Devin session: https://app.devin.ai/sessions/47d4fa2868ca426eb7bfc3181b136e00
Open in Devin Desktop: https://app.devin.ai/desktop/session/47d4fa2868ca426eb7bfc3181b136e00?variant=devin
Requested by: @espetro