Skip to content

docs(spec): L0 spec suite — store layout, manifest, lockfile, trust - #70

Merged
devin-ai-integration[bot] merged 6 commits into
v2from
feat/l0-spec
Oct 8, 2026
Merged

devin-ai-integration[bot] merged 6 commits into
v2from
feat/l0-spec

Conversation

@espetro

@espetro espetro commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

L0 specification suite for AnyHarness: four normative spec docs under spec/ with a companion JSON Schema each, plus a refreshed spec/README.md index. Everything is a delta on existing conventions — we codify what exists (skills/, Agent Plugins 1.0, skills.sh locks) and ship explicitly-namespaced extensions (harness/, dev.anyharness/). We claim exactly one ~/.agents/ root key: harness/.

Changes

  • spec/store-layout.md + store-layout.schema.json — ~/.agents/ coexistence: harness/ sole owned key (packages/, data/, extensions.lock, config.toml, audit.log, store.json, tmp/, .lock inside); skills/ adopted per the Agent Skills spec with foreign-dir protections; plugins/ never touched (Codex marketplace.json + rival claimants); mcp.json member-level merge only; skills.sh .skill-lock.json/skills-lock.json read-only. Pins Extension, ExtensionKind (skill | mcp | plugin | hook | command | agent | rule), ManifestRef, Capabilities. Atomic-write protocol + harness/.lock mutex + skills/ ownership reconciliation.
  • spec/manifest.md + manifest.schema.json — Agent Plugins 1.0 plugin.json adopted verbatim as closed base (cited, not redefined); dev.anyharness vendor namespace in both forms per their §8 precedent (com.github.copilot): extensions["dev.anyharness"] data (namespaceVersion, capabilities, engines.harness semver range) and the dev.anyharness/ extension directory (hooks.json, commands/, agents/, rules/, setup). Component locations map to ExtensionKind. Four-layer versioning policy (base $schema, namespaceVersion, per-kind formats, engines.harness). Manifests are data — JSON only, never runtime-evaluated.
  • spec/lockfile.md + lockfile.schema.json — harness/extensions.lock: per-Extension {kind, manifest: ManifestRef, source{type: git|github|registry|local, uri, ref, path}, integrity sha256 (SRI syntax), installedAt, updatedAt, targets[], components, capabilities, attestations}. Floating refs MUST resolve to commit SHAs at install. SRI manifest-of-files digest construction specified; treeHash reserved for GitHub tree-SHA update checks. Field-level interop mapping to skills.sh lock conventions documented.
  • spec/trust.md + trust.schema.json — full threat model: agent-executed installs (prompt-injection → package install vector; actor-aware policy defaults ask→deny non-interactive + sources.allow allowlists), executable components (no-sandbox stance stated), provenance (git-pin + digest; sigstore attestations reserved not required), and an explicit descope statement (installer + lockfile + integrity + audit; no central registry, no sandbox, no mandatory signing). Integrity verification at install and load; config.toml [policy] exec defaults; append-only harness/audit.log JSONL with closed event enum.

Test plan

  • All four schemas pass jsonschema meta-validation and validate positive + negative fixture instances (namespaceVersion>1 rejected, bad extension name rejected, bad audit event rejected)
  • pnpm test — N/A (docs + JSON only; no code touched)
  • Linked to a refined issue in Project 14

Notes

  • Companion to the parallel feat/bridge-spec work: Extension/ExtensionKind/ManifestRef/Capabilities names are used verbatim in prose and schema $defs.
  • The root README.md "Store" diagram still shows extensions.lock/anyharness.toml at ~/.agents/ root — superseded by the single-root-key layout spec'd here (config file is harness/config.toml). Left untouched per scaffold rules; flagged for owner review.
  • Canonical $id domain anyharness.dev is provisional pending the org/domain decision.

Link to Devin session: https://app.devin.ai/sessions/f361123e8d92416ebd96b59c204a8ec2
Open in Devin Desktop: https://app.devin.ai/desktop/session/f361123e8d92416ebd96b59c204a8ec2?variant=devin
Requested by: @espetro

~/.agents coexistence rules: harness/ as the sole owned root key
(packages/, data/, extensions.lock, config.toml, audit.log, store.json,
tmp/, .lock inside), skills/ adopted per Agent Skills spec, plugins/
never touched, mcp.json merge-only, skills-lock read-only. Pins
Extension/ExtensionKind/ManifestRef/Capabilities. Write mutex,
atomic-write protocol, and skills.sh ownership reconciliation.
Agent Plugins 1.0 plugin.json as closed base (fields adopted by
reference), dev.anyharness vendor namespace in both forms:
extensions["dev.anyharness"] manifest data (namespaceVersion,
capabilities, engines.harness) and the dev.anyharness/ extension
directory (hooks.json, commands/, agents/, rules/, setup). Component
discovery maps to ExtensionKind; 4-layer versioning policy.
Per-Extension {kind, manifest: ManifestRef, source{type,uri,ref,path},
integrity sha256 (SRI), installedAt/updatedAt, targets[], components,
capabilities, attestations}. Pinned-ref reproducibility, manifest-of-
files digest construction, skills.sh field-interop mapping.
Threat model covering agent-executed installs (prompt-injection to
package install), executable components, provenance (git-pin + digest;
sigstore attestations reserved), explicit descope (no sandbox, no
central registry, no mandatory signing). Integrity verification at
install and load, config.toml exec policy defaults (ask -> deny
non-interactive), append-only audit.log JSONL.
@devin-ai-integration

Copy link
Copy Markdown

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Deploying agentplugins with  Cloudflare Pages  Cloudflare Pages

Latest commit: f1c0ee8
Status:🚫  Build failed.

View logs

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot was not present after the first check poll, so that signal was skipped; no applicable approval policy requires human review, and this automation has no prior approval to re-evaluate. Remaining configured signals are clean.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

[[serve.caller]] (caller identity + per-token allow/deny op lists for
HTTP-loopback daemon mode) is owned by spec/bridge/transports.md §3 —
this spec defines only the reservation and the key-partitioning rule
for config.toml.
@devin-ai-integration
devin-ai-integration Bot merged commit 2143b48 into v2 Oct 8, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant