Repository navigation
docs(spec): L0 spec suite — store layout, manifest, lockfile, trust - #70
Merged
Merged
Conversation
~/.agents coexistence rules: harness/ as the sole owned root key (packages/, data/, extensions.lock, config.toml, audit.log, store.json, tmp/, .lock inside), skills/ adopted per Agent Skills spec, plugins/ never touched, mcp.json merge-only, skills-lock read-only. Pins Extension/ExtensionKind/ManifestRef/Capabilities. Write mutex, atomic-write protocol, and skills.sh ownership reconciliation.
Agent Plugins 1.0 plugin.json as closed base (fields adopted by reference), dev.anyharness vendor namespace in both forms: extensions["dev.anyharness"] manifest data (namespaceVersion, capabilities, engines.harness) and the dev.anyharness/ extension directory (hooks.json, commands/, agents/, rules/, setup). Component discovery maps to ExtensionKind; 4-layer versioning policy.
Per-Extension {kind, manifest: ManifestRef, source{type,uri,ref,path},
integrity sha256 (SRI), installedAt/updatedAt, targets[], components,
capabilities, attestations}. Pinned-ref reproducibility, manifest-of-
files digest construction, skills.sh field-interop mapping.
Threat model covering agent-executed installs (prompt-injection to package install), executable components, provenance (git-pin + digest; sigstore attestations reserved), explicit descope (no sandbox, no central registry, no mandatory signing). Integrity verification at install and load, config.toml exec policy defaults (ask -> deny non-interactive), append-only audit.log JSONL.
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
There was a problem hiding this comment.
Approved. Cursor Bugbot was not present after the first check poll, so that signal was skipped; no applicable approval policy requires human review, and this automation has no prior approval to re-evaluate. Remaining configured signals are clean.
Sent by Cursor Approval Agent: Pull Request Router and Approver
[[serve.caller]] (caller identity + per-token allow/deny op lists for HTTP-loopback daemon mode) is owned by spec/bridge/transports.md §3 — this spec defines only the reservation and the key-partitioning rule for config.toml.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
L0 specification suite for AnyHarness: four normative spec docs under
spec/with a companion JSON Schema each, plus a refreshedspec/README.mdindex. Everything is a delta on existing conventions — we codify what exists (skills/, Agent Plugins 1.0, skills.sh locks) and ship explicitly-namespaced extensions (harness/,dev.anyharness/). We claim exactly one~/.agents/root key:harness/.Changes
spec/store-layout.md+store-layout.schema.json—~/.agents/coexistence:harness/sole owned key (packages/,data/,extensions.lock,config.toml,audit.log,store.json,tmp/,.lockinside);skills/adopted per the Agent Skills spec with foreign-dir protections;plugins/never touched (Codexmarketplace.json+ rival claimants);mcp.jsonmember-level merge only; skills.sh.skill-lock.json/skills-lock.jsonread-only. PinsExtension,ExtensionKind(skill | mcp | plugin | hook | command | agent | rule),ManifestRef,Capabilities. Atomic-write protocol +harness/.lockmutex +skills/ownership reconciliation.spec/manifest.md+manifest.schema.json— Agent Plugins 1.0plugin.jsonadopted verbatim as closed base (cited, not redefined);dev.anyharnessvendor namespace in both forms per their §8 precedent (com.github.copilot):extensions["dev.anyharness"]data (namespaceVersion,capabilities,engines.harnesssemver range) and thedev.anyharness/extension directory (hooks.json,commands/,agents/,rules/,setup). Component locations map toExtensionKind. Four-layer versioning policy (base$schema,namespaceVersion, per-kind formats,engines.harness). Manifests are data — JSON only, never runtime-evaluated.spec/lockfile.md+lockfile.schema.json—harness/extensions.lock: per-Extension{kind, manifest: ManifestRef, source{type: git|github|registry|local, uri, ref, path}, integrity sha256 (SRI syntax), installedAt, updatedAt, targets[], components, capabilities, attestations}. Floating refs MUST resolve to commit SHAs at install. SRI manifest-of-files digest construction specified;treeHashreserved for GitHub tree-SHA update checks. Field-level interop mapping to skills.sh lock conventions documented.spec/trust.md+trust.schema.json— full threat model: agent-executed installs (prompt-injection → package install vector; actor-aware policy defaultsask→denynon-interactive +sources.allowallowlists), executable components (no-sandbox stance stated), provenance (git-pin + digest; sigstoreattestationsreserved not required), and an explicit descope statement (installer + lockfile + integrity + audit; no central registry, no sandbox, no mandatory signing). Integrity verification at install and load;config.toml [policy]exec defaults; append-onlyharness/audit.logJSONL with closed event enum.Test plan
jsonschemameta-validation and validate positive + negative fixture instances (namespaceVersion>1 rejected, bad extension name rejected, bad audit event rejected)pnpm test— N/A (docs + JSON only; no code touched)Notes
feat/bridge-specwork:Extension/ExtensionKind/ManifestRef/Capabilitiesnames are used verbatim in prose and schema$defs.README.md"Store" diagram still showsextensions.lock/anyharness.tomlat~/.agents/root — superseded by the single-root-key layout spec'd here (config file isharness/config.toml). Left untouched per scaffold rules; flagged for owner review.$iddomainanyharness.devis provisional pending the org/domain decision.Link to Devin session: https://app.devin.ai/sessions/f361123e8d92416ebd96b59c204a8ec2
Open in Devin Desktop: https://app.devin.ai/desktop/session/f361123e8d92416ebd96b59c204a8ec2?variant=devin
Requested by: @espetro