Repository navigation
Author syscalls: agent-facing launch/sleep tool (JSON becomes internal ABI) - #133
Conversation
…l ABI
The author's interface is now a tool, not hand-written JSON (Mengye 2026-08-24):
syscall_cli.py — standalone by contract (stdlib-only; the kernel copies its
source into the sandbox at .autoresearch/syscall, since the target repo lacks
autoresearch). The author calls:
python .autoresearch/syscall launch --name train --minutes 90 \
--artifact results/curve.json -- uv run python train.py --lr 3e-4
python .autoresearch/syscall note "..."; status; cancel
python .autoresearch/syscall sleep # commit + end turn
launch/note stage into request.json; sleep commits to syscall.json (the ABI the
kernel reads). Building a request and committing to hibernate are separate acts,
so an in-progress request never triggers a sleep. The big win over raw JSON:
validation is INTERACTIVE — bad name/minutes/path/command fail in-session
immediately, never as a burned post-sleep session-error.
The tool is a convenience layer, NEVER a trust boundary: syscall.py's
read_request stays the authoritative validator (an author that writes the ABI
directly is still fully checked). Kernel side: install_tool() copies the tool +
write_budget() drops the informational budget the tool's shows; both
run in live_climb's armed block (still dark behind the AUTHOR_SLEEP_WAKE_READY
interlock). syscall.py docstring reframed: JSON = internal ABI, tool = surface.
Tests: the full CLI surface (stage/commit/checkpoint/validation-fails-fast/
budget) via main(argv), plus a run of the INSTALLED copy proving it
is standalone under a bare interpreter (no site-packages) like the sandbox.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
Round 1 — reviewed head 28596594 — reviewer hermes/gpt-5.6-terra.
terra
Advisory findings from autoresearch — the code owner decides. Reply to disagree; the autoresearch:no-review label opts this PR out.
Verdict: 2 blocking, 0 advisory.
2 findings attached to the lines below.
Two blocking findings, both real: - SYMLINK CHANNEL: a target could commit `.autoresearch` as a symlink to a host path; install_tool/ensure_excluded/write_budget would then write THROUGH it with the orchestrator's permissions. Fix: the channel must be kernel-owned — a single guard BEFORE any channel write disables author syscalls for the run if `.autoresearch` pre-exists in ANY form (symlink, tracked dir, or tracked file) in the fresh clone. This also subsumes the old tracked-request check (one guard now, checked before the install, not after). Test: a symlinked `.autoresearch` -> the run proceeds with the feature off and nothing is written through the link. - QUOTED ARGS LOST: the CLI joined the parsed command tokens with " ", so `-- python t.py --label "a b"` collapsed `a b` into two args. Fix: shlex.join re-quotes the tokens so the eventual `sh -c "$(cat command.txt)"` re-parses the SAME tokens. Test: round-trips `--label "a b"`/`--flag=x y` through the CLI -> ABI -> kernel reader and shlex.split back to the exact tokens. Gate green; 745 tests.
There was a problem hiding this comment.
Round 2 — reviewed head a902f46a — reviewer hermes/gpt-5.6-terra.
terra
Advisory findings from autoresearch — the code owner decides. Reply to disagree; the autoresearch:no-review label opts this PR out.
Verdict: nothing blocking — 1 advisory note.
1 finding attached to the lines below.
The CLI's artifact-path check was looser than syscall._rel_path_ok — `.`, `out/./x`, `out//x`, and empty passed the tool but failed the kernel reader, so the author would burn a sleep on a post-session validation error (the exact failure the tool exists to prevent). The tool now uses an identical _rel_path_ok (duplicated by contract — the CLI is standalone — with a comment binding it to the kernel's). A parity test cross-checks every tricky path through BOTH validators and asserts they agree. Gate green; 746 tests.
There was a problem hiding this comment.
Round 3 — reviewed head d57dd7cb — reviewer hermes/gpt-5.6-terra.
terra
Advisory findings from autoresearch — the code owner decides. Reply to disagree; the autoresearch:no-review label opts this PR out.
Verdict: no defects found.
No defects found in the reviewed diff.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The judge's checkout is the author's tree, so it could ship .verdict as a symlink to a host path and install_tool's write_text would write through it (same class as the syscall channel, #133 r1). install_tool now removes any pre-existing .verdict (symlink -> unlink, dir -> rmtree, file -> unlink) and recreates it as a kernel-owned dir, so nothing is followed. Test: a symlinked .verdict -> real dir after install, nothing written through to the target. Full gate green; 764 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
What
The author's interface for launch/sleep is now a tool, not hand-written JSON (your 2026-08-24 redirect).
.autoresearch/syscall.jsonbecomes an internal ABI; the agent drives everything through a CLI:syscall_cli.py— standalone by contract (stdlib-only; the kernel copies its source into the sandbox, since the target repo has no autoresearch).launch/notestage intorequest.json;sleepcommits tosyscall.json(the ABI). Building a request and committing to hibernate are separate acts — an in-progress request never triggers a sleep;sleepwith nothing staged is a checkpoint.--name/--minutes/--artifact/command fail in-session immediately, instead of becoming a burned post-sleepsession-error.syscall.py'sread_requeststays the authoritative validator — an author that writes the ABI directly is still fully checked. The tool is pure UX.install_tool()+write_budget()run inlive_climb's armed block. Still fully dark behind theAUTHOR_SLEEP_WAKE_READYinterlock (the wake is the next PR).Test plan
main(argv): stage → commit → ABI parses through the kernel reader; note/status/cancel; checkpoint sleep; validation-fails-fast (5 cases) + duplicate-name.python -Irun of the installed copy — proves it's standalone under a bare interpreter (no site-packages), exactly like the sandbox.No secrets / no large files
Confirmed.