Skip to content

Author syscalls: agent-facing launch/sleep tool (JSON becomes internal ABI) - #133

Merged
renmengye merged 3 commits into
mainfrom
feat/author-syscall-tool
Aug 24, 2026
Merged

renmengye merged 3 commits into
mainfrom
feat/author-syscall-tool

Conversation

@renmengye

Copy link
Copy Markdown
Member

What

The author's interface for launch/sleep is now a tool, not hand-written JSON (your 2026-08-24 redirect). .autoresearch/syscall.json becomes an internal ABI; the agent drives everything through a CLI:

python .autoresearch/syscall launch --name train --minutes 90 \
    --artifact results/curve.json -- uv run python train.py --lr 3e-4
python .autoresearch/syscall note "compare with the lr sweep"
python .autoresearch/syscall status        # staged launches + remaining budget
python .autoresearch/syscall sleep         # commit, then end the turn
  • syscall_cli.py — standalone by contract (stdlib-only; the kernel copies its source into the sandbox, since the target repo has no autoresearch). launch/note stage into request.json; sleep commits to syscall.json (the ABI). Building a request and committing to hibernate are separate acts — an in-progress request never triggers a sleep; sleep with nothing staged is a checkpoint.
  • The win over raw JSON: interactive validation. Bad --name/--minutes/--artifact/command fail in-session immediately, instead of becoming a burned post-sleep session-error.
  • Not a trust boundary. syscall.py's read_request stays the authoritative validator — an author that writes the ABI directly is still fully checked. The tool is pure UX.
  • Kernel side: install_tool() + write_budget() run in live_climb's armed block. Still fully dark behind the AUTHOR_SLEEP_WAKE_READY interlock (the wake is the next PR).

Test plan

  • Full CLI surface via main(argv): stage → commit → ABI parses through the kernel reader; note/status/cancel; checkpoint sleep; validation-fails-fast (5 cases) + duplicate-name.
  • A python -I run of the installed copy — proves it's standalone under a bare interpreter (no site-packages), exactly like the sandbox.
  • The armed live climb test now asserts the tool + budget land in the channel dir.
  • Full suite 743 green; ruff + mypy green.

No secrets / no large files

Confirmed.

…l ABI

The author's interface is now a tool, not hand-written JSON (Mengye 2026-08-24):
syscall_cli.py — standalone by contract (stdlib-only; the kernel copies its
source into the sandbox at .autoresearch/syscall, since the target repo lacks
autoresearch). The author calls:

  python .autoresearch/syscall launch --name train --minutes 90 \
      --artifact results/curve.json -- uv run python train.py --lr 3e-4
  python .autoresearch/syscall note "..."; status; cancel
  python .autoresearch/syscall sleep     # commit + end turn

launch/note stage into request.json; sleep commits to syscall.json (the ABI the
kernel reads). Building a request and committing to hibernate are separate acts,
so an in-progress request never triggers a sleep. The big win over raw JSON:
validation is INTERACTIVE — bad name/minutes/path/command fail in-session
immediately, never as a burned post-sleep session-error.

The tool is a convenience layer, NEVER a trust boundary: syscall.py's
read_request stays the authoritative validator (an author that writes the ABI
directly is still fully checked). Kernel side: install_tool() copies the tool +
write_budget() drops the informational budget the tool's  shows; both
run in live_climb's armed block (still dark behind the AUTHOR_SLEEP_WAKE_READY
interlock). syscall.py docstring reframed: JSON = internal ABI, tool = surface.

Tests: the full CLI surface (stage/commit/checkpoint/validation-fails-fast/
budget) via main(argv), plus a  run of the INSTALLED copy proving it
is standalone under a bare interpreter (no site-packages) like the sandbox.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head 28596594 — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from autoresearch — the code owner decides. Reply to disagree; the autoresearch:no-review label opts this PR out.

Verdict: 2 blocking, 0 advisory.

2 findings attached to the lines below.

Comment thread src/autoresearch/syscall.py
Comment thread src/autoresearch/syscall_cli.py Outdated
Two blocking findings, both real:

- SYMLINK CHANNEL: a target could commit `.autoresearch` as a symlink to a host
  path; install_tool/ensure_excluded/write_budget would then write THROUGH it
  with the orchestrator's permissions. Fix: the channel must be kernel-owned —
  a single guard BEFORE any channel write disables author syscalls for the run
  if `.autoresearch` pre-exists in ANY form (symlink, tracked dir, or tracked
  file) in the fresh clone. This also subsumes the old tracked-request check
  (one guard now, checked before the install, not after). Test: a symlinked
  `.autoresearch` -> the run proceeds with the feature off and nothing is
  written through the link.

- QUOTED ARGS LOST: the CLI joined the parsed command tokens with " ", so
  `-- python t.py --label "a b"` collapsed `a b` into two args. Fix: shlex.join
  re-quotes the tokens so the eventual `sh -c "$(cat command.txt)"` re-parses
  the SAME tokens. Test: round-trips `--label "a b"`/`--flag=x y` through the
  CLI -> ABI -> kernel reader and shlex.split back to the exact tokens.

Gate green; 745 tests.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 2 — reviewed head a902f46a — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from autoresearch — the code owner decides. Reply to disagree; the autoresearch:no-review label opts this PR out.

Verdict: nothing blocking — 1 advisory note.

1 finding attached to the lines below.

Comment thread src/autoresearch/syscall_cli.py
The CLI's artifact-path check was looser than syscall._rel_path_ok — `.`,
`out/./x`, `out//x`, and empty passed the tool but failed the kernel reader, so
the author would burn a sleep on a post-session validation error (the exact
failure the tool exists to prevent). The tool now uses an identical _rel_path_ok
(duplicated by contract — the CLI is standalone — with a comment binding it to
the kernel's). A parity test cross-checks every tricky path through BOTH
validators and asserts they agree.

Gate green; 746 tests.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 3 — reviewed head d57dd7cb — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from autoresearch — the code owner decides. Reply to disagree; the autoresearch:no-review label opts this PR out.

Verdict: no defects found.

No defects found in the reviewed diff.

renmengye added a commit that referenced this pull request Aug 24, 2026
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@renmengye
renmengye merged commit c60fccf into main Aug 24, 2026
3 checks passed
@renmengye
renmengye deleted the feat/author-syscall-tool branch August 24, 2026 11:34
renmengye added a commit that referenced this pull request Aug 24, 2026
The judge's checkout is the author's tree, so it could ship .verdict as a
symlink to a host path and install_tool's write_text would write through it
(same class as the syscall channel, #133 r1). install_tool now removes any
pre-existing .verdict (symlink -> unlink, dir -> rmtree, file -> unlink) and
recreates it as a kernel-owned dir, so nothing is followed. Test: a symlinked
.verdict -> real dir after install, nothing written through to the target.

Full gate green; 764 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant