You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Track the advanced integration of concurrent Intents, constrained local resources, durable execution, remote labor, privacy, payments, and recovery.
This issue owns a finite architecture-and-evidence review and its decomposition into bounded work. It links existing delivery issues without expanding their acceptance criteria or making advanced work a prerequisite for the first local conversation or multimodal receipt.
“Advanced execution” names a finite architecture-and-evidence review. It introduces no runtime component, umbrella implementation, or additional authority.
This issue records coverage, dependencies, review findings, and follow-up scope.
#52 remains the project-wide roadmap and contribution route.
Accepted changes belong in their existing canonical owners. A discussion, diagram, closed issue, or passing simulation does not independently establish architecture or delivered behavior.
Current evidence boundary
The verified envelope remains local, loopback-oriented, single-user, and one control process.
State records available subsets for deployment-plan compilation, the narrow Animator/Dispatcher path, and Topology-A Run execution. Safe runtime transitions, persistence, consent recovery, and delegated execution have explicit partial boundaries. Host/model integration still needs named operator receipts.
Resource-aware scheduling, general service capabilities, execution-road planning, verified Privacy Cuts and egress, native Oculus, Shadow, A2A, Tether, Toll, and Legion remain designed within their respective boundaries. Portal grant issuance remains quarantined. The delegated reference adapter performs no external effect. Current Graph execution is serial; hardware waits are live and do not generally survive process loss.
Use State’s exact labels and limits when recording a review. Missing evidence is a review gap; an unknown physical observation is runtime uncertainty. Neither is a replacement delivery classification.
Advanced scenario
Use one versioned synthetic scenario, with independently executable stages as their dependencies become available.
The initial host profile is Linux with systemd, cgroup v2, and rootless Podman/Quadlet. Illustrative inputs are one 24 GiB GPU, an already-WARM coder profile with an 18 GiB observation and live leases, a conflicting vision profile with a 20 GiB observation, and an embedder profile with a 5 GiB observation and declared coexistence with coder.
Those numbers are fixture inputs, not hardware qualification or proof of fit. Each measured profile must include workload conditions, observation age, active and transition-peak demand, required headroom, relevant host resources, and device identity. A declared capability must also have an admitted executable interface; family metadata alone is insufficient.
Exercise the following sequence:
Concurrent demand. Admit independent Intents for foreground coding, deadline-windowed visual work, and bounded background work. Preserve each Run’s owner, exact workflow revision, authority, budgets, and deadlines. Later include Graph — nested subgraphs & bounded parallel execution #61’s nested branches without treating independent Runs and parallel branches as the same topology.
Contention and transition. Keep existing coder leases live while vision waits. Determine whether embedding is actually admissible. Close affected admission before drain; replan after preceding transitions and refuse stale or insufficient evidence.
Future-demand weighting. Compare current-demand-only policy with a proposed bounded prediction signal for later Graph requirements. Pin its source, horizon, confidence, age, units, normalization, tie-breaks, and missing-data behavior. Record false predictions, starvation, unnecessary switches, deadline misses, and transition cost. Prediction is a proposed policy input, never an admitted future demand, lease, reservation, or effect permission.
Distinct execution roads. For an explicitly declared station, evaluate local work, one Portal operation, one contained coding AgentJob, and one sovereign A2A task according to their different labor contracts. A delegated runtime’s child provider calls are separate disclosure boundaries. A peer chooses its own private decomposition.
Consumer-specific disclosure. Use synthetic records carrying representative classifications. Create independent minimum projections and required Privacy Cuts for the provider, peer, and delegated runtime. Reject a cheaper route when its privacy, utility, authority, custody, or containment requirements fail.
Durable interruption. Inject failure before submission, after possible acceptance but before acknowledgement, after checkpoint but before park, and after terminal commit but before cleanup. Recover the exact applicable delivery, attempt, task, or job identity. Demonstrate explicit refusal where current recovery is unsupported.
Network and economic interruption. Drop an admitted Tether route and revoke its peer without public fallback. Introduce a simulated x402 challenge, changed quote, expired authorization, and ambiguous settlement. Distinguish accounting, settlement, and delivered work.
Shadow and observation. Run a bounded Shadow comparison only under admitted service/resource policy. Retain reviewed alternatives or an honest non-decision, including cleanup residue. Correlate the competing work while preserving producer ordering, gaps, observation freshness, and ledger authority.
Eventual owned-node boundary. Document how the same requirements would change under Legion: expiring advertisements, node-local admission and refusal, reservations, epochs, partitions, and stale results. This stage is a boundary review, not a fleet implementation commitment.
Related execution roads and enabling layers
The master scenario composes several declared execution roads, but it must not flatten them into interchangeable provider buckets. For each station, Spellweaver seals one admitted road decision before submission:
Operationally, Portal, delegated coding and A2A expand the set of roads that an eligible station may use. They retain different identities, authority, custody, cancellation, reconciliation and terminal-adoption contracts. Local failure does not silently admit a remote road, and changing road is not an implementation detail.
Explicit private reachability for an admitted peer or endpoint
Application role, task authority, object access, anonymity or permission to fall back to a public route
A contained CLI runtime and any provider it invokes are separate consumers. Each child call therefore needs its own declared provider binding, disclosure decision and applicable Cut; admitting the outer AgentJob does not transitively admit arbitrary network use.
The VPN relationship is similarly narrow: it can make an A2A peer reachable and thereby make that declared road operationally available, but it cannot make the peer eligible, trusted or authorized. The road decision, Ward checks, Privacy Cut, egress decision and road-specific effect record remain necessary.
A2A over optional Tether
For a station whose pinned policy admits a private A2A road, review this exact chain:
Spellweaver selects the declared A2A road
-> Ward admits peer, task and current authority
-> Context produces the peer/purpose-specific Privacy Cut
-> egress admits the exact final bytes
-> optional Tether route is already admitted and healthy
-> A2A owner persists task identity and outbound intent before submission
-> Graph parks only after durable continuation, holding no local capability lease
-> authenticated terminal result is quarantined, checked and adopted once
If Tether is required but absent before submission, that road is ineligible and the declared policy may refuse or select another already admitted road. If the tunnel drops after possible submission, no public fallback is allowed: retain the same A2A task/effect identity, expose the uncertainty and reconcile. Tunnel restoration does not mint peer authority or permit a changed payload to reuse the old identity. #19 owns task semantics and #20 owns private reachability; neither becomes a generic provider adapter.
Worker progress, configurable fallback and Graph growth
The composed scenario must prove bounded progress, not claim that arbitrary future workflows are mathematically deadlock-free:
a Run parks only after its durable wait and continuation commit; it releases run-scoped context and any local grant or lease before waiting;
Ghoul and service-attempt claims are fenced, duplicate/stale delivery is rejected, heartbeats and shutdown are bounded, and every started branch reaches a terminal, parked or explicitly unknown owner state;
no waiter retains a resource needed by the work it awaits; Orchestrator closes admission before affected-set drain, then Graph redispatches from fresh evidence after convergence;
configuration pins policy for new admissions. Dispatch — configurable ranking & bounded fallback #17 may rank or fall back only among declared semantically compatible candidates under a total budget. Cold readiness is a wait/converge/redispatch cycle, not fallback;
pre-effect refusal may admit a declared alternative. Possible submitted effects reconcile under their road-specific identity; provider, peer, payload, workspace or road changes require a new Spellweaver road decision and applicable effect identity.
Graph extension remains additive. #29 admits exact owner-qualified Spell contracts, immutable Scrolls and Resolution Locks; #61 adds bounded branch identities, joins and cancellation. A router may fold only alternatives declared by the pinned Scroll into one typed execution projection using exact predicates and capability evidence. It cannot invent an edge, import code from YAML/TOML, or rewrite a live Run. YAML is at most a typed authoring projection compiled to canonical JSON; TOML selects already registered exact identities and bounded policy.
Altar review route
The operator review should remain distributed across the existing Altar instruments rather than creating an Orchestration Master screen:
Which stations and attempts actually occurred; which road decision, grant, wait, transition, AgentJob, A2A task or external effect was retained; and where are the evidence gaps?
Which continuing concern or decision cites the exact Bridge conversation or Orb evidence, without acquiring runtime authority?
The review journey is Bridge → Orb, with Orb → Loom for declared score and Orb → Nexus for a correlated physical transition; Atlas retains explicit references and decisions. #9 owns delivery and cross-screen navigation. Missing projections remain visible gaps and do not authorize a retry or infer an event.
Authority that the scenario must preserve
Owner
Responsibility
Composition / domain
Meaning of requested work, result acceptance, records, and effects
Spellweaver
Exact score, logical coordination, temporal admission, and declared execution-road policy
Dispatcher
Match current typed demand and admit an exact eligible WARM capability with a lease
Orchestrator
Admit and serialize managed local readiness transitions; close admission, drain, revalidate, converge, compensate, or contain
Bind / Scribe / actuator / systemd
Compile and attest owned topology, then execute and classify the bounded physical transaction
Workers / Graph / Phylactery
Exact delivery ownership, supported checkpoints, durable waits, settlement, and recovery
Ward / HitL / Security / Context
Current authority, exact consent, byte-time egress, lineage, and consumer-specific transformation
Road-specific effect owner
Submission, external identity, cancellation, reconciliation, and terminal evidence
Oculus / Orb
Bounded observation and explanation, without replacing authoritative records
A waiting hardware Run holds no capability lease. Successful convergence requires fresh dispatch.
Priority does not interrupt a submitted physical transaction. A “spare capacity” label does not establish safe preemption; scarce-resource background work needs a proved yield/containment boundary or an explicitly admitted quiet window.
Generated conflict relationships, Coven grouping, and measured capacity remain different facts. Direct systemd or Podman control cannot become a second application lifecycle path.
Concern and evidence matrix
Each row needs a review result, an exact evidence route, explicit limits, and a bounded disposition for remaining work. Existing issues retain their own scope.
Headroom and transition peaks; overlapping versus disjoint devices; priority/FIFO behavior; named physical measurements separated from synthetic stress fixtures
Consumer/purpose-specific projection; complete transformation chain; independent disclosure and utility checks; exact final bytes; refusal on missing lineage or stale evidence
Local versus remote reservation and fence boundaries; node refusal; partition/restore/version-skew cases; no shared database or raw remote host authority
Canonical ADRs are listed in the Covenant index. Operational routes:
Proved pre-effect failure: a declared retry or alternative may be considered under fresh admission.
Possible submitted effect: retain the same effect identity and reconcile. Timeout, cancellation request, worker death, or missing observation does not prove containment.
Permitted exact transport redelivery: retain sealed bytes, target, road-owned identity, road decision, and Cut/namespace; require adapter-proved same-key/same-payload replay or evidence of no prior effect, plus a fresh EgressDecision and remaining disclosure allowance.
Changed semantic attempt: changed payload, provider, peer, model, workspace, policy, or custody route requires a new road decision and applicable effect identity; transformation requires a fresh consumer-specific Cut.
Terminal or unknown result: apply the road’s own terminal/adoption law. LOST, INDETERMINATE, and cancellation states must not be flattened into a generic retriable failure.
Observation loss: show the gap while preserving the authoritative ledger outcome.
Host transitions, service attempts, AgentJobs, A2A tasks, and Toll settlements have different records and recovery rules. This master does not replace them with a universal state machine.
What counts as covered
For each matrix row, record:
The exact scenario, failure injection, expected result, and responsible decision/effect owner.
The governing invariant and canonical revision inspected.
The identities and durable state required across the tested boundary.
The no-effect/effect crossing, cancellation semantics, reconciliation path, and containment limit.
Source and focused tests for implemented behavior; a maintained receipt for any claimed integrated behavior.
Evidence class and limitations: deterministic fixture, database/process restart, inert private-systemd, named host/model, or independent endpoint.
The matching State entry and its exact delivery boundary.
A disposition: covered within that boundary, accepted gap assigned to bounded work, explicitly deferred, or not applicable with rationale.
Receipts identify source/configuration/profile revisions, commands, relevant runtime versions, expected and observed outcomes, and cleanup. Deterministic control tests do not establish deterministic model answers or predictable resource availability.
Published evidence uses synthetic material and allowlisted structural fields. Prompts, credentials, private errors, raw source identifiers, and pseudonym maps do not enter the tracker or ordinary telemetry.
Bounded follow-up gaps
Confirm the smallest useful slice before opening each follow-up. Prefer an existing issue when its accepted scope already covers the work.
Proposed follow-up
Finite first result
Why existing scope is insufficient
Spellweaver — one durable deadline-windowed Occurrence
One pinned schedule, deduplicated firing, eligibility/miss/overlap behavior, and restart receipt through ordinary Run admission
#29 explicitly defers schedules; queue names and scalar priority do not supply the temporal contract
Orchestration — durable local reservation and hardware-wait recovery
One managed service attempt with a durable reservation/fence, explicit park/restart ownership, and release only after proved containment
#16 and #22 defer durable reservations; current live hardware waits and process-local leases cannot prove this
Workflow — exact execution-road decisions and safe road changes
One native placement selecting between two declared roads, with persisted decision/effect linkage and pre-submit versus ambiguous-post-submit tests
#55, #28, and #19 each prove one road; #29’s first Scroll does not implement the cross-road policy
Runtime policy — bounded future-demand signal
One versioned non-authorizing prediction contract and controlled comparisons for correct, stale, absent, and wrong predictions
#16/#17 cover measured resources and local ranking, but do not yet define this cross-owner signal
Oculus — explain contention across two Runs
One bounded correlated view of competing Runs, resource observations, rejected choices, and transition outcomes
#36 deliberately proves one Run and defers multi-Run queries/resource snapshots
Consumer-specific Cut composition, Shadow resource behavior, and Toll integration should first use the relevant child issues’ receipts. Create additional work only for a demonstrated gap.
Legion remains an explicit deferred boundary under #52 and ADR 42 until local admission, durable delegation, identity, and fencing evidence justify a concrete first node slice.
Non-goals
Implement every execution road or close every linked issue through this tracker.
Change the completion order of first local conversation, multimodal integration, and later resource/ranking policy.
Create another scheduler, lifecycle controller, effect ledger, architecture source, or delivery ledger.
Treat declared coexistence, synthetic GPU arithmetic, broker concurrency, or prediction as resource admission.
Introduce unsafe preemption, silent remote fallback, live Graph rewriting, or automatic replay after an ambiguous effect.
Expose the current loopback application through a tunnel or generic proxy.
Move real money, enable production x402, or infer spending authority from a challenge.
Treat a technical return, simulation result, score, or trace as authority to merge, publish, deploy, or promote.
Completion condition
Close this tracking review when:
The versioned synthetic scenario and matrix have been reviewed against their canonical owners.
Existing executable evidence and its limits are linked at a recorded source revision.
Every accepted gap has one bounded issue or an explicit, reasoned deferral.
Dependencies distinguish completion blockers, coordination links, and actual sub-issues; existing delivery slices have not acquired reciprocal advanced blockers.
Contradictions discovered in owning documentation are repaired or linked to explicit unresolved work.
The final review records which scenarios are executable, which remain designed, and what evidence is still required.
Closure means this review and decomposition are complete. It does not mean the advanced integrated runtime has shipped. That claim requires the relevant implementation issues, composed acceptance receipts, and an updated State of Work.
Purpose and boundary
Track the advanced integration of concurrent Intents, constrained local resources, durable execution, remote labor, privacy, payments, and recovery.
This issue owns a finite architecture-and-evidence review and its decomposition into bounded work. It links existing delivery issues without expanding their acceptance criteria or making advanced work a prerequisite for the first local conversation or multimodal receipt.
“Advanced execution” names a finite architecture-and-evidence review. It introduces no runtime component, umbrella implementation, or additional authority.
The sources of truth remain separate:
Accepted changes belong in their existing canonical owners. A discussion, diagram, closed issue, or passing simulation does not independently establish architecture or delivered behavior.
Current evidence boundary
The verified envelope remains local, loopback-oriented, single-user, and one control process.
State records available subsets for deployment-plan compilation, the narrow Animator/Dispatcher path, and Topology-A Run execution. Safe runtime transitions, persistence, consent recovery, and delegated execution have explicit partial boundaries. Host/model integration still needs named operator receipts.
Resource-aware scheduling, general service capabilities, execution-road planning, verified Privacy Cuts and egress, native Oculus, Shadow, A2A, Tether, Toll, and Legion remain designed within their respective boundaries. Portal grant issuance remains quarantined. The delegated reference adapter performs no external effect. Current Graph execution is serial; hardware waits are live and do not generally survive process loss.
Use State’s exact labels and limits when recording a review. Missing evidence is a review gap; an unknown physical observation is runtime uncertainty. Neither is a replacement delivery classification.
Advanced scenario
Use one versioned synthetic scenario, with independently executable stages as their dependencies become available.
The initial host profile is Linux with systemd, cgroup v2, and rootless Podman/Quadlet. Illustrative inputs are one 24 GiB GPU, an already-WARM
coderprofile with an 18 GiB observation and live leases, a conflictingvisionprofile with a 20 GiB observation, and anembedderprofile with a 5 GiB observation and declared coexistence withcoder.Those numbers are fixture inputs, not hardware qualification or proof of fit. Each measured profile must include workload conditions, observation age, active and transition-peak demand, required headroom, relevant host resources, and device identity. A declared capability must also have an admitted executable interface; family metadata alone is insufficient.
Exercise the following sequence:
AgentJob, and one sovereign A2A task according to their different labor contracts. A delegated runtime’s child provider calls are separate disclosure boundaries. A peer chooses its own private decomposition.Related execution roads and enabling layers
The master scenario composes several declared execution roads, but it must not flatten them into interchangeable provider buckets. For each station, Spellweaver seals one admitted road decision before submission:
Operationally, Portal, delegated coding and A2A expand the set of roads that an eligible station may use. They retain different identities, authority, custody, cancellation, reconciliation and terminal-adoption contracts. Local failure does not silently admit a remote road, and changing road is not an implementation detail.
AgentJobroad for adapters around Codex-, Claude- or OpenCode-shaped runtimes, with a scoped workspace and quarantined returnRunContext, automatic merge/promotion or authority for the runtime's child provider callsA contained CLI runtime and any provider it invokes are separate consumers. Each child call therefore needs its own declared provider binding, disclosure decision and applicable Cut; admitting the outer
AgentJobdoes not transitively admit arbitrary network use.The VPN relationship is similarly narrow: it can make an A2A peer reachable and thereby make that declared road operationally available, but it cannot make the peer eligible, trusted or authorized. The road decision, Ward checks, Privacy Cut, egress decision and road-specific effect record remain necessary.
A2A over optional Tether
For a station whose pinned policy admits a private A2A road, review this exact chain:
If Tether is required but absent before submission, that road is ineligible and the declared policy may refuse or select another already admitted road. If the tunnel drops after possible submission, no public fallback is allowed: retain the same A2A task/effect identity, expose the uncertainty and reconcile. Tunnel restoration does not mint peer authority or permit a changed payload to reuse the old identity. #19 owns task semantics and #20 owns private reachability; neither becomes a generic provider adapter.
Worker progress, configurable fallback and Graph growth
The composed scenario must prove bounded progress, not claim that arbitrary future workflows are mathematically deadlock-free:
Graph extension remains additive. #29 admits exact owner-qualified Spell contracts, immutable Scrolls and Resolution Locks; #61 adds bounded branch identities, joins and cancellation. A router may fold only alternatives declared by the pinned Scroll into one typed execution projection using exact predicates and capability evidence. It cannot invent an edge, import code from YAML/TOML, or rewrite a live Run. YAML is at most a typed authoring projection compiled to canonical JSON; TOML selects already registered exact identities and bounded policy.
Altar review route
The operator review should remain distributed across the existing Altar instruments rather than creating an Orchestration Master screen:
AgentJob, A2A task or external effect was retained; and where are the evidence gaps?The review journey is Bridge → Orb, with Orb → Loom for declared score and Orb → Nexus for a correlated physical transition; Atlas retains explicit references and decisions. #9 owns delivery and cross-screen navigation. Missing projections remain visible gaps and do not authorize a retry or infer an event.
Authority that the scenario must preserve
A waiting hardware Run holds no capability lease. Successful convergence requires fresh dispatch.
Priority does not interrupt a submitted physical transaction. A “spare capacity” label does not establish safe preemption; scarce-resource background work needs a proved yield/containment boundary or an explicitly admitted quiet window.
Generated conflict relationships, Coven grouping, and measured capacity remain different facts. Direct systemd or Podman control cannot become a second application lifecycle path.
Concern and evidence matrix
Each row needs a review result, an exact evidence route, explicit limits, and a bounded disposition for remaining work. Existing issues retain their own scope.
Canonical ADRs are listed in the Covenant index. Operational routes:
Effect and retry coverage
The review must distinguish these cases:
LOST,INDETERMINATE, and cancellation states must not be flattened into a generic retriable failure.Host transitions, service attempts, AgentJobs, A2A tasks, and Toll settlements have different records and recovery rules. This master does not replace them with a universal state machine.
What counts as covered
For each matrix row, record:
Receipts identify source/configuration/profile revisions, commands, relevant runtime versions, expected and observed outcomes, and cleanup. Deterministic control tests do not establish deterministic model answers or predictable resource availability.
Published evidence uses synthetic material and allowlisted structural fields. Prompts, credentials, private errors, raw source identifiers, and pseudonym maps do not enter the tracker or ordinary telemetry.
Bounded follow-up gaps
Confirm the smallest useful slice before opening each follow-up. Prefer an existing issue when its accepted scope already covers the work.
Consumer-specific Cut composition, Shadow resource behavior, and Toll integration should first use the relevant child issues’ receipts. Create additional work only for a demonstrated gap.
Legion remains an explicit deferred boundary under #52 and ADR 42 until local admission, durable delegation, identity, and fencing evidence justify a concrete first node slice.
Non-goals
Completion condition
Close this tracking review when:
Closure means this review and decomposition are complete. It does not mean the advanced integrated runtime has shipped. That claim requires the relevant implementation issues, composed acceptance receipts, and an updated State of Work.