Skip to content

feat(harness): run one bounded correlated Prime text turn #7

Description

@rynfar

Outcome

Consume one fresh native PrimeSessionLease, submit exactly one bounded correlated text prompt, project a privacy-safe internal text/reasoning stream, support deterministic interruption, settle exactly once, and authoritatively close the owned native worker.

This is the host-private prompt/event normalization slice after #5 / PR #6. It does not register a public Prime Harness yet.

Coordination and dependency:

Implementation must wait for a reviewed Prime artifact that exposes the post-attach negotiation proof from Prime zeronsh#17 and for Pylon's correlated consumer gate to be reviewed against the same contract.

Owned area

  • focused extensions under crates/harness/src/prime/session/**;
  • focused fake SDK/daemon coverage under crates/harness/tests/**;
  • docs/prime-agent-integration.md contract and validation receipts.

Do not claim registry, proto, engine, document, RPC, settings, model, or UI files here.

Capability gate

Require:

  • frozen public-root SDK features bounded_daemon_ingress_v1 and proposed negotiated_daemon_session_capabilities_v1;
  • feat(harness): establish bounded native Prime SDK session host #5's existing daemon/session gates;
  • post-attach connection.supportsNegotiatedCapability("correlated_prompt_lifecycle_v1") === true for the current attachment generation;
  • public correlated submit/lifecycle/cancel methods.

A server offer, method presence, package/protocol/schema version, attach success alone, constructor arity, or ignored arguments are not proof. Stock Prime and older fork artifacts must return a typed local unsupported result and perform normal cleanup before prompt submission. There is no ordinary-prompt or ACP fallback in this slice.

Do not require or imply model_catalog, rlm_quiescence_barrier, queue mutation/modes, owned_prompt_cancellation, extension UI, MCP, or any other optional offer.

Prompt and attribution contract

  • Subscribe before submission.
  • Use only submitCorrelatedPrompt(text, { correlationId, queueIfBusy: false, signal }).
  • Generate one host-private random correlation token. Never log, serialize, persist, hash into, or export it.
  • Allow exactly one active and total prompt per fresh no-tools lease.
  • On uncertain submission, query getPromptLifecycles() once within a bound. Continue only from the exact retained record; never resubmit.
  • Require kind === "model_prompt", monotonic revisions, legal phase transitions, and non-regressing delivery evidence.
  • Accept turn events only when outer attribution is scope:"prompt" with the current correlation and the inner prompt correlation agrees. Session-scoped background metadata cannot settle the turn. Wrong/missing/stale attribution is a protocol failure.

Normalized projection

Only bounded normalized values may cross Node -> Rust:

  • assistant text deltas;
  • reasoning deltas, if implemented consistently;
  • finite terminal input/output token counts;
  • one fixed terminal outcome/error code.

Never forward raw snapshots/events/errors, native session/correlation/message/tool/child IDs, session files/paths, socket/package paths, credentials, provider diagnostics, costs, queues, tools, or extension UI data.

Native tool events or tool calls are an unsupported-state failure because the session is created with noTools: true. Unknown future event types may be ignored locally but never settle the turn.

Settlement and interruption

  • Correlated lifecycle is the ownership barrier. agent_end, message_end, turn_end, activity/idle, host EOF, or silence alone cannot complete the prompt.
  • Buffer/validate agent_end final message and usage, but emit exactly one terminal internal event only from the exact correlated terminal plus required final-response checks.
  • cancelled or completed with stopReason:"aborted" -> Interrupted.
  • lifecycle failed, native error, stopReason:"error", tool-use final state, malformed usage, or missing required final response -> fixed Errored outcome.
  • Other valid completed state -> Completed.
  • Cleanup uncertainty overrides Completed/Interrupted with cleanup-uncertain.
  • Pre-delivery interrupt uses cancelPromptLifecycle.
  • Delivered too_late may call session-scoped connection.abort() only because this slice owns one prompt, has tools disabled, and permits no other work. It must still await the exact terminal lifecycle or destructively close the lease.
  • expired/unknown cancellation evidence is Errored unless terminal ownership had already linearized.
  • Close, caller cancellation, Drop, host crash, and overflow retain all feat(harness): establish bounded native Prime SDK session host #5 cleanup ownership rules.

Bounds

Retain #5's 512 MiB V8 heap, 64 MiB daemon ingress, 16 KiB control frames, 8 pending requests, 32 normalized events, 256-byte native IDs, finite stage deadlines, and authoritative cleanup horizon.

Add and freeze before implementation:

  • non-empty prompt: at most 8 KiB UTF-8;
  • cumulative projected output: at most 16 MiB UTF-8;
  • one prompt per lease;
  • explicit admission, turn, interrupt, and terminal-grace deadlines;
  • UTF-8-safe output splitting that keeps every private frame within 16 KiB;
  • bounded lifecycle records and queue/coalescing behavior.

Overflow, backlog saturation, malformed data, partial/final mismatch, or host OOM is terminal failure plus authoritative cleanup. Never silently truncate and report success.

Deterministic acceptance tests

  1. Negotiation truth table: token/accessor/offer/attach proof combinations, stock behavior, stale generation, and unrelated optional offers.
  2. Event-before-response, response-before-event, terminal-before-response, duplicates, and uncertain submit reconciliation with an exact one-submit assertion.
  3. Wrong/session/unknown/stale attribution; conflicting duplicate revision; illegal transition/kind/delivery regression; post-terminal events.
  4. Text/reasoning UTF-8 boundaries, final-message fallback/consistency, unknown events, no-tools violation, per-frame/cumulative/backlog overflow, and FIFO ordering.
  5. Early agent_end during compaction/continuation cannot complete; full completed/cancelled/failed/aborted/error/toolUse/missing-final/usage matrix.
  6. Interrupt before ownership, owned/queued, delivered too_late, completion race, expired/unknown, abort failure/timeout, repeated interrupt, and Drop/close during every phase.
  7. Exactly one terminal only after authoritative cleanup proof; cleanup-uncertain never becomes success/interrupted.
  8. Privacy canaries for every forbidden identity/path/raw payload/error/credential in events, errors, logs, and Debug output.
  9. Preserve feat(harness): establish bounded native Prime SDK session host #5 process/reaper/descriptor/poison/OOM cleanup coverage.
  10. Env-gated no-model negotiation smoke against the exact new artifact; live credentialed prompts remain opt-in/ignored.

Non-goals

HarnessId::PrimeAgent, public AgentEvent, durable resume tokens, saved-session attach/reconnect, model/thinking selection, steering/follow-up, images, tools/subagents, approvals, resources/queues, compaction UI, refinement/goals/automation, background PrimeAgentTextGeneration, and ACP fallback.

Later merge order

  1. Prime Bound Rust development cache growth zeronsh/zeron#17 proof API and reproducible artifact.
  2. Pylon consumes the same post-attach proof and passes compatibility review.
  3. This issue in an isolated Comet worktree.
  4. Opaque host-local resume-token mapping with a cumulative saved-snapshot budget.
  5. Hidden normalized Prime Harness, then registry/settings/model/UI exposure for a text-only preview.

Do not emit AgentEvent::SessionStarted.session_id in this issue. That field is durable Comet resume state; a native Prime ID is forbidden and an unmapped random value is not a resume contract.

Activity

  1. rynfar commented on Aug 30, 2026

    @rynfar
    OwnerAuthor

    The blocking Pylon proof-consumer PR is now open: pylon-code/pylon#191

    It targets pylon at exact reviewed head f34744ac774b0570c0608ccc8def509d3ae88ece; hosted exact-SHA CI is running. Comet #7 remains intentionally blocked until that PR merges.

  2. rynfar commented on Aug 30, 2026

    @rynfar
    OwnerAuthor

    The blocking Pylon proof consumer merged: pylon-code/pylon#191

    Merge commit: 879d3692bfbabefe6aae26417100f035bf759ef1. All hosted checks passed on exact head f34744ac774b0570c0608ccc8def509d3ae88ece. This issue is now unblocked for implementation.

  3. rynfar commented on Aug 30, 2026

    @rynfar
    OwnerAuthor

    Claiming implementation in rynfar/comet on branch feat/prime-correlated-text-turn, isolated worktree /Users/rynfar/.prime/worktrees/comet-prime-correlated-text-turn at main@9ef2295877d33fe241479471e908105fccbeb434.

    Owned files:

    • focused additions/changes under crates/harness/src/prime/session/**;
    • focused fake-host coverage under crates/harness/tests/**;
    • docs/prime-agent-integration.md contract/validation updates.

    Shared contract:

    • require frozen public SDK features bounded_daemon_ingress_v1 and negotiated_daemon_session_capabilities_v1;
    • require completed attach plus current-generation supportsNegotiatedCapability("correlated_prompt_lifecycle_v1") === true;
    • subscribe before exactly one submitCorrelatedPrompt(text, { correlationId, queueIfBusy: false, signal }) on a fresh noTools:true lease;
    • never infer support, downgrade, use ordinary prompt submission, use ACP, or resubmit after uncertain admission;
    • keep correlation/session/native identifiers, paths, diagnostics, credentials, and raw payloads host-private;
    • settle only from the exact correlated lifecycle, then authoritatively clean up the owned worker.

    Dependencies are satisfied by Prime zeronsh#18 merge 91e13b6798343995291ccca6f523fba81ff96cd6 (package SHA-256 c46497e2870618bb2caa9d59d161fc5abfad27472eec7deff39cfb1380ebe70c) and Pylon zeronsh#191 merge 879d3692bfbabefe6aae26417100f035bf759ef1.

    Compatibility: stock/older/malformed registries and absent/false/stale post-attach proof return a typed local unsupported outcome and run normal cleanup before any prompt submission. No ordinary or ACP fallback.

    Validation will cover the issue's negotiation, attribution, lifecycle, ordering, UTF-8/bounds, cancellation, cleanup, privacy, process/reaper, exact-artifact, and stock-artifact matrices. I will freeze the final head for independent security, API/design, adversarial, and test review before push/PR. Merge order remains Prime zeronsh#18 → Pylon zeronsh#191 → this issue → opaque resume → hidden Harness and UI slices.

  4. rynfar commented on Aug 30, 2026

    @rynfar
    OwnerAuthor

    Independent review of frozen Comet candidate dd28320b2f2e3ff31b53f051cc372d83cd9d2ae8 found a new dependency blocker: approved Prime PR zeronsh#18 durably copies correlated lifecycle snapshots/actions into its worker recovery journal, including the host-random correlationId. That conflicts with this issue's explicit “never ... persist [or] hash” contract and cannot be repaired below Prime's public boundary.

    Opened pylon-code/prime-agent#20 for a capability-proved fresh nonpersistent worker mode. Comet #7 will require the new frozen SDK feature, daemon offer, explicit create request, exact create receipt, and the existing current-generation correlated proof. Older/stock artifacts will still create a normal lease and return typed Unsupported for this turn.

    Local Comet repairs for the other review findings are in progress, but this issue remains unmergeable until Prime zeronsh#20 produces an independently approved exact artifact.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions