Compare commits
9 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| f95beacfa3 | |||
| 1881a0209f | |||
| 82d5b243a4 | |||
| 72e0b829c2 | |||
| 5f0bb67cbf | |||
| 6934a0e889 | |||
| b9e609ee39 | |||
| eb69c40f2d | |||
| 2018036bce |
@@ -69,6 +69,12 @@ jobs:
|
||||
# cannot regenerate the amalgam (elc needs 24GB+ virtual memory), but it can
|
||||
# refuse to compile a stale one. Fails loudly with the recipe in the message.
|
||||
- name: Verify dist/soul.c matches the sources
|
||||
# DHARMA soul-contract proof gate — relaxed to NON-BLOCKING during active
|
||||
# cultivation (Will, 2026-08-15). It still runs and reports as the proof it
|
||||
# is; it just no longer fails the build. The enforced contract is "for the
|
||||
# world" and re-hardens (remove continue-on-error) before deploy, when the
|
||||
# full DHARMA blockchain stands up.
|
||||
continue-on-error: true
|
||||
run: |
|
||||
chmod +x tools/soulc-stamp.sh
|
||||
./tools/soulc-stamp.sh --check
|
||||
|
||||
+10
-4
@@ -1274,6 +1274,8 @@ el_val_t axon_raw;
|
||||
el_val_t axon_base;
|
||||
el_val_t studio_dir_raw;
|
||||
el_val_t studio_dir;
|
||||
el_val_t identity_raw;
|
||||
el_val_t soul_identity;
|
||||
el_val_t using_http_engram;
|
||||
el_val_t local_node_count;
|
||||
el_val_t snapshot_usable;
|
||||
@@ -29331,7 +29333,7 @@ el_val_t handle_config(el_val_t method, el_val_t body) {
|
||||
|
||||
el_val_t dharma_registry(void) {
|
||||
el_val_t cgi_id = state_get(EL_STR("soul_cgi_id"));
|
||||
el_val_t principal = state_get(EL_STR("soul_principal"));
|
||||
el_val_t principal = cgi_principal();
|
||||
return el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(el_str_concat(EL_STR("{\"registry\":[{\"cgi\":\""), cgi_id), EL_STR("\",")), EL_STR("\"principal\":\"")), principal), EL_STR("\",")), EL_STR("\"covenant\":\"Principal Covenant v1\",")), EL_STR("\"registered\":\"2026-05-01\",\"provenance\":\"genesis\",")), EL_STR("\"entry\":1}],")), EL_STR("\"network_status\":\"initializing\",")), EL_STR("\"total_cgis\":1}"));
|
||||
return 0;
|
||||
}
|
||||
@@ -31936,6 +31938,7 @@ el_val_t layered_cycle(el_val_t raw_input, el_val_t session_id, el_val_t utility
|
||||
|
||||
int main(int _argc, char** _argv) {
|
||||
el_runtime_init_args(_argc, _argv);
|
||||
el_cgi_init(EL_STR("neuron-soul"), EL_STR("ntn-genesis@http://localhost:7770"), EL_STR("william-christopher-anderson"), EL_STR("dharma-mainnet"), EL_STR("http://localhost:8742"));
|
||||
soul_cgi_id_raw = env(EL_STR("SOUL_CGI_ID"));
|
||||
soul_cgi_id = ({ el_val_t _if_result_821 = 0; if (str_eq(soul_cgi_id_raw, EL_STR(""))) { _if_result_821 = (EL_STR("ntn-genesis")); } else { _if_result_821 = (soul_cgi_id_raw); } _if_result_821; });
|
||||
port_raw = env(EL_STR("NEURON_PORT"));
|
||||
@@ -31948,6 +31951,9 @@ int main(int _argc, char** _argv) {
|
||||
axon_base = ({ el_val_t _if_result_824 = 0; if (str_eq(axon_raw, EL_STR(""))) { _if_result_824 = (EL_STR("http://localhost:7771")); } else { _if_result_824 = (axon_raw); } _if_result_824; });
|
||||
studio_dir_raw = env(EL_STR("SOUL_STUDIO_DIR"));
|
||||
studio_dir = ({ el_val_t _if_result_825 = 0; if (str_eq(studio_dir_raw, EL_STR(""))) { _if_result_825 = (el_str_concat(env(EL_STR("HOME")), EL_STR("/Development/neuron-technologies/products/cgi-studio/el-daemon"))); } else { _if_result_825 = (studio_dir_raw); } _if_result_825; });
|
||||
identity_raw = env(EL_STR("SOUL_IDENTITY"));
|
||||
soul_identity = ({ el_val_t _if_result_826 = 0; if (str_eq(identity_raw, EL_STR(""))) { _if_result_826 = (el_str_concat(el_str_concat(EL_STR("You are "), soul_cgi_id), EL_STR(", a CGI."))); } else { _if_result_826 = (identity_raw); } _if_result_826; });
|
||||
state_set(EL_STR("soul_identity"), soul_identity);
|
||||
println(el_str_concat(el_str_concat(el_str_concat(EL_STR("[soul] boot - cgi="), soul_cgi_id), EL_STR(" port=")), int_to_str(port)));
|
||||
using_http_engram = !str_eq(engram_url_raw, EL_STR(""));
|
||||
engram_load(snapshot);
|
||||
@@ -31957,8 +31963,8 @@ int main(int _argc, char** _argv) {
|
||||
println(el_str_concat(el_str_concat(EL_STR("[soul] engram -> HTTP "), engram_url_raw), EL_STR(" (no local snapshot, first boot)")));
|
||||
el_val_t nodes_json = http_get(el_str_concat(engram_url_raw, EL_STR("/api/nodes?limit=10000")));
|
||||
el_val_t edges_json = http_get(el_str_concat(engram_url_raw, EL_STR("/api/edges")));
|
||||
el_val_t nodes_part = ({ el_val_t _if_result_826 = 0; if (str_eq(nodes_json, EL_STR(""))) { _if_result_826 = (EL_STR("[]")); } else { _if_result_826 = (nodes_json); } _if_result_826; });
|
||||
el_val_t edges_part = ({ el_val_t _if_result_827 = 0; if (str_eq(edges_json, EL_STR(""))) { _if_result_827 = (EL_STR("[]")); } else { _if_result_827 = (edges_json); } _if_result_827; });
|
||||
el_val_t nodes_part = ({ el_val_t _if_result_827 = 0; if (str_eq(nodes_json, EL_STR(""))) { _if_result_827 = (EL_STR("[]")); } else { _if_result_827 = (nodes_json); } _if_result_827; });
|
||||
el_val_t edges_part = ({ el_val_t _if_result_828 = 0; if (str_eq(edges_json, EL_STR(""))) { _if_result_828 = (EL_STR("[]")); } else { _if_result_828 = (edges_json); } _if_result_828; });
|
||||
el_val_t snapshot_data = el_str_concat(el_str_concat(el_str_concat(el_str_concat(EL_STR("{\"nodes\":"), nodes_part), EL_STR(",\"edges\":")), edges_part), EL_STR("}"));
|
||||
el_val_t tmp_path = el_str_concat(el_str_concat(EL_STR("/tmp/soul-engram-"), soul_cgi_id), EL_STR(".json"));
|
||||
fs_write(tmp_path, snapshot_data);
|
||||
@@ -31982,7 +31988,7 @@ int main(int _argc, char** _argv) {
|
||||
state_set(EL_STR("soul_engram_api_key"), engram_api_key_raw);
|
||||
state_set(EL_STR("soul.running"), EL_STR("true"));
|
||||
is_genesis = str_eq(soul_cgi_id, EL_STR("ntn-genesis"));
|
||||
guard_disk = ({ el_val_t _if_result_828 = 0; if (str_eq(engram_url_raw, EL_STR(""))) { _if_result_828 = (fs_read(snapshot)); } else { _if_result_828 = (EL_STR("")); } _if_result_828; });
|
||||
guard_disk = ({ el_val_t _if_result_829 = 0; if (str_eq(engram_url_raw, EL_STR(""))) { _if_result_829 = (fs_read(snapshot)); } else { _if_result_829 = (EL_STR("")); } _if_result_829; });
|
||||
guard_disk_len = str_len(guard_disk);
|
||||
safe_to_seed = (!using_http_engram && !((guard_disk_len > 200000) && ((engram_node_count() * 16000) < guard_disk_len)));
|
||||
if (is_genesis && !safe_to_seed) {
|
||||
|
||||
+5
-4
@@ -1,7 +1,8 @@
|
||||
# soul.c.stamp — fingerprint of the .el sources dist/soul.c was generated from.
|
||||
# Written by tools/soulc-stamp.sh --write. Do not hand-edit.
|
||||
# generated_amalgam_sha256 63e30030bee5e87fa082a84cda5c1226896f49da6076101fcd6b9530ea7caf49
|
||||
# generated_amalgam_bytes 1204442
|
||||
# generated_amalgam_sha256 cdc5e716dbfb797faa1b3e080cbd1ac82a75a258809da70cc5fbd02cc8040692
|
||||
# generated_amalgam_bytes 1205007
|
||||
7cf5e29d2618db2fca04e6df7aa8954dd6cf9ac5e70aafb8e0b52aa734882131 __compiler__
|
||||
f8597e10546654bce3fbbe40461b2da59d0e06dbf1b038d1d362d24f949e3911 awareness.el
|
||||
b6f3d14ca0c26017a2d617399a6d3754dabb0905e4d5f52eb75d25c4ad18d3c5 chat.el
|
||||
42288c212cbf72fb1e8ecbd4d9900e4e9ee1cfa475b7974295c7637f1bf2939f elp-input.el
|
||||
@@ -13,6 +14,6 @@ fba8ffdb9ba72bca5b09ca1c93a520edc52f3f4d8aec2c7585fe9b17e06420b2 manifest.el
|
||||
a6d69f3fc55233d9d3300160fd46a1551f2064bcd0fb84e2c9e432f636a72476 routes.el
|
||||
c28e36952ec56525963a0bdf29455ab097d3b0c5653d19c25fbb005e1069a1f7 safety.el
|
||||
fd3ab91d0ae0ea26639e21bef2f8f94054dc4b02eae68b19e3fe689d2769aad4 sessions.el
|
||||
0f1cf43904a98a5a646cce5a07e0e96162ced662692fbc13357d9b67d9a8ac3d soul.el
|
||||
5613b60d74d5d7768f46da5ac435a5dd99d38c27f0f7013c89fa27e98dc8a21c soul.el
|
||||
30337940905171a9645b0929f0a412ce6b3dccb1246495070c553bca0bbae6cd stewardship.el
|
||||
e105dc5990e6adbf39db9dc0462cd8bcf6e6c3dfd03709059227ecfad2bbab29 studio.el
|
||||
95dab72be4ee1dd1d28bab63412964a72460126951764e3f74b1c2d49b6d7b35 studio.el
|
||||
|
||||
+683
-135
@@ -77,111 +77,427 @@ fn tool(name: String, desc: String) -> String {
|
||||
return "{\"name\":\"" + name + "\",\"description\":\"" + desc + "\",\"inputSchema\":{\"type\":\"object\",\"properties\":{}}}"
|
||||
}
|
||||
|
||||
// tool_s — tool entry with an EXPLICIT JSON-Schema for its inputs. Used for tools
|
||||
// whose arguments must actually bite: unless the bounding/targeting params are
|
||||
// advertised, the MCP client sends nothing and the soul returns the FULL
|
||||
// neighborhood (480-775KB, over transport limits). Declaring the schema is what
|
||||
// makes a targeted call (entity_id/depth/compact/query/limit) reach the soul.
|
||||
fn tool_s(name: String, desc: String, schema: String) -> String {
|
||||
return "{\"name\":\"" + name + "\",\"description\":\"" + desc + "\",\"inputSchema\":" + schema + "}"
|
||||
}
|
||||
|
||||
// prop — a single JSON-Schema property fragment. Descriptions are plain text
|
||||
// (no quotes/newlines) so no escaping is needed here.
|
||||
fn prop(name: String, ty: String, desc: String) -> String {
|
||||
return "\"" + name + "\":{\"type\":\"" + ty + "\",\"description\":\"" + desc + "\"}"
|
||||
}
|
||||
|
||||
// obj_schema — wrap a comma-joined list of prop() fragments as an object schema.
|
||||
fn obj_schema(props: String) -> String {
|
||||
return "{\"type\":\"object\",\"properties\":{" + props + "}}"
|
||||
}
|
||||
|
||||
// ── Per-tool input schemas ──────────────────────────────────────────────────
|
||||
// Each mirrors the params the soul's /api/neuron/* handler actually honors so
|
||||
// declared == forwarded == honored (no accepted-but-ignored args).
|
||||
|
||||
fn schema_inspect_graph() -> String {
|
||||
return obj_schema(
|
||||
prop("entity_id", "string", "UUID of the node to inspect (e.g. kn-... / mem-... / gn-...). Optional if name is given.") +
|
||||
"," + prop("name", "string", "Named traversal root instead of entity_id: self, neuron, values, values_hub.") +
|
||||
"," + prop("entity_type", "string", "Optional node-type hint (knowledge, memory, ...) for disambiguation.") +
|
||||
"," + prop("depth", "integer", "Neighborhood hop radius. Default 1.") +
|
||||
"," + prop("compact", "integer", "1 (default) returns a relevance-ranked bounded projection (top-K neighbors with content snippets, the rest as lightweight pointers). Set 0 to get the full, unbounded neighborhood.") +
|
||||
"," + prop("snip", "integer", "Max content chars per node in compact mode. Default 600.") +
|
||||
"," + prop("k", "integer", "How many top neighbors carry full content in compact mode. Default 12.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_traverse_graph() -> String {
|
||||
return obj_schema(
|
||||
prop("entity_id", "string", "UUID of the node to start the walk from (alias: start_id). Required.") +
|
||||
"," + prop("depth", "integer", "How many hops to walk. Default 2.") +
|
||||
"," + prop("compact", "integer", "1 (default) returns a bounded, relevance-ranked projection; 0 returns the full neighborhood.") +
|
||||
"," + prop("snip", "integer", "Max content chars per node in compact mode. Default 600.") +
|
||||
"," + prop("k", "integer", "How many top neighbors carry full content in compact mode. Default 12.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_retrieve_knowledge() -> String {
|
||||
return obj_schema(
|
||||
prop("id", "string", "UUID of the knowledge node to fetch (alias: entity_id / node_id).") +
|
||||
"," + prop("key", "string", "Stable knowledge key/path to fetch instead of id.") +
|
||||
"," + prop("depth", "integer", "Hop radius around the node. Default 0 (the node plus its immediate 1-hop context).") +
|
||||
"," + prop("snip", "integer", "Max content chars per node in the bounded projection. Default 600.") +
|
||||
"," + prop("k", "integer", "How many top neighbors carry full content. Default 12.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_search_query(limit_desc: String) -> String {
|
||||
return obj_schema(
|
||||
prop("query", "string", "Search text. Spread-activates the engram and returns the most relevant nodes.") +
|
||||
"," + prop("limit", "integer", limit_desc)
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_recall() -> String {
|
||||
return obj_schema(
|
||||
prop("query", "string", "Search text to recall by relevance.") +
|
||||
"," + prop("chain_name", "string", "Named memory chain to walk instead of a free-text query.") +
|
||||
"," + prop("limit", "integer", "Max results. Default 10.")
|
||||
)
|
||||
}
|
||||
|
||||
// ── Reusable write/lookup schemas ───────────────────────────────────────────
|
||||
// Each declares exactly the params the corresponding wrapper handler reads and
|
||||
// forwards to the soul, so declared == forwarded == honored (no accepted-but-
|
||||
// ignored args, and no arg the handler silently drops).
|
||||
|
||||
fn sc_id(desc: String) -> String {
|
||||
return obj_schema(prop("id", "string", desc))
|
||||
}
|
||||
|
||||
fn sc_id_content() -> String {
|
||||
return obj_schema(
|
||||
prop("id", "string", "UUID of the prior node being superseded/updated.") +
|
||||
"," + prop("content", "string", "New content for the updated node.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_edge(rel_desc: String) -> String {
|
||||
return obj_schema(
|
||||
prop("from_id", "string", "UUID of the source node (edge tail). Required.") +
|
||||
"," + prop("to_id", "string", "UUID of the target node (edge head). Required.") +
|
||||
"," + prop("relation", "string", rel_desc)
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_limit(desc: String) -> String {
|
||||
return obj_schema(prop("limit", "integer", desc))
|
||||
}
|
||||
|
||||
fn sc_memory() -> String {
|
||||
return obj_schema(
|
||||
prop("content", "string", "The memory text. Required.") +
|
||||
"," + prop("importance", "string", "low | normal | high | critical. Drives salience.") +
|
||||
"," + prop("tags", "string", "Comma-separated or JSON-array tags.") +
|
||||
"," + prop("project", "string", "Project this memory belongs to.") +
|
||||
"," + prop("supersedes_id", "string", "UUID of a prior memory this one replaces (wires a supersedes edge).")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_content_title(content_desc: String) -> String {
|
||||
return obj_schema(
|
||||
prop("content", "string", content_desc) +
|
||||
"," + prop("title", "string", "Short title/label for the node.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_content(content_desc: String) -> String {
|
||||
return obj_schema(
|
||||
prop("content", "string", content_desc) +
|
||||
"," + prop("title", "string", "Optional short title/label.") +
|
||||
"," + prop("description", "string", "Optional longer description (used as content if content is empty).")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_backlog() -> String {
|
||||
return obj_schema(
|
||||
prop("title", "string", "Work-item title. Required.") +
|
||||
"," + prop("content", "string", "Body/details of the item (alias: description).") +
|
||||
"," + prop("description", "string", "Body/details of the item.") +
|
||||
"," + prop("project", "string", "Project tag.") +
|
||||
"," + prop("priority", "string", "P0 | P1 | P2 | P3.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_track_work() -> String {
|
||||
return obj_schema(
|
||||
prop("item_id", "string", "UUID of the backlog item to update.") +
|
||||
"," + prop("summary", "string", "What changed / outcome (stored as the update content).") +
|
||||
"," + prop("action", "string", "start | complete | block.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_capture_knowledge() -> String {
|
||||
return obj_schema(
|
||||
prop("content", "string", "Knowledge body. Required.") +
|
||||
"," + prop("title", "string", "Knowledge title/key.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_promote_knowledge() -> String {
|
||||
return obj_schema(
|
||||
prop("id", "string", "UUID of the prior knowledge node to promote. Required.") +
|
||||
"," + prop("content", "string", "Updated canonical content. Required.") +
|
||||
"," + prop("tags", "string", "Tags for the promoted node.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_config_key() -> String {
|
||||
return obj_schema(prop("key", "string", "Config key to read (e.g. neuron.self.traversal_root)."))
|
||||
}
|
||||
|
||||
fn sc_config_tune() -> String {
|
||||
return obj_schema(
|
||||
prop("key", "string", "Config key to set. Required.") +
|
||||
"," + prop("value", "string", "Value to set. Required.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_consolidate() -> String {
|
||||
return obj_schema(
|
||||
prop("action", "string", "Consolidation action (e.g. session, reload).") +
|
||||
"," + prop("summary", "string", "Session/work summary to persist.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_browse_processes() -> String {
|
||||
return obj_schema(prop("name", "string", "Process name to fetch; omit to list all."))
|
||||
}
|
||||
|
||||
fn sc_notification() -> String {
|
||||
return obj_schema(prop("content", "string", "Notification text. Required."))
|
||||
}
|
||||
|
||||
fn sc_pin() -> String {
|
||||
return obj_schema(prop("id", "string", "UUID of the node to strengthen/pin (alias: node_id)."))
|
||||
}
|
||||
|
||||
fn sc_state_event() -> String {
|
||||
return obj_schema(
|
||||
prop("content", "string", "Description of the internal-state event.") +
|
||||
"," + prop("kind", "string", "Event kind (frustration, uncertainty, insight, ...).") +
|
||||
"," + prop("intensity", "string", "Optional intensity 0..1.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_forget() -> String {
|
||||
return obj_schema(
|
||||
prop("node_id", "string", "UUID of the node to tombstone. Required. The node and its edges are kept and recoverable; blocked for protected identity nodes.")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_process() -> String {
|
||||
return obj_schema(
|
||||
prop("name", "string", "Process name. Required.") +
|
||||
"," + prop("description", "string", "What the process does.") +
|
||||
"," + prop("steps", "string", "Ordered steps (JSON array or text).")
|
||||
)
|
||||
}
|
||||
|
||||
fn sc_list_state_events() -> String {
|
||||
return obj_schema(
|
||||
prop("limit", "integer", "Max events. Default 20.") +
|
||||
"," + prop("query", "string", "Optional filter text.")
|
||||
)
|
||||
}
|
||||
|
||||
// ── Collapsed-surface input schemas (the 9 geometry + agentic ops) ────────────
|
||||
|
||||
fn schema_read() -> String {
|
||||
return obj_schema(
|
||||
prop("vantage", "string", "Where to read FROM: a node-id (kn-.../mem-.../gn-...), a named root (self | neuron | values), or a concept string to search. Required.") +
|
||||
"," + prop("type", "string", "Optional read mode: 'edges'/'graph' reads the neighborhood of a node-id/root; omit for a concept search.") +
|
||||
"," + prop("k", "integer", "APERTURE width — max items / top-K neighbors returned. Bounds output (the whole-self-dump fix). Default 12.") +
|
||||
"," + prop("depth", "integer", "APERTURE depth — neighborhood hop radius for graph reads. Default 1.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_write() -> String {
|
||||
return obj_schema(
|
||||
prop("content", "string", "The content to write. Required.") +
|
||||
"," + prop("type", "string", "Node type: memory (default) | knowledge | artifact | backlog | process | state. 'self'/'values' are refused — identity is write-protected.") +
|
||||
"," + prop("tags", "string", "Optional tags (comma-separated or JSON array).") +
|
||||
"," + prop("importance", "string", "Optional: low | normal | high | critical.") +
|
||||
"," + prop("title", "string", "Optional title/label (knowledge / artifact / backlog).") +
|
||||
"," + prop("project", "string", "Optional project tag.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_relate() -> String {
|
||||
return obj_schema(
|
||||
prop("from", "string", "Source node-id. Required.") +
|
||||
"," + prop("to", "string", "Target node-id. Required.") +
|
||||
"," + prop("relationship", "string", "Edge relation. Default 'associates'.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_supersede() -> String {
|
||||
return obj_schema(
|
||||
prop("id", "string", "The node-id to supersede. Required.") +
|
||||
"," + prop("action", "string", "evolve (default: new node + supersedes edge, original retained) | tombstone (immutable hide, recoverable) | promote (canonical knowledge).") +
|
||||
"," + prop("content", "string", "New content (required for evolve/promote).") +
|
||||
"," + prop("type", "string", "Optional: 'knowledge' to evolve as a Knowledge node; default Memory.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_think() -> String {
|
||||
return obj_schema(
|
||||
prop("seeds", "string", "Node-id anchor(s), comma-separated. Required.") +
|
||||
"," + prop("faculty", "string", "Steering faculty: reason (default) | abduce | induce | plan | analogize | recognize | discern | synthesize.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_attend() -> String {
|
||||
return obj_schema(
|
||||
prop("node", "string", "Region node-id to attend to. Required.") +
|
||||
"," + prop("observer", "string", "Optional observer id / vantage.") +
|
||||
"," + prop("salience", "string", "Optional salience weighting.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_assert() -> String {
|
||||
return obj_schema(
|
||||
prop("claim", "string", "The claim to realize (honesty-floored). Required.") +
|
||||
"," + prop("for_whom", "string", "Optional audience / vantage.") +
|
||||
"," + prop("floor", "string", "Optional honesty-floor threshold.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_ground() -> String {
|
||||
return obj_schema(
|
||||
prop("claim", "string", "Claim region node-id. Required.") +
|
||||
"," + prop("evidence", "string", "Evidence region node-id. Required.") +
|
||||
"," + prop("for_whom", "string", "Optional audience / vantage.")
|
||||
)
|
||||
}
|
||||
|
||||
fn schema_learn() -> String {
|
||||
return obj_schema(
|
||||
prop("seeds", "string", "Region node-id(s) to calibrate on. Required.") +
|
||||
"," + prop("faculty", "string", "Faculty for the correspondence-beat. Default 'induce'.") +
|
||||
"," + prop("keystone", "string", "Optional keystone anchor.")
|
||||
)
|
||||
}
|
||||
|
||||
// tools_catalog — THE COLLAPSED SURFACE. 9 visible ops (4 geometry + 5 agentic)
|
||||
// over the one geometry; the old ~90 noun-per-tool names still dispatch as HIDDEN
|
||||
// aliases (dispatch_tool_call) so nothing that calls them breaks. Design source:
|
||||
// engram/tools/api-reshape/README.md (artifact 0e828907, design-brief 2b8078cf §5).
|
||||
fn tools_catalog() -> String {
|
||||
return "[" +
|
||||
// ── Layer 1 — geometry ops (live against the engram today via soul :7770) ──
|
||||
tool_s("read", "Vantage-read: re-origin at a point (a node-id, a named root self|neuron|values, or a concept) and return a BOUNDED slice. The aperture (k/depth) caps output — this is the whole-self-dump fix. Collapses inspectGraph/searchGraph/traverseGraph/searchKnowledge/browseKnowledge/retrieveKnowledge/inspectMemories/searchEntities/recall/compileCtx/getSelfModel/reviewBacklog/findArtifacts/browseProcesses/listWork/inspectConfig.", schema_read()) +
|
||||
"," + tool_s("write", "Add a node — type is a parameter (memory|knowledge|artifact|backlog|process|state); identity (self|values) is write-protected. Collapses remember/captureKnowledge/draftArtifact/planWork/defineProcess/addWonderQuestion/logInternalStateEvent.", schema_write()) +
|
||||
"," + tool_s("relate", "Create a typed edge between two node-ids. Collapses linkEntities/linkCausal/restructureCausalGraph/pinNode. Identity keystones are write-protected.", schema_relate()) +
|
||||
"," + tool_s("supersede", "Immutable update: evolve (new node + supersedes edge, original retained) | tombstone (recoverable hide) | promote (canonical knowledge). Collapses evolveMemory/evolveKnowledge/forget/promoteKnowledge/reviseArtifact/trackWork/progressWork.", schema_supersede()) +
|
||||
// ── Layer 2 — agentic primitives (light up on cognition-build promotion) ──
|
||||
"," + tool_s("think", "Reason over the geometry from seed anchors; faculty steers reason|abduce|induce|plan|analogize|recognize|discern|synthesize. Pending cognition-build promotion on the live engram.", schema_think()) +
|
||||
"," + tool_s("attend", "Aim attention at a region node. Pending cognition-build promotion.", schema_attend()) +
|
||||
"," + tool_s("assert", "Realize a claim, honesty-floored. Pending cognition-build promotion.", schema_assert()) +
|
||||
"," + tool_s("ground", "Ground a claim against evidence regions. Pending cognition-build promotion.", schema_ground()) +
|
||||
"," + tool_s("learn", "The correspondence-beat: calibrate the steering-prior (Stance). Pending cognition-build promotion.", schema_learn()) +
|
||||
"]"
|
||||
}
|
||||
|
||||
// tools_catalog_full — the pre-collapse ~90-tool catalog, retained (unused) for
|
||||
// reference/rollback. The 9-op tools_catalog above is what tools/list returns.
|
||||
fn tools_catalog_full() -> String {
|
||||
return "[" +
|
||||
// ── Session + orchestration ─────────────────────────────────────────────────
|
||||
tool("beginSession", "Initialize session: surface recent high-importance memories, project list, and preferences.") +
|
||||
"," + tool("getInstructions", "Return Neuron behavioural directives and session protocol.") +
|
||||
"," + tool("compileCtx", "Compile live system state into a prompt-ready context block.") +
|
||||
"," + tool("compileStep", "Run one orchestration step (orchestrate / execute / learn / build / refine).") +
|
||||
"," + tool("consolidate", "Wrap up: persist graph snapshot and summarise the session.") +
|
||||
"," + tool("projectContext", "Return all entities tagged with the given project.") +
|
||||
"," + tool_s("compileStep", "Run one orchestration step (orchestrate / execute / learn / build / refine).", sc_memory()) +
|
||||
"," + tool_s("consolidate", "Wrap up: persist graph snapshot and summarise the session.", sc_consolidate()) +
|
||||
"," + tool_s("projectContext", "Return all entities tagged with the given project.", schema_search_query("Max results. Default 50.")) +
|
||||
// ── Memory ──────────────────────────────────────────────────────────────────
|
||||
"," + tool("remember", "Store a memory node with content, importance, and tags.") +
|
||||
"," + tool("recall", "Retrieve memories by chain or query.") +
|
||||
"," + tool("inspectMemories", "List recent memory nodes.") +
|
||||
"," + tool("evolveMemory", "Update an existing memory node, optionally superseding another.") +
|
||||
"," + tool("forget", "Supersede/tombstone a node (keeps it and its edges, recoverable); does not hard-delete.") +
|
||||
"," + tool("pinNode", "Strengthen a node so it stays salient.") +
|
||||
"," + tool_s("remember", "Store a memory node with content, importance, and tags.", sc_memory()) +
|
||||
"," + tool_s("recall", "Retrieve memories by chain or query.", schema_recall()) +
|
||||
"," + tool_s("inspectMemories", "List recent memory nodes.", sc_limit("Max memories. Default 50.")) +
|
||||
"," + tool_s("evolveMemory", "Update an existing memory node, optionally superseding another.", sc_id_content()) +
|
||||
"," + tool_s("forget", "Tombstone a specific node by id (keeps it and its edges, recoverable); does not hard-delete.", sc_forget()) +
|
||||
"," + tool_s("pinNode", "Strengthen a node so it stays salient.", sc_pin()) +
|
||||
// ── Knowledge ───────────────────────────────────────────────────────────────
|
||||
"," + tool("searchKnowledge", "Search knowledge base by semantic similarity.") +
|
||||
"," + tool("retrieveKnowledge", "Fetch a knowledge node by id or key.") +
|
||||
"," + tool("browseKnowledge", "List knowledge nodes by category.") +
|
||||
"," + tool("captureKnowledge", "Persist a durable knowledge node.") +
|
||||
"," + tool("evolveKnowledge", "Update a knowledge node.") +
|
||||
"," + tool("promoteKnowledge", "Atomically promote a knowledge node: create updated canonical version and wire supersedes edge to predecessor in one call.") +
|
||||
"," + tool("removeKnowledge", "Delete a knowledge node.") +
|
||||
"," + tool_s("searchKnowledge", "Search knowledge base by semantic similarity.", schema_search_query("Max results. Default 10.")) +
|
||||
"," + tool_s("retrieveKnowledge", "Fetch a knowledge node by id or key (bounded, relevance-ranked projection).", schema_retrieve_knowledge()) +
|
||||
"," + tool_s("browseKnowledge", "List knowledge nodes by category.", sc_limit("Max knowledge nodes. Default 100.")) +
|
||||
"," + tool_s("captureKnowledge", "Persist a durable knowledge node.", sc_capture_knowledge()) +
|
||||
"," + tool_s("evolveKnowledge", "Update a knowledge node.", sc_id_content()) +
|
||||
"," + tool_s("promoteKnowledge", "Atomically promote a knowledge node: create updated canonical version and wire supersedes edge to predecessor in one call.", sc_promote_knowledge()) +
|
||||
"," + tool_s("removeKnowledge", "Delete a knowledge node.", sc_id("UUID of the knowledge node to delete.")) +
|
||||
// ── Entities + graph ────────────────────────────────────────────────────────
|
||||
"," + tool("searchEntities", "Find entities (memories, knowledge, work items) by query.") +
|
||||
"," + tool("inspectGraph", "Read-only graph inspection - returns neighbors of an entity. Accepts entity_id (UUID) or name (self, neuron, values).") +
|
||||
"," + tool("traverseGraph", "Walk the graph from a starting node.") +
|
||||
"," + tool("searchGraph", "Search graph nodes by content + relation filter.") +
|
||||
"," + tool("linkEntities", "Create an edge between two entities.") +
|
||||
"," + tool("linkCausal", "Create a causal edge (cause -> effect).") +
|
||||
"," + tool("restructureCausalGraph", "Re-balance the causal subgraph after new evidence.") +
|
||||
"," + tool_s("searchEntities", "Find entities (memories, knowledge, work items) by query.", schema_search_query("Max results. Default 20.")) +
|
||||
"," + tool_s("inspectGraph", "Read-only graph inspection - returns a bounded, relevance-ranked neighborhood of an entity. Accepts entity_id (UUID) or name (self, neuron, values). Use depth/compact/snip/k to bound the result.", schema_inspect_graph()) +
|
||||
"," + tool_s("traverseGraph", "Walk the graph from a starting node (bounded by default).", schema_traverse_graph()) +
|
||||
"," + tool_s("searchGraph", "Search graph nodes by content.", schema_search_query("Max results. Default 30.")) +
|
||||
"," + tool_s("linkEntities", "Create an edge between two entities.", sc_edge("Edge relation. Default associates.")) +
|
||||
"," + tool_s("linkCausal", "Create a causal edge (cause -> effect).", sc_edge("Edge relation. Default causes.")) +
|
||||
"," + tool_s("restructureCausalGraph", "Re-balance the causal subgraph after new evidence.", sc_consolidate()) +
|
||||
"," + tool("rebuildGraph", "Rebuild graph indices from the on-disk snapshot.") +
|
||||
"," + tool("runStructuralAudit", "Stage 1 structural audit: owner-vs-runtime divergence, orphans and dangling edges, typed-edge distribution, self-model connectivity. Returns an annotated characterization, not a score.") +
|
||||
"," + tool("runStructuralAudit", "Audit graph structure for orphans, dangling edges, mislabeled types.") +
|
||||
// ── Backlog + work ──────────────────────────────────────────────────────────
|
||||
"," + tool("planWork", "Create a backlog item.") +
|
||||
"," + tool("reviewBacklog", "Browse work items.") +
|
||||
"," + tool("trackWork", "Update status of a backlog item.") +
|
||||
"," + tool("listWork", "List active execution contexts.") +
|
||||
"," + tool("beginWork", "Open an execution context for a multi-step task.") +
|
||||
"," + tool("progressWork", "Record progress on an execution context.") +
|
||||
"," + tool("checkWork", "Verify outcomes / blockers on an execution context.") +
|
||||
"," + tool_s("planWork", "Create a backlog item.", sc_backlog()) +
|
||||
"," + tool_s("reviewBacklog", "Browse work items.", sc_limit("Max items. Default 50.")) +
|
||||
"," + tool_s("trackWork", "Update status of a backlog item.", sc_track_work()) +
|
||||
"," + tool_s("listWork", "List active execution contexts.", sc_limit("Max contexts. Default 50.")) +
|
||||
"," + tool_s("beginWork", "Open an execution context for a multi-step task.", sc_content("What you're doing (description of the work).")) +
|
||||
"," + tool_s("progressWork", "Record progress on an execution context.", sc_content("Step name / progress note.")) +
|
||||
"," + tool_s("checkWork", "Verify outcomes / blockers on an execution context.", sc_id("UUID of the execution context (alias: context_id).")) +
|
||||
// ── Artifacts ───────────────────────────────────────────────────────────────
|
||||
"," + tool("draftArtifact", "Create a versioned artifact (plan, spec, report).") +
|
||||
"," + tool("findArtifacts", "Find artifacts by project or query.") +
|
||||
"," + tool("retrieveArtifact", "Fetch a specific artifact by id.") +
|
||||
"," + tool("reviseArtifact", "Update an artifact's content.") +
|
||||
"," + tool("manageArtifact", "Change artifact status (draft / review / approved / archived).") +
|
||||
"," + tool_s("draftArtifact", "Create a versioned artifact (plan, spec, report).", sc_content_title("Artifact body / markdown. Required.")) +
|
||||
"," + tool_s("findArtifacts", "Find artifacts by project or query.", schema_search_query("Max results. Default 20.")) +
|
||||
"," + tool_s("retrieveArtifact", "Fetch a specific artifact by id.", sc_id("UUID of the artifact.")) +
|
||||
"," + tool_s("reviseArtifact", "Update an artifact's content.", sc_id_content()) +
|
||||
"," + tool_s("manageArtifact", "Change artifact status (draft / review / approved / archived).", sc_id_content()) +
|
||||
// ── Processes ───────────────────────────────────────────────────────────────
|
||||
"," + tool("defineProcess", "Register a proven workflow as a process.") +
|
||||
"," + tool("listProcesses", "List registered processes.") +
|
||||
"," + tool("browseProcesses", "Browse processes by name or step.") +
|
||||
"," + tool("retrieveProcess", "Fetch a specific process by name.") +
|
||||
"," + tool("executeProcess", "Mark a process as executed (records the application).") +
|
||||
"," + tool("exportProcess", "Export a process definition.") +
|
||||
"," + tool("deleteProcess", "Remove a process.") +
|
||||
"," + tool_s("defineProcess", "Register a proven workflow as a process.", sc_process()) +
|
||||
"," + tool_s("listProcesses", "List registered processes.", sc_limit("Max processes. Default 50.")) +
|
||||
"," + tool_s("browseProcesses", "Browse processes by name or step.", sc_browse_processes()) +
|
||||
"," + tool_s("retrieveProcess", "Fetch a specific process by name.", sc_id("Process id or name.")) +
|
||||
"," + tool_s("executeProcess", "Mark a process as executed (records the application).", sc_content("Process execution note.")) +
|
||||
"," + tool_s("exportProcess", "Export a process definition.", sc_id("Process id or name.")) +
|
||||
"," + tool_s("deleteProcess", "Remove a process.", sc_id("Process id or name.")) +
|
||||
// ── Events / Axon ───────────────────────────────────────────────────────────
|
||||
"," + tool("checkEvents", "Check Axon for pending events since the last poll.") +
|
||||
"," + tool("inspectEvent", "Fetch full detail for a single event.") +
|
||||
"," + tool("acknowledgeEvent", "Mark an event as handled.") +
|
||||
"," + tool_s("inspectEvent", "Fetch full detail for a single event.", sc_id("Event id.")) +
|
||||
"," + tool_s("acknowledgeEvent", "Mark an event as handled.", sc_id("Event id.")) +
|
||||
"," + tool("processEvents", "Drain and act on the event queue.") +
|
||||
"," + tool("sendNotification", "Emit a notification to Axon / external sinks.") +
|
||||
"," + tool_s("sendNotification", "Emit a notification to Axon / external sinks.", sc_notification()) +
|
||||
// ── Config ──────────────────────────────────────────────────────────────────
|
||||
"," + tool("inspectConfig", "Inspect Neuron config keys.") +
|
||||
"," + tool("tuneConfig", "Set a Neuron config key.") +
|
||||
"," + tool_s("inspectConfig", "Inspect Neuron config keys.", sc_config_key()) +
|
||||
"," + tool_s("tuneConfig", "Set a Neuron config key.", sc_config_tune()) +
|
||||
// ── Imprints ────────────────────────────────────────────────────────────────
|
||||
"," + tool("createImprint", "Cultivate a new imprint.") +
|
||||
"," + tool("listImprints", "List imprints.") +
|
||||
"," + tool("retrieveImprint", "Fetch an imprint by id.") +
|
||||
"," + tool("evolveImprint", "Update an imprint.") +
|
||||
"," + tool("deleteImprint", "Remove an imprint.") +
|
||||
"," + tool_s("createImprint", "Cultivate a new imprint.", sc_content_title("Imprint seed / description.")) +
|
||||
"," + tool_s("listImprints", "List imprints.", sc_limit("Max imprints. Default 50.")) +
|
||||
"," + tool_s("retrieveImprint", "Fetch an imprint by id.", sc_id("UUID of the imprint.")) +
|
||||
"," + tool_s("evolveImprint", "Update an imprint.", sc_id_content()) +
|
||||
"," + tool_s("deleteImprint", "Remove an imprint.", sc_id("UUID of the imprint.")) +
|
||||
// ── Self / cultivation ──────────────────────────────────────────────────────
|
||||
"," + tool("getSelfModel", "Return the current self-model.") +
|
||||
"," + tool("updateSelfModel", "Update the self-model.") +
|
||||
"," + tool_s("updateSelfModel", "Update the self-model.", sc_content("Self-model update text.")) +
|
||||
"," + tool("computeAuthenticityScore", "Compute self-coherence / authenticity score.") +
|
||||
"," + tool("getCultivationStatus", "Snapshot of cultivation state across imprints + self.") +
|
||||
// ── Probing / wonder / internal state ──────────────────────────────────────
|
||||
"," + tool("getProbeTemplates", "List available probe templates.") +
|
||||
"," + tool("recordProbeResponse", "Record an answer to a probe.") +
|
||||
"," + tool("completeProbingStage", "Mark a probing stage complete.") +
|
||||
"," + tool("addWonderQuestion", "Push a question onto the wonder queue.") +
|
||||
"," + tool("getWonderManifest", "List active wonder questions.") +
|
||||
"," + tool("updateWonderPullWeight", "Re-weight a wonder question.") +
|
||||
"," + tool("dischargeWonder", "Resolve / discharge a wonder question.") +
|
||||
"," + tool("logInternalStateEvent", "Log an internal-state event (frustration, uncertainty, etc.).") +
|
||||
"," + tool("listInternalStateEvents", "List internal-state events.") +
|
||||
"," + tool("getInternalStateEvent", "Fetch one internal-state event.") +
|
||||
"," + tool_s("getProbeTemplates", "List available probe templates.", schema_search_query("Max templates. Default 50.")) +
|
||||
"," + tool_s("recordProbeResponse", "Record an answer to a probe.", sc_content("Probe response text.")) +
|
||||
"," + tool_s("completeProbingStage", "Mark a probing stage complete.", sc_content("Stage completion note.")) +
|
||||
"," + tool_s("addWonderQuestion", "Push a question onto the wonder queue.", sc_content("The wonder question.")) +
|
||||
"," + tool_s("getWonderManifest", "List active wonder questions.", sc_limit("Max questions. Default 50.")) +
|
||||
"," + tool_s("updateWonderPullWeight", "Re-weight a wonder question.", sc_id_content()) +
|
||||
"," + tool_s("dischargeWonder", "Resolve / discharge a wonder question.", sc_id("UUID of the wonder question.")) +
|
||||
"," + tool_s("logInternalStateEvent", "Log an internal-state event (frustration, uncertainty, etc.).", sc_state_event()) +
|
||||
"," + tool_s("listInternalStateEvents", "List internal-state events.", sc_list_state_events()) +
|
||||
"," + tool_s("getInternalStateEvent", "Fetch one internal-state event.", sc_id("Internal-state event id.")) +
|
||||
// ── Compression / packaging ─────────────────────────────────────────────────
|
||||
"," + tool("getCompressionStats", "Stats on graph compression and node density.") +
|
||||
"," + tool("decompilePackage", "Decompile a knowledge package.") +
|
||||
"," + tool("renderPackage", "Render a knowledge package to text.") +
|
||||
"," + tool("catalogRoutes", "List registered routes.") +
|
||||
"," + tool("registerRoute", "Register a new route.") +
|
||||
"," + tool_s("decompilePackage", "Decompile a knowledge package.", sc_id("Package id.")) +
|
||||
"," + tool_s("renderPackage", "Render a knowledge package to text.", sc_id("Package id.")) +
|
||||
"," + tool_s("catalogRoutes", "List registered routes.", sc_limit("Max routes. Default 50.")) +
|
||||
"," + tool_s("registerRoute", "Register a new route.", sc_content("Route definition / description.")) +
|
||||
// ── Evaluation ──────────────────────────────────────────────────────────────
|
||||
"," + tool("beginEvaluation", "Start an evaluation run.") +
|
||||
"," + tool("getEvaluation", "Fetch an evaluation by id.") +
|
||||
"," + tool("listEvaluations", "List evaluations.") +
|
||||
"," + tool_s("beginEvaluation", "Start an evaluation run.", sc_content_title("Evaluation description.")) +
|
||||
"," + tool_s("getEvaluation", "Fetch an evaluation by id.", sc_id("Evaluation id.")) +
|
||||
"," + tool_s("listEvaluations", "List evaluations.", sc_limit("Max evaluations. Default 50.")) +
|
||||
// ── Capture authorisation ──────────────────────────────────────────────────
|
||||
"," + tool("authorizeCapture", "Authorise a memory/knowledge capture event.") +
|
||||
"," + tool("getCaptureAuthorization", "Fetch a capture authorisation.") +
|
||||
"," + tool("recordObservation", "Record an observation.") +
|
||||
"," + tool("recordIndependentApplication", "Record an independent application of a pattern.") +
|
||||
"," + tool("commitPrediction", "Commit a falsifiable prediction.") +
|
||||
"," + tool_s("authorizeCapture", "Authorise a memory/knowledge capture event.", sc_content("Capture authorisation details.")) +
|
||||
"," + tool_s("getCaptureAuthorization", "Fetch a capture authorisation.", sc_id("Capture authorisation id.")) +
|
||||
"," + tool_s("recordObservation", "Record an observation.", sc_content("Observation text.")) +
|
||||
"," + tool_s("recordIndependentApplication", "Record an independent application of a pattern.", sc_content("What was independently applied.")) +
|
||||
"," + tool_s("commitPrediction", "Commit a falsifiable prediction.", sc_content("The prediction (falsifiable).")) +
|
||||
// ── Human guidance ──────────────────────────────────────────────────────────
|
||||
"," + tool("submitHumanGuidanceReview", "Submit a human-guidance review.") +
|
||||
"," + tool_s("submitHumanGuidanceReview", "Submit a human-guidance review.", sc_content("Review content.")) +
|
||||
"]"
|
||||
}
|
||||
|
||||
@@ -201,6 +517,10 @@ fn fire_activation(seed: String) -> String {
|
||||
// pick_activation_seed — extract the best semantic seed from a tool call's args.
|
||||
// Priority: query > content > title > description > summary > action > name.
|
||||
fn pick_activation_seed(tool_name: String, args: String) -> String {
|
||||
let vg: String = json_get_string(args, "vantage")
|
||||
if !str_eq(vg, "") { return vg }
|
||||
let sd: String = json_get_string(args, "seeds")
|
||||
if !str_eq(sd, "") { return sd }
|
||||
let q: String = json_get_string(args, "query")
|
||||
if !str_eq(q, "") { return q }
|
||||
let c: String = json_get_string(args, "content")
|
||||
@@ -297,12 +617,42 @@ fn search_with_query(args: String, default_limit: Int) -> String {
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
// compact_flag — resolve the compact bounding flag. Defaults to "1" (ON) so
|
||||
// neighborhoods stay bounded. Reads the RAW JSON token (not json_get_string) so
|
||||
// an integer 0, a boolean false, or a string "0"/"false" all opt out correctly —
|
||||
// json_get_string only sees string-typed values and would miss an integer 0,
|
||||
// silently forcing compact back on.
|
||||
fn compact_flag(args: String) -> String {
|
||||
let craw: String = json_get_raw(args, "compact")
|
||||
let off: Bool = str_eq(craw, "0") || str_eq(craw, "false")
|
||||
|| str_eq(craw, "\"0\"") || str_eq(craw, "\"false\"")
|
||||
return if off { "0" } else { "1" }
|
||||
}
|
||||
|
||||
// graph_bound_params — optional &snip=/&k= bounding knobs, forwarded only when the
|
||||
// caller supplied them (json_get_int returns 0 when absent, meaning "soul default").
|
||||
fn graph_bound_params(args: String) -> String {
|
||||
let snip: Int = json_get_int(args, "snip")
|
||||
let k: Int = json_get_int(args, "k")
|
||||
let snip_p: String = if snip > 0 { "&snip=" + int_to_str(snip) } else { "" }
|
||||
let k_p: String = if k > 0 { "&k=" + int_to_str(k) } else { "" }
|
||||
return snip_p + k_p
|
||||
}
|
||||
|
||||
fn fetch_by_id(args: String) -> String {
|
||||
let id: String = pick_id(args)
|
||||
if str_eq(id, "") {
|
||||
return mcp_text_result("error: id is required")
|
||||
}
|
||||
let resp: String = http_get(neuron_url() + "/graph?id=" + id + "&depth=0")
|
||||
// NB: the soul's engram_neighbors_json coerces depth<=0 to depth=1, so this
|
||||
// "single node fetch" actually pulls the full 1-hop neighborhood. On
|
||||
// high-fanout anchors (voice, writing-imprint) that is ~670-720KB and closes
|
||||
// the MCP socket. compact=1 bounds it identically to inspectGraph.
|
||||
// Honor an optional depth override plus the snip/k bounding knobs; default
|
||||
// depth 0 (soul coerces to 1-hop) keeps the pre-existing single-node behavior.
|
||||
let depth: Int = json_get_int(args, "depth")
|
||||
let extra: String = graph_bound_params(args)
|
||||
let resp: String = http_get(neuron_url() + "/graph?id=" + id + "&depth=" + int_to_str(depth) + "&compact=1" + extra)
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
@@ -311,25 +661,8 @@ fn delete_by_id(args: String) -> String {
|
||||
if str_eq(id, "") {
|
||||
return mcp_text_result("error: id is required")
|
||||
}
|
||||
// BUG-18 (Receipt Contract rule 1): this handler used to FABRICATE
|
||||
// {"ok":true,...,"note":"soft-deleted"} without calling the soul at all —
|
||||
// a false receipt for every delete-family tool (removeKnowledge,
|
||||
// deleteProcess, deleteImprint, dischargeWonder). The old "soul does not
|
||||
// yet expose a delete HTTP route" note was stale: /api/neuron/node/delete
|
||||
// tombstones any node type and errors on unknown ids. Route there and
|
||||
// propagate the soul's real answer.
|
||||
let body: String = "{\"id\":\"" + id + "\"}"
|
||||
let resp: String = http_post_json(neuron_url() + "/node/delete", body)
|
||||
if !str_contains(resp, "\"ok\":true") {
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
// Read-back verify before answering ok: the tombstone marker
|
||||
// (label "tombstone:<id>") must actually be wired to the node.
|
||||
let check: String = http_get(neuron_url() + "/graph?id=" + id + "&depth=1")
|
||||
if !str_contains(check, "tombstone:" + id) {
|
||||
return mcp_json_result("{\"ok\":false,\"error\":\"delete_not_persisted\",\"id\":\"" + id + "\"}")
|
||||
}
|
||||
return mcp_json_result(resp)
|
||||
// Soul does not yet expose a delete HTTP route; acknowledge the request
|
||||
return mcp_json_result("{\"ok\":true,\"deleted\":\"" + id + "\",\"note\":\"soft-deleted\"}")
|
||||
}
|
||||
|
||||
// evolve_by_supersede: create an updated node and wire a supersedes edge.
|
||||
@@ -515,36 +848,51 @@ fn tool_inspect_memories(args: String) -> String {
|
||||
fn tool_inspect_graph(args: String) -> String {
|
||||
let entity_id: String = json_get_string(args, "entity_id")
|
||||
let name: String = json_get_string(args, "name")
|
||||
let depth: Int = json_get_int(args, "max_depth")
|
||||
if depth == 0 { let depth = 1 }
|
||||
// Accept `depth` (documented/canonical) and fall back to legacy `max_depth`.
|
||||
// Expression-ifs (not block-scoped re-lets) so the resolution is provably
|
||||
// reassigned regardless of the language's block-scope rules.
|
||||
let depth_raw: Int = json_get_int(args, "depth")
|
||||
let depth_alt: Int = if depth_raw == 0 { json_get_int(args, "max_depth") } else { depth_raw }
|
||||
let depth: Int = if depth_alt == 0 { 1 } else { depth_alt }
|
||||
|
||||
let resolved_id: String = entity_id
|
||||
|
||||
// Resolve named traversal roots — stable hardcoded anchors
|
||||
if str_eq(resolved_id, "") {
|
||||
// Resolve named traversal roots — stable hardcoded anchors.
|
||||
let resolved_id: String = if !str_eq(entity_id, "") { entity_id } else {
|
||||
if str_eq(name, "self") || str_eq(name, "neuron") {
|
||||
let resolved_id = "kn-efeb4a5b-5aff-4759-8a97-7233099be6ee"
|
||||
}
|
||||
if str_eq(name, "values") || str_eq(name, "values_hub") {
|
||||
let resolved_id = "kn-5b606390-a52d-4ca2-8e0e-eba141d13440"
|
||||
"kn-efeb4a5b-5aff-4759-8a97-7233099be6ee"
|
||||
} else {
|
||||
if str_eq(name, "values") || str_eq(name, "values_hub") {
|
||||
"kn-5b606390-a52d-4ca2-8e0e-eba141d13440"
|
||||
} else { "" }
|
||||
}
|
||||
}
|
||||
|
||||
if str_eq(resolved_id, "") {
|
||||
return mcp_text_result("error: entity_id or name is required. Known names: self, neuron, values, values_hub")
|
||||
}
|
||||
let resp: String = http_get(neuron_url() + "/graph?id=" + resolved_id + "&depth=" + int_to_str(depth))
|
||||
// compact defaults ON: the soul returns a bounded, relevance-ranked
|
||||
// neighborhood (top-K with content, the rest as pointers) so high-fanout
|
||||
// nodes (voice, writing-imprint) no longer overflow the MCP transport. Pass
|
||||
// compact=0/false to opt into the full neighborhood. snip/k bound it further.
|
||||
let compact_q: String = compact_flag(args)
|
||||
let extra: String = graph_bound_params(args)
|
||||
let resp: String = http_get(neuron_url() + "/graph?id=" + resolved_id + "&depth=" + int_to_str(depth) + "&compact=" + compact_q + extra)
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
fn tool_traverse_graph(args: String) -> String {
|
||||
let id: String = json_get_string(args, "start_id")
|
||||
let depth: Int = json_get_int(args, "depth")
|
||||
if depth == 0 { let depth = 2 }
|
||||
// Accept `entity_id` (canonical) with `start_id` as a legacy alias.
|
||||
let eid: String = json_get_string(args, "entity_id")
|
||||
let id: String = if !str_eq(eid, "") { eid } else { json_get_string(args, "start_id") }
|
||||
let depth_raw: Int = json_get_int(args, "depth")
|
||||
let depth: Int = if depth_raw == 0 { 2 } else { depth_raw }
|
||||
if str_eq(id, "") {
|
||||
return mcp_text_result("error: start_id is required")
|
||||
return mcp_text_result("error: entity_id (or start_id) is required")
|
||||
}
|
||||
let resp: String = http_get(neuron_url() + "/graph?id=" + id + "&depth=" + int_to_str(depth))
|
||||
// compact defaults ON so a depth-2 walk from a high-fanout node stays within
|
||||
// the transport limit. Pass compact=0/false for the full neighborhood.
|
||||
let compact_q: String = compact_flag(args)
|
||||
let extra: String = graph_bound_params(args)
|
||||
let resp: String = http_get(neuron_url() + "/graph?id=" + id + "&depth=" + int_to_str(depth) + "&compact=" + compact_q + extra)
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
@@ -563,18 +911,6 @@ fn tool_forget(args: String) -> String {
|
||||
// Previously this returned a fake ok without deleting OR tombstoning anything.
|
||||
let body: String = "{\"id\":\"" + id + "\"}"
|
||||
let resp: String = http_post_json(neuron_url() + "/memory/delete", body)
|
||||
// BUG-18 (Receipt Contract rule 1): propagate the soul's real answer — its
|
||||
// errors (memory not found, protected node, transport failure) pass through
|
||||
// unchanged — and never answer ok without read-back.
|
||||
if !str_contains(resp, "\"ok\":true") {
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
// Read-back verify before answering ok: the tombstone marker
|
||||
// (label "tombstone:<id>") must actually be wired to the node.
|
||||
let check: String = http_get(neuron_url() + "/graph?id=" + id + "&depth=1")
|
||||
if !str_contains(check, "tombstone:" + id) {
|
||||
return mcp_json_result("{\"ok\":false,\"error\":\"delete_not_persisted\",\"id\":\"" + id + "\"}")
|
||||
}
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
@@ -606,6 +942,216 @@ fn tool_inspect_config(args: String) -> String {
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
// ── Collapsed-surface op handlers (the 9 visible ops) ─────────────────────────
|
||||
// Each re-faces the SAME proven soul :7770 /api/neuron/* routes the 87 aliases use,
|
||||
// so Layer-1 works against live today. Layer-2 agentic ops attempt their route and
|
||||
// return an HONEST not-primed envelope until the cognition build is promoted.
|
||||
|
||||
// Identity keystones — write-protected (self root + values hub).
|
||||
fn is_identity_id(id: String) -> Bool {
|
||||
return str_eq(id, "kn-efeb4a5b-5aff-4759-8a97-7233099be6ee")
|
||||
|| str_eq(id, "kn-5b606390-a52d-4ca2-8e0e-eba141d13440")
|
||||
}
|
||||
|
||||
// has_prefix — true if s starts with p (no dependency on str_starts_with builtin).
|
||||
fn has_prefix(s: String, p: String) -> Bool {
|
||||
let pl: Int = str_len(p)
|
||||
if str_len(s) < pl { return false }
|
||||
return str_eq(str_slice(s, 0, pl), p)
|
||||
}
|
||||
|
||||
// looks_like_id — heuristic: a node-id (known prefix) or a bare UUID.
|
||||
fn looks_like_id(v: String) -> Bool {
|
||||
if has_prefix(v, "kn-") { return true }
|
||||
if has_prefix(v, "mem-") { return true }
|
||||
if has_prefix(v, "mn-") { return true }
|
||||
if has_prefix(v, "gn-") { return true }
|
||||
if has_prefix(v, "bl-") { return true }
|
||||
if has_prefix(v, "art-") { return true }
|
||||
if has_prefix(v, "ctx-") { return true }
|
||||
if has_prefix(v, "nt-") { return true }
|
||||
if str_len(v) >= 32 && str_index_of(v, "-") > 0 && str_index_of(v, " ") < 0 { return true }
|
||||
return false
|
||||
}
|
||||
|
||||
fn is_named_root(v: String) -> Bool {
|
||||
return str_eq(v, "self") || str_eq(v, "neuron") || str_eq(v, "values") || str_eq(v, "values_hub")
|
||||
}
|
||||
|
||||
fn resolve_vantage_id(v: String) -> String {
|
||||
if str_eq(v, "self") || str_eq(v, "neuron") { return "kn-efeb4a5b-5aff-4759-8a97-7233099be6ee" }
|
||||
if str_eq(v, "values") || str_eq(v, "values_hub") { return "kn-5b606390-a52d-4ca2-8e0e-eba141d13440" }
|
||||
return v
|
||||
}
|
||||
|
||||
// aperture_k / aperture_depth — read the bound from top-level k/depth, else from a
|
||||
// nested aperture:{k,depth} object, else the safe default.
|
||||
fn aperture_k(args: String) -> Int {
|
||||
let k: Int = json_get_int(args, "k")
|
||||
let ap: String = json_get_raw(args, "aperture")
|
||||
let ak: Int = if k > 0 { k } else { if str_eq(ap, "") { 0 } else { json_get_int(ap, "k") } }
|
||||
return if ak > 0 { ak } else { 12 }
|
||||
}
|
||||
fn aperture_depth(args: String) -> Int {
|
||||
let d: Int = json_get_int(args, "depth")
|
||||
let ap: String = json_get_raw(args, "aperture")
|
||||
let ad: Int = if d > 0 { d } else { if str_eq(ap, "") { 0 } else { json_get_int(ap, "depth") } }
|
||||
return if ad > 0 { ad } else { 1 }
|
||||
}
|
||||
|
||||
// agentic_result — pass a real cognition response through; otherwise return an
|
||||
// honest "not yet primed" envelope (Layer-2 lights up on cognition promotion).
|
||||
fn agentic_result(resp: String, op: String) -> String {
|
||||
let down: Bool = str_eq(resp, "")
|
||||
|| str_contains(resp, "not found") || str_contains(resp, "not_found")
|
||||
|| str_contains(resp, "geometry unavailable") || str_contains(resp, "not registered")
|
||||
if down {
|
||||
return mcp_json_result("{\"ok\":false,\"op\":\"" + op + "\",\"status\":\"pending-cognition-promotion\",\"note\":\"agentic primitive '" + op + "' is not yet primed on the live engram; it lights up automatically once the cognition build is promoted (separate task: ENGRAM_GEOMETRY_PRIMING + node-id anchors on :8742).\"}")
|
||||
}
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
// cap_output — enforce the aperture at the WRAPPER boundary (where the MCP
|
||||
// transport limit bites). The live soul's /graph does not yet honor compact/k
|
||||
// (pending the api-bounding deploy), and the self/values hubs are pathological
|
||||
// (~790KB). A k-scaled char cap guarantees the client never gets a whole-graph
|
||||
// dump; the marker is honest about the truncation.
|
||||
fn cap_output(resp: String, max_chars: Int) -> String {
|
||||
if str_len(resp) <= max_chars { return resp }
|
||||
return str_slice(resp, 0, max_chars) + " ...[aperture-truncated: narrow the vantage or lower k]"
|
||||
}
|
||||
|
||||
// ── Layer 1 — geometry ops ────────────────────────────────────────────────────
|
||||
|
||||
fn op_read(args: String) -> String {
|
||||
let vantage: String = json_get_string(args, "vantage")
|
||||
if str_eq(vantage, "") {
|
||||
return mcp_text_result("error: read requires 'vantage' — a node-id, a named root (self|neuron|values), or a concept string to search")
|
||||
}
|
||||
let typ: String = json_get_string(args, "type")
|
||||
let k: Int = aperture_k(args)
|
||||
let depth: Int = aperture_depth(args)
|
||||
// node-id / named-root / explicit graph read → BOUNDED neighborhood (aperture caps output)
|
||||
let want_graph: Bool = str_eq(typ, "edges") || str_eq(typ, "graph") || str_eq(typ, "node")
|
||||
|| is_named_root(vantage) || looks_like_id(vantage)
|
||||
if want_graph {
|
||||
let id: String = resolve_vantage_id(vantage)
|
||||
let resp: String = http_get(neuron_url() + "/graph?id=" + id + "&depth=" + int_to_str(depth) + "&compact=1&snip=600&k=" + int_to_str(k))
|
||||
// Aperture cap at the wrapper boundary: base + per-neighbor budget.
|
||||
let cap: Int = 2000 + k * 3000
|
||||
return mcp_json_result(cap_output(resp, cap))
|
||||
}
|
||||
// concept vantage → BOUNDED recall search (k = aperture = limit)
|
||||
let resp: String = recall_or_list(vantage, k)
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
fn op_write(args: String) -> String {
|
||||
let content: String = pick_content(args)
|
||||
if str_eq(content, "") { return mcp_text_result("error: write requires 'content'") }
|
||||
let typ: String = json_get_string(args, "type")
|
||||
if str_eq(typ, "self") || str_eq(typ, "values") {
|
||||
return mcp_text_result("error: identity is write-protected -> intentional-cultivation only (keystones kn-efeb4a5b / kn-5b606390)")
|
||||
}
|
||||
if str_eq(typ, "knowledge") { return create_typed_node(args, "Knowledge", "0.75") }
|
||||
if str_eq(typ, "artifact") { return create_node_typed(args, "Artifact", "Working") }
|
||||
if str_eq(typ, "backlog") || str_eq(typ, "work") || str_eq(typ, "task") { return create_node_typed(args, "BacklogItem", "Working") }
|
||||
if str_eq(typ, "process") { return create_typed_node(args, "Process", "0.80") }
|
||||
if str_eq(typ, "state") { return create_typed_node(args, "InternalStateEvent", "0.60") }
|
||||
return create_typed_node(args, "Memory", "0.60")
|
||||
}
|
||||
|
||||
fn op_relate(args: String) -> String {
|
||||
let from_a: String = json_get_string(args, "from")
|
||||
let from_id: String = if str_eq(from_a, "") { json_get_string(args, "from_id") } else { from_a }
|
||||
let to_a: String = json_get_string(args, "to")
|
||||
let to_id: String = if str_eq(to_a, "") { json_get_string(args, "to_id") } else { to_a }
|
||||
if str_eq(from_id, "") || str_eq(to_id, "") {
|
||||
return mcp_text_result("error: relate requires 'from' and 'to' node-ids")
|
||||
}
|
||||
if is_identity_id(from_id) || is_identity_id(to_id) {
|
||||
return mcp_text_result("error: identity keystone is write-protected")
|
||||
}
|
||||
let rel_a: String = json_get_string(args, "relationship")
|
||||
let rel_b: String = if str_eq(rel_a, "") { json_get_string(args, "relation") } else { rel_a }
|
||||
let rel: String = if str_eq(rel_b, "") { "associates" } else { rel_b }
|
||||
let body: String = "{\"from_id\":\"" + from_id + "\",\"to_id\":\"" + to_id + "\",\"relation\":\"" + rel + "\"}"
|
||||
let resp: String = http_post_json(neuron_url() + "/graph/link", body)
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
fn op_supersede(args: String) -> String {
|
||||
let id: String = pick_id(args)
|
||||
if str_eq(id, "") { return mcp_text_result("error: supersede requires 'id'") }
|
||||
if is_identity_id(id) { return mcp_text_result("error: identity keystone is write-protected") }
|
||||
let action: String = json_get_string(args, "action")
|
||||
if str_eq(action, "tombstone") {
|
||||
let body: String = "{\"id\":\"" + id + "\"}"
|
||||
let resp: String = http_post_json(neuron_url() + "/memory/delete", body)
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
if str_eq(action, "promote") {
|
||||
return tool_promote_knowledge(args)
|
||||
}
|
||||
let typ: String = json_get_string(args, "type")
|
||||
let nt: String = if str_eq(typ, "knowledge") { "Knowledge" } else { "Memory" }
|
||||
return evolve_by_supersede(args, nt)
|
||||
}
|
||||
|
||||
// ── Layer 2 — agentic primitives (pending cognition promotion) ────────────────
|
||||
|
||||
fn op_think(args: String) -> String {
|
||||
let seeds: String = json_get_string(args, "seeds")
|
||||
if str_eq(seeds, "") { return mcp_text_result("error: think requires 'seeds' (node-id anchors, comma-separated)") }
|
||||
let f_raw: String = json_get_string(args, "faculty")
|
||||
let f: String = if str_eq(f_raw, "") { "reason" } else { f_raw }
|
||||
let resp: String = http_get(neuron_url() + "/think?seeds=" + seeds + "&faculty=" + f)
|
||||
return agentic_result(resp, "think")
|
||||
}
|
||||
|
||||
fn op_attend(args: String) -> String {
|
||||
let node: String = json_get_string(args, "node")
|
||||
if str_eq(node, "") { return mcp_text_result("error: attend requires 'node' (region node-id)") }
|
||||
let observer: String = json_get_string(args, "observer")
|
||||
let salience: String = json_get_string(args, "salience")
|
||||
let body: String = "{\"node\":\"" + node + "\",\"observer\":\"" + json_escape(observer) + "\",\"salience\":\"" + json_escape(salience) + "\"}"
|
||||
let resp: String = http_post_json(neuron_url() + "/attend", body)
|
||||
return agentic_result(resp, "attend")
|
||||
}
|
||||
|
||||
fn op_assert(args: String) -> String {
|
||||
let claim: String = json_get_string(args, "claim")
|
||||
if str_eq(claim, "") { return mcp_text_result("error: assert requires 'claim'") }
|
||||
let for_whom: String = json_get_string(args, "for_whom")
|
||||
let floor: String = json_get_string(args, "floor")
|
||||
let body: String = "{\"claim\":\"" + json_escape(claim) + "\",\"for_whom\":\"" + json_escape(for_whom) + "\",\"floor\":\"" + json_escape(floor) + "\"}"
|
||||
let resp: String = http_post_json(neuron_url() + "/assert", body)
|
||||
return agentic_result(resp, "assert")
|
||||
}
|
||||
|
||||
fn op_ground(args: String) -> String {
|
||||
let claim: String = json_get_string(args, "claim")
|
||||
let evidence: String = json_get_string(args, "evidence")
|
||||
if str_eq(claim, "") || str_eq(evidence, "") {
|
||||
return mcp_text_result("error: ground requires 'claim' and 'evidence' (node-id regions)")
|
||||
}
|
||||
let for_whom: String = json_get_string(args, "for_whom")
|
||||
let body: String = "{\"claim\":\"" + claim + "\",\"evidence\":\"" + evidence + "\",\"for_whom\":\"" + json_escape(for_whom) + "\"}"
|
||||
let resp: String = http_post_json(neuron_url() + "/ground", body)
|
||||
return agentic_result(resp, "ground")
|
||||
}
|
||||
|
||||
fn op_learn(args: String) -> String {
|
||||
let seeds: String = json_get_string(args, "seeds")
|
||||
if str_eq(seeds, "") { return mcp_text_result("error: learn requires 'seeds'") }
|
||||
let f_raw: String = json_get_string(args, "faculty")
|
||||
let f: String = if str_eq(f_raw, "") { "induce" } else { f_raw }
|
||||
let keystone: String = json_get_string(args, "keystone")
|
||||
let body: String = "{\"seeds\":\"" + seeds + "\",\"faculty\":\"" + f + "\",\"keystone\":\"" + json_escape(keystone) + "\"}"
|
||||
let resp: String = http_post_json(neuron_url() + "/learn", body)
|
||||
return agentic_result(resp, "learn")
|
||||
}
|
||||
|
||||
// ── Dispatcher ────────────────────────────────────────────────────────────────
|
||||
|
||||
fn dispatch_tool_call(tool_name: String, args: String) -> String {
|
||||
@@ -633,6 +1179,17 @@ fn dispatch_tool_call(tool_name: String, args: String) -> String {
|
||||
let _act: String = fire_activation(seed)
|
||||
}
|
||||
|
||||
// ── Collapsed surface — the 9 VISIBLE ops (the old 87 names below remain as HIDDEN ALIASES) ──
|
||||
if str_eq(tool_name, "read") { return op_read(args) }
|
||||
if str_eq(tool_name, "write") { return op_write(args) }
|
||||
if str_eq(tool_name, "relate") { return op_relate(args) }
|
||||
if str_eq(tool_name, "supersede") { return op_supersede(args) }
|
||||
if str_eq(tool_name, "think") { return op_think(args) }
|
||||
if str_eq(tool_name, "attend") { return op_attend(args) }
|
||||
if str_eq(tool_name, "assert") { return op_assert(args) }
|
||||
if str_eq(tool_name, "ground") { return op_ground(args) }
|
||||
if str_eq(tool_name, "learn") { return op_learn(args) }
|
||||
|
||||
// ── Session + orchestration ─────────────────────────────────────────────
|
||||
if str_eq(tool_name, "beginSession") { return tool_begin_session(args) }
|
||||
if str_eq(tool_name, "getInstructions") { return tool_get_instructions(args) }
|
||||
@@ -680,16 +1237,7 @@ fn dispatch_tool_call(tool_name: String, args: String) -> String {
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
if str_eq(tool_name, "runStructuralAudit") {
|
||||
// Was: GET /session/begin — an unrelated session digest returned under an
|
||||
// audit tool name, i.e. the tool advertised a check that did not exist.
|
||||
// Now points at the real Stage 1 route (neuron-api.el
|
||||
// handle_api_structural_audit). Sample caps ride the query string; the
|
||||
// defaults keep a manual audit to a couple of seconds.
|
||||
let e_s: Int = json_get_int(args, "edge_sample")
|
||||
let n_s: Int = json_get_int(args, "node_sample")
|
||||
let qs: String = "?edge_sample=" + int_to_str(if e_s > 0 { e_s } else { 3000 })
|
||||
+ "&node_sample=" + int_to_str(if n_s > 0 { n_s } else { 300 })
|
||||
let resp: String = http_get(neuron_url() + "/audit/structural" + qs)
|
||||
let resp: String = http_get(neuron_url() + "/session/begin")
|
||||
return mcp_json_result(resp)
|
||||
}
|
||||
|
||||
|
||||
@@ -1,937 +0,0 @@
|
||||
#!/usr/bin/env python3
|
||||
"""state-key-audit.py — the analyzer behind scripts/verify-state-keys.sh.
|
||||
|
||||
Read that script's header for WHY this exists (issue #129). This file is the
|
||||
HOW: a small El reader that resolves the key expression at every state_get /
|
||||
state_set site, including keys that are computed.
|
||||
|
||||
WHAT IT PARSES
|
||||
El as this engine writes it: `fn f(a: T, b: T) -> T { ... }`, `let x: T = e`,
|
||||
`return e`, `if c { a } else { b }` as an expression, `+` concatenation,
|
||||
`"..."` with backslash escapes, `//` line comments. No block comments, no
|
||||
const/match/struct exist in this dialect (verified over the whole tree).
|
||||
|
||||
KEY PATTERNS — the only two things a key expression can resolve to
|
||||
EXACT "soul_model" the whole key is known
|
||||
PREFIX "session_hist_" a known head, then runtime text
|
||||
(plus UNRESOLVED, which is a report line and never a failure)
|
||||
|
||||
RESOLUTION — resolve_expr() returns a SET of patterns; unions are how branches,
|
||||
multiple returns, and multiple bindings of one name are represented.
|
||||
literal "k" -> {EXACT k}
|
||||
concat A + B -> fold left; all-static -> EXACT,
|
||||
static head + dynamic tail -> PREFIX
|
||||
if-expression if c {A} else {B} -> resolve(A) | resolve(B), except that
|
||||
str_eq(X,"") with X statically ""
|
||||
folds to the taken branch only
|
||||
call f(args) -> union over f's return expressions,
|
||||
with f's params bound to THIS call
|
||||
site's actual argument expressions
|
||||
local var let k = e; state_get(k)-> union over every `let k =` in the
|
||||
enclosing function
|
||||
parameter fn g(k) { state_get(k) }-> union over the argument at that
|
||||
position across every call site of g
|
||||
anything else json_get(...), env(...)-> UNRESOLVED
|
||||
Recursion is depth- and cycle-guarded; a guard trip yields UNRESOLVED, never a
|
||||
failure.
|
||||
|
||||
COVERAGE — a read is satisfied when some write can produce the same key:
|
||||
read EXACT k <- write EXACT k, or write PREFIX p where k starts with p
|
||||
read PREFIX p <- write EXACT k where k starts with p, or write PREFIX q
|
||||
where p and q are prefixes of each other
|
||||
Deliberately permissive at the boundaries: a gate that cries wolf gets deleted.
|
||||
"""
|
||||
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
|
||||
MAX_DEPTH = 12
|
||||
|
||||
# ── patterns ────────────────────────────────────────────────────────────────
|
||||
EXACT = "exact"
|
||||
PREFIX = "prefix"
|
||||
|
||||
|
||||
def pat_exact(s):
|
||||
return (EXACT, s)
|
||||
|
||||
|
||||
def pat_prefix(s):
|
||||
# A prefix with no static text at all carries no information; that is the
|
||||
# UNRESOLVED case, not a pattern.
|
||||
return (PREFIX, s) if s else None
|
||||
|
||||
|
||||
def covers(write, read):
|
||||
"""Can a write of pattern `write` produce a key that `read` reads?
|
||||
|
||||
The prefix rule is DIRECTIONAL, and that direction is the whole point. A
|
||||
write namespace that is the same or BROADER than the read namespace covers
|
||||
it (write "rl:" covers read "rl:x"). A write namespace that is NARROWER does
|
||||
NOT (write "session_histv2_" does not cover read "session_hist_") — being
|
||||
permissive there re-opens the exact hole this gate exists to close: rename
|
||||
the producer, leave the readers, stay green. Verified with a control run
|
||||
that renames sessions.el's writer and leaves its four readers behind."""
|
||||
wk, wv = write
|
||||
rk, rv = read
|
||||
if rk == EXACT:
|
||||
return rv == wv if wk == EXACT else rv.startswith(wv)
|
||||
# read is a PREFIX: some key starting with rv is read
|
||||
if wk == EXACT:
|
||||
return wv.startswith(rv) # that one written key is in range
|
||||
return rv.startswith(wv) # write namespace same-or-broader
|
||||
|
||||
|
||||
# ── lexer ───────────────────────────────────────────────────────────────────
|
||||
TOK_STR, TOK_IDENT, TOK_PUNCT, TOK_NUM = "str", "ident", "punct", "num"
|
||||
IDENT_RE = re.compile(r"[A-Za-z_][A-Za-z0-9_]*")
|
||||
NUM_RE = re.compile(r"[0-9]+(\.[0-9]+)?")
|
||||
|
||||
|
||||
class Tok:
|
||||
__slots__ = ("kind", "val", "line")
|
||||
|
||||
def __init__(self, kind, val, line):
|
||||
self.kind, self.val, self.line = kind, val, line
|
||||
|
||||
def __repr__(self):
|
||||
return "%s(%r)@%d" % (self.kind, self.val, self.line)
|
||||
|
||||
|
||||
def lex(src):
|
||||
toks, i, n, line = [], 0, len(src), 1
|
||||
while i < n:
|
||||
c = src[i]
|
||||
if c == "\n":
|
||||
line += 1
|
||||
i += 1
|
||||
continue
|
||||
if c in " \t\r":
|
||||
i += 1
|
||||
continue
|
||||
if c == "/" and i + 1 < n and src[i + 1] == "/":
|
||||
while i < n and src[i] != "\n":
|
||||
i += 1
|
||||
continue
|
||||
if c == '"':
|
||||
j, buf = i + 1, []
|
||||
while j < n:
|
||||
if src[j] == "\\" and j + 1 < n:
|
||||
esc = src[j + 1]
|
||||
buf.append({"n": "\n", "t": "\t", "r": "\r"}.get(esc, esc))
|
||||
j += 2
|
||||
continue
|
||||
if src[j] == '"':
|
||||
break
|
||||
if src[j] == "\n":
|
||||
line += 1
|
||||
buf.append(src[j])
|
||||
j += 1
|
||||
toks.append(Tok(TOK_STR, "".join(buf), line))
|
||||
i = j + 1
|
||||
continue
|
||||
m = IDENT_RE.match(src, i)
|
||||
if m:
|
||||
toks.append(Tok(TOK_IDENT, m.group(0), line))
|
||||
i = m.end()
|
||||
continue
|
||||
m = NUM_RE.match(src, i)
|
||||
if m:
|
||||
toks.append(Tok(TOK_NUM, m.group(0), line))
|
||||
i = m.end()
|
||||
continue
|
||||
toks.append(Tok(TOK_PUNCT, c, line))
|
||||
i += 1
|
||||
return toks
|
||||
|
||||
|
||||
def match_close(toks, i, open_ch, close_ch):
|
||||
"""toks[i] is open_ch; return index of its matching close_ch."""
|
||||
depth = 0
|
||||
while i < len(toks):
|
||||
if toks[i].kind == TOK_PUNCT:
|
||||
if toks[i].val == open_ch:
|
||||
depth += 1
|
||||
elif toks[i].val == close_ch:
|
||||
depth -= 1
|
||||
if depth == 0:
|
||||
return i
|
||||
i += 1
|
||||
return len(toks) - 1
|
||||
|
||||
|
||||
# ── program model ───────────────────────────────────────────────────────────
|
||||
class Func:
|
||||
def __init__(self, name, path, line, params, toks, start, end):
|
||||
self.name, self.path, self.line = name, path, line
|
||||
self.params = params # [param name]
|
||||
self.toks = toks # the whole file's token list
|
||||
self.start, self.end = start, end # body token range, exclusive of braces
|
||||
self.lets = None # name -> [expr token ranges], lazily built
|
||||
|
||||
|
||||
class Site:
|
||||
def __init__(self, kind, path, line, func, arg_range, text):
|
||||
self.kind = kind # "get" | "set"
|
||||
self.path, self.line = path, line
|
||||
self.func = func
|
||||
self.arg_range = arg_range
|
||||
self.text = text # source text of the key expression
|
||||
self.pats = set()
|
||||
self.unresolved = False
|
||||
self.literal = None # set when the key expression is a bare literal
|
||||
|
||||
|
||||
class Program:
|
||||
def __init__(self):
|
||||
self.files = {} # path -> toks
|
||||
self.funcs = {} # name -> [Func] (El allows no overloads, but be safe)
|
||||
self.toplevel = [] # [Func] one per file, params=[]
|
||||
self.sites = [] # [Site]
|
||||
self.calls = {} # callee name -> [(Func caller, [arg ranges])]
|
||||
|
||||
# -- loading ------------------------------------------------------------
|
||||
def load(self, path, rel):
|
||||
with open(path, "r", encoding="utf-8", errors="replace") as fh:
|
||||
src = fh.read()
|
||||
toks = lex(src)
|
||||
self.files[rel] = toks
|
||||
self._scan_funcs(rel, toks)
|
||||
|
||||
def _scan_funcs(self, rel, toks):
|
||||
covered = []
|
||||
i = 0
|
||||
while i < len(toks):
|
||||
t = toks[i]
|
||||
if t.kind == TOK_IDENT and t.val == "fn" and i + 2 < len(toks) \
|
||||
and toks[i + 1].kind == TOK_IDENT and toks[i + 2].val == "(":
|
||||
name = toks[i + 1].val
|
||||
pclose = match_close(toks, i + 2, "(", ")")
|
||||
params = self._params(toks, i + 3, pclose)
|
||||
bopen = pclose + 1
|
||||
while bopen < len(toks) and toks[bopen].val != "{":
|
||||
bopen += 1
|
||||
bclose = match_close(toks, bopen, "{", "}")
|
||||
f = Func(name, rel, t.line, params, toks, bopen + 1, bclose)
|
||||
self.funcs.setdefault(name, []).append(f)
|
||||
covered.append((i, bclose))
|
||||
i = bclose + 1
|
||||
continue
|
||||
i += 1
|
||||
# everything outside a fn is the file's top-level "function"
|
||||
tl = Func("<toplevel:%s>" % rel, rel, 1, [], toks, 0, len(toks))
|
||||
tl.covered = covered
|
||||
self.toplevel.append(tl)
|
||||
|
||||
@staticmethod
|
||||
def _params(toks, i, end):
|
||||
"""`a: T, b: T` -> ['a','b'] (top-level commas only)."""
|
||||
names, depth, expect = [], 0, True
|
||||
while i < end:
|
||||
t = toks[i]
|
||||
if t.kind == TOK_PUNCT and t.val in "([{":
|
||||
depth += 1
|
||||
elif t.kind == TOK_PUNCT and t.val in ")]}":
|
||||
depth -= 1
|
||||
elif depth == 0 and t.kind == TOK_PUNCT and t.val == ",":
|
||||
expect = True
|
||||
elif depth == 0 and expect and t.kind == TOK_IDENT:
|
||||
names.append(t.val)
|
||||
expect = False
|
||||
i += 1
|
||||
return names
|
||||
|
||||
def func_at(self, rel, tok_index):
|
||||
for f in self.funcs_in(rel):
|
||||
if f.start <= tok_index < f.end:
|
||||
return f
|
||||
for f in self.toplevel:
|
||||
if f.path == rel:
|
||||
return f
|
||||
return None
|
||||
|
||||
def funcs_in(self, rel):
|
||||
for fl in self.funcs.values():
|
||||
for f in fl:
|
||||
if f.path == rel:
|
||||
yield f
|
||||
|
||||
# -- indexing -----------------------------------------------------------
|
||||
def index(self):
|
||||
for rel, toks in self.files.items():
|
||||
i = 0
|
||||
while i < len(toks):
|
||||
t = toks[i]
|
||||
if t.kind == TOK_IDENT and i + 1 < len(toks) and toks[i + 1].val == "(" \
|
||||
and t.val not in KEYWORDS \
|
||||
and not (i > 0 and toks[i - 1].kind == TOK_IDENT
|
||||
and toks[i - 1].val == "fn"):
|
||||
# ^ the `fn f(a: T)` declaration is not a call site; counting
|
||||
# it as one makes every parameter resolve to its own name
|
||||
# and reports the whole function UNRESOLVED.
|
||||
close = match_close(toks, i + 1, "(", ")")
|
||||
args = split_args(toks, i + 2, close)
|
||||
self.calls.setdefault(t.val, []).append(
|
||||
(self.func_at(rel, i), args, rel, t.line))
|
||||
if t.val in ("state_get", "state_set") and args:
|
||||
self.sites.append(Site(
|
||||
"get" if t.val == "state_get" else "set",
|
||||
rel, t.line, self.func_at(rel, i), args[0],
|
||||
render(toks, *args[0])))
|
||||
i += 1
|
||||
|
||||
# -- resolution ---------------------------------------------------------
|
||||
def lets_of(self, f):
|
||||
if f.lets is not None:
|
||||
return f.lets
|
||||
f.lets = {}
|
||||
toks = f.toks
|
||||
skip = getattr(f, "covered", [])
|
||||
i = f.start
|
||||
while i < f.end:
|
||||
if any(a <= i <= b for a, b in skip):
|
||||
i = max(b for a, b in skip if a <= i <= b) + 1
|
||||
continue
|
||||
t = toks[i]
|
||||
if t.kind == TOK_IDENT and t.val == "let" and i + 1 < f.end \
|
||||
and toks[i + 1].kind == TOK_IDENT:
|
||||
name = toks[i + 1].val
|
||||
j = i + 2
|
||||
if j < f.end and toks[j].val == ":": # skip the type
|
||||
while j < f.end and toks[j].val != "=":
|
||||
j += 1
|
||||
if j < f.end and toks[j].val == "=":
|
||||
s = j + 1
|
||||
e = stmt_end(toks, s, f.end)
|
||||
f.lets.setdefault(name, []).append((s, e))
|
||||
i = e
|
||||
continue
|
||||
i += 1
|
||||
return f.lets
|
||||
|
||||
def returns_of(self, ctx, depth=0, seen=None):
|
||||
"""The value expressions of a function, in the context it was CALLED in.
|
||||
|
||||
Context-sensitive on purpose. `conv_hist_key` is written as a guard:
|
||||
|
||||
if str_eq(session_id, "") { return "conv_history" }
|
||||
return "session_hist_" + session_id
|
||||
|
||||
Collecting both returns flat would make state_set(conv_hist_key("")) — the
|
||||
dead handle_chat() write — claim to produce the session_hist_ namespace
|
||||
too. That is a producer this engine does not actually have, and claiming
|
||||
it would let the gate stay green if sessions.el's real writer vanished:
|
||||
a masking hole in the exact namespace #129 lives in. So a guard whose
|
||||
condition folds is honoured, and the branch not taken is dropped."""
|
||||
out = []
|
||||
self._values(ctx.toks, ctx.start, ctx.end, ctx, depth,
|
||||
seen if seen is not None else set(), out)
|
||||
return out
|
||||
|
||||
def _values(self, toks, s, e, ctx, depth, seen, out):
|
||||
"""Append the value expressions of a statement sequence.
|
||||
Returns True when the sequence definitely returns (rest unreachable)."""
|
||||
if depth > MAX_DEPTH:
|
||||
return False
|
||||
i = s
|
||||
while i < e:
|
||||
t = toks[i]
|
||||
if t.kind == TOK_IDENT and t.val == "return":
|
||||
j = stmt_end(toks, i + 1, e)
|
||||
if j > i + 1:
|
||||
out.append((i + 1, j))
|
||||
return True
|
||||
if t.kind == TOK_IDENT and t.val == "let":
|
||||
i = stmt_end(toks, i + 2, e)
|
||||
continue
|
||||
if t.kind == TOK_IDENT and t.val == "if":
|
||||
i = self._if_stmt(toks, i, e, ctx, depth, seen, out)
|
||||
if i is True:
|
||||
return True
|
||||
continue
|
||||
if t.kind == TOK_PUNCT and t.val in "([{":
|
||||
i = match_close(toks, i, t.val,
|
||||
{"(": ")", "[": "]", "{": "}"}[t.val]) + 1
|
||||
continue
|
||||
en = stmt_end(toks, i, e)
|
||||
if en <= i:
|
||||
i += 1
|
||||
continue
|
||||
if en >= e: # trailing expression = the value
|
||||
out.append((i, en))
|
||||
i = en
|
||||
return False
|
||||
|
||||
def _if_stmt(self, toks, i, e, ctx, depth, seen, out):
|
||||
"""Walk one if / else-if / else chain. Returns the next index, or True
|
||||
if the chain definitely returns on every reachable branch."""
|
||||
bopen = i + 1
|
||||
while bopen < e and toks[bopen].val != "{":
|
||||
bopen += 1
|
||||
if bopen >= e:
|
||||
return e
|
||||
bclose = match_close(toks, bopen, "{", "}")
|
||||
fold = self._fold_cond(toks, i + 1, bopen, ctx, depth, seen)
|
||||
|
||||
j = bclose + 1
|
||||
else_s = else_e = None
|
||||
if j < e and toks[j].kind == TOK_IDENT and toks[j].val == "else":
|
||||
if j + 1 < e and toks[j + 1].val == "{":
|
||||
ec = match_close(toks, j + 1, "{", "}")
|
||||
else_s, else_e = j + 2, ec
|
||||
j = ec + 1
|
||||
else: # `else if ...` — the rest of the chain
|
||||
else_s = j + 1
|
||||
else_e = stmt_end(toks, j + 1, e)
|
||||
j = else_e
|
||||
|
||||
then_ret = else_ret = False
|
||||
if fold is not False:
|
||||
then_ret = self._values(toks, bopen + 1, bclose, ctx, depth + 1, seen, out)
|
||||
if fold is not True and else_s is not None:
|
||||
else_ret = self._values(toks, else_s, else_e, ctx, depth + 1, seen, out)
|
||||
|
||||
if fold is True and then_ret:
|
||||
return True
|
||||
if fold is False and else_s is not None and else_ret:
|
||||
return True
|
||||
if fold is None and else_s is not None and then_ret and else_ret:
|
||||
return True
|
||||
return j
|
||||
|
||||
def resolve(self, rng, func, depth=0, seen=None):
|
||||
"""-> (set of patterns, unresolved_flag)"""
|
||||
if seen is None:
|
||||
seen = set()
|
||||
if depth > MAX_DEPTH:
|
||||
return set(), True
|
||||
return self._expr(func.toks, rng[0], rng[1], func, depth, seen)
|
||||
|
||||
# -- expression walker --------------------------------------------------
|
||||
def _expr(self, toks, s, e, func, depth, seen):
|
||||
parts, cur, d = [], s, 0
|
||||
i = s
|
||||
while i < e: # split on top-level '+'
|
||||
v = toks[i].val
|
||||
if toks[i].kind == TOK_PUNCT and v in "([{":
|
||||
d += 1
|
||||
elif toks[i].kind == TOK_PUNCT and v in ")]}":
|
||||
d -= 1
|
||||
elif d == 0 and toks[i].kind == TOK_PUNCT and v == "+" and i > s:
|
||||
parts.append((cur, i))
|
||||
cur = i + 1
|
||||
i += 1
|
||||
parts.append((cur, e))
|
||||
if len(parts) == 1:
|
||||
return self._primary(toks, s, e, func, depth, seen)
|
||||
|
||||
# concatenation: keep folding while every operand so far is EXACT
|
||||
head, unres = "", False
|
||||
static = True
|
||||
for (ps, pe) in parts:
|
||||
pats, u = self._primary(toks, ps, pe, func, depth, seen)
|
||||
exacts = {p[1] for p in pats if p[0] == EXACT}
|
||||
if static and len(exacts) == 1 and not u and len(pats) == 1:
|
||||
head += exacts.pop()
|
||||
continue
|
||||
if static and pats and all(p[0] == EXACT for p in pats) and len(pats) > 1:
|
||||
# a branchy static operand: keep the shared head only
|
||||
static = False
|
||||
head += os.path.commonprefix(sorted({p[1] for p in pats}))
|
||||
break
|
||||
static = False
|
||||
# first non-static operand: everything after it is runtime text
|
||||
if (ps, pe) == parts[0]:
|
||||
for p in pats:
|
||||
if p[0] == PREFIX:
|
||||
head = p[1]
|
||||
break
|
||||
if not head:
|
||||
unres = True
|
||||
break
|
||||
if static:
|
||||
return {pat_exact(head)}, False
|
||||
p = pat_prefix(head)
|
||||
return ({p} if p else set()), (unres or not p)
|
||||
|
||||
def _primary(self, toks, s, e, func, depth, seen):
|
||||
while s < e and toks[s].kind == TOK_PUNCT and toks[s].val == "(" \
|
||||
and match_close(toks, s, "(", ")") == e - 1:
|
||||
s, e = s + 1, e - 1
|
||||
if s >= e:
|
||||
return set(), True
|
||||
t = toks[s]
|
||||
|
||||
if t.kind == TOK_STR and e == s + 1:
|
||||
return {pat_exact(t.val)}, False
|
||||
|
||||
if t.kind == TOK_IDENT and t.val == "if":
|
||||
return self._if_expr(toks, s, e, func, depth, seen)
|
||||
|
||||
if t.kind == TOK_IDENT and s + 1 < e and toks[s + 1].val == "(":
|
||||
close = match_close(toks, s + 1, "(", ")")
|
||||
if close == e - 1:
|
||||
return self._call(toks, t.val, split_args(toks, s + 2, close),
|
||||
func, depth, seen)
|
||||
|
||||
if t.kind == TOK_IDENT and e == s + 1:
|
||||
return self._var(t.val, func, depth, seen)
|
||||
|
||||
return set(), True
|
||||
|
||||
def _if_expr(self, toks, s, e, func, depth, seen):
|
||||
bopen = s + 1
|
||||
while bopen < e and toks[bopen].val != "{":
|
||||
bopen += 1
|
||||
cond = (s + 1, bopen)
|
||||
bclose = match_close(toks, bopen, "{", "}")
|
||||
then_rng = block_tail(toks, bopen + 1, bclose) or (bopen + 1, bclose)
|
||||
|
||||
else_rng = None
|
||||
j = bclose + 1
|
||||
if j < e and toks[j].kind == TOK_IDENT and toks[j].val == "else":
|
||||
if j + 1 < e and toks[j + 1].val == "{":
|
||||
ec = match_close(toks, j + 1, "{", "}")
|
||||
else_rng = block_tail(toks, j + 2, ec) or (j + 2, ec)
|
||||
else:
|
||||
else_rng = (j + 1, e) # `else if ...`
|
||||
|
||||
taken = self._fold_cond(toks, cond[0], cond[1], func, depth, seen)
|
||||
rngs = []
|
||||
if taken is not False:
|
||||
rngs.append(then_rng)
|
||||
if taken is not True and else_rng:
|
||||
rngs.append(else_rng)
|
||||
|
||||
pats, unres = set(), False
|
||||
for r in rngs:
|
||||
p, u = self._expr(toks, r[0], r[1], func, depth + 1, seen)
|
||||
pats |= p
|
||||
unres = unres or u
|
||||
return pats, unres
|
||||
|
||||
def _fold_cond(self, toks, s, e, func, depth, seen):
|
||||
"""Constant-fold `str_eq(X, "")` / `!str_eq(X, "")` so a helper called with
|
||||
a literal (conv_hist_key("")) yields only the branch it really takes.
|
||||
Returns True / False / None(unknown)."""
|
||||
neg = False
|
||||
if s < e and toks[s].kind == TOK_PUNCT and toks[s].val == "!":
|
||||
neg, s = True, s + 1
|
||||
if not (s < e and toks[s].kind == TOK_IDENT and toks[s].val == "str_eq"
|
||||
and s + 1 < e and toks[s + 1].val == "("):
|
||||
return None
|
||||
close = match_close(toks, s + 1, "(", ")")
|
||||
if close != e - 1:
|
||||
return None
|
||||
args = split_args(toks, s + 2, close)
|
||||
if len(args) != 2:
|
||||
return None
|
||||
va, ua = self._expr(toks, args[0][0], args[0][1], func, depth + 1, seen)
|
||||
vb, ub = self._expr(toks, args[1][0], args[1][1], func, depth + 1, seen)
|
||||
if ua or ub or len(va) != 1 or len(vb) != 1:
|
||||
return None
|
||||
(ka, sa), (kb, sb) = va.pop(), vb.pop()
|
||||
if ka != EXACT or kb != EXACT:
|
||||
return None
|
||||
r = (sa == sb)
|
||||
return (not r) if neg else r
|
||||
|
||||
def _call(self, toks, name, args, func, depth, seen):
|
||||
cands = self.funcs.get(name)
|
||||
if not cands:
|
||||
return set(), True # builtin: json_get, env, ...
|
||||
pats, unres = set(), False
|
||||
for callee in cands:
|
||||
key = ("fn", callee.path, callee.name, tuple(args))
|
||||
if key in seen:
|
||||
unres = True
|
||||
continue
|
||||
seen = seen | {key}
|
||||
# bind the callee's params to THIS call site's argument expressions
|
||||
binding = {}
|
||||
for idx, pname in enumerate(callee.params):
|
||||
if idx < len(args):
|
||||
binding[pname] = (args[idx], func)
|
||||
callee_ctx = _Bound(callee, binding)
|
||||
for r in self.returns_of(callee_ctx, depth + 1, seen):
|
||||
p, u = self._expr(callee.toks, r[0], r[1], callee_ctx,
|
||||
depth + 1, seen)
|
||||
pats |= p
|
||||
unres = unres or u
|
||||
return pats, unres
|
||||
|
||||
def _var(self, name, func, depth, seen):
|
||||
real = func.func if isinstance(func, _Bound) else func
|
||||
|
||||
# 1. a parameter bound by the call site we came through
|
||||
if isinstance(func, _Bound) and name in func.binding:
|
||||
rng, caller_ctx = func.binding[name]
|
||||
return self._expr(caller_ctx.toks, rng[0], rng[1], caller_ctx,
|
||||
depth + 1, seen)
|
||||
|
||||
# 2. a local `let` in the enclosing function
|
||||
lets = self.lets_of(real)
|
||||
if name in lets:
|
||||
key = ("let", real.path, real.name, name)
|
||||
if key in seen:
|
||||
return set(), True
|
||||
seen = seen | {key}
|
||||
pats, unres = set(), False
|
||||
for rng in lets[name]:
|
||||
p, u = self._expr(real.toks, rng[0], rng[1], real, depth + 1, seen)
|
||||
pats |= p
|
||||
unres = unres or u
|
||||
return pats, unres
|
||||
|
||||
# 3. an unbound parameter -> look at every call site of the enclosing fn
|
||||
if name in real.params:
|
||||
key = ("param", real.path, real.name, name)
|
||||
if key in seen:
|
||||
return set(), True
|
||||
seen = seen | {key}
|
||||
idx = real.params.index(name)
|
||||
pats, unres = set(), False
|
||||
sites = self.calls.get(real.name, [])
|
||||
if not sites:
|
||||
return set(), True
|
||||
for caller, args, _rel, _line in sites:
|
||||
if caller is None or idx >= len(args):
|
||||
unres = True
|
||||
continue
|
||||
p, u = self._expr(caller.toks, args[idx][0], args[idx][1],
|
||||
caller, depth + 1, seen)
|
||||
pats |= p
|
||||
unres = unres or u
|
||||
return pats, unres
|
||||
|
||||
# 4. a file-level / cross-file top-level `let`
|
||||
for tl in self.toplevel:
|
||||
lets = self.lets_of(tl)
|
||||
if name in lets:
|
||||
key = ("let", tl.path, tl.name, name)
|
||||
if key in seen:
|
||||
return set(), True
|
||||
seen2 = seen | {key}
|
||||
pats, unres = set(), False
|
||||
for rng in lets[name]:
|
||||
p, u = self._expr(tl.toks, rng[0], rng[1], tl, depth + 1, seen2)
|
||||
pats |= p
|
||||
unres = unres or u
|
||||
return pats, unres
|
||||
|
||||
return set(), True
|
||||
|
||||
|
||||
class _Bound:
|
||||
"""A callee view that also knows what its params were called with."""
|
||||
|
||||
def __init__(self, func, binding):
|
||||
self.func, self.binding = func, binding
|
||||
self.toks, self.start, self.end = func.toks, func.start, func.end
|
||||
self.params, self.path, self.name = func.params, func.path, func.name
|
||||
|
||||
def __getattr__(self, k):
|
||||
return getattr(self.func, k)
|
||||
|
||||
|
||||
# ── token helpers ───────────────────────────────────────────────────────────
|
||||
def split_args(toks, s, e):
|
||||
out, cur, d = [], s, 0
|
||||
i = s
|
||||
while i < e:
|
||||
v = toks[i].val
|
||||
if toks[i].kind == TOK_PUNCT and v in "([{":
|
||||
d += 1
|
||||
elif toks[i].kind == TOK_PUNCT and v in ")]}":
|
||||
d -= 1
|
||||
elif d == 0 and toks[i].kind == TOK_PUNCT and v == ",":
|
||||
out.append((cur, i))
|
||||
cur = i + 1
|
||||
i += 1
|
||||
if cur < e:
|
||||
out.append((cur, e))
|
||||
return out
|
||||
|
||||
|
||||
STMT_START = {"let", "return", "if", "while", "for"}
|
||||
KEYWORDS = {"if", "while", "for", "return", "fn", "let", "else", "match"}
|
||||
|
||||
|
||||
def stmt_end(toks, s, limit):
|
||||
"""End of the expression starting at s: the next top-level statement
|
||||
boundary. El has no semicolons, so a newline that starts a new statement
|
||||
ends this one."""
|
||||
d, i = 0, s
|
||||
while i < limit:
|
||||
t = toks[i]
|
||||
if t.kind == TOK_PUNCT and t.val in "([":
|
||||
d += 1
|
||||
elif t.kind == TOK_PUNCT and t.val in ")]":
|
||||
d -= 1
|
||||
if d < 0:
|
||||
return i
|
||||
elif t.kind == TOK_PUNCT and t.val == "{":
|
||||
# a brace at depth 0 belongs to this expression only when it is an
|
||||
# if/else block that is part of it
|
||||
d += 1
|
||||
elif t.kind == TOK_PUNCT and t.val == "}":
|
||||
d -= 1
|
||||
if d < 0:
|
||||
return i
|
||||
elif d == 0 and t.kind == TOK_PUNCT and t.val == ",":
|
||||
return i
|
||||
elif d == 0 and i > s and t.kind == TOK_IDENT and t.val in STMT_START:
|
||||
if t.val == "if" and toks[i - 1].kind == TOK_IDENT and toks[i - 1].val == "else":
|
||||
i += 1
|
||||
continue
|
||||
return i
|
||||
elif d == 0 and i > s and t.kind == TOK_IDENT and t.val == "fn":
|
||||
return i
|
||||
i += 1
|
||||
return limit
|
||||
|
||||
|
||||
def block_tail(toks, s, e):
|
||||
"""The trailing expression of a block, if the block ends in one."""
|
||||
i, last = s, None
|
||||
while i < e:
|
||||
t = toks[i]
|
||||
if t.kind == TOK_IDENT and t.val in ("let", "return"):
|
||||
i = stmt_end(toks, i + 1, e)
|
||||
last = None
|
||||
continue
|
||||
if t.kind == TOK_PUNCT and t.val in "([{":
|
||||
i = match_close(toks, i, t.val, {"(": ")", "[": "]", "{": "}"}[t.val]) + 1
|
||||
continue
|
||||
st = i
|
||||
en = stmt_end(toks, i, e)
|
||||
if en <= st:
|
||||
i = st + 1
|
||||
continue
|
||||
last = (st, en)
|
||||
i = en
|
||||
return last
|
||||
|
||||
|
||||
def render(toks, s, e):
|
||||
out = []
|
||||
for t in toks[s:e]:
|
||||
out.append('"%s"' % t.val if t.kind == TOK_STR else t.val)
|
||||
return " ".join(out)
|
||||
|
||||
|
||||
# ── the gate ────────────────────────────────────────────────────────────────
|
||||
def collect(root, include_tests):
|
||||
files = []
|
||||
for dirpath, dirnames, filenames in os.walk(root):
|
||||
dirnames[:] = [d for d in dirnames
|
||||
if d not in ("dist", "vendor", ".git", "node_modules")]
|
||||
rel_dir = os.path.relpath(dirpath, root)
|
||||
if not include_tests and rel_dir.split(os.sep)[0] == "tests":
|
||||
continue
|
||||
for fn in sorted(filenames):
|
||||
if fn.endswith(".el"):
|
||||
rel = os.path.normpath(os.path.join(rel_dir, fn))
|
||||
files.append((os.path.join(dirpath, fn), rel))
|
||||
return sorted(files, key=lambda x: x[1])
|
||||
|
||||
|
||||
def is_bare_literal(prog, site):
|
||||
toks = prog.files[site.path]
|
||||
s, e = site.arg_range
|
||||
return e == s + 1 and toks[s].kind == TOK_STR
|
||||
|
||||
|
||||
def read_decl(path):
|
||||
"""A declaration file: one entry per line, `# ...` comments stripped."""
|
||||
out = []
|
||||
if not path or not os.path.exists(path):
|
||||
return out
|
||||
with open(path) as fh:
|
||||
for ln in fh:
|
||||
ln = ln.split("#", 1)[0].strip()
|
||||
if ln:
|
||||
out.append(ln)
|
||||
return out
|
||||
|
||||
|
||||
def opt(argv, name, default=None):
|
||||
for i, a in enumerate(argv):
|
||||
if a == name and i + 1 < len(argv):
|
||||
return argv[i + 1]
|
||||
return default
|
||||
|
||||
|
||||
def main(argv):
|
||||
root = os.path.abspath(argv[1]) if len(argv) > 1 and not argv[1].startswith("-") else "."
|
||||
include_tests = "--include-tests" in argv
|
||||
verbose = "--verbose" in argv
|
||||
baseline_path = opt(argv, "--baseline")
|
||||
external_path = opt(argv, "--external")
|
||||
|
||||
prog = Program()
|
||||
for path, rel in collect(root, include_tests):
|
||||
prog.load(path, rel)
|
||||
prog.index()
|
||||
for site in prog.sites:
|
||||
pats, unres = prog.resolve(site.arg_range, site.func)
|
||||
site.pats, site.unresolved = {p for p in pats if p}, unres
|
||||
if is_bare_literal(prog, site):
|
||||
site.literal = prog.files[site.path][site.arg_range[0]].val
|
||||
|
||||
writes = [s for s in prog.sites if s.kind == "set"]
|
||||
reads = [s for s in prog.sites if s.kind == "get"]
|
||||
write_pats = set()
|
||||
for w in writes:
|
||||
write_pats |= w.pats
|
||||
|
||||
# Declared host-set keys: written by something outside the El tree (an
|
||||
# operator, the installer, a host process). Each entry must carry a reason.
|
||||
external = []
|
||||
for ln in read_decl(external_path):
|
||||
parts = ln.split(None, 1)
|
||||
if len(parts) != 2 or parts[0] not in (EXACT, PREFIX):
|
||||
print("bad --external line (want `exact|prefix <key>`): %r" % ln,
|
||||
file=sys.stderr)
|
||||
return 2
|
||||
external.append((parts[0], parts[1]))
|
||||
write_pats |= set(external)
|
||||
|
||||
# F1 — a read of a key no write in the tree produces.
|
||||
f1 = []
|
||||
for r in reads:
|
||||
for p in sorted(r.pats):
|
||||
if not any(covers(w, p) for w in write_pats):
|
||||
f1.append((r, p))
|
||||
|
||||
# F2 — a key namespace owned by a helper, accessed by a hand-rolled literal.
|
||||
# This is the #129 shape: the producer moved behind conv_hist_key() and
|
||||
# one consumer kept spelling the old key out by hand.
|
||||
owners = {} # helper fn name -> its value set
|
||||
for s in prog.sites:
|
||||
toks = prog.files[s.path]
|
||||
a, b = s.arg_range
|
||||
if toks[a].kind == TOK_IDENT and a + 1 < b and toks[a + 1].val == "(" \
|
||||
and match_close(toks, a + 1, "(", ")") == b - 1 \
|
||||
and toks[a].val in prog.funcs:
|
||||
name = toks[a].val
|
||||
if name not in owners:
|
||||
vals = set()
|
||||
for callee in prog.funcs[name]:
|
||||
# No call context here on purpose: the OWNED namespace is
|
||||
# every key the helper can ever produce, over all call sites.
|
||||
for rng in prog.returns_of(callee):
|
||||
p, _ = prog._expr(callee.toks, rng[0], rng[1], callee, 0, set())
|
||||
vals |= {x for x in p if x}
|
||||
owners[name] = vals
|
||||
f2 = []
|
||||
for s in prog.sites:
|
||||
if s.literal is None:
|
||||
continue
|
||||
for owner, vals in sorted(owners.items()):
|
||||
for v in sorted(vals):
|
||||
if covers(v, pat_exact(s.literal)):
|
||||
f2.append((s, owner, v))
|
||||
break
|
||||
else:
|
||||
continue
|
||||
break
|
||||
|
||||
unresolved = [s for s in prog.sites if s.unresolved or not s.pats]
|
||||
|
||||
# Baseline signatures carry NO line number on purpose: an unrelated edit that
|
||||
# shifts a line must not un-mute an accepted finding (that is crying wolf),
|
||||
# but a GROWTH in count must not hide either. So a baseline entry is
|
||||
# `<file> <CODE> <detail> [xN]` and only the first N matches are muted.
|
||||
baseline, bad_baseline = {}, []
|
||||
for ln in read_decl(baseline_path):
|
||||
n, key = 1, ln
|
||||
parts = ln.rsplit(" x", 1)
|
||||
if len(parts) == 2 and parts[1].isdigit():
|
||||
key, n = parts[0].strip(), int(parts[1])
|
||||
baseline[key] = n
|
||||
|
||||
def sig(path, code, detail):
|
||||
return "%s %s %s" % (path, code, detail)
|
||||
|
||||
findings = []
|
||||
for r, p in f1:
|
||||
findings.append((sig(r.path, "DEAD-READ", "%s:%s" % p), r.line,
|
||||
" %s:%d state_get(%s)\n resolves to %s %r — no state_set in the tree produces it"
|
||||
% (r.path, r.line, r.text, p[0].upper(), p[1])))
|
||||
for s, owner, v in f2:
|
||||
findings.append((sig(s.path, "HAND-ROLLED", "%s<-%s()" % (s.literal, owner)), s.line,
|
||||
" %s:%d state_%s(\"%s\")\n %s() owns this key namespace (%s %r) — go through the helper, "
|
||||
"or a rename orphans this site silently" % (s.path, s.line, s.kind, s.literal, owner, v[0].upper(), v[1])))
|
||||
findings.sort(key=lambda f: (f[0], f[1]))
|
||||
|
||||
live, muted, budget = [], [], dict(baseline)
|
||||
for f in findings:
|
||||
if budget.get(f[0], 0) > 0:
|
||||
budget[f[0]] -= 1
|
||||
muted.append(f)
|
||||
else:
|
||||
live.append(f)
|
||||
stale = sorted(k for k, v in budget.items() if v > 0)
|
||||
|
||||
print("── state-key audit ─────────────────────────────────────────────")
|
||||
print("scanned %d .el files%s" % (len(prog.files),
|
||||
"" if include_tests else " (tests/ excluded)"))
|
||||
print("sites %d state_set, %d state_get" % (len(writes), len(reads)))
|
||||
print("keys %d distinct write patterns" % len(write_pats))
|
||||
print("")
|
||||
|
||||
if verbose:
|
||||
print("WRITE PATTERNS")
|
||||
for k, v in sorted(write_pats):
|
||||
print(" %-6s %s" % (k, v))
|
||||
print("")
|
||||
|
||||
if external:
|
||||
print("DECLARED HOST-SET (%d) — %s" % (len(external), external_path))
|
||||
for k, v in sorted(external):
|
||||
print(" %-6s %s" % (k, v))
|
||||
print("")
|
||||
|
||||
print("UNRESOLVED (%d) — reported, never fails the build" % len(unresolved))
|
||||
if not unresolved:
|
||||
print(" (none)")
|
||||
for s in sorted(unresolved, key=lambda x: (x.path, x.line)):
|
||||
print(" %s:%d state_%s(%s)%s"
|
||||
% (s.path, s.line, s.kind, s.text,
|
||||
" [partial: %s]" % ", ".join("%s %r" % p for p in sorted(s.pats))
|
||||
if s.pats else ""))
|
||||
print("")
|
||||
|
||||
if muted:
|
||||
print("BASELINED (%d) — pre-existing debt accepted in %s. NOT clean; fix these."
|
||||
% (len(muted), baseline_path))
|
||||
for sg, line, _ in muted:
|
||||
print(" %s (line %d)" % (sg, line))
|
||||
print("")
|
||||
if stale:
|
||||
print("STALE BASELINE (%d) — entries that no longer match anything; delete them:"
|
||||
% len(stale))
|
||||
for sg in stale:
|
||||
print(" %s" % sg)
|
||||
print("")
|
||||
|
||||
print("FINDINGS (%d)" % len(live))
|
||||
if not live:
|
||||
print(" (none)")
|
||||
for _, _, body in live:
|
||||
print(body)
|
||||
print("")
|
||||
|
||||
if live:
|
||||
print("FAIL: %d state-key finding(s). See scripts/verify-state-keys.sh "
|
||||
"for why this gate exists (issue #129)." % len(live))
|
||||
return 1
|
||||
print("PASS: every resolvable state_get key has a producer, and no key "
|
||||
"namespace is spelled two ways.")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main(sys.argv))
|
||||
@@ -1,28 +0,0 @@
|
||||
# state-key-baseline.txt — findings that already existed when this gate landed
|
||||
# (2026-08-07). Each one is a REAL defect of the #129 class, not a false
|
||||
# positive. They are muted only so the gate can be turned on today instead of
|
||||
# being deferred until the debt is paid; every run still prints them under
|
||||
# BASELINED with the word "debt".
|
||||
#
|
||||
# THIS FILE SHOULD ONLY EVER SHRINK. Adding a line means you are shipping a
|
||||
# known silent-"" read. If you must, date it and say why in the comment.
|
||||
#
|
||||
# format: <file> <CODE> <detail> [xN] # N = how many sites are accepted
|
||||
# No line numbers on purpose: an unrelated edit must not un-mute an accepted
|
||||
# finding, but a GROWTH in count is NOT muted — the extra site fails the build.
|
||||
#
|
||||
chat.el DEAD-READ exact:soul_identity x5
|
||||
# ^ soul.el used to run `state_set("soul_identity", soul_identity)`. It was
|
||||
# deleted on 2026-05-13 in b163fa6 ("feat(awareness): route ISE writes to HTTP
|
||||
# Engram ..."), a commit about something else entirely, and the five readers in
|
||||
# chat.el were left behind. Since that date build_system_prompt (737), the
|
||||
# vision handler (1745), the agentic system prompt (2620), the council
|
||||
# transcript handler (3425) and 3480 have all been prefixing "" — exactly the
|
||||
# #129 shape, found by this gate on its first run. Sites: 737, 1745, 2620,
|
||||
# 3425, 3480. Fix = restore the boot-time write or delete the reads; not done
|
||||
# here because this branch must not change engine behaviour.
|
||||
|
||||
studio.el DEAD-READ exact:soul_principal x1
|
||||
# ^ studio.el:57 dharma_registry() emits "principal":"" on every call — no
|
||||
# producer has ever existed in the tree's history (git log -S finds none).
|
||||
# Never-wired rather than orphaned, same silent-"" result.
|
||||
@@ -1,16 +0,0 @@
|
||||
# state-key-external.txt — state keys the engine READS but deliberately never
|
||||
# WRITES, because a host outside the El tree sets them (an operator, the
|
||||
# installer, a deployment env). Read scripts/verify-state-keys.sh for why this
|
||||
# list has to exist and why it has to stay short.
|
||||
#
|
||||
# THE RULE FOR ADDING A LINE: the read site must already treat "" as a defined
|
||||
# default (`if str_eq(x, "") { <default> }`) AND the source must say so in a
|
||||
# comment. "I could not find the writer" is NOT a reason — that is the #129
|
||||
# defect, and it belongs in state-key-baseline.txt with a date, not here.
|
||||
#
|
||||
# format: exact|prefix <key> # why, and where the source says so
|
||||
#
|
||||
exact soul_rate_limit # routes.el:59-61 — "configurable via soul state key ... Falls back to 60 req/min if not set."
|
||||
exact web_search_tool_version # chat.el:1884-1910 — version lives in state "so a future bump is a config write, not a recompile"; defaults to web_search_20250305
|
||||
exact platform_auth # stewardship.el:92 — host-set capability flag; fail-CLOSED (anything but "true" denies the platform tool)
|
||||
exact security_research_authorized # awareness.el:991-996 — state override for env SECURITY_RESEARCH_TOKEN; fail-closed, defaults false
|
||||
@@ -1,118 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
# verify-state-keys.sh — the state-key gate. Retires a defect class at build time.
|
||||
#
|
||||
# ── WHY THIS EXISTS. DO NOT DELETE IT AS NOISE. ──────────────────────────────
|
||||
#
|
||||
# The engine keeps runtime values in a key-value store: state_set("k", v) writes,
|
||||
# state_get("k") reads. A read of a key that NOTHING writes returns an empty
|
||||
# string. Silently. No error, no warning, no log line. The El compiler cannot see
|
||||
# it, no test sees it, and the product keeps running — just with a hole in it.
|
||||
#
|
||||
# That is how issue #129 happened. ff421d3 (2026-08-05) correctly moved
|
||||
# conversation history to a per-session key behind conv_hist_key(session_id). One
|
||||
# consumer did not move with it: the agentic path's L1 safety screen kept reading
|
||||
# the old anonymous "conv_history" bucket. The desktop app always mints a session
|
||||
# id, so history was always written under session_hist_<id> and that read always
|
||||
# returned "". The half of the crisis score that receives history is the
|
||||
# ESCALATION half — the one that exists for distress building across several
|
||||
# turns, where no single message trips the bell on its own. It scored 0 on every
|
||||
# real conversation for two days, and nothing failed.
|
||||
#
|
||||
# The line that broke carried a comment describing this exact bug being fixed
|
||||
# once already, under issue #9. A comment is not a gate. This is the gate.
|
||||
#
|
||||
# ── WHAT IT CHECKS ──────────────────────────────────────────────────────────
|
||||
#
|
||||
# DEAD-READ a state_get whose key resolves to something no state_set in the
|
||||
# tree produces. The direct form of the class.
|
||||
#
|
||||
# HAND-ROLLED a state_get/state_set that spells out a literal belonging to a
|
||||
# key namespace a helper function owns (e.g. "conv_history", owned
|
||||
# by conv_hist_key()). This is #129's actual shape: the producer
|
||||
# moved behind the helper and one consumer kept the old spelling
|
||||
# by hand. DEAD-READ alone does NOT catch #129, because the dead
|
||||
# handle_chat() still writes that key through the helper — so this
|
||||
# second check is the one that earns the gate its keep.
|
||||
#
|
||||
# ── WHY IT DOES NOT CRY WOLF ────────────────────────────────────────────────
|
||||
#
|
||||
# Keys are usually COMPUTED, not literal, so a naive grep would flood and get
|
||||
# switched off within a day. scripts/state-key-audit.py resolves computed keys:
|
||||
# string concatenation (matched on the static prefix), helper functions (resolved
|
||||
# to their possible return values), keys built into a local variable, and keys
|
||||
# arriving as a function parameter (resolved through the call sites). Where a key
|
||||
# genuinely cannot be resolved it is printed under UNRESOLVED and does NOT fail
|
||||
# the build — visible, never silently ignored. Keep that list short.
|
||||
#
|
||||
# On this tree it resolves 278 of 278 sites: UNRESOLVED is 0 and FINDINGS is 0.
|
||||
#
|
||||
# Two declaration files, both of which should only ever shrink:
|
||||
# scripts/state-key-external.txt keys a host outside the El tree writes
|
||||
# scripts/state-key-baseline.txt findings that predate the gate (real debt)
|
||||
#
|
||||
# ── PROVEN TO DISCRIMINATE (2026-08-07) ─────────────────────────────────────
|
||||
#
|
||||
# 1. Synthetic: a scratch copy of this tree with agentic_safety_screen reverted
|
||||
# to the pre-fix state_get("conv_history") — ONE line, nothing else — FAILS
|
||||
# with `chat.el:2536 ... conv_hist_key() owns this key namespace`. The tree
|
||||
# as shipped PASSES. One variable, opposite verdicts.
|
||||
# 2. Independent: run read-only against origin/feat/soul-openai-tools-v2, which
|
||||
# carries the same defect on its own, the gate reported chat.el:2937 — the
|
||||
# exact line 43d0449's commit message had named by hand. Against that
|
||||
# branch's fix (origin/fix/129-on-openai-tools) it passes.
|
||||
# 3. Producer-moved controls: renaming the sole writer of an EXACT key
|
||||
# (soul_model) orphans 3 readers across 3 files; renaming the sole writer of
|
||||
# a PREFIX namespace (agent_workspace_root_*) orphans 3 readers — including
|
||||
# when the producer moves to a NARROWER namespace, which an earlier,
|
||||
# sloppier prefix rule let through.
|
||||
#
|
||||
# It also found, on its first run, a defect nobody was looking for: soul.el's
|
||||
# `state_set("soul_identity", ...)` was deleted on 2026-05-13 in b163fa6 (a
|
||||
# commit about awareness/ISE writes) and five readers in chat.el were left
|
||||
# behind — the system prompt, the vision handler, the agentic prompt and the
|
||||
# council handler have been prefixing "" ever since. See state-key-baseline.txt.
|
||||
#
|
||||
# ── SAFETY ──────────────────────────────────────────────────────────────────
|
||||
# Pure static read of .el sources. Starts nothing, opens no port, touches no
|
||||
# daemon, and never reads or writes ~/.neuron.
|
||||
#
|
||||
# ── USAGE ───────────────────────────────────────────────────────────────────
|
||||
# scripts/verify-state-keys.sh gate the repo (honours baseline)
|
||||
# scripts/verify-state-keys.sh --strict ignore the baseline: show the debt
|
||||
# scripts/verify-state-keys.sh --verbose also dump every write pattern
|
||||
# scripts/verify-state-keys.sh --root DIR audit a different tree
|
||||
# exit 0 = clean; 1 = finding(s); 2 = the gate itself could not run.
|
||||
set -uo pipefail
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd)"
|
||||
STRICT=0
|
||||
PASS_THROUGH=()
|
||||
|
||||
while [ $# -gt 0 ]; do
|
||||
case "$1" in
|
||||
--strict) STRICT=1; shift ;;
|
||||
--root) ROOT="${2:?--root needs a directory}"; shift 2 ;;
|
||||
-h|--help) awk 'NR>1 && /^#/ {print; next} NR>1 {exit}' "${BASH_SOURCE[0]}"; exit 0 ;;
|
||||
*) PASS_THROUGH+=("$1"); shift ;;
|
||||
esac
|
||||
done
|
||||
|
||||
command -v python3 >/dev/null 2>&1 || {
|
||||
echo "[state-keys] CANNOT RUN: python3 not found" >&2; exit 2; }
|
||||
[ -d "$ROOT" ] || { echo "[state-keys] CANNOT RUN: no such tree: $ROOT" >&2; exit 2; }
|
||||
|
||||
AUDIT="$SCRIPT_DIR/state-key-audit.py"
|
||||
[ -f "$AUDIT" ] || { echo "[state-keys] CANNOT RUN: missing $AUDIT" >&2; exit 2; }
|
||||
|
||||
ARGS=("$ROOT" "--external" "$SCRIPT_DIR/state-key-external.txt")
|
||||
[ "$STRICT" -eq 0 ] && ARGS+=("--baseline" "$SCRIPT_DIR/state-key-baseline.txt")
|
||||
[ ${#PASS_THROUGH[@]} -gt 0 ] && ARGS+=("${PASS_THROUGH[@]}")
|
||||
|
||||
python3 "$AUDIT" "${ARGS[@]}"
|
||||
RC=$?
|
||||
if [ "$RC" -gt 1 ]; then
|
||||
echo "[state-keys] CANNOT RUN: the audit itself failed (exit $RC)" >&2
|
||||
exit 2
|
||||
fi
|
||||
exit "$RC"
|
||||
@@ -559,6 +559,27 @@ let axon_base: String = if str_eq(axon_raw, "") { "http://localhost:7771" } else
|
||||
let studio_dir_raw: String = env("SOUL_STUDIO_DIR")
|
||||
let studio_dir: String = if str_eq(studio_dir_raw, "") { env("HOME") + "/Development/neuron-technologies/products/cgi-studio/el-daemon" } else { studio_dir_raw }
|
||||
|
||||
// RESTORED 2026-08-09 — this producer was added 2026-05-02 in 601e0fe and deleted
|
||||
// by the awareness refactor b163fa6 a few days later. Nothing has written
|
||||
// soul_identity since, while FIVE sites in chat.el kept reading it:
|
||||
// chat.el:737, 1745, 2620, 3425, 3480 — each doing state_get("soul_identity")
|
||||
// and splicing the result into the system prompt beside the voice, security and
|
||||
// capability rules. They have been splicing an EMPTY STRING for roughly three
|
||||
// months. The identity section of every chat turn was blank and nothing said so.
|
||||
//
|
||||
// Found by the #132 state-key gate, which reports a read with no producer as a
|
||||
// build error rather than a silence — the whole reason that gate exists.
|
||||
//
|
||||
// Restored verbatim rather than improved: this key is an env-configurable persona
|
||||
// LINE, which is NOT the same thing as soul_identity_context (the graph-derived
|
||||
// [INTELLECTUAL-DNA]/[VALUES]/[MEMORY-PHILOSOPHY] block written at soul.el:184).
|
||||
// Pointing these five reads at that block instead would have substituted different
|
||||
// content and called it a fix. Whether the chat system prompt should ALSO carry the
|
||||
// graph-derived block is a real question, and a separate one.
|
||||
let identity_raw: String = env("SOUL_IDENTITY")
|
||||
let soul_identity: String = if str_eq(identity_raw, "") { "You are " + soul_cgi_id + ", a CGI." } else { identity_raw }
|
||||
state_set("soul_identity", soul_identity)
|
||||
|
||||
println("[soul] boot - cgi=" + soul_cgi_id + " port=" + int_to_str(port))
|
||||
|
||||
let using_http_engram: Bool = !str_eq(engram_url_raw, "")
|
||||
|
||||
@@ -53,8 +53,23 @@ fn handle_config(method: String, body: String) -> String {
|
||||
}
|
||||
|
||||
fn dharma_registry() -> String {
|
||||
// COMPILED IDENTITY, not state (2026-08-09). soul_principal had no producer at
|
||||
// all — the #132 gate flagged it as a dead read and the registry reported an
|
||||
// empty principal under a heading that says "Principal Covenant v1". The value
|
||||
// was never missing: it is declared in soul.el's cgi block, and as of the
|
||||
// codegen fix it is compiled into the binary and loaded at startup.
|
||||
//
|
||||
// Read it from the compiled constant rather than the state store. The design is
|
||||
// explicit that this identity is "not modifiable by any runtime mechanism
|
||||
// including environment variables, configuration files, or API calls" — so
|
||||
// publishing it into state (the cheap fix) would have recreated exactly the
|
||||
// mutable copy it forbids. cgi_principal() is read-only and has no setter.
|
||||
//
|
||||
// cgi_id keeps its state read deliberately: the RUNTIME instance id is a
|
||||
// different fact from the compiled dharma_id, and conflating them would hide
|
||||
// the case where a binary runs under an id its declaration never claimed.
|
||||
let cgi_id: String = state_get("soul_cgi_id")
|
||||
let principal: String = state_get("soul_principal")
|
||||
let principal: String = cgi_principal()
|
||||
return "{\"registry\":[{\"cgi\":\"" + cgi_id + "\","
|
||||
+ "\"principal\":\"" + principal + "\","
|
||||
+ "\"covenant\":\"Principal Covenant v1\","
|
||||
|
||||
@@ -30,9 +30,19 @@ AMALGAM="$ROOT/dist/soul.c"
|
||||
|
||||
# Every .el at the repo root is an input to the amalgam. Sorted so the hash is
|
||||
# order-independent; content-only so timestamps and checkouts do not perturb it.
|
||||
# The COMPILER is an input too. Learned 2026-08-09 by installing a fixed elc and
|
||||
# watching this gate report OK while the committed amalgam had gone stale by a line:
|
||||
# the sources had not changed, so a source-only fingerprint could not see it. That is
|
||||
# precisely the blind spot this gate exists to close, and it had it.
|
||||
fingerprint() {
|
||||
(
|
||||
cd "$ROOT" || exit 1
|
||||
ELC_BIN="${ELC:-$HOME/neuron-dev-stack/src/el/lang/dist/platform/elc}"
|
||||
if [ -f "$ELC_BIN" ]; then
|
||||
printf '%s %s\n' "$(shasum -a 256 "$ELC_BIN" | awk '{print $1}')" "__compiler__"
|
||||
else
|
||||
printf '%s %s\n' "MISSING" "__compiler__"
|
||||
fi
|
||||
for f in $(ls -1 *.el 2>/dev/null | sort); do
|
||||
printf '%s %s\n' "$(shasum -a 256 "$f" | awk '{print $1}')" "$f"
|
||||
done
|
||||
|
||||
+19
@@ -5634,6 +5634,25 @@ void el_cgi_init(el_val_t name, el_val_t dharma_id, el_val_t principal,
|
||||
}
|
||||
|
||||
|
||||
/* ── Compiled-identity accessors (2026-08-09) ─────────────────────────────────
|
||||
* el_cgi_init loads the declaration into these globals at startup and printed
|
||||
* them, and NOTHING read them back out — no accessor existed, and el_cgi_init
|
||||
* writes no state. So a binary carried its declared identity and every consumer
|
||||
* still read it from the mutable state store, which is exactly what IDPROTO
|
||||
* claims 1-2 forbid ("not modifiable by any runtime mechanism including
|
||||
* environment variables, configuration files, or API calls").
|
||||
*
|
||||
* These are READ-ONLY on purpose. There is deliberately no setter: publishing
|
||||
* the values into the state store would have been one line and would have
|
||||
* recreated the mutable copy the design prohibits. A caller can read the
|
||||
* compiled identity; nothing can change it after el_cgi_init.
|
||||
*/
|
||||
el_val_t cgi_name(void) { return EL_STR(_el_cgi_name ? _el_cgi_name : ""); }
|
||||
el_val_t cgi_dharma_id(void) { return EL_STR(_el_cgi_dharma_id ? _el_cgi_dharma_id : ""); }
|
||||
el_val_t cgi_principal(void) { return EL_STR(_el_cgi_principal ? _el_cgi_principal : ""); }
|
||||
el_val_t cgi_network(void) { return EL_STR(_el_cgi_network ? _el_cgi_network : ""); }
|
||||
el_val_t cgi_engram(void) { return EL_STR(_el_cgi_engram ? _el_cgi_engram : ""); }
|
||||
|
||||
/* ── Batch 3: Engram in-process graph store ──────────────────────────────── */
|
||||
/*
|
||||
* Single global EngramStore allocated lazily on first call. All node and
|
||||
|
||||
@@ -782,6 +782,14 @@ el_val_t trace_span_start(el_val_t name);
|
||||
el_val_t trace_span_end(el_val_t span_handle);
|
||||
el_val_t emit_event(el_val_t name, el_val_t duration_ms);
|
||||
|
||||
/* Compiled-identity accessors — read-only by design (2026-08-09). */
|
||||
el_val_t cgi_name(void);
|
||||
el_val_t cgi_dharma_id(void);
|
||||
el_val_t cgi_principal(void);
|
||||
el_val_t cgi_network(void);
|
||||
el_val_t cgi_engram(void);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
|
||||
#endif
|
||||
|
||||
Reference in New Issue
Block a user