Skip to content

Add DSH-derived adapter admission discipline and egress tripwire - #38

Merged
hsliuustc0106 merged 2 commits into
mainfrom
docs/dsh-adapter-discipline
Oct 3, 2026
Merged

hsliuustc0106 merged 2 commits into
mainfrom
docs/dsh-adapter-discipline

Conversation

@hsliuustc0106

Copy link
Copy Markdown
Contributor

What

  • docs/design/adapter-seam.md: new Adapter admission discipline section — four rules adapted from DeepSeek Harness (DSH)'s plugin discipline, adopting the discipline without the machinery:

    1. declared at boot, validated before task state is touched;
    2. registrations are effects — reverse-order disposers on shutdown (tracked in Runner registrations as effects: reverse-order disposers for shutdown #37);
    3. provider-visible implies activity-logged;
    4. typed errors across the seam, no prose matching, no string passthrough.

    Also sharpens the rule 3 trigger: swappability alone never justifies machinery (the fakes already substitute every port); the machinery-grade trigger is a second party extending nanodot without forking it.

  • tests/test_inference.py: egress tripwire — every provider-visible StateChange must be reconstructable from the activity log via state_change_from_event, and the StateChange surface must stay exactly SUMMARIZE_FIELDS. Widening the egress surface now fails here until it is whitelisted in docs/design/egress.md.

  • .gitignore: ignore run-logs/ and the tool-local .zcodeignore.

Why

Follow-up from the DSH plugin-mechanism study (DSH is a candidate adapter under rule 3): adopt its proven engineering discipline now, while the adapter machinery itself stays gated until a demonstrated native-runner limitation.

Tests

540 passed in 22.85s

Full offline suite (dead-proxy environment per README), including the new tripwire test.

Record four adapter admission rules in adapter-seam.md (boot-declared
manifest validated before state, registrations as effects with reverse
order disposers, provider-visible implies activity-logged, typed errors
across the seam), adapted from DeepSeek Harness's plugin discipline, and
sharpen the rule 3 trigger: machinery is justified by a second party
extending nanodot, not by swappability, which the fakes already prove.

Add the egress tripwire test asserting every provider-visible field is
reconstructable from the activity log and that the StateChange surface
stays exactly the documented whitelist.

Ignore run-logs/ and the tool-local .zcodeignore.

Ref: #37
@hsliuustc0106
hsliuustc0106 merged commit 5ce7d51 into main Oct 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant