docs(readme): rewrite README + add runnable examples - #5

Merged
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples
May 10, 2026
Merged

docs(readme): rewrite README + add runnable examples#5
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • Replace the broken getBox -> sandboxId README snippet with a self-contained examples/sandbox-stream-backend/ whose sandboxClient and sandboxId are visibly defined inline — fixes the "where does sandboxId come from?" reader confusion
  • Restructure README.md around TOC / Overview / Install / Getting started / entry-point picker, mirroring the docs pattern in agent-eval
  • Ship six runnable examples in examples/: basic-task, with-knowledge-readiness, sanitized-telemetry, sse-stream, sandbox-stream-backend, openai-stream-backend — five run with no creds; the OpenAI one needs OPENAI_API_KEY

Test plan

  • pnpm typecheck
  • All five synthetic examples run end-to-end with pnpm tsx examples/<name>/<name>.ts and produce coherent output (status / SSE stream / readiness scoring / sanitized vs verbose telemetry)
  • openai-stream-backend exits with a clear message when creds are absent

Remove the broken `getBox -> sandboxId` snippet and replace it with a
self-contained sandbox-stream-backend example whose `sandboxClient` and
`sandboxId` are visibly defined inline. Restructure README around TOC /
Overview / Install / Getting started / entry-point picker / examples,
and ship six runnable examples covering basic-task, knowledge readiness,
sanitized telemetry, SSE serialization, the sandbox stream backend, and
the OpenAI-compatible stream backend.
@drewstone
drewstone merged commit 7b04ca2 into mainMay 10, 2026
drewstone added a commit that referenced this pull request May 26, 2026
…ehavior (#65)
Investigation surfaced two doc inaccuracies the freshly-merged spec doc
inherited from my own assumption rather than measurement:
1. Refusal status code is 429 + body code 'bridge_depth_exceeded' (live
in tangle-router app/api/chat/route.ts:1390-1410), not the 413 the
spec claimed. Updated header table + invariant #5 accordingly.
2. The spec read as fully shipped end-to-end. Added an Implementation
status table making the per-layer reality explicit:
- agent-runtime emits all six headers (this is the work that
shipped in #64).
- tangle-router enforces depth + forwards auth (already live).
- cli-bridge forwards authorization to sandbox backends (already
live); does not enforce depth locally — inherits via router.
- agent-gateway middleware: NOT YET. Deferred to a real consumer.
No code changes. The agent-runtime headers builders and emitters are
already correct (they emit the header; refusal is the gateway's job).
The doc was the only thing out of step.
tangletools pushed a commit that referenced this pull request Jun 4, 2026
…-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
drewstone added a commit that referenced this pull request Jun 4, 2026
…r runLoop (backend-blind) (#150)
* feat(loops): opt-in session continuation + checkpoint-fork lineage (backend-blind)
Two @experimental, default-OFF seams on runLoop so a loop can CONTINUE a sandbox
session across iterations (same box + sessionId, no prompt-text replay) and FORK
fanout branches from a parent checkpoint (shared context prefix) — both behind a
capability probe so the kernel asks 'can I fork?' (client.criuStatus) and never
names Docker/Firecracker, degrading to fresh boxes when CRIU is absent.
- sandbox-capabilities.ts: memoized, fail-closed criuStatus probe -> {canFork}.
- sandbox-lineage.ts: createSandboxLineage owns box+session handles with
start/continue/fork/teardown; reuses the kernel's acquireSandbox /
buildBackendOptions / deleteBoxSafe; fail-loud if the probe says canFork but
the box has no fork().
- run-loop.ts: RunLoopOptions.lineage (sessionContinuity / forkFanout); refine
continues, fanout forks-once, else fresh-through-lineage. Default OFF is
byte-identical to today, so random@k stays N independent fresh boxes (the
compute-control invariant). Rejects lineage + onWorkerBox (both own boxes).
- 7 new unit tests (continuation reuses session; fork when canFork; fresh
fallback; default-off invariant). Full suite 621 pass, typecheck clean.
* fix(loops): address PR #150 review — bound forks, prune lineage, fail-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@drewstone
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

docs(readme): rewrite README + add runnable examples - #5

Merged
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples
May 10, 2026
Merged

docs(readme): rewrite README + add runnable examples#5
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • Replace the broken getBox -> sandboxId README snippet with a self-contained examples/sandbox-stream-backend/ whose sandboxClient and sandboxId are visibly defined inline — fixes the "where does sandboxId come from?" reader confusion
  • Restructure README.md around TOC / Overview / Install / Getting started / entry-point picker, mirroring the docs pattern in agent-eval
  • Ship six runnable examples in examples/: basic-task, with-knowledge-readiness, sanitized-telemetry, sse-stream, sandbox-stream-backend, openai-stream-backend — five run with no creds; the OpenAI one needs OPENAI_API_KEY

Test plan

  • pnpm typecheck
  • All five synthetic examples run end-to-end with pnpm tsx examples/<name>/<name>.ts and produce coherent output (status / SSE stream / readiness scoring / sanitized vs verbose telemetry)
  • openai-stream-backend exits with a clear message when creds are absent

Remove the broken `getBox -> sandboxId` snippet and replace it with a
self-contained sandbox-stream-backend example whose `sandboxClient` and
`sandboxId` are visibly defined inline. Restructure README around TOC /
Overview / Install / Getting started / entry-point picker / examples,
and ship six runnable examples covering basic-task, knowledge readiness,
sanitized telemetry, SSE serialization, the sandbox stream backend, and
the OpenAI-compatible stream backend.
@drewstone
drewstone merged commit 7b04ca2 into mainMay 10, 2026
drewstone added a commit that referenced this pull request May 26, 2026
…ehavior (#65)
Investigation surfaced two doc inaccuracies the freshly-merged spec doc
inherited from my own assumption rather than measurement:
1. Refusal status code is 429 + body code 'bridge_depth_exceeded' (live
in tangle-router app/api/chat/route.ts:1390-1410), not the 413 the
spec claimed. Updated header table + invariant #5 accordingly.
2. The spec read as fully shipped end-to-end. Added an Implementation
status table making the per-layer reality explicit:
- agent-runtime emits all six headers (this is the work that
shipped in #64).
- tangle-router enforces depth + forwards auth (already live).
- cli-bridge forwards authorization to sandbox backends (already
live); does not enforce depth locally — inherits via router.
- agent-gateway middleware: NOT YET. Deferred to a real consumer.
No code changes. The agent-runtime headers builders and emitters are
already correct (they emit the header; refusal is the gateway's job).
The doc was the only thing out of step.
tangletools pushed a commit that referenced this pull request Jun 4, 2026
…-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
drewstone added a commit that referenced this pull request Jun 4, 2026
…r runLoop (backend-blind) (#150)
* feat(loops): opt-in session continuation + checkpoint-fork lineage (backend-blind)
Two @experimental, default-OFF seams on runLoop so a loop can CONTINUE a sandbox
session across iterations (same box + sessionId, no prompt-text replay) and FORK
fanout branches from a parent checkpoint (shared context prefix) — both behind a
capability probe so the kernel asks 'can I fork?' (client.criuStatus) and never
names Docker/Firecracker, degrading to fresh boxes when CRIU is absent.
- sandbox-capabilities.ts: memoized, fail-closed criuStatus probe -> {canFork}.
- sandbox-lineage.ts: createSandboxLineage owns box+session handles with
start/continue/fork/teardown; reuses the kernel's acquireSandbox /
buildBackendOptions / deleteBoxSafe; fail-loud if the probe says canFork but
the box has no fork().
- run-loop.ts: RunLoopOptions.lineage (sessionContinuity / forkFanout); refine
continues, fanout forks-once, else fresh-through-lineage. Default OFF is
byte-identical to today, so random@k stays N independent fresh boxes (the
compute-control invariant). Rejects lineage + onWorkerBox (both own boxes).
- 7 new unit tests (continuation reuses session; fork when canFork; fresh
fallback; default-off invariant). Full suite 621 pass, typecheck clean.
* fix(loops): address PR #150 review — bound forks, prune lineage, fail-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@drewstone
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(readme): rewrite README + add runnable examples - #5

Merged
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples
May 10, 2026
Merged

docs(readme): rewrite README + add runnable examples#5
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • Replace the broken getBox -> sandboxId README snippet with a self-contained examples/sandbox-stream-backend/ whose sandboxClient and sandboxId are visibly defined inline — fixes the "where does sandboxId come from?" reader confusion
  • Restructure README.md around TOC / Overview / Install / Getting started / entry-point picker, mirroring the docs pattern in agent-eval
  • Ship six runnable examples in examples/: basic-task, with-knowledge-readiness, sanitized-telemetry, sse-stream, sandbox-stream-backend, openai-stream-backend — five run with no creds; the OpenAI one needs OPENAI_API_KEY

Test plan

  • pnpm typecheck
  • All five synthetic examples run end-to-end with pnpm tsx examples/<name>/<name>.ts and produce coherent output (status / SSE stream / readiness scoring / sanitized vs verbose telemetry)
  • openai-stream-backend exits with a clear message when creds are absent

Remove the broken `getBox -> sandboxId` snippet and replace it with a
self-contained sandbox-stream-backend example whose `sandboxClient` and
`sandboxId` are visibly defined inline. Restructure README around TOC /
Overview / Install / Getting started / entry-point picker / examples,
and ship six runnable examples covering basic-task, knowledge readiness,
sanitized telemetry, SSE serialization, the sandbox stream backend, and
the OpenAI-compatible stream backend.
@drewstone
drewstone merged commit 7b04ca2 into mainMay 10, 2026
drewstone added a commit that referenced this pull request May 26, 2026
…ehavior (#65)
Investigation surfaced two doc inaccuracies the freshly-merged spec doc
inherited from my own assumption rather than measurement:
1. Refusal status code is 429 + body code 'bridge_depth_exceeded' (live
in tangle-router app/api/chat/route.ts:1390-1410), not the 413 the
spec claimed. Updated header table + invariant #5 accordingly.
2. The spec read as fully shipped end-to-end. Added an Implementation
status table making the per-layer reality explicit:
- agent-runtime emits all six headers (this is the work that
shipped in #64).
- tangle-router enforces depth + forwards auth (already live).
- cli-bridge forwards authorization to sandbox backends (already
live); does not enforce depth locally — inherits via router.
- agent-gateway middleware: NOT YET. Deferred to a real consumer.
No code changes. The agent-runtime headers builders and emitters are
already correct (they emit the header; refusal is the gateway's job).
The doc was the only thing out of step.
tangletools pushed a commit that referenced this pull request Jun 4, 2026
…-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
drewstone added a commit that referenced this pull request Jun 4, 2026
…r runLoop (backend-blind) (#150)
* feat(loops): opt-in session continuation + checkpoint-fork lineage (backend-blind)
Two @experimental, default-OFF seams on runLoop so a loop can CONTINUE a sandbox
session across iterations (same box + sessionId, no prompt-text replay) and FORK
fanout branches from a parent checkpoint (shared context prefix) — both behind a
capability probe so the kernel asks 'can I fork?' (client.criuStatus) and never
names Docker/Firecracker, degrading to fresh boxes when CRIU is absent.
- sandbox-capabilities.ts: memoized, fail-closed criuStatus probe -> {canFork}.
- sandbox-lineage.ts: createSandboxLineage owns box+session handles with
start/continue/fork/teardown; reuses the kernel's acquireSandbox /
buildBackendOptions / deleteBoxSafe; fail-loud if the probe says canFork but
the box has no fork().
- run-loop.ts: RunLoopOptions.lineage (sessionContinuity / forkFanout); refine
continues, fanout forks-once, else fresh-through-lineage. Default OFF is
byte-identical to today, so random@k stays N independent fresh boxes (the
compute-control invariant). Rejects lineage + onWorkerBox (both own boxes).
- 7 new unit tests (continuation reuses session; fork when canFork; fresh
fallback; default-off invariant). Full suite 621 pass, typecheck clean.
* fix(loops): address PR #150 review — bound forks, prune lineage, fail-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@drewstone
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(readme): rewrite README + add runnable examples - #5

Merged
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples
May 10, 2026
Merged

docs(readme): rewrite README + add runnable examples#5
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • Replace the broken getBox -> sandboxId README snippet with a self-contained examples/sandbox-stream-backend/ whose sandboxClient and sandboxId are visibly defined inline — fixes the "where does sandboxId come from?" reader confusion
  • Restructure README.md around TOC / Overview / Install / Getting started / entry-point picker, mirroring the docs pattern in agent-eval
  • Ship six runnable examples in examples/: basic-task, with-knowledge-readiness, sanitized-telemetry, sse-stream, sandbox-stream-backend, openai-stream-backend — five run with no creds; the OpenAI one needs OPENAI_API_KEY

Test plan

  • pnpm typecheck
  • All five synthetic examples run end-to-end with pnpm tsx examples/<name>/<name>.ts and produce coherent output (status / SSE stream / readiness scoring / sanitized vs verbose telemetry)
  • openai-stream-backend exits with a clear message when creds are absent

Remove the broken `getBox -> sandboxId` snippet and replace it with a
self-contained sandbox-stream-backend example whose `sandboxClient` and
`sandboxId` are visibly defined inline. Restructure README around TOC /
Overview / Install / Getting started / entry-point picker / examples,
and ship six runnable examples covering basic-task, knowledge readiness,
sanitized telemetry, SSE serialization, the sandbox stream backend, and
the OpenAI-compatible stream backend.
@drewstone
drewstone merged commit 7b04ca2 into mainMay 10, 2026
drewstone added a commit that referenced this pull request May 26, 2026
…ehavior (#65)
Investigation surfaced two doc inaccuracies the freshly-merged spec doc
inherited from my own assumption rather than measurement:
1. Refusal status code is 429 + body code 'bridge_depth_exceeded' (live
in tangle-router app/api/chat/route.ts:1390-1410), not the 413 the
spec claimed. Updated header table + invariant #5 accordingly.
2. The spec read as fully shipped end-to-end. Added an Implementation
status table making the per-layer reality explicit:
- agent-runtime emits all six headers (this is the work that
shipped in #64).
- tangle-router enforces depth + forwards auth (already live).
- cli-bridge forwards authorization to sandbox backends (already
live); does not enforce depth locally — inherits via router.
- agent-gateway middleware: NOT YET. Deferred to a real consumer.
No code changes. The agent-runtime headers builders and emitters are
already correct (they emit the header; refusal is the gateway's job).
The doc was the only thing out of step.
tangletools pushed a commit that referenced this pull request Jun 4, 2026
…-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
drewstone added a commit that referenced this pull request Jun 4, 2026
…r runLoop (backend-blind) (#150)
* feat(loops): opt-in session continuation + checkpoint-fork lineage (backend-blind)
Two @experimental, default-OFF seams on runLoop so a loop can CONTINUE a sandbox
session across iterations (same box + sessionId, no prompt-text replay) and FORK
fanout branches from a parent checkpoint (shared context prefix) — both behind a
capability probe so the kernel asks 'can I fork?' (client.criuStatus) and never
names Docker/Firecracker, degrading to fresh boxes when CRIU is absent.
- sandbox-capabilities.ts: memoized, fail-closed criuStatus probe -> {canFork}.
- sandbox-lineage.ts: createSandboxLineage owns box+session handles with
start/continue/fork/teardown; reuses the kernel's acquireSandbox /
buildBackendOptions / deleteBoxSafe; fail-loud if the probe says canFork but
the box has no fork().
- run-loop.ts: RunLoopOptions.lineage (sessionContinuity / forkFanout); refine
continues, fanout forks-once, else fresh-through-lineage. Default OFF is
byte-identical to today, so random@k stays N independent fresh boxes (the
compute-control invariant). Rejects lineage + onWorkerBox (both own boxes).
- 7 new unit tests (continuation reuses session; fork when canFork; fresh
fallback; default-off invariant). Full suite 621 pass, typecheck clean.
* fix(loops): address PR #150 review — bound forks, prune lineage, fail-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@drewstone
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

docs(readme): rewrite README + add runnable examples - #5

Merged
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples
May 10, 2026
Merged

docs(readme): rewrite README + add runnable examples#5
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • Replace the broken getBox -> sandboxId README snippet with a self-contained examples/sandbox-stream-backend/ whose sandboxClient and sandboxId are visibly defined inline — fixes the "where does sandboxId come from?" reader confusion
  • Restructure README.md around TOC / Overview / Install / Getting started / entry-point picker, mirroring the docs pattern in agent-eval
  • Ship six runnable examples in examples/: basic-task, with-knowledge-readiness, sanitized-telemetry, sse-stream, sandbox-stream-backend, openai-stream-backend — five run with no creds; the OpenAI one needs OPENAI_API_KEY

Test plan

  • pnpm typecheck
  • All five synthetic examples run end-to-end with pnpm tsx examples/<name>/<name>.ts and produce coherent output (status / SSE stream / readiness scoring / sanitized vs verbose telemetry)
  • openai-stream-backend exits with a clear message when creds are absent

Remove the broken `getBox -> sandboxId` snippet and replace it with a
self-contained sandbox-stream-backend example whose `sandboxClient` and
`sandboxId` are visibly defined inline. Restructure README around TOC /
Overview / Install / Getting started / entry-point picker / examples,
and ship six runnable examples covering basic-task, knowledge readiness,
sanitized telemetry, SSE serialization, the sandbox stream backend, and
the OpenAI-compatible stream backend.
@drewstone
drewstone merged commit 7b04ca2 into mainMay 10, 2026
drewstone added a commit that referenced this pull request May 26, 2026
…ehavior (#65)
Investigation surfaced two doc inaccuracies the freshly-merged spec doc
inherited from my own assumption rather than measurement:
1. Refusal status code is 429 + body code 'bridge_depth_exceeded' (live
in tangle-router app/api/chat/route.ts:1390-1410), not the 413 the
spec claimed. Updated header table + invariant #5 accordingly.
2. The spec read as fully shipped end-to-end. Added an Implementation
status table making the per-layer reality explicit:
- agent-runtime emits all six headers (this is the work that
shipped in #64).
- tangle-router enforces depth + forwards auth (already live).
- cli-bridge forwards authorization to sandbox backends (already
live); does not enforce depth locally — inherits via router.
- agent-gateway middleware: NOT YET. Deferred to a real consumer.
No code changes. The agent-runtime headers builders and emitters are
already correct (they emit the header; refusal is the gateway's job).
The doc was the only thing out of step.
tangletools pushed a commit that referenced this pull request Jun 4, 2026
…-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
drewstone added a commit that referenced this pull request Jun 4, 2026
…r runLoop (backend-blind) (#150)
* feat(loops): opt-in session continuation + checkpoint-fork lineage (backend-blind)
Two @experimental, default-OFF seams on runLoop so a loop can CONTINUE a sandbox
session across iterations (same box + sessionId, no prompt-text replay) and FORK
fanout branches from a parent checkpoint (shared context prefix) — both behind a
capability probe so the kernel asks 'can I fork?' (client.criuStatus) and never
names Docker/Firecracker, degrading to fresh boxes when CRIU is absent.
- sandbox-capabilities.ts: memoized, fail-closed criuStatus probe -> {canFork}.
- sandbox-lineage.ts: createSandboxLineage owns box+session handles with
start/continue/fork/teardown; reuses the kernel's acquireSandbox /
buildBackendOptions / deleteBoxSafe; fail-loud if the probe says canFork but
the box has no fork().
- run-loop.ts: RunLoopOptions.lineage (sessionContinuity / forkFanout); refine
continues, fanout forks-once, else fresh-through-lineage. Default OFF is
byte-identical to today, so random@k stays N independent fresh boxes (the
compute-control invariant). Rejects lineage + onWorkerBox (both own boxes).
- 7 new unit tests (continuation reuses session; fork when canFork; fresh
fallback; default-off invariant). Full suite 621 pass, typecheck clean.
* fix(loops): address PR #150 review — bound forks, prune lineage, fail-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@drewstone
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(readme): rewrite README + add runnable examples - #5

Merged
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples
May 10, 2026
Merged

docs(readme): rewrite README + add runnable examples#5
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • Replace the broken getBox -> sandboxId README snippet with a self-contained examples/sandbox-stream-backend/ whose sandboxClient and sandboxId are visibly defined inline — fixes the "where does sandboxId come from?" reader confusion
  • Restructure README.md around TOC / Overview / Install / Getting started / entry-point picker, mirroring the docs pattern in agent-eval
  • Ship six runnable examples in examples/: basic-task, with-knowledge-readiness, sanitized-telemetry, sse-stream, sandbox-stream-backend, openai-stream-backend — five run with no creds; the OpenAI one needs OPENAI_API_KEY

Test plan

  • pnpm typecheck
  • All five synthetic examples run end-to-end with pnpm tsx examples/<name>/<name>.ts and produce coherent output (status / SSE stream / readiness scoring / sanitized vs verbose telemetry)
  • openai-stream-backend exits with a clear message when creds are absent

Remove the broken `getBox -> sandboxId` snippet and replace it with a
self-contained sandbox-stream-backend example whose `sandboxClient` and
`sandboxId` are visibly defined inline. Restructure README around TOC /
Overview / Install / Getting started / entry-point picker / examples,
and ship six runnable examples covering basic-task, knowledge readiness,
sanitized telemetry, SSE serialization, the sandbox stream backend, and
the OpenAI-compatible stream backend.
@drewstone
drewstone merged commit 7b04ca2 into mainMay 10, 2026
drewstone added a commit that referenced this pull request May 26, 2026
…ehavior (#65)
Investigation surfaced two doc inaccuracies the freshly-merged spec doc
inherited from my own assumption rather than measurement:
1. Refusal status code is 429 + body code 'bridge_depth_exceeded' (live
in tangle-router app/api/chat/route.ts:1390-1410), not the 413 the
spec claimed. Updated header table + invariant #5 accordingly.
2. The spec read as fully shipped end-to-end. Added an Implementation
status table making the per-layer reality explicit:
- agent-runtime emits all six headers (this is the work that
shipped in #64).
- tangle-router enforces depth + forwards auth (already live).
- cli-bridge forwards authorization to sandbox backends (already
live); does not enforce depth locally — inherits via router.
- agent-gateway middleware: NOT YET. Deferred to a real consumer.
No code changes. The agent-runtime headers builders and emitters are
already correct (they emit the header; refusal is the gateway's job).
The doc was the only thing out of step.
tangletools pushed a commit that referenced this pull request Jun 4, 2026
…-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
drewstone added a commit that referenced this pull request Jun 4, 2026
…r runLoop (backend-blind) (#150)
* feat(loops): opt-in session continuation + checkpoint-fork lineage (backend-blind)
Two @experimental, default-OFF seams on runLoop so a loop can CONTINUE a sandbox
session across iterations (same box + sessionId, no prompt-text replay) and FORK
fanout branches from a parent checkpoint (shared context prefix) — both behind a
capability probe so the kernel asks 'can I fork?' (client.criuStatus) and never
names Docker/Firecracker, degrading to fresh boxes when CRIU is absent.
- sandbox-capabilities.ts: memoized, fail-closed criuStatus probe -> {canFork}.
- sandbox-lineage.ts: createSandboxLineage owns box+session handles with
start/continue/fork/teardown; reuses the kernel's acquireSandbox /
buildBackendOptions / deleteBoxSafe; fail-loud if the probe says canFork but
the box has no fork().
- run-loop.ts: RunLoopOptions.lineage (sessionContinuity / forkFanout); refine
continues, fanout forks-once, else fresh-through-lineage. Default OFF is
byte-identical to today, so random@k stays N independent fresh boxes (the
compute-control invariant). Rejects lineage + onWorkerBox (both own boxes).
- 7 new unit tests (continuation reuses session; fork when canFork; fresh
fallback; default-off invariant). Full suite 621 pass, typecheck clean.
* fix(loops): address PR #150 review — bound forks, prune lineage, fail-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@drewstone
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(readme): rewrite README + add runnable examples - #5

Merged
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples
May 10, 2026
Merged

docs(readme): rewrite README + add runnable examples#5
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • Replace the broken getBox -> sandboxId README snippet with a self-contained examples/sandbox-stream-backend/ whose sandboxClient and sandboxId are visibly defined inline — fixes the "where does sandboxId come from?" reader confusion
  • Restructure README.md around TOC / Overview / Install / Getting started / entry-point picker, mirroring the docs pattern in agent-eval
  • Ship six runnable examples in examples/: basic-task, with-knowledge-readiness, sanitized-telemetry, sse-stream, sandbox-stream-backend, openai-stream-backend — five run with no creds; the OpenAI one needs OPENAI_API_KEY

Test plan

  • pnpm typecheck
  • All five synthetic examples run end-to-end with pnpm tsx examples/<name>/<name>.ts and produce coherent output (status / SSE stream / readiness scoring / sanitized vs verbose telemetry)
  • openai-stream-backend exits with a clear message when creds are absent

Remove the broken `getBox -> sandboxId` snippet and replace it with a
self-contained sandbox-stream-backend example whose `sandboxClient` and
`sandboxId` are visibly defined inline. Restructure README around TOC /
Overview / Install / Getting started / entry-point picker / examples,
and ship six runnable examples covering basic-task, knowledge readiness,
sanitized telemetry, SSE serialization, the sandbox stream backend, and
the OpenAI-compatible stream backend.
@drewstone
drewstone merged commit 7b04ca2 into mainMay 10, 2026
drewstone added a commit that referenced this pull request May 26, 2026
…ehavior (#65)
Investigation surfaced two doc inaccuracies the freshly-merged spec doc
inherited from my own assumption rather than measurement:
1. Refusal status code is 429 + body code 'bridge_depth_exceeded' (live
in tangle-router app/api/chat/route.ts:1390-1410), not the 413 the
spec claimed. Updated header table + invariant #5 accordingly.
2. The spec read as fully shipped end-to-end. Added an Implementation
status table making the per-layer reality explicit:
- agent-runtime emits all six headers (this is the work that
shipped in #64).
- tangle-router enforces depth + forwards auth (already live).
- cli-bridge forwards authorization to sandbox backends (already
live); does not enforce depth locally — inherits via router.
- agent-gateway middleware: NOT YET. Deferred to a real consumer.
No code changes. The agent-runtime headers builders and emitters are
already correct (they emit the header; refusal is the gateway's job).
The doc was the only thing out of step.
tangletools pushed a commit that referenced this pull request Jun 4, 2026
…-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
drewstone added a commit that referenced this pull request Jun 4, 2026
…r runLoop (backend-blind) (#150)
* feat(loops): opt-in session continuation + checkpoint-fork lineage (backend-blind)
Two @experimental, default-OFF seams on runLoop so a loop can CONTINUE a sandbox
session across iterations (same box + sessionId, no prompt-text replay) and FORK
fanout branches from a parent checkpoint (shared context prefix) — both behind a
capability probe so the kernel asks 'can I fork?' (client.criuStatus) and never
names Docker/Firecracker, degrading to fresh boxes when CRIU is absent.
- sandbox-capabilities.ts: memoized, fail-closed criuStatus probe -> {canFork}.
- sandbox-lineage.ts: createSandboxLineage owns box+session handles with
start/continue/fork/teardown; reuses the kernel's acquireSandbox /
buildBackendOptions / deleteBoxSafe; fail-loud if the probe says canFork but
the box has no fork().
- run-loop.ts: RunLoopOptions.lineage (sessionContinuity / forkFanout); refine
continues, fanout forks-once, else fresh-through-lineage. Default OFF is
byte-identical to today, so random@k stays N independent fresh boxes (the
compute-control invariant). Rejects lineage + onWorkerBox (both own boxes).
- 7 new unit tests (continuation reuses session; fork when canFork; fresh
fallback; default-off invariant). Full suite 621 pass, typecheck clean.
* fix(loops): address PR #150 review — bound forks, prune lineage, fail-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@drewstone
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

docs(readme): rewrite README + add runnable examples - #5

Merged
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples
May 10, 2026
Merged

docs(readme): rewrite README + add runnable examples#5
drewstone merged 1 commit into
mainfrom
docs/readme-and-examples

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Summary

  • Replace the broken getBox -> sandboxId README snippet with a self-contained examples/sandbox-stream-backend/ whose sandboxClient and sandboxId are visibly defined inline — fixes the "where does sandboxId come from?" reader confusion
  • Restructure README.md around TOC / Overview / Install / Getting started / entry-point picker, mirroring the docs pattern in agent-eval
  • Ship six runnable examples in examples/: basic-task, with-knowledge-readiness, sanitized-telemetry, sse-stream, sandbox-stream-backend, openai-stream-backend — five run with no creds; the OpenAI one needs OPENAI_API_KEY

Test plan

  • pnpm typecheck
  • All five synthetic examples run end-to-end with pnpm tsx examples/<name>/<name>.ts and produce coherent output (status / SSE stream / readiness scoring / sanitized vs verbose telemetry)
  • openai-stream-backend exits with a clear message when creds are absent

Remove the broken `getBox -> sandboxId` snippet and replace it with a
self-contained sandbox-stream-backend example whose `sandboxClient` and
`sandboxId` are visibly defined inline. Restructure README around TOC /
Overview / Install / Getting started / entry-point picker / examples,
and ship six runnable examples covering basic-task, knowledge readiness,
sanitized telemetry, SSE serialization, the sandbox stream backend, and
the OpenAI-compatible stream backend.
@drewstone
drewstone merged commit 7b04ca2 into mainMay 10, 2026
drewstone added a commit that referenced this pull request May 26, 2026
…ehavior (#65)
Investigation surfaced two doc inaccuracies the freshly-merged spec doc
inherited from my own assumption rather than measurement:
1. Refusal status code is 429 + body code 'bridge_depth_exceeded' (live
in tangle-router app/api/chat/route.ts:1390-1410), not the 413 the
spec claimed. Updated header table + invariant #5 accordingly.
2. The spec read as fully shipped end-to-end. Added an Implementation
status table making the per-layer reality explicit:
- agent-runtime emits all six headers (this is the work that
shipped in #64).
- tangle-router enforces depth + forwards auth (already live).
- cli-bridge forwards authorization to sandbox backends (already
live); does not enforce depth locally — inherits via router.
- agent-gateway middleware: NOT YET. Deferred to a real consumer.
No code changes. The agent-runtime headers builders and emitters are
already correct (they emit the header; refusal is the gateway's job).
The doc was the only thing out of step.
tangletools pushed a commit that referenced this pull request Jun 4, 2026
…-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
drewstone added a commit that referenced this pull request Jun 4, 2026
…r runLoop (backend-blind) (#150)
* feat(loops): opt-in session continuation + checkpoint-fork lineage (backend-blind)
Two @experimental, default-OFF seams on runLoop so a loop can CONTINUE a sandbox
session across iterations (same box + sessionId, no prompt-text replay) and FORK
fanout branches from a parent checkpoint (shared context prefix) — both behind a
capability probe so the kernel asks 'can I fork?' (client.criuStatus) and never
names Docker/Firecracker, degrading to fresh boxes when CRIU is absent.
- sandbox-capabilities.ts: memoized, fail-closed criuStatus probe -> {canFork}.
- sandbox-lineage.ts: createSandboxLineage owns box+session handles with
start/continue/fork/teardown; reuses the kernel's acquireSandbox /
buildBackendOptions / deleteBoxSafe; fail-loud if the probe says canFork but
the box has no fork().
- run-loop.ts: RunLoopOptions.lineage (sessionContinuity / forkFanout); refine
continues, fanout forks-once, else fresh-through-lineage. Default OFF is
byte-identical to today, so random@k stays N independent fresh boxes (the
compute-control invariant). Rejects lineage + onWorkerBox (both own boxes).
- 7 new unit tests (continuation reuses session; fork when canFork; fresh
fallback; default-off invariant). Full suite 621 pass, typecheck clean.
* fix(loops): address PR #150 review — bound forks, prune lineage, fail-loud session continuity
Resolve all six findings from the review (none blocked landing; #1 gated
enabling, #3/#4 wanted documenting). Lineage remains default-OFF and
byte-identical to the fresh-box path when both flags are unset.
- #1 sessionContinuity silent no-op: `continue` now asserts the session is
still known to the sandbox via `box.session(id).status()` before streaming.
A `null` (platform never honored the client-minted id, or it was reaped)
raises a ValidationError, which executeIteration now propagates as a hard
structural failure instead of degrading to a soft empty iteration — so a
non-honoring platform errors loudly rather than running contextless turns.
- #2 unbounded fork creation: `fork` provisions child boxes through
`mapWithConcurrency` bounded by the loop's `maxConcurrency`, not a single
`Promise.all` over all N branches.
- #3 fork ignores per-branch specs: documented on `fork` and
`LoopLineageOptions.forkFanout` that a real CRIU fork inherits the parent
image/profile (per-branch specs apply only on the degraded fresh path).
- #4 lineage holds every box to loop end: kernel prunes boxes no future round
can descend from after each round, gated on a kernel-inferred (monotonic)
branch point — skipped when the driver authors its own `parentIndex`. The
unprunable case is documented as the box ceiling.
- #5 abort during fork: documented the SDK's signal-less fork; abort is now
checked per branch (between bounded waves) + an abort-under-lineage test.
- #6 export order: alphabetized the loops barrel.
Adds `mapWithConcurrency` util and six lineage tests (session-liveness pass/
fail, bounded-fork peak, mid-loop prune, no-prune-under-authored-parent,
abort-under-lineage). 627 tests pass, typecheck + biome clean.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@drewstone