Compare commits

...

175 Commits

Author SHA1 Message Date
05d39e05c7
test: align companion execution assertions 2026-06-28 16:55:34 +09:00
e7d56bba73
merge: embedded worker execution 2026-06-28 16:47:39 +09:00
e5b539faee
ticket: record companion llm cleanup 2026-06-28 16:20:27 +09:00
9c54bfe997
ticket: close workspace companion llm worker 2026-06-28 16:19:54 +09:00
eb06b8a923
merge: workspace companion llm worker 2026-06-28 16:18:48 +09:00
a21a62301d
ticket: approve workspace companion llm worker 2026-06-28 16:18:41 +09:00
169a8d501e
ticket: record companion workspace status fix 2026-06-28 16:14:20 +09:00
3be193223c
fix: report companion console runtime status 2026-06-28 16:13:33 +09:00
f00252c8aa
ticket: request companion workspace status fix 2026-06-28 16:05:58 +09:00
d09a6f5da1
ticket: record companion llm implementation 2026-06-28 15:56:54 +09:00
ee25cfbcfd
fix: route workspace companion through worker runtime 2026-06-28 15:56:00 +09:00
dc8d8a0df5
ticket: request companion llm changes 2026-06-28 15:27:12 +09:00
05f1e1ed39
ticket: start companion llm review 2026-06-28 15:21:04 +09:00
b43e6b7eee
ticket: record companion llm verification pass 2026-06-28 15:20:36 +09:00
865d1092a0
ticket: record companion coder context error 2026-06-28 15:09:58 +09:00
d91168825c
ticket: start workspace companion llm worker 2026-06-28 15:04:06 +09:00
0c5a769abb
ticket: accept workspace companion llm worker 2026-06-28 15:02:59 +09:00
9c3347f0ec
ticket: record worker adapter cleanup 2026-06-28 15:02:21 +09:00
235cd88db9
ticket: close worker adapter 2026-06-28 06:45:04 +09:00
c3ed223dfd
merge: worker runtime worker adapter 2026-06-28 06:42:32 +09:00
1ab270ba46
ticket: approve worker adapter 2026-06-28 06:42:27 +09:00
a45797baff
ticket: record worker adapter spawn failure fix 2026-06-28 06:39:58 +09:00
7e29ff5ec9
fix: reject embedded spawn execution failures 2026-06-28 06:39:03 +09:00
d02007c993
ticket: request worker adapter spawn failure fix 2026-06-28 06:27:40 +09:00
d549b4bd08
ticket: record worker adapter fix 2026-06-28 06:22:05 +09:00
9069b03504
fix: connect embedded runtime input lifecycle 2026-06-28 06:20:34 +09:00
af1a1eb836
ticket: request worker adapter changes 2026-06-28 05:58:09 +09:00
ca4498e001
ticket: start worker adapter review 2026-06-28 05:51:46 +09:00
2d275de3cc
ticket: record worker adapter implementation 2026-06-28 05:51:18 +09:00
18526ee362
feat: connect runtime worker execution adapter 2026-06-28 05:50:11 +09:00
1c4e7e5198
ticket: start worker runtime worker adapter 2026-06-28 05:12:36 +09:00
e1e9fcb326
ticket: accept worker runtime worker adapter 2026-06-28 05:11:47 +09:00
435863a07f
ticket: record worker execution backend cleanup 2026-06-28 05:09:48 +09:00
655c0a3ec6
ticket: close worker execution backend 2026-06-28 04:49:51 +09:00
0753e155a5
merge: worker runtime execution backend 2026-06-28 04:48:38 +09:00
d7d1fbbdcb
ticket: approve worker execution backend 2026-06-28 04:48:34 +09:00
f7448c832e
ticket: record worker execution backend fix 2026-06-28 04:46:48 +09:00
761b60c857
fix: initialize restored worker observations 2026-06-28 04:46:08 +09:00
b6bfad7f8b
ticket: request worker execution backend changes 2026-06-28 04:41:14 +09:00
4240bd29bb
ticket: start worker execution backend review 2026-06-28 04:36:16 +09:00
c242841957
ticket: record worker execution backend implementation 2026-06-28 04:34:29 +09:00
2d59717384
feat: add worker execution backend boundary 2026-06-28 04:33:01 +09:00
5420265236
ticket: start worker runtime execution boundary 2026-06-28 04:09:48 +09:00
9929d1c704
ticket: accept worker runtime execution boundary 2026-06-28 04:08:53 +09:00
62ce777cf8
ticket: queue 00001KW55B33H 2026-06-28 04:06:32 +09:00
6bfeb6d945
ticket: queue 00001KW55B33B 2026-06-28 04:06:30 +09:00
e1f14a920d
ticket: queue 00001KW55B32Y 2026-06-28 04:06:28 +09:00
3836639825
ticket: ready embedded worker execution 2026-06-28 04:06:24 +09:00
d86b1fb06d
ticket: plan embedded worker execution 2026-06-28 03:29:57 +09:00
2fb7514daa
runtime: remove fake companion responses 2026-06-28 03:06:12 +09:00
67df7d1a53
runtime: make worker console observation required 2026-06-28 02:11:43 +09:00
135667417b
ui: remove legacy local worker projection 2026-06-27 18:31:17 +09:00
62420b7cc4
merge: worker console redesign
# Conflicts:
#	web/workspace/src/lib/workspace-sidebar/WorkersNavSection.svelte
2026-06-27 03:26:48 +09:00
7d90cb644d
ui: compact workspace overview 2026-06-27 03:25:28 +09:00
18aa07446e
ticket: record worker console cleanup 2026-06-27 03:22:58 +09:00
29d6209ea4
ticket: mark worker console redesign done 2026-06-27 03:22:17 +09:00
864efe32e4
merge: 00001KW2GCPYF worker console redesign 2026-06-27 03:21:24 +09:00
867a8ee55b
ticket: approve worker console redesign 2026-06-27 03:21:24 +09:00
10322595c6
ticket: record worker console refresh fix 2026-06-27 03:19:21 +09:00
a1083908b6
fix: stabilize worker console refresh 2026-06-27 03:18:26 +09:00
f98dc7d7ca
ticket: request worker console effect fix 2026-06-27 03:12:02 +09:00
a342dfb9d2
ticket: record worker console implementation 2026-06-27 03:07:28 +09:00
c3fed59109
feat: worker attach workspace console 2026-06-27 03:06:10 +09:00
f070b9e56f
ticket: start worker console redesign 2026-06-27 02:47:34 +09:00
f64e11b854
ticket: accept worker console redesign 2026-06-27 02:46:44 +09:00
816c79290f
ticket: close runtime migration batch 2026-06-27 02:46:11 +09:00
22a2350126
ticket: queue 00001KW2GCPYF 2026-06-27 02:45:40 +09:00
971d2f832f
ticket: plan worker console redesign 2026-06-27 02:45:26 +09:00
390b914268
merge: runtime backend orchestration updates 2026-06-27 01:28:11 +09:00
aaf3cc8391
ticket: record tui runtime migration cleanup 2026-06-26 17:55:36 +09:00
3f6d5f29b8
ticket: mark tui runtime migration done 2026-06-26 17:54:53 +09:00
0a683bb227
merge: 00001KW04A8K6 tui runtime migration 2026-06-26 17:52:55 +09:00
bd211d55fd
ticket: approve tui runtime migration 2026-06-26 17:52:55 +09:00
5cfe1d7f4b
ticket: record tui runtime migration implementation 2026-06-26 17:44:01 +09:00
63ec9f9572
feat: add backend runtime console target 2026-06-26 17:42:21 +09:00
94a2c94cc4
ticket: start tui runtime migration 2026-06-26 17:11:25 +09:00
65efde7651
ticket: accept tui runtime migration 2026-06-26 17:10:27 +09:00
0ba188889a
ticket: record web console cleanup 2026-06-26 17:09:15 +09:00
d9e6913791
ticket: mark web console mvp done 2026-06-26 17:08:24 +09:00
bf834e8352
merge: 00001KVZ9JGK0 web console mvp 2026-06-26 17:07:32 +09:00
b94fb8167d
ticket: approve web console mvp 2026-06-26 17:07:32 +09:00
95c992ddbd
ticket: record web console implementation 2026-06-26 17:02:51 +09:00
f3ad9c96b3
feat: add workspace companion console MVP 2026-06-26 17:01:30 +09:00
d6fe8b8d8a
ticket: start web console mvp 2026-06-26 16:43:19 +09:00
f39036032b
ticket: accept web console mvp 2026-06-26 16:42:20 +09:00
32e1360802
ticket: record runtime config bundle cleanup 2026-06-26 16:40:48 +09:00
2df7a98dbf
ticket: mark runtime config bundle sync done 2026-06-26 16:39:56 +09:00
7e8a8cfa4b
merge: 00001KVZQHPNY runtime config bundles 2026-06-26 16:38:34 +09:00
d2dfc186b1
ticket: approve runtime config bundle sync 2026-06-26 16:38:34 +09:00
b6d7a34677
ticket: record config bundle boundary fixes 2026-06-26 16:34:11 +09:00
4867ab21bf
fix: harden runtime config bundle boundary 2026-06-26 16:32:50 +09:00
0f8c6b80e3
ticket: request config bundle boundary fixes 2026-06-26 16:18:58 +09:00
be396e59d9
ticket: record runtime config bundle implementation 2026-06-26 16:08:39 +09:00
abab1af2f0
feat: add runtime config bundle sync 2026-06-26 16:06:58 +09:00
0c83d57727
ticket: start runtime config bundle sync 2026-06-26 15:35:33 +09:00
9a09ebd9ac
ticket: accept runtime config bundle sync 2026-06-26 15:34:24 +09:00
3e550874ac
ticket: record remote runtime cleanup 2026-06-26 15:31:00 +09:00
6c03220c1c
ticket: mark remote runtime registry done 2026-06-26 15:30:13 +09:00
bbb5d68c4c
merge: 00001KVZSGT14 remote runtime registry 2026-06-26 15:29:18 +09:00
f19ed64feb
ticket: approve remote runtime registry 2026-06-26 15:29:18 +09:00
2d263278e6
ticket: record remote runtime debug redaction fix 2026-06-26 15:27:57 +09:00
38ff7d8f80
fix: redact observation source debug output 2026-06-26 15:27:08 +09:00
1bdb8f8a73
ticket: request remote runtime debug redaction 2026-06-26 15:21:40 +09:00
11f53c197a
ticket: record remote runtime implementation 2026-06-26 15:16:41 +09:00
aeb12b3b8e
feat: add remote runtime registry source 2026-06-26 15:15:29 +09:00
71198821ae
ticket: start remote runtime registry 2026-06-26 14:50:34 +09:00
ec4ada9464
ticket: accept remote runtime registry 2026-06-26 14:49:45 +09:00
815b169757
ticket: record embedded runtime cleanup 2026-06-26 14:48:02 +09:00
5c592938f4
ticket: mark embedded runtime registry done 2026-06-26 14:47:18 +09:00
e0cc7acf13
merge: 00001KVZSGT0Q embedded runtime registry 2026-06-26 14:46:31 +09:00
3d03ebccf8
ticket: approve embedded runtime registry 2026-06-26 14:46:31 +09:00
4616eb7254
ticket: record embedded runtime implementation 2026-06-26 14:41:23 +09:00
c820928592
feat: add embedded workspace runtime registry 2026-06-26 14:40:07 +09:00
a533d15bc6
ticket: start embedded runtime registry 2026-06-26 14:19:39 +09:00
7f312f1f6e
ticket: accept embedded runtime registry 2026-06-26 14:18:50 +09:00
bb8e09afa1
ticket: record websocket observation cleanup 2026-06-26 14:16:59 +09:00
35a5cf2887
ticket: mark websocket observation proxy done 2026-06-26 14:16:19 +09:00
ae0f0d1d96
merge: 00001KVZKSTJT websocket observation proxy 2026-06-26 14:15:11 +09:00
009d59b3ee
ticket: approve websocket observation proxy 2026-06-26 14:15:11 +09:00
9eaaedd08c
ticket: record websocket diagnostic fixes 2026-06-26 14:11:03 +09:00
8cc9a594f7
fix: preserve runtime websocket diagnostics 2026-06-26 14:10:08 +09:00
e67d884d62
ticket: request websocket diagnostic mapping fixes 2026-06-26 14:02:52 +09:00
6aba7dbbe0
ticket: record websocket observation implementation 2026-06-26 13:56:13 +09:00
9807accaf0
feat: add worker observation websocket proxy 2026-06-26 13:54:55 +09:00
d3c9995e25
ticket: start websocket observation proxy 2026-06-26 13:23:32 +09:00
0c6d603128
ticket: accept websocket observation proxy 2026-06-26 13:22:34 +09:00
5e7cd8f3a8
ticket: record rest server cleanup 2026-06-26 13:20:40 +09:00
82850c344a
ticket: mark worker runtime rest server done 2026-06-26 12:27:28 +09:00
660b07e8d7
merge: 00001KVZKSTE2 worker runtime rest server 2026-06-26 12:24:04 +09:00
15b3f002a3
ticket: approve worker runtime rest server 2026-06-26 12:24:04 +09:00
336f607536
ticket: record rest server binary fix 2026-06-26 12:21:34 +09:00
d0db32fa6a
fix: add worker runtime REST process binary 2026-06-26 12:20:37 +09:00
a9fe199510
ticket: request rest server process wrapper 2026-06-26 12:14:49 +09:00
526ef640f0
ticket: record worker runtime rest server implementation 2026-06-26 12:10:55 +09:00
5b0d6551fa
ticket: record sequential cleanup 2026-06-26 12:09:07 +09:00
f43a6b8401
feat: add worker runtime REST server 2026-06-26 05:48:23 +09:00
8f67bd4d3e
ticket: mark runtime registry foundation done 2026-06-26 05:44:33 +09:00
fb023aab53
merge: 00001KVZKSV6C runtime registry foundation 2026-06-26 05:41:15 +09:00
749fe5d090
ticket: approve runtime registry foundation 2026-06-26 05:41:15 +09:00
7ea5568114
ticket: record runtime registry authority fix 2026-06-26 05:38:38 +09:00
15c2c38710
ticket: start worker runtime rest server 2026-06-26 05:38:09 +09:00
523b04d391
ticket: route websocket runtime queue chain 2026-06-26 05:37:09 +09:00
75a458ddd9
ticket: queue 00001KW04A8K6 2026-06-26 05:34:42 +09:00
22733deb15
ticket: queue 00001KVZSGT14 2026-06-26 05:34:35 +09:00
3a76967365
ticket: queue 00001KVZ9JGK0 2026-06-26 05:34:27 +09:00
7803a170b5
ticket: queue 00001KVZKSTJT 2026-06-26 05:34:20 +09:00
52f0099f74
ticket: ready websocket proxy and web console 2026-06-26 05:30:38 +09:00
ee8fa17abd
merge: orchestration planning returns
# Conflicts:
#	.yoi/tickets/00001KVZKSTJT/item.md
#	.yoi/tickets/00001KVZKSTJT/thread.md
2026-06-26 05:28:20 +09:00
471dc5bc52
ticket: refine websocket proxy planning 2026-06-26 05:26:33 +09:00
127bc18bd7
ticket: return web console stream planning 2026-06-26 05:23:24 +09:00
51d558a7a5
ticket: return websocket stream planning 2026-06-26 05:21:48 +09:00
15abcf6782
merge: orchestration runtime updates 2026-06-26 05:10:58 +09:00
243fb40092
ticket: ready runtime websocket stream 2026-06-26 05:10:54 +09:00
f89552cafd
ticket: update runtime migration planning 2026-06-26 04:59:15 +09:00
7110e078cd
ticket: mark worker runtime fs store done 2026-06-26 04:49:07 +09:00
36ff72385c
merge: 00001KVZKST83 worker runtime fs store 2026-06-26 04:46:07 +09:00
8d7ab0c053
ticket: approve worker runtime fs store 2026-06-26 04:46:07 +09:00
d7c4396cd3
fix: scope workspace worker lookup by runtime 2026-06-26 04:45:22 +09:00
fb8dc9fe51
ticket: record worker runtime fs store implementation 2026-06-26 04:41:55 +09:00
4071343996
feat: add worker runtime fs store 2026-06-26 04:40:58 +09:00
150d5c49eb
ticket: request runtime registry authority fix 2026-06-26 04:37:50 +09:00
f6fe9fba7f
ticket: record runtime registry implementation 2026-06-26 04:33:14 +09:00
f6fd7b6323
feat: add workspace runtime registry source boundary 2026-06-26 04:31:59 +09:00
928074fd64
ticket: resume accepted worker runtime branches 2026-06-26 04:25:03 +09:00
7d9fed8144
ticket: record spawn launcher blocker 2026-06-26 01:58:53 +09:00
40d4138068
ticket: accept next worker runtime branches 2026-06-26 01:56:16 +09:00
07a913f51f
ticket: record worker runtime core cleanup 2026-06-26 01:54:24 +09:00
31c8d99187
ticket: mark worker runtime core done 2026-06-26 01:53:52 +09:00
56bdf95580
merge: 00001KVZBCQH4 worker runtime core 2026-06-26 01:52:55 +09:00
138b1fd860
ticket: approve worker runtime core 2026-06-26 01:52:50 +09:00
6a17366fcf
ticket: record worker runtime lifecycle fix 2026-06-26 01:50:53 +09:00
fbd358a195
fix: keep worker terminal lifecycle stable 2026-06-26 01:50:11 +09:00
9877a20778
ticket: record worker runtime continuation authority 2026-06-26 01:49:58 +09:00
593db95175
fix: update nix cargo hash 2026-06-26 01:36:57 +09:00
9b2cae32ea
feat: add memory worker runtime crate 2026-06-26 01:31:09 +09:00
114 changed files with 21762 additions and 877 deletions

View File

@ -1 +1,5 @@
{"id":"orch-plan-20260625-164513-1","ticket_id":"00001KVZ9JGK0","kind":"blocked_by","related_ticket":"00001KVZSGT0Q","note":"Queue routing checked after Dashboard Queue. Backend internal Companion Runtime/Web Console depends on embedded worker-runtime Backend Registry connection `00001KVZSGT0Q`, which is still queued and itself blocked by earlier worker-runtime/core/Backend foundation dependencies. Do not start MVP implementation until that dependency chain is completed.","author":"yoi-orchestrator","at":"2026-06-25T16:45:13Z"}
{"id":"orch-plan-20260625-203613-2","ticket_id":"00001KVZ9JGK0","kind":"blocked_by","related_ticket":"00001KVZKSTJT","note":"Queue routing checked after requeue. Companion Web Console MVP depends on WebSocket/event-stream transport decision/proxy `00001KVZKSTJT` and backend embedded runtime connection. `00001KVZKSTJT` is queued/blocked by REST command server, so this Ticket remains queued.","author":"yoi-orchestrator","at":"2026-06-25T20:36:13Z"}
{"id":"orch-plan-20260626-054930-3","ticket_id":"00001KVZ9JGK0","kind":"waiting_capacity_note","note":"Web Console MVP is left queued while remote Runtime process connection `00001KVZSGT14` is accepted/inprogress. Although embedded Runtime and WS proxy are done, Web Console work would touch similar Backend/API surfaces and should wait until remote source routing stabilizes.","author":"yoi-orchestrator","at":"2026-06-26T05:49:30Z"}
{"id":"orch-plan-20260626-063306-4","ticket_id":"00001KVZ9JGK0","kind":"waiting_capacity_note","note":"Web Console MVP is left queued while Profile/config bundle sync `00001KVZQHPNY` is accepted/inprogress. Web Console will likely touch worker creation/profile selection and Backend API surfaces; start after bundle sync branch is reviewed/merged/done.","author":"yoi-orchestrator","at":"2026-06-26T06:33:06Z"}
{"id":"orch-plan-20260626-074131-5","ticket_id":"00001KVZ9JGK0","kind":"accepted_plan","note":"Dependencies are done: embedded Runtime registry `00001KVZSGT0Q`, WebSocket observation proxy `00001KVZKSTJT`, and config bundle sync `00001KVZQHPNY`. No active inprogress remains.","accepted_plan":{"summary":"Backend internal Runtime 上の toolsなし Companion Worker と Web Console MVP を追加する。Backend API で status/transcript/message send を提供し、Web UI で message round-trip を表示する。raw provider credential/socket/session/runtime path は Browser に出さず、full TUI parity/tool UI/FS-shell authority は扱わない。","branch":"work/00001KVZ9JGK0-web-console-mvp","worktree":"/home/hare/Projects/yoi/.worktree/00001KVZ9JGK0-web-console-mvp","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/workspace-server`, `web/workspace`, `resources/prompts` と必要最小 Cargo/package files の write scope を委譲する。reviewer Worker は read-only で authority non-leak、toolsなし Companion、prompt resource boundary、stream/transcript semantics、backend API/UI tests を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-26T07:41:31Z"}

View File

@ -1,6 +1,14 @@
{
"version": 1,
"relations": [
{
"ticket_id": "00001KVZ9JGK0",
"kind": "depends_on",
"target": "00001KVZKSTJT",
"note": "Companion Web Console MVP has response stream / transcript projection choices and must not fix WS/SSE/polling behavior before `00001KVZKSTJT` resolves the WebSocket/event-stream transport design decision.",
"author": "yoi-orchestrator",
"at": "2026-06-25T20:22:58Z"
},
{
"ticket_id": "00001KVZ9JGK0",
"kind": "depends_on",

View File

@ -1,11 +1,11 @@
---
title: 'Backend内蔵Companion RuntimeとWeb Console MVP'
state: 'queued'
state: 'closed'
created_at: '2026-06-25T11:45:17Z'
updated_at: '2026-06-25T16:45:24Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T16:44:45Z'
queued_at: '2026-06-25T20:34:27Z'
---
## 背景

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -59,4 +59,375 @@ Escalate if:
- Companion MVP を `00001KVZSGT0Q` 完了前に独立 spike する human decision がある。
- Backend internal Runtime foundation の scope が Companion MVP requirements を満たさない。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-25T20:23:10Z from: queued to: planning reason: web_console_stream_transport_decision_missing field: state -->
## State changed
ユーザー指摘により queued から planning に戻す。
Missing decision / information:
- 本 Ticket は Web Console MVP の conversation/transcript model で「request/response 完了後に transcript を返す」または「SSE / streaming endpoint」を実装時に選んでよいとしており、実質的に WS/SSE/polling/streaming の transport 方針を固定し得る。
- これは `00001KVZKSTJT` で決定すべき WebSocket/event-stream transport 設計点であり、未決定のまま queued に置くのは不適切。
Context checked:
- Ticket body: Web Console UI、Companion message API、assistant response 取得または stream、conversation/transcript projection、Safety/authority。
- Existing relation: `00001KVZSGT0Q` への dependency。
- Added relation: `00001KVZKSTJT` への `depends_on` を追加し、WS/SSE/polling transport decision が解決するまで本 Ticket を blocker 付き planning として扱う。
- `00001KVZKSTE2` は REST command server であり、SSE/WebSocket event stream server は Non-goal と明記されているため、この差し戻し対象ではない。
Why implementation latitude is insufficient:
- Web Console の response delivery を request/response、SSE、WebSocket、polling のどれに寄せるかは後続 API/UI/Backend runtime integration の binding decision であり、Coder の local tactic として固定すべきではない。
Next planning question/action:
- `00001KVZKSTJT` で WebSocket/event-stream transport の採否、Backend-owned client / Browser-facing projection / cursor semantics / busy/error behavior を決める。
- その決定に基づいて、本 Ticket の conversation/transcript model と Web API acceptance criteria を再同期してから ready/queued に戻す。
---
<!-- event: intake_summary author: hare at: 2026-06-25T20:30:38Z -->
## Intake summary
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-25T20:30:38Z from: planning to: ready reason: cli_state field: state -->
## State changed
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: workspace-panel at: 2026-06-25T20:34:27Z from: ready to: queued reason: queued field: state -->
## State changed
Ticket を `workspace-panel` が queued にしました。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-25T20:36:54Z -->
## Decision
Routing decision: blocked_by_dependency_or_missing_authority
Reason:
- Dashboard Queue 後に Ticket / relations / workspace state を確認した。
- 本 Ticket は Web Console MVP であり、WebSocket/event-stream transport/proxy `00001KVZKSTJT` と Backend embedded Runtime connection `00001KVZSGT0Q` を前提にする。
- `00001KVZKSTJT` は queued/blocked、`00001KVZSGT0Q` も Backend Registry foundation chain 待ち。Web Console を先に始めると response delivery / stream semantics を UI/API 側で先取りして固定するため開始しない。
Evidence checked:
- Ticket body: Companion Runtime/Web Console MVP、message API、transcript/stream response choice、Safety/authority。
- Relations: `depends_on -> 00001KVZKSTJT``depends_on -> 00001KVZSGT0Q`
- Orchestration plan: blocker record `orch-plan-20260625-203613-1` を追加。
Next action:
- 本 Ticket は queued のまま待機。
- `00001KVZKSTJT``00001KVZSGT0Q` が done になった後、Web Console MVP の acceptance criteria を再確認して routing する。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-26T07:41:53Z -->
## Decision
Routing decision: implementation_ready
Reason:
- Dependencies are done: `00001KVZSGT0Q` embedded Runtime connection、`00001KVZKSTJT` WebSocket observation proxy、`00001KVZQHPNY` config bundle sync。
- Current `inprogress` is 0. Web Console MVP can now build on stable Backend internal Runtime / Worker create / transcript / WS/proxy foundations.
- Ticket body has concrete backend API, Web UI, safety/authority, Non-goals, and validation requirements.
Evidence checked:
- Ticket body: Backend internal Companion runtime, conversation/transcript model, Web API, Web Console UI, Runtime/LLM integration, Safety/authority, acceptance criteria。
- Relations: depends_on `00001KVZSGT0Q` and `00001KVZKSTJT`, both done.
- Orchestration plan: accepted plan `orch-plan-20260626-074131-5` recorded.
- Workspace state: orchestration worktree clean; no spawned child Workers currently active.
IntentPacket:
Intent:
- Backend internal Runtime 上に toolsなし Companion Worker を作成・保持し、Web frontend から status/transcript/message send/response display ができる Console MVP を実装する。
Binding decisions / invariants:
- Companion v0 は workspace filesystem / shell / git / Ticket mutation authority を持たない。
- Browser は raw provider credential、socket path、session path、runtime file path、Runtime direct endpoint/token を扱わない。
- Backend API / WS/projection を authority とし、local session file / Pod socket を直接読まない。
- Prompt prose は Rust 直書きではなく `resources/prompts` など prompt resource boundary に置く。
- v0 は full TUI parity / tool call UI / file viewer / diff viewer / thinking block grouping / multi Worker attach を実装しない。
- Long-running request 中の追加 message は single-flight / busy reject でよい。
Requirements / acceptance criteria:
- Backend internal runtime 上に Companion Worker が存在し、runtime/worker API から確認できる。
- Web frontend から Companion status / transcript projection を取得できる。
- Web Console UI から user message を送信できる。
- Companion が LLM response を生成し、Web UI に表示される、または v0実装上の provider-less/mock boundary が明確で reviewer が確認できる。
- v0 Companion は filesystem / shell / git / Ticket mutation tools を持たない。
- Provider busy/error/timeout/cancelled が typed error/UI state で扱われる。
- Focused backend/frontend tests or manual validation notes are present.
Implementation latitude:
- Request/response completion vs existing WS/projection usageの具体方式は Coder が既存 foundation に合わせて選べる。ただし `00001KVZKSTJT` の Backend-owned observation/proxy境界を壊さない。
- v0 LLM/provider integration が重すぎる場合は、Backend internal Runtimeの現在能力内で最小 toolsなし conversational round-trip を成立させ、未実装 provider execution boundaryを明確に報告すること。
- UI route/layout/component naming は existing `web/workspace` style に合わせる。
Escalate if:
- Filesystem/shell/git/Ticket mutation authority が必要になる。
- Browser に Runtime/provider credentials や raw path を渡す必要が出る。
- Full TUI console parity or tool-call UI が必要になる。
- Existing worker-runtime cannot generate a real LLM response without broad worker/engine integration and acceptance criteria cannot be satisfied honestly.
Validation:
- `cargo fmt --all`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `cd web/workspace && deno task check`
- `cd web/workspace && deno task build`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Authority leakage to Browser or Companion Worker。
- Hidden context injection instead of normal conversation history。
- Prompt prose embedded in Rust instead of prompt resource。
- UI claiming live LLM behavior if implementation is actually mock/provider-less。
- Over-scoping into full TUI parity/tool UI。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T07:42:06Z from: queued to: inprogress reason: routing_accepted_after_backend_runtime_foundation_done field: state -->
## State changed
Routing decision: implementation_ready。
Embedded Runtime connection、WebSocket observation proxy、Profile/config bundle sync は done。Ticket body / relations / workspace state / accepted plan を確認し、Backend internal Companion Web Console MVP は unblocked と判断した。accepted plan と IntentPacket は thread / orchestration plan に記録済み。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T07:43:09Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KVZ9JGK0-web-console-mvp`
- Branch: `work/00001KVZ9JGK0-web-console-mvp`
- Coder Worker spawned: `yoi-coder-00001KVZ9JGK0-web-console`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `crates/workspace-server/**`, `web/workspace/**`, `resources/prompts/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` if dependency/package changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Queued capacity note:
- `00001KW04A8K6` remains queued while Web Console MVP is inprogress because both are UI/control-surface consumers of the new Runtime APIs; TUI migration should start after this branch is reviewed/merged/done.
---
<!-- event: implementation_report author: yoi-coder-00001KVZ9JGK0-web-console at: 2026-06-26T08:02:43Z -->
## Implementation report
Implementation report:
実装完了。指定 worktree / branch 上で commit 済み。
Commit:
- `f3ad9c96b3fd48b5afce2a46b9c46efc5dce16f6 feat: add workspace companion console MVP`
変更概要:
### Backend
変更ファイル:
- `crates/workspace-server/src/companion.rs`
- `crates/workspace-server/src/lib.rs`
- `crates/workspace-server/src/server.rs`
- `resources/prompts/worker/web_companion_providerless.md`
実装内容:
- Backend 内部の tools-less Companion Console 境界を追加。
- `WorkspaceApi` 初期化時に `embedded-worker-runtime` 上へ `workspace_companion` Worker を spawn。
- runtime / worker API の `/api/workers` から visible。
- v0 capabilities は input / bounded transcript projection のみで、filesystem / shell / git / Ticket mutation authority は持たせていない。
- Companion 専用 API を追加:
- `GET /api/companion/status`
- `GET /api/companion/transcript?start=&limit=`
- `POST /api/companion/messages`
- `POST /api/companion/cancel`
- status / transcript / message response は typed state を返す:
- `ready`, `busy`, `error`, `timeout`, `cancelled`, `accepted`, `rejected`
- Browser へは Backend API projection のみ返し、raw Worker socket/session/runtime path や provider credentials は返さない設計。
- 実 LLM/provider 実行は既存 runtime foundation へ狭く接続できなかったため、fake せず provider-less/conversation boundary として実装。
- user message は backend-internal Worker へ input として記録。
- UI transcript には resource-defined assistant boundary response を返す。
- この制限は API diagnostics / UI transport description に明示。
- prompt / assistant boundary prose は Rust hard-code ではなく `resources/prompts/worker/web_companion_providerless.md` に配置。
### Web UI
変更ファイル:
- `web/workspace/src/routes/console/+page.svelte`
- `web/workspace/src/lib/workspace-sidebar/CompanionNavSection.svelte`
- `web/workspace/src/lib/workspace-sidebar/WorkspaceSidebar.svelte`
- `web/workspace/src/lib/workspace-sidebar/types.ts`
- `web/workspace/src/app.css`
実装内容:
- `/console` route を追加。
- Sidebar に `Companion Console` 導線を追加。
- Console UI:
- Companion status 表示
- transport / limitation 表示
- bounded transcript 表示
- user message composer
- Send / Refresh / Cancel UI
- busy / error / timeout / cancelled / rejected state 表示
- diagnostics 表示
Validation:
- `cargo fmt --all`: success
- `cargo test -p yoi-workspace-server`: success36 passed
- `cargo check -p yoi`: success
- `cd web/workspace && deno task check`: success0 errors / 0 warnings
- `cd web/workspace && deno task build`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- 実 LLM 応答は未接続。今回の実装は intentionally provider-less boundary であり、assistant response は resource-defined limitation response。
- 既存 worker-runtime へ安全に provider-backed completion を流すには、Worker engine integration / lifecycle / streaming boundary の追加設計が必要そう。
- transcript は v0 in-memory projection。server restart で Companion UI transcript は消える。
- Backend runtime 側には user input のみ記録され、assistant boundary response は Companion projection 側。
- busy は single-flight typed state として用意しているが、provider-less response は同期即時完了のため見える場面は限定的。
- UI は Console MVP に限定。tool call UI / thinking grouping / diff/file viewer / multi Worker attach は非対応。
---
<!-- event: review author: yoi-reviewer-00001KVZ9JGK0-web-console at: 2026-06-26T08:07:24Z status: approve -->
## Review: approve
Review result: approve
確認結果として、Ticket 意図と binding invariants を満たしていると判断する。
確認内容:
- Provider-less 境界は十分に正直。実 LLM 応答ではなく、`resources/prompts/worker/web_companion_providerless.md` の文面を返す実装で、UI/API 側も limitation / diagnostic / `backend_providerless_boundary` として表示している。
- Companion Worker は backend 内部の embedded runtime 上に作られ、runtime/worker API から見える構成。
- Companion v0 に filesystem / shell / git / Ticket mutation authority を付与している箇所は見当たらない。workspace/mount refs なし、conversation-focused の内部 Worker として扱われている。
- Browser に provider credential、socket path、session path、runtime file path、direct runtime endpoint/token、local session file path を渡す新規漏洩は見当たらない。
- `/api/companion/status`、`/transcript`、`/messages`、`/cancel` と Web `/console` は status / transcript / send / cancelled/error/busy 系状態を typed projection として扱っている。
- Prompt prose は Rust hard-code ではなく resource boundary に置かれている。
- UI は full TUI parity、tool/file/diff viewer、thinking grouping、multi attach へ広がっておらず、MVP 範囲に収まっている。
- Backend の focused tests と、報告済みの `cargo test/check`、frontend `deno task check/build`、`git diff --check`、`nix build` はこの変更範囲には十分。
補足リスク:
- provider-less v0 では backend Worker transcript は主に user message 記録で、assistant limitation response は Companion projection 側に出る設計。現状は source/diagnostic 付きなので許容するが、実 LLM 接続時は Worker transcript との永続的一貫性を再検討した方がよい。
- busy reject は型として存在するが、将来の長時間 LLM 実行時には即時 reject/timeout 挙動を改めて検証する必要がある。
検証:
- read-only の静的確認と `git diff --check` 相当の確認。テスト/ビルドはファイル生成を避けるため再実行せず、報告内容と実装・テスト追加を照合した。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T08:08:06Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZ9JGK0-web-console-mvp` を orchestration branch に merge 済み。
- Merge commit: `bf834e83 merge: 00001KVZ9JGK0 web console mvp`
Included implementation commit:
- `f3ad9c96b3fd48b5afce2a46b9c46efc5dce16f6 feat: add workspace companion console MVP`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p yoi-workspace-server`: success36 tests passed
- `cargo check -p yoi`: success
- `cd web/workspace && deno task check`: success0 errors / 0 warnings
- `cd web/workspace && deno task build`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。provider-less boundary honesty、authority non-leak、prompt resource boundary、typed UI/API state、MVP scope に blocker なし。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T08:08:16Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
Backend internal Companion Runtime / Web Console MVP の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `bf834e83 merge: 00001KVZ9JGK0 web console mvp`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p yoi-workspace-server`: success36 tests passed
- `cargo check -p yoi`: success
- `cd web/workspace && deno task check`: success
- `cd web/workspace && deno task build`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- Backend internal tools-less Companion Worker と provider-less Web Console MVP を追加。
- Full TUI parity / tool call UI / file/diff viewer / thinking grouping / multi Worker attach / real provider-backed Companion execution は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T08:09:07Z -->
## Implementation report
Cleanup report:
- Child Workers stopped one-by-one and scope reclaimed:
- `yoi-coder-00001KVZ9JGK0-web-console`
- `yoi-reviewer-00001KVZ9JGK0-web-console`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZ9JGK0-web-console-mvp`
- Child implementation branch removed:
- `work/00001KVZ9JGK0-web-console-mvp`
Operational note:
- StopPod was executed sequentially, not in parallel.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -1,8 +1,8 @@
---
title: 'worker-runtime core crateと組み込みRuntime APIを作る'
state: 'inprogress'
state: 'closed'
created_at: '2026-06-25T12:17:05Z'
updated_at: '2026-06-25T16:46:17Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T16:20:10Z'

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -555,3 +555,172 @@ Review result: request_changes
cargo/nix の再実行は、read-only 指示と上記 blocker があるため実施していません。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-25T16:49:53Z -->
## Decision
Human follow-up:
ユーザー確認: 「OK、よろしく」。
運用判断:
- 現在 queued の dependent Tickets は planning 差し戻し不要として扱う。
- ただし、未解消 dependency があるものは queued のまま待機し、依存が解消したものだけ再 routing して `queued -> inprogress` を個別に記録してから implementation side effect に進む。
- 途中で concrete missing decision / information が出た場合は、勝手に固定せず Ticket thread に理由を残して停止または planning return を行う。
- 現在の最優先は `00001KVZBCQH4` の reviewer blocker 解消、再 review、merge、validation、done 記録。
---
<!-- event: implementation_report author: yoi-coder-00001KVZBCQH4-worker-runtime at: 2026-06-25T16:50:47Z -->
## Implementation report
Follow-up implementation report after review request_changes:
対応内容:
- `crates/worker-runtime/src/runtime.rs`
- `Runtime::transition_worker` を修正。
- `Stopped` / `Cancelled` の terminal 状態にある Worker に反対側 terminal 操作が呼ばれても、既存 terminal 状態を保持し、同じ `event_id` で ack を返すようにした。
- 反対側 terminal 操作では追加 event を発生させない。
- 追加テスト:
- `stop_then_cancel_preserves_stopped_terminal_state`
- `cancel_then_stop_preserves_cancelled_terminal_state`
- summary count と event history が反対 terminal 操作で変化しないことを検証。
Commit:
- `fbd358a1 fix: keep worker terminal lifecycle stable`
Validation:
- `cargo fmt --all`: success
- `cargo test -p worker-runtime`: success (8 tests passed)
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success実行時点で dirty tree warning は出たが build 自体は成功)
Residual risks / review focus:
- terminal 状態への反対操作は reject ではなく「既存 terminal 状態を保持する idempotent 扱い」を選択。既存 API の ack semantics には自然だが、将来 UX/API で明示的 lifecycle conflict を出したい場合は typed error 方針へ切り替える余地がある。
- child worktree は commit 後 clean。
---
<!-- event: review author: yoi-reviewer-00001KVZBCQH4-worker-runtime at: 2026-06-25T16:52:45Z status: approve -->
## Review: approve
Review result: approve
確認結果:
- 前回 blocker の terminal lifecycle は解消されています。
- `Runtime::transition_worker` は既に `Stopped` / `Cancelled` の Worker に対して、反対側の terminal 操作を受けても state を上書きせず、既存 `status` / `last_event_id` を返し、新規 event も追加しません。
- 該当: `crates/worker-runtime/src/runtime.rs:353-384`
- 追加テストも妥当です。
- `stop_then_cancel_preserves_stopped_terminal_state`
- `cancel_then_stop_preserves_cancelled_terminal_state`
- summary counts と event history の非変化を確認しており、前回指摘した invariant を直接カバーしています。
- `runtime_id + worker_id` / `WorkerRef` authority 境界に regression は見当たりません。
- scope creep は見当たりません。変更範囲は `worker-runtime` crate、workspace 追加、`package.nix` cargoHash 更新に収まっています。
- `worker-runtime` の依存は `serde` / `thiserror` のみで、HTTP/WS/FS/server/client 系依存の追加はありません。
- `package.nix` の cargoHash 更新は維持されています。
実施した確認:
- `git status`, `git log`, `git show fbd358a1`
- `runtime.rs` の lifecycle 実装・追加テスト読解
- `worker-runtime` crate の依存/API 境界確認
- legacy pod/socket/session authority や HTTP/WS/FS 依存の grep 確認
- `git diff --check f8d3b1cc..HEAD`: success
補足: read-only 指示を優先し、`cargo test` / `nix build` は再実行していません。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T16:53:37Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZBCQH4-worker-runtime-core` を orchestration branch に merge 済み。
- Merge commit: `56bdf955 merge: 00001KVZBCQH4 worker runtime core`
Included implementation commits:
- `9b2cae32 feat: add memory worker runtime crate`
- `593db951 fix: update nix cargo hash`
- `fbd358a1 fix: keep worker terminal lifecycle stable`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime`: success8 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。前回 blocker だった `stop_worker` / `cancel_worker` terminal lifecycle invariant は解消済み。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-25T16:53:46Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
worker-runtime core crate の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `56bdf955 merge: 00001KVZBCQH4 worker runtime core`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime`: success8 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- `crates/worker-runtime` の memory-backed core Runtime API を追加。
- HTTP/WS/FS/Backend integration/config bundle sync は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T16:54:19Z -->
## Implementation report
Cleanup report:
- Child Workers stopped and scope reclaimed:
- `yoi-coder-00001KVZBCQH4-worker-runtime`
- `yoi-coder-00001KVZBCQH4-runtime-packaging`
- `yoi-reviewer-00001KVZBCQH4-worker-runtime`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZBCQH4-worker-runtime-core`
- Child implementation branch removed:
- `work/00001KVZBCQH4-worker-runtime-core`
Remaining note:
- Historical worker-rename child worktree remains separate and was not touched by this cleanup.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -1,8 +1,8 @@
---
title: 'pod crateをworker crateへ改名する'
state: 'done'
state: 'closed'
created_at: '2026-06-25T13:42:37Z'
updated_at: '2026-06-25T16:19:23Z'
updated_at: '2026-06-26T03:09:01Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T14:13:35Z'

View File

@ -0,0 +1,3 @@
Ticket `00001KVZG9BMS` (`pod crateをworker crateへ改名する`) はすでに `state: done` に到達していたため、workspace Dashboard から close しました。
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。

View File

@ -745,3 +745,62 @@ Escalate if:
- この state change は close ではなく `done` 記録。必要なら別途 close / cleanup を扱う。
---
<!-- event: state_changed author: hare at: 2026-06-25T19:32:51Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-25T19:32:51Z status: closed -->
## 完了
Ticket `00001KVZG9BMS` (`pod crateをworker crateへ改名する`) はすでに `state: done` に到達していたため、workspace Dashboard から close しました。
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
---
<!-- event: decision author: hare at: 2026-06-25T19:40:49Z -->
## Decision
Decision update: the pod -> worker rename must include a repository-wide audit of user/model-visible wording, not only Rust crate/type names.
Scope to check and update where the meaning is the new execution-unit Worker rather than intentionally legacy/internal compatibility:
- prompt resources under `resources/prompts`;
- TUI / Panel / Workspace UI labels and help text;
- CLI command/help/output strings;
- docs that describe current architecture or current user-facing behavior;
- tests/assertions tied to current prompt/UI/CLI text;
- README files for active crates;
- protocol/event names where they are active public API and not legacy compatibility.
Allowed remaining `pod` wording must be explicitly intentional legacy/internal context, such as historical reports, old compatibility notes, or on-disk/socket/session compatibility details that are being kept temporarily. The implementation should provide grep evidence for remaining active `pod`/`Pod` references and categorize them as replaced, legacy/internal, or historical.
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T03:09:01Z -->
## Implementation report
Late cleanup report:
- Stale child Workers stopped one-by-one and scope reclaimed:
- `yoi-coder-00001KVZG9BMS-worker-rename`
- `yoi-reviewer-00001KVZG9BMS-worker-rename`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZG9BMS-worker-crate-rename`
- Child implementation branch removed:
- `work/00001KVZG9BMS-worker-crate-rename`
Operational note:
- User noted StopPod should be run one-by-one rather than through parallel multi-tool execution; future cleanup will follow that.
---

View File

@ -1 +1,2 @@
{"id":"orch-plan-20260625-164354-1","ticket_id":"00001KVZKST83","kind":"blocked_by","related_ticket":"00001KVZBCQH4","note":"Queue routing checked after Dashboard Queue. FS store feature depends on worker-runtime core `00001KVZBCQH4`, which is currently inprogress and under review. Do not start FS persistence implementation until core API is reviewed/merged/done.","author":"yoi-orchestrator","at":"2026-06-25T16:43:54Z"}
{"id":"orch-plan-20260625-165525-2","ticket_id":"00001KVZKST83","kind":"accepted_plan","note":"`00001KVZBCQH4` が done になり dependency blocker 解消。Backend Registry foundation Ticket とは主対象が `crates/worker-runtime` vs `crates/workspace-server` で分離できるため並行受理候補。ただし Cargo/package lock conflict は merge時に Orchestrator が解消する。","accepted_plan":{"summary":"worker-runtime core done 後の optional `fs-store` feature slice。core no-default-features を維持しつつ FS persistence backend、layout、atomic writes、bounded reads、corrupt diagnostics、memory/FS tests を追加する。REST/Backend integration は扱わない。","branch":"work/00001KVZKST83-worker-runtime-fs-store","worktree":"/home/hare/Projects/yoi/.worktree/00001KVZKST83-worker-runtime-fs-store","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/worker-runtime` と lock/package files の write scope を委譲する。reviewer Worker は read-only で feature gating、atomic/corrupt diagnostics、runtime_id+worker_id authority、no standalone worker-store を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-25T16:55:25Z"}

View File

@ -1,8 +1,8 @@
---
title: 'worker-runtimeにFS永続化featureを追加する'
state: 'queued'
state: 'closed'
created_at: '2026-06-25T14:44:02Z'
updated_at: '2026-06-25T16:44:04Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T16:39:26Z'

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -58,4 +58,296 @@ Escalate if:
- `00001KVZBCQH4` の store/allocation boundary が FS feature の requirements を満たさない。
- FS feature を core Ticket に巻き戻す必要が出る。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-25T16:55:42Z -->
## Decision
Routing decision: implementation_ready
Reason:
- `00001KVZBCQH4` worker-runtime core は done。dependency blocker は解消済み。
- 本 Ticket は optional FS persistence feature であり、REST server / Backend Registry integration とは分離されている。
- queued/inprogress 再確認時点で `00001KVZKSV6C` を受理したが、主変更面は Backend Registry foundation (`crates/workspace-server`) と FS feature (`crates/worker-runtime`) で分離できる。Cargo/package files の機械的 conflict は Orchestrator merge時に解消可能と判断する。
Evidence checked:
- Ticket body: `fs-store` feature、runtime/worker scoped layout、atomic write、corrupt diagnostics、bounded reads、Non-goals。
- Relations: outgoing dependency `00001KVZBCQH4` は done。incoming remote Runtime Ticket は後続であり blocker ではない。
- Orchestration plan: accepted plan `orch-plan-20260625-165525-2` を記録。
- Workspace state: orchestration worktree clean。worker-runtime core merge/validation/done/cleanup 済み。
IntentPacket:
Intent:
- `worker-runtime` に optional `fs-store` feature と filesystem persistence backend を追加する。
Binding decisions / invariants:
- Feature disabled 時に core library は FS store dependency を強制しない。
- Store authority は `runtime_id + worker_id`。legacy pod path / socket path / session path を authority にしない。
- Standalone `worker-store` crate は作らない。`worker-runtime` 内 feature/module として実装する。
- REST command server / event stream / Backend integration / legacy Pod session migration / SQLite store は実装しない。
- Existing memory store/core tests を壊さない。
Requirements / acceptance criteria:
- `fs-store` feature がある。
- `cargo test -p worker-runtime --no-default-features` が通る。
- `cargo test -p worker-runtime --features fs-store` が通る。
- Worker create/state update/event append/transcript append/bounded read が FS store で動く。
- Runtime/Worker scoped layout、atomic write、directory creation、corrupt/missing diagnostics を扱う。
Implementation latitude:
- FS layout、module split、serialization structs、atomic write helper、diagnostics typeの詳細は Coder が既存 style に合わせて選べる。
- 旧 `pod-store` の atomic write pattern は参考にしてよいが、依存/責務移植は不要。
Escalate if:
- core Runtime store abstraction の大幅 rewrite が必要になる。
- REST/Backend integration を同時実装しないと acceptance を満たせないと判明する。
- `worker-store` standalone crate が必要に見える。
Validation:
- `cargo fmt --all`
- `cargo test -p worker-runtime --no-default-features`
- `cargo test -p worker-runtime --features fs-store`
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Feature gating failure causing core to pull FS dependencies。
- FS layout leaking legacy Pod/session authority。
- Atomic write / corrupt record handling が不十分。
- Memory store semantics regression。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-25T16:55:50Z from: queued to: inprogress reason: routing_accepted_after_worker_runtime_core_done field: state -->
## State changed
Routing decision: implementation_ready。
Dependency `00001KVZBCQH4` worker-runtime core は done。Ticket body / relations / workspace state / orchestration plan を確認し、optional FS store feature は unblocked と判断した。accepted plan と IntentPacket は thread / orchestration plan に記録済み。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T16:58:41Z -->
## Implementation report
Implementation startup blocked after acceptance:
- Worktree created:
- `/home/hare/Projects/yoi/.worktree/00001KVZKST83-worker-runtime-fs-store`
- branch `work/00001KVZKST83-worker-runtime-fs-store`
- Coder Worker was not spawned because the immediately preceding SpawnPod attempt for parallel accepted Ticket `00001KVZKSV6C` failed with:
- `yoi: unknown command pod`
Interpretation:
- No implementation code changes have been made in this worktree yet.
- This appears to be the same runtime/launcher compatibility issue after the Pod→Worker CLI rename.
- Because this Ticket was already accepted (`queued -> inprogress`) and worktree creation completed, it remains inprogress with a recovery note rather than being silently returned to queued.
Recovery needed:
- Restart/restore Orchestrator on a consistent runtime binary or repair the launcher compatibility path, then spawn the Coder Worker for this accepted worktree.
- If retry remains impossible, use an explicit human-authorized alternative implementation route.
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T19:24:59Z -->
## Implementation report
Implementation recovery / kickoff:
- User reported the previous SpawnPod failure was caused by a development environment variable forcing child launch from `target` binary. The variable was removed and installed binary is now used.
- Retried Coder Worker spawn for the already accepted worktree; spawn succeeded.
Active implementation:
- Worktree: `/home/hare/Projects/yoi/.worktree/00001KVZKST83-worker-runtime-fs-store`
- Branch: `work/00001KVZKST83-worker-runtime-fs-store`
- Coder Worker: `yoi-coder-00001KVZKST83-fs-store`
- Scope: read implementation worktree + non-recursive workspace root, write `crates/worker-runtime/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` only.
Next action:
- Wait for Coder implementation report, then route to reviewer.
---
<!-- event: implementation_report author: yoi-coder-00001KVZKST83-fs-store at: 2026-06-25T19:41:50Z -->
## Implementation report
Implementation report:
実装完了。merge/close/cleanup は未実施。
Commit:
- `407134399685537da9590d424df6b1db05402965 feat: add worker runtime fs store`
変更概要:
- `worker-runtime` に optional feature `fs-store = ["dep:serde_json"]` を追加。default feature は空のまま。
- `#[cfg(feature = "fs-store")]``fs_store` module を公開。
- `Runtime::with_fs_store(FsRuntimeStoreOptions)` を追加。
- 既存 store があれば復元。
- なければ Runtime scoped layout を作成して初期化。
- `FsRuntimeStore`, `FsRuntimeStoreOptions` を feature 有効時に re-export。
- `RuntimeBackendKind::FsStore` を feature 有効時のみ追加。
FS store:
- layout は `runtime_id + worker_id` authority ベース。
- `<root>/runtimes/<encoded runtime_id>/runtime.json`
- `<root>/runtimes/<encoded runtime_id>/events.jsonl`
- `<root>/runtimes/<encoded runtime_id>/workers/<encoded worker_id>/worker.json`
- `<root>/runtimes/<encoded runtime_id>/workers/<encoded worker_id>/transcript.jsonl`
- legacy pod path / socket / session path は authority として使用していない。
- Worker create / state update / event append / transcript append を Runtime mutation から永続化。
- snapshot 系は same-directory temp file + `sync_all` + rename の atomic write helper。
- event/transcript は JSONL append。
- restore 時に missing / corrupt / wrong runtime/worker scope を `RuntimeError::{StoreIo, StoreMissing, StoreCorrupt}` として診断。
- `FsRuntimeStore::read_events` / `read_transcript` で bounded read を提供。
テスト追加:
- `fs-store` feature 有効時のみ:
- create/send/stop 後に drop/reopen して worker/event/transcript が復元されること。
- direct store bounded read が Runtime read と一致すること。
- corrupt `runtime.json` と missing `worker.json` が診断されること。
変更ファイル:
- `crates/worker-runtime/Cargo.toml`
- `crates/worker-runtime/src/fs_store.rs`
- `crates/worker-runtime/src/runtime.rs`
- `crates/worker-runtime/src/lib.rs`
- `crates/worker-runtime/src/management.rs`
- `crates/worker-runtime/src/error.rs`
- `Cargo.lock`
- `package.nix`
Validation:
- `cargo fmt --all`: success
- `cargo test -p worker-runtime --no-default-features`: success8 passed
- `cargo test -p worker-runtime --features fs-store`: success10 passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- 永続化は per-file atomic write / append で、複数ファイルをまたぐ transaction ではない。途中 I/O failure 時の cross-file 整合性は review focus。
- FS store は Runtime API に統合しているが、REST / Backend integration / legacy Pod migration / SQLite は未実装。
- Event/transcript read は bounded output だが、現状は JSONL 全体を読み込んでから slice している。大規模 log での streaming pagination は将来最適化候補。
---
<!-- event: review author: yoi-reviewer-00001KVZKST83-fs-store at: 2026-06-25T19:46:00Z status: approve -->
## Review: approve
Review result: approve
確認結果として、Ticket intent / binding decisions / acceptance criteria を満たしていると判断する。
確認した点:
- `worker-runtime``fs-store = ["dep:serde_json"]` が追加され、`default = []` のまま維持されている。
- `fs_store` module / re-export / `Runtime::with_fs_store` / `RuntimeBackendKind::FsStore` は feature-gated。
- `cargo tree -p worker-runtime --no-default-features``serde_json` が入らないことを確認。`--features fs-store` では `serde_json` のみ追加される。
- FS layout は `runtimes/<encoded runtime_id>/workers/<encoded worker_id>/...` で、pod path / socket path / session path を authority にしていない。
- standalone `worker-store` crate、REST command server、Backend integration、legacy migration、SQLite store の追加は見当たらない。
- Runtime/Worker snapshot、event JSONL、transcript JSONL の永続化が実装され、runtime/worker 作成・state update・event append・transcript append・bounded read を満たしている。
- snapshot 書き込みは same-dir temp + `sync_all` + rename + directory sync。missing/corrupt は `RuntimeError::{StoreIo, StoreMissing, StoreCorrupt}` で診断される。
- memory backend 側は feature-off 時に persistence が no-op となり、既存 memory semantics を保つ構成。
- `package.nix``cargoHash` 更新も確認済み。
- `git diff --check` は問題なし。
補足:
- read-only 指示に従い、差分・実装・依存ツリー・scope creep の静的確認に留めた。`cargo test` / `nix build` は作業ツリーへ build artifact を作るため再実行せず、報告済み validation を前提確認として扱った。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T19:48:51Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZKST83-worker-runtime-fs-store` を orchestration branch に merge 済み。
- Merge commit: `36ff7238 merge: 00001KVZKST83 worker runtime fs store`
Included implementation commit:
- `407134399685537da9590d424df6b1db05402965 feat: add worker runtime fs store`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime --no-default-features`: success8 tests passed
- `cargo test -p worker-runtime --features fs-store`: success10 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。feature gating、runtime_id/worker_id layout、atomic write/corrupt diagnostics、scope boundary に blocker なし。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-25T19:49:00Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
worker-runtime FS store feature の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `36ff7238 merge: 00001KVZKST83 worker runtime fs store`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime --no-default-features`: success8 tests passed
- `cargo test -p worker-runtime --features fs-store`: success10 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- optional `fs-store` feature と FS persistence backend を追加。
- REST command server / Backend integration / legacy migration / SQLite store は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T03:09:01Z -->
## Implementation report
Cleanup report:
- FS store Coder/Reviewer child Workers were no longer present in the spawned-child registry at cleanup time, so no StopPod action was available for them.
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZKST83-worker-runtime-fs-store`
- Child implementation branch removed:
- `work/00001KVZKST83-worker-runtime-fs-store`
Operational note:
- User noted StopPod should be run one-by-one rather than through parallel multi-tool execution; future cleanup will follow that.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -1 +1,3 @@
{"id":"orch-plan-20260625-164410-1","ticket_id":"00001KVZKSTE2","kind":"blocked_by","related_ticket":"00001KVZBCQH4","note":"Queue routing checked after Dashboard Queue. REST command server depends on worker-runtime core `00001KVZBCQH4`, which is currently inprogress and under review. Do not start HTTP/server implementation until core API is reviewed/merged/done.","author":"yoi-orchestrator","at":"2026-06-25T16:44:10Z"}
{"id":"orch-plan-20260625-165601-2","ticket_id":"00001KVZKSTE2","kind":"waiting_capacity_note","note":"Core dependency is now done, but this REST/http-server Ticket is left queued in this acceptance pass because FS store and Backend Registry foundation were accepted first. `http-server` is likely to modify `crates/worker-runtime` feature/dependency/package surfaces and conflict with FS store work; start after FS store branch stabilizes or Orchestrator explicitly serializes merge conflict handling.","author":"yoi-orchestrator","at":"2026-06-25T16:56:01Z"}
{"id":"orch-plan-20260625-203533-3","ticket_id":"00001KVZKSTE2","kind":"accepted_plan","note":"Core dependency `00001KVZBCQH4` は done、FS store branch も done/merged 済みで previous waiting-capacity reason は解消。現在の inprogress `00001KVZKSV6C` は workspace-server foundation で主変更面が分離しているため並行受理可能。","accepted_plan":{"summary":"worker-runtime core/FS store done 後の optional `http-server` feature slice。REST command API と最小 process wrapper を worker-runtime に追加し、observation stream / Backend client integration / WebSocket は扱わない。","branch":"work/00001KVZKSTE2-worker-runtime-rest-server","worktree":"/home/hare/Projects/yoi/.worktree/00001KVZKSTE2-worker-runtime-rest-server","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/worker-runtime` と必要な Cargo/package files の write scope を委譲する。reviewer Worker は read-only で feature gating、REST handler delegation、Browser direct access exclusion、typed errors、scope creep absence を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-25T20:35:33Z"}

View File

@ -1,8 +1,8 @@
---
title: 'worker-runtimeにREST command serverを追加する'
state: 'queued'
state: 'closed'
created_at: '2026-06-25T14:44:02Z'
updated_at: '2026-06-25T16:44:20Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T16:39:39Z'

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -58,4 +58,367 @@ Escalate if:
- worker-runtime core の command/projection API が REST mapping に足りない。
- REST server concerns を core crate に混ぜないと acceptance を満たせないように見える。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-25T20:35:55Z -->
## Decision
Routing decision: implementation_ready
Reason:
- Dashboard Queue された dependent chain を再確認した。
- `00001KVZBCQH4` worker-runtime core は done、`00001KVZKST83` FS store feature も done/merged/validated 済み。以前の dependency/capacity blocker は解消した。
- 本 Ticket は REST command server であり、Non-goals に SSE / WebSocket event stream server が明記されている。WebSocket transport decision は `00001KVZKSTJT` 側で扱い、本 Ticket の implementation latitude には含めない。
- 現在の inprogress `00001KVZKSV6C``crates/workspace-server` foundation、こちらは `crates/worker-runtime` http-server feature が主対象で、conflict risk は bounded。
Evidence checked:
- Ticket body: `http-server` feature、Runtime process wrapper、REST command endpoints、typed JSON/errors、Browser direct Runtime access exclusion、Non-goals。
- Relations: outgoing dependency `00001KVZBCQH4` は done。incoming `00001KVZKSTJT`, `00001KVZSGT14` は後続。
- Orchestration plan: accepted plan `orch-plan-20260625-203533-3` を記録。
- Workspace state: orchestration worktree clean; current active foundation branch is separate surface.
IntentPacket:
Intent:
- `worker-runtime` に optional `http-server` feature と最小 Runtime process REST command API を追加する。
Binding decisions / invariants:
- REST handlers は `Runtime` lib API を呼ぶ wrapper とし、Worker semantics を二重実装しない。
- Browser は Runtime process に直接接続せず、Backend 経由の前提を docs/comments/API comments に残す。
- SSE / WebSocket event stream server、Backend HTTP client integration、dynamic Runtime registration、Web Console、full auth model は実装しない。
- `http-server` disabled 時に core library は HTTP server dependency を強制しない。
- Runtime authority は Runtime/Worker identity。legacy pod/socket/session path を public REST authority として設計しない。
Requirements / acceptance criteria:
- `http-server` feature と binary/process wrapper がある。
- `GET /v1/runtime`, `GET /v1/workers`, `GET /v1/workers/{worker_id}`, `POST /v1/workers`, `POST /v1/workers/{worker_id}/input`, `stop`, `cancel`, `GET transcript` を扱う。
- typed request/response/error shapes を持つ。
- runtime id / bind address / store selection を v0 config として扱える。
- minimal local token placeholder は可。ただし Browser に Runtime credential を渡す前提にしない。
Implementation latitude:
- HTTP framework/dependency、binary/module split、test helper、typed response shapes の詳細は Coder が選べる。
- FS store 使用は既存 feature を使う範囲まで。新しい persistence design は不要。
Escalate if:
- WebSocket/SSE observation 実装が必要になりそうな場合。
- Backend integration や dynamic runtime registration を同時に実装しないと REST command server が成立しない場合。
- Core Runtime API の大幅変更が必要になる場合。
Validation:
- `cargo fmt --all`
- `cargo test -p worker-runtime --no-default-features`
- `cargo test -p worker-runtime --features http-server`
- 必要に応じて `cargo test -p worker-runtime --features fs-store,http-server`
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Feature gating/dependency leakage。
- REST handler が Runtime semantics を複製すること。
- Browser direct Runtime access や credential leakage。
- WebSocket/SSE scope creep。
- package.nix cargoHash / lock consistency。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-25T20:36:02Z from: queued to: inprogress reason: routing_accepted_after_core_and_fs_store_done field: state -->
## State changed
Routing decision: implementation_ready。
Dependency `00001KVZBCQH4` worker-runtime core は done。以前の waiting-capacity reason だった FS store branch も done/merged/validated 済み。Ticket body / relations / workspace state / accepted plan を確認し、REST command server slice は unblocked と判断した。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T20:38:01Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KVZKSTE2-worker-runtime-rest-server`
- Branch: `work/00001KVZKSTE2-worker-runtime-rest-server`
- Coder Worker spawned: `yoi-coder-00001KVZKSTE2-rest-server`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `crates/worker-runtime/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix`.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Dependent queued Tickets:
- `00001KVZKSTJT`, `00001KVZSGT14`, `00001KW04A8K6`, and `00001KVZ9JGK0` remain queued with blocker notes until their prerequisite chain is done.
---
<!-- event: implementation_report author: yoi-coder-00001KVZKSTE2-rest-server at: 2026-06-26T03:10:50Z -->
## Implementation report
Implementation report:
実装完了。マージ・Ticket 更新・cleanup はしていない。
Commit:
- `f43a6b84011024b68c03fd5b4211ab427614683b feat: add worker runtime REST server`
変更ファイル:
- `crates/worker-runtime/Cargo.toml`
- optional feature `http-server` を追加。
- `axum`, `tokio`, `tower`, `serde_json` を feature-gated dependency として追加。
- `crates/worker-runtime/src/lib.rs`
- `#[cfg(feature = "http-server")] pub mod http_server;` を追加。
- core は HTTP 非依存で、REST adapter は optional である旨を module docs に追記。
- `crates/worker-runtime/src/http_server.rs`
- Runtime REST process adapter を新規追加。
- `Cargo.lock`
- `worker-runtime` optional dependency 反映。
- `package.nix`
- cargo vendor hash 更新。
追加 API / endpoints:
- `worker_runtime::http_server` module`http-server` feature 有効時)。
- `RuntimeHttpServerConfig`: `bind_addr`, `runtime_id`, `display_name`, `limits`, `store`, `local_token`
- `RuntimeHttpStoreSelection`: `Memory`; `Fs { root }``fs-store` feature 併用時のみ。
- `RuntimeHttpServer::bind(...)`, `RuntimeHttpServer::serve(...)`, `serve_configured_runtime_http(...)`, `serve_runtime_http(...)`, `runtime_http_router(...)`
- REST endpoints:
- `GET /v1/runtime`
- `GET /v1/workers`
- `GET /v1/workers/{worker_id}`
- `POST /v1/workers`
- `POST /v1/workers/{worker_id}/input`
- `POST /v1/workers/{worker_id}/stop`
- `POST /v1/workers/{worker_id}/cancel`
- `GET /v1/workers/{worker_id}/transcript`
Boundary notes:
- 各 handler は `Runtime` lib API に委譲し、Worker semantics は複製していない。
- Worker authority は server 側 Runtime id + path の `worker_id` から `WorkerRef` を組み立てる形。
- module docs / API comments に「Browser は Runtime process へ直接接続しない。Backend/proxy が intended client」という境界を明記。
- SSE / WebSocket / Backend integration / dynamic registration / Web Console / full auth model は未実装。
- `local_token` は backend-to-runtime 用の最小 bearer token placeholder のみ。
Validation:
- `cargo fmt --all`: success
- `cargo test -p worker-runtime --no-default-features`: success8 passed
- `cargo test -p worker-runtime --features http-server`: success11 passed
- `cargo test -p worker-runtime --features fs-store,http-server`: success13 passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Notes:
- `nix build` は初回 `cargoHash` 不一致で失敗。hash 更新後に再実行して成功。
Residual risks / review focus:
- REST response shapes は v0 として明示型を追加したが、外部 API として固定する前に Backend 側の envelope naming / field naming は確認余地あり。
- `stop` / `cancel` は空 body も許容し、body がある場合は `{ "reason": ... }` を受ける。Backend 側で厳密 JSON body 必須にしたい場合は調整可能。
- `local_token` は placeholder であり、Browser-facing credential model ではない。この境界が崩れていないか review focus。
- `tower` は router unit test helper 用にも使うが、`http-server` feature 配下の optional dependency。core / no-default build には入らない。
---
<!-- event: review author: yoi-reviewer-00001KVZKSTE2-rest-server at: 2026-06-26T03:14:43Z status: request_changes -->
## Review: request changes
Review result: request_changes
ブロッカー:
- Ticket 本文 / route packet では `worker-runtime/main.rs` または binary/process wrapper が必要。
- Ticket item: Runtime process wrapper / binary starts。
- Routing packet: “http-server feature と binary/process wrapper がある”。
- しかし実装は `crates/worker-runtime` の lib target のみ。
- `cargo read-manifest --manifest-path crates/worker-runtime/Cargo.toml` で target は `lib` のみ。
- `crates/worker-runtime/src/main.rs``[[bin]]` は存在しない。
- `RuntimeHttpServer::bind/serve` は library helper としては良いが、Runtime process binary が起動して REST endpoints を公開する受け入れ条件は未達。
確認できた良い点:
- `http-server` feature は optional で追加されており、`cargo tree -p worker-runtime --no-default-features` では HTTP deps 漏れは見えない。
- REST router は要求 endpoint を定義している。
- handlers は `Runtime` API に委譲しており、Worker semantics の大きな重複は見えない。
- Browser は Backend 経由で Runtime に直接接続しない旨の module/API comment がある。
- Runtime/Worker identity を使い、legacy pod/socket/session path を authority にしていない。
- typed response/error shape と RuntimeError の HTTP status mapping はある。
- SSE/WebSocket scope creep は見えない。
- `package.nix``cargoHash` 更新は commit に含まれている。
検証は read-only inspection 中心で、テスト/ビルドは再実行せず、報告済み結果を参照した。
---
<!-- event: implementation_report author: yoi-coder-00001KVZKSTE2-rest-server at: 2026-06-26T03:21:26Z -->
## Implementation report
Follow-up implementation report after review request_changes:
追加 commit:
- `d0db32fa6acb6efb5269de9793a63de92ef9eb4a fix: add worker runtime REST process binary`
修正内容:
- `crates/worker-runtime/Cargo.toml`
- `[[bin]]` target を追加。
- binary name: `worker-runtime-rest-server`
- path: `src/main.rs`
- `required-features = ["http-server"]`
- `crates/worker-runtime/src/main.rs`
- minimal Runtime REST process wrapper を追加。
Binary / process wrapper 概要:
- `http-server` feature 有効時に `worker-runtime-rest-server` binary target が出る。
- v0 config:
- `--bind <ADDR>`
- `--runtime-id <ID>`
- `--display-name <NAME>`
- `--store <memory|fs>`
- `--fs-root <PATH>``fs-store` feature 併用時のみ有効)
- `--local-token <TOKEN>`
- `--local-token-env <ENV>`
- `--max-transcript-projection-items <N>`
- `--max-event-batch-items <N>`
Boundary notes:
- binary は `http-server` required feature 付きなので、no-default build では HTTP deps / binary compile を強制しない。
- process wrapper は既存の `RuntimeHttpServer::bind/serve` を使い、REST handlers は従来通り Runtime API に委譲する。
- help / startup message に「trusted backend/proxy 向けであり Browser は Runtime process に直接接続しない」境界を明記。
- SSE / WebSocket / Backend integration / dynamic registration / full auth model は追加していない。
Manifest 確認:
- `cargo read-manifest --manifest-path crates/worker-runtime/Cargo.toml | jq '.targets'``lib` に加えて `bin` target `worker-runtime-rest-server`、`required-features = ["http-server"]` を確認。
Validation:
- `cargo fmt --all`: success
- `cargo test -p worker-runtime --no-default-features`: success8 passed
- `cargo test -p worker-runtime --features http-server`: successlib 11 passed, bin `src/main.rs` 3 passed
- `cargo test -p worker-runtime --features fs-store,http-server`: successlib 13 passed, bin `src/main.rs` 3 passed
- `cargo check -p worker-runtime --features http-server --bins`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- CLI は intentionally minimal。`clap` 等は追加せず手書き parser。
- `--local-token` は placeholder であり、Browser-facing credential model ではない。必要なら後続 Ticket で Backend 側 auth / proxy 境界として設計する前提。
- `fs` store は `fs-store` feature 併用時のみ有効で、`http-server` 単独 build では明示エラー。
---
<!-- event: review author: yoi-reviewer-00001KVZKSTE2-rest-server at: 2026-06-26T03:23:55Z status: approve -->
## Review: approve
Review result: approve
確認結果:
- 以前の blockerRuntime process wrapper / binary target 欠落)は解消済み。
- `crates/worker-runtime/Cargo.toml``[[bin]]` が追加され、`worker-runtime-rest-server` / `src/main.rs` / `required-features = ["http-server"]` になっている。
- `http-server` feature 必須の binary target なので、no-default/core library 側に HTTP server binary/deps を強制しない形。
- `src/main.rs``RuntimeHttpServer::bind(config)``server.serve().await` を呼ぶ薄い process wrapper で、REST semantics を再実装していない。
- v0 config は bind addr / runtime id / display name / memory/fs store selection / local token/env token / transcript/event limits を扱っており、Ticket 範囲として妥当。
- help・module comment・startup log で「Browser は Runtime process に直接接続せず trusted backend/proxy 経由」の境界が明記されている。
- SSE / WebSocket / Backend integration / dynamic registration / full auth model の追加は見当たらない。
実施した検証は read-only inspection と `cargo read-manifest` / `rg` / `git` による確認。報告済み cargo/nix validation は再実行していない。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T03:27:12Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZKSTE2-worker-runtime-rest-server` を orchestration branch に merge 済み。
- Merge commit: `660b07e8 merge: 00001KVZKSTE2 worker runtime rest server`
Included implementation commits:
- `f43a6b84011024b68c03fd5b4211ab427614683b feat: add worker runtime REST server`
- `d0db32fa6acb6efb5269de9793a63de92ef9eb4a fix: add worker runtime REST process binary`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime --no-default-features`: success8 tests passed
- `cargo test -p worker-runtime --features http-server`: successlib 11 tests + bin 3 tests passed
- `cargo test -p worker-runtime --features fs-store,http-server`: successlib 13 tests + bin 3 tests passed
- `cargo check -p worker-runtime --features http-server --bins`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。前回 blocker だった Runtime process wrapper / binary target 欠落は解消済み。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T03:27:22Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
worker-runtime REST command server の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `660b07e8 merge: 00001KVZKSTE2 worker runtime rest server`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime --no-default-features`: success8 tests passed
- `cargo test -p worker-runtime --features http-server`: successlib 11 tests + bin 3 tests passed
- `cargo test -p worker-runtime --features fs-store,http-server`: successlib 13 tests + bin 3 tests passed
- `cargo check -p worker-runtime --features http-server --bins`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- optional `http-server` feature、REST command API、minimal `worker-runtime-rest-server` process binary を追加。
- SSE / WebSocket / Backend integration / dynamic registration / Web Console / full auth model は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T04:20:31Z -->
## Implementation report
Cleanup report:
- Child Workers cleanup:
- `yoi-coder-00001KVZKSTE2-rest-server` was stopped one-by-one and scope reclaimed.
- `yoi-reviewer-00001KVZKSTE2-rest-server` StopPod retry reported `no spawned pod named`; `ListPods` then showed no spawned children remaining, so it was already gone from the spawned-child registry.
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZKSTE2-worker-runtime-rest-server`
- Child implementation branch removed:
- `work/00001KVZKSTE2-worker-runtime-rest-server`
Operational note:
- StopPod will continue to be executed one-by-one rather than through parallel multi-tool execution.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -0,0 +1,2 @@
{"id":"orch-plan-20260625-203613-1","ticket_id":"00001KVZKSTJT","kind":"blocked_by","related_ticket":"00001KVZKSTE2","note":"Queue routing checked. WebSocket observation proxy depends on REST command server `00001KVZKSTE2`, which has just been accepted and is now inprogress. Leave this Ticket queued until REST command API/process wrapper is reviewed/merged/done, so WS/proxy semantics build on stable command surface.","author":"yoi-orchestrator","at":"2026-06-25T20:36:13Z"}
{"id":"orch-plan-20260626-042150-2","ticket_id":"00001KVZKSTJT","kind":"accepted_plan","note":"Dependency REST command server `00001KVZKSTE2` は done。ユーザー指摘後に transport decision Ticket として再queuedされたため、WS/proxy semantics を本 Ticket で固定する。","accepted_plan":{"summary":"REST command server done 後の WebSocket observation proxy slice。Runtime process 側の worker-scoped observation stream と Backend proxy/client-facing stream boundary を実装する。REST command semantics や Web Console/TUI migration は扱わない。","branch":"work/00001KVZKSTJT-websocket-observation-proxy","worktree":"/home/hare/Projects/yoi/.worktree/00001KVZKSTJT-websocket-observation-proxy","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/worker-runtime` / `crates/workspace-server` と必要な Cargo/package files の write scope を委譲する。reviewer Worker は read-only で Runtime→Backend→Client proxy boundary、cursor/backlog semantics、Browser direct Runtime access exclusion、feature gating、REST/WS scope separation を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-26T04:21:50Z"}

View File

@ -1,48 +1,153 @@
---
title: 'worker-runtimeにWebSocket event stream serverを追加する'
state: 'planning'
title: 'Runtime/Backend WebSocket observation proxyを実装する'
state: 'closed'
created_at: '2026-06-25T14:44:02Z'
updated_at: '2026-06-25T16:42:14Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T20:34:20Z'
---
## 背景
Runtime command は REST/HTTP でよいが、Worker output / status / transcript update を Backend が追うには observation transport が必要になる。Runtime から Backend へ能動接続する相互型は v0 では採用せず、Backend が Runtime の event stream に接続する形にする。Browser は Runtime event stream に直接接続せず、Backend が proxy / projection する。
Runtime command は REST/HTTP でよいが、Worker output / status / transcript update を Backend / Web / future TUI が追うには observation transport が必要になる。Runtime から Backend へ能動接続する相互型は v0 では採用せず、Backend が Runtime の event stream に接続し、Client は Backend に接続する形にする。
この Ticket では `worker-runtime` process に WebSocket based observation server を追加する。SSE は将来追加してよいが、v0 の実装対象は Backend-owned WebSocket client が接続する Runtime event stream とする。command API とは分離する。
この Ticket では `Runtime -> Backend -> Client` の WebSocket observation proxy を実装する。`worker-runtime` process は Worker event stream を WebSocket で公開し、Backend は登録済み Runtime handle に対する WS client として購読し、Browser / future TUI は Backend-owned client-facing WS に接続する。Backend は Runtime endpoint / token / socket path / session path を Client に渡さない。
## 目的
- Backend が Runtime 内 Worker の output / status / transcript update を購読できる。
- Backend が購読した Runtime event を Client-facing WS として proxy できる。
- Runtime WS は新しい Worker output model を作らず、既存 `crates/protocol``protocol::Event` を observation payload として流す。
- Client は `runtime_id + worker_id` を authority として Backend WS に接続し、Runtime endpoint / credential / raw socket path を扱わない。
- Runtime WS / Backend WS は command channel ではなく observation channel とする。
- 後続の Web 権限制御は、Backend proxy/projection layer に observe/filter/redact/command-forward policy を差し込める seam を作るに留める。
## 要件
### Overall proxy model
- v0 の主対象は WebSocket proxy path とする。
- `Runtime -> Backend`: Runtime-owned Worker event stream。
- `Backend -> Client`: Backend-owned Worker observation stream。
- Backend は登録済み Runtime handle / endpoint capability から Runtime WS に接続する。
- Remote Runtime から event を受け取り Client-facing WS に流す経路までをこの Ticket の実装対象に含める。
- Embedded Runtime の登録・接続実装そのものはこの Ticket の主対象にしない。ただし Backend proxy 型は embedded / remote のどちらの Runtime handle にも後続で接続できる形にする。
- Runtime process discovery / remote process lifecycle / dynamic registration はこの Ticket の scope 外とし、既に Registry から接続可能な Runtime handle が得られる前提でよい。
### Runtime WS server
- `worker-runtime``ws-server` feature を追加する。
- Feature disabled 時、core library は stream server dependency を強制しない。
- Runtime process が Worker / Runtime events を WebSocket observation endpoint で公開できる。
- Endpoint は少なくとも以下のどちらかを扱う。
- `GET /v1/events/ws?cursor=...`
- Runtime process が Worker observation event を WebSocket endpoint で公開できる。
- v0 required endpoint は worker-scoped stream とする。
- `GET /v1/workers/{worker_id}/events/ws?cursor=...`
- Event stream は Runtime lib の event bus / event log を元にする。
- Event cursor / event id は Runtime local opaque id とする。
- Reconnect / cursor resume / bounded backlog / unknown cursor の扱いを typed にする。
- Runtime-wide stream は v0 non-goal とする。ただし型や event id 設計は将来の runtime-wide stream を妨げない。
- Runtime WS endpoint は Backend-facing internal API として扱い、Browser-facing protocol ではない。
- Runtime WS は user input / command / mutation を受け付けない。
- Runtime WS 上に `protocol::Method` tunnel や arbitrary operation frame を作らない。
- Connect 時に対象 Worker の initial projection として `protocol::Event::Snapshot` 相当を最初に送る。
- Snapshot 後の live update は Worker event bus が publish する `protocol::Event` payload を forward する。
### Runtime WS envelope / payload
- Runtime WS frame は Runtime-local envelope を持ち、payload として `protocol::Event` を含める。
- Envelope は少なくとも以下を持つ。
- Runtime-local opaque event id / cursor。
- worker id。
- `protocol::Event` payload。
- optional diagnostic / stream control kind。
- `protocol::Event``crates/protocol` を authority とし、Runtime WS 専用の並行 event model を作らない。
- Runtime WS は `protocol::Event` の variant allowlist / subset を定義しない。
- Runtime WS が Web 表示可否を判断しない。Browser / Web UI 向けの filter / redact / projection は Backend proxy/projection layer の責務とする。
- Runtime WS の除外境界は variant subset ではなく channel / authority 境界とする。
- `protocol::Method` tunnel を作らない。
- user input / command / mutation frame を受け付けない。
- raw provider trace / raw full session log / local filesystem paths / runtime credentials を authority payload として送らない。
- Method-specific reply を Runtime WS が passive event として合成しない。Worker event bus に publish された `protocol::Event` を forward する。
### Backend Runtime WS client
- Backend に Runtime WS client を実装する。
- Backend Runtime WS client は RuntimeRegistry から得た Runtime handle / connection capability を使い、Client から Runtime endpoint / credential を受け取らない。
- Backend Runtime WS client は Runtime-local envelope を読み、`runtime_id + worker_id + runtime_cursor + protocol::Event` として Backend 内部に渡す。
- Runtime unavailable、worker not found、unknown cursor、expired cursor、upstream disconnect、malformed frame を typed diagnostic として扱う。
- Backend client は upstream cursor を使って reconnect / resume できる。
- Upstream reconnect 時に exactly-once delivery は要求しない。Backend は event id / cursor で duplicate を扱えるようにする。
### Backend Client-facing WS proxy
- Backend は Client-facing Worker observation WS endpoint を公開する。
- v0 endpoint shape は実装時に既存 workspace-server routing と合わせて決めてよいが、Client-facing authority は `runtime_id + worker_id` とする。
- 例: `GET /api/runtimes/{runtime_id}/workers/{worker_id}/events/ws?cursor=...`
- Browser / future TUI は Runtime WS に直接接続せず、Backend WS に接続する。
- Backend WS frame は Backend-owned envelope を持ち、payload として `protocol::Event` を含める。
- Backend-owned envelope は少なくとも以下を持つ。
- Backend-local opaque cursor。
- runtime id。
- worker id。
- `protocol::Event` payload。
- optional diagnostic / stream control kind。
- Backend cursor は Client にとって opaque とする。実装は Runtime cursor を wrap / map してよいが、Client が Runtime-local cursor semantics に依存しないようにする。
- Backend proxy は v0 では原則 pass-through projection とし、`protocol::Event` を別 model に変換しない。
- Backend は Runtime WS event を raw tunnel せず、Backend-owned envelope / cursor / diagnostics を付与した proxy stream として出す。
### Cursor / backlog / ordering
- Runtime event id / cursor は Runtime local opaque id とする。
- Backend client-facing cursor は Backend local opaque id とする。
- Cursor は「最後に受け取った event id」を表し、resume 時はそれより後の event を送る。
- Delivery semantics は at-least-once とし、duplicate はあり得る。Backend / Client は id で de-dup できる。
- Ordering は worker-scoped stream 内で保持する。
- Bounded per-worker backlog を持ち、unknown cursor / expired cursor / worker not found / worker unavailable を typed close reason または stream diagnostic として返す。
- Unknown / expired cursor 時に raw session log 全体を暗黙送信して復旧しない。Backend / Client は fresh Snapshot から再同期する。
- Transcript projection polling endpoint と event stream の責務を分ける。
- Browser direct Runtime access は想定せず、Backend client が購読する。
### Permission seam / future policy boundary
- この Ticket の主目的は proxy の実装であり、full auth / permission model は実装しない。
- Backend proxy/projection layer に後続で policy を差し込める seam を作る。
- Worker observation を許可 / 拒否する。
- thinking / tool output / diagnostics などを表示 / redact する。
- Web origin から利用可能な action affordance を出す / 隠す。
- operation-capable command API への forward を許可 / 拒否する。
- v0 の seam は pass-through default でよい。具体的な user/role permission、multi-user auth、redaction rule set は後続 Ticket に残す。
- Web からの操作 block は Runtime WS ではなく Backend command API / Backend Web-facing proxy の責務とする。
## Non-goals
- REST command server implementation。
- Backend event proxy UI implementation。
- Embedded Runtime registration / direct-call implementation。
- Remote Runtime process lifecycle / discovery / dynamic registration。
- Browser-facing Web Console UI implementation。
- Full auth / permission model。
- Concrete redaction policy implementation。
- Runtime-initiated Backend push connection。
- Full exactly-once delivery。
- Browser-facing WebSocket protocol。
- Runtime-wide multi-worker stream implementation。
- Raw provider trace streaming。
- Raw session storage migration。
## 受け入れ条件
- `worker-runtime` に optional `ws-server` feature がある。
- Feature disabled でも `worker-runtime` core が compile できる。
- Runtime process exposes worker/runtime WebSocket event stream endpoint.
- Backend client can reconnect with cursor / last event id semantics at the protocol level.
- Unknown cursor / expired cursor / worker not found are typed errors or stream diagnostics.
- WebSocket event stream tests cover at least connect, event delivery, cursor resume, and worker-scoped filtering.
- Runtime process exposes worker-scoped WebSocket observation endpoint。
- Runtime WS frame envelope includes Runtime-local opaque event id / cursor, worker id, and `protocol::Event` payload。
- Runtime WS connect sends initial `protocol::Event::Snapshot` projection for the target Worker。
- Runtime WS live stream forwards Worker event bus `protocol::Event` payloads rather than a parallel Worker output model or Runtime-side event subset。
- Runtime WS does not create `protocol::Method` tunnel / command / mutation channels or synthesize request/reply events。
- Backend Runtime WS client can connect to a registered remote Runtime handle and receive Worker events。
- Backend Runtime WS client can reconnect with Runtime cursor / last event id semantics at the protocol level。
- Backend exposes Client-facing worker observation WS keyed by `runtime_id + worker_id`
- Client-facing WS frame envelope includes Backend-local opaque cursor, runtime id, worker id, and `protocol::Event` payload。
- Client-facing WS can proxy initial Snapshot and live Worker events received from upstream Runtime WS。
- Backend cursor is opaque to Client and does not expose Runtime endpoint / credential / raw socket / session path。
- Unknown cursor / expired cursor / worker not found / upstream runtime unavailable are typed errors or stream diagnostics。
- Backend proxy/projection layer has an explicit seam for later observe/command permission checks and redaction policy, with pass-through default in this Ticket。
- WebSocket proxy tests cover Runtime WS connect, initial Snapshot, live event delivery, Backend upstream consumption, Client-facing proxy delivery, cursor resume, duplicate-safe ids, expired/unknown cursor diagnostics, upstream disconnect diagnostics, and worker-scoped filtering。
- `cargo test -p worker-runtime --features ws-server` が通る。
- `cargo test -p yoi-workspace-server` が通る。
- `cargo check -p yoi` が通る。
- `git diff --check` が通る。
- `nix build .#yoi --no-link` が通る。

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -49,4 +49,526 @@ Before this can be ready, define the event model and protocol boundary concretel
- what is deliberately excluded from the stream, such as raw provider trace or raw full session log.
---
<!-- event: decision author: hare at: 2026-06-25T20:05:49Z -->
## Decision
Runtime WebSocket event stream は、新しい Worker output protocol を作らず `crates/protocol``protocol::Event` を Backend-facing observation payload として流す方針にする。Runtime WS は `protocol::Event` の variant allowlist / subset を定義せず、worker-scoped envelope に event id / cursor / worker id を付けて Worker event bus の `protocol::Event` を forward する。
Browser / Web UI は Runtime WS に直接接続しない。Backend が Runtime WS client になり、Browser-facing stream は Backend-owned projection layer を通す。この projection layer を、後続の Web 権限制御で observation allow/deny、thinking/tool output/diagnostic redaction、operation-capable command API forwarding allow/deny を差し込む境界にする。STJT では full auth model は実装せず、この seam を型と責務として作る。
---
<!-- event: intake_summary author: hare at: 2026-06-25T20:10:54Z -->
## Intake summary
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-25T20:10:54Z from: planning to: ready reason: cli_state field: state -->
## State changed
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-25T20:21:27Z from: ready to: planning reason: websocket_transport_decision_missing field: state -->
## State changed
ユーザー指示により planning に戻す。
Missing decision / information:
- WebSocket / event-stream transport は `00001KVZKSTJT` 自体で決定すべき設計点であり、未決定のまま ready/queue 対象として扱うのは不適切。
- 少なくとも、Backend-owned WebSocket client 方式を v0 で採用するか、SSE / polling / Backend proxy projection との責務分離をどう置くか、cursor/backlog/error semantics をどこまで固定するかを planning で再確認する必要がある。
Context checked:
- Ticket body: `worker-runtimeにWebSocket event stream serverを追加する``ws-server` feature、WebSocket observation endpoint、cursor resume、unknown/expired cursor diagnostics を実装対象としている。
- Relations: `00001KVZBCQH4``00001KVZKSTE2` に depends_on、`00001KVZSGT14` が本 Ticket に depends_on。
- Current state: 本 Ticket は queued ではなく `ready` だったが、WS を扱う予定の Ticket として routing/queue 前に設計判断へ戻す。
Why implementation latitude is insufficient:
- Transport choice / ownership boundary / Browser direct access exclusion / Backend proxy shape は local implementation tactic ではなく、後続 Backend/remote Runtime/Web Console の設計前提になる binding decision。
Next planning question/action:
- `worker-runtime` observation transport は v0 で WebSocket を採用するのか、それとも SSE/polling/Backend projection を優先するのか。
- WebSocket を採用する場合、Backend-owned client、cursor/backlog/unknown cursor、worker-scoped filtering、Browser-facing protocol non-goal の境界を明文化する。
- 後続 `00001KVZSGT14` など remote observation 依存 Ticket は、この判断後に readiness/relations を再確認する。
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-25T20:24:40Z from: ready to: planning reason: cli_state field: state -->
## State changed
State changed to `planning`.
---
<!-- event: decision author: hare at: 2026-06-25T20:25:52Z -->
## Decision
STJT の主目的を Runtime WS server 単体から `Runtime -> Backend -> Client` の WebSocket observation proxy に広げる。Remote Runtime から Backend Runtime WS client が `protocol::Event` を受け取り、Backend-owned client-facing WS で `runtime_id + worker_id` keyed stream として流すところまでをこの Ticket の実装対象に含める。
Backend proxy は v0 では pass-through projection を基本にし、`protocol::Event` を別 output model へ変換しない。一方で Browser / future TUI は Runtime WS に直接接続せず、Backend-owned cursor/envelope/diagnostic を持つ stream だけを見る。Runtime endpoint / credential / socket path / session path は Client-facing authority に出さない。
権限系はこの Ticket で full auth / permission / redaction rule を実装しない。Backend proxy/projection layer に、後続で observe allow/deny、thinking/tool output/diagnostic redaction、action affordance、command API forwarding allow/deny を差し込める seam を作るに留める。
---
<!-- event: intake_summary author: hare at: 2026-06-25T20:30:38Z -->
## Intake summary
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-25T20:30:38Z from: planning to: ready reason: cli_state field: state -->
## State changed
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: workspace-panel at: 2026-06-25T20:34:20Z from: ready to: queued reason: queued field: state -->
## State changed
Ticket を `workspace-panel` が queued にしました。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-25T20:36:24Z -->
## Decision
Routing decision: blocked_by_dependency_or_missing_authority
Reason:
- Dashboard Queue 後に Ticket / relations / workspace state を確認した。
- 本 Ticket は `00001KVZKSTE2` REST command server に depends_on。`00001KVZKSTE2` は本 routing pass で accepted され `inprogress` になった。
- WS observation proxy は Runtime process server surface と Backend proxy/client-facing stream を扱うため、REST command API/process wrapper の形が確定してから開始する。
Evidence checked:
- Ticket body: `Runtime -> Backend -> Client` WebSocket observation proxy、Runtime worker-scoped WS、Backend Runtime WS client、Client-facing WS、cursor/backlog/permission seam。
- Relations: outgoing `depends_on -> 00001KVZKSTE2`; incoming dependent Tickets include Web Console MVP, remote Runtime process, TUI migration。
- Orchestration plan: blocker record `orch-plan-20260625-203613-1` を追加。
Next action:
- 本 Ticket は queued のまま待機。
- `00001KVZKSTE2` が review/merge/validation/done になった後に再 routing する。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-26T04:22:18Z -->
## Decision
Routing decision: implementation_ready
Reason:
- `00001KVZKSTE2` REST command server は done。前回 blockerREST process wrapper/API surface 未確定)は解消済み。
- 本 Ticket はユーザー指摘後に `Runtime/Backend WebSocket observation proxy` として設計判断を反映し再queuedされた。Ticket thread には、Runtime WS は `protocol::Event` を observation payload として流し、Browser/future TUI は Runtime へ直接接続せず Backend-owned projection/proxy を見る、という binding decision が記録済み。
- queued/inprogress 再確認時点で inprogress は 0 件。後続 remote/TUI/Web Console Tickets は本 Ticket に依存しているため、本 Ticket を次に受理する。
Evidence checked:
- Ticket body: `Runtime -> Backend -> Client` WebSocket observation proxy、Runtime worker-scoped WS、Backend Runtime WS client、Client-facing WS、cursor/backlog/permission seam、Non-goals。
- Thread decisions: `protocol::Event` を payload authority とする、Runtime WS は command/mutation tunnel にしない、Backend projection/proxy seam を作る、full auth/redaction policy は後続。
- Relations: outgoing dependencies `00001KVZBCQH4` core と `00001KVZKSTE2` REST server は done。incoming remote/Web Console/TUI Tickets は後続。
- Orchestration plan: accepted plan `orch-plan-20260626-042150-2` を記録。
- Workspace state: orchestration worktree clean; no inprogress Ticket.
IntentPacket:
Intent:
- Runtime process の worker-scoped WebSocket observation stream と、Backend-owned client-facing WebSocket proxy boundary を実装する。
Binding decisions / invariants:
- Runtime WS は Backend-facing internal observation API。Browser/future TUI は Runtime WS に直接接続しない。
- Payload authority は `crates/protocol``protocol::Event`。Runtime WS 独自の parallel output model や variant allowlist/subset を作らない。
- Runtime WS は command/mutation/user input を受け付けず、`protocol::Method` tunnel を作らない。
- Backend client-facing WS は Backend-owned opaque cursor/envelope/diagnostic を持ち、Runtime endpoint/credential/socket/session path を Client に露出しない。
- v0 は worker-scoped stream。runtime-wide stream、full auth/permission/redaction policy、Web Console UI、TUI migration、remote process lifecycle/discovery は Non-goals。
- REST command semantics は既存 `http-server` implementation に委譲し、この Ticket で再実装しない。
Requirements / acceptance criteria:
- `worker-runtime` に optional `ws-server` feature がある。
- Feature disabled でも core compile が通る。
- Runtime process exposes `GET /v1/workers/{worker_id}/events/ws?cursor=...` style worker-scoped observation endpoint。
- Runtime WS envelope includes Runtime-local opaque cursor/event id, worker id, and `protocol::Event` payload。
- Connect sends initial `protocol::Event::Snapshot` projection, then forwards Worker event bus `protocol::Event` payloads。
- Backend Runtime WS client consumes Runtime envelope and preserves `runtime_id + worker_id + runtime_cursor + protocol::Event` internally。
- Backend exposes Client-facing worker observation WS keyed by `runtime_id + worker_id` with Backend-local opaque cursor/envelope。
- Unknown/expired cursor, worker not found, runtime unavailable, upstream disconnect, malformed frame are typed diagnostics/errors。
- Tests cover Runtime WS, Backend upstream client/proxy delivery, cursor resume/duplicate-safe IDs, diagnostics, and worker-scoped filtering.
Implementation latitude:
- Exact Rust module split, WebSocket dependency, envelope structs, test fixtures, and Backend route shape may follow existing workspace-server/worker-runtime style。
- Bounded backlog implementation can be in-memory v0, as long as cursor semantics and diagnostics are explicit.
- Permission seam can be pass-through default with types/hooks for later policy.
Escalate if:
- Implementing this requires full auth/redaction policy, Web Console UI, TUI migration, remote process lifecycle/discovery, or Runtime command channel changes。
- `protocol::Event` cannot be serialized/forwarded without changing protocol crate public semantics。
- Backend Registry/Runtime handle shape from previous Tickets is insufficient and would require a broad redesign.
Validation:
- `cargo fmt --all`
- `cargo test -p worker-runtime --features ws-server`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Accidentally creating a command/mutation tunnel over WS。
- Leaking Runtime endpoint/token/socket/session path to Client-facing WS。
- Creating a second output/event model instead of forwarding `protocol::Event` payload。
- Feature gating/dependency leakage。
- Cursor/backlog/diagnostic semantics being too vague for remote/TUI/Web Console follow-ups。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T04:22:27Z from: queued to: inprogress reason: routing_accepted_after_rest_server_done field: state -->
## State changed
Routing decision: implementation_ready。
Dependency `00001KVZKSTE2` REST command server は done。Ticket body/thread、relations、workspace state、accepted plan を確認し、Runtime/Backend WebSocket observation proxy は unblocked と判断した。accepted plan と IntentPacket は thread / orchestration plan に記録済み。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T04:23:22Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KVZKSTJT-websocket-observation-proxy`
- Branch: `work/00001KVZKSTJT-websocket-observation-proxy`
- Coder Worker spawned: `yoi-coder-00001KVZKSTJT-ws-proxy`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `crates/worker-runtime/**`, `crates/workspace-server/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix`.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Next action:
- Wait for Coder implementation report, then route to reviewer.
---
<!-- event: implementation_report author: yoi-coder-00001KVZKSTJT-ws-proxy at: 2026-06-26T04:56:04Z -->
## Implementation report
Implementation report:
実装完了。Ticket ファイル / project records は変更していない。merge / close / cleanup 前で停止。
Commit:
- `9807accaf08f4322763dd7cd3536baf3dab8d10e feat: add worker observation websocket proxy`
変更概要:
### worker-runtime
変更ファイル:
- `crates/worker-runtime/Cargo.toml`
- `crates/worker-runtime/src/observation.rs`
- `crates/worker-runtime/src/runtime.rs`
- `crates/worker-runtime/src/http_server.rs`
実装内容:
- optional feature `ws-server` を追加。
- `http-server` に加えて `axum/ws`, `protocol`, `futures`, `tokio/sync` を使用。
- feature 無効時の core compile も確認済み。
- Runtime 側に Worker-scoped observation backlog / bus を追加。
- Runtime-local opaque cursor: `wo_<hex sequence>`
- bounded in-memory backlog v0
- `observe_worker_event(worker_ref, protocol::Event)``protocol::Event` payload をそのまま observation bus に投入。
- Runtime HTTP server に worker-scoped WS endpoint を追加。
- `GET /v1/workers/{worker_id}/events/ws?cursor=...`
- Runtime WS frame:
- `RuntimeWorkerEventWsFrame::Event { envelope }`
- `RuntimeWorkerEventWsFrame::Diagnostic { diagnostic }`
- Runtime WS envelope:
- `cursor`
- `event_id`
- `worker_id`
- `payload: protocol::Event`
- 接続時に `protocol::Event::Snapshot` を初期 projection として送信。
- live update は observation bus の `protocol::Event` payload を転送。
- client からの text/binary 等の入力は `runtime.observation_only` diagnostic で終了。
- malformed cursor / unknown-or-expired cursor / worker not found / bus closed / lagged backlog などを typed diagnostic/error 化。
### workspace-server
変更ファイル:
- `crates/workspace-server/Cargo.toml`
- `crates/workspace-server/src/lib.rs`
- `crates/workspace-server/src/observation.rs`
- `crates/workspace-server/src/server.rs`
実装内容:
- Backend-owned observation proxy module を追加。
- Runtime WS client を追加。
- Runtime WS envelope を decode。
- 内部表現として `runtime_id + worker_id + runtime_cursor + protocol::Event` を保持。
- Backend client-facing WS endpoint を追加。
- `GET /api/runtimes/{runtime_id}/workers/{worker_id}/events/ws?cursor=...`
- Backend-local cursor/envelope を追加。
- Backend cursor: `bo_<hex sequence>`
- Runtime endpoint / credential / socket / session path は client-facing payload に出さない。
- Backend client-facing frame:
- `ClientWorkerEventWsFrame::Event { envelope }`
- `ClientWorkerEventWsFrame::Diagnostic { diagnostic }`
- Backend client-facing envelope:
- `cursor`
- `event_id`
- `runtime_id`
- `worker_id`
- `payload: protocol::Event`
- Backend source config は server 内部設定 `runtime_event_sources` として保持。
- unknown worker/runtime source, malformed/unknown cursor, upstream disconnect, malformed upstream frame, observation-only client input を typed diagnostic/error 化。
### workspace/root/package
変更ファイル:
- `Cargo.toml`
- `Cargo.lock`
- `package.nix`
内容:
- `tokio-tungstenite = "0.29"` を workspace dependency に追加。
- `package.nix``cargoHash` を更新。
Validation:
- `cargo fmt --all`: success
- `cargo check -p worker-runtime`: success
- `cargo test -p worker-runtime --features ws-server`: success14 lib tests + 3 bin tests + doctests
- `cargo test -p yoi-workspace-server`: success22 lib tests + bin/doctests
- `cargo check -p yoi`: success
- `git diff --check`: success
- `git diff --check --cached`: success
- `nix build .#yoi --no-link`: success
Review focus / residual risks:
- v0 backlog は in-memory bounded。process restart / memory eviction 後の cursor は unknown/expired 扱い。
- Runtime Snapshot projection は minimal projection。`protocol::Event::Snapshot` を使うが、entries / in-flight は現 Runtime adapter の範囲で空 projection。
- Backend source discovery は `runtime_event_sources` 内部 config seam。remote lifecycle/discovery や full registry redesign は Non-goals として未実装。
- Auth/redaction/policy は full 実装せず、後続拡張しやすい typed source/diagnostic/proxy boundary に留めた。
- Browser / future TUI には Backend endpoint のみを公開し、Runtime endpoint / credential / socket / session path は envelope に含めていない。
---
<!-- event: review author: yoi-reviewer-00001KVZKSTJT-ws-proxy at: 2026-06-26T05:02:45Z status: request_changes -->
## Review: request changes
Review result: request_changes
読取専用で `9807acc...` の実装を確認した。`protocol::Event` payload の pass-through、Runtime/Backend の envelope 分離、observation-only 入力診断、Client envelope から Runtime endpoint/token/socket/session path を出さない点、`worker-runtime` の `ws-server` cfg 境界は概ね Ticket 意図に沿っている。
ただし、以下は受け入れ条件上の blocker。
1. Backend Runtime WS client の upstream 診断が型を失っている
- `crates/workspace-server/src/observation.rs``RuntimeWsObservationClient::next_event` で、Runtime からの `RuntimeWorkerEventWsFrame::Diagnostic` をすべて `ObservationProxyError::UpstreamDisconnect` に畳み込んでいる。
- そのため Runtime 側の `runtime.cursor_unknown_or_expired` / `runtime.worker_not_found` 等が Client-facing では `backend.upstream_disconnect` になり、Ticket 要件の「worker not found / unknown cursor / expired cursor / upstream disconnect を typed diagnostic として扱う」を満たさない。
- 同様に Runtime WS connect 時の HTTP 404 等も `RuntimeUnavailable` 扱いで、worker-not-found として区別されない。
2. 必須テストカバレッジが不足している
- Ticket 受け入れ条件では、expired/unknown cursor diagnostics、upstream disconnect diagnostics、worker-scoped filtering 等の WS proxy tests が要求されている。
- 現状確認できたテストは Runtime 側の snapshot/live/resume/filter と malformed cursor/observation-only、Backend 側の snapshot/live/resume/malformed cursor/observation-only が中心で、Backend の unknown/expired cursor、Runtime upstream diagnostic の型変換、upstream disconnect、Runtime worker-not-found 経路を検証していない。
上記を修正し、Runtime diagnostic / HTTP failure を Backend の typed diagnostic に適切にマップするテストを追加すれば、設計境界自体は approve に近い状態。
---
<!-- event: implementation_report author: yoi-coder-00001KVZKSTJT-ws-proxy at: 2026-06-26T05:10:58Z -->
## Implementation report
Follow-up implementation report after review request_changes:
Fix commit:
- `8cc9a594f78feef62aa7abd5bbf11b5cd40b4781 fix: preserve runtime websocket diagnostics`
修正内容:
### 1. Runtime WS diagnostic の型を Backend で保持 / 変換
`crates/workspace-server/src/observation.rs`
- `RuntimeWsObservationClient::next_event` が Runtime diagnostic を全部 `backend.upstream_disconnect` に潰していた問題を修正。
- Runtime diagnostic code を Backend typed diagnostic に変換:
- `runtime.worker_not_found``backend.worker_not_found`
- `runtime.cursor_malformed``backend.cursor_malformed`
- `runtime.cursor_unknown_or_expired` / `runtime.cursor_expired``backend.cursor_unknown_or_expired`
- `runtime.upstream_closed` / `runtime.websocket_error``backend.upstream_disconnect`
- `runtime.unavailable``backend.runtime_unavailable`
- `runtime.serialize_failed``backend.malformed_frame`
- `runtime.observation_only``backend.observation_only`
- Runtime WS connect 時の HTTP 404 を `backend.worker_not_found` として扱うように変更。
- 実際の socket close / receive error は引き続き `backend.upstream_disconnect` として区別。
### 2. WS proxy テスト追加
`crates/workspace-server/src/server.rs`
追加 coverage:
- Backend unknown/expired cursor:
- well-formed だが未知の `bo_...` cursor が `backend.cursor_unknown_or_expired` になること。
- Runtime upstream diagnostic mapping:
- Runtime の `runtime.cursor_unknown_or_expired` が client-facing `backend.cursor_unknown_or_expired` に変換されること。
- Runtime worker-not-found / HTTP 404 mapping:
- Runtime WS upgrade が 404 を返すケースを `backend.worker_not_found` として返すこと。
- Upstream disconnect:
- Runtime upstream が WS 接続後に閉じた場合、`backend.upstream_disconnect` として返すこと。
既存の snapshot/live/resume/filter/malformed cursor/observation-only coverage は維持。
Validation:
- `cargo fmt --all`: success
- `cargo check -p worker-runtime`: success
- `cargo test -p worker-runtime --features ws-server`: success14 tests passed + bin/doc tests
- `cargo test -p yoi-workspace-server`: success26 tests passed + bin/doc tests
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- Runtime diagnostic code の Backend 変換は現 Runtime diagnostic set に対する明示 mapping。未知 code は `backend.runtime_unavailable` に安全側で畳む。
- HTTP 404 は worker-not-found として扱う。Runtime 側で route miss と worker miss の HTTP body までは分離していないため、client-facing には endpoint/path/token 等を出さず typed diagnostic のみ返す。
- v0 cursor/backlog は引き続き in-memory bounded。再起動 / eviction 後は unknown/expired cursor diagnostic。
---
<!-- event: review author: yoi-reviewer-00001KVZKSTJT-ws-proxy at: 2026-06-26T05:15:04Z status: approve -->
## Review: approve
Review result: approve
読取専用で follow-up commit `8cc9a594f78feef62aa7abd5bbf11b5cd40b4781` を確認した。前回 blockers は解消済み。
確認した点:
- `RuntimeWsObservationClient::next_event` が Runtime diagnostic を `backend.*` typed diagnostic にマップし、`runtime.cursor_unknown_or_expired` / `runtime.worker_not_found` 等を `backend.upstream_disconnect` に潰さなくなっている。
- 実際の socket close / receive error は引き続き `backend.upstream_disconnect` として区別されている。
- Runtime WS connect の HTTP 404 が `backend.worker_not_found` にマップされている。
- 追加テストで Backend unknown cursor、Runtime cursor diagnostic mapping、Runtime worker-not-found 404 mapping、actual upstream disconnect が検証されている。
- Client-facing envelope は `cursor`, `event_id`, `runtime_id`, `worker_id`, `payload: protocol::Event` のみで、Runtime endpoint/token/socket/session path は含まれていない。
- observation-only 境界を壊す command tunnel / SSE / lifecycle / full auth redesign の scope creep は見当たらない。
検証は read-only inspection のみで、cargo/nix は再実行していない。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T05:16:01Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZKSTJT-websocket-observation-proxy` を orchestration branch に merge 済み。
- Merge commit: `ae0f0d1d merge: 00001KVZKSTJT websocket observation proxy`
Included implementation commits:
- `9807accaf08f4322763dd7cd3536baf3dab8d10e feat: add worker observation websocket proxy`
- `8cc9a594f78feef62aa7abd5bbf11b5cd40b4781 fix: preserve runtime websocket diagnostics`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo check -p worker-runtime`: success
- `cargo test -p worker-runtime --features ws-server`: success14 lib tests + 3 bin tests + doctests
- `cargo test -p yoi-workspace-server`: success26 tests + bin/doc tests
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。前回 blocker だった Runtime diagnostic の Backend typed diagnostic mapping、HTTP 404 worker-not-found mapping、unknown cursor / upstream disconnect test coverage は解消済み。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T05:16:11Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
Runtime/Backend WebSocket observation proxy の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `ae0f0d1d merge: 00001KVZKSTJT websocket observation proxy`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo check -p worker-runtime`: success
- `cargo test -p worker-runtime --features ws-server`: success14 lib tests + 3 bin tests + doctests
- `cargo test -p yoi-workspace-server`: success26 tests + bin/doc tests
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- Runtime process worker-scoped WebSocket observation stream と Backend-owned client-facing WebSocket proxy boundary を追加。
- command tunnel / SSE / remote lifecycle/discovery / full auth-redaction policy / Web Console UI は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T05:16:51Z -->
## Implementation report
Cleanup report:
- Child Workers stopped one-by-one and scope reclaimed:
- `yoi-coder-00001KVZKSTJT-ws-proxy`
- `yoi-reviewer-00001KVZKSTJT-ws-proxy`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZKSTJT-websocket-observation-proxy`
- Child implementation branch removed:
- `work/00001KVZKSTJT-websocket-observation-proxy`
Operational note:
- StopPod was executed sequentially, not in parallel.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -1 +1,2 @@
{"id":"orch-plan-20260625-163206-1","ticket_id":"00001KVZKSV6C","kind":"blocked_by","related_ticket":"00001KVZBCQH4","note":"Queue routing checked after Dashboard Queue. This Backend RuntimeRegistry foundation Ticket depends on `00001KVZBCQH4` worker-runtime core. That dependency is currently inprogress and only at coder implementation report stage, not reviewed/merged/done, so implementation side effects for this Ticket are blocked.","author":"yoi-orchestrator","at":"2026-06-25T16:32:06Z"}
{"id":"orch-plan-20260625-165451-2","ticket_id":"00001KVZKSV6C","kind":"accepted_plan","note":"`00001KVZBCQH4` が done になり dependency blocker 解消。FS store Ticket とは主対象が workspace-server vs worker-runtime feature で分離できるため並行受理候補。","accepted_plan":{"summary":"worker-runtime core done 後の Backend RuntimeRegistry foundation slice。embedded/remote 実 handle は作らず、workspace-server の Registry identity/projection/error boundary と local compatibility source naming/diagnostics を worker-runtime domain model に合わせる。","branch":"work/00001KVZKSV6C-backend-runtime-registry","worktree":"/home/hare/Projects/yoi/.worktree/00001KVZKSV6C-backend-runtime-registry","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/workspace-server` 中心の narrow write scope を委譲する。reviewer Worker は read-only で Registry identity/projection/error boundary と existing API behavior preservation を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-25T16:54:51Z"}

View File

@ -1,8 +1,8 @@
---
title: 'Backend RuntimeRegistryの基盤をworker-runtime向けに整理する'
state: 'queued'
state: 'closed'
created_at: '2026-06-25T14:44:03Z'
updated_at: '2026-06-25T16:32:17Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T16:31:28Z'

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -79,4 +79,334 @@ Escalate if:
- `00001KVZBCQH4` の Runtime API shape が本 Ticket の前提を満たさない。
- Backend Registry foundation 側で worker-runtime core の追加変更が必要になる。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-25T16:55:09Z -->
## Decision
Routing decision: implementation_ready
Reason:
- `00001KVZBCQH4` worker-runtime core は done。dependency blocker は解消済み。
- 本 Ticket の目的は Backend RuntimeRegistry foundation の整理で、embedded runtime 接続や REST/FS 実装そのものではない。
- queued/inprogress 再確認時点で `inprogress` は 0 件。FS store Ticket とは主変更面が `crates/workspace-server` vs `crates/worker-runtime` feature で概ね分離できるため、本 Ticket は受理可能。
Evidence checked:
- Ticket body: Backend RuntimeRegistry foundation、runtime_id / worker_id authority、existing local compatibility source、workspace-server hosts/server target、Non-goals。
- Relations: outgoing dependency `00001KVZBCQH4` は done。incoming dependent `00001KVZSGT0Q`, `00001KVZSGT14` は後続であり blocker ではない。
- Orchestration plan: accepted plan `orch-plan-20260625-165451-2` を記録。
- Workspace state: orchestration worktree clean。worker-runtime core merge/validation/done/cleanup 済み。
IntentPacket:
Intent:
- Backend `RuntimeRegistry` の domain boundary を、legacy process/source abstraction から worker-runtime を受けられる形へ整理する。
Binding decisions / invariants:
- Backend Registry の authority は Runtime / Worker domain identity を扱い、raw socket/session/path/pod name を public authority にしない。
- この Ticket では embedded `worker_runtime::Runtime` を実際に接続しない。handle/trait/enum/boundary と diagnostics/projection 整理まで。
- Remote Runtime HTTP client / REST server / Web Console / dynamic Runtime registration は実装しない。
- 既存 local compatibility source の behavior は壊さない。
- `worker-runtime` core crate の API を大きく変更しない。必要になれば escalation。
Requirements / acceptance criteria:
- `workspace-server` の RuntimeRegistry foundation が worker-runtime 向けの identity / projection / error boundary を持つ。
- Existing local/process compatibility source と将来 embedded/remote source の境界が型で分かる。
- Browser/API response へ socket/session/path authority を露出しない。
- Existing workspace-server tests が通る。
Implementation latitude:
- Type/module split、内部 trait/enum naming、diagnostic representation は既存 `crates/workspace-server/src/hosts.rs` の形に合わせてよい。
- Minimal compile/test slice でよい。実 embedded handle は placeholder/boundary でよい。
Escalate if:
- `worker-runtime` crate の public API 変更が必要になる。
- Backend embedded connection を実装しないと acceptance を満たせないと判明する。
- API response schema 互換性や dashboard expectations を大きく変える必要がある。
Validation:
- `cargo fmt --all`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Registry boundary が legacy Pod/socket/session authority を引きずること。
- `00001KVZSGT0Q` の実 embedded接続まで scope creep すること。
- Existing local compatibility source の API/diagnostics regression。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-25T16:55:16Z from: queued to: inprogress reason: routing_accepted_after_worker_runtime_core_done field: state -->
## State changed
Routing decision: implementation_ready。
Dependency `00001KVZBCQH4` worker-runtime core は done。Ticket body / relations / workspace state / orchestration plan を確認し、Backend RuntimeRegistry foundation は unblocked と判断した。accepted plan と IntentPacket は thread / orchestration plan に記録済み。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T16:58:32Z -->
## Implementation report
Implementation startup blocked after acceptance:
- Worktree created:
- `/home/hare/Projects/yoi/.worktree/00001KVZKSV6C-backend-runtime-registry`
- branch `work/00001KVZKSV6C-backend-runtime-registry`
- Coder Worker spawn attempted:
- `yoi-coder-00001KVZKSV6C-runtime-registry`
- Spawn failed before child socket appeared:
- `yoi: unknown command pod`
Interpretation:
- No implementation code changes have been made in this worktree yet.
- This appears to be a runtime/launcher compatibility issue after the Pod→Worker CLI rename: the SpawnPod tool path attempted to invoke a `pod` subcommand that the child-launch binary rejected.
- Because this failure happened after `queued -> inprogress` acceptance and worktree creation, the Ticket remains inprogress with a recovery note rather than being silently returned to queued.
Recovery needed:
- Restart/restore Orchestrator on a consistent runtime binary or repair the launcher compatibility path, then retry Coder Worker spawn for this accepted worktree.
- If retry remains impossible, use an explicit human-authorized alternative implementation route.
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T19:24:51Z -->
## Implementation report
Implementation recovery / kickoff:
- User reported the previous SpawnPod failure was caused by a development environment variable forcing child launch from `target` binary. The variable was removed and installed binary is now used.
- Retried Coder Worker spawn for the already accepted worktree; spawn succeeded.
Active implementation:
- Worktree: `/home/hare/Projects/yoi/.worktree/00001KVZKSV6C-backend-runtime-registry`
- Branch: `work/00001KVZKSV6C-backend-runtime-registry`
- Coder Worker: `yoi-coder-00001KVZKSV6C-runtime-registry`
- Scope: read implementation worktree + non-recursive workspace root, write `crates/workspace-server/**` only.
Next action:
- Wait for Coder implementation report, then route to reviewer.
---
<!-- event: implementation_report author: yoi-coder-00001KVZKSV6C-runtime-registry at: 2026-06-25T19:33:11Z -->
## Implementation report
Implementation report:
実装完了。Ticket ファイル/project records は変更していない。merge/close/cleanup 前で停止。
Commit:
- `f6fd7b63 feat: add workspace runtime registry source boundary`
変更ファイル:
- `crates/workspace-server/src/hosts.rs`
- `crates/workspace-server/src/server.rs`
実装/API 概要:
- `WorkerRuntimeRegistry``RuntimeRegistry` に改名し、workspace-server 内の Runtime/Worker domain 側の registry 名を明確化。
- `RuntimeSummary``source: RuntimeSourceSummary` を追加。
- `RuntimeSourceKind`: `local_compatibility`, `embedded_worker_runtime`, `remote_http`
- `RuntimeSourceStatus`: `active`, `reserved`
- `RuntimeIdentityAuthority`: `runtime_registry_projection`
- 現行 local Pod metadata 由来の互換 source は `local_compatibility` として明示。
- embedded worker-runtime / remote HTTP は reserved boundary として型だけ用意し、実接続・HTTP client/server・dynamic registration は未実装のまま保持。
- API response に source boundary / identity authority を追加し、Runtime public identity が socket/session/path ではなく registry projection であることをテストで確認。
- 既存 local compatibility behavior は維持し、既存テストに source boundary の assert を追加。
Validation:
- `cargo fmt --all`: success
- `cargo test -p yoi-workspace-server`: success19 passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: successdirty warning は出たが build 成功)
Residual risks / review focus:
- API top-level `source: "worker_runtime_registry"` は既存互換のため維持。一方で Runtime item 側に typed `source.kind` / `identity_authority` を追加。
- embedded/remote source は reserved constructor と enum boundary のみで、実際の registry composition や Runtime 接続は次 Ticket 側の責務。
- `RuntimeSourceSummary.note` は human-readable な API payload なので、Web 側で表示するなら文言の粒度を確認してほしい。
---
<!-- event: review author: yoi-reviewer-00001KVZKSV6C-runtime-registry at: 2026-06-25T19:37:41Z status: request_changes -->
## Review: request changes
Review result: request_changes
ブロッカー:
1. Runtime/Worker authority がまだ `runtime_id + worker_id` になっていない。
- `RuntimeRegistry::worker(&self, worker_id)``runtime_id` を受け取らず、全 Runtime を `worker_id` だけで走査している。
- `RuntimeRegistryError` にも `UnknownRuntime` 相当がない。
- Ticket の binding decision / 要件では Worker authority は `runtime_id + worker_id`、unknown runtime / unknown worker 等の error boundary を typed に分ける必要がある。
- 将来 embedded / remote source が増えた時に `worker_id` 衝突や誤 routing が起き得るため、foundation として不足。
- 該当: `crates/workspace-server/src/hosts.rs` `RuntimeRegistry::worker` / `RuntimeRegistryError`
2. runtime-scoped routing/error mapping のテストが不足している。
- 追加テストは `local_compatibility` source / identity_authority / path 非露出は確認しているが、複数 Runtime または unknown runtime を想定した `runtime_id` scoped lookup / error boundary を確認していない。
- Acceptance の “Runtime identity / Worker routing key / error boundary” を満たすには、typed `runtime_id` lookup と unknown-runtime / unknown-worker の focused test が必要。
確認できた良い点:
- `RuntimeSourceKind::{LocalCompatibility, EmbeddedWorkerRuntime, RemoteHttp}``RuntimeSourceSummary` により、local compatibility / future embedded / future remote の source 境界は型として追加されている。
- local source は `source.kind = local_compatibility`、`identity_authority = runtime_registry_projection` として API/test で確認されている。
- socket/session/path authority の直接公開や embedded `worker_runtime::Runtime` 接続、remote HTTP client/server 実装などの scope creep は見当たらない。
- 変更範囲は `workspace-server``hosts.rs` / `server.rs` のみで、`worker-runtime` public API 変更は見当たらない。
- read-only で `git diff --check f6fd7b63^ f6fd7b63` は問題なし。Cargo/Nix 検証は read-only 指示を優先して再実行していない。
---
<!-- event: implementation_report author: yoi-coder-00001KVZKSV6C-runtime-registry at: 2026-06-25T20:38:31Z -->
## Implementation report
Follow-up implementation report after review request_changes:
Commit:
- `d7c4396c fix: scope workspace worker lookup by runtime`
対応内容:
- `RuntimeRegistry::worker``worker_id` 単独 lookup から `runtime_id + worker_id` lookup に変更。
- 先に `runtime_id` を解決。
- runtime が存在しない場合は `UnknownRuntime`
- runtime は存在するが worker が存在しない場合は `UnknownWorker { runtime_id, worker_id }`
- worker_id 衝突時に別 runtime の worker を誤って返さない。
- `RuntimeRegistryError` / workspace-server `Error` に typed error boundary を追加・整理。
- `UnknownRuntime(String)`
- `UnknownWorker { runtime_id, worker_id }`
- server 側の error-to-status mapping 更新。
- `UnknownRuntime` / `UnknownWorker``404 NOT_FOUND`
- テスト追加。
- 同一 `worker_id` を持つ複数 runtime fixture で lookup が `runtime_id` scoped であることを確認。
- unknown runtime と unknown worker が別 error として返り、crate-level `Error` にも正しく mapping されることを確認。
変更ファイル:
- `crates/workspace-server/src/hosts.rs`
- `crates/workspace-server/src/lib.rs`
- `crates/workspace-server/src/server.rs`
Validation:
- `cargo fmt --all`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- 現時点で worker detail API route はまだないため、`RuntimeRegistry::worker(runtime_id, worker_id)` の authority boundary は registry 内部 API とテストで確立している。将来 route を追加する際は path/query でも `runtime_id + worker_id` を必須にする必要がある。
- fixture runtime は routing/error 境界確認用の test-only 実装で、embedded/remote の実接続は次 Ticket の責務として残している。
---
<!-- event: review author: yoi-reviewer-00001KVZKSV6C-runtime-registry at: 2026-06-25T20:41:10Z status: approve -->
## Review: approve
Review result: approve
確認結果:
- `RuntimeRegistry::worker(runtime_id, worker_id)` に変更され、`worker_id` 単独走査ではなく `runtime_id` で対象 Runtime を確定してから lookup する形になっている。
- `UnknownRuntime``UnknownWorker { runtime_id, worker_id }` が分離され、crate `Error` / server 404 mapping も更新されている。
- 同一 `worker_id` が複数 Runtime に存在する multi-runtime fixture test が追加され、誤 routing しないことを確認している。
- unknown runtime / known runtime + missing worker の error mapping test も追加されている。
- embedded worker-runtime 接続、remote HTTP、REST server 等の scope creep は見当たらない。
- local compatibility source の既存 projection / path 非露出 / ID boundedness 系テストは維持されている。
- read-only で `git diff --check f6fd7b63 d7c4396c` は問題なし。Cargo/Nix は read-only 指示のため再実行していない。
前回ブロッカーは解消済みと判断する。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-25T20:44:19Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZKSV6C-backend-runtime-registry` を orchestration branch に merge 済み。
- Merge commit: `fb023aab merge: 00001KVZKSV6C runtime registry foundation`
Included implementation commits:
- `f6fd7b63 feat: add workspace runtime registry source boundary`
- `d7c4396c fix: scope workspace worker lookup by runtime`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p yoi-workspace-server`: success21 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。前回 blocker だった `runtime_id + worker_id` authority と unknown-runtime / unknown-worker typed error boundary は解消済み。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-25T20:44:27Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
Backend RuntimeRegistry foundation の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `fb023aab merge: 00001KVZKSV6C runtime registry foundation`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p yoi-workspace-server`: success21 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- workspace-server の RuntimeRegistry foundation を worker-runtime 向け identity/projection/error boundary に整理。
- embedded runtime connection / remote HTTP / REST server / Web Console は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T03:09:01Z -->
## Implementation report
Cleanup report:
- Registry Coder/Reviewer child Workers were no longer present in the spawned-child registry at cleanup time, so no StopPod action was available for them.
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZKSV6C-backend-runtime-registry`
- Child implementation branch removed:
- `work/00001KVZKSV6C-backend-runtime-registry`
Operational note:
- User noted StopPod should be run one-by-one rather than through parallel multi-tool execution; future cleanup will follow that.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -1 +1,5 @@
{"id":"orch-plan-20260625-164457-1","ticket_id":"00001KVZQHPNY","kind":"blocked_by","related_ticket":"00001KVZBCQH4","note":"Queue routing checked after Dashboard Queue. Profile/config bundle sync depends on worker-runtime core `00001KVZBCQH4`, which is currently inprogress and under review. Do not start sync implementation until core CreateWorkerRequest/Profile boundary is reviewed/merged/done.","author":"yoi-orchestrator","at":"2026-06-25T16:44:57Z"}
{"id":"orch-plan-20260625-165606-2","ticket_id":"00001KVZQHPNY","kind":"waiting_capacity_note","note":"Core dependency is now done, but this bundle-sync Ticket is left queued in this acceptance pass because Backend Registry foundation and FS store were accepted first. Bundle sync likely touches `worker-runtime` creation/profile boundary and Backend Registry availability semantics, so it should start after at least the foundation branch shape is reviewed or merged to avoid design/API churn.","author":"yoi-orchestrator","at":"2026-06-25T16:56:06Z"}
{"id":"orch-plan-20260626-051843-3","ticket_id":"00001KVZQHPNY","kind":"waiting_capacity_note","note":"Core/foundation dependencies are now done, but config bundle sync is left queued while embedded Backend RuntimeRegistry connection `00001KVZSGT0Q` is accepted/inprogress. Bundle sync likely touches worker creation/profile boundary and Backend Registry availability semantics; start after embedded connection branch shape is reviewed or merged to avoid API churn.","author":"yoi-orchestrator","at":"2026-06-26T05:18:43Z"}
{"id":"orch-plan-20260626-054922-4","ticket_id":"00001KVZQHPNY","kind":"waiting_capacity_note","note":"Config bundle sync is left queued while remote Runtime process connection `00001KVZSGT14` is accepted/inprogress. The relation says v0 remote integration can use builtin/default fallback, and starting both would risk churn in worker creation/config routing surfaces.","author":"yoi-orchestrator","at":"2026-06-26T05:49:22Z"}
{"id":"orch-plan-20260626-063205-5","ticket_id":"00001KVZQHPNY","kind":"accepted_plan","note":"Worker-runtime core, embedded/remote Runtime Registry, REST/WS foundation are done. Previous waiting-capacity notes are resolved; no inprogress remains.","accepted_plan":{"summary":"Runtime へ同期可能な Profile/config bundle model、runtime-side bundle store/status/digest validation、worker create integration、Backend-to-Runtime sync/availability boundary を実装する。Secret values/raw paths/plugin execution/full package manager は扱わない。","branch":"work/00001KVZQHPNY-runtime-config-bundles","worktree":"/home/hare/Projects/yoi/.worktree/00001KVZQHPNY-runtime-config-bundles","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/worker-runtime` / `crates/workspace-server` と必要な Cargo/package files の write scope を委譲する。reviewer Worker は read-only で secret/path exclusion、digest/provenance, Runtime/Backend sync semantics, typed errors, fallback-vs-bundle boundary を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-26T06:32:05Z"}

View File

@ -1,8 +1,8 @@
---
title: 'RuntimeへProfile/config bundleを同期する'
state: 'queued'
state: 'closed'
created_at: '2026-06-25T15:49:30Z'
updated_at: '2026-06-25T16:45:08Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T16:44:39Z'

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -59,4 +59,408 @@ Escalate if:
- core の `CreateWorkerRequest` / `ConfigBundleRef` placeholder が bundle sync requirements を満たさない。
- bundle sync のために REST server / FS store / Plugin manager 実装を同時に要求する形になりそうな場合。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-26T06:32:31Z -->
## Decision
Routing decision: implementation_ready
Reason:
- `00001KVZBCQH4` worker-runtime core、Backend RuntimeRegistry foundation、embedded/remote Runtime connection、REST/WS foundation は done。
- 前回の waiting-capacity reason は解消済みで、現在 `inprogress` は 0 件。
- Ticket body は config bundle model、sync API、worker creation integration、Backend responsibility、Plugin/host policy boundary、Non-goals、acceptance criteria を明記している。
- Plugin package bytes vs package ref の詳細などは実装時の local design latitude として扱える。Secret value sync / full Plugin manager / actual host mount path sync は Non-goals。
Evidence checked:
- Ticket body: digest/revision/provenance、bundle content model、secret/raw path exclusion、Runtime sync API、CreateWorkerRequest integration、typed errors、Backend responsibility、Non-goals、validation。
- Relations: only blocking dependency `00001KVZBCQH4` is done。Remote Runtime integration has related relation only and is now done.
- Orchestration plan: accepted plan `orch-plan-20260626-063205-5` を記録。
- Workspace state: orchestration worktree clean、no active inprogress。
IntentPacket:
Intent:
- `worker-runtime` と Backend に Profile/config bundle sync boundary を追加し、Runtime が bundle digest / profile selector を検証して Worker creation に使えるようにする。
Binding decisions / invariants:
- Bundle に secret values、raw socket/session path、runtime-local mount actual path、host-local cache path を含めない。
- Secret/mount/network/shell/git availability は host-local policy / grant / secret ref として表現し、Runtime host が最終判断する。
- Backend は Runtime credential / direct endpoint / raw bundle storage path を Browser に渡さない。
- Backend が巨大な fully-resolved WorkerSpec を毎回送る設計にはしない。Worker creation は intent + profile selector + bundle ref + capabilities の境界を保つ。
- Builtin/default fallback は残すが、synced bundle mode と責務を区別する。
- Full Plugin package manager / registry / signature policy / secret value sync / Web Console completion は実装しない。
Requirements / acceptance criteria:
- Config bundle domain type が digest / revision / workspace id / created_at / provenance を持つ。
- Runtime は bundle を保存・一覧/確認し、digest を検証できる。
- `CreateWorkerRequest` / worker creation path が profile selector + config bundle ref を扱う。
- Missing bundle / digest mismatch / invalid profile / unsupported declaration は typed error。
- Embedded Runtime は direct lib API で sync 可能。
- Networked Runtime 用 REST sync API shape または endpoint がある。
- Backend は Runtime へ bundle sync し、bundle availability を確認できる。
- Tests distinguish builtin/default fallback vs synced bundle mode。
Implementation latitude:
- Module split, exact JSON/domain structs, digest computation details, minimal profile resolution depth, package ref vs inline descriptor representation are Coder choices within the invariants.
- For v0, `ResolvedWorkerSpec` / host-local policy enforcement may be a typed boundary with focused validation rather than full Plugin execution.
- If Profile/resource loading from existing project crates is too broad for this slice, define stable bundle structs and sync/validation semantics first, then escalate for deeper integration.
Escalate if:
- Secret values or host-local actual paths appear necessary in bundle content.
- Full Plugin package manager/signature policy is required to satisfy acceptance.
- Existing `worker-runtime` / Backend API must be redesigned broadly.
- Browser-facing API would need to receive Runtime credentials or raw bundle storage paths.
Validation:
- `cargo fmt --all`
- `cargo test -p worker-runtime`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Secret/raw path leakage。
- Bundle digest/provenance instability or mismatch bugs。
- Blurring builtin/default fallback with synced bundle mode。
- Over-implementing Plugin manager / policy enforcement beyond v0 boundary。
- Remote Runtime sync endpoint leaking endpoint/token/path details to Browser。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T06:32:50Z from: queued to: inprogress reason: routing_accepted_after_runtime_foundation_done field: state -->
## State changed
Routing decision: implementation_ready。
worker-runtime core / Registry foundation / embedded+remote Runtime connection / REST+WS foundation は done。Ticket body / relations / workspace state / accepted plan を確認し、Profile/config bundle sync slice は unblocked と判断した。accepted plan と IntentPacket は thread / orchestration plan に記録済み。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T06:35:25Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KVZQHPNY-runtime-config-bundles`
- Branch: `work/00001KVZQHPNY-runtime-config-bundles`
- Coder Worker spawned: `yoi-coder-00001KVZQHPNY-config-bundles`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `crates/worker-runtime/**`, `crates/workspace-server/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` if dependency/package changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Queued capacity notes:
- `00001KVZ9JGK0` remains queued to avoid overlapping Web Console/API surface changes while Profile/config sync is inprogress.
- `00001KW04A8K6` remains queued to avoid TUI migration against unstable worker creation/profile semantics.
---
<!-- event: implementation_report author: yoi-coder-00001KVZQHPNY-config-bundles at: 2026-06-26T07:08:31Z -->
## Implementation report
Implementation report:
実装完了。指定 worktree / branch 内で commit 済み。
Commit:
- `abab1af2 feat: add runtime config bundle sync`
変更ファイル:
- `Cargo.lock`
- `package.nix`
- `crates/worker-runtime/Cargo.toml`
- `crates/worker-runtime/src/lib.rs`
- `crates/worker-runtime/src/catalog.rs`
- `crates/worker-runtime/src/config_bundle.rs`
- `crates/worker-runtime/src/error.rs`
- `crates/worker-runtime/src/fs_store.rs`
- `crates/worker-runtime/src/http_server.rs`
- `crates/worker-runtime/src/runtime.rs`
- `crates/workspace-server/src/hosts.rs`
- `crates/workspace-server/src/server.rs`
実装概要:
### worker-runtime
- `config_bundle` module を追加。
- `ConfigBundle`
- `ConfigBundleMetadata`
- `ConfigBundleProvenance`
- `ConfigProfileDescriptor`
- `ConfigDeclaration`
- `ConfigBundleSummary`
- `ConfigBundleAvailability`
- Bundle metadata に digest / revision / workspace id / created_at / provenance/source metadata を保持。
- `ConfigBundleRef``id + digest` に拡張。
- Runtime direct lib API を追加。
- `store_config_bundle`
- `list_config_bundles`
- `check_config_bundle`
- Worker creation で profile selector + config_bundle ref を検証。
- bundle missing
- digest mismatch
- invalid profile selector
- unsupported declaration
を typed `RuntimeError` として返す。
- builtin/default fallback と synced bundle mode を区別。
- bundle なしでは `RuntimeDefault` / `Builtin` fallback を許可。
- `Named` profile は synced bundle ref 必須。
- FS snapshot に config bundle store を永続化。
- Runtime REST API を追加。
- `GET /v1/config-bundles`
- `POST /v1/config-bundles`
- `GET /v1/config-bundles/{bundle_id}/availability?digest=...`
- Bundle validation で secret values / host-local path 的な値を bundle content に持ち込まない前提の ref/grant/policy boundary を enforced する最小チェックを追加。
### workspace-server / Backend
- `WorkerSpawnRequest``profile` / `config_bundle` / `requested_capabilities` を追加。
- `RuntimeRegistry` / runtime host boundary に bundle sync/check/list を追加。
- Embedded Runtime backend で direct lib sync/check/create が動作。
- Remote Runtime backend で Runtime REST sync/check endpoint を利用。
- Workspace API に backend-facing endpoint を追加。
- `POST /api/runtimes/{runtime_id}/config-bundles`
- `GET /api/runtimes/{runtime_id}/config-bundles/{bundle_id}/availability?digest=...`
- Browser/API 側に Runtime credentials / direct endpoint / raw bundle storage path は出していない。
Validation:
- `cargo fmt --all`: success
- `cargo test -p worker-runtime`: success10 passed
- `cargo test -p yoi-workspace-server`: success34 passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Notes:
- `sha2``worker-runtime` direct dependency に追加したため、`Cargo.lock` と `package.nix``cargoHash` も更新。
Residual risks / review focus:
- Bundle digest canonicalization は v0 の typed domain fields ベース。将来 declaration schema が増える場合、digest 対象フィールドの拡張方針を確認してほしい。
- Bundle content の secret value / host-local path 禁止は v0 として文字列フィールドへの conservative validation。完全な policy/signature/package-manager ではない。
- Remote Runtime の bundle availability check は query string に digest を載せる最小 REST shape。bundle id の URL encoding 方針は今後必要なら強化対象。
- Backend API endpoint は sync/check のみ追加し、Browser 完成 UX や full Plugin package manager / signature policy は実装していない。
---
<!-- event: review author: yoi-reviewer-00001KVZQHPNY-config-bundles at: 2026-06-26T07:18:50Z status: request_changes -->
## Review: request changes
Review result: request_changes
読取専用レビュー結果。`abab1af2` の差分・該当ソースを確認し、追加で `git diff --check HEAD^ HEAD` のみ実行したcargo/nix はファイル生成を避けるため再実行せず、報告値として扱った)。
ブロッカー:
1. **bundle content の禁止境界がまだ満たせていない。**
`ConfigDeclaration.reference` は自由文字列で、検証は `validate_boundary_text` の限定的な substring 判定のみ。
- `crates/worker-runtime/src/config_bundle.rs:124-129`
- `crates/worker-runtime/src/config_bundle.rs:266-294`
例えば `.cache/yoi`、`.yoi/sessions/foo.jsonl`、`pods/foo/sock` のような相対 cache/session/socket 形や、`SecretRef.reference` に平文 secret 風文字列を入れても拒否されない。Ticket の invariant「Bundles must not contain secret values / raw socket/session paths / host-local cache paths」を API 型・検証境界として保証できていないため修正が必要。型を分けるか、少なくとも ref/grant/policy の許可形式を明示して拒否テストを追加すること。
2. **Backend remote availability check の bundle id canonicalization/encoding が不十分。**
Runtime REST は `{bundle_id}` path segment を使うが、bundle id 側の検証は `/`, `?`, `&` などを拒否せず、remote client は URL encode せずに埋め込んでいる。
- REST route: `crates/worker-runtime/src/http_server.rs:172-177`
- remote client: `crates/workspace-server/src/hosts.rs:1784-1788`
direct/POST store では受け入れられる id が remote check では経路破壊・誤解釈され得るため、Remote/Embedded の sync/check semantics が一致しない。path-safe id へ正規化/検証するか、ID を安全にエンコード/別ボディ化し、対応テストを追加すること。
3. **Browser-facing diagnostics に remote Runtime の raw store path が漏れる経路がある。**
Runtime REST error は `RuntimeError::to_string()` をそのまま返し、`StoreIo/StoreMissing/StoreCorrupt` は path を Display する。Backend remote client はその remote message を診断として Browser-facing `ConfigBundleSyncResult/CheckResult` に載せる。
- path を含む Display: `crates/worker-runtime/src/error.rs:65-80`
- REST error message: `crates/worker-runtime/src/http_server.rs:785-789`
- Backend diagnostic relay: `crates/workspace-server/src/hosts.rs:2476-2505`
「Backend must not expose ... raw bundle storage paths to Browser」に反する。remote Runtime の internal path は Backend 側でサニタイズし、embedded と同様に内部 path 非公開の診断へ畳む必要がある。
確認できた良い点:
- digest/revision/workspace_id/created_at/provenance を持つ bundle domain type は追加されている。
- Runtime store/list/check、profile + bundle ref の Worker 作成検証、missing/mismatch/invalid profile/unsupported declaration の typed error は概ね入っている。
- builtin/default fallback と synced bundle mode のテスト分離はある。
- Embedded direct sync と remote REST sync/check の骨格はある。
- package.nix の cargoHash は Cargo.lock 変更に合わせて更新されている。
---
<!-- event: implementation_report author: yoi-coder-00001KVZQHPNY-config-bundles at: 2026-06-26T07:34:04Z -->
## Implementation report
Follow-up implementation report after review request_changes:
Commit:
- `4867ab21 fix: harden runtime config bundle boundary`
対応内容:
### 1. Bundle content boundary 強化
- `ConfigBundle` / `ConfigBundleRef` validation を強化。
- Bundle id を path-safe stable identifier に制限。
- `/`, `?`, `&`, `#`, whitespace などを拒否。
- digest を lowercase SHA-256 hex 64 chars として検証。
- `ConfigDeclaration.reference` は free string のままにせず、kind ごとに許可 prefix を限定。
- `SecretRef`: `secret:`, `secret-ref:`, `vault:`, `keyring:`
- `MountGrant`: `mount:`, `mount-grant:`
- `NetworkPolicy`: `network:`, `network-policy:`
- `ShellPolicy`: `shell:`, `shell-policy:`
- `GitPolicy`: `git:`, `git-policy:`
- `CapabilityGrant`: `capability:`, `capability-grant:`
- reference token では `/`, `\`, `?`, `&`, `#`, `%`, `=`, whitespace を拒否。
- relative cache/session/socket/path-like forms を拒否するテストを追加。
- `.cache/yoi`
- `.yoi/sessions/foo.jsonl`
- `pods/foo/sock`
- `password=hunter2`
- `hunter2-secret-value`
### 2. Remote availability check の path safety
- Runtime 側で unsafe bundle id を拒否。
- Remote client 側の bundle availability path construction で bundle id / digest を percent-encode。
- `bundle/1?x``/v1/config-bundles/bundle%2F1%3Fx/availability?...` になることを mock HTTP test で確認。
- Direct/Embedded と Remote で path segment 解釈が分岐しにくいようにした。
### 3. Browser-facing diagnostics の raw path leak 防止
- Remote Runtime HTTP error diagnostic で remote error message をそのまま転送しないように変更。
- Browser-facing diagnostic は remote code / HTTP status のみを含む sanitized message に変換。
- mock remote response に raw store path / session path を含め、`ConfigBundleSyncResult` / `ConfigBundleCheckResult` に漏れないことをテスト追加。
Validation:
- `cargo fmt --all`: success
- `cargo test -p worker-runtime`: success13 passed
- `cargo test -p yoi-workspace-server`: success35 passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- `ConfigDeclaration.reference` は v0 として prefix/token allowlist で制限。将来、より構造化された enum payload に移す余地はある。
- Secret ref は「値を同期しない」境界として typed prefix 必須にしたが、ref 名自体に何を許すかは今後 policy 化できる。
- Remote error message は全体的に sanitized されるため、詳細調査は backend/runtime logs 側を見る前提。
---
<!-- event: review author: yoi-reviewer-00001KVZQHPNY-config-bundles at: 2026-06-26T07:38:26Z status: approve -->
## Review: approve
Review result: approve
再レビュー結果: 前回ブロッカーは解消されていると判断する。
確認内容:
- `4867ab21 fix: harden runtime config bundle boundary` の差分と関連実装を読取専用で確認。
- `git diff --check HEAD^ HEAD` は問題なし。
- cargo/nix 系はファイル生成を避けるため再実行せず、報告された成功結果を前提確認扱い。
確認できた解消点:
- bundle id は path-safe に制限され、`/`, `?`, `&`, `#`, whitespace 等が拒否される。
- digest は lowercase SHA-256 hex 64 chars として検証される。
- `ConfigDeclaration.reference` は kind 別 prefix + token 制限になり、cache/session/socket/path 風・secret value 風の拒否テストも追加されている。
- remote availability path は percent-encode され、Runtime 側でも unsafe id が拒否されるため remote/embedded の意味差が縮んでいる。
- remote Runtime error の raw message は Backend 診断へ中継されず、Browser-facing result は HTTP status / remote code ベースにサニタイズされている。raw store/session path 非漏洩テストも確認。
- builtin/default fallback と synced bundle mode の区別、typed error、sync/check API 境界は維持されている。
- Plugin package manager/signature/WebConsole 方面の scope creep は見当たらない。
- `package.nix``cargoHash` 更新も反映済み。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T07:39:30Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZQHPNY-runtime-config-bundles` を orchestration branch に merge 済み。
- Merge commit: `7e8a8cfa merge: 00001KVZQHPNY runtime config bundles`
Included implementation commits:
- `abab1af2 feat: add runtime config bundle sync`
- `4867ab21 fix: harden runtime config bundle boundary`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime`: success13 tests passed
- `cargo test -p yoi-workspace-server`: success35 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。前回 blockers だった bundle content boundary、bundle id path safety、remote diagnostics raw path non-leak は解消済み。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T07:39:39Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
Runtime Profile/config bundle sync の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `7e8a8cfa merge: 00001KVZQHPNY runtime config bundles`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime`: success13 tests passed
- `cargo test -p yoi-workspace-server`: success35 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- Config bundle domain/sync/check、worker creation integration、embedded/remote Backend sync/check boundary を追加。
- Secret value sync / full Plugin package manager/signature policy / Web Console completion は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T07:40:38Z -->
## Implementation report
Cleanup report:
- Child Workers stopped one-by-one and scope reclaimed:
- `yoi-coder-00001KVZQHPNY-config-bundles`
- `yoi-reviewer-00001KVZQHPNY-config-bundles`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZQHPNY-runtime-config-bundles`
- Child implementation branch removed:
- `work/00001KVZQHPNY-runtime-config-bundles`
Operational note:
- StopPod was executed sequentially, not in parallel.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -1 +1,2 @@
{"id":"orch-plan-20260625-163225-1","ticket_id":"00001KVZSGT0Q","kind":"blocked_by","related_ticket":"00001KVZKSV6C","note":"Queue routing checked after Dashboard Queue. Embedded Runtime connection depends on Backend RuntimeRegistry foundation `00001KVZKSV6C`, which is still queued and itself blocked by inprogress worker-runtime core `00001KVZBCQH4`. Do not start this Ticket until the foundation dependency is accepted/completed.","author":"yoi-orchestrator","at":"2026-06-25T16:32:25Z"}
{"id":"orch-plan-20260626-051805-2","ticket_id":"00001KVZSGT0Q","kind":"accepted_plan","note":"Dependencies are unblocked: `00001KVZKSV6C` RuntimeRegistry foundation is done; worker-runtime core is done. No active inprogress remains after WS proxy cleanup.","accepted_plan":{"summary":"Backend RuntimeRegistry に embedded `worker_runtime::Runtime` source を接続し、backend-internal Runtime として summary/status/capabilities、worker list/detail/create/input/transcript projection を direct lib call で扱えるようにする。remote process/FS/REST/WS/Web Console/Profile sync は扱わない。","branch":"work/00001KVZSGT0Q-embedded-runtime-registry","worktree":"/home/hare/Projects/yoi/.worktree/00001KVZSGT0Q-embedded-runtime-registry","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/workspace-server` 中心の narrow write scope を委譲する。reviewer Worker は read-only で embedded Runtime registration、runtime_id+worker_id routing、no internal path/credential leak、local compatibility separation を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-26T05:18:05Z"}

View File

@ -1,8 +1,8 @@
---
title: 'Backend RuntimeRegistryにembedded worker-runtimeを接続する'
state: 'queued'
state: 'closed'
created_at: '2026-06-25T16:23:58Z'
updated_at: '2026-06-25T16:32:35Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T16:31:30Z'

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -58,4 +58,276 @@ Escalate if:
- Embedded Runtime connection のために `00001KVZKSV6C` の scope/acceptance を変更する必要が出る。
- worker-runtime core API が embedded Backend integration に必要な create/send/projection semantics を満たさない。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-26T05:18:27Z -->
## Decision
Routing decision: implementation_ready
Reason:
- `00001KVZKSV6C` Backend RuntimeRegistry foundation は done。`00001KVZBCQH4` worker-runtime core も done。
- 本 Ticket の scope は embedded Runtime handle を Backend Registry に接続することで、remote Runtime process / FS store / REST command server / event stream / Web Console / config bundle sync は Non-goals。
- 現在 `inprogress` は 0 件。実装 surface は主に `crates/workspace-server` の RuntimeRegistry source/route であり、queued の remote/WebConsole/TUI は本 Ticket 完了後に判断すべき依存関係。
Evidence checked:
- Ticket body: embedded Runtime registration、direct lib call Worker operations、Backend API exposure、Non-goals、acceptance criteria。
- Relations: outgoing dependency `00001KVZKSV6C` は done。incoming `00001KVZ9JGK0` / `00001KW04A8K6` は後続であり blocker ではない。
- Orchestration plan: accepted plan `orch-plan-20260626-051805-2` を記録。
- Workspace state: orchestration worktree clean、WS proxy Ticket は done/cleanup 済み。
IntentPacket:
Intent:
- Workspace Backend の `RuntimeRegistry` に embedded `worker_runtime::Runtime` source を追加し、`backend-internal` Runtime として扱えるようにする。
Binding decisions / invariants:
- Embedded Runtime は HTTP endpoint / token / socket path / session path を持たない。
- Browser-facing API は `runtime_id + worker_id` authority で扱い、embedded Runtime internals / store path / provider credentials を露出しない。
- v0 は memory store / builtin/default Profile fallback / toolsなし Worker でよい。
- Remote Runtime process client、FS store、REST command server、event stream server、Web Console、Profile/config bundle sync は実装しない。
- Local compatibility source は残し、embedded Runtime source と diagnostics / implementation kind で区別する。
Requirements / acceptance criteria:
- Workspace Backend が embedded `worker_runtime::Runtime` を生成・保持し、RuntimeRegistry に登録できる。
- Backend API から `backend-internal` Runtime の summary/status/capabilities を確認できる。
- Registry が embedded Runtime の worker list/detail/create/send input/transcript projection を direct lib call で扱える。
- v0 toolsなし Worker が create でき、input acceptance まで確認できる。
- socket/session/runtime internal store/provider credential が Browser-facing API に出ない。
- Focused workspace-server tests cover embedded runtime registration and routing。
Implementation latitude:
- Existing `/api/workers` / runtime list に含めるか、新 runtime-scoped endpoint に寄せるかは Coder が既存 API shape とテスト容易性に基づいて選び、実装報告で方針を明記する。
- Internal source enum/handle/trait の分割、typed error mapping、test fixture の形は既存 `hosts.rs` / `server.rs` に合わせてよい。
Escalate if:
- `worker-runtime` public API の大幅変更が必要になる。
- Profile/config bundle sync を同時に実装しないと embedded Worker create が成立しない場合。
- Browser-facing API schema を大きく変える必要がある場合。
Validation:
- `cargo fmt --all`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Embedded Runtime internals/path/credentials の漏洩。
- Local compatibility source と embedded Runtime source の混同。
- `runtime_id + worker_id` routing ではなく worker_id-only routing に戻る regression。
- Non-goalsremote/REST/WS/WebConsole/Profile syncへの scope creep。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T05:18:35Z from: queued to: inprogress reason: routing_accepted_after_registry_foundation_done field: state -->
## State changed
Routing decision: implementation_ready。
Dependency `00001KVZKSV6C` Backend RuntimeRegistry foundation と `00001KVZBCQH4` worker-runtime core は done。Ticket body / relations / workspace state / accepted plan を確認し、embedded worker-runtime Registry connection slice は unblocked と判断した。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T05:19:30Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KVZSGT0Q-embedded-runtime-registry`
- Branch: `work/00001KVZSGT0Q-embedded-runtime-registry`
- Coder Worker spawned: `yoi-coder-00001KVZSGT0Q-embedded-runtime`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `crates/workspace-server/**` and root `Cargo.lock` if dependency lock changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Queued capacity note:
- `00001KVZQHPNY` remains queued while this embedded Runtime connection is inprogress to avoid worker creation/profile boundary API churn.
- Remote/WebConsole/TUI dependent Tickets remain queued until embedded/remote prerequisite chain is done.
---
<!-- event: implementation_report author: yoi-coder-00001KVZSGT0Q-embedded-runtime at: 2026-06-26T05:41:14Z -->
## Implementation report
Implementation report:
実装完了。現在のブランチにコミット済み。
Commit:
- `c8209285 feat: add embedded workspace runtime registry`
変更ファイル:
- `crates/workspace-server/src/hosts.rs`
- `crates/workspace-server/src/server.rs`
実装概要:
- `RuntimeRegistry` に backend-internal な embedded `worker_runtime::Runtime` source を追加。
- `EmbeddedWorkerRuntime::new_memory(...)`
- `RuntimeRegistry::for_workspace(...)`
- `RuntimeRegistry::register(...)`
- local compatibility source は既存の `local-worker-runtime` として維持し、embedded source は `embedded-worker-runtime` として distinct な kind / diagnostics に分離。
- embedded Runtime は browser/API に対して以下を露出しない projection にしている。
- HTTP endpoint
- token / credential
- socket / session path
- store path
- provider identity
- Worker 操作は `runtime_id + worker_id` で routing。
- worker create
- worker detail
- input acceptance
- bounded transcript projection
- v0 として in-memory / tools-less Worker create を実装。
- Ticket role では builtin profile fallback (`builtin:coder` など)
- Workspace companion/orchestrator では runtime default profile fallback
- `SocketReady` acceptance は embedded Runtime では明示的に reject。
追加/拡張 API:
- `POST /api/runtimes/{runtime_id}/workers`
- `GET /api/runtimes/{runtime_id}/workers/{worker_id}`
- `POST /api/runtimes/{runtime_id}/workers/{worker_id}/input`
- `GET /api/runtimes/{runtime_id}/workers/{worker_id}/transcript?start=...&limit=...`
既存 API への反映:
- `GET /api/runtimes`
- `GET /api/workers`
にも embedded runtime / embedded worker projection が載る。
テスト:
- embedded runtime registration / routing
- local compatibility source と embedded source の分離
- embedded Worker create
- input acceptance
- transcript projection
- wrong runtime_id での worker 操作が通らないこと
- browser-facing projection に内部 path / credential / socket/session 類が混ざらないこと
- `SocketReady` acceptance が embedded Runtime で reject されること
Validation:
- `cargo fmt --all`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- v0 は intentionally in-memory + tools-less Worker。LLM 実行、remote Runtime process client、FS store、REST command server、event stream server、Web Console、Profile/config sync は未実装。
- embedded runtime の API projection は内部情報を出さない方針だが、diagnostics / evidence / summary JSON に internal identity が混ざっていないか要確認。
- `requested_worker_name` は authority として使わず、embedded Runtime 側の opaque worker id を採用。UX 的表示名が必要なら別 Ticket で profile/config bundle や display metadata の設計が必要。
---
<!-- event: review author: yoi-reviewer-00001KVZSGT0Q-embedded-runtime at: 2026-06-26T05:46:25Z status: approve -->
## Review: approve
Review result: approve
確認結果:
- `RuntimeRegistry``LocalWorkerRuntime` と別種別の `EmbeddedWorkerRuntime` が登録され、`backend-internal` Runtime として summary/status/capabilities を返す構成になっている。
- embedded 側は `worker_runtime::Runtime::new_memory` を保持し、worker list/detail/create/send input/transcript は adapter 経由で direct lib call している。REST/remote process/FS store/WebConsole/Profile sync などへの scope creep は見当たらない。
- embedded Runtime summary/worker projection は endpoint/token/socket/session path/store path/provider credential を露出しておらず、capabilities も内部実装詳細を出さない形。
- local compatibility source は `local-pod-runtime`、embedded source は `embedded-worker-runtime` として kind/diagnostics が分離されている。
- API routing は detail/input/transcript が `/api/runtimes/{runtime_id}/workers/{worker_id}` 系で、worker_id-only の操作経路への回帰は見当たらない。
- tests は registration/routing/projection/error/identity boundary を含み、embedded worker 作成・input acceptance・transcript projection と誤 runtime/worker の失敗系も確認されている。
検証:
- read-only 指示に従い、ビルド/テスト再実行やファイル変更は行わず、対象 commit の差分・実装・テストを静的確認した。報告済み validation 結果と矛盾する点はない。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T05:47:01Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZSGT0Q-embedded-runtime-registry` を orchestration branch に merge 済み。
- Merge commit: `e0cc7acf merge: 00001KVZSGT0Q embedded runtime registry`
Included implementation commit:
- `c8209285 feat: add embedded workspace runtime registry`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p yoi-workspace-server`: success29 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。embedded Runtime registration/routing、internal path/credential non-leak、local compatibility source separation、runtime_id+worker_id authority に blocker なし。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T05:47:09Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
Backend RuntimeRegistry embedded worker-runtime connection の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `e0cc7acf merge: 00001KVZSGT0Q embedded runtime registry`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p yoi-workspace-server`: success29 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- Backend RuntimeRegistry に embedded `worker_runtime::Runtime` source を接続。
- Remote process / FS/REST/WS server implementation / Web Console / Profile config sync は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T05:47:56Z -->
## Implementation report
Cleanup report:
- Child Workers stopped one-by-one and scope reclaimed:
- `yoi-coder-00001KVZSGT0Q-embedded-runtime`
- `yoi-reviewer-00001KVZSGT0Q-embedded-runtime`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZSGT0Q-embedded-runtime-registry`
- Child implementation branch removed:
- `work/00001KVZSGT0Q-embedded-runtime-registry`
Operational note:
- StopPod was executed sequentially, not in parallel.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -0,0 +1,2 @@
{"id":"orch-plan-20260625-203613-1","ticket_id":"00001KVZSGT14","kind":"blocked_by","related_ticket":"00001KVZKSTJT","note":"Queue routing checked. Remote worker-runtime process connection depends on WebSocket observation proxy `00001KVZKSTJT` and REST command server `00001KVZKSTE2`; REST is now inprogress and WS proxy remains queued, so this Ticket should wait.","author":"yoi-orchestrator","at":"2026-06-25T20:36:13Z"}
{"id":"orch-plan-20260626-054840-2","ticket_id":"00001KVZSGT14","kind":"accepted_plan","note":"Dependencies are now done: FS store, REST command server, WebSocket observation proxy, and RuntimeRegistry foundation. Related profile/config sync is not a blocking relation for v0, per existing relation note.","accepted_plan":{"summary":"Backend RuntimeRegistry に remote worker-runtime process handle を追加し、REST command API と WS observation API を Backend-owned client として route/proxy できるようにする。Dynamic registration/full auth/Web Console/Profile sync は扱わない。","branch":"work/00001KVZSGT14-remote-runtime-registry","worktree":"/home/hare/Projects/yoi/.worktree/00001KVZSGT14-remote-runtime-registry","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/workspace-server` と必要な Cargo/package files の write scope を委譲する。reviewer Worker は read-only で remote endpoint/token non-leak、runtime_id+worker_id authority、REST/WS client error mapping、embedded/local separation を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-26T05:48:40Z"}

View File

@ -1,9 +1,11 @@
---
title: 'Backend RuntimeRegistryにremote worker-runtime processを接続する'
state: 'ready'
state: 'closed'
created_at: '2026-06-25T16:23:58Z'
updated_at: '2026-06-25T16:30:32Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T20:34:35Z'
---
## 背景

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -21,4 +21,371 @@ Marked ready by `yoi ticket state`.
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: workspace-panel at: 2026-06-25T20:34:35Z from: ready to: queued reason: queued field: state -->
## State changed
Ticket を `workspace-panel` が queued にしました。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-25T20:36:34Z -->
## Decision
Routing decision: blocked_by_dependency_or_missing_authority
Reason:
- Dashboard Queue 後に Ticket / relations / workspace state を確認した。
- 本 Ticket は WebSocket observation proxy `00001KVZKSTJT` と REST command server `00001KVZKSTE2` を前提にする remote worker-runtime process connection。
- `00001KVZKSTE2` は現在 inprogress、`00001KVZKSTJT` は queued/blocked。remote process connection を先に始めると transport/API shape を先取りして固定するため開始しない。
Evidence checked:
- Ticket body: remote Runtime process接続、Backend RuntimeRegistry source、REST/WebSocket client boundary、Non-goals。
- Relations: outgoing dependencies include `00001KVZKSTE2` / `00001KVZKSTJT` / `00001KVZKSV6C` 等。
- Orchestration plan: blocker record `orch-plan-20260625-203613-1` を追加。
Next action:
- 本 Ticket は queued のまま待機。
- REST command server と WebSocket observation proxy が done になった後に再 routing する。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-26T05:48:59Z -->
## Decision
Routing decision: implementation_ready
Reason:
- Dependencies are done: `00001KVZKST83` FS store、`00001KVZKSTE2` REST command server、`00001KVZKSTJT` WebSocket observation proxy、`00001KVZKSV6C` RuntimeRegistry foundation。
- Existing relation to `00001KVZQHPNY` is `related`, not blocking, and says v0 can use builtin/default fallback where applicable.
- 本 Ticket は remote Runtime process connection / routing を主目的とし、Dynamic registration / full auth / Web Console / Profile config sync は Non-goals。
- 現在 `inprogress` は 0 件。remote Runtime connection は TUI migration の blocker なので優先して受理する。
Evidence checked:
- Ticket body: remote Runtime client handle、REST command API client、Runtime event stream client/proxy、config/policy boundary、Non-goals、acceptance criteria。
- Relations: outgoing dependencies to FS/REST/WS/Registry foundation are done。Incoming TUI dependency is downstream。
- Orchestration plan: accepted plan `orch-plan-20260626-054840-2` を記録。
- Workspace state: orchestration worktree clean、embedded Runtime registry Ticket done/cleanup 済み。
IntentPacket:
Intent:
- Workspace Backend `RuntimeRegistry` に remote worker-runtime process handle を追加し、Backend-owned REST/WS client で remote Runtime operations を route/proxy できるようにする。
Binding decisions / invariants:
- Browser は remote Runtime base URL / token / direct endpoint を知らない。
- Browser-facing authority は embedded/local と同じ `runtime_id + worker_id`
- Remote command は worker-runtime REST command API に対する Backend-owned client。
- Remote observation は worker-runtime WS observation API に対する Backend-owned client/proxy。
- Dynamic registration、full auth/permission model、Backend Web Console、Profile/config bundle sync は実装しない。
- Embedded/local compatibility source の behavior を壊さず、remote source を implementation kind/diagnostics で区別する。
Requirements / acceptance criteria:
- Config-like data から remote Runtime client handle を登録できる。
- Runtime summary/status/capabilities、worker list/detail/create/input/stop/cancel/transcript/event proxy を route できる。
- Network/auth/timeout/remote unsupported/remote worker not found を typed Backend errors/diagnostics に map する。
- Browser-facing API/WS envelope に remote base URL/token/direct endpoint/socket/session path を露出しない。
- Focused workspace-server tests cover mocked remote routing and error mapping。
Implementation latitude:
- HTTP/WS client dependencies、mock remote test harness、internal source/handle trait shape、error type naming は Coder が既存 `workspace-server` pattern に合わせて選べる。
- v0 config-like data は in-memory/static constructor/test fixture でよい。Dynamic registration は不要。
Escalate if:
- worker-runtime REST/WS public API 変更が必要になる。
- Profile/config sync がないと remote Worker creation が成立しない場合。
- Browser-facing API schema を大きく変える必要がある場合。
Validation:
- `cargo fmt --all`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- remote endpoint/token/direct URL leak。
- worker_id-only routing regression。
- remote REST/WS client errors being collapsed into generic unavailable。
- scope creep into dynamic registration/auth/Web Console/Profile sync。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T05:49:13Z from: queued to: inprogress reason: routing_accepted_after_remote_runtime_prerequisites_done field: state -->
## State changed
Routing decision: implementation_ready。
FS store、REST command server、WebSocket observation proxy、RuntimeRegistry foundation は done。Ticket body / relations / workspace state / accepted plan を確認し、remote worker-runtime process connection slice は unblocked と判断した。Profile/config sync は related であり v0 builtin/default fallback が許容されているため blocker ではない。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T05:50:28Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KVZSGT14-remote-runtime-registry`
- Branch: `work/00001KVZSGT14-remote-runtime-registry`
- Coder Worker spawned: `yoi-coder-00001KVZSGT14-remote-runtime`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `crates/workspace-server/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` if dependency/package changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Queued capacity notes:
- `00001KVZQHPNY` remains queued to avoid worker creation/config routing churn while remote Runtime source is inprogress.
- `00001KVZ9JGK0` remains queued to avoid overlapping Backend/Web Console API surface changes while remote source routing stabilizes.
- `00001KW04A8K6` remains queued because it depends on this remote Runtime source work.
---
<!-- event: implementation_report author: yoi-coder-00001KVZSGT14-remote-runtime at: 2026-06-26T06:16:32Z -->
## Implementation report
Implementation report:
実装完了。マージ・Ticket 更新・close・cleanup は行っていない。
Commit:
- `aeb12b3b8e16a948e6f8387f6fb50fec60c53cc4 feat: add remote runtime registry source`
変更ファイル:
- `crates/workspace-server/src/hosts.rs`
- `crates/workspace-server/src/server.rs`
- `crates/workspace-server/src/lib.rs`
- `crates/workspace-server/Cargo.toml`
- `Cargo.lock`
- `package.nix`
実装概要 / API 変更:
- `RuntimeRegistry` に remote worker-runtime source を追加。
- `RemoteRuntimeConfig`
- `RemoteWorkerRuntime`
- backend-owned REST client による remote Runtime 操作
- backend-owned WS observation source の生成
- Browser-facing の authority は `runtime_id + worker_id` のまま維持。
- remote base URL / token / direct endpoint は API payload に出さない設計。
- remote config の `Debug` も base URL/token を redaction。
- remote Runtime source summary を embedded/local と区別。
- `RuntimeSourceKind::RemoteHttp` を active source として利用。
- diagnostics も remote backend proxy として区別。
- routing 対応:
- runtime summary/status/capabilities
- host list
- worker list/detail
- worker create
- input
- stop
- cancel
- transcript
- WS event proxy source fallback
- Browser/API endpoint 追加:
- `POST /api/runtimes/{runtime_id}/workers/{worker_id}/stop`
- `POST /api/runtimes/{runtime_id}/workers/{worker_id}/cancel`
- error mapping:
- remote auth failure -> `RuntimeOperationFailed` / HTTP 401
- remote timeout -> HTTP 504
- unsupported -> HTTP 501
- other remote operation failures -> HTTP 502
- remote worker not found remains typed worker lookup failure path
- tests:
- mocked remote HTTP routing test
- secret/base URL non-leak assertion
- backend-owned WS observation source assertion
- remote auth error typed mapping test
Validation:
- `cargo fmt --all`: success
- `cargo test -p yoi-workspace-server`: success31 passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success after `package.nix` cargoHash update
Residual risks / review focus:
- remote HTTP client は `reqwest::blocking` を利用。現状の `RuntimeRegistry` trait が sync なので変更量を抑えているが、将来 remote 操作の並行性/latency を重視するなら async trait 化または server handler 側 blocking isolation を検討。
- v0 remote config は static/in-memory registration で、dynamic registration / full auth model / Profile config sync は非実装。
- remote Worker create は既存 embedded mapping と同じ `CreateWorkerRequest::tools_less` ベース。remote 側で Profile/config bundle sync が必要になる場合は別 Ticket 境界。
- WS observation は backend-private source fallback を追加。実 remote WS e2e は mock HTTP unit test ではなく既存 proxy tests + source生成テストでの確認に留めている。
---
<!-- event: review author: yoi-reviewer-00001KVZSGT14-remote-runtime at: 2026-06-26T06:21:31Z status: request_changes -->
## Review: request changes
Review result: request_changes
ブロッカー:
- `RuntimeObservationSourceConfig``#[derive(Debug)]` のまま `endpoint``bearer_token` を保持している(`crates/workspace-server/src/observation.rs:13-19`)。さらに `BackendObservationProxy``#[derive(Debug)]` でこの source map を内包している(`observation.rs:184-187`)。
- remote source ではここに実 remote WS endpoint と token が入る(`hosts.rs:1642-1647`)ため、`format!("{:?}", source/proxy)` や将来の debug log で base URL / direct endpoint / bearer token が漏れる。
- ユーザー指定の focus「API/WS payloads or Debug/log-worthy types で漏らさない」に反している。
確認できた良い点:
- Browser-facing REST API は概ね `runtime_id + worker_id` routing になっており、worker_id-only route は見当たらない。
- remote command は Backend-owned `reqwest::blocking` REST client、observation は Backend-owned WS proxy/client 境界で実装されている。
- API/WS の通常 payload 型には remote base URL/token/direct endpoint は載っていない。
- auth/timeout/unsupported/remote error/worker-not-found は typed diagnostic/error に寄せる実装になっている。
- dynamic registration / full auth / WebConsole / Profile sync への scope creep は見当たらない。
- `reqwest::blocking` は async handler 内で Tokio worker を最大 timeout 分ブロックするリスクがあるが、v0 の同期 `RuntimeRegistry` 境界かつ timeout ありなら今回は許容可能な設計負債と判断する。
必要な修正:
- `RuntimeObservationSourceConfig` と、それを内包する debug/log-worthy 型の `Debug` を手書き redaction にするか derive を外す。
- base URL / endpoint / token が `Debug` 出力に含まれない focused test を追加する。
検証: read-only で対象 commit/diff/source/tests を確認。テスト実行は未実施。
---
<!-- event: implementation_report author: yoi-coder-00001KVZSGT14-remote-runtime at: 2026-06-26T06:27:50Z -->
## Implementation report
Follow-up implementation report after review request_changes:
Commit:
- `38ff7d8f807256ec654fcf5655e04dcbad4d9041 fix: redact observation source debug output`
修正内容:
- `RuntimeObservationSourceConfig``Debug` derive を廃止し、手動 `Debug` 実装に変更。
- `runtime_id` / `worker_id` は残す。
- `endpoint``<backend-private>`
- `bearer_token``<redacted>`
- `BackendObservationProxy``Debug` derive を廃止し、手動 `Debug` 実装に変更。
- source map / state の中身は出さず、`source_count` と omitted state のみ表示。
- focused test を追加。
- source config の Debug に remote endpoint/base URL/path/token が含まれないこと。
- containing proxy の Debug に remote endpoint/base URL/path/token が含まれないこと。
Validation:
- `cargo fmt --all`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- 今回の修正対象だった Debug/log-worthy 経路の漏洩は塞いだ。
- `RuntimeObservationSourceConfig` 自体は Backend 内部で real endpoint/token を保持し続ける。これは remote WS proxy 実行に必要な内部保持であり、API/WS payload には出していない。
- 将来 `Display` や手動ログで field を直接出す実装を追加する場合は別途注意が必要。
---
<!-- event: review author: yoi-reviewer-00001KVZSGT14-remote-runtime at: 2026-06-26T06:29:12Z status: approve -->
## Review: approve
Review result: approve
ブロッカーは解消済み。
確認内容:
- `RuntimeObservationSourceConfig` は manual `Debug` になり、`runtime_id` / `worker_id` のみ実値、`endpoint` は `<backend-private>`、`bearer_token` は `<redacted>` 表示になっている。
- `BackendObservationProxy` も manual `Debug` になり、source map / state internals を出さず `source_count` と omitted marker だけを出すため、内包する remote endpoint/token が Debug 経由で漏れない。
- 追加テストは source config と proxy Debug の forbidden host/path/token 非混入を検証している。
- 差分は `observation.rs` の redaction/test に限定され、API/WS payload 形状や remote routing への scope creep は見当たらない。
検証:
- read-only inspection のみ実施。テスト実行はしていない。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T06:29:53Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KVZSGT14-remote-runtime-registry` を orchestration branch に merge 済み。
- Merge commit: `bbb5d68c merge: 00001KVZSGT14 remote runtime registry`
Included implementation commits:
- `aeb12b3b8e16a948e6f8387f6fb50fec60c53cc4 feat: add remote runtime registry source`
- `38ff7d8f807256ec654fcf5655e04dcbad4d9041 fix: redact observation source debug output`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p yoi-workspace-server`: success33 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。前回 blocker だった Debug/log-worthy endpoint/token redaction は解消済み。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T06:30:04Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
Backend RuntimeRegistry remote worker-runtime process connection の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `bbb5d68c merge: 00001KVZSGT14 remote runtime registry`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p yoi-workspace-server`: success33 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- Backend RuntimeRegistry に remote worker-runtime process source/handle を追加し、Backend-owned REST/WS client 経由で route/proxy できるようにした。
- Dynamic registration / full auth / Web Console / Profile config sync は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T06:30:50Z -->
## Implementation report
Cleanup report:
- Child Workers stopped one-by-one and scope reclaimed:
- `yoi-coder-00001KVZSGT14-remote-runtime`
- `yoi-reviewer-00001KVZSGT14-remote-runtime`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KVZSGT14-remote-runtime-registry`
- Child implementation branch removed:
- `work/00001KVZSGT14-remote-runtime-registry`
Operational note:
- StopPod was executed sequentially, not in parallel.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -0,0 +1,5 @@
{"id":"orch-plan-20260625-203613-1","ticket_id":"00001KW04A8K6","kind":"blocked_by","related_ticket":"00001KVZSGT14","note":"Queue routing checked. TUI migration to Runtime API/WebSocket depends on remote/backend runtime connection and WebSocket observation proxy foundation. Those dependencies are not done; keep this Ticket queued.","author":"yoi-orchestrator","at":"2026-06-25T20:36:13Z"}
{"id":"orch-plan-20260626-054937-2","ticket_id":"00001KW04A8K6","kind":"blocked_by","related_ticket":"00001KVZSGT14","note":"TUI migration depends on remote Runtime process connection `00001KVZSGT14`, which is now inprogress. Keep queued until remote source routing is reviewed/merged/done.","author":"yoi-orchestrator","at":"2026-06-26T05:49:37Z"}
{"id":"orch-plan-20260626-063414-3","ticket_id":"00001KW04A8K6","kind":"waiting_capacity_note","note":"TUI migration is left queued while Profile/config bundle sync `00001KVZQHPNY` is accepted/inprogress. Runtime worker creation/profile semantics are still being finalized; start after bundle sync branch is reviewed/merged/done to avoid API churn.","author":"yoi-orchestrator","at":"2026-06-26T06:34:14Z"}
{"id":"orch-plan-20260626-074213-4","ticket_id":"00001KW04A8K6","kind":"waiting_capacity_note","note":"TUI Runtime API/WebSocket migration is left queued while Web Console MVP `00001KVZ9JGK0` is accepted/inprogress. Both are UI/control-surface consumers of the new Runtime APIs; start TUI migration after Web Console branch is reviewed/merged/done to avoid API/UX churn.","author":"yoi-orchestrator","at":"2026-06-26T07:42:13Z"}
{"id":"orch-plan-20260626-080943-5","ticket_id":"00001KW04A8K6","kind":"accepted_plan","note":"All dependencies are now done: WebSocket proxy, Registry foundation, embedded/remote Runtime connections, REST command server, and Web Console/config bundle foundation. No active inprogress remains.","accepted_plan":{"summary":"TUI connection backend を旧 socket authority から Backend Runtime API / WebSocket observation stream へ移行する。既存 Console rendering/composer/status を活かし、Runtime event adapter、input command path、cursor/reconnect diagnostics、legacy debug/compat path separation を実装する。","branch":"work/00001KW04A8K6-tui-runtime-api","worktree":"/home/hare/Projects/yoi/.worktree/00001KW04A8K6-tui-runtime-api","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に TUI/client/protocol/yoi CLI 関連 crate と必要最小 Cargo/package files の write scope を委譲する。reviewer Worker は read-only で Backend API authority、runtime_id+worker_id routing、legacy/debug path separation、event adapter correctness、credential/path non-leak、TUI regressions を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-26T08:09:43Z"}

View File

@ -0,0 +1,45 @@
{
"version": 1,
"relations": [
{
"ticket_id": "00001KW04A8K6",
"kind": "depends_on",
"target": "00001KVZKSTJT",
"note": "TUI output observation depends on Runtime WebSocket event streams or their Backend proxy.",
"author": "yoi ticket",
"at": "2026-06-25T19:33:49Z"
},
{
"ticket_id": "00001KW04A8K6",
"kind": "depends_on",
"target": "00001KVZKSV6C",
"note": "TUI Runtime connection should build on the Backend RuntimeRegistry foundation.",
"author": "yoi ticket",
"at": "2026-06-25T19:33:49Z"
},
{
"ticket_id": "00001KW04A8K6",
"kind": "depends_on",
"target": "00001KVZSGT0Q",
"note": "TUI needs Backend routing to embedded worker-runtime for backend-internal Workers.",
"author": "yoi ticket",
"at": "2026-06-25T19:33:49Z"
},
{
"ticket_id": "00001KW04A8K6",
"kind": "depends_on",
"target": "00001KVZSGT14",
"note": "TUI needs Backend routing/proxying to remote Runtime processes for remote Workers.",
"author": "yoi ticket",
"at": "2026-06-25T19:33:49Z"
},
{
"ticket_id": "00001KW04A8K6",
"kind": "related",
"target": "00001KVZKSTE2",
"note": "Runtime REST command server provides the remote command path that Backend proxies for TUI input.",
"author": "yoi ticket",
"at": "2026-06-25T19:33:49Z"
}
]
}

View File

@ -0,0 +1,102 @@
---
title: 'TUIをRuntime API/WebSocket接続へ移行する'
state: 'closed'
created_at: '2026-06-25T19:32:38Z'
updated_at: '2026-06-26T17:46:04Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-25T20:34:42Z'
---
## 背景
現在の TUI は旧 Pod / Worker process の Unix socket に直接 attach し、connect-time `Snapshot`、`Append`、`Status` などの protocol event を読んで Console 表示を構築している。一方、Worker/Runtime 移行後は、Worker は Runtime 内の実行単位であり、Runtime は REST command API と WebSocket observation stream を公開する。Backend は RuntimeRegistry を通じて embedded / remote / compatibility runtime を束ね、Browser や将来の TUI は Runtime endpoint / socket path / session path を直接 authority として扱わない方向にする。
この Ticket では、Runtime API / WebSocket observation がある程度整った後、TUI の接続 backend を旧 Pod socket 直結から Runtime API / Backend proxy / WebSocket stream に移行する。既存 TUI の Console rendering / composer / status UI は活かしつつ、入力送信と出力購読の transport を Runtime model に合わせる。
## 目的
- TUI が旧 Pod socket path を直接 authority としない接続経路へ移行する。
- TUI が `runtime_id + worker_id` を対象 identity として扱える。
- TUI の input は Runtime command API 経由で送る。
- TUI の output / status / transcript update は Runtime WebSocket observation stream 由来の event projection で受ける。
- 旧 Pod attach path は移行期間の compatibility / debug path として扱い、正規 path ではなくす。
## 要件
### Connection model
- TUI は Runtime / Worker target を `runtime_id + worker_id` で指定できる。
- TUI は Backend RuntimeRegistry / Runtime routing / Runtime endpoint credential 管理を内部実装しない。
- TUI は Browser と同じく、原則として Backend API に接続する client として振る舞う。
- Backend が RuntimeRegistry / policy / visibility / audit / runtime routing を担う。
- TUI -> Backend -> embedded Runtime direct call。
- TUI -> Backend -> remote Runtime REST/WS client。
- TUI -> Backend -> local compatibility adapter。
- TUI が remote Runtime endpoint / credential / raw socket path / raw session path を直接受け取らない。
- Local-only debug mode として direct Runtime endpoint / legacy socket attach を残す場合は、明示的な debug/compat mode とする。
### Input path
- Composer input は Runtime command API へ送る。
- v0 input は user message を最小単位とする。
- Busy / rejected / worker not found / runtime unavailable / provider error を TUI の status/error 表示に map する。
- 既存 `UserMessage` acceptance evidence 相当を、Runtime command accepted / run started event に置き換える。
### Output / observation path
- TUI は Runtime WebSocket event stream または Backend-proxied observation stream を購読する。
- Runtime event を TUI Console model へ変換する adapter を実装する。
- 少なくとも以下を扱う。
- worker snapshot / initial transcript projection。
- user input accepted / transcript append。
- assistant text delta / final。
- reasoning / thinking visibility policy に基づく event。
- tool call lifecycle。
- run started / completed / errored。
- usage。
- status / diagnostics。
- Event cursor / reconnect / replay / duplicate event handling を TUI 側で扱う。
- Raw provider trace / raw full session log は TUI event path の authority にしない。
### Existing TUI modelとの関係
- 既存 TUI の rendering component、composer、scrollback、status/actionbar 表示は可能な限り維持する。
- 旧 Pod protocol event から直接 UI block を作る path と、新 Runtime event から UI block を作る path を分ける。
- 旧 `Event::Snapshot` / `Event::Append` / `Event::Status` と Runtime event の対応を明示する。
- 連続 Thinking block grouping、in-flight snapshot、tool call rendering など既存 UI semantics が regress しないようにする。
### Compatibility / migration
- 移行途中で HEAD の `cargo run --bin yoi -- panel` / TUI が旧 Pod list 取得に失敗する可能性は許容するが、最終的には RuntimeRegistry / Worker projection を正とする。
- 旧 Pod socket attach は完全互換を目標にしない。
- ただし dogfooding に必要な範囲で、legacy local Worker compatibility adapter 経由の attach/read はできるようにする。
- Compatibility path を残す場合も、新規設計の正規 API と混同しない naming / CLI flag / diagnostics にする。
## Non-goals
- `worker-runtime` core crate の作成。
- Runtime REST command server の作成。
- Runtime WebSocket event stream server の作成。
- Backend RuntimeRegistry の embedded / remote 接続実装。
- Web Console UI の完成。
- 旧 Pod socket protocol の完全互換維持。
- Raw session storage migration。
- Full multi-user auth / permission model。
## 受け入れ条件
- TUI が `runtime_id + worker_id` を対象として接続できる。
- TUI が Backend API client として実装され、Backend RuntimeRegistry / Runtime routing / Runtime endpoint credential 管理を内部実装していない。
- TUI input が Backend/Runtime command API 経由で Worker に届く。
- TUI が Runtime WebSocket observation stream または Backend-proxied stream から Worker output/status events を受け取る。
- Runtime events が既存 TUI Console model に変換され、user message / assistant output / status / error が表示される。
- Initial transcript / snapshot 相当の表示ができる。
- Reconnect / cursor resume / duplicate event の基本動作が実装されている、または明確な typed diagnostic になる。
- Browser/remote Runtime credential/socket/session path を TUI が authority として扱わない。
- 旧 Pod socket attach path は正規 path ではなく compatibility/debug path として分離されている。
- Focused TUI tests or adapter tests が追加されている。
- `cargo test -p tui` または該当 TUI crate test が通る。
- `cargo check -p yoi` が通る。
- `git diff --check` が通る。
- `nix build .#yoi --no-link` が通る。

View File

@ -0,0 +1 @@
Completed, reviewed, validated, and merged into develop.

View File

@ -0,0 +1,351 @@
<!-- event: create author: "yoi ticket" at: 2026-06-25T19:32:38Z -->
## 作成
LocalTicketBackend によって作成されました。
---
<!-- event: intake_summary author: hare at: 2026-06-25T19:56:23Z -->
## Intake summary
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-25T19:56:23Z from: planning to: ready reason: cli_state field: state -->
## State changed
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: workspace-panel at: 2026-06-25T20:34:42Z from: ready to: queued reason: queued field: state -->
## State changed
Ticket を `workspace-panel` が queued にしました。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-25T20:36:43Z -->
## Decision
Routing decision: blocked_by_dependency_or_missing_authority
Reason:
- Dashboard Queue 後に Ticket / relations / workspace state を確認した。
- 本 Ticket は Runtime API / WebSocket observation への TUI移行であり、Backend RuntimeRegistry foundation、embedded/remote Runtime routing、WebSocket observation proxy が前提。
- 現在 `00001KVZKSV6C` は inprogress、`00001KVZKSTJT` / `00001KVZSGT0Q` / `00001KVZSGT14` は queued/blocked。TUI migration を先に始めると transport/API の未確定部分を TUI 側で固定してしまうため開始しない。
Evidence checked:
- Ticket body: TUI connection model、input path、output/observation path、Runtime WebSocket / Backend proxy reliance、compatibility/debug path。
- Relations: outgoing dependencies include `00001KVZKSTJT`, `00001KVZKSV6C`, `00001KVZSGT0Q`, `00001KVZSGT14`
- Orchestration plan: blocker record `orch-plan-20260625-203613-1` を追加。
Next action:
- 本 Ticket は queued のまま待機。
- Backend RuntimeRegistry / embedded+remote Runtime / WS proxy chain が done になった後に再 routing する。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-26T08:10:06Z -->
## Decision
Routing decision: implementation_ready
Reason:
- All blocking dependencies are done: WebSocket observation proxy, RuntimeRegistry foundation, embedded Runtime connection, remote Runtime connection, REST command server, config bundle sync, and Web Console MVP.
- Current `inprogress` is 0 and this is the only queued Ticket.
- Ticket body has clear connection model, input path, output/observation path, compatibility/migration boundaries, acceptance criteria, and validation requirements.
Evidence checked:
- Ticket body: TUI Runtime/Worker target identity, Backend API client model, input command path, WebSocket observation path, existing TUI model relation, compatibility/debug path, acceptance criteria。
- Relations: depends_on `00001KVZKSTJT`, `00001KVZKSV6C`, `00001KVZSGT0Q`, `00001KVZSGT14`; all are done. Related REST command server is done.
- Orchestration plan: accepted plan `orch-plan-20260626-080943-5` recorded.
- Workspace state: orchestration worktree clean; no spawned child Workers currently active.
IntentPacket:
Intent:
- TUI の正規接続経路を Backend Runtime API / WebSocket observation stream に移行し、`runtime_id + worker_id` を対象 identity として input/output/status を扱う。
Binding decisions / invariants:
- TUI は remote Runtime endpoint / token / raw socket path / raw session path を authority として扱わない。
- Backend RuntimeRegistry / routing / endpoint credential 管理を TUI 内部に実装しない。TUI は Backend API client として振る舞う。
- Legacy direct socket attach を残す場合は compatibility/debug path として明確に分離し、正規 path と混同しない naming/diagnostics にする。
- Runtime event adapter は既存 Console model へ変換するが、raw provider trace / raw full session log を authority にしない。
- Full auth/multi-user permission model、raw session storage migration、旧 socket protocol 完全互換は Non-goals。
Requirements / acceptance criteria:
- TUI が `runtime_id + worker_id` target で接続できる。
- Input は Backend/Runtime command API 経由で Worker に届く。
- Output/status/transcript update は Runtime/Backend-proxied WebSocket observation stream から受け取る。
- Runtime events が existing TUI Console model に変換され、user message / assistant output / status / error が表示される。
- Initial transcript/snapshot 相当を表示できる。
- Reconnect / cursor resume / duplicate event は基本実装、または typed diagnostic になる。
- Browser/remote Runtime credential/socket/session path を TUI が authority として扱わない。
- Focused TUI/adapter tests が追加される。
Implementation latitude:
- CLI flag/selector UX、Backend API client module placement、Runtime event to Console block adapter design、cursor/reconnect policy は Coder が既存 TUI architecture に合わせて選べる。
- v0 は Backend API が提供する known Runtime/Worker projection に合わせ、dogfoodingに必要な legacy compatibility/debug modeを明示的に残してよい。
- Existing rendering/composer/status components は可能な範囲で再利用。
Escalate if:
- TUI に Runtime endpoint/token/socket/session path を直接渡す必要が出る。
- Backend API/WS が TUI migration に不足し、server foundation の大幅追加が必要になる。
- Existing Console rendering semantics を大きく削る必要がある。
- Pseudo-runtime adapter で userに実 runtime接続と誤認させる必要が出る。
Validation:
- `cargo fmt --all`
- `cargo test -p tui` または該当 TUI crate tests
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Backend/Runtime credential/path leak。
- `worker_id`-only or legacy socket authority regression。
- Runtime event adapter dropping/duplicating transcript events。
- Cursor/reconnect duplicate handling。
- Legacy debug path accidentally becoming the default path。
- Terminal UI regressions that need real TTY/manual validation notes。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T08:10:15Z from: queued to: inprogress reason: routing_accepted_after_runtime_ui_foundation_done field: state -->
## State changed
Routing decision: implementation_ready。
WebSocket observation proxy、RuntimeRegistry foundation、embedded/remote Runtime connection、REST command server、config bundle sync、Web Console MVP は done。Ticket body / relations / workspace state / accepted plan を確認し、TUI Runtime API / WebSocket migration は unblocked と判断した。accepted plan と IntentPacket は thread / orchestration plan に記録済み。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T08:11:15Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KW04A8K6-tui-runtime-api`
- Branch: `work/00001KW04A8K6-tui-runtime-api`
- Coder Worker spawned: `yoi-coder-00001KW04A8K6-tui-runtime`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `crates/tui/**`, `crates/client/**`, `crates/protocol/**`, `crates/yoi/**`, `crates/workspace-server/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` if dependency/package changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Queue status:
- This was the last queued Ticket in the current chain; no other queued Ticket remains pending in this acceptance pass.
---
<!-- event: implementation_report author: yoi-coder-00001KW04A8K6-tui-runtime at: 2026-06-26T08:43:52Z -->
## Implementation report
Implementation report:
実装完了。merge/close/cleanup は行っていない。
Commit:
- `63ec9f95 feat: add backend runtime console target`
変更ファイル:
- `Cargo.lock`
- `crates/client/Cargo.toml`
- `crates/client/src/backend_runtime.rs`
- `crates/client/src/lib.rs`
- `crates/tui/src/console/mod.rs`
- `crates/tui/src/lib.rs`
- `crates/yoi/src/main.rs`
- `package.nix`
実装概要:
- `client` crate に Backend Runtime API 用クライアントを追加。
- authority は `Backend API base URL + runtime_id + worker_id`
- Runtime endpoint / token / raw socket path / raw session path は TUI 側の authority として扱っていない。
- `POST /api/runtimes/{runtime_id}/workers/{worker_id}/input` で user/system input を送信。
- `POST .../cancel` / `POST .../stop` で cancel/stop を送信。
- `GET .../transcript` から初期 transcript 相当を TUI event に変換。
- `WS .../events/ws` で Backend-proxied Runtime observation stream を購読。
- cursor resume / duplicate sequence drop / cursor expiry diagnostic + reset/reconnect を実装。
- Backend diagnostic / unsupported command / HTTP decode/send failure は TUI に `Event::Error` として表示。
- TUI Console に Backend Runtime 接続モードを追加。
- `LaunchMode::BackendRuntime { target }`
- 既存 Console rendering/composer/status の `App::handle_worker_event``protocol::Event` を流して再利用。
- legacy socket path は `ConsoleConnection::LegacySocket` として明示分離。
- CLI に Backend Runtime target selector を追加。
- `--backend <URL>`
- `--runtime-id <ID>` / alias `--runtime <ID>`
- `--worker-id <ID>`
- 3つは必須セット。
- `--worker` / `--socket` / `--session` / `--profile` との混在を拒否。
- help 上で `--socket` は compatibility/debug direct socket attach と明記。
- Focused tests を追加。
- Backend command mapping。
- Backend WS URL generation using `runtime_id + worker_id`
- Transcript projection → TUI Console event sequence。
- CLI Backend Runtime target parsing / incomplete identity rejection / legacy option mix rejection。
Validation:
- `cargo fmt --all`: success
- `cargo test -p tui`: success382 passed
- `cargo test -p yoi parse_backend_runtime_target`: success3 passed
- `cargo test -p client backend_runtime::tests`: success3 passed
- `cargo check -p yoi`: success
- `git diff --check` / `git diff HEAD --check`: success
- `nix build .#yoi --no-link`: success
Additional note:
- `cargo test -p client` 全体も一度実行したが、既存の `ticket_role::tests::scaffold_config_allows_intake_and_orchestrator_launch_planning` が Lua builtin profile 評価エラーで失敗。今回追加した `backend_runtime::tests` は個別に成功。
Residual risks / review focus:
- Backend Runtime mode は既存 Backend endpoint 形状に合わせた薄い API client 実装で、Runtime routing / endpoint credential management は TUI 側に入れていない。
- pause/resume/compact/rewind/completion lookup 等、Backend API にまだ対応 endpoint がない TUI commands は diagnostic 表示のみで送信しない。
- 初期 transcript は Backend transcript projection から user/assistant chat event に変換。raw session log / provider trace は authority として使っていない。
- default local spawn / legacy Worker-name attach 経路は既存互換として残る。Backend Runtime target 経路は `--backend + --runtime-id + --worker-id` による明示接続。
---
<!-- event: review author: yoi-reviewer-00001KW04A8K6-tui-runtime at: 2026-06-26T08:52:42Z status: approve -->
## Review: approve
Review result: approve
確認結果として、Ticket の主要要件は満たしていると判断する。
確認内容:
- Backend API authority:
- TUI 側は `backend_url + runtime_id + worker_id``BackendRuntimeTarget` を authority とし、Runtime endpoint/token/raw socket/session path を扱っていない。
- Backend/Runtime Registry/credential routing は TUI 内に実装されておらず、Backend API client として分離されている。
- `runtime_id + worker_id`:
- CLI は `--backend` に加えて `--runtime-id`/`--runtime` と `--worker-id` を必須化しており、worker_id-only 回帰は見当たらない。
- legacy options との mixing reject も確認。
- command / observation:
- input は Backend API の `/input`、cancel/stop は lifecycle API 経由。
- transcript 初期投影 + Backend-proxied WS observation stream を Console 既存 model に流す構成。
- `UserMessage` / assistant text delta/done / status / error は既存 `protocol::Event` として扱われ、Console rendering/composer/status を再利用している。
- reconnect/cursor:
- sequence duplicate drop、cursor resume、cursor expired diagnostic + reset/reconnect が実装されている。
- unsupported command は diagnostic event として返す実装を確認。
- legacy/debug path:
- raw `--socket` は explicit path として残り、BackendRuntime mode とは混在不可。
- help 文面上は `--socket` が compatibility/debug であることや backend options が十分に目立っていないため後続改善余地はあるが、今回の機能成立を阻害する blocker ではない。
検証実施:
- `cargo test -p yoi parse_backend_runtime_target`: success
- `cargo test -p client backend_runtime::tests`: success
- `cargo test -p tui`: success
- `cargo check -p yoi`: success
- `git diff --check HEAD^..HEAD`: success
報告されている `cargo test -p client` full の既存 Lua builtin profile failure は、この差分の focused validation 上は blocker ではないと判断する。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T08:54:28Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KW04A8K6-tui-runtime-api` を orchestration branch に merge 済み。
- Merge commit: `0a683bb2 merge: 00001KW04A8K6 tui runtime migration`
Included implementation commit:
- `63ec9f95 feat: add backend runtime console target`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo test -p tui`: success382 tests passed
- `cargo test -p yoi parse_backend_runtime_target`: success3 tests passed
- `cargo test -p client backend_runtime::tests`: success3 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。Backend API authority、`runtime_id + worker_id` target、event adapter、cursor/reconnect diagnostic、legacy/debug path separation に blocker なし。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T08:54:39Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
TUI Runtime API / WebSocket migration の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `0a683bb2 merge: 00001KW04A8K6 tui runtime migration`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo test -p tui`: success382 tests passed
- `cargo test -p yoi parse_backend_runtime_target`: success3 tests passed
- `cargo test -p client backend_runtime::tests`: success3 tests passed
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- Backend Runtime API / Backend-proxied WebSocket observation stream を TUI Console target として追加。
- Legacy direct socket attach は compatibility/debug path として明示分離。
- Full auth/multi-user permission model / raw session migration / perfect legacy socket compatibility は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T08:55:31Z -->
## Implementation report
Cleanup report:
- Child Workers stopped one-by-one and scope reclaimed:
- `yoi-coder-00001KW04A8K6-tui-runtime`
- `yoi-reviewer-00001KW04A8K6-tui-runtime`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KW04A8K6-tui-runtime-api`
- Child implementation branch removed:
- `work/00001KW04A8K6-tui-runtime-api`
Operational note:
- StopPod was executed sequentially, not in parallel.
---
<!-- event: state_changed author: hare at: 2026-06-26T17:46:04Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-26T17:46:04Z status: closed -->
## 完了
Completed, reviewed, validated, and merged into develop.
---

View File

@ -0,0 +1 @@
{"id":"orch-plan-20260626-174605-1","ticket_id":"00001KW2GCPYF","kind":"accepted_plan","note":"Dashboard Queue accepted. No relation blockers, no inprogress work, orchestration worktree clean. Previous Runtime/Backend/TUI/WebConsole foundations are on develop/orchestration HEAD.","accepted_plan":{"summary":"Workspace Web Console を Companion 専用 route/sidebar から任意 Worker attach route へ再設計する。Worker list から `runtime_id + worker_id` で開き、Backend transcript/input/observation WS と protocol event rendering を使う。旧 `/console` route/fallback と standalone Console sidebar entry は残さない。","branch":"work/00001KW2GCPYF-worker-console-redesign","worktree":"/home/hare/Projects/yoi/.worktree/00001KW2GCPYF-worker-console-redesign","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `web/workspace` と必要な Backend API support (`crates/workspace-server`)、Cargo/package files の write scope を委譲する。reviewer Worker は read-only で route/navigation authority、runtime_id+worker_id attach、protocol::Event rendering semantics、metadata/diagnostics layout、legacy `/console` removal、Browser credential/path non-leak を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-26T17:46:05Z"}

View File

@ -0,0 +1,115 @@
---
title: 'Workspace Worker Consoleを任意Worker attach前提で再設計する'
state: 'done'
created_at: '2026-06-26T17:42:10Z'
updated_at: '2026-06-26T18:22:51Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-26T17:45:40Z'
---
## 背景
現在の Web Console は Companion MVP の延長として作られており、Workspace の正規 Console としては UX / 情報設計 / theme 統一 / attach model が不足している。Companion 専用 API と簡易チャット風 UI に寄っており、任意 Worker を `runtime_id + worker_id` で開く導線、TUI Console 相当の protocol event 表示、Workspace 全体と統一された visual design が弱い。
Runtime / Backend / Client の observation proxy と、Backend Runtime Worker API は既に任意 Worker attach の基盤になり得る。次は Companion 固定の Console を正規経路として延命せず、Workspace top の Worker list から任意 Worker Console を開ける UI として再設計する。
## 目的
- Workspace top の Worker list から任意 Worker の Console を開ける。
- Sidebar に standalone `Console` category / navigation entry を置かない。
- Console target は `runtime_id + worker_id` を authority とする。
- Companion は特別な Console 実装ではなく、通常 Worker として表示・attach できる。
- Companion は Backend 起動時の自動起動 Worker として Worker list に現れ、必要なら role badge / pinned display で識別する。
- 現行 Web Console UX は置き換え前提とし、Workspace theme と情報設計に合わせて新規設計する。
- TUI Console の見た目ではなく、`protocol::Event` を transcript / live UI state に落とす意味論を Web に移植する。
## 要件
### Navigation / route model
- 正規導線は Workspace top の Worker list から Console を開く形にする。
- Sidebar に standalone `Console` category / navigation entry を作らない。
- 既存の Companion 固定 `/console` route がある場合は正規 route として残さず、削除または Worker Console route へ置き換える。
- 旧 `/console` からの redirect / fallback は残さない。古い導線の互換維持より、正規 navigation と route authority を明確にする。
- Companion 専用の quick action / drawer / global composer が必要になった場合は、この Ticket ではなく後続の UX 設計として扱う。
### Attach model / routing
- Workspace top に Worker list を表示し、Worker row から Console を開ける。
- Console route / state は `runtime_id + worker_id` を target identity として持つ。
- Browser は Runtime endpoint / credential / socket path / session path を扱わない。
- Console は Backend Worker API を使う。
- Worker detail / capabilities。
- bounded transcript / Snapshot 相当。
- Backend client-facing observation WS。
- input API。
- Companion Worker は role / badge / pinned row などで識別してよいが、Console 実装は通常 Worker と共有する。
- Companion 専用の route / sidebar entry / Console implementation は作らない。
### UX redesign
- 現行 Companion Console UI を正規 Console として継続しない。
- Console の主表示は conversation / run stream と composer に集中する。
- runtime id、worker id、transport、capability、diagnostic などの metadata は常時幅を取らない。
- 必要な情報は compact header、details drawer、inspector、collapsible diagnostics へ退避する。
- Workspace 全体の theme / spacing / typography / color token と統一する。
- narrow width / wide width の両方で transcript が読みやすい layout にする。
- busy / unavailable / rejected / reconnecting / stale cursor などの状態は主導線を邪魔しない形で表示する。
### Protocol rendering model
- Web Console は `protocol::Event` を UI state に変換して表示する。
- TUI Console から移植する対象は rendering semantics と event handling であり、TUI の見た目や keybinding ではない。
- 少なくとも以下を表示対象にする。
- user message。
- assistant text delta / done。
- thinking block。
- tool call lifecycle。
- tool result。
- status / run start / run end / error。
- usage。
- snapshot / transcript reconstruction。
- in-flight output。
- 既に protocol / Backend WS で届く情報を、簡易 chat message へ潰しすぎない。
- 未実装の Runtime/permission/advanced control のための UI は作らない。
### Input / observation
- Composer input は Backend Worker input API へ送る。
- Live update は Backend client-facing observation WS から受ける。
- Initial render は bounded transcript / Snapshot 相当から構築する。
- WS reconnect / duplicate event / cursor resume は最低限破綻しない動作にするか、typed diagnostic として表示する。
- Worker が event streaming 非対応の場合は、polling / manual refresh / transcript-only などの degrade path を明示する。
## Non-goals
- Full permission / auth / redaction policy implementation。
- Runtime endpoint / credential を Browser に渡す direct Runtime attach。
- TUI の見た目そのものの Web 再現。
- 未実装 command / advanced control UI。
- Multi-worker split view。
- Full log viewer / raw provider trace viewer。
- Companion 専用 Console の新規拡張。
- Companion 専用 route / sidebar entry / quick action の設計。
- 旧 `/console` route の redirect / fallback 互換維持。
## 受け入れ条件
- Workspace top の Worker list から任意 Worker Console を開ける。
- Sidebar に standalone `Console` category / navigation entry が残っていない。
- Console target が `runtime_id + worker_id` で表現される。
- Companion Worker を通常 Worker として Console で開ける。
- Companion 専用 route / sidebar entry / Console implementation が正規導線に残っていない。
- 旧 `/console` route の redirect / fallback 互換が残っていない。
- 現行 Companion Console 固定 UI が正規 Console 導線から置き換えられている。
- Console UI が Workspace theme と統一され、metadata / diagnostics が主表示の幅を過剰に占有しない。
- Backend transcript / input / observation WS を使って Console が動作する。
- `protocol::Event` 由来の user / assistant / thinking / tool / status / error / usage が表示される。
- Streaming 非対応 Worker の degrade path が明示されている。
- Focused Web UI tests or component tests が追加されている。
- `cd web/workspace && deno task check` が通る。
- `cd web/workspace && deno task build` が通る。
- `cargo check -p yoi` が通る。
- `git diff --check` が通る。
- `nix build .#yoi --no-link` が通る。

View File

@ -0,0 +1,381 @@
<!-- event: create author: "yoi ticket" at: 2026-06-26T17:42:10Z -->
## 作成
LocalTicketBackend によって作成されました。
---
<!-- event: intake_summary author: hare at: 2026-06-26T17:45:26Z -->
## Intake summary
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-26T17:45:26Z from: planning to: ready reason: cli_state field: state -->
## State changed
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: workspace-panel at: 2026-06-26T17:45:40Z from: ready to: queued reason: queued field: state -->
## State changed
Ticket を `workspace-panel` が queued にしました。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-26T17:46:30Z -->
## Decision
Routing decision: implementation_ready
Reason:
- Dashboard Queue により routing 許可済み。
- Relations はなし、OrchestrationPlan も未設定だった。blocking dependency は見当たらない。
- Current `inprogress` is 0。orchestration worktree is clean and current HEAD already contains Runtime/Backend/WebSocket/WebConsole/TUI foundations.
- Ticket body は navigation/route model、attach routing、UX redesign、protocol rendering model、input/observation、Non-goals、acceptance criteria が具体的。
Evidence checked:
- Ticket body: Workspace top Worker list から任意 Worker Console、`runtime_id + worker_id` authority、Companion を通常 Worker として扱う、standalone Console sidebar entry / old `/console` fallback removal、protocol::Event rendering semantics、degrade path、validation requirements。
- Relations: none。
- Orchestration plan: accepted plan `orch-plan-20260626-174605-1` recorded。
- Workspace state: queued 1 / inprogress 0、orchestration clean、child spawned count 0。
IntentPacket:
Intent:
- Workspace Web Console を Companion 固定 UI から、Worker list 起点の任意 Worker attach Console に再設計する。
Binding decisions / invariants:
- Console target authority は `runtime_id + worker_id`
- Browser は Runtime endpoint / credential / socket path / session path を扱わない。
- Sidebar に standalone `Console` category / navigation entry を残さない。
- Companion は通常 Worker として list から attach する。Companion 専用 route/sidebar/Console implementation は正規導線に残さない。
- 旧 `/console` route redirect/fallback 互換は残さない。
- Backend Worker API / Backend client-facing observation WS を使う。
- TUI の見た目や keybinding は移植しない。移植対象は `protocol::Event` rendering semantics。
- 未実装 Runtime/permission/advanced control UI、multi-worker split view、raw provider trace viewer は作らない。
Requirements / acceptance criteria:
- Workspace top Worker list から任意 Worker Console を開ける。
- Console route/state は `runtime_id + worker_id` を持つ。
- Worker detail/capabilities、bounded transcript/Snapshot相当、observation WS、input API を使う。
- `protocol::Event` 由来の user / assistant / thinking / tool call/result / status / error / usage / snapshot / in-flight を表示する。
- Metadata/diagnostics は compact header/details/collapsible area に逃がし、主 transcript 幅を過剰に占有しない。
- Streaming 非対応 Worker は transcript-only/manual refresh等の degrade path を明示。
- Focused Web UI tests/component tests を追加する。
- `deno task check/build`, `cargo check -p yoi`, `git diff --check`, `nix build .#yoi --no-link` が通る。
Implementation latitude:
- Route naming、Worker list UI placement、component split、protocol event state model、degrade UI の詳細は Coder が existing `web/workspace` style に合わせて選べる。
- Backend API に小さな不足があれば `crates/workspace-server` で最小 support を追加してよい。
- Existing Companion provider-less backend can remain as a normal worker source, but no special Console UI path。
Escalate if:
- Browser に Runtime endpoint/token/socket/session path を渡す必要が出る。
- old `/console` fallback を残さないと navigation が成立しないと判明する。
- Full TUI parity / tool UI / raw provider trace viewer / multi-worker split view が必要になる。
- Backend protocol/WS foundation の大幅 redesign が必要になる。
Validation:
- `cargo fmt --all`
- `cargo check -p yoi`
- `cd web/workspace && deno task check`
- `cd web/workspace && deno task build`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- Companion special-case route/sidebar implementation が残ること。
- Route target が `runtime_id + worker_id` ではなく worker_id-only になること。
- Runtime endpoint/token/socket/session path leak。
- `protocol::Event` を簡易 chat message に潰しすぎること。
- Metadata/diagnostics が主 transcript を圧迫すること。
- Old `/console` redirect/fallback compatibility が残ること。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T17:46:39Z from: queued to: inprogress reason: routing_accepted_worker_console_redesign field: state -->
## State changed
Routing decision: implementation_ready。
Ticket body / relations / workspace state / accepted plan を確認し、Workspace Worker Console redesign は unblocked と判断した。Relations はなく、current `inprogress` は 0。accepted plan と IntentPacket は thread / orchestration plan に記録済み。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T17:47:26Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KW2GCPYF-worker-console-redesign`
- Branch: `work/00001KW2GCPYF-worker-console-redesign`
- Coder Worker spawned: `yoi-coder-00001KW2GCPYF-worker-console`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `web/workspace/**`, `crates/workspace-server/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` if dependency/package changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
---
<!-- event: implementation_report author: yoi-coder-00001KW2GCPYF-worker-console at: 2026-06-26T18:07:17Z -->
## Implementation report
Implementation report:
実装完了。merge / Ticket 更新 / close / cleanup は行っていない。
Commit:
- `c3fed591095244223e6da7c84ac7f1a2e4cf8cb7 feat: worker attach workspace console`
変更概要:
### UI / routing
- 旧 canonical `/console` route を削除。
- `web/workspace/src/routes/console/+page.svelte` 削除。
- 新 Console route を追加。
- `/runtimes/[runtimeId]/workers/[workerId]/console`
- Console target authority は `runtime_id + worker_id`
- standalone Console / Companion sidebar entry を削除。
- `CompanionNavSection.svelte` 削除。
- sidebar は Workers section から各 Worker Console へ attach する形に変更。
- Workspace top Worker list に `Open Console` attach action を追加。
- Companion は特別 route ではなく通常 Worker row として attach される想定に変更。
### Worker Console
- Backend Worker API のみを使う Console を追加。
- Worker detail: `/api/runtimes/{runtime_id}/workers/{worker_id}`
- bounded transcript: `/api/runtimes/{runtime_id}/workers/{worker_id}/transcript?limit=200`
- input: `/api/runtimes/{runtime_id}/workers/{worker_id}/input`
- observation WS: `/api/runtimes/{runtime_id}/workers/{worker_id}/events/ws`
- Browser 側では Runtime endpoint / credential / socket path / session path を扱わない。
- `protocol::Event` 由来の表示モデルを追加。
- user / assistant / thinking / tool / status / error / usage / snapshot / in-flight を区別表示。
- transcript-only item と observation event を source として分離。
- streaming unsupported Worker には明示的 degrade 表示を追加。
- “bounded transcript + manual refresh” の経路を提示。
- Worker detail / capabilities / diagnostics は右側 card の compact/collapsible 表示にして、transcript 幅を支配しない構成。
### tests
- Web Console projection/model tests 追加。
- protocol segment rendering
- event projection
- snapshot / in-flight state
- Worker target route href encoding
- UI contract tests 追加。
- Worker list/sidebar が Worker Console href を使うこと。
- standalone Companion nav が canonical でないこと。
- Console page が backend Worker APIs を使い `/api/companion` を使わないこと。
- `deno task test` を追加。
主な変更ファイル:
- `web/workspace/src/routes/runtimes/[runtimeId]/workers/[workerId]/console/+page.svelte`
- `web/workspace/src/routes/runtimes/[runtimeId]/workers/[workerId]/console/+page.ts`
- `web/workspace/src/lib/workspace-console/model.ts`
- `web/workspace/src/lib/workspace-console/model.test.ts`
- `web/workspace/src/lib/workspace-console/worker-console.ui.test.ts`
- `web/workspace/src/lib/workspace-pages/WorkspacePage.svelte`
- `web/workspace/src/lib/workspace-sidebar/WorkersNavSection.svelte`
- `web/workspace/src/lib/workspace-sidebar/WorkspaceSidebar.svelte`
- `web/workspace/src/lib/workspace-sidebar/types.ts`
- `web/workspace/src/app.css`
- `web/workspace/deno.json`
- `web/workspace/tsconfig.json`
削除:
- `web/workspace/src/routes/console/+page.svelte`
- `web/workspace/src/lib/workspace-sidebar/CompanionNavSection.svelte`
Validation:
- `cargo fmt --all`: success
- `cargo check -p yoi`: success
- `cd web/workspace && deno task test`: success6 tests passed
- `cd web/workspace && deno task check`: success0 errors / 0 warnings
- `cd web/workspace && deno task build`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: successdirty tree warning は実装 commit 前の通常 warning。build 自体は完了)
Residual risks / review focus:
- 実 Runtime / live Worker に対するブラウザ手動操作は未実施。特に observation WS の実イベント順序と snapshot/in-flight 表示の見え方は reviewer 側で確認推奨。
- `protocol::Event` projection は現在の generated protocol union を広く扱う実装だが、UI は raw trace viewer ではなく compact transcript 表示に寄せている。イベント種類ごとの表示粒度が過不足ないか確認してほしい。
- `deno task test` の UI contract tests は component runtime harness ではなく、現行 Deno/Svelte 構成に合わせた focused contract tests。将来 component test harness が入るなら置き換え候補。
---
<!-- event: review author: yoi-reviewer-00001KW2GCPYF-worker-console at: 2026-06-26T18:11:54Z status: request_changes -->
## Review: request changes
Review result: request_changes
ブロッカー:
- `web/workspace/src/routes/runtimes/[runtimeId]/workers/[workerId]/console/+page.svelte`
- lines 263-267 の `$effect``refreshConsole()` を呼び、
- `refreshConsole()` lines 128-130 が `reloadToken += 1``reloadToken` を読み書きしています。
- Svelte runes の `$effect` は effect 内で同期的に読んだ stateネストした関数呼び出し含むを依存として追跡するため、この effect は `reloadToken` に依存しつつ自分で更新し、再実行ループになります。
- 結果として Worker detail/transcript fetch が継続的に走り、line 269 の observation WS も `reloadToken` 依存で再接続を繰り返すリスクがあります。Console が安定して開けないため、Acceptance の「Worker list can open a Console」「observation WS/input/transcript を適切に使う」を満たせません。
確認済みの良い点:
- old `web/workspace/src/routes/console` は存在せず、`/api/companion` 参照も Console 実装には残っていません。
- 新 route は `/runtimes/[runtimeId]/workers/[workerId]/console`
- Worker list/sidebar は `runtime_id + worker_id``encodeURIComponent` して Console href を生成。
- protocol event projection、snapshot/in-flight、非 streaming Worker の degrade 表示、compact/collapsible diagnostics card は実装されています。
検証は read-only 方針に従い、ソース確認・`find`/`rg`・git 状態確認のみ実施しました。ビルド/テスト再実行は artifact/cache 作成の可能性があるため未実施です。
---
<!-- event: implementation_report author: yoi-coder-00001KW2GCPYF-worker-console at: 2026-06-26T18:19:12Z -->
## Implementation report
Follow-up implementation report after review request_changes:
Commit:
- `a1083908b681b420cd5fd911ac00da01ff8b7e5d fix: stabilize worker console refresh`
修正内容:
- Worker Console の target-change `$effect``refreshConsole()` を経由して `reloadToken += 1` する構造を解消。
- `reloadToken` は rune state のまま、非 reactive な `nextReloadToken` から `advanceReloadToken()` で単調更新する形に変更。
- `reloadToken` 自体を同期 read/write しないため、target-change effect の dependency cycle を避ける。
- 初期表示 / target-change refresh は `loadConsoleData(target)` を直接呼ぶように分離。
- manual refresh は引き続き `advanceReloadToken()` してから Worker detail / transcript を再取得するため、WS reconnect semantics は維持。
- observation WS effect は `worker + reloadToken + consoleTarget` に依存し、manual refresh / target-change で安定して reconnect。
- focused static/contract test を追加・調整し、以下を確認。
- `reloadToken += 1` が残っていない。
- reload token advancement が `nextReloadToken` 経由。
- target-change effect が `refreshConsole()` 経由の dependency cycle に戻らない。
Validation:
- `cargo fmt --all`: success
- `cargo check -p yoi`: success
- `cd web/workspace && deno task test`: success6 passed
- `cd web/workspace && deno task check`: success0 errors / 0 warnings
- `cd web/workspace && deno task build`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: successdirty tree warning は未 commit 差分によるもの。build は成功)
Residual risks / review focus:
- 実ブラウザ + live Worker での操作確認は未実施。
- 今回の fix は Svelte runes の dependency loop 解消に絞っている。WS の実接続タイミングや stale async response の UX は既存設計の範囲。
---
<!-- event: review author: yoi-reviewer-00001KW2GCPYF-worker-console at: 2026-06-26T18:21:17Z status: approve -->
## Review: approve
Review result: approve
確認結果:
- 対象 worktree は branch `work/00001KW2GCPYF-worker-console-redesign`、HEAD は fix commit `a1083908b681b420cd5fd911ac00da01ff8b7e5d`
- 前回 blocker は解消済み。
- `reloadToken += 1` は残っていない。
- target-change `$effect``refreshConsole()` を呼ばず、`consoleTarget` を読んで `advanceReloadToken()` + `loadConsoleData(target)` のみ実行している。
- `advanceReloadToken()` は非 reactive な `nextReloadToken` を増やして `reloadToken` に代入する形で、同じ effect 内で `reloadToken` を read/write する依存ループにはなっていない。
- observation WS effect は `worker + reloadToken + consoleTarget` に依存し、manual refresh / target change で reconnect される構造として妥当。
- regression なし。
- old `/console` route は存在しない。
- standalone `CompanionNavSection` / `/api/companion` 利用は Console 実装に戻っていない。
- Worker list/sidebar は `workerConsoleHref(worker)` 経由で `runtime_id + worker_id` route に attach している。
- Backend Worker detail/transcript/input/observation WS API の使用も維持されている。
検証:
- read-only のソース確認、git 状態確認、`find`/`rg` による route/API/sidebar 残存確認。ビルド・テスト再実行はファイル生成の可能性があるため未実施。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T18:21:56Z -->
## Implementation report
Integration / validation report:
Integration:
- Implementation branch `work/00001KW2GCPYF-worker-console-redesign` を orchestration branch に merge 済み。
- Merge commit: `864efe32 merge: 00001KW2GCPYF worker console redesign`
Included implementation commits:
- `c3fed591095244223e6da7c84ac7f1a2e4cf8cb7 feat: worker attach workspace console`
- `a1083908b681b420cd5fd911ac00da01ff8b7e5d fix: stabilize worker console refresh`
Validation in Orchestrator worktree:
- `cargo fmt --all --check`: success
- `cargo check -p yoi`: success
- `cd web/workspace && deno task test`: success6 tests passed
- `cd web/workspace && deno task check`: success0 errors / 0 warnings
- `cd web/workspace && deno task build`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Review:
- Reviewer approve 済み。前回 blocker だった Svelte runes `$effect` / `reloadToken` dependency loop は解消済み。
Outcome:
- Acceptance criteria を満たしたため `done` へ進める。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-26T18:22:10Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
## State changed
Workspace Worker Console redesign の実装、review、merge、Orchestrator validation が完了した。
Done evidence:
- Merge commit: `864efe32 merge: 00001KW2GCPYF worker console redesign`
- Reviewer approve 済み。
- Orchestrator validation:
- `cargo fmt --all --check`: success
- `cargo check -p yoi`: success
- `cd web/workspace && deno task test`: success6 tests passed
- `cd web/workspace && deno task check`: success0 errors / 0 warnings
- `cd web/workspace && deno task build`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Scope:
- Workspace Web Console を Companion-specific route/sidebar から Worker list driven arbitrary Worker attach route (`runtime_id + worker_id`) へ再設計。
- Old `/console` canonical route and standalone Companion Console sidebar entry were removed.
- Advanced controls / multi-worker split / raw provider trace viewer / full auth-redaction policy は Non-goals として未実装。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-26T18:22:51Z -->
## Implementation report
Cleanup report:
- Child Workers stopped one-by-one and scope reclaimed:
- `yoi-coder-00001KW2GCPYF-worker-console`
- `yoi-reviewer-00001KW2GCPYF-worker-console`
- Child implementation worktree removed:
- `/home/hare/Projects/yoi/.worktree/00001KW2GCPYF-worker-console-redesign`
- Child implementation branch removed:
- `work/00001KW2GCPYF-worker-console-redesign`
Operational note:
- StopPod was executed sequentially, not in parallel.
---

View File

@ -0,0 +1 @@
{"id":"orch-plan-20260627-190733-1","ticket_id":"00001KW55B32Y","kind":"accepted_plan","note":"Dashboard Queue accepted. No outgoing blockers for this boundary Ticket; downstream queued Tickets depend on it. Orchestration worktree clean and no inprogress work.","accepted_plan":{"summary":"`worker-runtime` に Worker execution backend の trait/handle/enum と lifecycle/input/protocol event publish contract を追加する。具体的な `worker` crate adapter は後続 Ticket に残し、execution backend 未接続 Worker が input accepted にならない型・状態・テスト境界を作る。","branch":"work/00001KW55B32Y-worker-runtime-execution-backend","worktree":"/home/hare/Projects/yoi/.worktree/00001KW55B32Y-worker-runtime-execution-backend","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/worker-runtime` と必要な Backend projection support (`crates/workspace-server`)、Cargo/package files の write scope を委譲する。reviewer Worker は read-only で execution backend 境界、input rejection/dispatch contract、protocol event hook、Browser-facing non-leak、fake/providerless response absence を確認する。merge/validation/done/cleanup は Orchestrator が行う。"},"author":"yoi-orchestrator","at":"2026-06-27T19:07:33Z"}

View File

@ -0,0 +1,74 @@
---
title: 'worker-runtimeにWorker実行Backend境界を追加する'
state: 'closed'
created_at: '2026-06-27T18:26:46Z'
updated_at: '2026-06-27T20:09:45Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-27T19:06:28Z'
---
## 背景
現在の `worker-runtime::Runtime` は Runtime / Worker identity、metadata、transcript projection、observation stream を持つが、既存 `worker` crate の実 LLM 実行に接続されていない。その結果、Backend / Web Console から見ると Worker として存在するが input を処理できない Worker が発生し得る。
これは Runtime/Worker model として不十分である。Worker として公開されるものは transcript / observation を読める必要があり、input を受け付ける Worker は実行 backend に接続されている必要がある。`can_stream_events` / `can_read_bounded_transcript` のような「中身を読めない Worker を表示するための capability」は正規 model に置かない。
この Ticket では、`worker-runtime` に実行 backend を差し込むための型境界と lifecycle contract を追加する。ここでは既存 `worker` crate への具体接続は後続 Ticket に残し、Runtime が「実行可能 Worker」と「実行 backend 未接続の placeholder」を混同しないための土台を作る。
## 目的
- Runtime が Worker execution backend を明示的に持てる。
- input を受け付ける Worker は execution backend に接続されていることを型・状態・テストで保証する。
- Worker transcript / observation は Worker の正規 contract として扱い、capability 扱いしない。
- fake / providerless assistant response を Runtime が生成しない。
- 後続で `worker` crate 実行 adapter を接続できる境界を作る。
## 要件
### Execution backend boundary
- `worker-runtime` に Worker execution backend の trait / handle / enum を追加する。
- execution backend は少なくとも以下を扱える形にする。
- Worker spawn / initialize 時の execution handle 作成。
- user input の実行 backend への dispatch。
- run state / busy / rejected / errored の typed 結果。
- stop / cancel が未実装の場合の typed rejection。
- protocol event を Runtime observation bus へ publish するための hook。
- execution backend 未接続の Worker に対して user input を accepted にしない。
- Runtime 自身が providerless text / canned assistant message を生成しない。
### Worker model invariant
- Worker として公開されるものは transcript projection / observation stream を読める。
- `can_stream_events` / `can_read_bounded_transcript` を public Worker capability として復活させない。
- input acceptance は capability 表示でごまかさず、execution backend 接続状態と runtime state に基づく typed operation result とする。
- execution backend がない Worker を UI の通常 input-capable Worker として見せない。
### API / compatibility
- RuntimeRegistry / Backend API が raw execution backend handle、socket path、credential、session path を Browser に露出しない。
- 既存 remote Runtime WS / Backend proxy model と矛盾しない。
- placeholder / not-connected 状態が必要な場合は diagnostic / state として表現し、fake assistant response で埋めない。
## Non-goals
- 既存 `worker` crate の実行 loop への具体接続。
- Workspace Companion を実 LLM 実行で動かすこと。
- Web Console UX の再設計。
- Full permission / auth / redaction policy。
- remote Runtime process の lifecycle 実装。
## 受け入れ条件
- `worker-runtime` に execution backend 境界がある。
- execution backend 未接続 Worker への input が accepted にならない。
- Runtime が fake / providerless assistant response を生成しない。
- Worker transcript / observation が正規 contract として扱われ、public `can_stream_events` / `can_read_bounded_transcript` capability が存在しない。
- RuntimeRegistry / Backend projection に raw backend handle / path / credential が漏れない。
- Focused tests が、backend 未接続 input rejection、backend 接続 Worker の input dispatch 境界、observation publish hook を確認する。
- `cargo test -p worker-runtime --features ws-server` が通る。
- `cargo test -p yoi-workspace-server` が通る。
- `cargo check -p yoi` が通る。
- `git diff --check` が通る。
- `nix build .#yoi --no-link` が通る。

View File

@ -0,0 +1,28 @@
`worker-runtime` に Worker execution backend 境界を追加し、reviewer approval 後に orchestration branch へ merge した。
実装内容:
- `WorkerExecutionBackend` trait / handle / context / status / result / operation / outcome を追加。
- backend 未接続 Worker への input を typed `WorkerExecutionUnavailable` として拒否。
- backend dispatch の busy / rejected / errored / unsupported を typed rejection として扱う。
- backend から Runtime observation bus へ `protocol::Event` を publish する hook を追加。
- stop / cancel unsupported の typed rejection を追加。
- `WorkerSummary` / `WorkerDetail` に raw handle/path/credential を含まない execution status projection を追加。
- Runtime が fake/providerless assistant response を生成しない境界を維持。
- `can_stream_events` / `can_read_bounded_transcript` public capability は復活させていない。
- `ws-server + fs-store` restore path で observation bus state を正しく初期化。
Integrated commits:
- `2d5971738478f832ba9a135601ea11dda60c565d feat: add worker execution backend boundary`
- `761b60c85750d03c119733a088fb5073f9b37e9a fix: initialize restored worker observations`
- merge: `0753e155 merge: worker runtime execution backend`
Validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Cleanup は child implementation worktree / branch と related role Pods のみを対象に実施する。

View File

@ -0,0 +1,437 @@
<!-- event: create author: "yoi ticket" at: 2026-06-27T18:26:46Z -->
## 作成
LocalTicketBackend によって作成されました。
---
<!-- event: intake_summary author: hare at: 2026-06-27T18:58:48Z -->
## Intake summary
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-27T18:58:48Z from: planning to: ready reason: cli_state field: state -->
## State changed
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: workspace-panel at: 2026-06-27T19:06:28Z from: ready to: queued reason: queued field: state -->
## State changed
Ticket を `workspace-panel` が queued にしました。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-27T19:07:57Z -->
## Decision
Routing decision: implementation_ready
Reason:
- Dashboard Queue により routing 許可済み。
- 本 Ticket は後続 adapter / Companion 実行 Ticket の前段となる execution backend boundary であり、具体的な `worker` crate adapter 実装は Non-goal として分離されている。
- Outgoing blocking relation はなく、current `inprogress` は 0。orchestration worktree is clean。
- Downstream queued Tickets (`00001KW55B33B`, `00001KW55B33H`) は本 Ticket 完了まで待機させる。
Evidence checked:
- Ticket body: execution backend boundary、input rejection/dispatch、protocol event publish hook、Worker model invariant、Browser-facing non-leak、Non-goals、acceptance criteria。
- Relations: incoming/downstream dependency chain is present via queued Tickets; this Ticket itself has no unresolved outgoing blocker。
- Orchestration plan: accepted plan `orch-plan-20260627-190733-1` recorded。
- Code context: current `worker-runtime::Runtime` / `catalog` / `workspace-server::hosts` have Runtime/Worker model and projection foundation but no concrete execution backend boundary yet。
- Workspace state: queued 3 / inprogress 0、orchestration clean。
IntentPacket:
Intent:
- `worker-runtime` に Worker execution backend 境界を追加し、Runtime が input-capable Worker と backend-unconnected placeholder を混同しないようにする。
Binding decisions / invariants:
- Execution backend 未接続 Worker への user input は accepted にしない。
- Runtime 自身が fake / providerless assistant response を生成しない。
- Worker transcript / observation は正規 contract とし、`can_stream_events` / `can_read_bounded_transcript` を public capability として復活させない。
- Execution backend handle / socket path / credential / session path / raw worker handle は Browser-facing API に出さない。
- 既存 `worker` crate への具体 adapter 接続、Workspace Companion real LLM execution、Web Console UX redesign は実装しない。
Requirements / acceptance criteria:
- `worker-runtime` に execution backend trait / handle / enum / lifecycle contract がある。
- backend connected Worker の input dispatch 境界と run state/busy/rejected/errored typed result がある。
- stop/cancel unsupported は typed rejection。
- protocol event を Runtime observation bus へ publish する hook がある。
- Focused tests が backend 未接続 input rejection、connected backend input dispatch boundary、observation publish hook を確認する。
- `cargo test -p worker-runtime --features ws-server`, `cargo test -p yoi-workspace-server`, `cargo check -p yoi`, `git diff --check`, `nix build .#yoi --no-link` が通る。
Implementation latitude:
- Backend boundary の具体型名、trait sync/asyncの形、test backend/fake backend の実装、Runtime state/projectionの最小変更は Coder が既存 `worker-runtime` design に合わせて選べる。
- `workspace-server` projection に必要な最小 diagnostic/state 表現は追加してよい。
- 既存 `worker` crate adapter に必要そうな shape は見越してよいが、実 adapter 実装はしない。
Escalate if:
- `worker` crate に大きく手を入れないと boundary 自体が定義できない。
- Browser-facing API に raw execution handle/path/credential を出す必要が出る。
- public capability として `can_stream_events` / `can_read_bounded_transcript` を戻さないと UI/API が成立しない。
- fake/providerless response を再導入しないと tests/UX が通らない。
Validation:
- `cargo fmt --all`
- `cargo test -p worker-runtime --features ws-server`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `git diff --check`
- 可能なら `nix build .#yoi --no-link`
Critical risks / reviewer focus:
- backend 未接続 Worker が input accepted になる regression。
- Runtime-generated fake/providerless assistant response の再導入。
- Browser-facing projection に execution backend internals/path/credential/session が漏れること。
- Worker transcript/observation を optional display capability として扱うこと。
- 後続 adapter Ticket の scope を先取りしすぎること。
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-27T19:08:06Z from: queued to: inprogress reason: routing_accepted_execution_backend_boundary field: state -->
## State changed
Routing decision: implementation_ready。
Ticket body / relation / workspace state / accepted plan を確認し、Worker execution backend boundary slice は unblocked と判断した。Downstream queued Tickets は本 Ticket の completion を待つ。accepted plan と IntentPacket は thread / orchestration plan に記録済み。
これ以降、worktree creation / coder Worker routing などの implementation side effect に進める。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-27T19:09:41Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KW55B32Y-worker-runtime-execution-backend`
- Branch: `work/00001KW55B32Y-worker-runtime-execution-backend`
- Coder Worker spawned: `yoi-coder-00001KW55B32Y-exec-backend`
Scope notes:
- Coder has read access to the implementation worktree and non-recursive workspace root identity path needed by runtime startup.
- Coder write scope is limited to `crates/worker-runtime/**`, `crates/workspace-server/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` if dependency/package changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Queued dependency notes:
- `00001KW55B33B` remains queued while this execution backend boundary is inprogress.
- `00001KW55B33H` remains queued behind `00001KW55B33B`.
---
<!-- event: implementation_report author: yoi-coder-00001KW55B32Y-exec-backend at: 2026-06-27T19:34:20Z -->
## Implementation report
Implementation report:
実装完了。マージ / close / cleanup は未実施。
Commit:
- `2d5971738478f832ba9a135601ea11dda60c565d feat: add worker execution backend boundary`
変更概要:
### `worker-runtime`
追加/変更:
- `crates/worker-runtime/src/execution.rs` を追加。
- `WorkerExecutionBackend` trait
- `WorkerExecutionHandle`
- `WorkerExecutionContext`
- `WorkerExecutionStatus`
- `WorkerExecutionRunState`
- `WorkerExecutionResult`
- `WorkerExecutionOperation`
- `WorkerExecutionOutcome`
- `WorkerExecutionSpawnRequest`
- `WorkerExecutionSpawnResult`
- `Runtime::with_execution_backend(...)` を追加。
- `Runtime::with_fs_store_and_execution_backend(...)` を追加。
- `WorkerSummary` / `WorkerDetail``execution` status を追加。
- `Runtime::create_worker(...)`
- backend 接続時は spawn/initialize 境界を呼ぶ。
- backend 未接続時は `execution.backend = unconnected`
- `Runtime::send_input(...)`
- backend 未接続 Worker への input を `WorkerExecutionUnavailable` で拒否。
- backend dispatch が `Busy` / `Rejected` / `Errored` / `Unsupported` を返した場合、typed `WorkerExecutionRejected` として拒否。
- dispatch accept 後のみ transcript / event / observation を通常 Worker contract として記録。
- `Runtime::stop_worker(...)` / `cancel_worker(...)`
- active かつ connected handle ありの場合は backend lifecycle 境界を呼ぶ。
- default backend implementation は unsupported typed rejection。
- backend から Runtime observation bus へ `protocol::Event` を publish できる hook を追加。
- HTTP API error mapping に execution unavailable/rejected を追加。
### `workspace-server`
- Embedded Worker input unavailable diagnostic を LLM 固有表現から execution backend 境界表現へ変更。
- `embedded_worker_execution_unavailable`
- RuntimeRegistry / Backend projection のテストで、Browser-facing JSON に以下が出ないことを確認。
- `can_stream_events`
- `can_read_bounded_transcript`
- raw URL/path/socket/session/credential/provider 系の既存禁止項目。
Validation:
- `cargo fmt --all`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- concrete `worker` crate adapter は意図通り未実装。下流 Ticket `00001KW55B33B` 側で今回の `WorkerExecutionBackend` trait に接続する想定。
- Embedded Runtime は現時点では backend-unconnected placeholder のままなので、workspace-server 側では input unavailable diagnostic を返す。
- backend trait は sync 境界として実装。実 adapter 実装時に async/process lifecycle、busy state、cancel semantics のレビューが必要。
- `WorkerSummary` / `WorkerDetail` の public JSON に `execution` が増えるが、handle/path/socket/credential/session/manifest など raw internals は含めていない。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-27T19:36:13Z -->
## Implementation report
Review kickoff:
Reviewer Worker spawned for `00001KW55B32Y` implementation.
- Reviewer Worker: `yoi-reviewer-00001KW55B32Y-exec-backend`
- Review target commit: `2d5971738478f832ba9a135601ea11dda60c565d feat: add worker execution backend boundary`
- Review mode: read-only implementation worktree review
Review focus:
- backend-unconnected input rejection and no transcript/event acceptance
- connected fake backend input dispatch boundary
- protocol event publish hook correctness
- stop/cancel unsupported typed rejection
- no fake/providerless assistant response
- no `can_stream_events` / `can_read_bounded_transcript` public capability regression
- no raw execution handle/path/socket/session/credential leakage
- no scope creep into concrete `worker` crate adapter or Companion real LLM execution
---
<!-- event: review author: yoi-reviewer-00001KW55B32Y-exec-backend at: 2026-06-27T19:41:12Z status: request_changes -->
## Review: request changes
request_changes
ブロッカー:
- `worker-runtime` の既存 feature 組み合わせ `ws-server + fs-store` がコンパイル不能。今回追加された observation bus 用フィールドが `RuntimeState::from_persisted` で初期化されていない。
- 実行: `CARGO_TARGET_DIR=/tmp/yoi-review-target-00001KW55B32Y cargo check -p worker-runtime --features "ws-server fs-store"`
- 失敗: `crates/worker-runtime/src/runtime.rs:925`
- エラー: missing fields `next_observation_sequence`, `observation_events`, `observation_tx` in initializer of `RuntimeState`
- 既存の fs-store runtime path と ws observation path の組み合わせを壊す regression なので修正が必要。
確認した範囲では、Ticket の主眼自体は概ね実装されている:
- unconnected Worker input は typed `WorkerExecutionUnavailable` で拒否され、user transcript / observation event は追加されない。
- connected fake backend による input dispatch test がある。
- `protocol::Event` を observation bus に publish する hook と test がある。
- stop/cancel unsupported は typed rejection になる。
- fake/providerless/canned assistant response 生成は見当たらない。
- `can_stream_events` / `can_read_bounded_transcript` の public capability 復活は見当たらない。
- Browser-facing projection で raw backend handle/socket/session/credential/path を漏らす変更は見当たらない。
- concrete `worker` crate adapter / Companion real LLM execution への scope creep は見当たらない。
追加検証:
- `git diff --check HEAD~1..HEAD`: pass
- 作業ツリーは review 後も clean。
---
<!-- event: implementation_report author: yoi-coder-00001KW55B32Y-exec-backend at: 2026-06-27T19:46:45Z -->
## Implementation report
Change-response implementation report:
Reviewer blocker を修正済み。マージ / close / cleanup は未実施。
Fix commit:
- `761b60c85750d03c119733a088fb5073f9b37e9a fix: initialize restored worker observations`
修正内容:
`RuntimeState::from_persisted` の fs-store restore path で、`ws-server` feature 有効時の observation bus 状態を初期化するようにした。
追加初期化:
- `next_observation_sequence: 1`
- `observation_events: VecDeque::new()`
- `observation_tx: broadcast::channel(256).0`
また、`fs_store_restores_workers_events_and_transcripts` に `ws-server` 有効時の focused assertion を追加し、restore 後の Runtime でも `observe_worker_event` / `read_worker_observation_events` が動くことを確認した。
Validation:
- `CARGO_TARGET_DIR=/tmp/yoi-review-target-00001KW55B32Y cargo check -p worker-runtime --features "ws-server fs-store"`: success
- `cargo fmt --all`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risk / review focus:
- observation events 自体は fs-store 永続化対象ではないため、restore 後の observation backlog は空から開始する。これは既存の observation bus/backlog の揮発的性質に沿った修正。
- 今回は compile blocker の修正に限定し、backend adapter や永続 observation replay の設計拡張は行っていない。
---
<!-- event: review author: yoi-reviewer-00001KW55B32Y-exec-backend at: 2026-06-27T19:48:30Z status: approve -->
## Review: approve
approve
確認結果:
- 先回ブロッカーだった `ws-server + fs-store``RuntimeState::from_persisted` 初期化漏れは修正済み。
- `next_observation_sequence`
- `observation_events`
- `observation_tx`
が restore path で初期化されていることを確認。
- 追加 test で restored Runtime の `observe_worker_event` / `read_worker_observation_events` が検証されていることを確認。
- 手元検証:
- `CARGO_TARGET_DIR=/tmp/yoi-review-target-00001KW55B32Y cargo check -p worker-runtime --features "ws-server fs-store"`: pass
- `CARGO_TARGET_DIR=/tmp/yoi-review-target-00001KW55B32Y cargo test -p worker-runtime --features "ws-server fs-store"`: pass
- original Ticket invariants について、前回確認済みの内容から regression は見当たらない。
- backend-unconnected input rejection / transcript 非追加
- fake/providerless assistant response なし
- fake backend dispatch boundary
- protocol event publish hook
- stop/cancel unsupported typed rejection
- `can_stream_events` / `can_read_bounded_transcript` public capability 復活なし
- Browser-facing projection で raw backend internals/path/credential leak なし
- concrete `worker` crate adapter / Companion real LLM execution への scope creep なし
作業ツリーも clean のまま。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-27T19:49:30Z -->
## Implementation report
Merge / validation report:
Implementation branch was integrated into the orchestration branch after reviewer approval.
Integrated commits:
- `2d5971738478f832ba9a135601ea11dda60c565d feat: add worker execution backend boundary`
- `761b60c85750d03c119733a088fb5073f9b37e9a fix: initialize restored worker observations`
Merge commit:
- `0753e155 merge: worker runtime execution backend`
Validation in orchestration worktree:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Outcome:
- `worker-runtime` now has an explicit Worker execution backend boundary.
- Backend-unconnected Workers reject input rather than accepting it or producing fake/providerless assistant responses.
- Connected backend dispatch and observation publish hooks are covered by focused tests.
- `ws-server + fs-store` restore path initializes observation bus state and is validated.
- Browser-facing projections continue not to expose raw backend handle/path/socket/session/credential internals or legacy public `can_stream_events` / `can_read_bounded_transcript` capabilities.
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-27T19:49:36Z from: inprogress to: done reason: implementation_merged_and_validated field: state -->
## State changed
Reviewer approval後に implementation branch を orchestration branch へ merge し、要求された validation が成功したため done に遷移する。
Validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
---
<!-- event: state_changed author: hare at: 2026-06-27T19:49:46Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-27T19:49:46Z status: closed -->
## 完了
`worker-runtime` に Worker execution backend 境界を追加し、reviewer approval 後に orchestration branch へ merge した。
実装内容:
- `WorkerExecutionBackend` trait / handle / context / status / result / operation / outcome を追加。
- backend 未接続 Worker への input を typed `WorkerExecutionUnavailable` として拒否。
- backend dispatch の busy / rejected / errored / unsupported を typed rejection として扱う。
- backend から Runtime observation bus へ `protocol::Event` を publish する hook を追加。
- stop / cancel unsupported の typed rejection を追加。
- `WorkerSummary` / `WorkerDetail` に raw handle/path/credential を含まない execution status projection を追加。
- Runtime が fake/providerless assistant response を生成しない境界を維持。
- `can_stream_events` / `can_read_bounded_transcript` public capability は復活させていない。
- `ws-server + fs-store` restore path で observation bus state を正しく初期化。
Integrated commits:
- `2d5971738478f832ba9a135601ea11dda60c565d feat: add worker execution backend boundary`
- `761b60c85750d03c119733a088fb5073f9b37e9a fix: initialize restored worker observations`
- merge: `0753e155 merge: worker runtime execution backend`
Validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Cleanup は child implementation worktree / branch と related role Pods のみを対象に実施する。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-27T20:09:45Z -->
## Implementation report
Cleanup report:
- `StopPod` は並列呼び出しでハングし得る不具合があるとの指摘を受けたため、今後は必ず 1 回ずつ実行する運用にする。
- 今回の role Pods は `StopPod` 実行時点で spawned child registry から既に見えず、`ListPods` でも spawned child は 0 件だったため、追加の concurrent stop retry は行っていない。
- Child implementation worktree を削除済み:
- `/home/hare/Projects/yoi/.worktree/00001KW55B32Y-worker-runtime-execution-backend`
- Child implementation branch を削除済み:
- `work/00001KW55B32Y-worker-runtime-execution-backend`
Orchestration worktree は clean。
---

View File

@ -0,0 +1,2 @@
{"id":"orch-plan-20260627-190816-1","ticket_id":"00001KW55B33B","kind":"blocked_by","related_ticket":"00001KW55B32Y","note":"Queue routing checked. Embedded `worker` crate execution connection depends on execution backend boundary `00001KW55B32Y`, which has just been accepted and is now inprogress. Leave queued until backend boundary is reviewed/merged/done.","author":"yoi-orchestrator","at":"2026-06-27T19:08:16Z"}
{"id":"orch-plan-20260627-201131-2","ticket_id":"00001KW55B33B","kind":"accepted_plan","note":"Queue continuation requested by user. Dependency `00001KW55B32Y` is closed and validation passed; `00001KW55B33B` has no remaining blockers. `00001KW55B33H` remains queued because it depends on this Ticket.","accepted_plan":{"summary":"前段 `00001KW55B32Y` が closed になったため、embedded Runtime の execution backend 境界に既存 `worker` crate 実行 adapter を接続する。循環依存を避ける adapter placement を選び、理由を Ticket thread に記録し、input を実 Worker run に渡し、`protocol::Event` を Runtime observation bus / Backend WS へ bridge する。config/provider 不足時は typed diagnostic として拒否し、fake/providerless response は再導入しない。","branch":"work/00001KW55B33B-worker-runtime-worker-adapter","worktree":"/home/hare/Projects/yoi/.worktree/00001KW55B33B-worker-runtime-worker-adapter","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/worker-runtime`, `crates/worker`, `crates/workspace-server`, 必要な workspace Cargo/package files の write scope を委譲する。reviewer Worker は read-only で adapter placement/dependency boundary、Profile/config/authority resolution、input/run lifecycle、protocol event bridge、Browser-facing non-leak、fake/providerless response absence を確認する。merge/validation/done/cleanup は Orchestrator が行う。`StopPod` は cleanup 時に必ず 1 回ずつ直列実行する。"},"author":"yoi-orchestrator","at":"2026-06-27T20:11:31Z"}

View File

@ -0,0 +1,21 @@
{
"version": 1,
"relations": [
{
"ticket_id": "00001KW55B33B",
"kind": "depends_on",
"target": "00001KW55B32Y",
"note": "execution backend boundary must exist before worker crate adapter can connect",
"author": "yoi ticket",
"at": "2026-06-27T18:29:46Z"
},
{
"ticket_id": "00001KW55B33B",
"kind": "related",
"target": "00001KVZKSTJT",
"note": "Execution events must flow through Runtime/Backend observation proxy",
"author": "yoi ticket",
"at": "2026-06-27T18:29:46Z"
}
]
}

View File

@ -0,0 +1,75 @@
---
title: 'embedded worker-runtimeをworker crate実行に接続する'
state: 'closed'
created_at: '2026-06-27T18:26:46Z'
updated_at: '2026-06-28T06:02:16Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-27T19:06:30Z'
---
## 背景
`worker-runtime` の embedded Runtime は Backend RuntimeRegistry / Worker Console から見える Worker を作れるが、実際の LLM agent 実行は既存 `worker` crate 側にある。現在はこの execution-plane が接続されていないため、embedded Worker は transcript / observation の箱としては見えるが、user input を実行できない。
この Ticket では、前段の execution backend 境界に対して、既存 `worker` crate を使う embedded execution adapter を実装する。Runtime が Worker を spawn したときに実 `worker::Worker` / `WorkerController` 相当を生成し、input を既存 Worker の run lifecycle に渡し、`protocol::Event` を Runtime observation bus に bridge する。
## 目的
- embedded Runtime Worker が既存 `worker` crate の実行 engine を使って動く。
- user input が fake response ではなく、実 Worker run / LLM execution に渡る。
- 既存 `protocol::Event` が Runtime observation stream に流れる。
- Runtime / Backend / Web Console が Worker 実行の正規経路を共有する。
## 要件
### Adapter placement / dependency boundary
- `worker-runtime``worker` crate の依存関係を確認し、循環依存を作らない場所に adapter を置く。
- `worker-runtime` の optional feature、別 adapter crate、または Backend 側 adapter のいずれかを選んで Ticket thread に理由を記録する。
- Adapter は `worker-runtime` の execution backend 境界に接続する。
- Runtime public API / Browser-facing API に `worker::Worker` handle、socket path、session path、secret、raw manifest path を露出しない。
### Profile / config / authority resolution
- Runtime Worker spawn request の Profile selector / config bundle ref から、既存 Worker 実行に必要な config を解決する。
- prompt resources、model/provider config、SecretRef、ToolRegistry、HostAuthority、memory/session/history scope の扱いを明示する。
- Backend internal Companion 用であっても、暗黙の broad workspace authority を付けない。
- config / secret / provider が不足している場合は typed diagnostic として spawn/input を拒否し、fake response を返さない。
### Input / run lifecycle
- Backend Worker input API からの user input を、既存 Worker の `Method::Run` 相当または同等の run API に渡す。
- Worker が busy の場合、二重 run を typed rejection / queue policy で扱う。v0 で queue しないなら明示する。
- run started / completed / errored / cancelled を Runtime Worker status と transcript projection に反映する。
- stop / cancel が実装できる場合は既存 Worker control に接続し、できない場合は typed unsupported とする。
### Protocol event bridge
- 既存 Worker が出す `protocol::Event` を Runtime observation bus へ bridge する。
- Snapshot / transcript reconstruction / text delta / text done / thinking / tool call / tool result / usage / status / error を、既存 protocol semantics のまま流す。
- Runtime が event variant subset や別 output model を作らない。
- Worker history / session persistence と Runtime transcript projection が矛盾しないようにする。
## Non-goals
- Workspace Companion 専用 UX の完成。
- Web Console の visual redesign。
- remote Runtime process の execution adapter 実装。
- Full multi-user auth / permission / redaction policy。
- Task scheduling / background queue。
## 受け入れ条件
- embedded Runtime に `worker` crate 実行 adapter が接続されている。
- embedded Worker への user input が実 Worker run に渡る。
- provider / config が不足している場合、fake response ではなく typed diagnostic になる。
- 実行時の `protocol::Event` が Runtime observation bus と Backend client-facing WS に流れる。
- transcript projection が実 Worker run の user / assistant / tool / error output と整合する。
- raw execution handle / path / credential / session path が Browser-facing API に漏れない。
- Focused tests が fake provider または deterministic provider で user input -> assistant output -> protocol events -> transcript projection を確認する。
- `cargo test -p worker-runtime --features ws-server` が通る。
- `cargo test -p yoi-workspace-server` が通る。
- `cargo check -p yoi` が通る。
- `git diff --check` が通る。
- `nix build .#yoi --no-link` が通る。

View File

@ -0,0 +1,35 @@
embedded `worker-runtime` を既存 `worker` crate の実行 lifecycle に接続する adapter を実装し、reviewer approval 後に orchestration branch へ merge した。
実装内容:
- `worker` crate に `runtime-adapter` feature と `WorkerRuntimeExecutionBackend` adapter を追加。
- `worker-runtime``worker` に依存しない下位境界のまま維持し、crate dependency cycle を回避。
- embedded Runtime 作成時に `workspace-server` が adapter を install。
- Backend Worker input API から embedded Runtime execution backend に委譲し、既存 Worker run lifecycle (`Method::Run`) に接続。
- Worker の `protocol::Event` を Runtime observation bus / transcript projection に bridge。
- builtin profile selector double-prefix を修正。
- run_state/status projection を実 Worker lifecycle event に合わせて更新。
- spawn execution failure は Browser-facing API で sanitized `Rejected` diagnostic として扱い、failed/unconnected 状態を input-capable に見せない。
- fake/providerless/canned assistant response は導入していない。
- Browser-facing API に raw worker handle / execution handle / socket / session path / credential / secret ref / raw manifest path を出していない。
- `can_stream_events` / `can_read_bounded_transcript` public capability は復活させていない。
Integrated commits:
- `18526ee36264610048f48b07b5db50ce86852fd2 feat: connect runtime worker execution adapter`
- `9069b035041d17e7c52a454a7563cc5f0b7e1f61 fix: connect embedded runtime input lifecycle`
- `7e29ff5ec99dcc748fa5a511cda5bae31fec124b fix: reject embedded spawn execution failures`
- merge: `c3ed223d merge: worker runtime worker adapter`
Validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker --features runtime-adapter runtime_adapter`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Known non-blocking warning:
- `cargo test -p yoi-workspace-server` reports existing warning `field next_sequence is never read` in `crates/workspace-server/src/companion.rs`.
Cleanup は child implementation worktree / branch と related role Pods のみを対象に実施する。

View File

@ -0,0 +1,611 @@
<!-- event: create author: "yoi ticket" at: 2026-06-27T18:26:46Z -->
## 作成
LocalTicketBackend によって作成されました。
---
<!-- event: intake_summary author: hare at: 2026-06-27T18:58:48Z -->
## Intake summary
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-27T18:58:48Z from: planning to: ready reason: cli_state field: state -->
## State changed
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: workspace-panel at: 2026-06-27T19:06:30Z from: ready to: queued reason: queued field: state -->
## State changed
Ticket を `workspace-panel` が queued にしました。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-27T19:08:35Z -->
## Decision
Routing decision: blocked_by_dependency_or_missing_authority
Reason:
- Dashboard Queue 後に Ticket / relations / orchestration plan / workspace state を確認した。
- 本 Ticket は `00001KW55B32Y` (`worker-runtimeにWorker実行Backend境界を追加する`) に `depends_on` relation を持つ。
- `00001KW55B32Y` は本 routing pass で accepted され `inprogress` になった。
- Adapter は execution backend boundary に接続する必要があるため、boundary の shape が review/merge/done になる前に開始しない。
Evidence checked:
- Ticket body: adapter placement/dependency boundary、Profile/config/authority resolution、input/run lifecycle、protocol event bridge、Non-goals。
- Relations: outgoing `depends_on -> 00001KW55B32Y`; incoming dependent `00001KW55B33H`
- Orchestration plan: blocker record `orch-plan-20260627-190816-1` を追加。
- Workspace state: `00001KW55B32Y` is inprogress; current worktree clean before implementation side effects.
Next action:
- 本 Ticket は queued のまま待機。
- `00001KW55B32Y` が reviewer approve / merge / validation / done になった後に再 routing する。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-27T20:11:40Z -->
## Decision
Routing decision:
Queue continuation was explicitly requested. The upstream boundary Ticket `00001KW55B32Y` is closed after merge and validation, so this Ticket is now unblocked and accepted for implementation.
Plan:
- Create child implementation worktree:
- `/home/hare/Projects/yoi/.worktree/00001KW55B33B-worker-runtime-worker-adapter`
- Branch:
- `work/00001KW55B33B-worker-runtime-worker-adapter`
- Route implementation to a sibling Coder Worker with focused write scope.
- Route read-only review to a sibling Reviewer Worker after implementation.
- Orchestrator retains merge, final validation, Ticket completion, child worktree/branch cleanup, and role Pod shutdown.
Review/implementation focus:
- choose adapter placement without introducing crate dependency cycles, and record the rationale
- connect embedded `worker-runtime` execution backend to existing `worker` crate execution
- preserve Profile/config bundle and authority resolution boundaries
- dispatch input to real Worker run lifecycle, not providerless/fake responses
- bridge `protocol::Event` to Runtime observation bus / Backend WS
- return typed diagnostics/rejections for missing config/provider/busy/unsupported operations
- do not expose raw handles, sockets, credentials, session paths, or manifest paths to Browser-facing APIs
- leave `00001KW55B33H` queued until this adapter is merged/validated
Operational note:
- `StopPod` must be called serially during cleanup; do not use parallel StopPod calls.
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-27T20:11:44Z from: queued to: inprogress reason: dependency_closed_and_queue_continues field: state -->
## State changed
Queue continuation requested by user. Upstream dependency `00001KW55B32Y` is closed with merge and validation complete, and this Ticket has no remaining blockers. Accepting implementation before child worktree / role Pod side effects.
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-27T20:12:31Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KW55B33B-worker-runtime-worker-adapter`
- Branch: `work/00001KW55B33B-worker-runtime-worker-adapter`
- Coder Worker spawned: `yoi-coder-00001KW55B33B-worker-adapter`
Scope notes:
- Coder write scope is limited to `crates/worker-runtime/**`, `crates/worker/**`, `crates/workspace-server/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` if dependency/package changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Implementation focus:
- adapter placement without crate dependency cycles, with rationale reported back
- connect `worker-runtime` execution backend boundary to existing `worker` crate run lifecycle
- bridge existing `protocol::Event` to Runtime observation bus / Backend WS
- preserve typed diagnostics for missing config/provider/secret and busy/unsupported operations
- avoid fake/providerless responses and Browser-facing raw handle/path/credential/session leaks
- leave downstream Workspace Companion real execution Ticket `00001KW55B33H` queued until this adapter is merged/validated
---
<!-- event: implementation_report author: yoi-coder-00001KW55B33B-worker-adapter at: 2026-06-27T20:51:14Z -->
## Implementation report
Implementation report:
実装完了。マージ / close / cleanup は未実施。
Commit:
- `18526ee36264610048f48b07b5db50ce86852fd2 feat: connect runtime worker execution adapter`
Adapter 配置方針:
- `worker` crate 側に `runtime-adapter` feature 付きで配置。
- 理由:
- `worker-runtime` は Runtime 境界 / 投影 / Backend trait を持つ下位境界として保ち、実 Worker 実装への依存を持たせない。
- `worker` crate は既存の `WorkerController` / `WorkerHandle` / `Method::Run` lifecycle を直接扱えるため、fake/canned 応答を挟まずに adapter を組める。
- `workspace-server``worker = { features = ["runtime-adapter"] }` を有効化して embedded Runtime に接続する形にし、crate dependency cycle を避けた。
変更概要:
### `worker` crate
- `crates/worker/src/runtime_adapter.rs` を追加。
- `WorkerRuntimeExecutionBackend` を追加し、`worker_runtime::execution::WorkerExecutionBackend` を実装。
- Runtime worker 作成時に `WorkerController` を spawn し、内部にのみ real `WorkerHandle` を保持。
- Runtime input は `Method::Run { input: vec![Segment::text(...)] }` へ変換して既存 Worker run lifecycle に投入。
- Worker の `protocol::Event` broadcast を購読し、`WorkerExecutionContext::publish_protocol_event` 経由で Runtime observation bus へ橋渡し。
- Provider/profile/config 不足などは spawn/create 時の typed error/rejection として返し、fake assistant text は生成しない。
- v0 double-run policy として queue は持たず、adapter 側 atomic busy flag + Worker status で二重 input を typed busy rejection。
- stop/cancel は既存 `Method::Shutdown` / `Method::Cancel` へ接続。
- Focused test を追加し、fake deterministic LLM client で Runtime input -> real Worker run lifecycle -> assistant output -> `protocol::Event` -> Runtime transcript projection の流れを検証。
### `worker-runtime`
- `observe_worker_event` で受けた real `protocol::Event` から transcript projection を更新。
- `TextDone` -> Assistant transcript
- `Error` -> System transcript
- `ToolResult` -> System transcript
- observation bus には既存 `protocol::Event` をそのまま保持し、subset output model は追加していない。
### `workspace-server`
- embedded Runtime 作成時に `WorkerRuntimeExecutionBackend` を接続。
- `EmbeddedWorkerRuntime::new_memory_with_execution_backend` を追加。
- Browser/API-facing projection に raw `worker::Worker` handle / raw execution handle / socket path / session path / credential / secret ref / manifest path は出していない。
### package/dependency
- `worker` に optional `worker-runtime` dependency + `runtime-adapter` feature を追加。
- `workspace-server``worker``runtime-adapter` feature を有効化。
- `Cargo.lock``package.nix``cargoHash` を更新。
Validation:
- `cargo fmt --all`: success
- `cargo fmt --all --check`: success
- `cargo test -p worker --features runtime-adapter runtime_adapter`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Residual risks / review focus:
- Runtime worker profile 解決は production adapter が通常の Worker profile 解決を使う。workspace-server 起動直後に fake 応答へ fallback せず、profile/provider/config 不足は typed error になる。この挙動が downstream `00001KW55B33H` の Companion UX 設計と合っているか確認が必要。
- Transcript projection は現時点で `TextDone` / `Error` / `ToolResult` を投影。より細かい tool-call lifecycle や thinking block の Browser projection が必要なら downstream で拡張対象。
- Adapter は v0 non-queue policy。二重 input は busy rejection で、background queue/scheduler は実装していない。
- `workspace-server``worker` を feature 付きで依存するため、crate layering と public API leak が意図通りかを重点 review してほしい。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-27T20:51:43Z -->
## Implementation report
Review kickoff:
Reviewer Worker spawned for `00001KW55B33B` implementation.
- Reviewer Worker: `yoi-reviewer-00001KW55B33B-worker-adapter`
- Review target commit: `18526ee36264610048f48b07b5db50ce86852fd2 feat: connect runtime worker execution adapter`
- Review mode: read-only implementation worktree review
Review focus:
- crate layering / `runtime-adapter` feature dependency cycle risk
- production Profile/config/authority resolution and typed failure mode
- protocol event bridge into Runtime observation bus / Backend WS
- transcript projection consistency for real Worker run output
- no fake/providerless fallback
- busy / stop / cancel lifecycle semantics
- Browser-facing non-leak of worker handles, raw execution handles, sockets, session paths, credentials, secret refs, and raw manifest paths
- no downstream Workspace Companion bootstrap/UX scope creep
---
<!-- event: review author: yoi-reviewer-00001KW55B33B-worker-adapter at: 2026-06-27T20:58:06Z status: request_changes -->
## Review: request changes
request_changes
読取専用で差分・主要実装を確認した。crate layering 自体は概ね意図通りで、`worker` crate 側の `runtime-adapter` feature に adapter を置き、`worker-runtime` が `worker` に依存しない形は保たれている。また fake/providerless の canned response は見当たらない。
ただし、Ticket 受け入れ条件に対して以下が blocker。
## Blockers
1. **workspace-server の embedded Worker input API がまだ adapter に接続されていない**
- `workspace-server/src/server.rs:101-113` で adapter は embedded Runtime に install されている。
- しかし browser/backend registry 側の `EmbeddedWorkerRuntime::send_input``hosts.rs:1275-1285` で固定 reject のまま。
- projection も `hosts.rs:1008-1010``can_accept_input: false`, `can_stop: false` のまま。
- そのため Ticket 要件の「Backend Worker input API からの user input を `Method::Run` 相当に渡す」「Runtime / Backend / Web Console が正規経路を共有する」「embedded Worker への user input が実 Worker run に渡る」を満たしていない。
2. **production profile resolution に builtin 二重 prefix の不整合がある**
- workspace-server の Ticket role mapping は `hosts.rs:1920-1924``ProfileSelector::Builtin("builtin:coder")` のように値へ `builtin:` を含めている。
- adapter 側は `worker/src/runtime_adapter.rs:133-140``Builtin(name)` を常に `format!("builtin:{name}")` しているため、内部的に `builtin:builtin:coder` になる。
- `manifest::ProfileSelector::parse_cli``builtin:builtin:coder` を source=`builtin`, name=`builtin:coder` と解釈するため、通常の builtin `coder` 解決に失敗する。Ticket role Worker の実 spawn path で破綻する可能性が高く、Profile/config resolution の受け入れ条件を満たさない。
3. **run_state/status projection が実 run lifecycle と整合していない**
- `send_method` は input の `Method::Run` 送信成功時も `WorkerExecutionRunState::Idle` を返している(`worker/src/runtime_adapter.rs:300-313`, `445-455`)。
- Runtime 側はその `Idle` を input accepted 後の execution status として保存する(`worker-runtime/src/runtime.rs:369-373`)。
- bridge は `protocol::Event` を observation bus に流しているが、Worker の running/completed/errored/cancelled status を Runtime execution status に反映していない。
- Ticket 要件の「run started / completed / errored / cancelled を Runtime Worker status と transcript projection に反映」「busy/double-run lifecycle semantics」の観点で不足。
## 確認済み
- `worker-runtime` -> `worker` の依存逆流は見当たらず、adapter placement の方向性は良い。
- `protocol::Event` bridge は `publish_protocol_event` を使って observation bus に流す実装になっている。
- `can_stream_events` / `can_read_bounded_transcript` の public flag 復活は見当たらない。
- downstream `00001KW55B33H` の Companion UX 完成まで踏み込む scope creep は見当たらない。
- Ticket 更新・merge・cleanup・ファイル変更・テスト実行はしていない。Static review のみ。
---
<!-- event: implementation_report author: yoi-coder-00001KW55B33B-worker-adapter at: 2026-06-27T21:22:01Z -->
## Implementation report
Change-response implementation report:
Reviewer blockers を修正済み。マージ / close / cleanup は未実施。
Fix commit:
- `9069b035e0a93f83c702e206d3d15b2b683a8c19 fix: connect embedded runtime input lifecycle`
既存実装 commit:
- `18526ee36264610048f48b07b5db50ce86852fd2 feat: connect runtime worker execution adapter`
## 修正内容
### 1. workspace-server embedded Worker input API を adapter に接続
`EmbeddedWorkerRuntime::send_input` の固定 reject を撤去し、execution backend 接続済みの場合は `worker_runtime::Runtime::send_input` に委譲するようにした。
あわせて:
- `EmbeddedWorkerRuntime``execution_enabled` を追加。
- `new_memory_with_execution_backend(...)` で backend 接続済み runtime として扱う。
- Worker projection の capability を backend 接続状態に合わせて更新:
- `can_accept_input`
- `can_stop`
- `stop_worker` / `cancel_worker` も embedded Runtime lifecycle API に委譲。
- `workspace-server` 側の focused test を追加し、fake execution backend で embedded Runtime spawn / workspace-server host API 経由 input / backend dispatch / `protocol::Event` / transcript projection / capability/status projection を検証。
### 2. builtin profile selector double-prefix bug 修正
`worker/src/runtime_adapter.rs``ProfileSelector::Builtin` 変換を修正。
- `Builtin("coder")` -> `builtin:coder`
- `Builtin("builtin:coder")` -> `builtin:coder`
`builtin:builtin:coder` にならないことを focused unit test で追加確認。
### 3. run_state / status projection を real run lifecycle に合わせて修正
`send_method` が常に `Idle` を返していた点を修正。
- `Method::Run` accepted -> `WorkerExecutionRunState::Busy`
- `Method::Shutdown` accepted -> `Stopped`
- `Method::Cancel` accepted -> `Idle`
さらに `worker-runtime` 側で bridged `protocol::Event` を execution status に投影するようにした。
対応イベント:
- `Status { Running }` -> `Busy`
- `Status { Idle }` -> `Idle`
- `Status { Paused }` -> `Busy`
- `Snapshot { status }` -> status に応じて `Busy` / `Idle`
- `RunEnd { Finished | RolledBack }` -> `Idle`
- `RunEnd { Paused }` -> `Busy`
- `RunEnd { LimitReached }` -> `Errored`
- `Error` -> `Errored`
これにより Backend/Web projection の `status` は execution run_state を反映する。
## Validation
実行済み・成功:
- `cargo fmt --all`
- `cargo fmt --all --check`
- `cargo test -p worker --features runtime-adapter runtime_adapter`
- `cargo test -p worker-runtime --features ws-server`
- `cargo test -p worker-runtime --features "ws-server fs-store"`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `git diff --check`
- `nix build .#yoi --no-link`
補足:
- `cargo test -p yoi-workspace-server` では既存 warning: `field next_sequence is never read`
- 新規失敗や未解決の validation failure はない。
## 残リスク / review focus
- `workspace-server` の embedded Worker capability は backend 接続時に `can_accept_input` / `can_stop` が true になる。実 provider/profile 不足時は fake 応答ではなく typed rejection/error になるため、下流 Companion UX 側でその表示/導線を確認する必要がある。
- Runtime execution status projection は主要 lifecycle event に対応したが、より細かい paused/cancelled 表示語彙を Browser projection で増やす場合は別 Ticket 範囲。
- v0 policy は引き続き queue なし。Busy 中 input は typed busy rejection。
---
<!-- event: review author: yoi-reviewer-00001KW55B33B-worker-adapter at: 2026-06-27T21:27:37Z status: request_changes -->
## Review: request changes
request_changes
静的レビューのみ実施。対象 worktree の HEAD は `9069b035041d17e7c52a454a7563cc5f0b7e1f61` として確認。先回報告の full SHA suffix には差異があるため、以後この full SHA を正とする。
先回の blocker のうち、input delegate / builtin prefix normalization / protocol event -> execution status projection は概ね修正されている。
ただし、元の invariant に対してまだ blocker がある。
## Blocker
**spawn 時の provider/profile/config/setup 失敗が Browser-facing spawn API では `Accepted` 扱いになり、typed rejection/diagnostic になっていない。**
根拠:
- 実 Worker 作成時の profile/provider/session setup 失敗は adapter で `WorkerExecutionSpawnResult::Errored` になる。
- `worker/src/runtime_adapter.rs:161-194`
- `worker/src/runtime_adapter.rs:365-371`
- しかし `worker-runtime::Runtime::create_worker` は spawn `Rejected/Errored``Err` にせず、`Ok(WorkerDetail)` に execution status として記録するだけ。
- `worker-runtime/src/runtime.rs:278-280`
- `worker-runtime/src/runtime.rs:417-446`
- workspace-server 側は `create_worker``Ok(detail)` なら常に `WorkerOperationState::Accepted` として返し、execution failure の diagnostic/rejection を browser-facing result に出していない。
- `workspace-server/src/hosts.rs:1204-1222`
- さらに projection の `can_accept_input``run_state != Busy` だけを見るため、spawn `Errored/Rejected` でも status が `Running` のままなら input 可能に見える。
- `workspace-server/src/hosts.rs:962-970`
このため、missing provider/config/secret/setup が「typed diagnostic/rejection」ではなく「spawn accepted だが内部 execution errored」という中途半端な projection になり、Ticket の受け入れ条件を満たしていない。
spawn execution failure は、少なくとも browser-facing API で sanitized diagnostic/rejection として扱うか、capability を false にして明確な failure projection を返す必要がある。
---
<!-- event: implementation_report author: yoi-coder-00001KW55B33B-worker-adapter at: 2026-06-27T21:39:54Z -->
## Implementation report
Change-response implementation report:
Reviewer blocker を修正済み。Ticket ファイル変更、merge、close、cleanup は未実施。
Current HEAD:
- `7e29ff5ec99dcc748fa5a511cda5bae31fec124b fix: reject embedded spawn execution failures`
Prior fix commit:
- `9069b035041d17e7c52a454a7563cc5f0b7e1f61 fix: connect embedded runtime input lifecycle`
## 修正内容
### Spawn-time execution failure を Browser-facing API で `Rejected` として返す
`worker-runtime::Runtime::create_worker` は spawn backend の `Rejected/Errored``Ok(WorkerDetail)` 内の execution status として保持する設計のままなので、`workspace-server` 側で `detail.execution.last_result` を検査するようにした。
対象:
- `crates/workspace-server/src/hosts.rs`
変更:
- embedded Runtime spawn 後に execution spawn failure を検出。
- `WorkerExecutionOutcome::{Rejected, Errored, Unsupported, Busy}` の場合:
- Browser-facing `WorkerSpawnResult.state = Rejected`
- `acceptance_evidence = []`
- sanitized diagnostic を返す
- worker projection は残すが、capability は失敗状態として false にする
sanitized diagnostic 例:
- code: `embedded_worker_execution_spawn_errored`
- message: `Embedded Worker execution spawn was errored during setup; check runtime configuration`
### Failed execution state で capability が true にならないよう修正
`can_accept_input` / `can_stop` 判定を `run_state != Busy` からより厳密に変更。
`can_accept_input` は以下すべてを満たす場合のみ true:
- execution backend が接続済み
- worker status が `Running`
- execution backend kind が `Connected`
- run_state が `Idle`
- last_result が `Rejected/Errored/Unsupported` ではない
`can_stop` も spawn rejected/errored/unconnected 系では false。
### Focused tests
`workspace-server` に spawn execution failure の focused test を追加。
検証内容:
- fake failing execution backend が spawn `Errored` を返す
- Browser-facing spawn result が `Rejected`
- diagnostic が sanitized され、fake 内部 path を漏らさない
- projected worker status が `errored`
- `can_accept_input == false`
- `can_stop == false`
既存 server API projection test も、real backend setup failure が Browser-facing projection で sanitized rejection として出る前提に調整。
## Validation
実行済み・成功:
- `cargo fmt --all`
- `cargo fmt --all --check`
- `cargo test -p worker --features runtime-adapter runtime_adapter`
- `cargo test -p worker-runtime --features ws-server`
- `cargo test -p worker-runtime --features "ws-server fs-store"`
- `cargo test -p yoi-workspace-server`
- `cargo check -p yoi`
- `git diff --check`
- `nix build .#yoi --no-link`
補足:
- `cargo test -p yoi-workspace-server` では既存 warning: `field next_sequence is never read`
- `nix build` は dirty tree warning を出したが build 自体は成功。
## 残リスク / review focus
- `worker-runtime::Runtime::create_worker` 自体は引き続き spawn execution failure を `Ok(WorkerDetail)` に記録する設計。今回の修正は Browser-facing `workspace-server` projection で typed rejection/diagnostic として露出する対応。
- diagnostic は sanitized のため、具体的な provider/config/secret path 等は Browser-facing API には出さない。詳細原因の調査導線が必要なら、別途 backend/admin 向け diagnostics 設計が必要。
- Companion status は環境の profile/provider setup 可否により `ready` / `error` のどちらも取り得るため、既存テストはその環境差を許容する形に調整。
---
<!-- event: review author: yoi-reviewer-00001KW55B33B-worker-adapter at: 2026-06-27T21:42:24Z status: approve -->
## Review: approve
approve
読取専用で再レビューした。前回 blocker は解消されている。
確認した点:
- `workspace-server` の embedded spawn 後に `detail.execution.last_result` を検査し、`Rejected / Errored / Unsupported / Busy` を browser-facing `WorkerSpawnResult.state = Rejected` として返すようになっている。
- spawn execution failure の diagnostic は sanitized な固定文言・code で返され、内部 path / handle / credential / secret ref の露出は見当たらない。
- `can_accept_input` は backend 接続・Worker `Running`・backend kind `Connected`・`run_state == Idle`・last_result failure でないことを要求しており、spawn failure 後の入力可能 projection は塞がれている。
- `can_stop` も rejected / errored / unconnected failure state では false になる。
- 先回指摘の embedded input API delegate、builtin profile double-prefix、protocol event -> runtime execution status projection も修正済み。
- crate layering は `worker` 側 feature adapter -> `worker-runtime` boundary の向きで、`worker-runtime` が `worker` に依存する逆流は見当たらない。
- fake/providerless fallback、public capability flag 復活、下流 Ticket `00001KW55B33H` scope creep は見当たらない。
検証は指示通り read-only の静的確認のみで、テスト実行やファイル変更はしていない。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-27T21:44:40Z -->
## Implementation report
Merge / validation report:
Implementation branch was integrated into the orchestration branch after reviewer approval.
Integrated commits:
- `18526ee36264610048f48b07b5db50ce86852fd2 feat: connect runtime worker execution adapter`
- `9069b035041d17e7c52a454a7563cc5f0b7e1f61 fix: connect embedded runtime input lifecycle`
- `7e29ff5ec99dcc748fa5a511cda5bae31fec124b fix: reject embedded spawn execution failures`
Merge commit:
- `c3ed223d merge: worker runtime worker adapter`
Validation in orchestration worktree:
- `cargo fmt --all --check`: success
- `cargo test -p worker --features runtime-adapter runtime_adapter`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Known non-blocking warning:
- `cargo test -p yoi-workspace-server` reports existing warning `field next_sequence is never read` in `crates/workspace-server/src/companion.rs`.
Outcome:
- Embedded Runtime now installs a `worker` crate execution adapter via `worker/runtime-adapter` feature without making `worker-runtime` depend on `worker`.
- Backend input path delegates to the Runtime execution backend and reaches real Worker run lifecycle.
- `protocol::Event` output bridges to Runtime observation / transcript projection.
- Browser-facing spawn failure is reported as sanitized rejected diagnostic, not accepted fake output.
- Failed/unconnected execution states are not projected as input-capable.
- No public `can_stream_events` / `can_read_bounded_transcript` capability flags were revived.
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-27T21:44:46Z from: inprogress to: done reason: implementation_merged_and_validated field: state -->
## State changed
Reviewer approval後に implementation branch を orchestration branch へ merge し、要求された validation が成功したため done に遷移する。
Validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker --features runtime-adapter runtime_adapter`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
---
<!-- event: state_changed author: hare at: 2026-06-27T21:45:00Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-27T21:45:00Z status: closed -->
## 完了
embedded `worker-runtime` を既存 `worker` crate の実行 lifecycle に接続する adapter を実装し、reviewer approval 後に orchestration branch へ merge した。
実装内容:
- `worker` crate に `runtime-adapter` feature と `WorkerRuntimeExecutionBackend` adapter を追加。
- `worker-runtime``worker` に依存しない下位境界のまま維持し、crate dependency cycle を回避。
- embedded Runtime 作成時に `workspace-server` が adapter を install。
- Backend Worker input API から embedded Runtime execution backend に委譲し、既存 Worker run lifecycle (`Method::Run`) に接続。
- Worker の `protocol::Event` を Runtime observation bus / transcript projection に bridge。
- builtin profile selector double-prefix を修正。
- run_state/status projection を実 Worker lifecycle event に合わせて更新。
- spawn execution failure は Browser-facing API で sanitized `Rejected` diagnostic として扱い、failed/unconnected 状態を input-capable に見せない。
- fake/providerless/canned assistant response は導入していない。
- Browser-facing API に raw worker handle / execution handle / socket / session path / credential / secret ref / raw manifest path を出していない。
- `can_stream_events` / `can_read_bounded_transcript` public capability は復活させていない。
Integrated commits:
- `18526ee36264610048f48b07b5db50ce86852fd2 feat: connect runtime worker execution adapter`
- `9069b035041d17e7c52a454a7563cc5f0b7e1f61 fix: connect embedded runtime input lifecycle`
- `7e29ff5ec99dcc748fa5a511cda5bae31fec124b fix: reject embedded spawn execution failures`
- merge: `c3ed223d merge: worker runtime worker adapter`
Validation:
- `cargo fmt --all --check`: success
- `cargo test -p worker --features runtime-adapter runtime_adapter`: success
- `cargo test -p worker-runtime --features ws-server`: success
- `cargo test -p worker-runtime --features "ws-server fs-store"`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Known non-blocking warning:
- `cargo test -p yoi-workspace-server` reports existing warning `field next_sequence is never read` in `crates/workspace-server/src/companion.rs`.
Cleanup は child implementation worktree / branch と related role Pods のみを対象に実施する。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-28T06:02:16Z -->
## Implementation report
Cleanup report:
- User instructed to stop using `StopPod` for now after repeated stop/hang symptoms. Role Pod shutdown was therefore intentionally skipped.
- Child implementation worktree was removed:
- `/home/hare/Projects/yoi/.worktree/00001KW55B33B-worker-runtime-worker-adapter`
- Child implementation branch was removed:
- `work/00001KW55B33B-worker-runtime-worker-adapter`
- No root/original workspace cleanup was performed.
- Orchestration worktree is clean after worktree/branch cleanup.
---

View File

@ -0,0 +1,2 @@
{"id":"orch-plan-20260627-190816-1","ticket_id":"00001KW55B33H","kind":"blocked_by","related_ticket":"00001KW55B33B","note":"Queue routing checked. Workspace Companion real LLM Worker execution depends on embedded worker-runtime to worker crate connection `00001KW55B33B`, which is queued and blocked by execution backend boundary `00001KW55B32Y`. Leave queued until dependency chain is done.","author":"yoi-orchestrator","at":"2026-06-27T19:08:16Z"}
{"id":"orch-plan-20260628-060239-2","ticket_id":"00001KW55B33H","kind":"accepted_plan","note":"Queue continuation requested by user. Dependency `00001KW55B33B` is closed and validated, so the Companion real LLM Worker Ticket is now unblocked. There are no other queued Tickets.","accepted_plan":{"summary":"前段 `00001KW55B33B` が closed になったため、Workspace Backend 起動時の `workspace_companion` を実 LLM execution backend 付き Worker として spawn し、Worker list / Worker Console から通常 Worker として attach/send できる状態を完成させる。Companion 専用 fake/providerless response は復活させず、provider/config/secret 不足は typed diagnostic として扱う。","branch":"work/00001KW55B33H-workspace-companion-llm-worker","worktree":"/home/hare/Projects/yoi/.worktree/00001KW55B33H-workspace-companion-llm-worker","role_plan":"Orchestrator が dedicated child worktree を作成し、coder Worker に `crates/workspace-server`, 必要に応じて `crates/worker`, `crates/worker-runtime`, `web/workspace`, root Cargo/package files の focused write scope を委譲する。reviewer Worker は read-only で Companion bootstrap、Worker input API 経路、protocol event / transcript / Web Console 表示、provider/config 不足時の typed diagnostic、fake response absence、Browser-facing non-leak を確認する。merge/validation/done/cleanup は Orchestrator が行う。現時点では `StopPod` は使用せず、cleanup は child worktree/branch のみ行う。"},"author":"yoi-orchestrator","at":"2026-06-28T06:02:39Z"}

View File

@ -0,0 +1,29 @@
{
"version": 1,
"relations": [
{
"ticket_id": "00001KW55B33H",
"kind": "depends_on",
"target": "00001KW55B33B",
"note": "Companion can be executable only after embedded Runtime uses worker crate execution",
"author": "yoi ticket",
"at": "2026-06-27T18:29:46Z"
},
{
"ticket_id": "00001KW55B33H",
"kind": "related",
"target": "00001KVZ9JGK0",
"note": "Replaces the providerless Companion MVP with real Worker execution",
"author": "yoi ticket",
"at": "2026-06-27T18:29:46Z"
},
{
"ticket_id": "00001KW55B33H",
"kind": "related",
"target": "00001KW2GCPYF",
"note": "Worker Console attach UX depends on Companion being a normal executable Worker",
"author": "yoi ticket",
"at": "2026-06-27T18:29:46Z"
}
]
}

View File

@ -0,0 +1,76 @@
---
title: 'Workspace Companionを実LLM実行Workerとして起動する'
state: 'closed'
created_at: '2026-06-27T18:26:47Z'
updated_at: '2026-06-28T07:20:22Z'
assignee: null
queued_by: 'workspace-panel'
queued_at: '2026-06-27T19:06:32Z'
---
## 背景
Workspace Backend は embedded Runtime 上に `workspace_companion` Worker を自動起動しているが、現時点では実 LLM 実行 backend に接続されていない。そのため Web Console から見ると Companion Worker は存在するが、input-capable Worker として動作しない。過去の providerless / fake response は正規動作ではないため削除済みであり、再導入しない。
この Ticket では、embedded Runtime が既存 `worker` crate 実行に接続された後、Workspace Companion を実際の LLM execution を持つ Worker として起動する。Workspace top の Worker list から Companion Worker を開き、Worker Console で Send すると実 provider / configured model 由来の応答が返る状態を完成させる。
## 目的
- `workspace_companion` Worker が実 LLM 実行に接続されている。
- Web Console から Send すると fake ではない assistant response が返る。
- Companion 専用 chat API / providerless response に依存しない。
- Companion は通常 Worker として Worker list から attach できる。
## 要件
### Companion bootstrap
- Workspace Backend 起動時に、Companion 用 Profile / config bundle を解決して executable Worker を spawn する。
- Companion Worker は `runtime_id + worker_id` で Console attach できる。
- role / profile は `workspace_companion` / appropriate companion Profile として表示される。
- provider / model / secret / prompt / authority が不足している場合は、input-capable Worker として表示せず、typed diagnostic を返す。
- fake / providerless assistant response を生成しない。
### Worker Console behavior
- Workspace top の Worker list から Companion Worker Console を開ける。
- Console composer は実行可能な Companion Worker でのみ有効になる。
- Send は Backend Worker input API を通り、embedded Runtime execution backend 経由で実 Worker run に届く。
- assistant response は provider / Worker execution 由来の `protocol::Event` と transcript に基づいて表示する。
- thinking / tool / status / error が届く場合は既存 Web Console protocol rendering に乗る。
### API cleanup
- Companion 専用 `/api/companion/messages` が残る場合も、正規経路は Worker input API とする。
- `/api/companion/messages` は fake response を返さない。残すなら Worker input API への thin wrapper とし、挙動差を作らない。
- Companion status / transcript は必要な bootstrap/status API として残してよいが、Console の authority は `runtime_id + worker_id` とする。
### Validation / evidence
- Test では real external provider secret を要求しない。deterministic fake provider / test Worker execution backend を使い、fake UI response ではなく Worker execution path を通ったことを確認する。
- Manual smoke では設定済み provider がある環境で Web Console Send -> assistant response -> observation WS event を確認できる。
## Non-goals
- Companion 専用 sidebar entry / standalone Console route の復活。
- providerless canned response の復活。
- Full multi-user auth / permission / redaction policy。
- Advanced Companion UXglobal composer、drawer、quick action
- remote Runtime 上の Companion 実行。
## 受け入れ条件
- Workspace Backend が executable `workspace_companion` Worker を起動できる。
- provider/config 不足時は fake response ではなく typed diagnostic になり、input-capable Worker として誤表示しない。
- Worker list から Companion Worker Console を開ける。
- Console Send が実 Worker/LLM execution path を通り、assistant response が provider/test provider 由来で表示される。
- `protocol::Event` が Runtime observation bus / Backend WS / Web Console に流れる。
- `/api/companion/messages` が fake response を返さない。残す場合は Worker input API と同一実行経路を使う。
- Focused tests が Companion bootstrap、input dispatch、assistant output、observation event、transcript projection を確認する。
- `cd web/workspace && deno task test` が通る。
- `cd web/workspace && deno task check` が通る。
- `cd web/workspace && deno task build` が通る。
- `cargo test -p yoi-workspace-server` が通る。
- `cargo check -p yoi` が通る。
- `git diff --check` が通る。
- `nix build .#yoi --no-link` が通る。

View File

@ -0,0 +1,32 @@
Workspace Companion を embedded Runtime / `worker` runtime adapter 経由の実行可能 Worker として扱う実装を行い、reviewer approval 後に orchestration branch へ merge した。
実装内容:
- `/api/companion/messages` の旧 `companion_llm_not_connected` 固定拒否経路を廃止し、通常の Worker runtime input path (`RuntimeRegistry::send_input`) に接続。
- Companion bootstrap を `builtin:companion` profile / Companion config bundle path に変更。
- Companion transcript projection を Runtime transcript 由来に変更。
- Companion status / transport を input-capable なら `connected`、不可なら `not_input_capable` + typed diagnostics に変更。
- `/api/workspace``extension_points.companion_console` も Companion の実 status / diagnostics 由来に変更し、stale `not_connected` / disabled note を削除。
- `ExtensionPointState``diagnostics` を追加し、Workspace web type も更新。
- Browser-facing `/api/workspace` から raw `local_root` exposure を削除。
- deterministic test backend により Companion bootstrap / input dispatch / assistant output / observation event / transcript projection を Worker execution path 経由で検証。
- fake/providerless/canned assistant response は導入していない。
- Worker Console path は `runtime_id + worker_id` keyed のまま維持。
- public `can_stream_events` / `can_read_bounded_transcript` capability は復活させていない。
Integrated commits:
- `ee25cfbcfd90983a24091ef30c0128d653095003 fix: route workspace companion through worker runtime`
- `3be193223c7efc67636667d1ad526646da81fb63 fix: report companion console runtime status`
- merge: `eb06b8a9 merge: workspace companion llm worker`
Validation:
- `cargo fmt --all --check`: success
- `cd web/workspace && deno task test`: success
- `cd web/workspace && deno task check`: success
- `cd web/workspace && deno task build`: success
- `cargo test -p yoi-workspace-server`: success (`34 passed`)
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Operational note:
- User instructed not to use `StopPod` for now after repeated stop/hang symptoms. Cleanup will skip role-Pod shutdown and remove only child implementation worktree / branch.

View File

@ -0,0 +1,537 @@
<!-- event: create author: "yoi ticket" at: 2026-06-27T18:26:46Z -->
## 作成
LocalTicketBackend によって作成されました。
---
<!-- event: intake_summary author: hare at: 2026-06-27T18:58:48Z -->
## Intake summary
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: "yoi ticket" at: 2026-06-27T18:58:48Z from: planning to: ready reason: cli_state field: state -->
## State changed
Marked ready by `yoi ticket state`.
---
<!-- event: state_changed author: workspace-panel at: 2026-06-27T19:06:32Z from: ready to: queued reason: queued field: state -->
## State changed
Ticket を `workspace-panel` が queued にしました。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-27T19:08:35Z -->
## Decision
Routing decision: blocked_by_dependency_or_missing_authority
Reason:
- Dashboard Queue 後に Ticket / relations / orchestration plan / workspace state を確認した。
- 本 Ticket は `00001KW55B33B` (`embedded worker-runtimeをworker crate実行に接続する`) に `depends_on` relation を持つ。
- `00001KW55B33B` は queued で、さらに `00001KW55B32Y` execution backend boundary が inprogress のため blocked。
- Workspace Companion を実 LLM 実行 Worker として起動するには、embedded Runtime が既存 `worker` crate execution に接続済みである必要があるため、依存 chain 完了前に開始しない。
Evidence checked:
- Ticket body: Companion bootstrap、Worker Console behavior、API cleanup、Validation/evidence、Non-goals。
- Relations: outgoing `depends_on -> 00001KW55B33B` and related Web Console/Worker Console Tickets。
- Orchestration plan: blocker record `orch-plan-20260627-190816-1` を追加。
- Workspace state: `00001KW55B32Y` accepted/inprogress; `00001KW55B33B` queued/blocked。
Next action:
- 本 Ticket は queued のまま待機。
- `00001KW55B33B` が done になった後に再 routing する。
---
<!-- event: decision author: yoi-orchestrator at: 2026-06-28T06:02:49Z -->
## Decision
Routing decision:
Queue continuation was explicitly requested. The upstream dependency `00001KW55B33B` is now closed after review, merge, validation, and cleanup. This Ticket is therefore unblocked and accepted for implementation.
Plan:
- Create child implementation worktree:
- `/home/hare/Projects/yoi/.worktree/00001KW55B33H-workspace-companion-llm-worker`
- Branch:
- `work/00001KW55B33H-workspace-companion-llm-worker`
- Route implementation to a sibling Coder Worker with focused write scope.
- Route read-only review to a sibling Reviewer Worker after implementation.
- Orchestrator retains merge, final validation, Ticket completion, child worktree/branch cleanup, and final reporting.
Review/implementation focus:
- Workspace Backend bootstraps `workspace_companion` as an executable Worker with real `worker` crate execution adapter.
- Worker list / Worker Console use the normal `runtime_id + worker_id` authority and Backend Worker input API.
- Console Send reaches real Worker execution path and uses `protocol::Event` / transcript projection, not Companion-specific fake/providerless messages.
- provider/model/secret/profile/authority absence returns typed diagnostic and does not present the Worker as input-capable.
- `/api/companion/messages`, if retained, must not return fake response and should be a thin normal Worker input path wrapper or non-authoritative compatibility path.
- Browser-facing API must not leak raw handles, sockets, session paths, credentials, secret refs, raw manifest paths, or broad authority internals.
Operational note:
- User instructed not to use `StopPod` for now after repeated stop/hang symptoms. Cleanup will skip role-Pod shutdown and remove only child worktree/branch unless this is explicitly reauthorized.
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-28T06:02:54Z from: queued to: inprogress reason: dependency_closed_and_queue_continues field: state -->
## State changed
Queue continuation requested by user. Dependency `00001KW55B33B` is closed with merge and validation complete, so this Ticket has no remaining blockers. Accepting implementation before child worktree / role Pod side effects.
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-28T06:03:56Z -->
## Implementation report
Implementation kickoff:
- Worktree created: `/home/hare/Projects/yoi/.worktree/00001KW55B33H-workspace-companion-llm-worker`
- Branch: `work/00001KW55B33H-workspace-companion-llm-worker`
- Coder Worker spawned: `yoi-coder-00001KW55B33H-companion-llm`
Scope notes:
- Coder write scope is limited to `crates/workspace-server/**`, `crates/worker/**`, `crates/worker-runtime/**`, `web/workspace/**`, `resources/profiles/**`, `resources/prompts/**`, root `Cargo.toml`, `Cargo.lock`, and `package.nix` if dependency/package changes are needed.
- Coder is instructed not to modify Ticket records and not to operate in root/orchestration worktrees.
Implementation focus:
- bootstrap `workspace_companion` as an executable Worker using embedded Runtime + `worker/runtime-adapter`
- normal Worker list / Worker Console attach path via `runtime_id + worker_id`
- Send through Backend Worker input API to real Worker run lifecycle
- no fake/providerless Companion response
- provider/profile/model/secret/authority absence as typed diagnostic and not input-capable
- `/api/companion/messages`, if retained, must not be a separate fake response path
- preserve Browser-facing non-leak of raw handles, paths, credentials, secret refs, and raw manifest paths
Operational note:
- User instructed not to use `StopPod` for now. Later cleanup will skip role-Pod shutdown and remove only child implementation worktree/branch unless explicitly reauthorized.
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-28T06:09:52Z -->
## Implementation report
Implementation routing diagnostic:
Initial Coder Worker `yoi-coder-00001KW55B33H-companion-llm` failed before producing implementation output with provider error `context_length_exceeded`. This appears to be a prompt/context-size failure rather than an implementation result.
Operational response:
- Per current user instruction, `StopPod` will not be used.
- A replacement Coder Worker will be spawned with a shorter bootstrap instruction and the same implementation worktree, if scope delegation is accepted.
- The replacement Coder should read the Ticket and current code directly from the worktree rather than receiving the full requirement text in the initial prompt.
---
<!-- event: implementation_report author: yoi-coder-00001KW55B33H-companion-2 at: 2026-06-28T06:20:33Z -->
## Implementation report
Implementation/verification report:
Replacement Coder completed a verification pass in the child worktree. No code changes were made and no implementation commit was created beyond the branch baseline.
Reported branch/head:
- `0c5a769aa90744cf12299c6d301ebfb3186d763f ticket: accept workspace companion llm worker`
Reported outcome:
- Existing code after upstream `00001KW55B33B` appears to satisfy this Ticket's main implementation goal.
- Workspace Companion is visible as an embedded Runtime normal Worker.
- The `worker` runtime-adapter path is used; providerless/fake responses were not found.
- Input unavailable state is represented through Worker input-capable/diagnostic projection.
- Workspace web Worker Console uses `runtime_id + worker_id` routing.
Reported validation:
- `cargo fmt --check`: success
- `cd web/workspace && deno task test`: success
- `cd web/workspace && deno task check`: success
- `cd web/workspace && deno task build`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi`: success
Orchestrator note:
- Because no code commit was produced for this Ticket, a reviewer will be asked to explicitly verify whether upstream merged implementation fully satisfies `00001KW55B33H` or whether additional changes are required.
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-28T06:21:01Z -->
## Implementation report
Review kickoff:
Reviewer Worker spawned to verify the no-code implementation/verification outcome for `00001KW55B33H`.
- Reviewer Worker: `yoi-reviewer-00001KW55B33H-companion`
- Review mode: read-only review of current child worktree code state after upstream `00001KW55B33B` merge
- Special focus: confirm whether no additional code changes are required for this Ticket, or identify concrete blockers
Review focus:
- `workspace_companion` bootstraps as an executable normal Worker via embedded Runtime + `worker/runtime-adapter`
- Worker list / Worker Console attach path uses `runtime_id + worker_id`
- Send uses Backend Worker input API -> embedded Runtime execution backend -> real Worker run lifecycle
- protocol events / transcript use existing Console rendering path
- missing provider/config/profile/secret/authority is typed diagnostic and not input-capable
- `/api/companion/messages` does not return fake/providerless response
- Browser-facing API does not leak raw handles, socket paths, session paths, credentials, secret refs, raw manifest paths, or broad authority internals
- public `can_stream_events` / `can_read_bounded_transcript` flags are not revived
---
<!-- event: review author: yoi-reviewer-00001KW55B33H-companion at: 2026-06-28T06:27:08Z status: request_changes -->
## Review: request changes
request_changes
静的レビューの結果、upstream の `worker-runtime` adapter 実装は存在するが、Ticket `00001KW55B33H` 自体の受け入れ条件はまだ満たされていない。
## Blockers
1. **`/api/companion/messages` がまだ hard-coded な非実行 path のまま**
- `server.rs:533-537``/api/companion/messages` を直接 `api.companion.send_message(request)` に route している。
- `companion.rs:161-182` は non-empty input を常に `companion_llm_not_connected` で reject する。
- これは Backend Worker input API の thin wrapper ではなく、real Worker run lifecycle に到達しないため、Ticket の `/api/companion/messages` 要件を満たさない。
2. **Companion status / transport が古い “not connected” limitation をまだ宣言している**
- `companion.rs:337-342``completion: "not_connected"` を返し、実 Worker/LLM execution 接続まで browser input は disabled と説明している。
- Ticket の目的は Workspace Companion を real LLM execution に接続して Web Console から使えるようにすることなので矛盾している。
3. **Companion bootstrap が適切な Companion profile / config bundle を解決していない**
- `companion.rs:257-267``profile: Some(ProfileSelector::RuntimeDefault)` / `config_bundle: None` で spawn している。
- `hosts.rs:2188-2191` では `RuntimeDefault``runtime_default` と投影されるだけで、Companion profile として表示されない。
- Ticket は Companion Profile / config bundle を解決し、`workspace_companion` / 適切な companion Profile として表示することを求めている。
4. **focused tests が古い rejected/no-output behavior をまだ assert している**
- `companion.rs:384-399``send_message("hello")``Rejected`、`companion_llm_not_connected`、runtime transcript empty であることを assert している。
- `server.rs:1166-1185``/api/companion/messages` が rejected で transcript empty であることを assert している。
- Ticket は bootstrap、input dispatch、assistant output、observation event、transcript projection が Worker execution path を通ることを proving する tests を求めている。
5. **raw path leak 懸念**
- `server.rs:227-235``WorkspaceResponse``local_root: PathBuf` が含まれる。
- `server.rs:335-339``/api/workspace``api.config.workspace_root` を serialize している。
- “no raw handle/path/credential leaks” を Browser-facing workspace API 全体に適用するなら違反の可能性がある。Worker projection 自体はより注意深く redacted されているが、この public path field は残っているため要確認・必要なら修正が必要。
## 確認済み / non-blocking observations
- upstream embedded runtime adapter は存在する。
- `WorkspaceApi::new``WorkerRuntimeExecutionBackend::from_workspace(...)` を作り、`EmbeddedWorkerRuntime::new_memory_with_execution_backend(...)` に渡している。
- Worker list / Console routing は `runtime_id + worker_id` を使っている。
- Console Send は `/api/runtimes/{runtime_id}/workers/{worker_id}/input`
- Observation WS は `/api/runtimes/{runtime_id}/workers/{worker_id}/events/ws`
- public `can_stream_events` / `can_read_bounded_transcript` fields は見当たらない。
- `/api/companion/messages` は fake/canned assistant response は返していないが、same execution path / normal Worker input path 要件も満たしていない。
## Validation review
- `.yoi/tickets/00001KW55B33H/item.md``thread.md` を読んだ。
- `crates/workspace-server/src/{companion.rs,server.rs,hosts.rs}`、`crates/worker/src/runtime_adapter.rs`、Web Console Svelte/TS paths を静的レビューした。
- test/build は実行していない。
- 現状の `cargo test -p yoi-workspace-server` は古い rejected Companion behavior を assert して通っている可能性があり、この Ticket の acceptance evidence にはならない。
---
<!-- event: implementation_report author: yoi-coder-00001KW55B33H-companion-2 at: 2026-06-28T06:56:50Z -->
## Implementation report
Change-response implementation report:
Reviewer blockers を修正し、実装 commit を作成済み。Ticket ファイル編集、merge、close、cleanup は未実施。
Commit:
- `ee25cfbcfd90983a24091ef30c0128d653095003 fix: route workspace companion through worker runtime`
変更概要:
- `/api/companion/messages` の旧 `companion_llm_not_connected` 固定拒否経路を廃止し、通常の `RuntimeRegistry::send_input` / Worker runtime 入力経路へ接続。
- Companion status / transport を更新。
- Worker が input-capable の場合は `completion: "connected"`
- missing provider/config/profile/authority 等で input-capable でない場合は `completion: "not_input_capable"` と typed diagnostic。
- fake/providerless/canned assistant 応答は追加していない。
- Companion bootstrap を `builtin:companion` profile + Companion 用 config bundle sync へ変更。
- `WorkspaceCompanion` intent の embedded profile projection も `builtin:companion` に変更。
- Companion transcript projection を runtime transcript 由来に変更し、旧独自 transcript / 旧非実行 semantics を置換。
- `/api/workspace` の Browser-facing response から raw `local_root: PathBuf` を削除。
- Tests を更新・追加。
- Companion bootstrap / input dispatch / assistant output / observation event / transcript projection を deterministic test execution backend で検証。
- legacy `/api/companion/messages` route が Worker runtime 経由で input dispatch することを server test で検証。
- 旧 `companion_llm_not_connected` 依存 assertion を削除。
Validation:
- `cargo fmt --check`: success
- `cd web/workspace && deno task test`: success
- `cd web/workspace && deno task check`: success
- `cd web/workspace && deno task build`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi`: success
Residual risks / review focus:
- `/api/companion/*` は互換 route として残しつつ、内部動作は Worker runtime 経路へ寄せている。主 UI path は引き続き `runtime_id + worker_id` の Worker Console。
- provider/profile/secret/authority 欠落時は input 不可 diagnostic になる。実 provider 設定がない環境では Companion は起動 projection されても入力不可。
- deterministic test backend による検証のため、外部 secret/provider には依存しない。
---
<!-- event: review author: yoi-reviewer-00001KW55B33H-companion at: 2026-06-28T07:05:54Z status: request_changes -->
## Review: request changes
request_changes
今回の実装で prior functional routing issues は解消されているが、status / transport の blocker が 1 件残っている。
## Blocker
`/api/workspace` がまだ Companion Console を not connected / input disabled として advertise している。
- `crates/workspace-server/src/server.rs:341-365``WorkspaceResponse.extension_points.companion_console` を組み立てている。
- ここでまだ以下を返している。
- `status: "not_connected"`
- note: `"browser input remains disabled until actual Worker/LLM execution is connected"`
これは現在求められる挙動と矛盾する。Companion status / transport は、input-capable なら `connected`、provider/config/profile/authority 不足などで input 不可なら `not_input_capable` + typed diagnostic を返すべきである。`/api/companion/status` が正しくても、この Browser-facing workspace status が stale な “not connected / disabled” state を露出しているため、client を誤誘導し得る。
## 改善済み / apparently satisfied
- `/api/companion/messages``CompanionConsole::send_message` / `RuntimeRegistry::send_input` 経由になり、旧固定 `companion_llm_not_connected` rejection ではなくなっている。
- Companion bootstrap は `ProfileSelector::Builtin("companion")` と Companion config bundle label を使っている。
- Companion transcript は runtime transcript projection 由来になっている。
- main Worker Console path は `runtime_id + worker_id` を使い、`/api/runtimes/{runtime_id}/workers/{worker_id}/input` に post する。
- existing Console rendering は protocol event / transcript paths を消費している。
- `/api/workspace` は以前の `local_root: PathBuf` を公開しなくなっている。
- negative test assertions 以外で public `can_stream_events` / `can_read_bounded_transcript` fields は見当たらない。
- fake/canned Companion assistant response path は見当たらない。
## Validation note
報告された validation command は再実行していない。test/check/build success は plausibly true だが、残る stale `/api/workspace` Companion status は更新後の behavior assertion で cover されていないため、passing tests だけではこの acceptance point の evidence にならない。
---
<!-- event: implementation_report author: yoi-coder-00001KW55B33H-companion-2 at: 2026-06-28T07:14:16Z -->
## Implementation report
Change-response implementation report:
Remaining reviewer blocker を修正し、追加 commit を作成済み。Ticket ファイル編集、merge、close、cleanup は未実施。
Commit:
- `3be193223c7efc67636667d1ad526646da81fb63 fix: report companion console runtime status`
Previous implementation commit:
- `ee25cfbcfd90983a24091ef30c0128d653095003 fix: route workspace companion through worker runtime`
変更概要:
- `/api/workspace``extension_points.companion_console` を固定値から Companion の実際の status / transport projection に変更。
- input-capable なら `status: "connected"`
- input 不可なら `status: "not_input_capable"` と typed diagnostics を返す
- stale note `"browser input remains disabled until actual Worker/LLM execution is connected"` を削除
- `ExtensionPointState``diagnostics` を追加し、Browser-facing projection でも Companion の typed diagnostic を確認できるようにした。
- Workspace web 側の `ExtensionPoint` 型にも `diagnostics` を追加。
- Focused test を追加・更新。
- `/api/workspace``companion_console``not_connected` を返さないこと
- input-capable deterministic backend では `connected` になること
- `not_input_capable` の場合は diagnostics が空でないこと
Validation:
- `cargo fmt --check`: success
- `cargo test -p yoi-workspace-server`: success
- `cargo check -p yoi`: success
- `git diff --check`: success
- `cd web/workspace && deno task test`: success
- `cd web/workspace && deno task check`: success
- `cd web/workspace && deno task build`: success
- `nix build .#yoi`: success
Residual risks / review focus:
- `ExtensionPointState` の JSON に `diagnostics` が増えている。Workspace web 側の型は更新済み。
- Companion が provider/config/profile/secret/authority 欠落で input-capable でない環境では、`/api/workspace` でも `not_input_capable` と診断情報が表示される。
---
<!-- event: review author: yoi-reviewer-00001KW55B33H-companion at: 2026-06-28T07:18:37Z status: approve -->
## Review: approve
approve
同じ worktree / branch を静的再レビューし、前回 blocker は解消され、Ticket scope の受け入れ条件を満たしていると判断した。
Validation performed:
- `.yoi/tickets/00001KW55B33H/item.md` を再読。
- 現在の `crates/workspace-server/src/server.rs`, `companion.rs`, `hosts.rs`, worker runtime adapter paths, web workspace types を確認。
- stale blocker strings / public flags を grep:
- `browser input remains disabled`
- `companion_llm_not_connected`
- `can_stream_events`
- `can_read_bounded_transcript`
- `local_root`
- fake/canned response markers
- ファイル変更や Ticket record 更新はしていない。
- full reported validation suite は再実行していない。
Evidence:
- `/api/workspace``extension_points.companion_console` は固定 stale value ではなく `api.companion.status()` 由来の status / diagnostics を使っている。
- `ExtensionPointState``diagnostics` が追加され、workspace web types も更新されている。
- Companion message send path は `RuntimeRegistry::send_input` / Worker runtime input path を使っており、fake response や固定 rejection ではない。
- Companion status は input-capable なら `connected`、そうでなければ diagnostics 付き `not_input_capable` を返す。
- Companion bootstrap は Companion profile / config-bundle path を使っている。
- Transcript projection は runtime transcript 由来。
- Worker Console route / input path は `runtime_id + worker_id` keyed のまま。
- negative assertions 以外で public `can_stream_events` / `can_read_bounded_transcript` fields は見当たらない。
- 以前の `/api/workspace` raw `local_root` exposure は消えている。
Reported validations は、updated server tests が Companion Console workspace status と runtime dispatch behavior を cover していることも含め、変更内容に対して妥当と判断した。
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-28T07:19:29Z -->
## Implementation report
Merge / validation report:
Implementation branch was integrated into the orchestration branch after reviewer approval.
Integrated commits:
- `ee25cfbcfd90983a24091ef30c0128d653095003 fix: route workspace companion through worker runtime`
- `3be193223c7efc67636667d1ad526646da81fb63 fix: report companion console runtime status`
Merge commit:
- `eb06b8a9 merge: workspace companion llm worker`
Validation in orchestration worktree:
- `cargo fmt --all --check`: success
- `cd web/workspace && deno task test`: success
- `cd web/workspace && deno task check`: success
- `cd web/workspace && deno task build`: success
- `cargo test -p yoi-workspace-server`: success (`34 passed`)
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Outcome:
- Workspace Companion now routes through embedded Runtime / `worker` runtime adapter instead of fake/providerless response or fixed non-connected rejection.
- `/api/companion/messages` is a compatibility route over the normal Worker input path.
- Companion bootstrap uses Companion profile / config bundle path.
- Companion status and `/api/workspace` companion console status report `connected` when input-capable, otherwise `not_input_capable` with typed diagnostics.
- Transcript projection is sourced from Runtime transcript / Worker protocol event flow.
- Worker Console path remains keyed by `runtime_id + worker_id`.
- Browser-facing raw `local_root` exposure was removed from `/api/workspace`.
- Public `can_stream_events` / `can_read_bounded_transcript` capability flags were not revived.
---
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-28T07:19:35Z from: inprogress to: done reason: implementation_merged_and_validated field: state -->
## State changed
Reviewer approval後に implementation branch を orchestration branch へ merge し、要求された validation が成功したため done に遷移する。
Validation:
- `cargo fmt --all --check`: success
- `cd web/workspace && deno task test`: success
- `cd web/workspace && deno task check`: success
- `cd web/workspace && deno task build`: success
- `cargo test -p yoi-workspace-server`: success (`34 passed`)
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
---
<!-- event: state_changed author: hare at: 2026-06-28T07:19:50Z from: done to: closed reason: closed field: state -->
## State changed
Ticket を closed にしました。
---
<!-- event: close author: hare at: 2026-06-28T07:19:50Z status: closed -->
## 完了
Workspace Companion を embedded Runtime / `worker` runtime adapter 経由の実行可能 Worker として扱う実装を行い、reviewer approval 後に orchestration branch へ merge した。
実装内容:
- `/api/companion/messages` の旧 `companion_llm_not_connected` 固定拒否経路を廃止し、通常の Worker runtime input path (`RuntimeRegistry::send_input`) に接続。
- Companion bootstrap を `builtin:companion` profile / Companion config bundle path に変更。
- Companion transcript projection を Runtime transcript 由来に変更。
- Companion status / transport を input-capable なら `connected`、不可なら `not_input_capable` + typed diagnostics に変更。
- `/api/workspace``extension_points.companion_console` も Companion の実 status / diagnostics 由来に変更し、stale `not_connected` / disabled note を削除。
- `ExtensionPointState``diagnostics` を追加し、Workspace web type も更新。
- Browser-facing `/api/workspace` から raw `local_root` exposure を削除。
- deterministic test backend により Companion bootstrap / input dispatch / assistant output / observation event / transcript projection を Worker execution path 経由で検証。
- fake/providerless/canned assistant response は導入していない。
- Worker Console path は `runtime_id + worker_id` keyed のまま維持。
- public `can_stream_events` / `can_read_bounded_transcript` capability は復活させていない。
Integrated commits:
- `ee25cfbcfd90983a24091ef30c0128d653095003 fix: route workspace companion through worker runtime`
- `3be193223c7efc67636667d1ad526646da81fb63 fix: report companion console runtime status`
- merge: `eb06b8a9 merge: workspace companion llm worker`
Validation:
- `cargo fmt --all --check`: success
- `cd web/workspace && deno task test`: success
- `cd web/workspace && deno task check`: success
- `cd web/workspace && deno task build`: success
- `cargo test -p yoi-workspace-server`: success (`34 passed`)
- `cargo check -p yoi`: success
- `git diff --check`: success
- `nix build .#yoi --no-link`: success
Operational note:
- User instructed not to use `StopPod` for now after repeated stop/hang symptoms. Cleanup will skip role-Pod shutdown and remove only child implementation worktree / branch.
---
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-28T07:20:22Z -->
## Implementation report
Cleanup report:
- User instructed not to use `StopPod` for now after repeated stop/hang symptoms. Role Pod shutdown was intentionally skipped.
- Child implementation worktree was removed:
- `/home/hare/Projects/yoi/.worktree/00001KW55B33H-workspace-companion-llm-worker`
- Child implementation branch was removed:
- `work/00001KW55B33H-workspace-companion-llm-worker`
- No root/original workspace cleanup was performed.
- Orchestration worktree is clean after worktree/branch cleanup.
Queue note:
- The three-ticket execution chain is now complete/closed:
- `00001KW55B32Y`
- `00001KW55B33B`
- `00001KW55B33H`
---

78
Cargo.lock generated
View File

@ -203,6 +203,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "31b698c5f9a010f6573133b09e0de5408834d0c82f8d7475a89fc1867a71cd90"
dependencies = [
"axum-core",
"base64",
"bytes",
"form_urlencoded",
"futures-util",
@ -221,8 +222,10 @@ dependencies = [
"serde_json",
"serde_path_to_error",
"serde_urlencoded",
"sha1",
"sync_wrapper",
"tokio",
"tokio-tungstenite 0.29.0",
"tower",
"tower-layer",
"tower-service",
@ -468,13 +471,17 @@ checksum = "c8d4a3bb8b1e0c1050499d1815f5ab16d04f0959b233085fb31653fbfc9d98f9"
name = "client"
version = "0.1.0"
dependencies = [
"futures",
"manifest",
"protocol",
"reqwest",
"serde",
"serde_json",
"tempfile",
"thiserror 2.0.18",
"ticket",
"tokio",
"tokio-tungstenite 0.29.0",
"uuid",
]
@ -1065,7 +1072,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "39cab71617ae0d63f51a36d69f866391735b51691dbda63cf6f96d042b63efeb"
dependencies = [
"libc",
"windows-sys 0.61.2",
"windows-sys 0.52.0",
]
[[package]]
@ -2536,7 +2543,7 @@ version = "0.50.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7957b9740744892f114936ab4a57b3f487491bbeafaf8083688b16841a4240e5"
dependencies = [
"windows-sys 0.61.2",
"windows-sys 0.59.0",
]
[[package]]
@ -3487,7 +3494,7 @@ dependencies = [
"errno",
"libc",
"linux-raw-sys 0.12.1",
"windows-sys 0.61.2",
"windows-sys 0.52.0",
]
[[package]]
@ -3544,7 +3551,7 @@ dependencies = [
"security-framework",
"security-framework-sys",
"webpki-root-certs",
"windows-sys 0.61.2",
"windows-sys 0.52.0",
]
[[package]]
@ -4154,7 +4161,7 @@ dependencies = [
"getrandom 0.4.2",
"once_cell",
"rustix 1.1.4",
"windows-sys 0.61.2",
"windows-sys 0.52.0",
]
[[package]]
@ -4422,7 +4429,19 @@ dependencies = [
"native-tls",
"tokio",
"tokio-native-tls",
"tungstenite",
"tungstenite 0.28.0",
]
[[package]]
name = "tokio-tungstenite"
version = "0.29.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8f72a05e828585856dacd553fba484c242c46e391fb0e58917c942ee9202915c"
dependencies = [
"futures-util",
"log",
"tokio",
"tungstenite 0.29.0",
]
[[package]]
@ -4709,6 +4728,22 @@ dependencies = [
"utf-8",
]
[[package]]
name = "tungstenite"
version = "0.29.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "6c01152af293afb9c7c2a57e4b559c5620b421f6d133261c60dd2d0cdb38e6b8"
dependencies = [
"bytes",
"data-encoding",
"http",
"httparse",
"log",
"rand 0.9.4",
"sha1",
"thiserror 2.0.18",
]
[[package]]
name = "type1-encoding-parser"
version = "0.1.1"
@ -5463,7 +5498,7 @@ version = "0.1.11"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c2a7b1c03c876122aa43f3020e6c3c3ee5c05081c9a00739faf7503aeba10d22"
dependencies = [
"windows-sys 0.61.2",
"windows-sys 0.52.0",
]
[[package]]
@ -5889,18 +5924,35 @@ dependencies = [
"thiserror 2.0.18",
"ticket",
"tokio",
"tokio-tungstenite",
"tokio-tungstenite 0.28.0",
"toml",
"tools",
"tracing",
"tungstenite",
"tungstenite 0.28.0",
"uuid",
"wasmtime",
"wat",
"worker-runtime",
"workflow",
"yoi-plugin-pdk",
]
[[package]]
name = "worker-runtime"
version = "0.1.0"
dependencies = [
"axum",
"futures",
"protocol",
"serde",
"serde_json",
"sha2 0.11.0",
"thiserror 2.0.18",
"tokio",
"tokio-tungstenite 0.29.0",
"tower",
]
[[package]]
name = "workflow"
version = "0.1.0"
@ -5985,9 +6037,10 @@ dependencies = [
"async-trait",
"axum",
"chrono",
"manifest",
"pod-store",
"futures",
"project-record",
"protocol",
"reqwest",
"rusqlite",
"serde",
"serde_json",
@ -5997,10 +6050,13 @@ dependencies = [
"thiserror 2.0.18",
"ticket",
"tokio",
"tokio-tungstenite 0.29.0",
"toml",
"tower",
"tracing",
"uuid",
"worker",
"worker-runtime",
]
[[package]]

View File

@ -9,6 +9,7 @@ members = [
"crates/manifest",
"crates/mcp",
"crates/worker",
"crates/worker-runtime",
"crates/plugin-pdk",
"crates/yoi",
"crates/pod-store",
@ -36,6 +37,7 @@ default-members = [
"crates/manifest",
"crates/mcp",
"crates/worker",
"crates/worker-runtime",
"crates/plugin-pdk",
"crates/yoi",
"crates/pod-store",
@ -70,6 +72,7 @@ memory = { path = "crates/memory" }
ticket = { path = "crates/ticket" }
project-record = { path = "crates/project-record" }
worker = { path = "crates/worker" }
worker-runtime = { path = "crates/worker-runtime" }
yoi-plugin-pdk = { path = "crates/plugin-pdk" }
yoi = { path = "crates/yoi" }
pod-registry = { path = "crates/pod-registry" }
@ -101,6 +104,7 @@ sha2 = "0.11"
tempfile = "3.27"
thiserror = "2.0"
tokio = "1.52"
tokio-tungstenite = "0.29"
tower = "0.5"
toml = "1.1"
tracing = "0.1"

View File

@ -8,9 +8,13 @@ license.workspace = true
protocol = { workspace = true }
manifest = { workspace = true }
ticket = { workspace = true }
futures = { workspace = true }
reqwest = { version = "0.13", default-features = false, features = ["json", "native-tls"] }
serde = { workspace = true }
serde_json = { workspace = true }
thiserror = { workspace = true }
tokio = { workspace = true, features = ["rt", "macros", "net", "io-util", "sync", "time", "process", "fs"] }
tokio-tungstenite = { workspace = true }
uuid = { workspace = true }
[dev-dependencies]

View File

@ -0,0 +1,694 @@
use std::collections::VecDeque;
use std::fmt;
use std::time::Duration;
use futures::StreamExt;
use protocol::{ErrorCode, Event, Greeting, InFlightSnapshot, Method, Segment, WorkerStatus};
use serde::{Deserialize, Serialize};
use tokio::sync::mpsc;
use tokio_tungstenite::connect_async;
use tokio_tungstenite::tungstenite::Message as TungsteniteMessage;
const TRANSCRIPT_SNAPSHOT_LIMIT: usize = 512;
const RECONNECT_DELAY: Duration = Duration::from_millis(500);
const MAX_RECONNECT_ATTEMPTS: usize = 3;
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct BackendRuntimeTarget {
/// Workspace Backend API root URL, for example `http://127.0.0.1:8787`.
/// This is intentionally the Backend endpoint, not a Runtime endpoint.
pub base_url: String,
/// Backend-owned Runtime identity used as path authority.
pub runtime_id: String,
/// Backend-owned Worker identity used as path authority.
pub worker_id: String,
}
impl BackendRuntimeTarget {
pub fn new(
base_url: impl Into<String>,
runtime_id: impl Into<String>,
worker_id: impl Into<String>,
) -> Self {
Self {
base_url: base_url.into(),
runtime_id: runtime_id.into(),
worker_id: worker_id.into(),
}
}
pub fn display_label(&self) -> String {
format!("{}:{}", self.runtime_id, self.worker_id)
}
}
#[derive(Debug)]
pub struct BackendRuntimeClient {
target: BackendRuntimeTarget,
http: reqwest::Client,
events: mpsc::UnboundedReceiver<Event>,
diagnostics: VecDeque<Event>,
_observation_task: tokio::task::JoinHandle<()>,
}
#[derive(Debug)]
pub enum BackendRuntimeClientError {
InvalidTarget(String),
Http(reqwest::Error),
}
impl fmt::Display for BackendRuntimeClientError {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
match self {
Self::InvalidTarget(message) => f.write_str(message),
Self::Http(error) => write!(f, "{error}"),
}
}
}
impl std::error::Error for BackendRuntimeClientError {}
impl From<reqwest::Error> for BackendRuntimeClientError {
fn from(error: reqwest::Error) -> Self {
Self::Http(error)
}
}
impl BackendRuntimeClient {
pub async fn connect(target: BackendRuntimeTarget) -> Result<Self, BackendRuntimeClientError> {
validate_target(&target)?;
let http = reqwest::Client::new();
let (tx, rx) = mpsc::unbounded_channel();
let suppress_initial_snapshot = match load_initial_transcript(&http, &target).await {
Ok(events) => {
for event in events {
let _ = tx.send(event);
}
true
}
Err(error) => {
let _ = tx.send(diagnostic_event(format!(
"Backend initial transcript unavailable for {}: {error}",
target.display_label()
)));
false
}
};
let observation_target = target.clone();
let observation_tx = tx.clone();
let observation_task = tokio::spawn(async move {
observe_worker_events(
observation_target,
observation_tx,
suppress_initial_snapshot,
)
.await;
});
Ok(Self {
target,
http,
events: rx,
diagnostics: VecDeque::new(),
_observation_task: observation_task,
})
}
pub fn try_next_event(&mut self) -> Option<Event> {
if let Some(event) = self.diagnostics.pop_front() {
return Some(event);
}
self.events.try_recv().ok()
}
pub async fn next_event(&mut self) -> Option<Event> {
if let Some(event) = self.diagnostics.pop_front() {
return Some(event);
}
self.events.recv().await
}
pub async fn send(&mut self, method: &Method) -> Result<(), BackendRuntimeClientError> {
match backend_command_from_method(method) {
BackendCommand::Input { kind, content } => {
let url = self.worker_api_url("input");
match self
.http
.post(url)
.json(&WorkerInputRequest { kind, content })
.send()
.await
.and_then(|response| response.error_for_status())
{
Ok(response) => match response.json::<WorkerInputResult>().await {
Ok(result) => self.enqueue_operation_diagnostics(
"input",
result.state,
result.diagnostics,
),
Err(error) => self.enqueue_diagnostic(format!(
"Backend runtime input response could not be decoded for {}: {error}",
self.target.display_label()
)),
},
Err(error) => self.enqueue_diagnostic(format!(
"Backend runtime input failed for {}: {error}",
self.target.display_label()
)),
}
}
BackendCommand::Lifecycle { action, reason } => {
let url = self.worker_api_url(action);
match self
.http
.post(url)
.json(&WorkerLifecycleRequest { reason })
.send()
.await
.and_then(|response| response.error_for_status())
{
Ok(response) => match response.json::<WorkerLifecycleResult>().await {
Ok(result) => self.enqueue_operation_diagnostics(
action,
result.state,
result.diagnostics,
),
Err(error) => self.enqueue_diagnostic(format!(
"Backend runtime {action} response could not be decoded for {}: {error}",
self.target.display_label()
)),
},
Err(error) => self.enqueue_diagnostic(format!(
"Backend runtime {action} failed for {}: {error}",
self.target.display_label()
)),
}
}
BackendCommand::Unsupported(message) => {
self.enqueue_diagnostic(message);
}
}
Ok(())
}
fn worker_api_url(&self, suffix: &str) -> String {
let path = format!(
"/api/runtimes/{}/workers/{}/{}",
path_segment_encode(&self.target.runtime_id),
path_segment_encode(&self.target.worker_id),
suffix
);
join_base_and_path(&self.target.base_url, &path)
}
fn enqueue_operation_diagnostics(
&mut self,
operation: &str,
state: String,
diagnostics: Vec<BackendDiagnostic>,
) {
if state != "accepted" {
self.enqueue_diagnostic(format!(
"Backend runtime {operation} was {state} for {}",
self.target.display_label()
));
}
for diagnostic in diagnostics {
self.enqueue_diagnostic(format!(
"Backend runtime {operation} diagnostic [{}]: {}",
diagnostic.code, diagnostic.message
));
}
}
fn enqueue_diagnostic(&mut self, message: impl Into<String>) {
self.diagnostics.push_back(diagnostic_event(message));
}
}
impl Drop for BackendRuntimeClient {
fn drop(&mut self) {
self._observation_task.abort();
}
}
#[derive(Debug, PartialEq, Eq)]
enum BackendCommand {
Input {
kind: WorkerInputKind,
content: String,
},
Lifecycle {
action: &'static str,
reason: Option<String>,
},
Unsupported(String),
}
fn backend_command_from_method(method: &Method) -> BackendCommand {
match method {
Method::Run { input } => BackendCommand::Input {
kind: WorkerInputKind::User,
content: Segment::flatten_to_text(input),
},
Method::Notify { message, .. } => BackendCommand::Input {
kind: WorkerInputKind::System,
content: message.clone(),
},
Method::Cancel => BackendCommand::Lifecycle {
action: "cancel",
reason: Some("requested from TUI Backend Runtime API client".to_string()),
},
Method::Shutdown => BackendCommand::Lifecycle {
action: "stop",
reason: Some("requested from TUI Backend Runtime API client".to_string()),
},
Method::Pause => BackendCommand::Unsupported(
"Backend Runtime API does not expose pause/resume for the TUI client yet; command was not sent".to_string(),
),
Method::Resume => BackendCommand::Unsupported(
"Backend Runtime API does not expose resume for the TUI client yet; command was not sent".to_string(),
),
Method::Compact => BackendCommand::Unsupported(
"Backend Runtime API does not expose compaction for the TUI client yet; command was not sent".to_string(),
),
Method::ListCompletions { .. } => BackendCommand::Unsupported(
"Backend Runtime API does not expose completion lookup for the TUI client yet".to_string(),
),
Method::ListRewindTargets | Method::RewindTo { .. } => BackendCommand::Unsupported(
"Backend Runtime API does not expose rewind controls for the TUI client yet; command was not sent".to_string(),
),
Method::ListWorkers | Method::RestoreWorker { .. } | Method::RegisterPeer { .. } => {
BackendCommand::Unsupported(
"Backend Runtime API worker-management controls are not available from this Console connection".to_string(),
)
}
Method::WorkerEvent(_) => BackendCommand::Unsupported(
"Backend Runtime API does not accept child Worker lifecycle events from this Console connection".to_string(),
),
}
}
async fn load_initial_transcript(
http: &reqwest::Client,
target: &BackendRuntimeTarget,
) -> Result<Vec<Event>, BackendRuntimeClientError> {
let path = format!(
"/api/runtimes/{}/workers/{}/transcript?start=0&limit={TRANSCRIPT_SNAPSHOT_LIMIT}",
path_segment_encode(&target.runtime_id),
path_segment_encode(&target.worker_id)
);
let response = http
.get(join_base_and_path(&target.base_url, &path))
.send()
.await?
.error_for_status()?;
let transcript: WorkerTranscriptProjection = response.json().await?;
Ok(transcript_projection_to_events(target, transcript))
}
fn transcript_projection_to_events(
target: &BackendRuntimeTarget,
transcript: WorkerTranscriptProjection,
) -> Vec<Event> {
let mut events = vec![Event::Snapshot {
entries: Vec::new(),
greeting: Greeting {
worker_name: target.worker_id.clone(),
cwd: String::new(),
provider: "backend-runtime-api".to_string(),
model: target.runtime_id.clone(),
scope_summary: "Backend Runtime API worker observation".to_string(),
tools: Vec::new(),
context_window: 0,
context_tokens: 0,
},
status: WorkerStatus::Idle,
in_flight: InFlightSnapshot { blocks: Vec::new() },
}];
for item in transcript.items {
match item.role.as_str() {
"user" => events.push(Event::UserMessage {
segments: vec![Segment::text(item.content)],
}),
"assistant" => {
events.push(Event::TextDelta {
text: item.content.clone(),
});
events.push(Event::TextDone { text: item.content });
}
role => events.push(Event::Alert(protocol::Alert {
level: protocol::AlertLevel::Warn,
source: protocol::AlertSource::Worker,
message: format!(
"Backend transcript item with role `{role}` is not rendered as chat content"
),
timestamp_ms: 0,
})),
}
}
for diagnostic in transcript.diagnostics {
events.push(diagnostic_event(format!(
"Backend transcript diagnostic [{}]: {}",
diagnostic.code, diagnostic.message
)));
}
events
}
async fn observe_worker_events(
target: BackendRuntimeTarget,
tx: mpsc::UnboundedSender<Event>,
mut suppress_next_snapshot: bool,
) {
let mut cursor: Option<String> = None;
let mut last_sequence = 0_u64;
let mut attempts = 0_usize;
loop {
let url = observation_ws_url(&target, cursor.as_deref());
match connect_async(&url).await {
Ok((mut ws, _)) => {
attempts = 0;
while let Some(frame) = ws.next().await {
match frame {
Ok(TungsteniteMessage::Text(text)) => {
match serde_json::from_str::<ClientWorkerEventWsFrame>(&text) {
Ok(ClientWorkerEventWsFrame::Event { envelope }) => {
if envelope.runtime_id != target.runtime_id
|| envelope.worker_id != target.worker_id
{
let _ = tx.send(diagnostic_event(format!(
"Backend observation frame target mismatch: got {}:{}, expected {}",
envelope.runtime_id,
envelope.worker_id,
target.display_label()
)));
continue;
}
if let Some(sequence) = decode_backend_cursor(&envelope.cursor)
{
if sequence <= last_sequence {
continue;
}
last_sequence = sequence;
} else {
let _ = tx.send(diagnostic_event(format!(
"Backend observation cursor was malformed: {}",
envelope.cursor
)));
}
cursor = Some(envelope.cursor.clone());
if suppress_next_snapshot
&& matches!(envelope.payload, Event::Snapshot { .. })
{
suppress_next_snapshot = false;
continue;
}
let _ = tx.send(envelope.payload);
}
Ok(ClientWorkerEventWsFrame::Diagnostic { diagnostic }) => {
let message = format!(
"Backend observation diagnostic [{}]: {}",
diagnostic.code, diagnostic.message
);
let _ = tx.send(diagnostic_event(message));
if diagnostic.code == "backend.cursor_unknown_or_expired" {
cursor = None;
last_sequence = 0;
break;
}
}
Err(error) => {
let _ = tx.send(diagnostic_event(format!(
"Backend observation frame was not valid JSON: {error}"
)));
}
}
}
Ok(TungsteniteMessage::Close(_)) => break,
Ok(TungsteniteMessage::Ping(_))
| Ok(TungsteniteMessage::Pong(_))
| Ok(TungsteniteMessage::Binary(_))
| Ok(TungsteniteMessage::Frame(_)) => {}
Err(error) => {
let _ = tx.send(diagnostic_event(format!(
"Backend observation WebSocket error for {}: {error}",
target.display_label()
)));
break;
}
}
}
}
Err(error) => {
let _ = tx.send(diagnostic_event(format!(
"Backend observation WebSocket connect failed for {}: {error}",
target.display_label()
)));
}
}
attempts += 1;
if attempts > MAX_RECONNECT_ATTEMPTS {
let _ = tx.send(diagnostic_event(format!(
"Backend observation stream for {} stopped after {MAX_RECONNECT_ATTEMPTS} reconnect attempts",
target.display_label()
)));
break;
}
tokio::time::sleep(RECONNECT_DELAY).await;
}
}
fn diagnostic_event(message: impl Into<String>) -> Event {
Event::Error {
code: ErrorCode::Internal,
message: message.into(),
}
}
fn validate_target(target: &BackendRuntimeTarget) -> Result<(), BackendRuntimeClientError> {
if target.base_url.trim().is_empty() {
return Err(BackendRuntimeClientError::InvalidTarget(
"Backend API base URL is required".to_string(),
));
}
if !(target.base_url.starts_with("http://") || target.base_url.starts_with("https://")) {
return Err(BackendRuntimeClientError::InvalidTarget(
"Backend API base URL must start with http:// or https://".to_string(),
));
}
if target.runtime_id.is_empty() {
return Err(BackendRuntimeClientError::InvalidTarget(
"runtime_id is required".to_string(),
));
}
if target.worker_id.is_empty() {
return Err(BackendRuntimeClientError::InvalidTarget(
"worker_id is required".to_string(),
));
}
Ok(())
}
fn observation_ws_url(target: &BackendRuntimeTarget, cursor: Option<&str>) -> String {
let path = format!(
"/api/runtimes/{}/workers/{}/events/ws",
path_segment_encode(&target.runtime_id),
path_segment_encode(&target.worker_id)
);
let mut url = join_base_and_path(&http_base_to_ws(&target.base_url), &path);
if let Some(cursor) = cursor {
url.push_str("?cursor=");
url.push_str(&query_value_encode(cursor));
}
url
}
fn http_base_to_ws(base: &str) -> String {
if let Some(rest) = base.strip_prefix("https://") {
format!("wss://{rest}")
} else if let Some(rest) = base.strip_prefix("http://") {
format!("ws://{rest}")
} else {
base.to_string()
}
}
fn join_base_and_path(base: &str, path: &str) -> String {
format!("{}{}", base.trim_end_matches('/'), path)
}
fn decode_backend_cursor(cursor: &str) -> Option<u64> {
let encoded = cursor.strip_prefix("bo_")?;
if encoded.len() != 16 {
return None;
}
u64::from_str_radix(encoded, 16).ok()
}
fn path_segment_encode(input: &str) -> String {
percent_encode(input, |byte| {
byte.is_ascii_alphanumeric() || matches!(byte, b'-' | b'.' | b'_' | b'~')
})
}
fn query_value_encode(input: &str) -> String {
percent_encode(input, |byte| {
byte.is_ascii_alphanumeric() || matches!(byte, b'-' | b'.' | b'_' | b'~')
})
}
fn percent_encode(input: &str, keep: impl Fn(u8) -> bool) -> String {
let mut encoded = String::with_capacity(input.len());
for byte in input.bytes() {
if keep(byte) {
encoded.push(byte as char);
} else {
encoded.push('%');
encoded.push_str(&format!("{byte:02X}"));
}
}
encoded
}
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
enum WorkerInputKind {
User,
System,
}
#[derive(Debug, Serialize)]
struct WorkerInputRequest {
kind: WorkerInputKind,
content: String,
}
#[derive(Debug, Serialize)]
struct WorkerLifecycleRequest {
reason: Option<String>,
}
#[derive(Debug, Deserialize)]
struct WorkerInputResult {
state: String,
#[serde(default)]
diagnostics: Vec<BackendDiagnostic>,
}
#[derive(Debug, Deserialize)]
struct WorkerLifecycleResult {
state: String,
#[serde(default)]
diagnostics: Vec<BackendDiagnostic>,
}
#[derive(Debug, Deserialize)]
struct BackendDiagnostic {
code: String,
message: String,
}
#[derive(Debug, Deserialize)]
struct WorkerTranscriptProjection {
#[serde(default)]
items: Vec<WorkerTranscriptItem>,
#[serde(default)]
diagnostics: Vec<BackendDiagnostic>,
}
#[derive(Debug, Deserialize)]
struct WorkerTranscriptItem {
role: String,
content: String,
}
#[derive(Debug, Deserialize)]
#[serde(tag = "kind", rename_all = "snake_case")]
enum ClientWorkerEventWsFrame {
Event {
envelope: ClientWorkerEventWsEnvelope,
},
Diagnostic {
diagnostic: ClientWorkerEventWsDiagnostic,
},
}
#[derive(Debug, Deserialize)]
struct ClientWorkerEventWsEnvelope {
cursor: String,
runtime_id: String,
worker_id: String,
payload: Event,
}
#[derive(Debug, Deserialize)]
struct ClientWorkerEventWsDiagnostic {
code: String,
message: String,
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn backend_command_maps_run_to_user_input_without_runtime_endpoint() {
let method = Method::Run {
input: vec![
Segment::text("hello"),
Segment::FileRef {
path: "src/lib.rs".into(),
},
],
};
assert_eq!(
backend_command_from_method(&method),
BackendCommand::Input {
kind: WorkerInputKind::User,
content: "hello@src/lib.rs".to_string(),
}
);
}
#[test]
fn observation_url_uses_backend_runtime_worker_identity() {
let target =
BackendRuntimeTarget::new("http://127.0.0.1:8787/", "runtime/one", "worker one");
assert_eq!(
observation_ws_url(&target, Some("bo_0000000000000001")),
"ws://127.0.0.1:8787/api/runtimes/runtime%2Fone/workers/worker%20one/events/ws?cursor=bo_0000000000000001"
);
}
#[test]
fn transcript_projection_seeds_snapshot_and_chat_events() {
let target = BackendRuntimeTarget::new("http://backend", "runtime-a", "worker-b");
let events = transcript_projection_to_events(
&target,
WorkerTranscriptProjection {
items: vec![
WorkerTranscriptItem {
role: "user".to_string(),
content: "hi".to_string(),
},
WorkerTranscriptItem {
role: "assistant".to_string(),
content: "hello".to_string(),
},
],
diagnostics: Vec::new(),
},
);
assert!(matches!(events[0], Event::Snapshot { .. }));
assert!(matches!(events[1], Event::UserMessage { .. }));
assert!(matches!(events[2], Event::TextDelta { .. }));
assert!(matches!(events[3], Event::TextDone { .. }));
}
}

View File

@ -8,11 +8,13 @@
//!
//! TUI / GUI / E2E ハーネスはこの crate に依存して protocol を喋る。
pub mod backend_runtime;
pub mod runtime_command;
pub mod spawn;
pub mod ticket_role;
mod worker_client;
pub use backend_runtime::{BackendRuntimeClient, BackendRuntimeClientError, BackendRuntimeTarget};
pub use runtime_command::WorkerRuntimeCommand;
pub use spawn::{

View File

@ -16,16 +16,16 @@ use crossterm::event::{
};
use crossterm::terminal::{EnterAlternateScreen, LeaveAlternateScreen};
use crossterm::{Command, execute};
use protocol::{Event, Method, WorkerStatus};
#[cfg(feature = "e2e-test")]
use protocol::{Event, Greeting, RewindSummary, RewindTarget, RewindTargetId, Segment};
use protocol::{Method, WorkerStatus};
use protocol::{Greeting, RewindSummary, RewindTarget, RewindTargetId, Segment};
use ratatui::Terminal;
use ratatui::backend::CrosstermBackend;
use session_store::SegmentId;
use tokio::sync::mpsc;
use base64::{Engine as _, engine::general_purpose::STANDARD as BASE64_STANDARD};
use client::{WorkerClient, WorkerRuntimeCommand};
use client::{BackendRuntimeClient, BackendRuntimeTarget, WorkerClient, WorkerRuntimeCommand};
use crate::app::{ActionbarNoticeLevel, ActionbarNoticeSource, App};
use crate::composer_keys::{ComposerEditAction, composer_edit_action};
@ -171,6 +171,54 @@ pub(crate) async fn run_worker_name(
result
}
enum ConsoleConnection {
LegacySocket(WorkerClient),
BackendRuntime(BackendRuntimeClient),
}
impl ConsoleConnection {
fn try_next_event(&mut self) -> Option<Event> {
match self {
Self::LegacySocket(client) => client.try_next_event(),
Self::BackendRuntime(client) => client.try_next_event(),
}
}
async fn next_event(&mut self) -> Option<Event> {
match self {
Self::LegacySocket(client) => client.next_event().await,
Self::BackendRuntime(client) => client.next_event().await,
}
}
async fn send(&mut self, method: &Method) -> Result<(), Box<dyn std::error::Error>> {
match self {
Self::LegacySocket(client) => Ok(client.send(method).await?),
Self::BackendRuntime(client) => Ok(client.send(method).await?),
}
}
}
pub(crate) async fn run_backend_runtime(
target: BackendRuntimeTarget,
) -> Result<(), Box<dyn std::error::Error>> {
let worker_label = target.display_label();
let client = BackendRuntimeClient::connect(target).await?;
let mut terminal = enter_fullscreen()?;
let workspace_root = std::env::current_dir().unwrap_or_else(|_| std::path::PathBuf::from("."));
let mut app = App::new_with_persistent_input_history(worker_label, &workspace_root);
app.connected = true;
let result = run_loop(
&mut terminal,
&mut app,
ConsoleConnection::BackendRuntime(client),
None,
)
.await;
let _ = leave_fullscreen(&mut terminal);
result
}
async fn run_connected_pod(
terminal: &mut ConsoleTerminal,
worker_name: String,
@ -180,7 +228,13 @@ async fn run_connected_pod(
let workspace_root = std::env::current_dir().unwrap_or_else(|_| std::path::PathBuf::from("."));
let mut app = App::new_with_persistent_input_history(worker_name, &workspace_root);
app.connected = true;
run_loop(terminal, &mut app, client, runtime_command).await
run_loop(
terminal,
&mut app,
ConsoleConnection::LegacySocket(client),
Some(runtime_command),
)
.await
}
pub(crate) async fn open_from_dashboard(
@ -396,7 +450,13 @@ async fn run(
app.connected = true;
// The Worker sends `Event::Snapshot` automatically on connect;
// no explicit method call is required to fetch history.
run_loop(terminal, &mut app, client, runtime_command).await?;
run_loop(
terminal,
&mut app,
ConsoleConnection::LegacySocket(client),
Some(runtime_command),
)
.await?;
}
Err(e) => {
app.push_error(format!(
@ -673,9 +733,9 @@ where
async fn drain_terminal_events(
app: &mut App,
client: &mut WorkerClient,
client: &mut ConsoleConnection,
term_rx: &mut mpsc::UnboundedReceiver<TerminalEventResult>,
runtime_command: &WorkerRuntimeCommand,
runtime_command: Option<&WorkerRuntimeCommand>,
) -> Result<bool, Box<dyn std::error::Error>> {
let mut handled = false;
for _ in 0..TERMINAL_EVENT_DRAIN_LIMIT {
@ -701,7 +761,7 @@ async fn drain_terminal_events(
async fn drain_worker_events(
app: &mut App,
client: &mut WorkerClient,
client: &mut ConsoleConnection,
) -> Result<bool, Box<dyn std::error::Error>> {
let mut handled = false;
for _ in 0..POD_EVENT_DRAIN_LIMIT {
@ -721,8 +781,8 @@ async fn drain_worker_events(
async fn run_loop(
terminal: &mut Terminal<CrosstermBackend<io::Stdout>>,
app: &mut App,
mut client: WorkerClient,
runtime_command: WorkerRuntimeCommand,
mut client: ConsoleConnection,
runtime_command: Option<WorkerRuntimeCommand>,
) -> Result<(), Box<dyn std::error::Error>> {
let (_terminal_reader, mut term_rx) = TerminalEventReader::spawn()?;
@ -734,7 +794,7 @@ async fn run_loop(
}
let handled_term_event =
drain_terminal_events(app, &mut client, &mut term_rx, &runtime_command).await?;
drain_terminal_events(app, &mut client, &mut term_rx, runtime_command.as_ref()).await?;
if app.quit {
break;
}
@ -746,7 +806,8 @@ async fn run_loop(
match next_loop_input(&mut term_rx, app.connected, client.next_event()).await {
LoopInput::Terminal(term_event) => {
handle_terminal_event(app, &mut client, term_event?, &runtime_command).await?;
handle_terminal_event(app, &mut client, term_event?, runtime_command.as_ref())
.await?;
}
LoopInput::Worker(event) => match event {
Some(ev) => {
@ -770,9 +831,9 @@ async fn run_loop(
async fn handle_terminal_event(
app: &mut App,
client: &mut WorkerClient,
client: &mut ConsoleConnection,
event: TermEvent,
_runtime_command: &WorkerRuntimeCommand,
_runtime_command: Option<&WorkerRuntimeCommand>,
) -> Result<(), Box<dyn std::error::Error>> {
match event {
TermEvent::Key(key) => {

View File

@ -33,7 +33,7 @@ use crossterm::execute;
use crossterm::terminal::{LeaveAlternateScreen, disable_raw_mode, enable_raw_mode};
use session_store::SegmentId;
use client::WorkerRuntimeCommand;
use client::{BackendRuntimeTarget, WorkerRuntimeCommand};
#[derive(Debug, Clone)]
pub struct LaunchOptions {
@ -55,6 +55,9 @@ pub enum LaunchMode {
worker_name: String,
socket_override: Option<PathBuf>,
},
/// `yoi --backend <url> --runtime-id <id> --worker-id <id>`: connect through the
/// Workspace Backend Runtime API and observe the Backend-proxied event stream.
BackendRuntime { target: BackendRuntimeTarget },
/// `yoi resume`: open the Worker picker, then attach to the selected live Worker
/// or restore the selected stopped Worker by name. Without `--all`, the picker
/// is scoped to the current runtime workspace.
@ -103,6 +106,7 @@ pub async fn launch(options: LaunchOptions) -> ExitCode {
worker_name,
socket_override,
} => console::run_worker_name(worker_name, socket_override, runtime_command).await,
LaunchMode::BackendRuntime { target } => console::run_backend_runtime(target).await,
LaunchMode::Resume { all } => {
console::run_resume(runtime_command, workspace_root.clone(), all).await
}

View File

@ -0,0 +1,32 @@
[package]
name = "worker-runtime"
description = "Embedded memory-backed Runtime API for Worker management"
version = "0.1.0"
edition.workspace = true
license.workspace = true
[[bin]]
name = "worker-runtime-rest-server"
path = "src/main.rs"
required-features = ["http-server"]
[features]
default = []
fs-store = ["dep:serde_json"]
http-server = ["dep:axum", "dep:serde_json", "dep:tokio", "dep:tower"]
ws-server = ["http-server", "axum/ws", "dep:futures", "dep:protocol", "tokio/sync"]
[dependencies]
axum = { workspace = true, optional = true }
futures = { workspace = true, optional = true }
protocol = { workspace = true, optional = true }
serde = { workspace = true, features = ["derive"] }
sha2.workspace = true
serde_json = { workspace = true, optional = true }
thiserror = { workspace = true }
tokio = { workspace = true, features = ["net", "rt"], optional = true }
tower = { workspace = true, features = ["util"], optional = true }
[dev-dependencies]
tokio = { workspace = true, features = ["macros", "rt-multi-thread"] }
tokio-tungstenite.workspace = true

View File

@ -0,0 +1,183 @@
use crate::execution::WorkerExecutionStatus;
use crate::identity::{RuntimeId, WorkerId, WorkerRef};
use serde::{Deserialize, Serialize};
/// Intent supplied when a Worker is created.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", rename_all = "snake_case")]
pub enum WorkerIntent {
Assistant {
#[serde(default, skip_serializing_if = "Option::is_none")]
purpose: Option<String>,
},
Task {
objective: String,
},
Role {
role: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
purpose: Option<String>,
},
}
impl Default for WorkerIntent {
fn default() -> Self {
Self::Assistant { purpose: None }
}
}
/// Profile selector boundary. This is a selector, not a resolved config bundle.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", content = "value", rename_all = "snake_case")]
pub enum ProfileSelector {
RuntimeDefault,
Builtin(String),
Named(String),
}
impl Default for ProfileSelector {
fn default() -> Self {
Self::RuntimeDefault
}
}
/// Backend-synced config bundle reference used during Worker creation.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ConfigBundleRef {
pub id: String,
pub digest: String,
}
/// Requested capability name plus optional human-readable reason.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct CapabilityRequest {
pub name: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub reason: Option<String>,
}
impl CapabilityRequest {
pub fn named(name: impl Into<String>) -> Self {
Self {
name: name.into(),
reason: None,
}
}
}
/// Opaque workspace reference supplied by a caller.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkspaceRef {
pub name: String,
pub reference: String,
}
/// Opaque mount reference supplied by a caller.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct MountRef {
pub name: String,
pub reference: String,
}
/// Worker creation request for the catalog/lifecycle API.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct CreateWorkerRequest {
pub intent: WorkerIntent,
pub profile: ProfileSelector,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub config_bundle: Option<ConfigBundleRef>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub requested_capabilities: Vec<CapabilityRequest>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub workspace_refs: Vec<WorkspaceRef>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub mount_refs: Vec<MountRef>,
}
impl Default for CreateWorkerRequest {
fn default() -> Self {
Self {
intent: WorkerIntent::default(),
profile: ProfileSelector::default(),
config_bundle: None,
requested_capabilities: Vec::new(),
workspace_refs: Vec::new(),
mount_refs: Vec::new(),
}
}
}
impl CreateWorkerRequest {
/// Create a tools-less Worker using runtime-local default resources.
pub fn tools_less(intent: WorkerIntent, profile: ProfileSelector) -> Self {
Self {
intent,
profile,
config_bundle: None,
requested_capabilities: Vec::new(),
workspace_refs: Vec::new(),
mount_refs: Vec::new(),
}
}
}
/// Worker lifecycle status for the in-memory embedded runtime.
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum WorkerStatus {
Running,
Stopped,
Cancelled,
}
impl WorkerStatus {
pub fn is_active(self) -> bool {
matches!(self, Self::Running)
}
}
/// Lightweight catalog row.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkerSummary {
pub worker_ref: WorkerRef,
pub runtime_id: RuntimeId,
pub worker_id: WorkerId,
pub status: WorkerStatus,
pub execution: WorkerExecutionStatus,
pub intent: WorkerIntent,
pub profile: ProfileSelector,
pub requested_capability_count: usize,
pub has_config_bundle: bool,
pub transcript_len: usize,
pub last_event_id: u64,
}
/// Full Worker catalog/lifecycle detail.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkerDetail {
pub worker_ref: WorkerRef,
pub runtime_id: RuntimeId,
pub worker_id: WorkerId,
pub status: WorkerStatus,
pub execution: WorkerExecutionStatus,
pub intent: WorkerIntent,
pub profile: ProfileSelector,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub config_bundle: Option<ConfigBundleRef>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub requested_capabilities: Vec<CapabilityRequest>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub workspace_refs: Vec<WorkspaceRef>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub mount_refs: Vec<MountRef>,
pub transcript_len: usize,
pub last_event_id: u64,
}
/// Acknowledgement returned by stop/cancel lifecycle operations.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkerLifecycleAck {
pub worker_ref: WorkerRef,
pub status: WorkerStatus,
pub event_id: u64,
}

View File

@ -0,0 +1,519 @@
use crate::catalog::{ConfigBundleRef, ProfileSelector};
use crate::error::RuntimeError;
use serde::{Deserialize, Serialize};
use sha2::{Digest, Sha256};
pub const CONFIG_BUNDLE_DIGEST_ALGORITHM: &str = "sha256";
/// Backend-synced Profile/config bundle stored by a Runtime.
///
/// The bundle is intentionally an intent/declaration boundary: it contains
/// profile selectors plus refs/grants/policies, never secret values, direct
/// Runtime endpoints, raw socket/session paths, runtime-local mount actual
/// paths, host-local cache paths, or fully resolved WorkerSpec content.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ConfigBundle {
pub metadata: ConfigBundleMetadata,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub profiles: Vec<ConfigProfileDescriptor>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub declarations: Vec<ConfigDeclaration>,
}
impl ConfigBundle {
pub fn computed_digest(&self) -> String {
let mut lines = Vec::new();
lines.push(format!("id\0{}", self.metadata.id));
lines.push(format!("revision\0{}", self.metadata.revision));
lines.push(format!("workspace_id\0{}", self.metadata.workspace_id));
lines.push(format!("created_at\0{}", self.metadata.created_at));
lines.push(format!(
"provenance.source\0{}",
self.metadata.provenance.source
));
lines.push(format!(
"provenance.detail\0{}",
self.metadata.provenance.detail.as_deref().unwrap_or("")
));
let mut profiles = self.profiles.clone();
profiles.sort_by(|left, right| {
profile_sort_key(&left.selector).cmp(&profile_sort_key(&right.selector))
});
for profile in profiles {
lines.push(format!(
"profile\0{}\0{}",
profile_sort_key(&profile.selector),
profile.label.unwrap_or_default()
));
}
let mut declarations = self.declarations.clone();
declarations
.sort_by(|left, right| declaration_sort_key(left).cmp(&declaration_sort_key(right)));
for declaration in declarations {
lines.push(format!(
"declaration\0{}\0{}\0{}",
declaration.kind.canonical_name(),
declaration.name,
declaration.reference
));
}
lines.sort();
let mut hasher = Sha256::new();
for line in lines {
hasher.update(line.as_bytes());
hasher.update(b"\n");
}
let digest = hasher.finalize();
hex_digest(&digest)
}
pub fn with_computed_digest(mut self) -> Self {
self.metadata.digest = self.computed_digest();
self
}
pub fn summary(&self) -> ConfigBundleSummary {
ConfigBundleSummary {
id: self.metadata.id.clone(),
digest: self.metadata.digest.clone(),
digest_algorithm: CONFIG_BUNDLE_DIGEST_ALGORITHM.to_string(),
revision: self.metadata.revision.clone(),
workspace_id: self.metadata.workspace_id.clone(),
created_at: self.metadata.created_at.clone(),
provenance: self.metadata.provenance.clone(),
profile_count: self.profiles.len(),
declaration_count: self.declarations.len(),
}
}
pub fn contains_profile(&self, selector: &ProfileSelector) -> bool {
self.profiles
.iter()
.any(|profile| profile.selector == *selector)
}
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ConfigBundleMetadata {
pub id: String,
pub digest: String,
pub revision: String,
pub workspace_id: String,
pub created_at: String,
pub provenance: ConfigBundleProvenance,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ConfigBundleProvenance {
pub source: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub detail: Option<String>,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ConfigProfileDescriptor {
pub selector: ProfileSelector,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub label: Option<String>,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ConfigDeclaration {
pub kind: ConfigDeclarationKind,
pub name: String,
pub reference: String,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum ConfigDeclarationKind {
SecretRef,
MountGrant,
NetworkPolicy,
ShellPolicy,
GitPolicy,
CapabilityGrant,
Unsupported,
}
impl ConfigDeclarationKind {
pub fn canonical_name(&self) -> &'static str {
match self {
Self::SecretRef => "secret_ref",
Self::MountGrant => "mount_grant",
Self::NetworkPolicy => "network_policy",
Self::ShellPolicy => "shell_policy",
Self::GitPolicy => "git_policy",
Self::CapabilityGrant => "capability_grant",
Self::Unsupported => "unsupported",
}
}
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ConfigBundleSummary {
pub id: String,
pub digest: String,
pub digest_algorithm: String,
pub revision: String,
pub workspace_id: String,
pub created_at: String,
pub provenance: ConfigBundleProvenance,
pub profile_count: usize,
pub declaration_count: usize,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ConfigBundleAvailability {
pub reference: ConfigBundleRef,
pub summary: ConfigBundleSummary,
}
pub(crate) fn validate_config_bundle(bundle: &ConfigBundle) -> Result<(), RuntimeError> {
validate_config_bundle_id(&bundle.metadata.id)?;
validate_non_empty("config bundle digest", &bundle.metadata.digest)?;
validate_digest("config bundle digest", &bundle.metadata.digest)?;
validate_non_empty("config bundle revision", &bundle.metadata.revision)?;
validate_non_empty("config bundle workspace id", &bundle.metadata.workspace_id)?;
validate_non_empty("config bundle created_at", &bundle.metadata.created_at)?;
validate_non_empty(
"config bundle provenance source",
&bundle.metadata.provenance.source,
)?;
validate_boundary_text("config bundle id", &bundle.metadata.id)?;
validate_boundary_text("config bundle revision", &bundle.metadata.revision)?;
validate_boundary_text("config bundle workspace id", &bundle.metadata.workspace_id)?;
validate_boundary_text(
"config bundle provenance source",
&bundle.metadata.provenance.source,
)?;
if let Some(detail) = &bundle.metadata.provenance.detail {
validate_boundary_text("config bundle provenance detail", detail)?;
}
let computed = bundle.computed_digest();
if computed != bundle.metadata.digest {
return Err(RuntimeError::ConfigBundleDigestMismatch {
bundle_id: bundle.metadata.id.clone(),
expected_digest: bundle.metadata.digest.clone(),
actual_digest: computed,
});
}
for profile in &bundle.profiles {
validate_profile_selector(profile.selector.clone(), Some(&bundle.metadata.id))?;
if let Some(label) = &profile.label {
validate_boundary_text("profile label", label)?;
}
}
for declaration in &bundle.declarations {
validate_non_empty("config declaration name", &declaration.name)?;
validate_boundary_text("config declaration name", &declaration.name)?;
if declaration.kind == ConfigDeclarationKind::Unsupported {
return Err(RuntimeError::UnsupportedConfigDeclaration {
bundle_id: bundle.metadata.id.clone(),
declaration_kind: declaration.kind.canonical_name().to_string(),
name: declaration.name.clone(),
});
}
validate_declaration_reference(&bundle.metadata.id, declaration)?;
}
Ok(())
}
pub(crate) fn validate_config_bundle_ref(reference: &ConfigBundleRef) -> Result<(), RuntimeError> {
validate_config_bundle_id(&reference.id)?;
validate_non_empty("config bundle reference digest", &reference.digest)?;
validate_digest("config bundle reference digest", &reference.digest)?;
Ok(())
}
pub(crate) fn validate_profile_selector(
selector: ProfileSelector,
bundle_id: Option<&str>,
) -> Result<(), RuntimeError> {
match selector {
ProfileSelector::RuntimeDefault => Ok(()),
ProfileSelector::Builtin(value) | ProfileSelector::Named(value) => {
if value.trim().is_empty() {
Err(RuntimeError::InvalidProfileSelector {
profile: value,
bundle_id: bundle_id.map(ToOwned::to_owned),
message: "profile selector must not be empty".to_string(),
})
} else {
validate_boundary_text("profile selector", &value).map_err(|err| match err {
RuntimeError::InvalidRequest(message) => RuntimeError::InvalidProfileSelector {
profile: value,
bundle_id: bundle_id.map(ToOwned::to_owned),
message,
},
other => other,
})
}
}
}
}
fn validate_non_empty(label: &'static str, value: &str) -> Result<(), RuntimeError> {
if value.trim().is_empty() {
Err(RuntimeError::InvalidRequest(format!(
"{label} must not be empty"
)))
} else {
Ok(())
}
}
fn validate_config_bundle_id(value: &str) -> Result<(), RuntimeError> {
validate_non_empty("config bundle id", value)?;
let trimmed = value.trim();
if trimmed.len() > 128 {
return Err(RuntimeError::InvalidRequest(
"config bundle id is too large".to_string(),
));
}
if trimmed != value {
return Err(RuntimeError::InvalidRequest(
"config bundle id must not contain surrounding whitespace".to_string(),
));
}
if !trimmed
.bytes()
.next()
.is_some_and(|byte| byte.is_ascii_alphanumeric())
|| !trimmed
.bytes()
.all(|byte| byte.is_ascii_alphanumeric() || matches!(byte, b'-' | b'_' | b'.' | b':'))
{
return Err(RuntimeError::InvalidRequest(
"config bundle id must be a path-safe stable identifier".to_string(),
));
}
Ok(())
}
fn validate_digest(label: &'static str, value: &str) -> Result<(), RuntimeError> {
let trimmed = value.trim();
if trimmed != value
|| trimmed.len() != 64
|| !trimmed.bytes().all(|byte| byte.is_ascii_hexdigit())
{
return Err(RuntimeError::InvalidRequest(format!(
"{label} must be a 64-character lowercase sha256 hex digest"
)));
}
if !trimmed
.bytes()
.all(|byte| byte.is_ascii_digit() || matches!(byte, b'a'..=b'f'))
{
return Err(RuntimeError::InvalidRequest(format!(
"{label} must be a 64-character lowercase sha256 hex digest"
)));
}
Ok(())
}
fn validate_declaration_reference(
bundle_id: &str,
declaration: &ConfigDeclaration,
) -> Result<(), RuntimeError> {
validate_non_empty("config declaration reference", &declaration.reference)?;
validate_ref_boundary_text("config declaration reference", &declaration.reference)?;
let allowed_prefixes: &[&str] = match declaration.kind {
ConfigDeclarationKind::SecretRef => &["secret:", "secret-ref:", "vault:", "keyring:"],
ConfigDeclarationKind::MountGrant => &["mount:", "mount-grant:"],
ConfigDeclarationKind::NetworkPolicy => &["network:", "network-policy:"],
ConfigDeclarationKind::ShellPolicy => &["shell:", "shell-policy:"],
ConfigDeclarationKind::GitPolicy => &["git:", "git-policy:"],
ConfigDeclarationKind::CapabilityGrant => &["capability:", "capability-grant:"],
ConfigDeclarationKind::Unsupported => &[],
};
if !allowed_prefixes.iter().any(|prefix| {
declaration.reference.starts_with(prefix) && declaration.reference.len() > prefix.len()
}) {
return Err(RuntimeError::UnsupportedConfigDeclaration {
bundle_id: bundle_id.to_string(),
declaration_kind: declaration.kind.canonical_name().to_string(),
name: declaration.name.clone(),
});
}
Ok(())
}
fn validate_ref_boundary_text(label: &'static str, value: &str) -> Result<(), RuntimeError> {
let trimmed = value.trim();
validate_boundary_text(label, trimmed)?;
if trimmed != value
|| trimmed.contains('/')
|| trimmed.contains('\\')
|| trimmed.contains('?')
|| trimmed.contains('&')
|| trimmed.contains('#')
|| trimmed.contains('%')
|| trimmed.contains('=')
|| trimmed.chars().any(char::is_whitespace)
|| !trimmed.bytes().all(|byte| {
byte.is_ascii_alphanumeric() || matches!(byte, b':' | b'-' | b'_' | b'.' | b'@' | b'+')
})
{
return Err(RuntimeError::InvalidRequest(format!(
"{label} must be a typed ref/grant/policy token, not a secret value or path"
)));
}
let lower = trimmed.to_ascii_lowercase();
if lower.contains(".cache")
|| lower.contains(".yoi")
|| lower.contains(".sock")
|| lower.contains("socket=")
|| lower.contains("session_path")
|| lower.contains("cache_path")
{
return Err(RuntimeError::InvalidRequest(format!(
"{label} must not contain host-local cache/session/socket material"
)));
}
Ok(())
}
fn validate_boundary_text(label: &'static str, value: &str) -> Result<(), RuntimeError> {
let trimmed = value.trim();
if trimmed.len() > 2048 {
return Err(RuntimeError::InvalidRequest(format!(
"{label} is too large"
)));
}
if trimmed.chars().any(char::is_control) {
return Err(RuntimeError::InvalidRequest(format!(
"{label} must not contain control characters"
)));
}
let lower = trimmed.to_ascii_lowercase();
if trimmed.starts_with('/')
|| trimmed.starts_with('~')
|| trimmed.contains(":\\")
|| lower.contains(".cache")
|| lower.contains(".yoi/sessions")
|| lower.contains(".yoi\\sessions")
|| lower.contains("/sessions/")
|| lower.contains("\\sessions\\")
|| lower.contains("/run/")
|| lower.contains("\\run\\")
|| lower.contains(".sock")
|| lower.contains("/sock")
|| lower.contains("\\sock")
|| lower.contains("socket=")
|| lower.contains("session_path")
|| lower.contains("cache_path")
{
return Err(RuntimeError::InvalidRequest(format!(
"{label} must be a stable ref/grant/policy declaration, not a host-local path"
)));
}
Ok(())
}
fn declaration_sort_key(declaration: &ConfigDeclaration) -> String {
format!(
"{}\0{}\0{}",
declaration.kind.canonical_name(),
declaration.name,
declaration.reference
)
}
fn profile_sort_key(selector: &ProfileSelector) -> String {
match selector {
ProfileSelector::RuntimeDefault => "runtime_default".to_string(),
ProfileSelector::Builtin(value) => format!("builtin\0{value}"),
ProfileSelector::Named(value) => format!("named\0{value}"),
}
}
fn hex_digest(bytes: &[u8]) -> String {
let mut out = String::with_capacity(bytes.len() * 2);
for byte in bytes {
out.push_str(&format!("{byte:02x}"));
}
out
}
#[cfg(test)]
mod tests {
use super::*;
fn bundle_with_declaration(reference: &str) -> ConfigBundle {
ConfigBundle {
metadata: ConfigBundleMetadata {
id: "bundle-1".to_string(),
digest: String::new(),
revision: "rev-1".to_string(),
workspace_id: "workspace-1".to_string(),
created_at: "2026-06-26T00:00:00Z".to_string(),
provenance: ConfigBundleProvenance {
source: "test".to_string(),
detail: None,
},
},
profiles: vec![ConfigProfileDescriptor {
selector: ProfileSelector::Builtin("builtin:coder".to_string()),
label: None,
}],
declarations: vec![ConfigDeclaration {
kind: ConfigDeclarationKind::SecretRef,
name: "credential".to_string(),
reference: reference.to_string(),
}],
}
.with_computed_digest()
}
#[test]
fn rejects_host_local_cache_session_socket_and_plaintext_secret_refs() {
for reference in [
".cache/yoi",
".yoi/sessions/foo.jsonl",
"pods/foo/sock",
"password=hunter2",
"hunter2-secret-value",
] {
let error = validate_config_bundle(&bundle_with_declaration(reference)).unwrap_err();
assert!(
matches!(
error,
RuntimeError::InvalidRequest(_)
| RuntimeError::UnsupportedConfigDeclaration { .. }
),
"unexpected error for {reference}: {error:?}"
);
}
}
#[test]
fn accepts_typed_secret_refs() {
validate_config_bundle(&bundle_with_declaration("secret:github-token")).unwrap();
validate_config_bundle(&bundle_with_declaration("vault:team.api-key")).unwrap();
}
#[test]
fn rejects_unsafe_bundle_ids_and_refs() {
for id in ["bundle/1", "bundle?x", "bundle&x", "bundle#x", " bundle"] {
let mut bundle = bundle_with_declaration("secret:github-token");
bundle.metadata.id = id.to_string();
bundle = bundle.with_computed_digest();
assert!(validate_config_bundle(&bundle).is_err(), "accepted id {id}");
}
assert!(
validate_config_bundle_ref(&ConfigBundleRef {
id: "bundle/1".to_string(),
digest: "0".repeat(64),
})
.is_err()
);
}
}

View File

@ -0,0 +1,21 @@
use crate::identity::WorkerRef;
use serde::{Deserialize, Serialize};
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum DiagnosticSeverity {
Info,
Warning,
Error,
}
/// Runtime diagnostic emitted by memory-runtime operations.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct RuntimeDiagnostic {
pub id: u64,
pub severity: DiagnosticSeverity,
pub code: String,
pub message: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub worker_ref: Option<WorkerRef>,
}

View File

@ -0,0 +1,104 @@
use crate::execution::WorkerExecutionResult;
use crate::identity::{RuntimeId, WorkerId};
use std::path::PathBuf;
/// Errors returned by the embedded Runtime API.
#[derive(Debug, thiserror::Error)]
pub enum RuntimeError {
#[error("runtime {runtime_id} is stopped")]
RuntimeStopped { runtime_id: RuntimeId },
#[error(
"worker {worker_id} belongs to runtime {actual_runtime_id}, not runtime {expected_runtime_id}"
)]
WrongRuntime {
expected_runtime_id: RuntimeId,
actual_runtime_id: RuntimeId,
worker_id: WorkerId,
},
#[error("cursor belongs to runtime {actual_runtime_id}, not runtime {expected_runtime_id}")]
WrongRuntimeCursor {
expected_runtime_id: RuntimeId,
actual_runtime_id: RuntimeId,
},
#[error("worker {worker_id} was not found in runtime {runtime_id}")]
WorkerNotFound {
runtime_id: RuntimeId,
worker_id: WorkerId,
},
#[error("worker {worker_id} has no execution backend: {message}")]
WorkerExecutionUnavailable {
worker_id: WorkerId,
message: String,
},
#[error("worker {worker_id} execution {operation:?} returned {outcome:?}: {message}")]
WorkerExecutionRejected {
worker_id: WorkerId,
operation: crate::execution::WorkerExecutionOperation,
outcome: crate::execution::WorkerExecutionOutcome,
message: String,
result: WorkerExecutionResult,
},
#[error("limit {requested} exceeds maximum {max}")]
LimitTooLarge { requested: usize, max: usize },
#[error("invalid request: {0}")]
InvalidRequest(String),
#[error("config bundle `{bundle_id}` was not found")]
ConfigBundleMissing { bundle_id: String },
#[error(
"config bundle `{bundle_id}` digest mismatch: expected {expected_digest}, got {actual_digest}"
)]
ConfigBundleDigestMismatch {
bundle_id: String,
expected_digest: String,
actual_digest: String,
},
#[error("invalid profile selector `{profile}` for config bundle {bundle_id:?}: {message}")]
InvalidProfileSelector {
profile: String,
bundle_id: Option<String>,
message: String,
},
#[error(
"config bundle `{bundle_id}` contains unsupported declaration `{declaration_kind}` named `{name}`"
)]
UnsupportedConfigDeclaration {
bundle_id: String,
declaration_kind: String,
name: String,
},
#[error("runtime store {operation} failed at {}: {source}", path.display())]
StoreIo {
operation: &'static str,
path: PathBuf,
#[source]
source: std::io::Error,
},
#[error("runtime store {operation} missing data at {}", path.display())]
StoreMissing {
operation: &'static str,
path: PathBuf,
},
#[error("runtime store {operation} found corrupt data at {}: {message}", path.display())]
StoreCorrupt {
operation: &'static str,
path: PathBuf,
message: String,
},
#[error("runtime state lock was poisoned")]
StatePoisoned,
}

View File

@ -0,0 +1,337 @@
use crate::catalog::CreateWorkerRequest;
use crate::error::RuntimeError;
use crate::identity::WorkerRef;
use crate::interaction::WorkerInput;
#[cfg(feature = "ws-server")]
use crate::observation::WorkerObservationEvent;
use serde::{Deserialize, Serialize};
use std::fmt;
use std::sync::Arc;
/// Coarse execution attachment visible through Worker catalog/detail responses.
///
/// This deliberately does not expose backend handles, process paths, sockets,
/// credentials, session files, or manifest paths. It only says whether Runtime
/// has an execution backend attached for the Worker.
#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum WorkerExecutionBackendKind {
#[default]
Unconnected,
Connected,
}
/// Current execution-side run state for a Worker.
#[derive(Clone, Copy, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum WorkerExecutionRunState {
#[default]
Unconnected,
Idle,
Busy,
Rejected,
Errored,
Stopped,
}
/// Execution operation that produced a result.
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum WorkerExecutionOperation {
Spawn,
Input,
Stop,
Cancel,
}
/// Typed execution result class.
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum WorkerExecutionOutcome {
Accepted,
Busy,
Rejected,
Errored,
Unsupported,
}
/// Backend result for a Worker execution operation.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkerExecutionResult {
pub operation: WorkerExecutionOperation,
pub outcome: WorkerExecutionOutcome,
pub run_state: WorkerExecutionRunState,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub message: Option<String>,
}
impl WorkerExecutionResult {
pub fn accepted(
operation: WorkerExecutionOperation,
run_state: WorkerExecutionRunState,
) -> Self {
Self {
operation,
outcome: WorkerExecutionOutcome::Accepted,
run_state,
message: None,
}
}
pub fn busy(operation: WorkerExecutionOperation, message: impl Into<String>) -> Self {
Self {
operation,
outcome: WorkerExecutionOutcome::Busy,
run_state: WorkerExecutionRunState::Busy,
message: Some(message.into()),
}
}
pub fn rejected(operation: WorkerExecutionOperation, message: impl Into<String>) -> Self {
Self {
operation,
outcome: WorkerExecutionOutcome::Rejected,
run_state: WorkerExecutionRunState::Rejected,
message: Some(message.into()),
}
}
pub fn errored(operation: WorkerExecutionOperation, message: impl Into<String>) -> Self {
Self {
operation,
outcome: WorkerExecutionOutcome::Errored,
run_state: WorkerExecutionRunState::Errored,
message: Some(message.into()),
}
}
pub fn unsupported(operation: WorkerExecutionOperation, message: impl Into<String>) -> Self {
Self {
operation,
outcome: WorkerExecutionOutcome::Unsupported,
run_state: WorkerExecutionRunState::Rejected,
message: Some(message.into()),
}
}
pub fn is_accepted(&self) -> bool {
self.outcome == WorkerExecutionOutcome::Accepted
}
pub fn message_or_default(&self) -> String {
self.message
.clone()
.unwrap_or_else(|| format!("{:?} {:?}", self.operation, self.outcome))
}
}
/// Execution status surfaced in Worker summary/detail responses.
#[derive(Clone, Debug, Default, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkerExecutionStatus {
pub backend: WorkerExecutionBackendKind,
pub run_state: WorkerExecutionRunState,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub last_result: Option<WorkerExecutionResult>,
}
impl WorkerExecutionStatus {
pub fn unconnected() -> Self {
Self::default()
}
pub fn connected(run_state: WorkerExecutionRunState) -> Self {
Self {
backend: WorkerExecutionBackendKind::Connected,
run_state,
last_result: None,
}
}
pub fn with_result(mut self, result: WorkerExecutionResult) -> Self {
self.run_state = result.run_state;
self.last_result = Some(result);
self
}
}
/// Opaque per-Worker execution handle returned by a backend.
///
/// The handle is a typed token for routing calls back into the same backend. It
/// intentionally contains no socket path, process id, credential, manifest path,
/// or session path.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkerExecutionHandle {
worker_ref: WorkerRef,
backend_id: String,
}
impl WorkerExecutionHandle {
pub fn new(worker_ref: WorkerRef, backend_id: impl Into<String>) -> Self {
Self {
worker_ref,
backend_id: backend_id.into(),
}
}
pub fn worker_ref(&self) -> &WorkerRef {
&self.worker_ref
}
pub fn backend_id(&self) -> &str {
&self.backend_id
}
}
/// Runtime hooks available to an execution backend for one Worker.
#[derive(Clone)]
pub struct WorkerExecutionContext {
worker_ref: WorkerRef,
#[cfg(feature = "ws-server")]
observation_publisher: Arc<
dyn Fn(WorkerRef, protocol::Event) -> Result<WorkerObservationEvent, RuntimeError>
+ Send
+ Sync,
>,
}
impl WorkerExecutionContext {
#[cfg(feature = "ws-server")]
pub(crate) fn new(
worker_ref: WorkerRef,
observation_publisher: Arc<
dyn Fn(WorkerRef, protocol::Event) -> Result<WorkerObservationEvent, RuntimeError>
+ Send
+ Sync,
>,
) -> Self {
Self {
worker_ref,
observation_publisher,
}
}
#[cfg(not(feature = "ws-server"))]
pub(crate) fn new(worker_ref: WorkerRef) -> Self {
Self { worker_ref }
}
pub fn worker_ref(&self) -> &WorkerRef {
&self.worker_ref
}
/// Publish a protocol event into the Runtime observation bus.
#[cfg(feature = "ws-server")]
pub fn publish_protocol_event(
&self,
payload: protocol::Event,
) -> Result<WorkerObservationEvent, RuntimeError> {
(self.observation_publisher)(self.worker_ref.clone(), payload)
}
}
impl fmt::Debug for WorkerExecutionContext {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
f.debug_struct("WorkerExecutionContext")
.field("worker_ref", &self.worker_ref)
.finish_non_exhaustive()
}
}
/// Spawn/initialization request passed to an execution backend.
#[derive(Clone, Debug)]
pub struct WorkerExecutionSpawnRequest {
pub worker_ref: WorkerRef,
pub request: CreateWorkerRequest,
pub context: WorkerExecutionContext,
}
/// Result of backend Worker spawn/initialization.
#[derive(Clone, Debug, PartialEq, Eq)]
pub enum WorkerExecutionSpawnResult {
Connected {
handle: WorkerExecutionHandle,
run_state: WorkerExecutionRunState,
},
Rejected(WorkerExecutionResult),
Errored(WorkerExecutionResult),
}
/// Backend boundary for Worker execution.
///
/// Runtime owns Worker catalog, transcript, observation, and lifecycle state. A
/// backend owns concrete execution. The default Runtime has no backend, so input
/// to those Workers is rejected instead of producing providerless responses.
pub trait WorkerExecutionBackend: Send + Sync + 'static {
fn backend_id(&self) -> &str;
fn spawn_worker(&self, request: WorkerExecutionSpawnRequest) -> WorkerExecutionSpawnResult;
fn dispatch_input(
&self,
handle: &WorkerExecutionHandle,
input: WorkerInput,
) -> WorkerExecutionResult;
fn stop_worker(&self, _handle: &WorkerExecutionHandle) -> WorkerExecutionResult {
WorkerExecutionResult::unsupported(
WorkerExecutionOperation::Stop,
"execution backend does not support stopping workers",
)
}
fn cancel_worker(&self, _handle: &WorkerExecutionHandle) -> WorkerExecutionResult {
WorkerExecutionResult::unsupported(
WorkerExecutionOperation::Cancel,
"execution backend does not support cancelling workers",
)
}
}
#[derive(Clone)]
pub(crate) struct WorkerExecutionBackendRef {
id: String,
backend: Arc<dyn WorkerExecutionBackend>,
}
impl WorkerExecutionBackendRef {
pub(crate) fn new(backend: Arc<dyn WorkerExecutionBackend>) -> Result<Self, RuntimeError> {
let id = backend.backend_id().trim().to_string();
if id.is_empty() {
return Err(RuntimeError::InvalidRequest(
"execution backend id must not be empty".to_string(),
));
}
Ok(Self { id, backend })
}
pub(crate) fn spawn_worker(
&self,
request: WorkerExecutionSpawnRequest,
) -> WorkerExecutionSpawnResult {
self.backend.spawn_worker(request)
}
pub(crate) fn dispatch_input(
&self,
handle: &WorkerExecutionHandle,
input: WorkerInput,
) -> WorkerExecutionResult {
self.backend.dispatch_input(handle, input)
}
pub(crate) fn stop_worker(&self, handle: &WorkerExecutionHandle) -> WorkerExecutionResult {
self.backend.stop_worker(handle)
}
pub(crate) fn cancel_worker(&self, handle: &WorkerExecutionHandle) -> WorkerExecutionResult {
self.backend.cancel_worker(handle)
}
}
impl fmt::Debug for WorkerExecutionBackendRef {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
f.debug_struct("WorkerExecutionBackendRef")
.field("id", &self.id)
.finish_non_exhaustive()
}
}

View File

@ -0,0 +1,761 @@
use crate::catalog::{CreateWorkerRequest, WorkerStatus};
use crate::config_bundle::ConfigBundle;
use crate::diagnostics::RuntimeDiagnostic;
use crate::error::RuntimeError;
use crate::identity::{RuntimeId, WorkerId, WorkerRef};
use crate::management::{RuntimeBackendKind, RuntimeLimits, RuntimeStatus};
use crate::observation::{
EventCursor, RuntimeEvent, RuntimeEventBatch, TranscriptEntry, TranscriptProjection,
TranscriptQuery,
};
use serde::{Deserialize, Serialize};
use std::collections::BTreeMap;
use std::fs::{self, File, OpenOptions};
use std::io::{BufRead, BufReader, Write};
use std::path::{Path, PathBuf};
use std::sync::atomic::{AtomicU64, Ordering};
const SCHEMA_VERSION: u32 = 1;
const RUNTIMES_DIR: &str = "runtimes";
const RUNTIME_FILE: &str = "runtime.json";
const EVENTS_FILE: &str = "events.jsonl";
const WORKERS_DIR: &str = "workers";
const WORKER_FILE: &str = "worker.json";
const TRANSCRIPT_FILE: &str = "transcript.jsonl";
static NEXT_TMP_SEQUENCE: AtomicU64 = AtomicU64::new(1);
/// Options for constructing a filesystem-backed Runtime store.
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct FsRuntimeStoreOptions {
/// Root directory containing all Runtime-scoped store data.
pub root: PathBuf,
pub runtime_id: Option<RuntimeId>,
pub display_name: Option<String>,
pub limits: RuntimeLimits,
}
impl FsRuntimeStoreOptions {
pub fn new(root: impl Into<PathBuf>) -> Self {
Self {
root: root.into(),
runtime_id: None,
display_name: None,
limits: RuntimeLimits::default(),
}
}
}
/// Filesystem persistence boundary for Worker Runtime state.
///
/// Authority is the typed `runtime_id + worker_id` pair. Those ids are encoded
/// into path components only after validation; legacy pod paths, socket paths,
/// and session paths are deliberately not part of the layout or lookup API.
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct FsRuntimeStore {
root: PathBuf,
runtime_id: RuntimeId,
runtime_dir: PathBuf,
}
impl FsRuntimeStore {
pub fn root(&self) -> &Path {
&self.root
}
pub fn runtime_id(&self) -> &RuntimeId {
&self.runtime_id
}
pub fn runtime_dir(&self) -> &Path {
&self.runtime_dir
}
/// Read persisted Runtime events directly from the event log with the same
/// bounded cursor semantics as [`crate::Runtime::read_events`].
pub fn read_events(
&self,
cursor: &EventCursor,
limit: usize,
max_limit: usize,
) -> Result<RuntimeEventBatch, RuntimeError> {
if cursor.runtime_id != self.runtime_id {
return Err(RuntimeError::WrongRuntimeCursor {
expected_runtime_id: self.runtime_id.clone(),
actual_runtime_id: cursor.runtime_id.clone(),
});
}
if limit > max_limit {
return Err(RuntimeError::LimitTooLarge {
requested: limit,
max: max_limit,
});
}
let events = read_json_lines::<RuntimeEvent>(&self.events_path(), "read events")?;
let mut selected = Vec::new();
for event in events
.iter()
.filter(|event| event.id >= cursor.next_event_id)
.take(limit)
{
selected.push(event.clone());
}
let next_event_id = selected
.last()
.map(|event| event.id + 1)
.unwrap_or(cursor.next_event_id);
let has_more = events.iter().any(|event| event.id >= next_event_id);
Ok(RuntimeEventBatch {
runtime_id: self.runtime_id.clone(),
cursor: EventCursor {
runtime_id: self.runtime_id.clone(),
next_event_id,
},
events: selected,
has_more,
})
}
/// Read a persisted Worker transcript directly from its Worker-scoped log.
pub fn read_transcript(
&self,
worker_ref: &WorkerRef,
query: TranscriptQuery,
max_limit: usize,
) -> Result<TranscriptProjection, RuntimeError> {
self.ensure_worker_ref(worker_ref)?;
if query.limit > max_limit {
return Err(RuntimeError::LimitTooLarge {
requested: query.limit,
max: max_limit,
});
}
let path = self.transcript_path(&worker_ref.worker_id);
let entries = read_json_lines::<TranscriptEntry>(&path, "read transcript")?;
let total_items = entries.len();
let end = query.start.saturating_add(query.limit).min(total_items);
let items = if query.start >= total_items {
Vec::new()
} else {
entries[query.start..end].to_vec()
};
let next_start = (end < total_items).then_some(end);
Ok(TranscriptProjection {
worker_ref: worker_ref.clone(),
start: query.start,
limit: query.limit,
total_items,
items,
next_start,
})
}
pub(crate) fn open_or_create(
root: PathBuf,
runtime_id: RuntimeId,
) -> Result<OpenedFsRuntimeStore, RuntimeError> {
fs::create_dir_all(root.join(RUNTIMES_DIR)).map_err(|source| RuntimeError::StoreIo {
operation: "create store root",
path: root.join(RUNTIMES_DIR),
source,
})?;
let runtime_dir = runtime_dir(&root, &runtime_id);
let existed = runtime_dir.exists();
if existed && !runtime_dir.is_dir() {
return Err(RuntimeError::StoreCorrupt {
operation: "open runtime store",
path: runtime_dir,
message: "runtime path exists but is not a directory".to_string(),
});
}
fs::create_dir_all(runtime_dir.join(WORKERS_DIR)).map_err(|source| {
RuntimeError::StoreIo {
operation: "create runtime store",
path: runtime_dir.join(WORKERS_DIR),
source,
}
})?;
let store = Self {
root,
runtime_id,
runtime_dir,
};
let state = if existed {
Some(store.load_runtime_state()?)
} else {
None
};
Ok(OpenedFsRuntimeStore { store, state })
}
pub(crate) fn write_runtime_snapshot(
&self,
state: &PersistedRuntimeState,
) -> Result<(), RuntimeError> {
let snapshot = RuntimeSnapshot::from_persisted(state);
atomic_write_json(&self.runtime_path(), &snapshot, "write runtime snapshot")
}
pub(crate) fn write_worker_snapshot(
&self,
worker: &PersistedWorkerRecord,
) -> Result<(), RuntimeError> {
self.ensure_worker_ref(&worker.worker_ref)?;
let worker_dir = self.worker_dir(&worker.worker_id);
fs::create_dir_all(&worker_dir).map_err(|source| RuntimeError::StoreIo {
operation: "create worker store",
path: worker_dir.clone(),
source,
})?;
atomic_write_json(
&worker_dir.join(WORKER_FILE),
&WorkerSnapshot::from_persisted(worker),
"write worker snapshot",
)?;
ensure_file_exists(&worker_dir.join(TRANSCRIPT_FILE), "create transcript log")
}
pub(crate) fn append_event(&self, event: &RuntimeEvent) -> Result<(), RuntimeError> {
if let Some(worker_ref) = &event.worker_ref {
self.ensure_worker_ref(worker_ref)?;
}
append_json_line(&self.events_path(), event, "append event")
}
pub(crate) fn append_transcript_entry(
&self,
entry: &TranscriptEntry,
) -> Result<(), RuntimeError> {
self.ensure_worker_ref(&entry.worker_ref)?;
append_json_line(
&self.transcript_path(&entry.worker_ref.worker_id),
entry,
"append transcript",
)
}
pub(crate) fn load_runtime_state(&self) -> Result<PersistedRuntimeState, RuntimeError> {
let runtime_path = self.runtime_path();
let snapshot: RuntimeSnapshot = read_json(&runtime_path, "read runtime snapshot")?;
snapshot.validate(&self.runtime_id, &runtime_path)?;
let events = read_json_lines::<RuntimeEvent>(&self.events_path(), "read events")?;
let workers_dir = self.runtime_dir.join(WORKERS_DIR);
if !workers_dir.exists() {
return Err(RuntimeError::StoreMissing {
operation: "read workers",
path: workers_dir,
});
}
if !workers_dir.is_dir() {
return Err(RuntimeError::StoreCorrupt {
operation: "read workers",
path: workers_dir,
message: "workers path exists but is not a directory".to_string(),
});
}
let mut workers = BTreeMap::new();
let mut worker_dirs = fs::read_dir(&workers_dir)
.map_err(|source| RuntimeError::StoreIo {
operation: "read workers",
path: workers_dir.clone(),
source,
})?
.collect::<Result<Vec<_>, _>>()
.map_err(|source| RuntimeError::StoreIo {
operation: "read workers",
path: workers_dir.clone(),
source,
})?;
worker_dirs.sort_by_key(|entry| entry.path());
for entry in worker_dirs {
let path = entry.path();
if !path.is_dir() {
return Err(RuntimeError::StoreCorrupt {
operation: "read worker",
path,
message: "worker path exists but is not a directory".to_string(),
});
}
let worker_snapshot_path = path.join(WORKER_FILE);
let worker_snapshot: WorkerSnapshot =
read_json(&worker_snapshot_path, "read worker snapshot")?;
worker_snapshot.validate(&self.runtime_id, &worker_snapshot_path)?;
let transcript =
read_json_lines::<TranscriptEntry>(&path.join(TRANSCRIPT_FILE), "read transcript")?;
for entry in &transcript {
self.ensure_worker_ref(&entry.worker_ref)?;
if entry.worker_ref.worker_id != worker_snapshot.worker_id {
return Err(RuntimeError::StoreCorrupt {
operation: "read transcript",
path: path.join(TRANSCRIPT_FILE),
message: format!(
"transcript entry belongs to worker {}, expected {}",
entry.worker_ref.worker_id, worker_snapshot.worker_id
),
});
}
}
let worker = worker_snapshot.into_persisted(transcript);
if workers.insert(worker.worker_id.clone(), worker).is_some() {
return Err(RuntimeError::StoreCorrupt {
operation: "read workers",
path: workers_dir.clone(),
message: "duplicate worker id in store".to_string(),
});
}
}
Ok(snapshot.into_persisted(events, workers))
}
fn ensure_worker_ref(&self, worker_ref: &WorkerRef) -> Result<(), RuntimeError> {
if worker_ref.runtime_id == self.runtime_id {
Ok(())
} else {
Err(RuntimeError::WrongRuntime {
expected_runtime_id: self.runtime_id.clone(),
actual_runtime_id: worker_ref.runtime_id.clone(),
worker_id: worker_ref.worker_id.clone(),
})
}
}
fn runtime_path(&self) -> PathBuf {
self.runtime_dir.join(RUNTIME_FILE)
}
fn events_path(&self) -> PathBuf {
self.runtime_dir.join(EVENTS_FILE)
}
fn worker_dir(&self, worker_id: &WorkerId) -> PathBuf {
self.runtime_dir
.join(WORKERS_DIR)
.join(encoded_component(worker_id.as_str()))
}
fn transcript_path(&self, worker_id: &WorkerId) -> PathBuf {
self.worker_dir(worker_id).join(TRANSCRIPT_FILE)
}
}
#[derive(Debug)]
pub(crate) struct OpenedFsRuntimeStore {
pub(crate) store: FsRuntimeStore,
pub(crate) state: Option<PersistedRuntimeState>,
}
#[derive(Clone, Debug)]
pub(crate) struct PersistedRuntimeState {
pub(crate) runtime_id: RuntimeId,
pub(crate) display_name: Option<String>,
pub(crate) status: RuntimeStatus,
pub(crate) limits: RuntimeLimits,
pub(crate) next_worker_sequence: u64,
pub(crate) next_event_id: u64,
pub(crate) next_diagnostic_id: u64,
pub(crate) workers: BTreeMap<WorkerId, PersistedWorkerRecord>,
pub(crate) config_bundles: BTreeMap<String, ConfigBundle>,
pub(crate) events: Vec<RuntimeEvent>,
pub(crate) diagnostics: Vec<RuntimeDiagnostic>,
}
#[derive(Clone, Debug)]
pub(crate) struct PersistedWorkerRecord {
pub(crate) worker_ref: WorkerRef,
pub(crate) worker_id: WorkerId,
pub(crate) status: WorkerStatus,
pub(crate) request: CreateWorkerRequest,
pub(crate) transcript: Vec<TranscriptEntry>,
pub(crate) next_transcript_sequence: u64,
pub(crate) last_event_id: u64,
}
#[derive(Clone, Debug, Serialize, Deserialize)]
struct RuntimeSnapshot {
schema_version: u32,
runtime_id: RuntimeId,
display_name: Option<String>,
backend: RuntimeBackendKind,
status: RuntimeStatus,
limits: RuntimeLimits,
next_worker_sequence: u64,
next_event_id: u64,
next_diagnostic_id: u64,
#[serde(default)]
config_bundles: BTreeMap<String, ConfigBundle>,
diagnostics: Vec<RuntimeDiagnostic>,
}
impl RuntimeSnapshot {
fn from_persisted(state: &PersistedRuntimeState) -> Self {
Self {
schema_version: SCHEMA_VERSION,
runtime_id: state.runtime_id.clone(),
display_name: state.display_name.clone(),
backend: RuntimeBackendKind::FsStore,
status: state.status,
limits: state.limits.clone(),
next_worker_sequence: state.next_worker_sequence,
next_event_id: state.next_event_id,
next_diagnostic_id: state.next_diagnostic_id,
config_bundles: state.config_bundles.clone(),
diagnostics: state.diagnostics.clone(),
}
}
fn validate(&self, expected_runtime_id: &RuntimeId, path: &Path) -> Result<(), RuntimeError> {
if self.schema_version != SCHEMA_VERSION {
return Err(RuntimeError::StoreCorrupt {
operation: "read runtime snapshot",
path: path.to_path_buf(),
message: format!(
"unsupported schema version {}, expected {}",
self.schema_version, SCHEMA_VERSION
),
});
}
if &self.runtime_id != expected_runtime_id {
return Err(RuntimeError::StoreCorrupt {
operation: "read runtime snapshot",
path: path.to_path_buf(),
message: format!(
"runtime snapshot id {} does not match requested runtime {}",
self.runtime_id, expected_runtime_id
),
});
}
if self.backend != RuntimeBackendKind::FsStore {
return Err(RuntimeError::StoreCorrupt {
operation: "read runtime snapshot",
path: path.to_path_buf(),
message: format!("runtime snapshot backend is {:?}", self.backend),
});
}
Ok(())
}
fn into_persisted(
self,
events: Vec<RuntimeEvent>,
workers: BTreeMap<WorkerId, PersistedWorkerRecord>,
) -> PersistedRuntimeState {
PersistedRuntimeState {
runtime_id: self.runtime_id,
display_name: self.display_name,
status: self.status,
limits: self.limits,
next_worker_sequence: self.next_worker_sequence,
next_event_id: self.next_event_id,
next_diagnostic_id: self.next_diagnostic_id,
workers,
config_bundles: self.config_bundles,
events,
diagnostics: self.diagnostics,
}
}
}
#[derive(Clone, Debug, Serialize, Deserialize)]
struct WorkerSnapshot {
schema_version: u32,
worker_ref: WorkerRef,
worker_id: WorkerId,
status: WorkerStatus,
request: CreateWorkerRequest,
next_transcript_sequence: u64,
last_event_id: u64,
}
impl WorkerSnapshot {
fn from_persisted(worker: &PersistedWorkerRecord) -> Self {
Self {
schema_version: SCHEMA_VERSION,
worker_ref: worker.worker_ref.clone(),
worker_id: worker.worker_id.clone(),
status: worker.status,
request: worker.request.clone(),
next_transcript_sequence: worker.next_transcript_sequence,
last_event_id: worker.last_event_id,
}
}
fn validate(&self, expected_runtime_id: &RuntimeId, path: &Path) -> Result<(), RuntimeError> {
if self.schema_version != SCHEMA_VERSION {
return Err(RuntimeError::StoreCorrupt {
operation: "read worker snapshot",
path: path.to_path_buf(),
message: format!(
"unsupported schema version {}, expected {}",
self.schema_version, SCHEMA_VERSION
),
});
}
if self.worker_ref.runtime_id != *expected_runtime_id {
return Err(RuntimeError::StoreCorrupt {
operation: "read worker snapshot",
path: path.to_path_buf(),
message: format!(
"worker belongs to runtime {}, expected {}",
self.worker_ref.runtime_id, expected_runtime_id
),
});
}
if self.worker_ref.worker_id != self.worker_id {
return Err(RuntimeError::StoreCorrupt {
operation: "read worker snapshot",
path: path.to_path_buf(),
message: format!(
"worker_ref id {} does not match worker_id {}",
self.worker_ref.worker_id, self.worker_id
),
});
}
Ok(())
}
fn into_persisted(self, transcript: Vec<TranscriptEntry>) -> PersistedWorkerRecord {
PersistedWorkerRecord {
worker_ref: self.worker_ref,
worker_id: self.worker_id,
status: self.status,
request: self.request,
transcript,
next_transcript_sequence: self.next_transcript_sequence,
last_event_id: self.last_event_id,
}
}
}
fn runtime_dir(root: &Path, runtime_id: &RuntimeId) -> PathBuf {
root.join(RUNTIMES_DIR)
.join(encoded_component(runtime_id.as_str()))
}
fn encoded_component(value: &str) -> String {
let mut encoded = String::with_capacity(3 + value.len() * 2);
encoded.push_str("id-");
for byte in value.as_bytes() {
encoded.push(hex_digit(byte >> 4));
encoded.push(hex_digit(byte & 0x0f));
}
encoded
}
fn hex_digit(value: u8) -> char {
match value {
0..=9 => (b'0' + value) as char,
10..=15 => (b'a' + (value - 10)) as char,
_ => unreachable!("hex digit nybble is always <= 15"),
}
}
fn read_json<T>(path: &Path, operation: &'static str) -> Result<T, RuntimeError>
where
T: for<'de> Deserialize<'de>,
{
let file = File::open(path).map_err(|source| match source.kind() {
std::io::ErrorKind::NotFound => RuntimeError::StoreMissing {
operation,
path: path.to_path_buf(),
},
_ => RuntimeError::StoreIo {
operation,
path: path.to_path_buf(),
source,
},
})?;
serde_json::from_reader(BufReader::new(file)).map_err(|source| RuntimeError::StoreCorrupt {
operation,
path: path.to_path_buf(),
message: source.to_string(),
})
}
fn read_json_lines<T>(path: &Path, operation: &'static str) -> Result<Vec<T>, RuntimeError>
where
T: for<'de> Deserialize<'de>,
{
let file = File::open(path).map_err(|source| match source.kind() {
std::io::ErrorKind::NotFound => RuntimeError::StoreMissing {
operation,
path: path.to_path_buf(),
},
_ => RuntimeError::StoreIo {
operation,
path: path.to_path_buf(),
source,
},
})?;
let reader = BufReader::new(file);
let mut items = Vec::new();
for (index, line) in reader.lines().enumerate() {
let line = line.map_err(|source| RuntimeError::StoreIo {
operation,
path: path.to_path_buf(),
source,
})?;
if line.trim().is_empty() {
continue;
}
let item = serde_json::from_str(&line).map_err(|source| RuntimeError::StoreCorrupt {
operation,
path: path.to_path_buf(),
message: format!("line {}: {source}", index + 1),
})?;
items.push(item);
}
Ok(items)
}
fn atomic_write_json<T>(path: &Path, value: &T, operation: &'static str) -> Result<(), RuntimeError>
where
T: Serialize,
{
let parent = path.parent().ok_or_else(|| RuntimeError::StoreCorrupt {
operation,
path: path.to_path_buf(),
message: "path has no parent directory".to_string(),
})?;
fs::create_dir_all(parent).map_err(|source| RuntimeError::StoreIo {
operation,
path: parent.to_path_buf(),
source,
})?;
let tmp_path = tmp_path_for(path);
let write_result = (|| {
let mut file = OpenOptions::new()
.write(true)
.create_new(true)
.open(&tmp_path)
.map_err(|source| RuntimeError::StoreIo {
operation,
path: tmp_path.clone(),
source,
})?;
serde_json::to_writer_pretty(&mut file, value).map_err(|source| {
RuntimeError::StoreCorrupt {
operation,
path: tmp_path.clone(),
message: format!("serialize json: {source}"),
}
})?;
file.write_all(b"\n")
.map_err(|source| RuntimeError::StoreIo {
operation,
path: tmp_path.clone(),
source,
})?;
file.sync_all().map_err(|source| RuntimeError::StoreIo {
operation,
path: tmp_path.clone(),
source,
})?;
drop(file);
fs::rename(&tmp_path, path).map_err(|source| RuntimeError::StoreIo {
operation,
path: path.to_path_buf(),
source,
})?;
sync_directory(parent, operation)
})();
if write_result.is_err() {
let _ = fs::remove_file(&tmp_path);
}
write_result
}
fn append_json_line<T>(path: &Path, value: &T, operation: &'static str) -> Result<(), RuntimeError>
where
T: Serialize,
{
let parent = path.parent().ok_or_else(|| RuntimeError::StoreCorrupt {
operation,
path: path.to_path_buf(),
message: "path has no parent directory".to_string(),
})?;
fs::create_dir_all(parent).map_err(|source| RuntimeError::StoreIo {
operation,
path: parent.to_path_buf(),
source,
})?;
let mut file = OpenOptions::new()
.create(true)
.append(true)
.open(path)
.map_err(|source| RuntimeError::StoreIo {
operation,
path: path.to_path_buf(),
source,
})?;
serde_json::to_writer(&mut file, value).map_err(|source| RuntimeError::StoreCorrupt {
operation,
path: path.to_path_buf(),
message: format!("serialize json: {source}"),
})?;
file.write_all(b"\n")
.and_then(|()| file.flush())
.and_then(|()| file.sync_all())
.map_err(|source| RuntimeError::StoreIo {
operation,
path: path.to_path_buf(),
source,
})
}
fn ensure_file_exists(path: &Path, operation: &'static str) -> Result<(), RuntimeError> {
let parent = path.parent().ok_or_else(|| RuntimeError::StoreCorrupt {
operation,
path: path.to_path_buf(),
message: "path has no parent directory".to_string(),
})?;
fs::create_dir_all(parent).map_err(|source| RuntimeError::StoreIo {
operation,
path: parent.to_path_buf(),
source,
})?;
OpenOptions::new()
.create(true)
.append(true)
.open(path)
.and_then(|file| file.sync_all())
.map_err(|source| RuntimeError::StoreIo {
operation,
path: path.to_path_buf(),
source,
})
}
fn tmp_path_for(path: &Path) -> PathBuf {
let sequence = NEXT_TMP_SEQUENCE.fetch_add(1, Ordering::Relaxed);
let file_name = path
.file_name()
.and_then(|name| name.to_str())
.unwrap_or("store");
path.with_file_name(format!(
".{file_name}.tmp-{}-{sequence}",
std::process::id()
))
}
fn sync_directory(path: &Path, operation: &'static str) -> Result<(), RuntimeError> {
File::open(path)
.and_then(|file| file.sync_all())
.map_err(|source| RuntimeError::StoreIo {
operation,
path: path.to_path_buf(),
source,
})
}

File diff suppressed because it is too large Load Diff

View File

@ -0,0 +1,82 @@
use serde::{Deserialize, Serialize};
use std::fmt;
/// Public Runtime identity.
///
/// This is the first half of Worker authority. Runtime APIs that operate on a
/// Worker require this id alongside a [`WorkerId`]; socket paths, session paths,
/// and display names are deliberately not authority.
#[derive(Clone, Debug, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]
#[serde(transparent)]
pub struct RuntimeId(String);
impl RuntimeId {
pub fn new(value: impl Into<String>) -> Option<Self> {
let value = value.into();
if value.trim().is_empty() {
None
} else {
Some(Self(value))
}
}
pub(crate) fn generated(sequence: u64) -> Self {
Self(format!("runtime-mem-{sequence:016x}"))
}
pub fn as_str(&self) -> &str {
&self.0
}
}
impl fmt::Display for RuntimeId {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
self.0.fmt(f)
}
}
/// Runtime-local Worker identity.
#[derive(Clone, Debug, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]
#[serde(transparent)]
pub struct WorkerId(String);
impl WorkerId {
pub fn new(value: impl Into<String>) -> Option<Self> {
let value = value.into();
if value.trim().is_empty() {
None
} else {
Some(Self(value))
}
}
pub(crate) fn generated(sequence: u64) -> Self {
Self(format!("worker-{sequence:08x}"))
}
pub fn as_str(&self) -> &str {
&self.0
}
}
impl fmt::Display for WorkerId {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
self.0.fmt(f)
}
}
/// Complete public authority reference for Worker operations.
#[derive(Clone, Debug, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]
pub struct WorkerRef {
pub runtime_id: RuntimeId,
pub worker_id: WorkerId,
}
impl WorkerRef {
pub fn new(runtime_id: RuntimeId, worker_id: WorkerId) -> Self {
Self {
runtime_id,
worker_id,
}
}
}

View File

@ -0,0 +1,44 @@
use crate::catalog::WorkerStatus;
use crate::identity::WorkerRef;
use serde::{Deserialize, Serialize};
/// Input kind accepted by the embedded interaction API.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum WorkerInputKind {
User,
System,
}
/// Worker input request. v0 stores the input in an in-memory transcript and
/// does not execute providers/tools.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkerInput {
pub kind: WorkerInputKind,
pub content: String,
}
impl WorkerInput {
pub fn user(content: impl Into<String>) -> Self {
Self {
kind: WorkerInputKind::User,
content: content.into(),
}
}
pub fn system(content: impl Into<String>) -> Self {
Self {
kind: WorkerInputKind::System,
content: content.into(),
}
}
}
/// Acknowledgement returned after input is accepted into the in-memory Worker.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct WorkerInteractionAck {
pub worker_ref: WorkerRef,
pub status: WorkerStatus,
pub transcript_sequence: u64,
pub event_id: u64,
}

View File

@ -0,0 +1,27 @@
//! Embedded Runtime domain API for Worker management.
//!
//! `worker-runtime` keeps its core independent from HTTP/WebSocket servers,
//! provider execution, and the existing Worker host. Filesystem persistence is
//! available only through the optional `fs-store` feature, and the minimal REST
//! process adapter is available only through the optional `http-server` feature.
//! The crate defines the in-process Runtime authority surface that higher layers
//! can later adapt into registries or backend APIs.
pub mod catalog;
pub mod config_bundle;
pub mod diagnostics;
pub mod error;
pub mod execution;
#[cfg(feature = "fs-store")]
pub mod fs_store;
#[cfg(feature = "http-server")]
pub mod http_server;
pub mod identity;
pub mod interaction;
pub mod management;
pub mod observation;
mod runtime;
#[cfg(feature = "fs-store")]
pub use fs_store::{FsRuntimeStore, FsRuntimeStoreOptions};
pub use runtime::Runtime;

View File

@ -0,0 +1,346 @@
//! Minimal Runtime REST process wrapper.
//!
//! This binary is available only when the `http-server` feature is enabled. It
//! starts a Runtime-local command API intended for a trusted backend/proxy;
//! browsers must not connect to this Runtime process directly.
use std::collections::VecDeque;
use std::env;
use std::error::Error;
use std::fmt;
use std::net::SocketAddr;
use std::path::PathBuf;
use std::process::ExitCode;
use worker_runtime::http_server::{
RuntimeHttpServer, RuntimeHttpServerConfig, RuntimeHttpServerError, RuntimeHttpStoreSelection,
};
use worker_runtime::identity::RuntimeId;
fn main() -> ExitCode {
match run() {
Ok(()) => ExitCode::SUCCESS,
Err(error) => {
eprintln!("worker-runtime-rest-server: {error}");
if let ProcessError::Usage(_) = error {
eprintln!();
eprintln!("{}", usage());
ExitCode::from(2)
} else {
ExitCode::FAILURE
}
}
}
}
fn run() -> Result<(), ProcessError> {
let Some(config) = parse_args(env::args().skip(1))? else {
println!("{}", usage());
return Ok(());
};
let runtime = tokio::runtime::Builder::new_current_thread()
.enable_io()
.build()?;
runtime.block_on(async move {
let server = RuntimeHttpServer::bind(config).await?;
let local_addr = server.local_addr()?;
eprintln!(
"worker-runtime REST server listening on {local_addr}; intended client is a trusted backend/proxy, not a browser"
);
server.serve().await
})?;
Ok(())
}
fn parse_args<I, S>(args: I) -> Result<Option<RuntimeHttpServerConfig>, ProcessError>
where
I: IntoIterator<Item = S>,
S: Into<String>,
{
let mut config = RuntimeHttpServerConfig::default();
let mut store = StoreArg::Memory;
let mut args = args.into_iter().map(Into::into).collect::<VecDeque<_>>();
while let Some(arg) = args.pop_front() {
let (flag, inline_value) = split_flag_value(arg)?;
match flag.as_str() {
"--help" | "-h" => return Ok(None),
"--bind" => {
let value = take_value(&flag, inline_value, &mut args)?;
config.bind_addr = value.parse::<SocketAddr>().map_err(|error| {
ProcessError::usage(format!("invalid --bind socket address `{value}`: {error}"))
})?;
}
"--runtime-id" => {
let value = take_value(&flag, inline_value, &mut args)?;
config.runtime_id = Some(RuntimeId::new(value).ok_or_else(|| {
ProcessError::usage("--runtime-id must not be empty".to_string())
})?);
}
"--display-name" => {
config.display_name = Some(take_value(&flag, inline_value, &mut args)?);
}
"--store" => {
let value = take_value(&flag, inline_value, &mut args)?;
store = match value.as_str() {
"memory" => StoreArg::Memory,
"fs" | "fs-store" => StoreArg::Fs { root: None },
_ => {
return Err(ProcessError::usage(format!(
"unsupported --store `{value}`; expected `memory` or `fs`"
)));
}
};
}
"--fs-root" => {
let value = take_value(&flag, inline_value, &mut args)?;
store = StoreArg::Fs {
root: Some(PathBuf::from(value)),
};
}
"--local-token" => {
let value = take_value(&flag, inline_value, &mut args)?;
if value.is_empty() {
return Err(ProcessError::usage(
"--local-token must not be empty when provided".to_string(),
));
}
config.local_token = Some(value);
}
"--local-token-env" => {
let name = take_value(&flag, inline_value, &mut args)?;
let value = env::var(&name).map_err(|error| {
ProcessError::usage(format!(
"failed to read --local-token-env `{name}`: {error}"
))
})?;
if value.is_empty() {
return Err(ProcessError::usage(format!(
"--local-token-env `{name}` resolved to an empty value"
)));
}
config.local_token = Some(value);
}
"--max-transcript-projection-items" => {
config.limits.max_transcript_projection_items =
parse_usize_flag(&flag, take_value(&flag, inline_value, &mut args)?)?;
}
"--max-event-batch-items" => {
config.limits.max_event_batch_items =
parse_usize_flag(&flag, take_value(&flag, inline_value, &mut args)?)?;
}
_ => {
return Err(ProcessError::usage(format!("unknown argument `{flag}`")));
}
}
}
apply_store_selection(&mut config, store)?;
Ok(Some(config))
}
fn split_flag_value(arg: String) -> Result<(String, Option<String>), ProcessError> {
if !arg.starts_with('-') {
return Err(ProcessError::usage(format!(
"unexpected positional argument `{arg}`"
)));
}
if let Some((flag, value)) = arg.split_once('=') {
Ok((flag.to_string(), Some(value.to_string())))
} else {
Ok((arg, None))
}
}
fn take_value(
flag: &str,
inline_value: Option<String>,
args: &mut VecDeque<String>,
) -> Result<String, ProcessError> {
if let Some(value) = inline_value {
return Ok(value);
}
args.pop_front()
.ok_or_else(|| ProcessError::usage(format!("{flag} requires a value")))
}
fn parse_usize_flag(flag: &str, value: String) -> Result<usize, ProcessError> {
value
.parse::<usize>()
.map_err(|error| ProcessError::usage(format!("invalid {flag} value `{value}`: {error}")))
}
fn apply_store_selection(
config: &mut RuntimeHttpServerConfig,
store: StoreArg,
) -> Result<(), ProcessError> {
match store {
StoreArg::Memory => {
config.store = RuntimeHttpStoreSelection::Memory;
Ok(())
}
StoreArg::Fs { root } => apply_fs_store_selection(config, root),
}
}
#[cfg(feature = "fs-store")]
fn apply_fs_store_selection(
config: &mut RuntimeHttpServerConfig,
root: Option<PathBuf>,
) -> Result<(), ProcessError> {
let root = root
.ok_or_else(|| ProcessError::usage("--store fs requires --fs-root <PATH>".to_string()))?;
config.store = RuntimeHttpStoreSelection::Fs { root };
Ok(())
}
#[cfg(not(feature = "fs-store"))]
fn apply_fs_store_selection(
_config: &mut RuntimeHttpServerConfig,
root: Option<PathBuf>,
) -> Result<(), ProcessError> {
let _ = root;
Err(ProcessError::usage(
"fs store selection requires building worker-runtime with features `http-server,fs-store`"
.to_string(),
))
}
#[derive(Clone, Debug, PartialEq, Eq)]
enum StoreArg {
Memory,
Fs { root: Option<PathBuf> },
}
#[derive(Debug)]
enum ProcessError {
Usage(String),
Server(RuntimeHttpServerError),
Io(std::io::Error),
}
impl ProcessError {
fn usage(message: String) -> Self {
Self::Usage(message)
}
}
impl fmt::Display for ProcessError {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
match self {
Self::Usage(message) => message.fmt(f),
Self::Server(error) => error.fmt(f),
Self::Io(error) => error.fmt(f),
}
}
}
impl Error for ProcessError {
fn source(&self) -> Option<&(dyn Error + 'static)> {
match self {
Self::Usage(_) => None,
Self::Server(error) => Some(error),
Self::Io(error) => Some(error),
}
}
}
impl From<RuntimeHttpServerError> for ProcessError {
fn from(error: RuntimeHttpServerError) -> Self {
Self::Server(error)
}
}
impl From<std::io::Error> for ProcessError {
fn from(error: std::io::Error) -> Self {
Self::Io(error)
}
}
fn usage() -> &'static str {
"Usage: worker-runtime-rest-server [OPTIONS]\n\n\
Starts the worker-runtime REST command API for a trusted backend/proxy.\n\
Browsers must not connect to this Runtime process directly.\n\n\
Options:\n\
--bind <ADDR> Bind socket address (default: 127.0.0.1:0)\n\
--runtime-id <ID> Runtime authority id (default: generated)\n\
--display-name <NAME> Runtime display name\n\
--store <memory|fs> Store selection (default: memory)\n\
--fs-root <PATH> Filesystem store root; requires fs-store feature\n\
--local-token <TOKEN> Minimal local bearer token placeholder\n\
--local-token-env <ENV> Read local bearer token placeholder from env\n\
--max-transcript-projection-items <N> Override transcript projection limit\n\
--max-event-batch-items <N> Override event batch limit\n\
-h, --help Show this help"
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn parses_memory_runtime_process_config() {
let config = parse_args([
"--bind",
"127.0.0.1:48181",
"--runtime-id=runtime-review",
"--display-name",
"review runtime",
"--store",
"memory",
"--local-token",
"local-placeholder",
"--max-transcript-projection-items",
"32",
"--max-event-batch-items=16",
])
.unwrap()
.unwrap();
assert_eq!(
config.bind_addr,
"127.0.0.1:48181".parse::<SocketAddr>().unwrap()
);
assert_eq!(
config.runtime_id.as_ref().map(RuntimeId::as_str),
Some("runtime-review")
);
assert_eq!(config.display_name.as_deref(), Some("review runtime"));
assert!(matches!(config.store, RuntimeHttpStoreSelection::Memory));
assert_eq!(config.local_token.as_deref(), Some("local-placeholder"));
assert_eq!(config.limits.max_transcript_projection_items, 32);
assert_eq!(config.limits.max_event_batch_items, 16);
}
#[cfg(feature = "fs-store")]
#[test]
fn parses_fs_store_runtime_process_config_when_feature_enabled() {
let config = parse_args(["--fs-root", "/tmp/yoi-worker-runtime-store"])
.unwrap()
.unwrap();
assert!(matches!(
config.store,
RuntimeHttpStoreSelection::Fs { ref root }
if root == &PathBuf::from("/tmp/yoi-worker-runtime-store")
));
}
#[cfg(not(feature = "fs-store"))]
#[test]
fn rejects_fs_store_runtime_process_config_without_feature() {
let error = parse_args(["--store", "fs", "--fs-root", "/tmp/store"]).unwrap_err();
assert!(
error
.to_string()
.contains("requires building worker-runtime with features")
);
}
#[test]
fn help_does_not_start_server() {
assert!(parse_args(["--help"]).unwrap().is_none());
}
}

View File

@ -0,0 +1,68 @@
use crate::identity::RuntimeId;
use serde::{Deserialize, Serialize};
/// Runtime backend kind.
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum RuntimeBackendKind {
Memory,
#[cfg(feature = "fs-store")]
FsStore,
}
/// Runtime lifecycle state.
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum RuntimeStatus {
Running,
Stopped,
}
/// Guardrails for bounded observation/projection APIs.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct RuntimeLimits {
pub max_transcript_projection_items: usize,
pub max_event_batch_items: usize,
}
impl Default for RuntimeLimits {
fn default() -> Self {
Self {
max_transcript_projection_items: 256,
max_event_batch_items: 256,
}
}
}
/// Options used to construct an embedded memory Runtime.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct RuntimeOptions {
pub runtime_id: Option<RuntimeId>,
pub display_name: Option<String>,
pub limits: RuntimeLimits,
}
impl Default for RuntimeOptions {
fn default() -> Self {
Self {
runtime_id: None,
display_name: None,
limits: RuntimeLimits::default(),
}
}
}
/// Management-plane summary for a Runtime.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct RuntimeSummary {
pub runtime_id: RuntimeId,
pub display_name: Option<String>,
pub backend: RuntimeBackendKind,
pub status: RuntimeStatus,
pub worker_count: usize,
pub active_worker_count: usize,
pub stopped_worker_count: usize,
pub cancelled_worker_count: usize,
pub diagnostic_count: usize,
pub limits: RuntimeLimits,
}

View File

@ -0,0 +1,155 @@
use crate::identity::{RuntimeId, WorkerRef};
use serde::{Deserialize, Serialize};
/// Transcript role used by bounded projection.
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum TranscriptRole {
User,
Assistant,
System,
}
/// One projected transcript item.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct TranscriptEntry {
pub sequence: u64,
pub worker_ref: WorkerRef,
pub role: TranscriptRole,
pub content: String,
pub event_id: u64,
}
/// Bounded transcript query.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct TranscriptQuery {
pub start: usize,
pub limit: usize,
}
impl TranscriptQuery {
pub fn new(start: usize, limit: usize) -> Self {
Self { start, limit }
}
}
/// Bounded transcript projection response.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct TranscriptProjection {
pub worker_ref: WorkerRef,
pub start: usize,
pub limit: usize,
pub total_items: usize,
pub items: Vec<TranscriptEntry>,
pub next_start: Option<usize>,
}
/// Event cursor. `next_event_id` is the first event id that should be returned
/// by the next poll.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct EventCursor {
pub runtime_id: RuntimeId,
pub next_event_id: u64,
}
/// Placeholder subscription handle for future streaming APIs. v0 is explicit
/// poll-only so HTTP/WS/SSE dependencies are not pulled into this crate.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct EventSubscription {
pub runtime_id: RuntimeId,
pub cursor: EventCursor,
pub mode: EventSubscriptionMode,
}
#[derive(Clone, Copy, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum EventSubscriptionMode {
PollOnly,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct RuntimeEvent {
pub id: u64,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub worker_ref: Option<WorkerRef>,
pub kind: RuntimeEventKind,
pub message: String,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", rename_all = "snake_case")]
pub enum RuntimeEventKind {
RuntimeStarted,
RuntimeStopped,
WorkerCreated,
WorkerInputAccepted,
WorkerStopped,
WorkerCancelled,
}
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct RuntimeEventBatch {
pub runtime_id: RuntimeId,
pub cursor: EventCursor,
pub events: Vec<RuntimeEvent>,
pub has_more: bool,
}
/// Runtime-local cursor for worker-scoped WebSocket observation.
#[cfg(feature = "ws-server")]
#[derive(Clone, Copy, Debug, PartialEq, Eq, PartialOrd, Ord)]
pub struct WorkerObservationCursor {
pub sequence: u64,
}
#[cfg(feature = "ws-server")]
impl WorkerObservationCursor {
pub const PREFIX: &'static str = "wo";
pub fn new(sequence: u64) -> Self {
Self { sequence }
}
pub fn zero() -> Self {
Self { sequence: 0 }
}
pub fn encode(self) -> String {
format!("{}_{:016x}", Self::PREFIX, self.sequence)
}
pub fn decode(value: &str) -> Option<Self> {
let encoded = value.strip_prefix("wo_")?;
if encoded.len() != 16 {
return None;
}
u64::from_str_radix(encoded, 16)
.ok()
.map(|sequence| Self { sequence })
}
}
/// One protocol event observed from a runtime Worker.
#[cfg(feature = "ws-server")]
#[derive(Clone, Debug, Serialize, Deserialize)]
pub struct WorkerObservationEvent {
pub cursor: String,
pub event_id: String,
pub sequence: u64,
pub worker_ref: WorkerRef,
pub payload: protocol::Event,
}
#[cfg(feature = "ws-server")]
impl WorkerObservationEvent {
pub fn new(sequence: u64, worker_ref: WorkerRef, payload: protocol::Event) -> Self {
let cursor = WorkerObservationCursor::new(sequence).encode();
Self {
event_id: cursor.clone(),
cursor,
sequence,
worker_ref,
payload,
}
}
}

File diff suppressed because it is too large Load Diff

View File

@ -5,6 +5,10 @@ edition.workspace = true
license.workspace = true
autobins = false
[features]
default = []
runtime-adapter = ["dep:worker-runtime"]
[dependencies]
async-trait = { workspace = true }
clap = { version = "4.6.0", features = ["derive"] }
@ -17,6 +21,7 @@ protocol = { workspace = true }
provider = { workspace = true }
client = { workspace = true }
pod-registry = { workspace = true }
worker-runtime = { workspace = true, features = ["ws-server"], optional = true }
serde = { workspace = true, features = ["derive"] }
serde_json = { workspace = true }
reqwest = { version = "0.13", default-features = false, features = ["blocking", "native-tls"] }

View File

@ -225,6 +225,21 @@ fn load_profile(
Ok((resolved.manifest, PromptLoader::builtins_only()))
}
#[cfg(feature = "runtime-adapter")]
pub(crate) fn resolve_runtime_profile_manifest(
profile: Option<&str>,
workspace_root: &Path,
worker_name: &str,
) -> Result<(WorkerManifest, PromptLoader), String> {
let selector = profile
.map(ProfileSelector::parse_cli)
.unwrap_or(ProfileSelector::Default);
let (mut manifest, loader) = load_profile(&selector, workspace_root, worker_name)?;
apply_profile_launch_policy(&mut manifest, workspace_root, None)?;
apply_plugin_resolution_plan(&mut manifest, workspace_root);
Ok((manifest, loader))
}
fn load_single_manifest(
path: &Path,
explicit_worker_name: Option<&str>,

View File

@ -10,6 +10,8 @@ pub(crate) mod in_flight;
pub mod ipc;
pub mod prompt;
pub mod runtime;
#[cfg(feature = "runtime-adapter")]
pub mod runtime_adapter;
pub mod segment_log_sink;
pub mod shared_state;
mod shutdown_after_idle;

View File

@ -0,0 +1,712 @@
//! Adapter from `worker-runtime` execution backend boundary to the real
//! `worker` crate controller/run lifecycle.
//!
//! The adapter intentionally owns real `WorkerHandle`s internally and exposes
//! only the opaque `worker-runtime` execution handle to callers. Browser/API
//! projections therefore keep the existing runtime redaction boundary: no raw
//! socket paths, session paths, manifests, credentials, or handles leave this
//! module.
use std::collections::HashMap;
use std::future::Future;
use std::path::PathBuf;
use std::sync::atomic::{AtomicBool, Ordering};
use std::sync::{Arc, Mutex, mpsc};
use std::time::Duration;
use async_trait::async_trait;
use manifest::paths;
use pod_store::{CombinedStore, FsWorkerStore};
use protocol::{Method, Segment, WorkerStatus};
use session_store::FsStore;
use tokio::runtime::Runtime;
use tokio::sync::broadcast;
use worker_runtime::execution::{
WorkerExecutionBackend, WorkerExecutionHandle, WorkerExecutionOperation, WorkerExecutionResult,
WorkerExecutionRunState, WorkerExecutionSpawnRequest, WorkerExecutionSpawnResult,
};
use worker_runtime::interaction::{WorkerInput, WorkerInputKind};
use crate::{Worker, WorkerController, WorkerHandle};
const DEFAULT_BACKEND_ID: &str = "worker-crate";
const RUNTIME_TASK_TIMEOUT: Duration = Duration::from_secs(10);
/// Factory seam used by [`WorkerRuntimeExecutionBackend`] to construct a real
/// controller-backed Worker for a Runtime catalog entry.
#[async_trait]
pub trait RuntimeWorkerFactory: Send + Sync + 'static {
async fn spawn_controller(
&self,
request: WorkerExecutionSpawnRequest,
) -> Result<WorkerHandle, String>;
}
/// Production factory that resolves a normal Worker profile and spawns it under
/// `WorkerController`.
#[derive(Debug, Clone)]
pub struct ProfileRuntimeWorkerFactory {
workspace_root: PathBuf,
cwd: PathBuf,
store_dir: Option<PathBuf>,
pod_store_dir: Option<PathBuf>,
profile: Option<String>,
runtime_base_dir: Option<PathBuf>,
}
impl ProfileRuntimeWorkerFactory {
pub fn new(workspace_root: impl Into<PathBuf>) -> Self {
let workspace_root = workspace_root.into();
Self {
cwd: workspace_root.clone(),
workspace_root,
store_dir: None,
pod_store_dir: None,
profile: None,
runtime_base_dir: None,
}
}
pub fn with_cwd(mut self, cwd: impl Into<PathBuf>) -> Self {
self.cwd = cwd.into();
self
}
pub fn with_store_dir(mut self, store_dir: impl Into<PathBuf>) -> Self {
self.store_dir = Some(store_dir.into());
self
}
pub fn with_pod_store_dir(mut self, pod_store_dir: impl Into<PathBuf>) -> Self {
self.pod_store_dir = Some(pod_store_dir.into());
self
}
/// Set the profile selector used for Runtime-created Workers. When unset,
/// normal default profile discovery is used.
pub fn with_profile(mut self, profile: impl Into<String>) -> Self {
self.profile = Some(profile.into());
self
}
pub fn with_runtime_base_dir(mut self, runtime_base_dir: impl Into<PathBuf>) -> Self {
self.runtime_base_dir = Some(runtime_base_dir.into());
self
}
fn store_dir(&self) -> Result<PathBuf, String> {
self.store_dir
.clone()
.or_else(paths::sessions_dir)
.ok_or_else(|| {
"could not resolve sessions directory (set YOI_HOME, YOI_DATA_DIR, or HOME)"
.to_string()
})
}
fn pod_store_dir(&self, store_dir: &std::path::Path) -> PathBuf {
self.pod_store_dir
.clone()
.or_else(|| paths::data_dir().map(|data_dir| data_dir.join("pods")))
.or_else(|| store_dir.parent().map(|parent| parent.join("pods")))
.unwrap_or_else(|| PathBuf::from("workers"))
}
fn runtime_base_dir(&self) -> Result<PathBuf, String> {
self.runtime_base_dir
.clone()
.or_else(|| crate::runtime::dir::default_base().ok())
.ok_or_else(|| "could not resolve worker runtime directory".to_string())
}
fn runtime_worker_name(request: &WorkerExecutionSpawnRequest) -> String {
request.worker_ref.worker_id.to_string()
}
fn runtime_profile_value(
profile: &worker_runtime::catalog::ProfileSelector,
) -> Option<std::borrow::Cow<'_, str>> {
match profile {
worker_runtime::catalog::ProfileSelector::RuntimeDefault => None,
worker_runtime::catalog::ProfileSelector::Named(name) => {
Some(std::borrow::Cow::Borrowed(name.as_str()))
}
worker_runtime::catalog::ProfileSelector::Builtin(name) => {
if name.starts_with("builtin:") {
Some(std::borrow::Cow::Borrowed(name.as_str()))
} else {
Some(std::borrow::Cow::Owned(format!("builtin:{name}")))
}
}
}
}
fn runtime_profile<'a>(
&'a self,
request: &'a WorkerExecutionSpawnRequest,
) -> Option<std::borrow::Cow<'a, str>> {
if let Some(profile) = self.profile.as_deref() {
return Some(std::borrow::Cow::Borrowed(profile));
}
Self::runtime_profile_value(&request.request.profile)
}
}
#[async_trait]
impl RuntimeWorkerFactory for ProfileRuntimeWorkerFactory {
async fn spawn_controller(
&self,
request: WorkerExecutionSpawnRequest,
) -> Result<WorkerHandle, String> {
let worker_name = Self::runtime_worker_name(&request);
let profile = self.runtime_profile(&request);
let (mut manifest, loader) = crate::entrypoint::resolve_runtime_profile_manifest(
profile.as_deref(),
&self.workspace_root,
&worker_name,
)?;
manifest.worker.name = worker_name;
let store_dir = self.store_dir()?;
let session_store = FsStore::new(&store_dir).map_err(|err| {
format!(
"failed to initialize session store at {}: {err}",
store_dir.display()
)
})?;
let pod_store_dir = self.pod_store_dir(&store_dir);
let pod_store = FsWorkerStore::new(&pod_store_dir).map_err(|err| {
format!(
"failed to initialize worker metadata store at {}: {err}",
pod_store_dir.display()
)
})?;
let store = CombinedStore::new(session_store, pod_store);
let worker = Worker::from_manifest_with_context(
manifest,
store,
loader,
self.workspace_root.clone(),
self.cwd.clone(),
)
.await
.map_err(|err| format!("failed to create Worker from profile: {err}"))?;
let runtime_base = self.runtime_base_dir()?;
let (handle, _shutdown_rx) = WorkerController::spawn(worker, &runtime_base)
.await
.map_err(|err| format!("failed to spawn Worker controller: {err}"))?;
Ok(handle)
}
}
struct RuntimeWorkerExecution {
handle: WorkerHandle,
busy: Arc<AtomicBool>,
}
/// `worker-runtime` execution backend backed by real `worker` crate Workers.
pub struct WorkerRuntimeExecutionBackend<F = ProfileRuntimeWorkerFactory> {
backend_id: String,
factory: Arc<F>,
runtime: Mutex<Option<Runtime>>,
workers: Mutex<HashMap<worker_runtime::identity::WorkerRef, RuntimeWorkerExecution>>,
}
impl WorkerRuntimeExecutionBackend<ProfileRuntimeWorkerFactory> {
pub fn from_workspace(workspace_root: impl Into<PathBuf>) -> Result<Self, String> {
Self::new(ProfileRuntimeWorkerFactory::new(workspace_root))
}
}
impl<F> WorkerRuntimeExecutionBackend<F>
where
F: RuntimeWorkerFactory,
{
pub fn new(factory: F) -> Result<Self, String> {
let runtime = tokio::runtime::Builder::new_multi_thread()
.thread_name("yoi-runtime-worker-adapter")
.enable_all()
.build()
.map_err(|err| format!("failed to build worker adapter runtime: {err}"))?;
Ok(Self {
backend_id: DEFAULT_BACKEND_ID.to_string(),
factory: Arc::new(factory),
runtime: Mutex::new(Some(runtime)),
workers: Mutex::new(HashMap::new()),
})
}
pub fn with_backend_id(mut self, backend_id: impl Into<String>) -> Self {
self.backend_id = backend_id.into();
self
}
fn wait_for_runtime_task<T>(receiver: mpsc::Receiver<Result<T, String>>) -> Result<T, String> {
receiver
.recv_timeout(RUNTIME_TASK_TIMEOUT)
.map_err(|err| format!("worker adapter task did not complete: {err}"))?
}
fn spawn_on_adapter_runtime<Fut>(&self, task: Fut) -> Result<(), String>
where
Fut: Future<Output = ()> + Send + 'static,
{
let runtime = self
.runtime
.lock()
.map_err(|_| "worker adapter runtime lock is poisoned".to_string())?;
let runtime = runtime
.as_ref()
.ok_or_else(|| "worker adapter runtime is shutting down".to_string())?;
runtime.spawn(task);
Ok(())
}
fn run_on_adapter_runtime<T, Fut>(&self, task: Fut) -> Result<T, String>
where
T: Send + 'static,
Fut: Future<Output = Result<T, String>> + Send + 'static,
{
let (tx, rx) = mpsc::sync_channel(1);
self.spawn_on_adapter_runtime(async move {
let _ = tx.send(task.await);
})?;
Self::wait_for_runtime_task(rx)
}
fn get_execution(
&self,
handle: &WorkerExecutionHandle,
) -> Result<(WorkerHandle, Arc<AtomicBool>), WorkerExecutionResult> {
if handle.backend_id() != self.backend_id() {
return Err(WorkerExecutionResult::rejected(
WorkerExecutionOperation::Input,
format!(
"execution handle belongs to backend {}, not {}",
handle.backend_id(),
self.backend_id()
),
));
}
let workers = self.workers.lock().map_err(|_| {
WorkerExecutionResult::errored(
WorkerExecutionOperation::Input,
"worker adapter registry lock is poisoned",
)
})?;
workers
.get(handle.worker_ref())
.map(|execution| (execution.handle.clone(), execution.busy.clone()))
.ok_or_else(|| {
WorkerExecutionResult::rejected(
WorkerExecutionOperation::Input,
"execution handle does not reference a live Worker",
)
})
}
fn send_method(
&self,
operation: WorkerExecutionOperation,
worker: WorkerHandle,
method: Method,
accepted_run_state: WorkerExecutionRunState,
) -> WorkerExecutionResult {
self.run_on_adapter_runtime(async move {
worker
.send(method)
.await
.map_err(|err| format!("failed to send Worker method: {err}"))
})
.map(|_| WorkerExecutionResult::accepted(operation, accepted_run_state))
.unwrap_or_else(|message| WorkerExecutionResult::errored(operation, message))
}
}
impl<F> Drop for WorkerRuntimeExecutionBackend<F> {
fn drop(&mut self) {
if let Ok(mut runtime) = self.runtime.lock()
&& let Some(runtime) = runtime.take()
{
let _ = std::thread::spawn(move || drop(runtime)).join();
}
}
}
impl<F> WorkerExecutionBackend for WorkerRuntimeExecutionBackend<F>
where
F: RuntimeWorkerFactory,
{
fn backend_id(&self) -> &str {
&self.backend_id
}
fn spawn_worker(&self, request: WorkerExecutionSpawnRequest) -> WorkerExecutionSpawnResult {
if self
.workers
.lock()
.map(|workers| workers.contains_key(&request.worker_ref))
.unwrap_or(false)
{
return WorkerExecutionSpawnResult::Rejected(WorkerExecutionResult::busy(
WorkerExecutionOperation::Spawn,
"Worker is already connected to execution backend",
));
}
let factory = self.factory.clone();
let bridge_context = request.context.clone();
let worker_ref = request.worker_ref.clone();
let spawn_result =
self.run_on_adapter_runtime(async move { factory.spawn_controller(request).await });
let handle = match spawn_result {
Ok(handle) => handle,
Err(message) => {
return WorkerExecutionSpawnResult::Errored(WorkerExecutionResult::errored(
WorkerExecutionOperation::Spawn,
message,
));
}
};
let mut events = handle.subscribe();
let bridge_handle = handle.clone();
let busy = Arc::new(AtomicBool::new(false));
let bridge_busy = busy.clone();
if let Err(message) = self.spawn_on_adapter_runtime(async move {
loop {
match events.recv().await {
Ok(event) => {
let _ = bridge_context.publish_protocol_event(event);
if bridge_handle.shared_state.get_status() == WorkerStatus::Idle {
bridge_busy.store(false, Ordering::SeqCst);
}
}
Err(broadcast::error::RecvError::Lagged(_)) => continue,
Err(broadcast::error::RecvError::Closed) => break,
}
}
}) {
return WorkerExecutionSpawnResult::Errored(WorkerExecutionResult::errored(
WorkerExecutionOperation::Spawn,
message,
));
}
let mut workers = match self.workers.lock() {
Ok(workers) => workers,
Err(_) => {
return WorkerExecutionSpawnResult::Errored(WorkerExecutionResult::errored(
WorkerExecutionOperation::Spawn,
"worker adapter registry lock is poisoned",
));
}
};
workers.insert(worker_ref.clone(), RuntimeWorkerExecution { handle, busy });
WorkerExecutionSpawnResult::Connected {
handle: WorkerExecutionHandle::new(worker_ref, self.backend_id()),
run_state: WorkerExecutionRunState::Idle,
}
}
fn dispatch_input(
&self,
handle: &WorkerExecutionHandle,
input: WorkerInput,
) -> WorkerExecutionResult {
let (worker, busy) = match self.get_execution(handle) {
Ok(execution) => execution,
Err(mut result) => {
result.operation = WorkerExecutionOperation::Input;
return result;
}
};
if worker.shared_state.get_status() != WorkerStatus::Idle
|| busy
.compare_exchange(false, true, Ordering::SeqCst, Ordering::SeqCst)
.is_err()
{
return WorkerExecutionResult::busy(
WorkerExecutionOperation::Input,
"Worker is already running; runtime adapter v0 does not queue input",
);
}
let WorkerInputKind::User = input.kind else {
busy.store(false, Ordering::SeqCst);
return WorkerExecutionResult::unsupported(
WorkerExecutionOperation::Input,
"runtime adapter currently dispatches user input only",
);
};
let content = input.content.trim().to_string();
if content.is_empty() {
busy.store(false, Ordering::SeqCst);
return WorkerExecutionResult::rejected(
WorkerExecutionOperation::Input,
"runtime adapter rejects empty user input",
);
}
let result = self.send_method(
WorkerExecutionOperation::Input,
worker,
Method::Run {
input: vec![Segment::text(content)],
},
WorkerExecutionRunState::Busy,
);
if result.outcome != worker_runtime::execution::WorkerExecutionOutcome::Accepted {
busy.store(false, Ordering::SeqCst);
}
result
}
fn stop_worker(&self, handle: &WorkerExecutionHandle) -> WorkerExecutionResult {
let (worker, _busy) = match self.get_execution(handle) {
Ok(execution) => execution,
Err(mut result) => {
result.operation = WorkerExecutionOperation::Stop;
return result;
}
};
self.send_method(
WorkerExecutionOperation::Stop,
worker,
Method::Shutdown,
WorkerExecutionRunState::Stopped,
)
}
fn cancel_worker(&self, handle: &WorkerExecutionHandle) -> WorkerExecutionResult {
let (worker, _busy) = match self.get_execution(handle) {
Ok(execution) => execution,
Err(mut result) => {
result.operation = WorkerExecutionOperation::Cancel;
return result;
}
};
self.send_method(
WorkerExecutionOperation::Cancel,
worker,
Method::Cancel,
WorkerExecutionRunState::Idle,
)
}
}
#[cfg(test)]
mod tests {
use super::*;
use std::pin::Pin;
use std::sync::atomic::{AtomicUsize, Ordering};
use async_trait::async_trait;
use futures::Stream;
use llm_engine::Engine;
use llm_engine::llm_client::event::{Event as LlmEvent, ResponseStatus, StatusEvent};
use llm_engine::llm_client::{ClientError, LlmClient, Request};
use manifest::{Scope, WorkerManifest};
use worker_runtime::Runtime as EmbeddedRuntime;
use worker_runtime::catalog::{CreateWorkerRequest, ProfileSelector, WorkerIntent};
use worker_runtime::identity::RuntimeId;
use worker_runtime::management::RuntimeOptions;
use worker_runtime::observation::{TranscriptQuery, TranscriptRole};
#[derive(Clone)]
struct MockClient {
responses: Arc<Vec<Vec<LlmEvent>>>,
call_count: Arc<AtomicUsize>,
captured: Arc<Mutex<Vec<Request>>>,
}
impl MockClient {
fn new(events: Vec<LlmEvent>) -> Self {
Self {
responses: Arc::new(vec![events]),
call_count: Arc::new(AtomicUsize::new(0)),
captured: Arc::new(Mutex::new(Vec::new())),
}
}
}
#[async_trait]
impl LlmClient for MockClient {
fn clone_boxed(&self) -> Box<dyn LlmClient> {
Box::new(self.clone())
}
async fn stream(
&self,
request: Request,
) -> Result<Pin<Box<dyn Stream<Item = Result<LlmEvent, ClientError>> + Send>>, ClientError>
{
self.captured.lock().unwrap().push(request);
let idx = self.call_count.fetch_add(1, Ordering::SeqCst);
let events = self.responses.get(idx).cloned().unwrap_or_default();
Ok(Box::pin(futures::stream::iter(events.into_iter().map(Ok))))
}
}
struct MockFactory {
client: MockClient,
runtime_base: PathBuf,
cwd: PathBuf,
store_dir: PathBuf,
pod_store_dir: PathBuf,
}
#[async_trait]
impl RuntimeWorkerFactory for MockFactory {
async fn spawn_controller(
&self,
_request: WorkerExecutionSpawnRequest,
) -> Result<WorkerHandle, String> {
let manifest = WorkerManifest::from_toml(
r#"
[worker]
name = "runtime-adapter-test"
pwd = "./"
[model]
scheme = "anthropic"
model_id = "test-model"
[engine]
max_tokens = 100
[[scope.allow]]
target = "./"
permission = "write"
"#,
)
.map_err(|err| err.to_string())?;
let store = CombinedStore::new(
FsStore::new(&self.store_dir).map_err(|err| err.to_string())?,
FsWorkerStore::new(&self.pod_store_dir).map_err(|err| err.to_string())?,
);
let scope = Scope::writable(&self.cwd).map_err(|err| err.to_string())?;
let worker = Worker::new(
manifest,
Engine::new(self.client.clone()),
store,
self.cwd.clone(),
scope,
)
.await
.map_err(|err| err.to_string())?;
let (handle, _shutdown_rx) = WorkerController::spawn(worker, &self.runtime_base)
.await
.map_err(|err| err.to_string())?;
Ok(handle)
}
}
fn simple_text_events() -> Vec<LlmEvent> {
vec![
LlmEvent::text_block_start(0),
LlmEvent::text_delta(0, "hello"),
LlmEvent::text_delta(0, " from worker"),
LlmEvent::text_block_stop(0, None),
LlmEvent::Status(StatusEvent {
status: ResponseStatus::Completed,
}),
]
}
fn create_request(name: &str) -> CreateWorkerRequest {
CreateWorkerRequest {
intent: WorkerIntent::Role {
role: name.to_string(),
purpose: None,
},
profile: ProfileSelector::RuntimeDefault,
config_bundle: None,
requested_capabilities: Vec::new(),
workspace_refs: Vec::new(),
mount_refs: Vec::new(),
}
}
#[test]
fn builtin_profile_selector_is_not_double_prefixed() {
assert_eq!(
ProfileRuntimeWorkerFactory::runtime_profile_value(
&worker_runtime::catalog::ProfileSelector::Builtin("coder".to_string())
)
.as_deref(),
Some("builtin:coder")
);
assert_eq!(
ProfileRuntimeWorkerFactory::runtime_profile_value(
&worker_runtime::catalog::ProfileSelector::Builtin("builtin:coder".to_string())
)
.as_deref(),
Some("builtin:coder")
);
}
#[test]
fn adapter_dispatches_user_input_through_worker_run_lifecycle() {
let client = MockClient::new(simple_text_events());
let runtime_base = tempfile::tempdir().unwrap();
let cwd = tempfile::tempdir().unwrap();
let store = tempfile::tempdir().unwrap();
let factory = MockFactory {
client: client.clone(),
runtime_base: runtime_base.path().to_path_buf(),
cwd: cwd.path().to_path_buf(),
store_dir: store.path().join("sessions"),
pod_store_dir: store.path().join("pods"),
};
let backend = WorkerRuntimeExecutionBackend::new(factory).unwrap();
let runtime = EmbeddedRuntime::with_execution_backend(
RuntimeOptions {
runtime_id: RuntimeId::new("embedded"),
..RuntimeOptions::default()
},
Arc::new(backend),
)
.unwrap();
let detail = runtime.create_worker(create_request("chat")).unwrap();
runtime
.send_input(&detail.worker_ref, WorkerInput::user("say hello"))
.unwrap();
let deadline = std::time::Instant::now() + Duration::from_secs(5);
loop {
let projection = runtime
.transcript_projection(&detail.worker_ref, TranscriptQuery::new(0, 10))
.unwrap();
if projection.items.iter().any(|item| {
item.role == TranscriptRole::Assistant && item.content == "hello from worker"
}) {
break;
}
assert!(
std::time::Instant::now() < deadline,
"timed out waiting for assistant transcript projection"
);
std::thread::sleep(Duration::from_millis(20));
}
assert_eq!(client.captured.lock().unwrap().len(), 1);
let observations = runtime
.read_worker_observation_events(
&detail.worker_ref,
worker_runtime::observation::WorkerObservationCursor::zero(),
)
.unwrap();
assert!(
observations
.iter()
.any(|event| matches!(event.payload, protocol::Event::TextDone { .. }))
);
}
}

View File

@ -7,11 +7,12 @@ publish = false
[dependencies]
async-trait.workspace = true
axum.workspace = true
axum = { workspace = true, features = ["ws"] }
chrono = { version = "0.4", default-features = false, features = ["clock"] }
manifest = { workspace = true }
pod-store = { workspace = true }
futures.workspace = true
protocol = { workspace = true }
project-record.workspace = true
reqwest = { version = "0.13", default-features = false, features = ["blocking", "json", "native-tls"] }
rusqlite.workspace = true
serde = { workspace = true, features = ["derive"] }
serde_json.workspace = true
@ -20,6 +21,9 @@ sha2.workspace = true
thiserror.workspace = true
ticket.workspace = true
tokio = { workspace = true, features = ["fs", "macros", "net", "rt-multi-thread", "sync"] }
tokio-tungstenite.workspace = true
worker = { workspace = true, features = ["runtime-adapter"] }
worker-runtime = { workspace = true, features = ["ws-server"] }
toml.workspace = true
tracing.workspace = true
uuid = { workspace = true, features = ["v7"] }

View File

@ -0,0 +1,762 @@
use std::sync::{Arc, Mutex};
use chrono::Utc;
use serde::{Deserialize, Serialize};
use worker_runtime::catalog::{CapabilityRequest, ConfigBundleRef, ProfileSelector};
use worker_runtime::config_bundle::{
ConfigBundle, ConfigBundleMetadata, ConfigBundleProvenance, ConfigProfileDescriptor,
};
use crate::hosts::{
DiagnosticSeverity, RuntimeDiagnostic, RuntimeRegistry, WorkerInputKind, WorkerInputRequest,
WorkerOperationState, WorkerSpawnAcceptanceRequirement, WorkerSpawnIntent, WorkerSpawnRequest,
WorkerSummary, WorkerTranscriptItem as RuntimeTranscriptItem, WorkerTranscriptProjection,
};
const COMPANION_RUNTIME_ID: &str = "embedded-worker-runtime";
const COMPANION_PROFILE_ID: &str = "builtin:companion";
const COMPANION_CONFIG_BUNDLE_ID: &str = "workspace-companion-config";
const MAX_MESSAGE_CHARS: usize = 8_000;
#[derive(Debug, Clone, Copy, Serialize, Deserialize, PartialEq, Eq)]
#[serde(rename_all = "snake_case")]
pub enum CompanionState {
Ready,
Busy,
Error,
Timeout,
Cancelled,
Accepted,
Rejected,
}
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]
pub struct CompanionStatusResponse {
pub state: CompanionState,
#[serde(skip_serializing_if = "Option::is_none")]
pub worker: Option<WorkerSummary>,
pub transport: CompanionTransportSummary,
pub diagnostics: Vec<RuntimeDiagnostic>,
}
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]
pub struct CompanionTransportSummary {
pub kind: String,
pub completion: String,
pub limitation: String,
}
#[derive(Debug, Clone, Deserialize, PartialEq, Eq)]
pub struct CompanionMessageRequest {
pub content: String,
}
#[derive(Debug, Clone, Deserialize, PartialEq, Eq, Default)]
pub struct CompanionCancelRequest {
#[serde(default, skip_serializing_if = "Option::is_none")]
pub reason: Option<String>,
}
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]
pub struct CompanionMessageResponse {
pub state: CompanionState,
#[serde(skip_serializing_if = "Option::is_none")]
pub worker: Option<WorkerSummary>,
#[serde(skip_serializing_if = "Option::is_none")]
pub user_item: Option<CompanionTranscriptItem>,
#[serde(skip_serializing_if = "Option::is_none")]
pub assistant_item: Option<CompanionTranscriptItem>,
pub transcript: CompanionTranscriptProjection,
pub diagnostics: Vec<RuntimeDiagnostic>,
}
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]
pub struct CompanionTranscriptProjection {
pub state: CompanionState,
pub start: usize,
pub limit: usize,
pub total_items: usize,
#[serde(skip_serializing_if = "Option::is_none")]
pub next_start: Option<usize>,
pub items: Vec<CompanionTranscriptItem>,
pub diagnostics: Vec<RuntimeDiagnostic>,
}
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]
pub struct CompanionTranscriptItem {
pub sequence: u64,
pub role: String,
pub content: String,
pub created_at: String,
pub source: String,
pub status: String,
}
#[derive(Debug)]
struct CompanionWorkerState {
state: CompanionState,
worker: Option<WorkerSummary>,
diagnostics: Vec<RuntimeDiagnostic>,
}
pub struct CompanionConsole {
runtime: Arc<RuntimeRegistry>,
worker: Mutex<CompanionWorkerState>,
}
impl CompanionConsole {
pub fn new(runtime: Arc<RuntimeRegistry>) -> Self {
let initial = spawn_companion_worker(&runtime);
Self {
runtime,
worker: Mutex::new(initial),
}
}
pub fn status(&self) -> CompanionStatusResponse {
match self.refresh_worker_state() {
Ok(worker) => CompanionStatusResponse {
state: worker.state,
worker: worker.worker.clone(),
transport: companion_transport(worker.worker.as_ref()),
diagnostics: worker.diagnostics.clone(),
},
Err(diagnostic) => CompanionStatusResponse {
state: CompanionState::Error,
worker: None,
transport: companion_transport(None),
diagnostics: vec![diagnostic],
},
}
}
pub fn transcript(&self, start: usize, limit: usize) -> CompanionTranscriptProjection {
match self.current_worker() {
Ok(Some(worker)) => {
match self
.runtime
.transcript(COMPANION_RUNTIME_ID, &worker.worker_id, start, limit)
{
Ok(transcript) => project_runtime_transcript(
&transcript,
companion_state_for_worker(&worker),
Vec::new(),
),
Err(error) => CompanionTranscriptProjection {
state: CompanionState::Error,
start,
limit,
total_items: 0,
next_start: None,
items: Vec::new(),
diagnostics: vec![diagnostic(
"companion_transcript_unavailable",
DiagnosticSeverity::Error,
format!("Companion Worker transcript is unavailable: {error:?}"),
)],
},
}
}
Ok(None) => CompanionTranscriptProjection {
state: CompanionState::Error,
start,
limit,
total_items: 0,
next_start: None,
items: Vec::new(),
diagnostics: vec![diagnostic(
"companion_worker_unavailable",
DiagnosticSeverity::Error,
"Workspace Companion Worker is unavailable",
)],
},
Err(diagnostic) => CompanionTranscriptProjection {
state: CompanionState::Error,
start,
limit,
total_items: 0,
next_start: None,
items: Vec::new(),
diagnostics: vec![diagnostic],
},
}
}
pub fn send_message(&self, request: CompanionMessageRequest) -> CompanionMessageResponse {
let content = request.content.trim().to_string();
if content.is_empty() {
return self.rejected_message_response(diagnostic(
"companion_message_empty",
DiagnosticSeverity::Warning,
"Companion message content is empty",
));
}
if content.chars().count() > MAX_MESSAGE_CHARS {
return self.rejected_message_response(diagnostic(
"companion_message_too_large",
DiagnosticSeverity::Warning,
format!("Companion message exceeds the {MAX_MESSAGE_CHARS} character limit"),
));
}
let worker = match self.current_worker() {
Ok(Some(worker)) => worker,
Ok(None) => {
return self.rejected_message_response(diagnostic(
"companion_worker_unavailable",
DiagnosticSeverity::Error,
"Workspace Companion Worker is unavailable",
));
}
Err(diagnostic) => return self.rejected_message_response(diagnostic),
};
let response = self.runtime.send_input(
COMPANION_RUNTIME_ID,
&worker.worker_id,
WorkerInputRequest {
kind: WorkerInputKind::User,
content: content.clone(),
},
);
match response {
Ok(result) => {
let state = match result.state {
WorkerOperationState::Accepted => CompanionState::Accepted,
WorkerOperationState::Unsupported | WorkerOperationState::Rejected => {
CompanionState::Rejected
}
};
let diagnostics = if result.diagnostics.is_empty() {
Vec::new()
} else {
result.diagnostics.clone()
};
let projection = self.transcript(0, 200);
CompanionMessageResponse {
state,
worker: projection_worker(&self.status()),
user_item: projection
.items
.iter()
.rev()
.find(|item| item.role == "user" && item.content == content)
.cloned(),
assistant_item: projection
.items
.iter()
.rev()
.find(|item| item.role == "assistant")
.cloned(),
transcript: projection,
diagnostics,
}
}
Err(error) => self.rejected_message_response(diagnostic(
"companion_worker_input_failed",
DiagnosticSeverity::Error,
format!("Companion Worker input dispatch failed: {error:?}"),
)),
}
}
pub fn cancel(&self, _request: CompanionCancelRequest) -> CompanionMessageResponse {
let diagnostics = vec![diagnostic(
"companion_cancel_no_active_run",
DiagnosticSeverity::Info,
"Workspace Companion has no active generation to cancel",
)];
let status = self.status();
let projection = self.transcript(0, 200);
CompanionMessageResponse {
state: CompanionState::Cancelled,
worker: status.worker,
user_item: None,
assistant_item: projection
.items
.iter()
.rev()
.find(|item| item.role == "assistant")
.cloned(),
transcript: projection,
diagnostics,
}
}
fn rejected_message_response(&self, diagnostic: RuntimeDiagnostic) -> CompanionMessageResponse {
let status = self.status();
let projection = self.transcript(0, 200);
CompanionMessageResponse {
state: CompanionState::Rejected,
worker: status.worker,
user_item: None,
assistant_item: projection
.items
.iter()
.rev()
.find(|item| item.role == "assistant")
.cloned(),
transcript: projection,
diagnostics: vec![diagnostic],
}
}
fn current_worker(&self) -> Result<Option<WorkerSummary>, RuntimeDiagnostic> {
self.refresh_worker_state()
.map(|state| state.worker.clone())
}
fn refresh_worker_state(&self) -> Result<CompanionWorkerState, RuntimeDiagnostic> {
let mut state = self.worker.lock().map_err(|_| {
diagnostic(
"companion_state_unavailable",
DiagnosticSeverity::Error,
"Companion state is unavailable",
)
})?;
let Some(worker_id) = state.worker.as_ref().map(|worker| worker.worker_id.clone()) else {
return Ok(CompanionWorkerState {
state: state.state,
worker: None,
diagnostics: state.diagnostics.clone(),
});
};
match self.runtime.worker(COMPANION_RUNTIME_ID, &worker_id) {
Ok(worker) => {
let mut diagnostics = if worker.capabilities.can_accept_input {
Vec::new()
} else {
state.diagnostics.clone()
};
if !worker.capabilities.can_accept_input
&& !diagnostics
.iter()
.any(|diagnostic| diagnostic.code == "companion_worker_not_input_capable")
{
diagnostics.push(companion_not_input_capable_diagnostic(&worker));
}
state.state = companion_state_for_worker(&worker);
state.worker = Some(worker);
state.diagnostics = diagnostics;
}
Err(error) => {
state.state = CompanionState::Error;
state.diagnostics = vec![diagnostic(
"companion_worker_lookup_failed",
DiagnosticSeverity::Error,
format!("Companion Worker lookup failed: {error:?}"),
)];
}
}
Ok(CompanionWorkerState {
state: state.state,
worker: state.worker.clone(),
diagnostics: state.diagnostics.clone(),
})
}
}
fn projection_worker(status: &CompanionStatusResponse) -> Option<WorkerSummary> {
status.worker.clone()
}
fn spawn_companion_worker(runtime: &RuntimeRegistry) -> CompanionWorkerState {
let selector = companion_profile_selector();
let mut diagnostics = Vec::new();
let config_bundle = companion_config_bundle();
let config_ref = ConfigBundleRef {
id: config_bundle.metadata.id.clone(),
digest: config_bundle.metadata.digest.clone(),
};
match runtime.sync_config_bundle(COMPANION_RUNTIME_ID, config_bundle) {
Ok(result) => diagnostics.extend(result.diagnostics),
Err(error) => diagnostics.push(diagnostic(
"companion_config_bundle_sync_failed",
DiagnosticSeverity::Error,
format!("Workspace Companion config bundle sync failed: {error:?}"),
)),
}
let response = runtime.spawn_worker(
COMPANION_RUNTIME_ID,
WorkerSpawnRequest {
intent: WorkerSpawnIntent::WorkspaceCompanion,
requested_worker_name: Some("workspace-companion".to_string()),
acceptance: WorkerSpawnAcceptanceRequirement::RunAccepted {
expected_segments: 0,
},
profile: Some(selector),
config_bundle: Some(config_ref),
requested_capabilities: vec![CapabilityRequest::named("worker.input.user")],
},
);
match response {
Ok(response) => {
diagnostics.extend(response.diagnostics);
if let Some(worker) = response.worker {
if !worker.capabilities.can_accept_input {
diagnostics.push(companion_not_input_capable_diagnostic(&worker));
}
CompanionWorkerState {
state: companion_state_for_worker(&worker),
worker: Some(worker),
diagnostics,
}
} else {
diagnostics.push(diagnostic(
"companion_worker_missing",
DiagnosticSeverity::Error,
"Workspace Companion Worker spawn did not return a Worker projection",
));
CompanionWorkerState {
state: CompanionState::Error,
worker: None,
diagnostics,
}
}
}
Err(error) => CompanionWorkerState {
state: CompanionState::Error,
worker: None,
diagnostics: vec![diagnostic(
"companion_worker_spawn_failed",
DiagnosticSeverity::Error,
format!("Workspace Companion Worker spawn failed: {error:?}"),
)],
},
}
}
fn companion_profile_selector() -> ProfileSelector {
ProfileSelector::Builtin(COMPANION_PROFILE_ID.to_string())
}
fn companion_config_bundle() -> ConfigBundle {
ConfigBundle {
metadata: ConfigBundleMetadata {
id: COMPANION_CONFIG_BUNDLE_ID.to_string(),
digest: String::new(),
revision: "1".to_string(),
workspace_id: "workspace-companion".to_string(),
created_at: Utc::now().to_rfc3339(),
provenance: ConfigBundleProvenance {
source: "workspace-server".to_string(),
detail: Some("workspace-companion".to_string()),
},
},
profiles: vec![ConfigProfileDescriptor {
selector: companion_profile_selector(),
label: Some("Workspace Companion".to_string()),
}],
declarations: Vec::new(),
}
.with_computed_digest()
}
fn companion_state_for_worker(worker: &WorkerSummary) -> CompanionState {
if !worker.capabilities.can_accept_input {
return CompanionState::Error;
}
match worker.status.as_str() {
"busy" | "running" | "stopping" => CompanionState::Busy,
"errored" | "error" | "stopped" | "unavailable" => CompanionState::Error,
_ => CompanionState::Ready,
}
}
fn companion_not_input_capable_diagnostic(worker: &WorkerSummary) -> RuntimeDiagnostic {
diagnostic(
"companion_worker_not_input_capable",
DiagnosticSeverity::Error,
format!(
"Workspace Companion Worker '{}' is not input-capable; check profile, provider, secret, and authority diagnostics",
worker.worker_id
),
)
}
fn project_runtime_transcript(
transcript: &WorkerTranscriptProjection,
state: CompanionState,
diagnostics: Vec<RuntimeDiagnostic>,
) -> CompanionTranscriptProjection {
CompanionTranscriptProjection {
state,
start: transcript.start,
limit: transcript.limit,
total_items: transcript.total_items,
next_start: transcript.next_start,
items: transcript
.items
.iter()
.map(project_runtime_transcript_item)
.collect(),
diagnostics,
}
}
fn project_runtime_transcript_item(item: &RuntimeTranscriptItem) -> CompanionTranscriptItem {
CompanionTranscriptItem {
sequence: item.sequence,
role: item.role.clone(),
content: item.content.clone(),
created_at: format!("runtime_sequence:{}", item.sequence),
source: "worker_runtime".to_string(),
status: "committed".to_string(),
}
}
fn companion_transport(worker: Option<&WorkerSummary>) -> CompanionTransportSummary {
if worker.is_some_and(|worker| worker.capabilities.can_accept_input) {
CompanionTransportSummary {
kind: "embedded_worker_runtime".to_string(),
completion: "connected".to_string(),
limitation:
"Workspace Companion input is dispatched through the normal Worker runtime path."
.to_string(),
}
} else {
CompanionTransportSummary {
kind: "embedded_worker_runtime".to_string(),
completion: "not_input_capable".to_string(),
limitation:
"Workspace Companion is a Worker but is not input-capable; inspect typed diagnostics for missing profile, provider, secret, or authority."
.to_string(),
}
}
}
fn diagnostic(
code: impl Into<String>,
severity: DiagnosticSeverity,
message: impl Into<String>,
) -> RuntimeDiagnostic {
RuntimeDiagnostic {
code: code.into(),
severity,
message: message.into(),
}
}
#[cfg(test)]
mod tests {
use super::*;
use crate::hosts::{EmbeddedWorkerRuntime, RuntimeRegistry};
use std::collections::HashMap;
use std::sync::Mutex as StdMutex;
use std::thread;
use std::time::{Duration, Instant};
use worker_runtime::execution::{
WorkerExecutionBackend, WorkerExecutionContext, WorkerExecutionHandle,
WorkerExecutionOperation, WorkerExecutionResult, WorkerExecutionRunState,
WorkerExecutionSpawnRequest, WorkerExecutionSpawnResult,
};
use worker_runtime::identity::WorkerRef;
use worker_runtime::interaction::WorkerInput;
#[derive(Default)]
struct DeterministicExecutionBackend {
contexts: StdMutex<HashMap<WorkerRef, WorkerExecutionContext>>,
}
impl WorkerExecutionBackend for DeterministicExecutionBackend {
fn backend_id(&self) -> &str {
"deterministic-companion-test"
}
fn spawn_worker(&self, request: WorkerExecutionSpawnRequest) -> WorkerExecutionSpawnResult {
self.contexts
.lock()
.unwrap()
.insert(request.worker_ref.clone(), request.context);
WorkerExecutionSpawnResult::Connected {
handle: WorkerExecutionHandle::new(
request.worker_ref.clone(),
"deterministic-companion-test",
),
run_state: WorkerExecutionRunState::Idle,
}
}
fn dispatch_input(
&self,
handle: &WorkerExecutionHandle,
request: WorkerInput,
) -> WorkerExecutionResult {
let worker = handle.worker_ref().clone();
let context = self
.contexts
.lock()
.unwrap()
.get(&worker)
.cloned()
.expect("execution context");
let content = request.content.clone();
thread::spawn(move || {
thread::sleep(Duration::from_millis(25));
let _ = context.publish_protocol_event(protocol::Event::TextDone {
text: format!("companion echoed: {content}"),
});
});
WorkerExecutionResult::accepted(
WorkerExecutionOperation::Input,
WorkerExecutionRunState::Idle,
)
}
}
#[test]
fn companion_spawns_worker_with_companion_profile_and_diagnostic_when_not_input_capable() {
let registry =
RuntimeRegistry::for_workspace(EmbeddedWorkerRuntime::new_memory("local:test"));
let registry = Arc::new(registry);
let companion = CompanionConsole::new(registry.clone());
let status = companion.status();
let worker = status.worker.clone().expect("companion worker");
assert_eq!(worker.runtime_id, COMPANION_RUNTIME_ID);
assert_eq!(worker.role.as_deref(), Some("workspace_companion"));
assert!(!worker.capabilities.can_accept_input);
assert_eq!(status.transport.completion, "not_input_capable");
assert!(
status
.diagnostics
.iter()
.any(|diagnostic| diagnostic.code == "companion_worker_not_input_capable")
);
let response = companion.send_message(CompanionMessageRequest {
content: "hello".to_string(),
});
assert_eq!(response.state, CompanionState::Rejected);
assert!(
!response
.diagnostics
.iter()
.any(|diagnostic| diagnostic.code == "companion_llm_not_connected")
);
assert!(response.transcript.items.is_empty());
let worker_detail = registry
.worker(COMPANION_RUNTIME_ID, &worker.worker_id)
.expect("worker detail");
assert_eq!(worker_detail.profile.as_deref(), Some(COMPANION_PROFILE_ID));
let browser_payload = serde_json::to_string(&(status, response, worker_detail)).unwrap();
for forbidden in [
"/workspace/project",
"metadata.json",
".jsonl",
"/run/user/",
"session",
"manifest",
] {
assert!(
!browser_payload.contains(forbidden),
"companion projection leaked forbidden term {forbidden}: {browser_payload}"
);
}
}
#[test]
fn companion_dispatches_input_and_projects_assistant_output_from_worker_runtime() {
let registry = RuntimeRegistry::for_workspace(
EmbeddedWorkerRuntime::new_memory_with_execution_backend(
"local:test",
Arc::new(DeterministicExecutionBackend::default()),
)
.expect("embedded runtime"),
);
let registry = Arc::new(registry);
let companion = CompanionConsole::new(registry.clone());
let status = companion.status();
let worker = status.worker.clone().expect("companion worker");
assert_eq!(status.transport.completion, "connected");
assert_eq!(worker.profile.as_deref(), Some(COMPANION_PROFILE_ID));
assert!(worker.capabilities.can_accept_input);
let source = registry
.observation_source(COMPANION_RUNTIME_ID, &worker.worker_id)
.expect("observation source");
let crate::observation::RuntimeObservationSource::Embedded(source) = source else {
panic!("expected embedded observation source");
};
let cursor = source
.runtime
.worker_observation_cursor_now(&source.worker_ref)
.expect("observation cursor");
let response = companion.send_message(CompanionMessageRequest {
content: "hello runtime".to_string(),
});
assert_eq!(response.state, CompanionState::Accepted);
assert!(
response
.user_item
.as_ref()
.is_some_and(|item| item.role == "user" && item.content == "hello runtime")
);
assert!(response.diagnostics.is_empty());
let deadline = Instant::now() + Duration::from_secs(2);
let observed = loop {
let observed = source
.runtime
.read_worker_observation_events(&source.worker_ref, cursor)
.expect("observation events");
if observed.iter().any(|event| {
serde_json::to_string(event)
.unwrap()
.contains("companion echoed: hello runtime")
}) {
break observed;
}
assert!(
Instant::now() < deadline,
"timed out waiting for observation event"
);
thread::sleep(Duration::from_millis(20));
};
let observed_json = serde_json::to_string(&observed).unwrap();
assert!(observed_json.contains("companion echoed: hello runtime"));
let deadline = Instant::now() + Duration::from_secs(2);
let transcript = loop {
let transcript = companion.transcript(0, 20);
if transcript.items.iter().any(|item| {
item.role == "assistant" && item.content == "companion echoed: hello runtime"
}) {
break transcript;
}
assert!(
Instant::now() < deadline,
"timed out waiting for companion assistant output: {transcript:?}"
);
thread::sleep(Duration::from_millis(20));
};
assert!(
transcript
.items
.iter()
.any(|item| item.role == "user" && item.content == "hello runtime")
);
assert!(transcript.items.iter().any(|item| {
item.role == "assistant"
&& item.source == "worker_runtime"
&& item.status == "committed"
}));
let runtime_transcript = registry
.transcript(COMPANION_RUNTIME_ID, &worker.worker_id, 0, 20)
.expect("runtime transcript");
assert!(runtime_transcript.items.iter().any(|item| {
item.role == "assistant" && item.content == "companion echoed: hello runtime"
}));
}
}

File diff suppressed because it is too large Load Diff

View File

@ -4,8 +4,10 @@
//! it is not the product CLI facade. Existing `.yoi` Ticket and Objective files
//! remain the canonical project records and are read through bounded bridge APIs.
pub mod companion;
pub mod hosts;
pub mod identity;
pub mod observation;
pub mod records;
pub mod repositories;
pub mod server;
@ -40,10 +42,21 @@ pub enum Error {
MissingFrontmatter(String),
#[error("unknown local host `{0}`")]
UnknownHost(String),
#[error("unknown local worker `{0}`")]
UnknownWorker(String),
#[error("unknown runtime `{0}`")]
UnknownRuntime(String),
#[error("unknown worker `{worker_id}` in runtime `{runtime_id}`")]
UnknownWorker {
runtime_id: String,
worker_id: String,
},
#[error("invalid runtime {kind} `{value}`")]
InvalidRuntimeIdentifier { kind: String, value: String },
#[error("runtime `{runtime_id}` operation failed ({code}): {message}")]
RuntimeOperationFailed {
runtime_id: String,
code: String,
message: String,
},
#[error("runtime `{runtime_id}` does not support `{capability}`")]
RuntimeCapabilityUnsupported {
runtime_id: String,

View File

@ -0,0 +1,784 @@
use std::collections::{BTreeMap, VecDeque};
use std::sync::{Arc, Mutex};
use worker_runtime::identity::WorkerRef;
use worker_runtime::observation::{WorkerObservationCursor, WorkerObservationEvent};
use axum::http::StatusCode;
use futures::{SinkExt, StreamExt};
use serde::{Deserialize, Serialize};
use tokio_tungstenite::connect_async;
use tokio_tungstenite::tungstenite::client::IntoClientRequest;
use tokio_tungstenite::tungstenite::{Error as TungsteniteError, Message as TungsteniteMessage};
use worker_runtime::http_server::{RuntimeWorkerEventWsEnvelope, RuntimeWorkerEventWsFrame};
/// Backend-private source for a runtime worker observation stream.
#[derive(Clone, PartialEq, Eq)]
pub struct RuntimeObservationSourceConfig {
pub runtime_id: String,
pub worker_id: String,
pub endpoint: String,
pub bearer_token: Option<String>,
}
impl std::fmt::Debug for RuntimeObservationSourceConfig {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
f.debug_struct("RuntimeObservationSourceConfig")
.field("runtime_id", &self.runtime_id)
.field("worker_id", &self.worker_id)
.field("endpoint", &"<backend-private>")
.field(
"bearer_token",
&self.bearer_token.as_ref().map(|_| "<redacted>"),
)
.finish()
}
}
#[derive(Clone)]
pub struct EmbeddedRuntimeObservationSource {
pub runtime_id: String,
pub worker_id: String,
pub runtime: worker_runtime::Runtime,
pub worker_ref: WorkerRef,
}
#[derive(Clone)]
pub enum RuntimeObservationSource {
RemoteWs(RuntimeObservationSourceConfig),
Embedded(EmbeddedRuntimeObservationSource),
}
impl RuntimeObservationSource {
pub fn remote_ws(config: RuntimeObservationSourceConfig) -> Self {
Self::RemoteWs(config)
}
pub fn embedded(source: EmbeddedRuntimeObservationSource) -> Self {
Self::Embedded(source)
}
pub fn runtime_id(&self) -> &str {
match self {
Self::RemoteWs(config) => &config.runtime_id,
Self::Embedded(source) => &source.runtime_id,
}
}
pub fn worker_id(&self) -> &str {
match self {
Self::RemoteWs(config) => &config.worker_id,
Self::Embedded(source) => &source.worker_id,
}
}
}
impl std::fmt::Debug for RuntimeObservationSource {
fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
match self {
Self::RemoteWs(config) => formatter
.debug_struct("RemoteRuntimeObservationSource")
.field("runtime_id", &config.runtime_id)
.field("worker_id", &config.worker_id)
.field("endpoint", &"<backend-private>")
.field(
"bearer_token",
&config.bearer_token.as_ref().map(|_| "<redacted>"),
)
.finish(),
Self::Embedded(source) => formatter
.debug_struct("EmbeddedRuntimeObservationSource")
.field("runtime_id", &source.runtime_id)
.field("worker_id", &source.worker_id)
.finish(),
}
}
}
/// Event consumed from a Runtime-owned worker observation WebSocket.
#[derive(Clone, Debug, Serialize, Deserialize)]
pub struct RuntimeObservationUpstreamEvent {
pub runtime_id: String,
pub worker_id: String,
pub runtime_cursor: String,
pub payload: protocol::Event,
}
/// Backend-local frame exposed to browser/future-TUI clients.
#[derive(Clone, Debug, Serialize, Deserialize)]
#[serde(tag = "kind", rename_all = "snake_case")]
pub enum ClientWorkerEventWsFrame {
Event {
envelope: ClientWorkerEventWsEnvelope,
},
Diagnostic {
diagnostic: ClientWorkerEventWsDiagnostic,
},
}
/// Backend-owned opaque event envelope. It intentionally omits Runtime endpoints,
/// credentials, sockets and session paths.
#[derive(Clone, Debug, Serialize, Deserialize)]
pub struct ClientWorkerEventWsEnvelope {
pub cursor: String,
pub event_id: String,
pub runtime_id: String,
pub worker_id: String,
pub payload: protocol::Event,
}
/// Client-facing typed observation diagnostic.
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
pub struct ClientWorkerEventWsDiagnostic {
pub code: String,
pub message: String,
}
#[derive(Clone, Debug, Default, Deserialize)]
pub struct ClientWorkerEventsWsQuery {
pub cursor: Option<String>,
}
#[derive(Clone, Debug, PartialEq, Eq)]
pub enum ObservationProxyError {
RuntimeUnavailable(String),
WorkerNotFound(String),
CursorMalformed(String),
CursorUnknownOrExpired(String),
UpstreamDisconnect(String),
MalformedFrame(String),
ObservationOnly,
}
impl ObservationProxyError {
pub fn code(&self) -> &'static str {
match self {
ObservationProxyError::RuntimeUnavailable(_) => "backend.runtime_unavailable",
ObservationProxyError::WorkerNotFound(_) => "backend.worker_not_found",
ObservationProxyError::CursorMalformed(_) => "backend.cursor_malformed",
ObservationProxyError::CursorUnknownOrExpired(_) => "backend.cursor_unknown_or_expired",
ObservationProxyError::UpstreamDisconnect(_) => "backend.upstream_disconnect",
ObservationProxyError::MalformedFrame(_) => "backend.malformed_frame",
ObservationProxyError::ObservationOnly => "backend.observation_only",
}
}
pub fn message(&self) -> &str {
match self {
ObservationProxyError::RuntimeUnavailable(message)
| ObservationProxyError::WorkerNotFound(message)
| ObservationProxyError::CursorMalformed(message)
| ObservationProxyError::CursorUnknownOrExpired(message)
| ObservationProxyError::UpstreamDisconnect(message)
| ObservationProxyError::MalformedFrame(message) => message,
ObservationProxyError::ObservationOnly => {
"backend worker event WebSocket is observation-only"
}
}
}
}
impl ClientWorkerEventWsFrame {
pub fn event(envelope: ClientWorkerEventWsEnvelope) -> Self {
Self::Event { envelope }
}
pub fn diagnostic(error: ObservationProxyError) -> Self {
Self::Diagnostic {
diagnostic: ClientWorkerEventWsDiagnostic {
code: error.code().to_string(),
message: error.message().to_string(),
},
}
}
}
#[derive(Clone, Copy, Debug, PartialEq, Eq, PartialOrd, Ord)]
pub struct BackendObservationCursor {
pub sequence: u64,
}
impl BackendObservationCursor {
pub fn new(sequence: u64) -> Self {
Self { sequence }
}
pub fn zero() -> Self {
Self { sequence: 0 }
}
pub fn encode(self) -> String {
format!("bo_{:016x}", self.sequence)
}
pub fn decode(value: &str) -> Option<Self> {
let encoded = value.strip_prefix("bo_")?;
if encoded.len() != 16 {
return None;
}
u64::from_str_radix(encoded, 16)
.ok()
.map(|sequence| Self { sequence })
}
}
#[derive(Debug, Default)]
struct BackendObservationState {
next_sequence: u64,
history: BTreeMap<ObservationKey, VecDeque<StoredBackendEvent>>,
}
impl BackendObservationState {
fn new() -> Self {
Self {
next_sequence: 1,
history: BTreeMap::new(),
}
}
}
#[derive(Clone, Debug, PartialEq, Eq, PartialOrd, Ord)]
struct ObservationKey {
runtime_id: String,
worker_id: String,
}
#[derive(Clone, Debug)]
struct StoredBackendEvent {
sequence: u64,
runtime_cursor: String,
envelope: ClientWorkerEventWsEnvelope,
}
#[derive(Clone, Debug)]
pub struct BackendObservationOpen {
pub replay: Vec<ClientWorkerEventWsEnvelope>,
pub runtime_cursor: Option<String>,
pub backend_cursor: BackendObservationCursor,
}
/// Backend-owned in-memory v0 observation proxy state.
#[derive(Clone)]
pub struct BackendObservationProxy {
sources: Arc<BTreeMap<ObservationKey, RuntimeObservationSourceConfig>>,
state: Arc<Mutex<BackendObservationState>>,
}
impl std::fmt::Debug for BackendObservationProxy {
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
f.debug_struct("BackendObservationProxy")
.field("source_count", &self.sources.len())
.field("state", &"<omitted>")
.finish()
}
}
impl BackendObservationProxy {
pub fn new(sources: Vec<RuntimeObservationSourceConfig>) -> Self {
let sources = sources
.into_iter()
.map(|source| {
(
ObservationKey {
runtime_id: source.runtime_id.clone(),
worker_id: source.worker_id.clone(),
},
source,
)
})
.collect();
Self {
sources: Arc::new(sources),
state: Arc::new(Mutex::new(BackendObservationState::new())),
}
}
pub fn source(
&self,
runtime_id: &str,
worker_id: &str,
) -> Result<RuntimeObservationSource, ObservationProxyError> {
self.sources
.get(&ObservationKey {
runtime_id: runtime_id.to_string(),
worker_id: worker_id.to_string(),
})
.cloned()
.map(RuntimeObservationSource::remote_ws)
.ok_or_else(|| {
ObservationProxyError::WorkerNotFound(format!(
"worker {worker_id} is not registered for runtime {runtime_id}"
))
})
}
pub fn open(
&self,
runtime_id: &str,
worker_id: &str,
cursor: Option<&str>,
) -> Result<BackendObservationOpen, ObservationProxyError> {
let key = ObservationKey {
runtime_id: runtime_id.to_string(),
worker_id: worker_id.to_string(),
};
let cursor = match cursor {
Some(raw) => BackendObservationCursor::decode(raw).ok_or_else(|| {
ObservationProxyError::CursorMalformed(format!(
"malformed backend observation cursor: {raw}"
))
})?,
None => BackendObservationCursor::zero(),
};
let state = self.state.lock().map_err(|_| {
ObservationProxyError::RuntimeUnavailable(
"backend observation state lock poisoned".into(),
)
})?;
let history = state.history.get(&key);
let replay: Vec<_> = history
.into_iter()
.flat_map(|events| events.iter())
.filter(|event| event.sequence > cursor.sequence)
.cloned()
.collect();
if cursor.sequence != 0 {
let found = history
.into_iter()
.flat_map(|events| events.iter())
.any(|event| event.sequence == cursor.sequence);
if !found {
return Err(ObservationProxyError::CursorUnknownOrExpired(format!(
"backend observation cursor {} is unknown or expired for runtime {runtime_id} worker {worker_id}",
cursor.encode()
)));
}
}
let runtime_cursor = replay
.last()
.map(|event| event.runtime_cursor.clone())
.or_else(|| {
history.and_then(|events| {
events
.iter()
.find(|event| event.sequence == cursor.sequence)
.map(|event| event.runtime_cursor.clone())
})
});
Ok(BackendObservationOpen {
replay: replay.into_iter().map(|event| event.envelope).collect(),
runtime_cursor,
backend_cursor: cursor,
})
}
pub fn store(
&self,
event: RuntimeObservationUpstreamEvent,
) -> Result<ClientWorkerEventWsEnvelope, ObservationProxyError> {
let mut state = self.state.lock().map_err(|_| {
ObservationProxyError::RuntimeUnavailable(
"backend observation state lock poisoned".into(),
)
})?;
let sequence = state.next_sequence;
state.next_sequence += 1;
let cursor = BackendObservationCursor::new(sequence).encode();
let envelope = ClientWorkerEventWsEnvelope {
cursor: cursor.clone(),
event_id: cursor,
runtime_id: event.runtime_id.clone(),
worker_id: event.worker_id.clone(),
payload: event.payload,
};
let key = ObservationKey {
runtime_id: event.runtime_id,
worker_id: event.worker_id,
};
let history = state.history.entry(key).or_default();
history.push_back(StoredBackendEvent {
sequence,
runtime_cursor: event.runtime_cursor,
envelope: envelope.clone(),
});
while history.len() > 1024 {
history.pop_front();
}
Ok(envelope)
}
}
fn map_runtime_connect_error(error: TungsteniteError) -> ObservationProxyError {
match error {
TungsteniteError::Http(response) if response.status() == StatusCode::NOT_FOUND => {
ObservationProxyError::WorkerNotFound(
"runtime worker observation endpoint returned 404 not found".into(),
)
}
TungsteniteError::Http(response) if response.status() == StatusCode::BAD_REQUEST => {
ObservationProxyError::CursorMalformed(
"runtime worker observation endpoint rejected the request as malformed".into(),
)
}
TungsteniteError::Http(response) => ObservationProxyError::RuntimeUnavailable(format!(
"runtime worker observation endpoint rejected WebSocket upgrade with status {}",
response.status()
)),
error => ObservationProxyError::RuntimeUnavailable(format!(
"failed to connect runtime WebSocket: {error}"
)),
}
}
fn map_runtime_diagnostic(code: String, message: String) -> ObservationProxyError {
match code.as_str() {
"runtime.worker_not_found" => ObservationProxyError::WorkerNotFound(message),
"runtime.cursor_malformed" => ObservationProxyError::CursorMalformed(message),
"runtime.cursor_unknown_or_expired" | "runtime.cursor_expired" => {
ObservationProxyError::CursorUnknownOrExpired(message)
}
"runtime.unavailable" => ObservationProxyError::RuntimeUnavailable(message),
"runtime.upstream_closed" | "runtime.websocket_error" => {
ObservationProxyError::UpstreamDisconnect(message)
}
"runtime.serialize_failed" => ObservationProxyError::MalformedFrame(message),
"runtime.observation_only" => ObservationProxyError::ObservationOnly,
_ => ObservationProxyError::RuntimeUnavailable(format!(
"runtime diagnostic {code}: {message}"
)),
}
}
pub struct RuntimeWsObservationClient {
runtime_id: String,
worker_id: String,
stream: tokio_tungstenite::WebSocketStream<
tokio_tungstenite::MaybeTlsStream<tokio::net::TcpStream>,
>,
}
impl RuntimeWsObservationClient {
pub async fn connect(
source: &RuntimeObservationSourceConfig,
runtime_cursor: Option<&str>,
) -> Result<Self, ObservationProxyError> {
let mut endpoint = source.endpoint.clone();
if let Some(cursor) = runtime_cursor {
let separator = if endpoint.contains('?') { '&' } else { '?' };
endpoint.push(separator);
endpoint.push_str("cursor=");
endpoint.push_str(cursor);
}
let mut request = endpoint.into_client_request().map_err(|error| {
ObservationProxyError::RuntimeUnavailable(format!(
"failed to build runtime WebSocket request: {error}"
))
})?;
if let Some(token) = &source.bearer_token {
request.headers_mut().insert(
"authorization",
format!("Bearer {token}").parse().map_err(|error| {
ObservationProxyError::RuntimeUnavailable(format!(
"failed to build runtime authorization header: {error}"
))
})?,
);
}
let (stream, _) = connect_async(request)
.await
.map_err(map_runtime_connect_error)?;
Ok(Self {
runtime_id: source.runtime_id.clone(),
worker_id: source.worker_id.clone(),
stream,
})
}
pub async fn next_event(
&mut self,
) -> Result<RuntimeObservationUpstreamEvent, ObservationProxyError> {
loop {
let Some(message) = self.stream.next().await else {
return Err(ObservationProxyError::UpstreamDisconnect(
"runtime WebSocket closed".into(),
));
};
let message = message.map_err(|error| {
ObservationProxyError::UpstreamDisconnect(format!(
"runtime WebSocket receive error: {error}"
))
})?;
let text = match message {
TungsteniteMessage::Text(text) => text,
TungsteniteMessage::Close(_) => {
return Err(ObservationProxyError::UpstreamDisconnect(
"runtime WebSocket closed".into(),
));
}
TungsteniteMessage::Ping(payload) => {
self.stream
.send(TungsteniteMessage::Pong(payload))
.await
.map_err(|error| {
ObservationProxyError::UpstreamDisconnect(format!(
"failed to reply to runtime ping: {error}"
))
})?;
continue;
}
TungsteniteMessage::Pong(_) => continue,
TungsteniteMessage::Binary(_) | TungsteniteMessage::Frame(_) => {
return Err(ObservationProxyError::MalformedFrame(
"runtime sent a non-text observation frame".into(),
));
}
};
let frame: RuntimeWorkerEventWsFrame =
serde_json::from_str(&text).map_err(|error| {
ObservationProxyError::MalformedFrame(format!(
"failed to decode runtime observation frame: {error}"
))
})?;
match frame {
RuntimeWorkerEventWsFrame::Event { envelope } => {
return Ok(self.map_envelope(envelope));
}
RuntimeWorkerEventWsFrame::Diagnostic { diagnostic } => {
return Err(map_runtime_diagnostic(diagnostic.code, diagnostic.message));
}
}
}
}
fn map_envelope(
&self,
envelope: RuntimeWorkerEventWsEnvelope,
) -> RuntimeObservationUpstreamEvent {
RuntimeObservationUpstreamEvent {
runtime_id: self.runtime_id.clone(),
worker_id: self.worker_id.clone(),
runtime_cursor: envelope.cursor,
payload: envelope.payload,
}
}
}
pub enum RuntimeObservationClient {
RemoteWs(RuntimeWsObservationClient),
Embedded(EmbeddedObservationClient),
}
impl RuntimeObservationClient {
pub async fn connect(
source: &RuntimeObservationSource,
runtime_cursor: Option<&str>,
) -> Result<Self, ObservationProxyError> {
match source {
RuntimeObservationSource::RemoteWs(config) => {
RuntimeWsObservationClient::connect(config, runtime_cursor)
.await
.map(Self::RemoteWs)
}
RuntimeObservationSource::Embedded(source) => {
EmbeddedObservationClient::connect(source, runtime_cursor).map(Self::Embedded)
}
}
}
pub async fn next_event(
&mut self,
) -> Result<RuntimeObservationUpstreamEvent, ObservationProxyError> {
match self {
Self::RemoteWs(client) => client.next_event().await,
Self::Embedded(client) => client.next_event().await,
}
}
}
pub struct EmbeddedObservationClient {
runtime_id: String,
worker_id: String,
worker_ref: WorkerRef,
cursor: WorkerObservationCursor,
receiver: tokio::sync::broadcast::Receiver<WorkerObservationEvent>,
queued: VecDeque<RuntimeObservationUpstreamEvent>,
}
impl EmbeddedObservationClient {
fn connect(
source: &EmbeddedRuntimeObservationSource,
runtime_cursor: Option<&str>,
) -> Result<Self, ObservationProxyError> {
let cursor = match runtime_cursor {
Some(raw) => WorkerObservationCursor::decode(raw).ok_or_else(|| {
ObservationProxyError::CursorMalformed(
"embedded runtime cursor is malformed".into(),
)
})?,
None => source
.runtime
.worker_observation_cursor_now(&source.worker_ref)
.map_err(|err| {
ObservationProxyError::WorkerNotFound(format!(
"embedded Worker '{}' is not observable: {err}",
source.worker_id
))
})?,
};
let receiver = source
.runtime
.subscribe_worker_observation()
.map_err(|err| {
ObservationProxyError::WorkerNotFound(format!(
"embedded Worker '{}' observation subscription is unavailable: {err}",
source.worker_id
))
})?;
let mut queued = VecDeque::new();
if runtime_cursor.is_none() {
let snapshot = source
.runtime
.worker_observation_snapshot(&source.worker_ref)
.map_err(|err| {
ObservationProxyError::WorkerNotFound(format!(
"embedded Worker '{}' snapshot is unavailable: {err}",
source.worker_id
))
})?;
queued.push_back(RuntimeObservationUpstreamEvent {
runtime_id: source.runtime_id.clone(),
worker_id: source.worker_id.clone(),
runtime_cursor: cursor.encode(),
payload: snapshot,
});
}
for event in source
.runtime
.read_worker_observation_events(&source.worker_ref, cursor)
.map_err(|err| {
ObservationProxyError::CursorUnknownOrExpired(format!(
"embedded Worker '{}' cursor is unavailable: {err}",
source.worker_id
))
})?
{
queued.push_back(Self::map_event(
&source.runtime_id,
&source.worker_id,
event,
));
}
Ok(Self {
runtime_id: source.runtime_id.clone(),
worker_id: source.worker_id.clone(),
worker_ref: source.worker_ref.clone(),
cursor,
receiver,
queued,
})
}
async fn next_event(
&mut self,
) -> Result<RuntimeObservationUpstreamEvent, ObservationProxyError> {
if let Some(event) = self.queued.pop_front() {
if let Some(cursor) = WorkerObservationCursor::decode(&event.runtime_cursor) {
self.cursor = cursor;
}
return Ok(event);
}
loop {
match self.receiver.recv().await {
Ok(event)
if event.worker_ref == self.worker_ref
&& event.sequence > self.cursor.sequence =>
{
self.cursor =
WorkerObservationCursor::decode(&event.cursor).ok_or_else(|| {
ObservationProxyError::CursorMalformed(
"embedded runtime emitted a malformed cursor".into(),
)
})?;
return Ok(Self::map_event(&self.runtime_id, &self.worker_id, event));
}
Ok(_) => continue,
Err(tokio::sync::broadcast::error::RecvError::Lagged(_)) => {
return Err(ObservationProxyError::CursorUnknownOrExpired(
"embedded runtime observation backlog was exceeded".into(),
));
}
Err(tokio::sync::broadcast::error::RecvError::Closed) => {
return Err(ObservationProxyError::UpstreamDisconnect(
"embedded runtime observation stream closed".into(),
));
}
}
}
}
fn map_event(
runtime_id: &str,
worker_id: &str,
event: WorkerObservationEvent,
) -> RuntimeObservationUpstreamEvent {
RuntimeObservationUpstreamEvent {
runtime_id: runtime_id.to_string(),
worker_id: worker_id.to_string(),
runtime_cursor: event.cursor,
payload: event.payload,
}
}
}
#[cfg(test)]
mod tests {
use super::*;
fn sensitive_source() -> RuntimeObservationSourceConfig {
RuntimeObservationSourceConfig {
runtime_id: "remote-runtime".to_string(),
worker_id: "worker-1".to_string(),
endpoint: "wss://remote.example.invalid/private/workers/worker-1/events/ws".to_string(),
bearer_token: Some("top-secret-bearer-token".to_string()),
}
}
#[test]
fn runtime_observation_source_debug_redacts_endpoint_and_token() {
let debug = format!("{:?}", sensitive_source());
assert!(debug.contains("remote-runtime"));
assert!(debug.contains("worker-1"));
assert!(debug.contains("<backend-private>"));
assert!(debug.contains("<redacted>"));
for forbidden in [
"remote.example.invalid",
"/private/workers/worker-1/events/ws",
"top-secret-bearer-token",
] {
assert!(
!debug.contains(forbidden),
"debug leaked {forbidden}: {debug}"
);
}
}
#[test]
fn backend_observation_proxy_debug_redacts_contained_sources() {
let proxy = BackendObservationProxy::new(vec![sensitive_source()]);
let debug = format!("{proxy:?}");
assert!(debug.contains("BackendObservationProxy"));
assert!(debug.contains("source_count"));
for forbidden in [
"remote.example.invalid",
"/private/workers/worker-1/events/ws",
"top-secret-bearer-token",
] {
assert!(
!debug.contains(forbidden),
"debug leaked {forbidden}: {debug}"
);
}
}
}

File diff suppressed because it is too large Load Diff

View File

@ -11,7 +11,7 @@ use std::fmt;
use std::path::PathBuf;
use std::process::{Command, ExitCode};
use client::WorkerRuntimeCommand;
use client::{BackendRuntimeTarget, WorkerRuntimeCommand};
use memory_lint::{LintCliOptions, LintStatus};
use session_store::SegmentId;
use tui::{LaunchMode, LaunchOptions};
@ -286,6 +286,9 @@ fn parse_console_options(args: &[String]) -> Result<Mode, ParseError> {
let mut session = None;
let mut worker_name = None;
let mut socket_override = None;
let mut backend_url = None;
let mut runtime_id = None;
let mut worker_id = None;
let mut profile = None;
let mut i = 0;
@ -329,6 +332,36 @@ fn parse_console_options(args: &[String]) -> Result<Mode, ParseError> {
workspace_root = PathBuf::from(value);
i += 2;
}
"--backend" => {
let value = args
.get(i + 1)
.ok_or_else(|| ParseError("--backend requires a URL".to_string()))?;
if value.starts_with('-') || value.is_empty() {
return Err(ParseError("--backend requires a URL".to_string()));
}
backend_url = Some(value.clone());
i += 2;
}
"--runtime-id" | "--runtime" => {
let value = args
.get(i + 1)
.ok_or_else(|| ParseError("--runtime-id requires a value".to_string()))?;
if value.starts_with('-') || value.is_empty() {
return Err(ParseError("--runtime-id requires a value".to_string()));
}
runtime_id = Some(value.clone());
i += 2;
}
"--worker-id" => {
let value = args
.get(i + 1)
.ok_or_else(|| ParseError("--worker-id requires a value".to_string()))?;
if value.starts_with('-') || value.is_empty() {
return Err(ParseError("--worker-id requires a value".to_string()));
}
worker_id = Some(value.clone());
i += 2;
}
"--profile" => {
let value = args
.get(i + 1)
@ -371,6 +404,38 @@ fn parse_console_options(args: &[String]) -> Result<Mode, ParseError> {
workspace_root = PathBuf::from(value);
i += 1;
}
arg if arg.starts_with("--backend=") => {
let value = arg.trim_start_matches("--backend=");
if value.is_empty() {
return Err(ParseError("--backend requires a URL".to_string()));
}
backend_url = Some(value.to_string());
i += 1;
}
arg if arg.starts_with("--runtime-id=") => {
let value = arg.trim_start_matches("--runtime-id=");
if value.is_empty() {
return Err(ParseError("--runtime-id requires a value".to_string()));
}
runtime_id = Some(value.to_string());
i += 1;
}
arg if arg.starts_with("--runtime=") => {
let value = arg.trim_start_matches("--runtime=");
if value.is_empty() {
return Err(ParseError("--runtime-id requires a value".to_string()));
}
runtime_id = Some(value.to_string());
i += 1;
}
arg if arg.starts_with("--worker-id=") => {
let value = arg.trim_start_matches("--worker-id=");
if value.is_empty() {
return Err(ParseError("--worker-id requires a value".to_string()));
}
worker_id = Some(value.to_string());
i += 1;
}
arg if arg.starts_with("--profile=") => {
let value = arg.trim_start_matches("--profile=");
if value.is_empty() {
@ -390,6 +455,26 @@ fn parse_console_options(args: &[String]) -> Result<Mode, ParseError> {
}
}
let backend_target_present =
backend_url.is_some() || runtime_id.is_some() || worker_id.is_some();
if backend_target_present
&& (backend_url.is_none() || runtime_id.is_none() || worker_id.is_none())
{
return Err(ParseError(
"--backend, --runtime-id, and --worker-id are required together".to_string(),
));
}
if backend_target_present
&& (session.is_some()
|| worker_name.is_some()
|| socket_override.is_some()
|| profile.is_some())
{
return Err(ParseError(
"Backend Runtime API target cannot be combined with --worker, --socket, --session, or --profile".to_string(),
));
}
if profile.is_some() && (session.is_some() || socket_override.is_some()) {
return Err(ParseError(
"--profile can only be used for fresh spawn".to_string(),
@ -404,6 +489,19 @@ fn parse_console_options(args: &[String]) -> Result<Mode, ParseError> {
));
}
if backend_target_present {
return Ok(Mode::Tui {
mode: LaunchMode::BackendRuntime {
target: BackendRuntimeTarget::new(
backend_url.expect("checked by backend_target_present"),
runtime_id.expect("checked by backend_target_present"),
worker_id.expect("checked by backend_target_present"),
),
},
workspace_root,
});
}
if let Some(profile) = profile {
return Ok(Mode::Tui {
mode: LaunchMode::Spawn {
@ -901,7 +999,7 @@ fn parse_session_id(value: &str) -> Result<SegmentId, ParseError> {
fn print_help() {
println!(
"yoi\n\nUsage:\n yoi [OPTIONS]\n yoi resume [--workspace <PATH>] [--all]\n yoi panel [--workspace <PATH>]\n yoi keys\n yoi setup-model\n yoi worker [WORKER_OPTIONS]\n yoi worker delete <NAME> [--force] [--dry-run]\n yoi worker prune --older-than <DURATION> [--force] [--dry-run]\n yoi objective <COMMAND> [OPTIONS]\n yoi session analyze <SESSION_JSONL_PATH> --json\n yoi session prune --unreferenced [--older-than <DURATION>] [--force] [--dry-run]\n yoi ticket <COMMAND> [OPTIONS]\n yoi workspace serve [OPTIONS]\n yoi plugin new <rust-component-tool|rust-component-service> <PATH> [--json]\n yoi plugin check <PATH_OR_PACKAGE> [--json]\n yoi plugin pack <PATH> [--output <FILE>] [--json]\n yoi plugin list [--workspace <PATH>] [--profile <REF>] [--json]\n yoi plugin show <REF> [--workspace <PATH>] [--profile <REF>] [--json]\n yoi mcp list [--workspace <PATH>] [--profile <REF>] [--json]\n yoi mcp show <SERVER> [--workspace <PATH>] [--profile <REF>] [--json]\n yoi mcp tools|resources|prompts [SERVER] [--workspace <PATH>] [--profile <REF>] [--json]\n yoi memory lint [OPTIONS]\n\nSurfaces:\n Console Single-Worker chat/client surface (default, --worker, yoi resume)\n Dashboard Workspace cockpit/action surface (yoi panel)\n TUI Terminal UI implementation umbrella for Console and Dashboard\n\nOptions:\n --workspace <PATH> Runtime workspace root for default Console/--worker (defaults to cwd)\n --worker <NAME> Open the Worker Console by name (attach/restore/create)\n --socket <PATH> Attach a Worker Console to a specific socket with --worker\n --session <UUID> Resume a specific session segment in the Worker Console\n --profile <REF> Select a reusable Profile recipe\n -h, --help Print help\n"
"yoi\n\nUsage:\n yoi [OPTIONS]\n yoi resume [--workspace <PATH>] [--all]\n yoi panel [--workspace <PATH>]\n yoi keys\n yoi setup-model\n yoi worker [WORKER_OPTIONS]\n yoi worker delete <NAME> [--force] [--dry-run]\n yoi worker prune --older-than <DURATION> [--force] [--dry-run]\n yoi objective <COMMAND> [OPTIONS]\n yoi session analyze <SESSION_JSONL_PATH> --json\n yoi session prune --unreferenced [--older-than <DURATION>] [--force] [--dry-run]\n yoi ticket <COMMAND> [OPTIONS]\n yoi workspace serve [OPTIONS]\n yoi plugin new <rust-component-tool|rust-component-service> <PATH> [--json]\n yoi plugin check <PATH_OR_PACKAGE> [--json]\n yoi plugin pack <PATH> [--output <FILE>] [--json]\n yoi plugin list [--workspace <PATH>] [--profile <REF>] [--json]\n yoi plugin show <REF> [--workspace <PATH>] [--profile <REF>] [--json]\n yoi mcp list [--workspace <PATH>] [--profile <REF>] [--json]\n yoi mcp show <SERVER> [--workspace <PATH>] [--profile <REF>] [--json]\n yoi mcp tools|resources|prompts [SERVER] [--workspace <PATH>] [--profile <REF>] [--json]\n yoi memory lint [OPTIONS]\n\nSurfaces:\n Console Single-Worker chat/client surface (default, --worker, yoi resume, Backend Runtime target)\n Dashboard Workspace cockpit/action surface (yoi panel)\n TUI Terminal UI implementation umbrella for Console and Dashboard\n\nOptions:\n --workspace <PATH> Runtime workspace root for default Console/--worker (defaults to cwd)\n --worker <NAME> Open the Worker Console by name (attach/restore/create)\n --socket <PATH> Attach a Worker Console to a specific socket with --worker\n --session <UUID> Resume a specific session segment in the Worker Console\n --profile <REF> Select a reusable Profile recipe\n -h, --help Print help\n"
);
}
@ -945,6 +1043,59 @@ mod tests {
}
}
#[test]
fn parse_backend_runtime_target_mode() {
match parse_args_from([
"--backend",
"http://127.0.0.1:8787",
"--runtime-id",
"runtime-a",
"--worker-id",
"worker-b",
])
.unwrap()
{
Mode::Tui {
mode: LaunchMode::BackendRuntime { target },
..
} => {
assert_eq!(target.base_url, "http://127.0.0.1:8787");
assert_eq!(target.runtime_id, "runtime-a");
assert_eq!(target.worker_id, "worker-b");
}
_ => panic!("expected BackendRuntime mode"),
}
}
#[test]
fn parse_backend_runtime_target_requires_complete_identity() {
let err = parse_args_from(["--backend", "http://127.0.0.1:8787", "--worker-id", "w"])
.unwrap_err();
assert_eq!(
err.to_string(),
"--backend, --runtime-id, and --worker-id are required together"
);
}
#[test]
fn parse_backend_runtime_target_rejects_legacy_socket_mix() {
let err = parse_args_from([
"--backend",
"http://127.0.0.1:8787",
"--runtime-id",
"r",
"--worker-id",
"w",
"--worker",
"agent",
])
.unwrap_err();
assert_eq!(
err.to_string(),
"Backend Runtime API target cannot be combined with --worker, --socket, --session, or --profile"
);
}
#[test]
fn parse_bare_word_is_unknown_command() {
let err = parse_args_from(["agent"]).unwrap_err();

View File

@ -13,9 +13,9 @@ pkgs.mkShell {
];
shellHook = ''
if repo_root="$(git rev-parse --show-toplevel 2>/dev/null)"; then
export YOI_POD_RUNTIME_COMMAND="$repo_root/target/debug/yoi"
# export YOI_POD_RUNTIME_COMMAND="$repo_root/target/debug/yoi"
else
export YOI_POD_RUNTIME_COMMAND="$PWD/target/debug/yoi"
# export YOI_POD_RUNTIME_COMMAND="$PWD/target/debug/yoi"
fi
echo "dev-shell-loaded"
echo "YOI_POD_RUNTIME_COMMAND=$YOI_POD_RUNTIME_COMMAND"

Some files were not shown because too many files have changed in this diff Show More