feat(routing): compatible Decisions transport with durable shadow receipts - #6604
Merged
Merged
Conversation
Adds a small, off-by-default System One decision gate at the turn-loop entry. When SUPERFAST_ENABLED is set, a detached task asks a Jev-compatible decision endpoint about the user turn and only logs the derived route and latency through tracing. It never changes routing, never skips the model call, and fails open on any error, timeout, non-2xx, or malformed body. No heavy new dependency (uses the existing reqwest). Concept and reference implementation by Andrea Bruno, CC BY 4.0 (harness-superfast).
Contributor
Author
|
A short white paper explains this idea in plain terms, covering the problem and the design. You can read it here: https://github.com/Andrea-Bruno/harness-superfast The work is released under CC BY 4.0. It is free to use, change, and ship, including in commercial products. We only ask that if you adopt the idea or the code you keep a short credit to Andrea Bruno and a link to that page. |
…System One client
Finish the contributor path for Hmbown#6603 on this PR, against the 0.10.1 acceptance: reuse the existing shared transport, typed and bounded shadow-only outcomes, loopback integration tests for disabled / error / timeout / no-op, activation kept separate from spend. Lint failed on this PR: scripts/check-reqwest-builders.py rejects the bare `reqwest::Client::builder()` built per call in superfast.rs (Hmbown#6153 — the workspace builds reqwest with `rustls-no-provider`, so a bare builder can panic before any provider is installed). That per-call client was also a second HTTP stack beside `client::system_one`, which already serves the same `POST {base}/systemone` wire for the `[auto.router] kind = "decision"` router with auth, TLS, secret redaction and a one-attempt policy. - superfast.rs now builds its client with `CodewhaleClient::for_decision_route` (off the async worker, it resolves keys) and calls `system_one_decide` under the configured deadline. No reqwest use remains in the module. - Outcomes are typed: `ShadowOutcome::{Recommendation{route, latency_ms}, Failed{failure: AutoRouterFailure, latency_ms}}`, reusing the router's non-secret failure classes (NotRunnable, Timeout, Http{status}, InvalidAnswer, ...). Provider bodies and prompt text never enter it; the tracing log carries route, failure class and latency only. - Bounded input: only the latest user message is sent, truncated to 4,000 characters with the router's `truncate_for_auto_router` (now pub(crate)) and redacted with the client's model-bound secret set. - Parsing goes through the typed `SystemOneResponse`: `SystemOneAnswer` gains the `noul` field; a noul answer counts only when typed `noul` with a finite value in [0, 1], the chat intent only when typed `choice` with calibrated confidence. Thresholds are the contributor's. - Activation vs spend: `SUPERFAST_ENABLED` alone never picks an endpoint; `SUPERFAST_PROVIDER` (typesafe | openrouter) must name the route, and a missing/unknown provider or out-of-range `SUPERFAST_TIMEOUT_MS` is logged at warn and sends nothing (misconfiguration fails loud). `SUPERFAST_BASE_URL` points the TypeSafe route at a self-hosted Jev server. Known limits are written in the module doc. - The turn-loop hook passes `self.api_config` and drops the handle explicitly; it still fires only on step 0 and never waits. Tests (wiremock loopback, no provider spend): disabled gate starts no task and sends nothing; enabled gate posts one redacted, bounded body with the expected auth and question set and returns NeedsTool; HTTP 500 and a malformed body fail open as Http{500} / InvalidAnswer; a 3 s endpoint under a 100 ms deadline returns Timeout while spawning returns at once; no user text starts no task and a missing key is NotRunnable with zero requests; settings parsing and route derivation unit cases. Refs Hmbown#6603 Refs Hmbown#6604 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…-Bruno - docs/CONFIGURATION.md: the gate's environment settings, activation and spend boundaries, known limits, and the requested attribution and link to Andrea Bruno's harness-superfast (CC BY 4.0). - CHANGELOG.md 0.10.1: an Added entry for Hmbown#6603/Hmbown#6604 and a Contributors line; docs/CONTRIBUTORS.md and web/lib/release-credits.ts carry the same credit, which the Version drift contributor-credit check required (@Andrea-Bruno was on none of the three surfaces). - crates/tui/CHANGELOG.md regenerated by scripts/sync-changelog.sh. Checks: check-contributor-credit.py OK (9 contributors, all surfaces); sync-changelog.sh --check OK; check-feature-release-notes.sh OK (14 references); web vitest lib/public-copy + public-surface-contract + changelog 24 passed / 0 failed. Refs Hmbown#6603 Refs Hmbown#6604 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Refs Hmbown#6604 and Hmbown#6603. Preserve original contributor head 87ee835 and attribution before the bounded transport, answer validation and Engine usage/cancellation repairs. No new verification claim at this checkpoint. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…bown#6604) OpenRouter uses /api/alpha/decisions and TypeSafe /v1/systemone on the existing authenticated transport. Validate Choice, Noul and fractional Score against each request, retain provider usage on rejected policy answers, and bound request/response bodies. Preserve original contributor branch/authorship and off-by-default shadow behavior. Detached shadow calls capture the existing turn/session usage owner and lease before dispatch, obey cancellation, and settle usage or missing-coverage evidence through the same runtime ledger. Bounded raw-cost decision receipts persist in that ledger, including late responses, with deletion admission and turn_mutation intact. Existing child metadata and TurnRecord constructors/decoders are migrated without another event authority. Source checkpoint only: rustfmt and git diff --check passed. Focused Rust tests, npm test && npm run check:web, clippy, negative controls and fresh hosted exact-head Linux/macOS/Windows proof are pending. No Jev spend, native UI acceptance or release claim. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Repair the one missed TurnRecord shorthand initializer from the first compile. Add TypeSafe auth and shared permit control, bounded child metadata roundtrip, and existing cost diagnostics projection for persisted decision evidence. Source-only checkpoint; first focused build failed E0063 at runtime_threads.rs:12667 before running tests. npm test and check:web passed on source checkpoint 3185d9c: SDK16/0, extension host54/0, web629/0; wrapper summary output was truncated and is not counted here. Focused Rust rerun, clippy and negative controls pending. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Required usage counters are tracked separately from decoded provider evidence. Incomplete/zero counters produce explicit coverage gaps while bounded receipts retain actual raw cost and reported counters. Keep receipt-only and empty-owner batches on the existing projections, bound decision diagnostics to 64 entries, sanitize receipt labels, and move Auto decision client credential construction off Tokio workers. Repair the restart fixture to drop its existing Runtime store lock before reopening. Previous focused packet: 30 passed, 1 failed because the fixture reopened a still-active Runtime. npm test && npm run check:web passed; 767 actual tests passed, 0 failed (wrapper68, SDK16, host54, web629), with one bounded wrapper-only receipt rerun because initial TAP summary output was truncated. Blocking-call budget and rustfmt/diff checks passed. Final focused rerun, clippy, negative controls and hosted CI remain pending. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Focused governed source c3dd6d1 passed: test result: ok. 33 passed; 0 failed; 0 ignored; 0 measured; 14113 filtered out; finished in 1.63s. No executable changes in this documentation follow-up. npm767/0 and check:web passed on unchanged relevant frontend files. Negative controls, clippy and fresh hosted exact-head proof remain pending. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Focused governed source c3dd6d1: test result: ok. 33 passed; 0 failed; 0 ignored; 0 measured; 14113 filtered out; finished in 1.63s. Fix-off strict policy/endpoint/cancellation/durable-sink packet: test result: FAILED. 0 passed; 6 failed; 0 ignored; 0 measured; 14140 filtered out; finished in 0.71s. All original three source hashes restored, then test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 14140 filtered out; finished in 0.24s. npm test 767 passed/0 failed (68 wrapper,16 SDK,54 host,629 web); check:web passed. Documentation-only followup did not change executable/frontend source. Blocking-call budget passed 749 sites/209 files. Clippy, hosted CI and provider/native acceptance remain pending. No Jev provider spend. Followup preserves reported usage independently of wrong-shape policy fields using the existing bounded transport and receipt authorities. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…malformed Decode the bounded response envelope independently: malformed answer/model/id fields fail the existing strict policy guard, while valid reported usage and verbatim raw cost survive. Missing, malformed, overflowed or ambiguous token counts remain incomplete and cannot authorize a route or fabricate priced usage. Preserve the existing RuntimeUsageBatch/decision/session receipt authorities and request/response/metadata bounds. Regression fixtures cover rejected wrong-type fields, raw-cost retention, overflow/negative/string/duplicate/fractional counters, and actual loopback transport preserving the heuristic route with diagnostic cost and explicit incomplete-usage coverage. Code first then tests. Source rustfmt and diff check passed; affected governed tests, fix-off controls and clippy pending. Prior 33/0 and6/0 restoration receipts are intermediate evidence recorded at4856432fa, not this followup proof. No Jev provider spend. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Apply the CI clippy collapsible_if recommendation without changing behavior: decision presence and is_bounded remain required before existing diagnostic receipt projection. No new lint suppression or authority. Source17af5a0ce0 affected packet: test result: ok. 21 passed; 0 failed; 0 ignored; 0 measured; 14128 filtered out; finished in 1.49s. Fix-off envelope regressions: test result: FAILED. 0 passed; 3 failed; 0 ignored; 0 measured; 14146 filtered out; finished in 0.21s. Exact source restored: test result: ok. 3 passed; 0 failed; 0 ignored; 0 measured; 14146 filtered out; finished in 0.08s. First CI-policy clippy failed solely on this nested guard; failure preserved. Repeat clippy pending for this equivalent expression, while prior npm767/0 and check:web input tree remains unchanged. No provider spend. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Preserve main13925 protections and original Andrea-Bruno ancestry/attribution alongside the bounded Decisions API and existing usage/session receipt changes. The merge-tree preview was clean; no conflict resolution or alternate store/turn loop is introduced. Dated branch-source receipts:17af5a0ce0 affected21/0,fix-off0/3 failed then exact-restored3/0; source507872fb0a CI-policy all-targets/all-features/locked clippy passed2m10s after one equivalent guarded-condition style repair. Combined main tree requires fresh focused verification and clippy before original non-force push. No provider spend or hosted/native pass claimed. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…merge Preserve original PR Hmbown#6604 by @Andrea-Bruno, its CC-BY attribution and contributor credit. OpenRouter /api/alpha/decisions and TypeSafe /v1/systemone reuse the existing client admission/auth/transport. Validate Choice/Noul/Score strictly; retain independently reported raw cost on invalid policy or partial counters without authorizing a route hop or fabricating priced usage. Shadow settlement captures the existing origin lease before detach, honors cancellation, and journals bounded receipts through the existing runtime/session authority. Executable source:91c85474b920cbec14319423183a0a1ee57d7ebb Tree:c66d6107d814ba95d23aa25279648519898e6826 Ordinary signed main13925 merge retains current safety protections. Governed focused combined packet: test result: ok. 41 passed; 0 failed; 0 ignored; 0 measured; 14149 filtered out; finished in 2.12s. CI-policy TUI all-target/all-feature locked clippy: PASS (-D warnings plus repository's three standing allowances), no new source suppressions. npm test:767 passed/0 failed (68wrapper+16SDK+54host+629web). npm run check:web:PASS. Current blocking-calls budget:PASS. Dated controls retained: six fix-off tests fail/restored6 pass before the bounded envelope follow-up; affected21 pass, three envelope fix-off tests fail, exact restored3 pass. Combined main merge leaves the tested guard sources unchanged. Earlier failed lint remains archived; equivalent guard style repair passed before this combined qualification. Hosted exact-head Linux/macOS/Windows, native/GPUI display and authenticated provider acceptance are not claimed. No Jev spend; loopback/fixtures only. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Integrate verified main5be652d6efdc2f922d812718240b64e1956b3db9 into the original Hmbown#6604 contributor ancestry. Existing shared Config/force_http1 builder semantics and newly landed CLI/runtime repairs are retained. This is a committed checkpoint before transport compatibility review and affected proof; no new combined-tree verification claimed yet. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Ordinary-merge green main 5be652d onto the original contributor history. The SystemOne factory now inherits client.force_http1 and Config through the existing shared client builder; only those two arguments changed. Seven decision validation/accounting/ cancellation/owner-lease/session-journal guard files are byte-identical. Frozen source 54930fd, tree e322f39: actual transport, typed decisions, bounded invalid-envelope cost survival, cancel/owner lease, restart/deletion persistence and configured H2/HTTP1 fixtures: test result: ok. 46 passed; 0 failed; 0 ignored; 0 measured; 14160 filtered out; finished in 4.04s CI-policy all-targets/all-features locked TUI clippy passed (2m12s). npm test 774 passed, 0 failed and check:web passed at the same frozen head. Prior six plus three negative-control receipts remain dated source proof, with exact unchanged guard hashes in pr-6604.compat-source.json; they are not relabeled as reruns. Full new three-OS CI remains required after this original-branch push. No Jev/provider spend, native Windows, deployment or release acceptance. Artifacts: pr-6604.compat-qualification.json and pr-6604.transport-compat-proof.json. Signed-off-by: CodeWhale Bot <bot@codewhale.net>
…h the new ones main added the Hmbown#6745 and Hmbown#6761 contributor credits after this branch's last merge. Only the four credit surfaces conflicted; each keeps both lines (@Andrea-Bruno for Hmbown#6604/Hmbown#6603 and @aiapienthusiast for Hmbown#6761). Routing, transport and accounting source is unchanged by this merge. Local: scripts/sync-changelog.sh --check up to date; check-contributor-credit.py "Every contributor in the window is credited on all three surfaces"; vitest public-copy + public-surface-contract 18 passed / 0 failed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Hmbown
pushed a commit
that referenced
this pull request
Sep 30, 2026
The auth-required classifier matched the bare substring "401". Transport errors carry the URL they failed on, so the connection reset in streamable_http_reset_after_tool_call_post_is_not_replayed read as a 401 whenever the loopback port contained it (#6604's macOS run: port 50401, twice). On a live call that misclassification drops the connection, flags the server ◆ auth required and names an OAuth login the server never asked for — for any real server whose URL or port carries those digits. text_names_http_status matches a whole digit run outside URL tokens. The doctor's 401/403 hints use it too. Known limit: word signals such as "unauthorized" are still matched anywhere in the text. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Hmbown
pushed a commit
that referenced
this pull request
Oct 1, 2026
- runtime_threads.rs: the durability lane stages seed turns for one journaled write (seed_turns.push) where main still saved each; #6604 added TurnRecord.decision_receipts. The staged seed turn carries the new field (empty, as main's saved turn did). - CHANGELOG.md, docs/CONTRIBUTORS.md: both sides added credits and entries at the same spot (@zhuowp #6745 and @Andrea-Bruno #6604); both are kept, and the TUI changelog mirror is resynced. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Hmbown
pushed a commit
that referenced
this pull request
Oct 1, 2026
…lay tests Batch 10 on fbb4572: - turn_route_plan.rs test built RuntimeUsageBatch without the `decisions` field #6604 added (E0063 on the lib test build); an empty batch carries none. - codewhale-config: overlay_tickets_disable_expiry_and_source_changes_keep_ channel_rollback_floors failed once in a parallel crate run (the third ticket's publish returned false) and passed 2/2 isolated and 3/3 in full crate runs. The overlay is process-global; the other overlay test's configure() invalidated this test's ticket mid-sequence. Both overlay tests now hold one test-only mutex (#6698 shared-process class; nextest's per-process isolation hides it from hosted CI). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
Hmbown
pushed a commit
that referenced
this pull request
Oct 1, 2026
The 0.10.1 integration merge (fbb4572, via #6604 6008745) added `RuntimeUsageBatch::decisions`, but the turn_route_plan test that rebuilds a batch after `/new` still used the old field set, so `cargo test -p codewhale-tui --lib` failed to compile: error[E0063]: missing field `decisions` in initializer of `cost_status::RuntimeUsageBatch` (turn_route_plan.rs:388) The replayed batch carries no decision receipts, like its empty `drop_records`. Test-only; no production change. Evidence: the V1 targeted lib run compiled with this and gave test result: ok. 19 passed; 0 failed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: CodeWhale Bot <bot@codewhale.net>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The optional Decision Gate now uses the documented OpenRouter Decisions and TypeSafe SystemOne transports through the existing client. Shadow mode remains off by default. This completes the original contributor's feature while retaining its attribution and the existing Engine routing, cancellation and usage authority.
/api/alpha/decisions; TypeSafe uses/v1/systemone. Each retains its own credential and endpoint identity, shared admission budget and bounded response reader. TypeSafe costs stay on its own route rather than being attributed to a chat provider.Configuration and evidence behavior are documented in
docs/CONFIGURATION.md. The originalsuperfast.rsattribution and contributor credit remain intact. Andrea-Bruno's original commits remain ancestors; the repair was pushed non-force to the original branch.Validation on executable source
91c85474b920cbec14319423183a0a1ee57d7ebb, treec66d6107d814ba95d23aa25279648519898e6826, with signed evidence-only head27bfa2d2735d6266871168ae927c7165375f61ee:npm test: 767 passed, 0 failed (68 wrapper, 16 SDK, 54 extension host, 629 web).npm run check:web: PASS. Blocking-call budget: PASS.These are local macOS and hermetic loopback/fixture receipts. Fresh exact-head Linux, macOS and Windows hosted checks remain required before merge. Authenticated Decisions calls, provider spend, native/GPUI receipt display and release/package qualification are not claimed.
Wire references: OpenRouter Jev/Decisions and TypeSafe OpenAPI.
Refs #6603.
Current main transport compatibility qualification
Ordinary main5be652d6efdc2f922d812718240b64e1956b3db9 merged into the original contributor history. SystemOne inherits the existing Config/force_http1 client-builder semantics. Only the two factory arguments changed; seven decision validation, accounting, cancellation and durable-owner guard files remain byte-identical.
Frozen54930fd88293a40224525368e526ead938889ee9: 46 passed, 0 failed (4.04s), covering actual loopback decisions transport, strict Choice/Noul/Score and malformed usage envelopes, raw-cost persistence on rejected answers, cancellation and owner leases, session restart/deletion, configured HTTP/2 keepalive and HTTP/1 pin behavior. TUI all-targets/all-features locked clippy under the exact CI policy passed (2m12s). npm test 774 passed, 0 failed, check:web passed at the same frozen head.
Earlier six plus three negative controls remain dated evidence; unchanged guard hashes preserve their source binding. Fresh exact-head Linux/macOS/Windows CI remains required. No Jev/provider spend, native Windows, deployment or release acceptance is claimed.
Maintainer update, 2026-09-30: the head is now
88b0b6f22fca886c210d50676613ce3ad677357f, an ordinary merge of main568abae0into this branch. Only the four contributor-credit surfaces conflicted, and each keeps both lines. The routing, transport and accounting source is unchanged from the qualified54930fd88/b8257a154tree. The changelog mirror is in sync, the contributor-credit check passes, and the credit consumers ran 18/0. Its workflow definitions are identical to main before the run was approved. The supersededb8257a1CI run was cancelled after this push was verified. Positive exact-head Linux, macOS and Windows tests and doctests are still required before merge. No Jev/OpenRouter provider spend was made.