Skip to content

feat(sdk): store + sources + lockfile + trust + bridge ops - #73

Merged
devin-ai-integration[bot] merged 6 commits into
v2from
feat/sdk-core
Oct 8, 2026
Merged

devin-ai-integration[bot] merged 6 commits into
v2from
feat/sdk-core

Conversation

@espetro

@espetro espetro commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

Implements packages/sdk — the isomorphic core of the AnyHarness store / trust / bridge layer (workstream W8 of .agents/plans/2026-10-07-v2-foundation.md, Wave 2). Everything goes through injected StorePorts; the package has zero node:* imports and zero runtime deps, so the same code ships in the harness binary, browser bundles, and worker runtimes.

Changes

Ports & types — FsPort / ExecPort / McpPort contracts (O_EXCL createExclusive, atomic rename, lstat stat, symlink? fallback contract) and the pinned bridge/lockfile/trust types verbatim from spec/bridge/operations.md + spec/lockfile.md + spec/trust.md.

Store — createStore(root, ports) over ~/.agents/:

  • install(source, opts?) — resolveSource spellings (git/github/local/registry, #ref fragments, monorepo subpaths), local copy or git clone→fetch→checkout→rev-parse pin, staging through harness/tmp/ under the .lock mutex, manifest inspect, collision checks (incl. refusing to shadow foreign skills/<name>), SRI integrity, capability grant, dev.anyharness/setup gated by trust policy + approveExec callback, mcp.json merge
  • remove / setEnabled / list / get — lockfile-driven, enabled flag persisted
  • materialize — skill components to shared ~/.agents/skills/ (§5.1 default) or inline files[].content|contentBase64 for storage-less hosts; integrity-verified first
  • verify — §4 SRI tree digest recomputation; doctor — lockfile-vs-filesystem/audit/mcp reconciliation findings
  • extensions.lock (sorted 2-space JSON, corrupt→preserve aside + lockfile.corrupt audit, version>1 refuse) + audit.log closed-enum JSONL

Trust — config.toml [policy] eval with spec §4.1 defaults (exec.*=ask, nonInteractive=deny, empty source lists), deny-first source globs, agent ask→deny unless allowlisted, audit events for every trust-relevant action.

Bridge — handleBridgeRequest(store, req[, session]) dispatching all 8 ops over JSON-RPC 2.0: capabilities.negotiate (once-per-session latch, -32002 gate, version intersection), extensions.list/get, hooks.invoke (hook-event + slots.exec + policy gating, streamed hook.progress/hook.delta notifications), commands.resolve, skills.materialize, tools.call (via optional McpPort), events.notify. Full -32001..-32012/-32800 error-kind mapping.

Testing — @any-harness/sdk/testing subpath: in-memory FsPort/ExecPort fakes (symlinks, exclusive create, exec handlers) used by the 59-test vitest suite.

Test plan

  • pnpm -F @any-harness/sdk test — 59 tests, 10 files, all green
  • pnpm -F @any-harness/sdk exec tsc --noEmit — clean
  • rg 'node:' packages/sdk/src — empty (isomorphic rule verified literally)
  • Capability matrix updated (if adapter behaviour changed)
  • Linked to a refined issue in Project 14

Notes

  • Store also exposes additive helpers beyond the pinned method set (get, policy, auditLog, subscribe, readLock) — pinned names verbatim, additions documented in the session report.
  • LockEntry.enabled is a new additive field: the bridge's Extension.enabled needed a persisted home the lockfile schema doesn't declare.
  • tools.call needs a real MCP transport; the sdk answers -32003/-32010 until a host injects McpPort (v0 grants mcp: external|none, never managed).
  • Detailed deviations/open questions are in the W8 report attached to the orchestrating session.

Link to Devin session: https://app.devin.ai/sessions/7f3725978b804442ace5bd12ed349a99
Open in Devin Desktop: https://app.devin.ai/desktop/session/7f3725978b804442ace5bd12ed349a99?variant=devin
Requested by: @espetro

FsPort/ExecPort/McpPort contracts, pinned bridge+lockfile+trust types,
pure-TS sha256 (SRI), path/semver/glob/toml/frontmatter helpers. Ambient
cross-runtime globals declared in ports.ts; zero node builtins.
…ty, policy, audit, mcp merge, manifest

Sibling-tmp+rename atomic writes, O_EXCL advisory lock with stale-break,
extensions.lock read/write (corrupt-aside, sorted 2-space), §4 SRI tree
digest, config.toml trust policy eval, JSONL audit log, mcp.json
merge-only writer, Agent Plugins manifest parse+inspect.
resolveSource (git/github/local/registry spellings, refs, monorepo
subpaths) and createStore over ~/.agents/: install (local copy / git
clone+pin, staging, collisions, SRI, mcp merge, setup policy), remove,
setEnabled, materialize (shared skills default §5.1 + inline), verify,
doctor.
capabilities.negotiate handshake (-32001/-32002/-32602 paths), per-store
default session + createBridgeSession for daemons, kind/slot capability
narrowing, extensions.list/get, hooks.invoke (policy+exec gating,
streaming notifications), commands.resolve, skills.materialize,
tools.call (mcp port), events.notify notifications.
testing.ts memfs/memexec (symlinks, createExclusive, exec handlers) and
the pinned export surface incl. ./testing subpath.
@devin-ai-integration

Copy link
Copy Markdown

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot was not present after the first check poll, so that signal was skipped; no approval-policy files apply, and there are no existing review findings that require human attention. This is a non-blocking approval from the Cursor Approval Agent.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@devin-ai-integration
devin-ai-integration Bot merged commit f1377dd into v2 Oct 8, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant