Skip to content

harness: System One, a decision loop over a typed action space (systemone, fifteenth base) - #225

Merged
richard-epsilla merged 16 commits into
mainfrom
systemone-base
Sep 20, 2026
Merged

richard-epsilla merged 16 commits into
mainfrom
systemone-base

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Supersedes #223 (same branch, same 15 commits plus the harness's own logo). Reopened under the bot author because the main ruleset needs an approving review from a writer other than the author, and #223's author is the only writer; the ruleset itself stays as it is.

What

The open-source System One Harness (v0.3.1) joins as the base systemone. It drives TypeSafe's Jev, a decision model that answers typed questions with probabilities and writes no text, through OpenRouter's decisions endpoint. Not a coding CLI: a loop over a finite action space.

  • Turn process runner/systemone_driver.py. The harness's MCP server is the environment, its tools compiled to actions each turn (observe and reset are the protocol; enumerable parameters compile; a tool that needs free text is named in the trace as not offered). With no server configured, the built-in order desk. disabledTools are withheld from the question itself. The desk's state and the loop's steps persist under the workspace for continuation.
  • Relay. The route is registered at the provider's API root, because OpenRouter serves decisions at /api/alpha/decisions and not under /api/v1 (404 measured 2026-09-19). Measured through the runner's own relay: six actions, 1.44 s; the relay's served-model and usage taps agree with the driver's report (typesafe/jev-1.13-20260917, 6304 in / 1410 out).
  • A new outcome in the turn contract. A result of subtype incomplete with a reason: the loop stopped because the model asked for help, or a destructive action never cleared its confidence bar. The runner reports the status, the poll body carries the reason, the gateway puts it in incomplete_details and retries nothing.
  • Gateway. jev-1.13 and jev-latest on OpenRouter's vendor table only (added after the shared copy so TokenRouter and Vercel do not inherit them), the systemone model and base catalogs, the OpenRouter wiring.
  • Console. The base, its mark, an Instructions label. Entrypoint. A pinned venv on the data volume, proven by import and version, rebuilt when the pin moves. CI. The runner job installs the same pin so the driver tests run.

Verified

  • runner/tests/test_systemone_backend.py (9) and gateway/tests/test_systemone_catalog.py (5): route roots, placeholder never the key, the event stream, continuation, the incomplete reason, disabling by omission, the catalog rules. Whole runner and gateway suites: 1035 passed; the 17 failures are test_media_mcp.py, which needs ffmpeg on the machine that ran them.
  • One live turn through _build_systemone and the driver against OpenRouter, as above.
  • The base on the OSS test VM as a derived image from 0.20.1 on a fresh volume: see the follow-up comment.

Notes in docs/support-matrix-notes.md ("systemone") and a line in docs/harness-verification.md on why the artifact scenario does not apply.

🤖 Generated with Claude Code

🤖 Generated with Claude Code

richard-epsilla and others added 16 commits September 19, 2026 18:24
… a typed action space (systemone)

The open-source System One Harness (HarnessRouter/SystemOneHarness, v0.1.1)
drives TypeSafe's Jev, a decision model that answers typed questions with
probabilities and writes no text. The base's turn process is
runner/systemone_driver.py: the harness's MCP server is the environment,
its tools compiled to actions each turn (the built-in order desk with none);
disabledTools are withheld from the question itself; the desk's state and
the loop's steps persist under the workspace for continuation. Events are
claude's stream-json, so the normaliser is the passthrough.

The route rides the loopback relay at the provider's API root, because
OpenRouter serves decisions at /api/alpha/decisions and not under /api/v1
(404 measured). One live turn: six actions, 1.44 s; the relay's served-model
and usage taps agree with the driver's own report (typesafe/jev-1.13-20260917,
6304 in / 1410 out).

New in the turn contract: a result of subtype "incomplete" with a "reason".
A loop that stops because the model asked for help, or a destructive action
never cleared its confidence bar, is neither a failure nor a step cap; the
runner reports the status, the poll body carries the reason, and the gateway
puts it in incomplete_details without retrying another connection.

Gateway: jev-1.13 and jev-latest on OpenRouter's table only, the systemone
model and base catalogs, the OpenRouter wiring. Console: the base, its mark
and an Instructions label. Entrypoint: a pinned venv on the data volume,
proven by import and version. CI installs the same pin for the driver tests.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…eaves no venv behind on failure

HR_SYSTEMONE_SPEC overrides the pip requirement (a mirror, a fork, a tree
copied into a derived image; the version proven is the pin either way). A
failed pip step used to leave the venv's python in place, and the executable
is the definition of installed, so the box reported the base available when
it could not run (fresh volume, 2026-09-19). Every failure path removes it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A follow-up that carries previous_response_id and no harness_id (the
protocol asks only for the former) was routed by the inherited model name,
and for a base whose models no chat backend serves that fell to the default
backend: a systemone follow-up asked claude for jev-1.13 (2026-09-19). The
session vertex records the harness the conversation started on; the
continuation takes it from there.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…tom format can drive

Every backend's model list carried the rows of custom-endpoint integrations
as unavailable, so a System One harness's picker offered claude-sonnet-4.6,
gpt-5.5 and four more as "(no provider)" (hr-test, 2026-09-19). On a chat
backend the greyed row explains why a configured model is not pickable
there; on a backend no custom format drives it is a chat model on a harness
that cannot use one. Both the global catalog and the per-harness view now
ask _custom_can_drive first.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…e says so

A skill is prose an agent reads and scripts it runs from a shell, and each
built-in needs free text (an image prompt, a document's content, HTML for a
PDF). A System One model chooses among offered actions and writes nothing,
so a harness on this base showed three skills enabled that could never act
(hr-test, 2026-09-19). The base declares "skills": False in the catalog;
the bases endpoint offers none and reports takesSkills; a turn mounts none
for the built-in harness and for a fork alike; the settings page replaces
the Skills list with one sentence on where guidance and scripts go instead.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
0.2.0 adds the browser environment on Browser Use and moves to the 2.x MCP
SDK. The base's venv is its own on the data volume, so the SDK major there
is independent of the runner's pin.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The venv installs the browser extra (Browser Use) and a Playwright
Chromium beside it on the data volume, world-readable, with
PLAYWRIGHT_BROWSERS_PATH exported for every session process: the image
ships no browser and a session uid cannot read root's cache. That is what
the browser environment and the Super Mario starter kit's environment run
on. Pins move to 0.2.1 (meta.risk for tools, canvas mode).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ner, not once per volume

The System One base's Chromium lives on the data volume, but the libraries it links against were
installed by `playwright install --with-deps` into the container that did the first run and
nowhere else. A container recreated over that volume (a new image version, a redeploy) had the
binary and none of its libraries: libatk, libatspi and libXcomposite "not found", every launch
dead before CDP came up, and every run of the Super Mario kit failing at reset. Measured on the
test box after a redeploy.

The libraries are now their own step, keyed on a marker in the container's own filesystem: taken
on the first install, and on every start that finds the venv already there. A failure on a later
start is a warning that names the consequence and is retried on the next start; on the first
install it fails the install, as a browser that cannot start should.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Its actions are its environment's: the tools of the MCP server the harness configures, compiled
at the start of every turn. Listing the order desk's six actions in the base catalog showed them
on the Super Mario harness as "built into System One", enabled, while that harness never offers
them (its environment is the kit's plugin). The order desk stays what the loop runs without a
server, as a demonstration; a tool disabled on a harness is still withheld by omission from the
question the model answers, whatever environment offers it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
A kit knows how long its turns run: a game played several decisions a second needs more steps
than a document does. kit.json harness.max_step and harness.timeout_seconds now reach the
HarnessBody a launch builds; absent, the base's defaults stand.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The extra wants mcp 2.1 and the runner pins 1.28.1; the tests use the recorded
provider and the built-in order environment, and the MCP client is imported only
when an MCP environment is opened. In the image the harness has its own
environment on the volume, so nothing there changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The System One Harness now has a logo of its own (assets/logo.png in its
repository); the placeholder SVG goes, and the console's base catalog shows
the mark at 512 by 512, the size the largest existing base logo ships at.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
unified-harness-protocol Ready Ready Preview Sep 20, 2026 10:39am UTC

Request Review

@richard-epsilla richard-epsilla left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the integration surface against the base pattern: pinned venv on the volume with an import proof and no venv left behind on failure, Chromium's libraries per container, the driver holds a one-turn relay token and never the provider key, skills withheld from a base that cannot read them, continuations routed by the session's harness. Verified by the System One session on hr-test with the Super Mario kit; checks green on the runner job installing the same pin.

@richard-epsilla
richard-epsilla merged commit 304cb1e into main Sep 20, 2026
8 checks passed
@richard-epsilla
richard-epsilla deleted the systemone-base branch September 20, 2026 10:41

This branch was successfully deployed

1 active deployment
Preview — 53cbfb24 Deployed Sep 20, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant