Skip to content

grants: 🐛 Bound evidence reads and bind Orca lanes to their Run coordinator's grants - #281

Merged
yasyf merged 5 commits into
mainfrom
feat/grants-core-3
Oct 3, 2026
Merged

yasyf merged 5 commits into
mainfrom
feat/grants-core-3

Conversation

@yasyf

@yasyf yasyf commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Why

evidence reads must be bounded, using indexed owner turns or cc-transcript grep windows, never a whole-transcript scan.

Replaying the Slack hook against a 206 MB root transcript produced 6 evidence-read refusals in 54 runs at 18 parallel cold processes. The snapshot admission queue caused those refusals; the bridge hid the host's error. Separately, root_excerpt scanned the whole root transcript five times per event.

What

  • Limit root_excerpt to the trailing tail_bytes, defaulting to 16 MiB, starting at the first whole line. Older owner words reach grant judges through recorded words and ask records.
  • Share recorded(evt, kind) between OwnerWords and Asked. Both require unexpired, unrevoked records; previously, expired words records remained readable.
  • Report host error frames as snapshot host failed the request: <host error>. Admission limits stay unchanged. At 18 parallel processes, refusals still occur, now reported as snapshot admission queue exhausted.
  • Document the excerpt window, live-record requirement, root-prompt recording, and 7-day ask expiry; remove promises of whole-transcript access from docstrings.

Orca lanes

The root's ruling on the owner's answer ("Allow cross-root sharing by agents"): an Orca lane of the same Run reads the root's grants with no manual adopt.

  • The builtin general pack records the Orca terminal (ORCA_TERMINAL_HANDLE) of each attended session (CLAUDE_CODE_SESSION_ATTENDED=1) in a new orca_terminals table, once per session. A nested claude -p reports CLAUDE_CODE_SESSION_ATTENDED=0 and records nothing.
  • On a grants check in an Orca terminal, orca orchestration worker-list finds the dispatched worker for that terminal, and run-show gives the Run's coordinator terminal. The coordinator's session tree comes from the recorded terminal, and its grants are adopted into the lane's tree as logged adoptions with agent orca:<run>, so spends stay shared and appear in grant show.
  • The Run lookup is cached per session. A terminal with no dispatched worker is looked up again after 5 minutes. Outside Orca, or with no recorded coordinator, nothing binds and nothing errors.
  • Live check against this Mac's Orca: a running lane's terminal resolves to run_7715a23a5657 and its coordinator terminal; the coordinator's own terminal resolves to no Run.

Review fixes on the Orca binding:

  • Only spendable grants are adopted. The coordinator's recorded words and ask records stay in its tree, so a lane cannot mint a fresh budget from an approval the coordinator already spent; one approval spends once.
  • A lane pins the coordinator session it first bound to for each Run and coordinator terminal. When that terminal's record moves to another session, the lane adopts nothing more from it.
  • The Run binding is revalidated after 1 minute, and whenever the session's terminal changes, so a finished or moved worker stops adopting.
  • A stored grant's judge also reads the owner's words and ask records said after the grant was minted whose records have expired, so an expired record never ends a withdrawal while the grant stays usable. A withdrawal the judge sees revokes the grant.

Accepted risk: ORCA_TERMINAL_HANDLE and CLAUDE_CODE_SESSION_ATTENDED come from the session environment, and an agent that sets them on purpose can claim another terminal's binding or replace a terminal record. Hooks catch agent mistakes, not deliberate forgery, as with #278's forged-receipt ruling. The same limit means a coordinator terminal that starts an unrelated session before a lane first binds hands the lane that session, and a resumed original session does not reclaim its terminal record; both cases leave existing bindings refusing rather than lending.

Measurements

The same replay on the 206 MB transcript measured:

Excerpt time Before After
Single event, per call 0.17–0.19 s 0.01–0.03 s
Single event, total 0.9 s 0.07 s
18 parallel processes, median per call 0.27–0.30 s 0.01–0.02 s
18 parallel processes, maximum per call 1.13 s 0.05 s
18 parallel processes, total per event 1.4–1.8 s 0.07–0.08 s

Median wall time remained about 10 s, dominated by judge calls and process startup.

Tests

  • Added coverage for older recorded owner words, expired words records, excerpt windows starting mid-line or at a line boundary, and host error reporting.
  • Orca: the terminal record (attended only, once), a lane binding and spending a coordinator grant with a shared budget, no binding outside Orca, recorded words never adopted, a reused coordinator terminal lending nothing, TTL revalidation of the Run binding, and an expired withdrawal still reaching the judge.
  • 963 passed across test_grants.py, test_dispatch.py, test_public_api.py, test_context.py, test_snapshot_owner.py, and test_pack_graphite.py; 427 passed across the pack, inline, and lint suites.
  • Monorepo Slack hook inline tests: 392 of 392 passed (the suite at its current head).
  • All 6 replay excerpts matched the whole-file scan, retaining 5, 20, 20, 15, 5, and 5 events. Five replay verdicts matched expectations. notours was expected to allow; it also refused in both versions as the judge's reading of the ruling's “one-line” scope varied. Its excerpt was unchanged.

@yasyf yasyf changed the title grants: 🐛 Bound evidence reads to fixed windows and name the snapshot host's refusals grants: 🐛 Bound evidence reads and bind Orca lanes to their Run coordinator's grants Oct 3, 2026
yasyf added 5 commits October 2, 2026 23:15
… host's refusals

Limit root excerpts to a trailing 16 MiB window starting at a whole line.
Read older owner words from live recorded evidence; exclude expired records.
Report snapshot host errors without changing admission limits.
Update evidence docs and correct the documented ask expiry to 7 days.
Cover excerpt boundaries, recorded words, expiry, and host errors in tests.
Record each attended session's Orca terminal in the grant store, once per session.
Resolve a lane's Run and coordinator terminal with orca orchestration worker-list and run-show.
Adopt the coordinator tree's grants into the lane tree, logged as agent orca:<run>.
Cache the Run lookup per session; outside Orca nothing binds.
Scrub ambient Orca session variables in the test suite.
…ned, revalidated coordinator

Adopt only spendable grants, never the coordinator's recorded words or asks.
Pin the coordinator session per Run and terminal; a reused terminal lends nothing.
Revalidate the Run binding after one minute or a terminal change.
Pass expired owner records said after a grant to its judge, so a withdrawal never lapses.
Resolve a lane's dispatch with the sessions pack's worker_of and orca_json, which page Orca's
worker list unscoped and tolerate its page shapes, instead of a second Orca client.
Stub the binding in the sessions recheck test, which scripts each worker_of reply.
@yasyf
yasyf force-pushed the feat/grants-core-3 branch from 5fcbb11 to 8cccc06 Compare October 3, 2026 06:17
@yasyf
yasyf merged commit a06ae89 into main Oct 3, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant