Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
e46c8a8
feat(canonical): sign attestations with a key held elsewhere
geekgonecrazy Sep 24, 2026
c643ed7
feat(intent): attest with a key held elsewhere
geekgonecrazy Sep 24, 2026
8f55095
fix(agent): never record agent work under the human's key
geekgonecrazy Sep 24, 2026
d06dee6
feat(token): name the server a token is for (aud)
geekgonecrazy Sep 24, 2026
238384f
feat(repository): render a view's tree without touching disk
geekgonecrazy Sep 24, 2026
ac56c30
Never treat a sandbox's pointer as untracked
geekgonecrazy Sep 24, 2026
5270b04
Reach a repository's owner from a remote sandbox, over the same protocol
geekgonecrazy Sep 24, 2026
cfa915d
Record in a remote sandbox's cache exactly as on the repository
geekgonecrazy Sep 24, 2026
62ebab7
Record in a remote sandbox and land the change through the owner
geekgonecrazy Sep 24, 2026
12bccdd
Read a remote sandbox's recorded state: diff, restore, log
geekgonecrazy Sep 24, 2026
f1872bb
Remote sandboxes inside Repository: any caller records, and provenanc…
geekgonecrazy Sep 24, 2026
42e12cc
A remote sandbox's cache takes its view's vault
geekgonecrazy Sep 24, 2026
081e6eb
Draft views: render them as themselves, and index their vault
geekgonecrazy Sep 24, 2026
76aef1d
Stage and seal a view as it renders
geekgonecrazy Sep 25, 2026
3d20044
Let the owner's iroh endpoints bind IPv4 only
geekgonecrazy Sep 25, 2026
fd840db
Merge dev: Ed25519 signing for recorded changes
geekgonecrazy Sep 26, 2026
3e7ca25
fix(remote-sandbox): five ways a sandbox could be wrong, wrong again,…
geekgonecrazy Sep 28, 2026
9b7defc
refactor(wasm): the wasm crate is atomic-wasm
geekgonecrazy Sep 28, 2026
1cf8ab6
test(remote-sandbox): several sandboxes at once, and the two bugs it …
geekgonecrazy Sep 28, 2026
3443cd4
test(remote-sandbox): 20 sandboxes at once, and the working tree they…
geekgonecrazy Sep 28, 2026
6b8c345
fix(remote-sandbox): the owner writes a submitted change into the wor…
geekgonecrazy Sep 28, 2026
4315ce5
fix(remote-sandbox): a slice's CRDT rows cross views; the graph rows …
geekgonecrazy Sep 28, 2026
677d300
test(remote-sandbox): size the stress tests for CI, and measure the c…
geekgonecrazy Sep 28, 2026
1f175ae
Merge remote-tracking branch 'origin/dev' into feat/remote-sandboxes
geekgonecrazy Sep 28, 2026
ce2b280
fix(remote-sandbox): a cache holds the view as it is, not flattened
geekgonecrazy Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -340,6 +340,37 @@ Human: "I can review that!"
| `EdgeFlags` | 1 byte | Bitflags: BLOCK, PSEUDO, FOLDER, PARENT, DELETED |
| `SerializedGraphEdge` | 24 bytes | Compact edge: (flags+pos, change, introduced_by) |

#### Endianness: keys that sort are big-endian, opaque values are little-endian

The storage layer encodes integers two ways, and the rule is whether the
bytes ever get sorted:

| Encoded as | Endian | Which |
|------------|--------|-------|
| **Big-endian** | BE | B-tree **keys** that are range-scanned: `encode_vertex`, `encode_inode_vertex`, `encode_position`, `encode_view_seq` (`pristine/tables.rs`) |
| **Little-endian** | LE | Values and ids only ever looked up by exact key: `SerializedGraphEdge`, and the CRDT `TrunkId`/`BranchId`/`LeafId` (`crdt/tables.rs`, `crdt/ids.rs`) |

BE is load-bearing for the keys: byte order has to match numeric order or a
range scan means nothing. `export_graph_slice` depends on it —

```rust
let lo = encode_inode_vertex(inode, 0, 0, 0);
let hi = encode_inode_vertex(inode, u64::MAX, u64::MAX, u64::MAX);
for row in inode_graph.range::<&[u8; 32]>(&lo..=&hi)? { ... } // every row for one inode
```

For the LE side, sorting never happens, so byte order costs nothing and there
is no reason to pay for BE.

**The two meet in the same files**, so match the *writer*, never the
neighbours. `export_graph_slice` decodes graph vertex keys (BE) and CRDT ids
(LE) within a few lines of each other, which is exactly how a BE decode of a
LE id shipped unnoticed. Decode an id with its own type's `from_bytes`
(`TrunkId::from_bytes`, `BranchId::from_bytes`, `LeafId::from_bytes`) instead
of slicing `id[0..8]` by hand, so the two sides cannot drift. `id_rows`
`debug_assert`s on an id with no `EXTERNAL` row, because a mis-decoded id is
indistinguishable from an absent one at runtime.

### Hash Type Design

Following the original Atomic project, `Hash` is a **type alias** for `Merkle`:
Expand Down
Loading
Loading