Conversation
This was referenced Sep 25, 2026
Draft
📊 cpp-sdk doc-test reportThe real accounts module, run through a logoscore daemon with the whole stack built against this commit of the C++ SDK — rendered alongside the commands actually run and their output (updated each run, commit Pages can take a minute to update after the run finishes. |
LogosCore::Config::tokenListener installs liblogos' logos_core_set_token_listener() before start() and removes it before cleanup. An embedder whose modules calls read their own token store (a Qt host's TokenManager) mirrors core's module tokens from it, instead of relying on core sharing that store. The listener is removed before logos_core_cleanup(); liblogos waits out a running call on removal, so the std::function can be destroyed after it. A throwing listener is swallowed rather than unwound into liblogos. Tests: the stub core records the install before start and the removal before cleanup, and a token it reports reaches the listener; no listener means no call. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ntract - Config gains bundledModulesDirs, placementPolicyJson and shellName, the protected input logos-liblogos#227 takes before start. A refused one throws std::invalid_argument after cleaning up. - With a shell name, start() takes the shell binding (when capability_module is the token authority). Load, unload, refresh, the module lists and the stats then go through core_service as that identity; admitConsumer() and retireConsumer() admit UI plugins; shellCredential() hands the identity to a co-process or a Qt LogosAPI. Without a binding the C API serves, as before. - tokenListener is deprecated: a runtime whose capability_module is the authority saves no tokens. - cpp/core_service.lidl is core_service's contract, installed at share/logos. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Mirrors logos_core_set_package_config (logos-liblogos#227): the runtime applies package_manager's directories and signature policy as it loads, since a shell calling as itself can no longer set them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
dlipicar
force-pushed
the
feat/runtime-delegate-export
branch
from
October 3, 2026 12:46
4e5f8c8 to
cb91ad8
Compare
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
dlipicar
force-pushed
the
feat/core-service-client
branch
from
October 3, 2026 12:47
5e3245d to
18c224c
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Phase 7 of the runtime-control plan:
logos::host::LogosCorecan act as a shell, a named consumer of the runtime, instead of reaching modules through the C API and a mirrored token store.Stacked on #168 (
feat/runtime-delegate-export). It also merges #167 (feat/core-token-listener, d9617aa), because the apps moving to this API still use #167's token listener during the transition. The diff therefore shows #167's two files as well.What changes in
logos_host_core.hProtected input.
Configgains:bundledModulesDirsplacementPolicyJsonshellNameThis is the input feat: one token authority, core_service embedded in liblogos, and the shell binding logos-liblogos#227 takes before start. If liblogos refuses one, the constructor cleans up and throws
std::invalid_argument.The shell binding. With a
shellName,start()takes liblogos' shell binding. It gets one only when capability_module runs in-process as the token authority. From then on:loadModule,unloadModule,refreshModules,knownModules,loadedModulesandallStats/statsgo throughcore_serviceas that identity, with per-call deadlines (120 s for lifecycle calls, 15 s for queries).LogosLoadDepsmaps ontoloadModule's newdepsargument.admitConsumer(name)returns the credential capability minted for a UI plugin;retireConsumer(name)ends that consumer.shellCredential()hands the shell identity to a co-process or to a QtLogosAPI.shellBinding()is for calls and subscriptions this class does not wrap.Without a binding, the C API serves exactly as before, so a host can set
shellNamewhatever mode the runtime runs in.Deprecated:
tokenListener. Once capability_module is the authority, core saves no tokens.Mirror.
logos_core_set_bundled_modules_dirs,logos_core_set_placement_policy,logos_core_set_shell_identity,logos_core_take_shell_bindingandlogos_consumer_*. As with feat: let a host observe the tokens core saves #167, a host needs the liblogos that exports them (#227).cpp/core_service.lidlThis is core_service's contract: every method and its scope, the answer shapes, and the
moduleStateChangedandmodule_eventevents. It is installed atshare/logos/core_service.lidl.logos-cpp-generator --lidlparses it and generates a client.Tests
tests/sdk/test_logos_host_core.cppstubs the new entry points and adds seven cases:macOS:
checks.testspasses 394/394.🤖 Generated with Claude Code