Skip to content

feat: module configuration, scoped callers and moduleConfigs - #174

Draft
dlipicar wants to merge 5 commits into
feat/runtime-processfrom
feat/method-scopes
Draft

dlipicar wants to merge 5 commits into
feat/runtime-processfrom
feat/method-scopes

Conversation

@dlipicar

Copy link
Copy Markdown
Contributor

Part of the method-scoped grants and per-module configuration layer (feat/method-scopes). Stacked on #171 (feat/runtime-process); the diff shows only this layer. Relocked onto logos-protocol#101.

What changes

Module configuration: LogosModuleContext::configuration()

  • The generated glue exports logos_module_set_configuration(const char*).
    • The export is optional and looked up by name, like logos_module_set_runtime_delegate, so the module-impl-abi check is unaffected.
    • It is guarded MAJOR-aware on protocol 0.13, so unifdef can resolve it.
  • The export:
    • stores the host's document under the context lock;
    • refuses JSON it cannot parse;
    • refuses once the context has fired;
    • calls no lp_*.
  • The one-shot latch hands the document to the impl (_logos_codegen_::maybeSetConfiguration) before maybeSetContext. So onContextReady() already sees configuration().
  • The latch now checks and fires under that lock, so a race can't fire it twice.
  • The configuration never carries authority. What a caller may call comes from the access policy.

LogosCaller::scoped

  • True only when the caller document carries "scoped":true. The target's runtime writes that when the call passed a method-list grant for exactly this method (logos-protocol#101).
  • It is read only from a boolean true, on any arm that parses. A failed arm resets it with everything else.

not_authorised

  • The refusal code keeps its value through LpClient's error channel to the generated wrappers. A new test pins it.

LogosCore

  • Config::moduleConfigs maps each module name to one JSON document.
    • For a separate runtime it is sent as the module_config spawn key.
    • In-process it goes through logos_core_set_module_config.
  • logos_core_set_access_policy now returns int, and a refused policy throws like every other protected input. It is refused when malformed or when its mode is unknown.

Verification

  • macOS: checks.tests (399/399), checks.module-impl-abi and checks.generator-cli all pass.
  • CI runs on this PR.
  • Configuration arriving before onContextReady() is tested end to end downstream:
    • logos-module-loader-qt's native host fixture;
    • the test-modules probe module, driven by the logoscore-cli and logoscore-py suites.

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

📊 cpp-sdk doc-test report

The real accounts module, run through a logoscore daemon with the whole stack built against this commit of the C++ SDK — rendered alongside the commands actually run and their output (updated each run, commit a856b19):

Pages can take a minute to update after the run finishes.

@dlipicar
dlipicar force-pushed the feat/runtime-process branch from e106edb to 1cb7a74 Compare October 3, 2026 12:48
dlipicar and others added 5 commits October 3, 2026 11:09
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The generated glue exports logos_module_set_configuration, optional and
looked up by name like the runtime delegate (guarded on protocol 0.13). It
stores the host's document under the context lock, refuses JSON it cannot
parse and refuses once the context has fired; the one-shot latch sets it
before the context, so onContextReady() already sees it. The latch now
checks and fires under that lock, so a race cannot fire it twice.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
scoped is true only for "scoped":true in the caller document, which the
target's runtime writes when the call passed a method-list grant; a failed
arm resets it with everything else. A not_authorised refusal keeps its code
through LpClient's error channel.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
moduleConfigs (module name -> one JSON document) goes to a separate runtime
as the module_config spawn key, and in-process through
logos_core_set_module_config. logos_core_set_access_policy now returns int,
and a refusal throws like every other protected input.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dlipicar
dlipicar force-pushed the feat/method-scopes branch from 0d028fb to 314a0a8 Compare October 3, 2026 14:19

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant