# Agent runtime guide
Owns preparation, prompt/replay projection, provider turns, tool lifecycle and continuation.
## Where to look
| Run request/session/output types | `run_request.rs`, `session.rs`, `output.rs`; facade: `../agent.rs` |
| Orchestration and continuation | `runner.rs`, `turn_run.rs`, `continuation.rs` |
| Provider/auth/tool/hook/title preparation | `runner/preparation.rs` |
| Auto-compaction and optional Jev decisions | `runner/auto_compaction.rs`, `compaction_timing.rs`, `completion.rs`, `completion_verification.rs` |
| Stream acceptance and incremental context | `provider_stream.rs`, `provider_stream/context_projection.rs`, `turn_state.rs` |
| Tool ordering and durable records | `tool_lifecycle.rs`, `tool_continuation.rs`, `session_persistence.rs`; helpers: `tool_lifecycle/` |
| Prompt sources, cache identity and tool advertising | `prompt.rs`, `prompt_cache_key.rs`, `tool_advertising.rs`, `titles.rs` |
| Review tags, directory instructions, steering/recovery | `prompt_injections.rs`, `subdir_instructions.rs`, `steering.rs`, `recovery.rs` |
| Guarded Code Mode host calls | `code_mode.rs`; sandbox guide: `../code_mode/AGENTS.md` |
| Failed-search context diagnostics | `tool_result_diagnostics.rs` |
## Local contracts
- Preparation selects normal-run provider; `../providers/factory.rs` constructs it. Auto-compaction surrounds the existing request loop.
- Preflight token projection is single-use for first non-compacted execution. Rebuild/validate replay and compare the complete projection request before reuse; retain fresh diagnostics and invalidate on provider/session/generation changes.
- Stream acceptance belongs in `provider_stream.rs`; terminal partial-text recording in `session_persistence.rs`. Accepted text survives cancellation/failure for replay; rejected sink deltas never enter accumulated output.
- Steering is delivered at continuation boundaries and acknowledged only after required persistence. Flush assistant completion before tools; preserve call/result identity and order across retries.
- Standalone `#diff-changes` is allowed only in root user input or consumed steering, not internal/subagent prompts. Expand unresolved comments once, without Bash, changed code or file list. Reanchor saved paths without scanning worktree, report tag failures and persist expanded prompts. Later comment resolution cannot rewrite prior messages.
- Persist dispatched `execution_effects` in the same required tool-result append, including partial edit failures. Codex routing context belongs to execution and is shared only across requests/retries within that run.
- Code Mode reuses guarded tools, hooks, cancellation and nested persistence; sandbox limits/evidence belong to its sibling guide, not a second dispatch path.
- Keep raw tool output local and redact through storage. Provider overlays include validated duplicate-skill references, prompt-injection protection and empty failed grep/ffgrep diagnostics (stderr before stdout); never rewrite stored results.
- Persist protected results as pending before network assessment; append `ToolResultAssessment` with the same unique result ID before delivery. Background events may intervene.
- Skill-read provenance requires whole projected-request token counts before budget checks. Anthropic calibration compares projections, not raw suffixes; Claude subscription also enforces uncalibrated estimate so overflow reaches auto-compaction.