Expand description
Bounded wire contract for the local Gate4Agent node.
Modules§
- correlation
- Opaque correlation ids and tool-class labels the node mints for a session’s provider events.
Structs§
- Adapter
Contract Revision - Adapter
Id - Stable identifier for one provider adapter implementation.
- AgentId
- Stable, extensible identifier for an agent CLI.
- Agent
Progress Attention V1 - Agent
Progress Usage V1 - Agent
Progress V1 - Agent
Stream Chunk V1 - One chunk of the outbound agent content stream – the
agent-stream-events-v1capability’s push channel, mirroringNodeEvent::TerminalFrameexactly: its own subscription, its own type, no resync promise.source_sequenceorders chunks within one provider source, the same number the provider event carries. - Agent
Stream Interaction Option V1 - One selectable answer to an
InteractionPromptchunk – an ACP permission option, named by the provider rather than invented here. - Agent
Stream Named IdV1 - One named catalog entry – a selectable session mode or model on the
ModeCatalog/ModelCatalogchunk kinds.idis whatSetSessionMode/SetSessionModeltake back. - Architecture
Id - Capability
Id - Client
Authentication - Client
Compatibility Offer - Client
Hello - Context
Pack Bytes Read - Context
Pack Lineage Receipt - Controller
State - Delivery
Blob Chunk HexV1 - Delivery
Blob Digest V1 - Delivery
Blob Receipt V1 - Delivery
Bundle Manifest V2 - Delivery
Commit Receipt V1 - Delivery
Component V2 - Delivery
Digest Error - Delivery
Manifest Digest V2 - Delivery
Relative Path Error - Delivery
Relative Path V2 - Delivery
Stage Id - Delivery
Stage IdError - GitCommit
Details - GitCommit
Summary - GitDiff
- GitDiff
Request - GitHistory
Page - GitObject
Id - GitObject
IdError - GitSnapshot
- GitStatus
Entry - GitWorktree
Snapshot - Harness
McpActivation Digest - Harness
McpCall Id - Harness
McpLaunch Trace V1 - Optional stdio trace opt-in of a harness-MCP launch: when the node process
has a non-empty environment variable named
dir_env, the node adds an environment entry namedenvholding a trace-file path under that directory. - Harness
McpLaunch V1 - How the node exposes a reserved harness-MCP door to the provider session it spawns – every name in it is the CALLER’s, never the node’s.
- Harness
McpLocal Request V1 - Harness
McpLocal Token - Harness
McpOpaque Payload V1 - An opaque harness-MCP payload.
- Harness
McpReply Chunk HexV1 - Harness
McpReservation Id - History
Candidate Summary - Host
Descriptor - Host
Directory Entry - Host
Directory Listing - Launch
Inventory - Managed
Session Record - Managed
Worktree GitScope - Managed
Worktree Identifier Error - Managed
Worktree Lease Id - Managed
Worktree Lease Snapshot - Managed
Worktree Profile Summary - Managed
Worktree Spawn Receipt - Managed
Worktree Spawn Request - Managed
Worktree Spawn Request V2 - Native
Session Catalog Entry - Native
Session Catalog Page - Native
Session Catalog Route - Native
Session Catalog Summary - Native
Session External Group - Native
Session Selection - Negotiated
Node Compatibility - Node
Call Home Announce - The first frame on a CALL-HOME connection, and the only frame this protocol adds for it: the node announcing which node it is.
- Node
Compatibility Support - Node
Cursor - Node
Event Envelope - Node
Failure - Node
Hello - NodeId
- Node
Incarnation Id - Node
Snapshot - Opaque
Host Path - Operating
System Id - Path
Semantics - Protocol
Range - Provider
Adapter Contract Support - Provider
Config Choice - One selectable value of a
select-kindProviderConfigOption.value_jsonis the choice’s value pre-serialized to JSON text (this crate is a pure data contract and does not depend onserde_json; seeProviderConfigOption::value_jsonfor the same convention applied to the option’s own current value). - Provider
Config Option - One session configuration setting – the mechanism ACP uses to change
model, reasoning effort, and similar settings, superseding session
modes.
ProviderEvent::ConfigOptionsUpdatedalways carries the FULL current set, never a delta. - Provider
Contract Revision - Provider
Contract Support - Provider
Runtime Contract Id - Provider
Runtime Status - Provider
Runtime Statuses - Provider
Runtime Version - Repository
Path - Request
Envelope - Resolved
Bundle Receipt - Resolved
Context Pack Receipt - Resolved
Environment Profile Receipt - Resolved environment-profile identity echoed on spawn receipts.
- Resolved
Harness McpProxy Receipt V1 - Resolved
Spawn Receipt - Resolved
Spawn Spec - Response
Envelope - Server
Challenge - Session
Address - Session
Agent Progress - Session
History Summary V1 - Aggregate facts about one session record’s native history: how many messages and completed turns it holds and what it cost, without any of its content.
- Session
Key - Session
Record Id - Session
Record Preview - Session
Record Retention Config - Node-local policy for retiring dead
ManagedSessionState::Unavailablerecords so a long-lived node’s durable state does not grow forever. Both fields default to0(disabled) – a freshly started node must never silently delete a record until an operator has chosen real values via--session-record-retention-age-ms/--session-record-retention-keep. Never applies toLive,IdentityPending, orDormantrecords: onlyUnavailableis both inert (noactive_session) and not resumable. - Session
Task Binding V1 - Spawn
Browser Profile Id - Opaque dig2browser station browserProfile id under node-local
profiles_root. - Spawn
Bundle Digest - Spawn
Bundle Digest Error - Spawn
Bundle Id - Spawn
Bundle Revision - Spawn
Context Digest - Spawn
Context Digest Error - Spawn
Context Id - Spawn
Deadline Ms - Spawn
Environment Profile Id - Spawn
Environment Profile Revision - Spawn
Idempotency Key - Spawn
Network Allowlist Id - Opaque node-local network allowlist policy id (station axis).
- Spawn
Overrides - Spawn-time overrides for an accepted
SpawnSpec. - Spawn
Profile Defaults - Spawn
Profile Id - Spawn
Profile Revision - Spawn
Profile Summary - Spawn
Prompt - Spawn
Prompt Metadata - Spawn
Required Capabilities - Spawn
Resolution Provenance - Spawn
Spec - Spawn
Target - State
Schema Support - TaskId
- Task
IdError - Workspace
Entry - Workspace
File Read - Workspace
File Revision - Workspace
File Revision Error - Workspace
Id - Workspace
Inspection - Workspace
Inspection Truncation V1 - Additive: records why (if at all) a
WorkspaceInspectionwas cut short by the node’s own inner walk+git time/entry budget (GATE4AGENT_NODE_WORKSPACE_INSPECTION_BUDGET_MS/GATE4AGENT_NODE_WORKSPACE_INSPECTION_ENTRY_CAP) — distinct fromtree_truncated, which only reflects the walk’s fixed per-response caps (WORKSPACE_TREE_MAX_ENTRIES/WORKSPACE_TREE_MAX_DEPTH). Every field is#[serde(default)]and the field itself is optional onWorkspaceInspection, so payloads produced before this field existed still parse. - Workspace
Snapshot - Worktree
Profile Id - Worktree
Profile Inventory - Worktree
Profile Revision
Enums§
- Adapter
Family - Agent
Progress Attention Kind V1 - Agent
Progress Current V1 - Agent
Progress Event Kind V1 - Agent
Stream Chunk Kind V1 - The kind of a single
AgentStreamChunkV1– content the operator needs to act on a running ACP session: what the agent is saying, a pending interaction it needs answered, and the catalogs the three ACP setter verbs (SetSessionMode,SetSessionConfigOption,SetSessionModel) operate over. Mirrorsgate4agent_types::ProviderEvent’s content variants deliberately – seedocs/gate4agent/plans/gate4agent-acp-control-plane-on-the-wire-2026-09-02.md§3-4. - Block
Authority V1 - WHO or WHAT blocked an action – see
AgentStreamChunkKindV1::Blocked. - Client
Frame - Client
Role - Compatibility
Identifier Error - Delivery
Component Kind V2 - Delivery
Contract Error - Delivery
Scope V2 - Frame
Error - GitDiff
Mode - GitSignature
Status - Harness
McpContent Type V1 - Names what shape an opaque harness-MCP payload’s
bodyholds. - Harness
McpContract Error - Harness
McpLocal Reply V1 - The proxy’s terminal reply to a local session’s harness-MCP call.
- Harness
McpReject Reason V1 - Host
Directory Entry Error - Local
Transport Kind - Managed
Session State - Managed
Worktree Cleanup Failure - Managed
Worktree Lease State - Managed
Worktree Retention - Native
Session Catalog Scope - Native
Session Catalog Window - Native
Session External Group Kind - Node
Compatibility Auth Binding Error - Node
Event - Node
Failure Code - Node
Identifier Error - Node
Incarnation IdError - Node
Negotiated Handshake Capacity Error - Node
Request - Node
Response - Opaque
Host Path Error - Path
Encoding - Path
Style - Protocol
Negotiation Error - Provider
Config Option Kind - The kind of a
ProviderConfigOption–select(choose one ofchoices) orboolean(toggle the option’s current value).Unknownis the fallback for a kind string this build does not recognize. - Provider
Contract Manifest Error - Provider
Interaction Kind - Provider
Interaction Response - Provider
Runtime Mode - Provider
Runtime Status Error - Repository
Path Error - Server
Frame - Session
Mode - Session
Task Target V1 - Spawn
Deadline Error - Spawn
Field Provenance - Spawn
Identifier Error - Spawn
Override - Spawn
Prompt Error - Spawn
Required Capabilities Error - Spawn
Spec Resolve Error - Workspace
Entry Kind - Workspace
File Content - Worktree
Service Mode
Constants§
- BUILD_
STAMP - CAPABILITY_
HOST_ DIRECTORY_ BROWSE_ V1 - Read-only, paged directory browsing using UTF-8 absolute host paths only.
OpaqueHostPath::UnixBytesis outside this capability revision. - DEFAULT_
CONTROLLER_ LEASE_ MS - DELIVERY_
STAGE_ NONCE_ BYTES - HISTORY_
DISCOVERY_ LIMIT_ MAX - MAX_
ACP_ BLOCKED_ HELP_ BYTES - Bound on the
helpof an agent-streamBlockedchunk – the guidance tail a CLI attaches after naming the block, which runs longer than a one-line refusal. - MAX_
ACP_ BLOCKED_ REASON_ BYTES - Bound on the
reasonof an agent-streamBlockedchunk. - MAX_
ACP_ CATALOG_ ENTRIES - Mirrors
gate4agent_types::PROVIDER_CONFIG_OPTIONS_MAX– the catalog list onModeCatalog/ModelCatalog/ConfigOptionschunks. - MAX_
ACP_ CONTROL_ ID_ BYTES - Mirrors
gate4agent_types::PROVIDER_EVENT_ID_MAX_BYTES– the ACP control verbs’mode_id/option_id/model_idand the agent stream’stool_name/catalog id fields round-trip provider-minted ids through the same bound the provider event stream already validates them against. - MAX_
ACP_ CONTROL_ TEXT_ BYTES - Mirrors
gate4agent_types::PROVIDER_EVENT_TEXT_MAX_BYTES– free text carried on the agent content stream (Text,Thinking, interactionprompt/title, configvalue_json) andSetSessionConfigOption’svalue_json. - MAX_
ACP_ CORRELATION_ ID_ BYTES - Bound on
ResolveInteraction.correlation_idand on the short labels (tool_class,reason_kind) of an agent-streamBlockedchunk. - MAX_
ACP_ INTERACTION_ OPTIONS - Mirrors
gate4agent_types::PROVIDER_CONFIG_OPTION_CHOICES_MAX– the option list on oneInteractionPromptchunk. - MAX_
ADAPTER_ CONTRACT_ REVISION_ BYTES - MAX_
AGENT_ PROGRESS_ ACTIVE_ TOOL_ LABELS - MAX_
AGENT_ PROGRESS_ ENTRIES - MAX_
AGENT_ PROGRESS_ ENTRY_ BYTES - MAX_
AGENT_ PROGRESS_ TOOL_ LABEL_ BYTES - MAX_
COMPATIBILITY_ IDENTIFIER_ BYTES - MAX_
CONTEXT_ PACK_ BYTES - MAX_
CONTEXT_ PACK_ RETAINED_ MESSAGES - MAX_
CONTROLLER_ LEASE_ MS - MAX_
DELIVERY_ CHUNK_ RAW_ BYTES - MAX_
DELIVERY_ FILES - MAX_
DELIVERY_ FILE_ BYTES - MAX_
DELIVERY_ RELATIVE_ PATH_ BYTES - MAX_
DELIVERY_ TOTAL_ BYTES - MAX_
GIT_ DIFF_ BYTES - MAX_
GIT_ HISTORY_ COMMITS - MAX_
HARNESS_ MCP_ AGGREGATE_ REPLY_ BYTES - MAX_
HARNESS_ MCP_ CALL_ DEADLINE_ MS - MAX_
HARNESS_ MCP_ LAUNCH_ ARGS - Most arguments a launch description may pass to the MCP server program.
- MAX_
HARNESS_ MCP_ LAUNCH_ ARG_ BYTES - Longest single argument of a launch description.
- MAX_
HARNESS_ MCP_ LAUNCH_ NAME_ BYTES - Longest server name or environment-variable name a launch description may carry.
- MAX_
HARNESS_ MCP_ LAUNCH_ SCRUB_ ENV - Most environment variables a launch description may ask the node to scrub.
- MAX_
HARNESS_ MCP_ LOCAL_ REQUEST_ BYTES - MAX_
HARNESS_ MCP_ PENDING_ CALLS_ PER_ NODE - MAX_
HARNESS_ MCP_ PENDING_ CALLS_ PER_ SESSION - MAX_
HARNESS_ MCP_ REPLY_ CHUNK_ RAW_ BYTES - MAX_
HARNESS_ MCP_ RESERVATION_ TTL_ MS - MAX_
HARNESS_ MCP_ SPAWN_ RELAY_ DEADLINE_ MS - MAX_
HOST_ DIRECTORY_ DISPLAY_ NAME_ BYTES - MAX_
HOST_ DIRECTORY_ ENTRIES - MAX_
LAUNCH_ BUNDLES - MAX_
MANAGED_ WORKTREE_ LEASES - MAX_
MANAGED_ WORKTREE_ LEASE_ ID_ BYTES - MAX_
MANAGED_ WORKTREE_ PROFILES_ PER_ WORKSPACE - MAX_
NETWORK_ ALLOWLIST_ CATALOG_ ENTRIES - Soft bound on station network allowlist catalog ids exposed on launch inventory.
- MAX_
NODE_ CLIENT_ FRAME_ BYTES - MAX_
NODE_ FRAME_ BYTES - MAX_
NODE_ HELLO_ FRAME_ BYTES - MAX_
NODE_ IDENTIFIER_ BYTES - MAX_
NODE_ TERMINAL_ BYTES - MAX_
NODE_ TEXT_ BYTES - MAX_
PROVIDER_ ADAPTER_ CONTRACTS - MAX_
PROVIDER_ CONTRACTS - MAX_
PROVIDER_ CONTRACT_ REVISION_ BYTES - MAX_
PROVIDER_ IDENTITIES - MAX_
PROVIDER_ RUNTIME_ CONTRACT_ ID_ BYTES - MAX_
PROVIDER_ RUNTIME_ STATUSES - MAX_
PROVIDER_ RUNTIME_ VERSION_ BYTES - MAX_
REPOSITORY_ PATH_ BYTES - MAX_
SESSION_ DISPLAY_ NAME_ BYTES - MAX_
SPAWN_ BUNDLE_ REVISION_ BYTES - MAX_
SPAWN_ DEADLINE_ MS - MAX_
SPAWN_ ENVIRONMENT_ PROFILE_ REVISION_ BYTES - MAX_
SPAWN_ IDEMPOTENCY_ KEY_ BYTES - MAX_
SPAWN_ PROFILES - MAX_
SPAWN_ PROFILE_ ID_ BYTES - MAX_
SPAWN_ PROFILE_ REVISION_ BYTES - MAX_
SPAWN_ REQUIRED_ CAPABILITIES - MAX_
SPAWN_ RESOURCE_ ID_ BYTES - MAX_
WORKSPACE_ FILE_ BYTES - MAX_
WORKSPACE_ ROOT_ BYTES - MAX_
WORKTREE_ PROFILE_ ID_ BYTES - MAX_
WORKTREE_ PROFILE_ REVISION_ BYTES - MIN_
CONTROLLER_ LEASE_ MS - NATIVE_
SESSION_ CATALOG_ LIMIT_ MAX - NATIVE_
SESSION_ PREVIEW_ MESSAGE_ LIMIT_ MAX - NODE_
ACP_ CONTROL_ CAPABILITY - The inbound ACP control verbs –
ResolveInteraction,SetSessionMode,SetSessionConfigOption,SetSessionModel– that answer whatNODE_AGENT_STREAM_EVENTS_CAPABILITYreports (same plan, §5). - NODE_
AGENT_ PROGRESS_ SNAPSHOT_ CAPABILITY - NODE_
AGENT_ STREAM_ EVENTS_ CAPABILITY - The outbound content stream –
NodeEvent::AgentStream– mirroringNODE_TERMINAL_FRAME_EVENTS_CAPABILITY’s own subscription/type split rather than folding content into a telemetry vocabulary (docs/gate4agent/plans/gate4agent-acp-control-plane-on-the-wire-2026-09-02.md§3-4). - NODE_
AUTH_ NONCE_ BYTES - NODE_
AUTH_ PROOF_ BYTES - NODE_
CHILD_ ENVIRONMENT_ PROFILE_ CAPABILITY - NODE_
COMPATIBILITY_ METADATA_ CAPABILITY - NODE_
DELIVERY_ BUNDLE_ V2_ STAGE_ COMMIT_ CAPABILITY - NODE_
GIT_ READ_ CAPABILITY - NODE_
HARNESS_ MCP_ READ_ PROXY_ CAPABILITY - NODE_
HISTORY_ CONTEXT_ PACK_ CAPABILITY - NODE_
INCARNATION_ ID_ BYTES - NODE_
LEGACY_ PROVIDER_ IDS - NODE_
MANAGED_ WORKTREE_ LIFECYCLE_ CAPABILITY - NODE_
MANAGED_ WORKTREE_ SPAWN_ V2_ CAPABILITY - NODE_
NATIVE_ SESSION_ CATALOG_ CAPABILITY - NODE_
NATIVE_ SESSION_ CATALOG_ PAGING_ CAPABILITY - NODE_
NATIVE_ SESSION_ INDEX_ CAPABILITY - NODE_
NATIVE_ SESSION_ PREVIEW_ CAPABILITY - NODE_
OPAQUE_ UNIX_ PATH_ CAPABILITY - NODE_
PROVIDER_ CONTRACT_ MANIFEST_ CAPABILITY - NODE_
PROVIDER_ ID_ OPEN_ CAPABILITY - NODE_
PROVIDER_ RUNTIME_ STATUS_ CAPABILITY - NODE_
PROVIDER_ SESSION_ REFERENCE_ INDEX_ CAPABILITY - NODE_
REPOSITORY_ PATH_ CAPABILITY - NODE_
SESSION_ BUNDLE_ MATERIALIZATION_ CAPABILITY - NODE_
SESSION_ RECORD_ CONTEXT_ EXPORT_ CAPABILITY - NODE_
SESSION_ TASK_ CORRELATION_ CAPABILITY - NODE_
SPAWN_ PROFILE_ REVISION_ CAPABILITY - NODE_
SPAWN_ SPEC_ DEFAULTS_ OVERRIDES_ CAPABILITY - NODE_
STANDALONE_ WORKSPACE_ LIFECYCLE_ CAPABILITY - NODE_
STATE_ SCHEMA_ V1 - NODE_
STATE_ SCHEMA_ V2 - NODE_
STATE_ SCHEMA_ V3 - NODE_
STATE_ SCHEMA_ V4 - NODE_
STATE_ SCHEMA_ V5 - NODE_
STATE_ SCHEMA_ V6 - NODE_
STATE_ SCHEMA_ V7 - NODE_
STATE_ SCHEMA_ V8 - NODE_
STATE_ SCHEMA_ V9 - NODE_
STATE_ SCHEMA_ V10 - NODE_
TERMINAL_ FRAME_ EVENTS_ CAPABILITY - NODE_
WORKSPACE_ ENTRY_ CREATE_ CAPABILITY - NODE_
WORKSPACE_ FILE_ READ_ CAPABILITY - NODE_
WORKSPACE_ FILE_ WRITE_ CAPABILITY - NODE_
WORKTREE_ SELECTION_ CAPABILITY - SPAWN_
RUNTIME_ PROVIDER_ SESSION_ IDENTITY - SPAWN_
RUNTIME_ RAW_ PTY_ LIFECYCLE - SPAWN_
RUNTIME_ SEMANTIC_ READINESS - SPAWN_
RUNTIME_ SEMANTIC_ RESUME - SPAWN_
RUNTIME_ STRUCTURED_ PROMPT - TASK_
ID_ NONCE_ BYTES
Functions§
- context_
pack_ digest - The one definition of the context pack digest formula:
SHA256(domain || JSON(lineage) || 0x00 || bytes), renderedsha256:<hex>. Both the node (computing a pack’s digest when it exports one) and the harness (recomputing a fetched pack’s digest to check it against a mailed receipt) call this instead of keeping their own copy, so the formula can only drift in one place. - encode_
node_ compatibility_ auth_ binding - production_
node_ client_ compatibility_ offer - provider_
id_ is_ legacy - read_
json_ frame - read_
json_ frame_ limited - read_
json_ frame_ limited_ body_ timeout - sha256_
hex - A bare (no
sha256:prefix) lowercase hex SHA-256 digest ofbytes. Used where the wire already names the hash algorithm by convention rather than in the value itself –HarnessMailRefV1::WorkspacePath.sha256and the node’s ownWorkspaceFileRevisionare both this shape (unlike the context pack digest above, which reuses the prefixedsha256:<hex>form since it must distinguish itself from any other hash the wire might one day carry for the same object). Plain SHA-256 with no domain separation: a workspace file’s bytes are not reused as an input to any other digest this wire computes, so there is nothing for a domain tag to separate it from. - validate_
node_ negotiated_ handshake_ capacity - validate_
provider_ contract_ manifest - write_
json_ frame - write_
json_ frame_ limited