Expand description
Pure data contracts shared by gate4agent engines and shells.
Structs§
- AcpTransport
Spec - Active
Provider Tool - Adapter
Binding - Adapter
Id - Stable identifier for one provider adapter implementation.
- Agent
Adapter Capabilities - Agent
Capabilities - Agent
Command - AgentId
- Stable, extensible identifier for an agent CLI.
- Agent
Instance Id - Agent
Readiness Spec - Agent
Spec - Agent
Transport Capabilities - Capability
Model Summary - Capability
Probe Request - Capability
Snapshot - Command
Envelope - Command
Id - Context
Window Usage - Control
Event - Control
Health - Control
Snapshot - Detection
Spec - Effect
Envelope - Foreground
Process - Foreground
Snapshot - History
Candidate Summary - History
Message Record - History
Query - History
Session Record - History
Snapshot - Launch
Spec - Native
Session Catalog Entry - Native
Session Catalog Page - Native
Session Catalog Summary - Native
Session External Group - Native
Session Preview - Native
Session Preview Message - Observation
Envelope - Operation
Id - Operator
Gate Option - One choice as rendered on screen inside an
OperatorGateState. - Operator
Gate State - The full classification of a screen recognized as an
OperatorGate, replacing what used to be a bare label string.kindis always known (a matcher only returns this type once it has matched a specific gate phrase);subject,input, andoptionsdegrade independently toUnknown/empty when the screen’s specific shape was not recognized – never invented fromkindalone. - Pending
Capability Probe - Pending
History Operation - Pending
Resume Operation - Pipe
Transport Spec - Optional catalog override used by controlled fixtures and providers whose headless executable differs from their interactive PTY executable.
- Prepared
Input - Prepared
Write - Prompt
Payload - Prompt
Spec - Provider
Available Command - A single slash-style command the agent advertises (ACP transport’s
available_commands_update). - Provider
Config Choice - One selectable value of a
select-kindProviderConfigOption.value_jsonis the choice’s value pre-serialized to JSON text (this crate is a pure data contract and does not depend onserde_json; seeProviderConfigOption::value_jsonfor the same convention applied to the option’s own current value). - Provider
Config Option - One session configuration setting – the mechanism ACP uses to change
model, reasoning effort, and similar settings, superseding session
modes.
ProviderEvent::ConfigOptionsUpdatedalways carries the FULL current set, never a delta. - Provider
Interaction - Provider
Interaction Id - Provider
Interaction Option - One option the agent offered on a
session/request_permission-style interaction, carried onProviderEvent::InteractionRequested::optionsexactly as the agent gave it – see ACP’sPermissionOptioninsrc/acp/protocol.rs(option_id,name,kind). This crate cannot depend ongate4agent(see this crate’s ownCLAUDE.md), so the shape is repeated here rather than shared, the same precedentProviderRateLimitKindalready sets for a wire-typed mirror of agate4agent-side enum. - Provider
Interaction Target - Provider
Mode Info - One mode the agent advertised as selectable, read from ACP’s
session/newhandshake result (AcpSession::available_modes()) and carried onProviderEvent::ModeChangedalongside the id that changed. Mirrorsgate4agent-node-protocol’sAgentStreamNamedIdV1field-for-field; this crate does not depend on that one (see this crate’s ownCLAUDE.md), so the shape is repeated rather than shared. - Provider
Plan Step - One step of the agent’s execution plan (ACP transport’s
planupdate).ProviderEvent::Planalways carries the FULL plan snapshot, never a delta. - Provider
Runtime Policy - Provider
Session Identity - Provider
Snapshot - Provider
Source - Provider
Source Cursor - Provider
Subagent - Resume
Launch Request - Resume
Session Summary - Resume
Snapshot - Session
Generation - Session
Option Selection - Session
Record Preview - Session
Snapshot - Shell
Command - Start
Request - Terminal
Frame - Terminal
Size - Terminal
Text - Token
Usage
Enums§
- Adapter
Binding Error - Adapter
Family - Adapter
IdError - Adapter
Verification - Agent
Command Mode - Agent
IdError - Approval
Level - How much autonomy a freshly spawned provider CLI process is granted at launch, independent of which transport (PTY, inline/pipe, ACP) execs it – these are process launch arguments, the same axis regardless of transport.
- Capability
Probe Failure - Capability
Validation Error - Control
Command - Control
Effect - Control
Error - Control
Event Kind - Control
Observation - Draft
Ready Signal - Foreground
Authority - Foreground
Process Kind - Foreground
Requirement - Route proof an effect executor must obtain immediately before a PTY write.
- History
Message Role - History
Operation - History
Validation Error - Host
Decision Authority - WHO decided a host request the agent sent to the ACP host – see
ProviderEvent::HostRequestObserved. Mirrorsgate4agent’s ownHostDecisionAuthorityone-for-one; this crate cannot depend ongate4agent(see this crate’sCLAUDE.md), so the value is converted at the boundary that already depends on both (gate4agent-shell-native). - Host
Request Decision - A typed answer to “what happened to this host request” – see
ProviderEvent::HostRequestObserved. Mirrorsgate4agent’s ownHostRequestDecisionone-for-one; seeHostDecisionAuthority’s doc comment for why this crate keeps its own copy rather than importing it. - Host
Request Outcome - Whether a
Grantedhost request’s underlying operation actually ran without an I/O or execution problem – see [ProviderEvent:: HostRequestObserved]. Mirrorsgate4agent’s ownHostRequestOutcomeone-for-one; seeHostDecisionAuthority’s doc comment for why this crate keeps its own copy rather than importing it. - Initial
Prompt Mode - Input
Action - Input
Prepare Error - Native
Draft Mode - Native
Session Catalog Scope - Native
Session Catalog Window - Native
Session External Group Kind - Observation
Ignored Reason - Operator
Gate Input - HOW
OperatorGateStateis controlled – what a caller resolving it (typically a human, occasionally a scripted answer) needs to send. - Operator
Gate Kind - What TYPE of blocking question
OperatorGateStateis showing, classified from the screen’s own top-level phrasing (seestartup_operator_gateingate4agent-shell-native, the only producer). Distinct kinds exist so a consumer can react differently to “an update is running” versus “type an answer” without parsingOperatorGateSubject/optionsfirst. - Operator
Gate Option Semantics - What choosing a given
OperatorGateOptiondoes, inferred from the verb in its own on-screen text (seeclassify_operator_gate_option_semanticsingate4agent-shell-native) – never from its position or number, since neither is stable across CLIs or screen wraps. - Operator
Gate Subject - WHAT entity
OperatorGateStateis gating access to – narrower thankind(which says what TYPE of question this is): twoWorkspaceTrustgates always sharesubject: Directory, but thepathdetail (when a matcher can read one off the screen) distinguishes which directory.Unknownis the honest reading for akindwhose screen text does not name a concrete subject from this list (a vendor updater or onboarding splash is not “about” a directory, a hook set, or an account) – it is never upgraded into a guess. - Pipe
Prompt Delivery - Pipe
Protocol - Prepared
Input Kind - Prepared
Write Kind - Process
Matcher - Prompt
Framing - Provider
Activity - Provider
Config Option Kind - The kind of a
ProviderConfigOption–select(choose one ofchoices) orboolean(toggle the option’s current value).Unknownis the fallback for a kind string this build does not recognize. - Provider
Event - Provider
Event Validation Error - Provider
Interaction Kind - Provider
Interaction Outcome - Provider
Interaction Response - Provider
Interaction Response Error - Provider
Interaction Response Kind - Provider
Interaction Status - Provider
Plan Priority - Priority of a single
ProviderPlanStep, carried onProviderEvent::Plan. - Provider
Plan Status - Status of a single
ProviderPlanStep, carried onProviderEvent::Plan. - Provider
Rate Limit Kind - Which class of budget a
ProviderEvent::RateLimitedobservation concerns. This is the wire-typed counterpart ofgate4agent’s own (source-of-truth)RateLimitType– kept as its own type here, rather than imported, because this crate’s contract forbids depending ongate4agent(see this crate’sCLAUDE.md); the conversion from the detector’s enum lives in the shell that already depends on both. - Provider
Runtime Capability - Provider
Runtime Policy Error - Provider
Session Key - Provider
Stop Reason - Why an ACP turn stopped – mirrors
gate4agent’s ownStopReason(src/core/types.rs) one-for-one; this crate cannot depend ongate4agent(see this crate’s ownCLAUDE.md), the same reason every other wire-typed mirror here exists (ProviderRateLimitKind,ProviderInteractionOption, …).ProviderErroris synthesized locally bygate4agent’s ACP session whensession/promptitself answers with a JSON-RPC error instead of a normal response – see that type’s own doc comment for the live Codex fixture this shape was measured against. - PtyScreen
State - Whether the screen currently painted at a PTY looks like the agent’s own
composer, as classified by the node from the same terminal text a human
would read. This is a screen-content judgement, never a process-liveness
one –
SessionStatusalready answers “is something running”, and a consumer must not fold the two into a single “is it running” question: a process can beRunningwhile its screen sits on an unrelated installer prompt, and that combination is exactly the case this type exists to distinguish. - Resume
Authority Target - Resume
Phase - Resume
Target - Resume
Validation Error - Runtime
Platform - Runtime in which an executable is detected or launched.
- Session
Option Validation Error - Session
Option Value - Session
Status - Spec
Verification - Provenance state for a built-in launch specification.
- Terminal
Control - Terminal
Mouse Protocol Encoding - Transport
Kind
Constants§
- BRACKETED_
PASTE_ END - BRACKETED_
PASTE_ START - CAPABILITY_
MODELS_ MAX - CAPABILITY_
MODEL_ ID_ MAX_ BYTES - CAPABILITY_
MODEL_ LABEL_ MAX_ BYTES - CONTROL_
INSTANCE_ IDENTITIES_ CAPACITY - CONTROL_
INSTANCE_ IDENTITIES_ MAX - CONTROL_
SESSIONS_ MAX - FOREGROUND_
PROCESS_ NAME_ MAX_ BYTES - HISTORY_
CANDIDATE_ ID_ MAX_ BYTES - HISTORY_
DISCOVERY_ LIMIT_ MAX - HISTORY_
ERROR_ MAX_ BYTES - HISTORY_
MESSAGES_ MAX - HISTORY_
MESSAGE_ MAX_ BYTES - HISTORY_
MODEL_ MAX_ BYTES - HISTORY_
SESSION_ ID_ MAX_ BYTES - HISTORY_
TITLE_ MAX_ BYTES - MAX_
ADAPTER_ REVISION_ LEN - NATIVE_
SESSION_ CATALOG_ LIMIT_ MAX - NATIVE_
SESSION_ EXTERNAL_ GROUP_ ID_ MAX_ BYTES - NATIVE_
SESSION_ EXTERNAL_ GROUP_ LABEL_ MAX_ BYTES - NATIVE_
SESSION_ PREVIEW_ MESSAGE_ LIMIT_ MAX - NATIVE_
SESSION_ PREVIEW_ TEXT_ MAX_ BYTES - OPERATOR_
GATE_ OPTIONS_ MAX - Bound on
OperatorGateState::options– large enough for any list a real prompt has ever been observed to render (2-4 choices), small enough that a garbled or hostile screen capture cannot inflate the wire payload. - OPERATOR_
GATE_ OPTION_ TEXT_ MAX_ BYTES - Per-
OperatorGateOption::textbyte bound, same scale asPTY_SCREEN_GATE_NAME_MAX_BYTES– an option label is a single short line off the screen, never a paragraph. - OPERATOR_
GATE_ PATH_ MAX_ BYTES - Bound on
OperatorGateSubject::Directory’spath, matching the scale of other path-shaped fields carried on this wire (seeWORKING_DIRECTORY_MAX_BYTESfor the same order of magnitude on a full working-directory string). - PROVIDER_
AVAILABLE_ COMMANDS_ MAX - PROVIDER_
CONFIG_ OPTIONS_ MAX - PROVIDER_
CONFIG_ OPTION_ CHOICES_ MAX - PROVIDER_
EVENT_ ID_ MAX_ BYTES - PROVIDER_
EVENT_ TEXT_ MAX_ BYTES - PROVIDER_
EVENT_ TOOLS_ MAX - PROVIDER_
INGRESS_ EVENTS_ MAX - PROVIDER_
INTERACTIONS_ MAX - PROVIDER_
INTERACTION_ FAILURE_ MAX_ BYTES - PROVIDER_
INTERACTION_ OPTIONS_ MAX - Bound on
ProviderEvent::InteractionRequested::options– same rationale asOPERATOR_GATE_OPTIONS_MAX: an ACPsession/request_ permissioncall offers a subset of exactly fourPermissionOptionKindvalues, so this gives headroom over that domain maximum without letting a garbled or hostile agent inflate the wire payload. - PROVIDER_
INTERACTION_ RESPONSE_ MAX_ BYTES - PROVIDER_
MODE_ CATALOG_ MAX - PROVIDER_
PLAN_ STEPS_ MAX - PROVIDER_
SESSION_ LOCATOR_ MAX_ BYTES - PROVIDER_
SUBAGENTS_ MAX - PTY_
SCREEN_ GATE_ NAME_ MAX_ BYTES - RESUME_
ERROR_ MAX_ BYTES - SEMANTIC_
PROMPT_ MAX_ BYTES - SESSION_
OPTION_ ID_ MAX_ BYTES - SESSION_
OPTION_ VALUES_ MAX - SESSION_
OPTION_ VALUE_ MAX_ BYTES - TERMINAL_
COLUMNS_ MAX - TERMINAL_
INPUT_ CHUNK_ MAX_ BYTES - TERMINAL_
INPUT_ MAX_ BYTES - TERMINAL_
ROWS_ MAX - TERMINAL_
SUBMIT_ DELAY_ MS - TERMINAL_
WRITE_ DELAY_ MAX_ MS - WORKING_
DIRECTORY_ MAX_ BYTES
Functions§
- normalize_
executable_ name - Normalize an executable name for portable provider matching.
- normalize_
semantic_ prompt - Validate and normalize a semantic prompt before it crosses a process or protocol boundary. Terminal controls are rendered inert consistently with PTY prompt preparation, but no terminal framing bytes are added.
- prepare_
agent_ command - Prepare a provider-native slash command after a dispatcher has selected the foreground agent. Arguments are TUI text segments, not shell arguments.
- prepare_
input - Converts an input action to bounded writes without touching a PTY.
- prepare_
input_ with_ limits - prepare_
shell_ command - Prepare an intentional command line for a dispatcher that has just confirmed a shell owns the PTY foreground.
- sanitize_
prompt_ text - Neutralizes terminal control sequences while preserving prompt newlines and tabs.
- validate_
candidate_ id - validate_
capability_ models - validate_
history_ error - validate_
native_ session_ id - validate_
resume_ error - validate_
session_ config_ value_ json - Bounds check for
ControlCommand::SetSessionConfigOption’svalue_json: required, bounded the same as any other provider-scoped free text (PROVIDER_EVENT_TEXT_MAX_BYTES), free of unsafe control bytes. Mirrorsgate4agent-node-protocol’sdeserialize_acp_config_value_jsonminus the JSON-parseability check – this crate is a pure data contract and does not depend onserde_json, so confirming the text actually parses is the shell executor’s job (AcpSession::set_config_optiontakes an already-parsedserde_json::Value). - validate_
session_ control_ id - Bounds check for the
mode_id/option_id/model_idan ACP session control command (ControlCommand::SetSessionMode/SetSessionConfigOption/SetSessionModel) carries – the same bound as any other provider-scoped id (PROVIDER_EVENT_ID_MAX_BYTES), required and free of control characters. Mirrors whatgate4agent-node-protocol’s wire boundary already enforces (deserialize_acp_control_id) before a command ever reachesgate4agent-engine; re-checked here because aControlCommandis constructible directly (tests, other embedders), not only through that one wire.