Skip to main content

harn_cli/package/
extensions.rs

1use super::errors::PackageError;
2use super::*;
3
4pub(crate) fn manifest_capabilities(
5    manifest: &Manifest,
6) -> Option<&harn_vm::llm::capabilities::CapabilitiesFile> {
7    manifest.capabilities.as_ref()
8}
9
10pub(crate) fn is_empty_capabilities(file: &harn_vm::llm::capabilities::CapabilitiesFile) -> bool {
11    file.provider.is_empty() && file.provider_family.is_empty()
12}
13
14pub fn validate_runtime_manifest_extensions(anchor: &Path) -> Result<(), PackageError> {
15    let Some((manifest, _manifest_dir)) = find_nearest_manifest(anchor) else {
16        return Ok(());
17    };
18    validate_handoff_routes(&manifest.handoff_routes, &manifest)
19}
20
21/// Load the nearest project manifest plus any installed package manifests and
22/// merge the root project's runtime extensions.
23pub fn try_load_runtime_extensions(anchor: &Path) -> Result<RuntimeExtensions, PackageError> {
24    ensure_dependencies_materialized(anchor)?;
25    let Some((root_manifest, manifest_dir)) = find_nearest_manifest(anchor) else {
26        return Ok(RuntimeExtensions::default());
27    };
28
29    let mut llm = harn_vm::llm_config::ProvidersConfig::default();
30    let mut capabilities = harn_vm::llm::capabilities::CapabilitiesFile::default();
31    let mut hooks = Vec::new();
32    let mut triggers = Vec::new();
33
34    llm.merge_from(&root_manifest.llm);
35    if let Some(file) = manifest_capabilities(&root_manifest) {
36        merge_capability_overrides(&mut capabilities, file);
37    }
38    hooks.extend(resolved_hooks_from_manifest(&root_manifest, &manifest_dir));
39    triggers.extend(resolved_triggers_from_manifest(
40        &root_manifest,
41        &manifest_dir,
42    ));
43    let handoff_routes = root_manifest.handoff_routes.clone();
44    validate_handoff_routes(&handoff_routes, &root_manifest)?;
45    let provider_connectors =
46        resolved_provider_connectors_from_manifest(&root_manifest, &manifest_dir);
47
48    Ok(RuntimeExtensions {
49        root_manifest_path: Some(manifest_dir.join(MANIFEST)),
50        root_manifest_dir: Some(manifest_dir),
51        root_manifest: Some(root_manifest),
52        llm: (!llm.is_empty()).then_some(llm),
53        capabilities: (!is_empty_capabilities(&capabilities)).then_some(capabilities),
54        hooks,
55        triggers,
56        handoff_routes,
57        provider_connectors,
58    })
59}
60
61pub fn load_runtime_extensions(anchor: &Path) -> RuntimeExtensions {
62    match try_load_runtime_extensions(anchor) {
63        Ok(extensions) => extensions,
64        Err(error) => {
65            eprintln!("error: {error}");
66            process::exit(1);
67        }
68    }
69}
70
71/// Install merged runtime extensions on the current thread.
72pub fn install_runtime_extensions(extensions: &RuntimeExtensions) {
73    harn_vm::llm_config::set_user_overrides(extensions.llm.clone());
74    harn_vm::llm::capabilities::set_user_overrides(extensions.capabilities.clone());
75    install_manifest_handoff_routes(extensions);
76    install_orchestrator_budget(extensions);
77}
78
79pub fn install_manifest_handoff_routes(extensions: &RuntimeExtensions) {
80    harn_vm::install_handoff_routes(extensions.handoff_routes.clone());
81}
82
83pub fn install_orchestrator_budget(extensions: &RuntimeExtensions) {
84    let budget = extensions
85        .root_manifest
86        .as_ref()
87        .map(|manifest| harn_vm::OrchestratorBudgetConfig {
88            daily_cost_usd: manifest.orchestrator.budget.daily_cost_usd,
89            hourly_cost_usd: manifest.orchestrator.budget.hourly_cost_usd,
90        })
91        .unwrap_or_default();
92    harn_vm::install_orchestrator_budget(budget);
93}
94
95pub async fn install_manifest_hooks(
96    vm: &mut harn_vm::Vm,
97    extensions: &RuntimeExtensions,
98) -> Result<(), PackageError> {
99    harn_vm::orchestration::clear_runtime_hooks();
100    let mut loaded_exports: HashMap<ManifestModuleCacheKey, ManifestModuleExports> = HashMap::new();
101    for hook in &extensions.hooks {
102        let Some((module_name, function_name)) = hook.handler.rsplit_once("::") else {
103            return Err(format!(
104                "invalid hook handler '{}': expected <module>::<function>",
105                hook.handler
106            )
107            .into());
108        };
109        let cache_key = (
110            hook.manifest_dir.clone(),
111            hook.package_name.clone(),
112            Some(module_name.to_string()),
113        );
114        if !loaded_exports.contains_key(&cache_key) {
115            let exports = resolve_manifest_exports(
116                vm,
117                &hook.manifest_dir,
118                hook.package_name.as_deref(),
119                &hook.exports,
120                Some(module_name),
121            )
122            .await?;
123            loaded_exports.insert(cache_key.clone(), exports);
124        }
125        let exports = loaded_exports
126            .get(&cache_key)
127            .expect("manifest hook exports cached");
128        let Some(closure) = exports.get(function_name) else {
129            return Err(format!(
130                "hook handler '{}' is not exported by module '{}'",
131                function_name, module_name
132            )
133            .into());
134        };
135        harn_vm::orchestration::register_vm_hook(
136            hook.event,
137            hook.pattern.clone(),
138            hook.handler.clone(),
139            closure.clone(),
140        );
141    }
142    Ok(())
143}
144
145pub async fn collect_manifest_triggers(
146    vm: &mut harn_vm::Vm,
147    extensions: &RuntimeExtensions,
148) -> Result<Vec<CollectedManifestTrigger>, PackageError> {
149    let _provider_schema_guard = lock_manifest_provider_schemas().await;
150    let provider_catalog = build_manifest_provider_catalog(extensions).await?;
151    validate_orchestrator_budget(extensions.root_manifest.as_ref())?;
152    validate_static_trigger_configs(&extensions.triggers, &provider_catalog)?;
153    let mut loaded_exports: HashMap<ManifestModuleCacheKey, ManifestModuleExports> = HashMap::new();
154    let mut module_signatures: HashMap<PathBuf, BTreeMap<String, TriggerFunctionSignature>> =
155        HashMap::new();
156    let mut collected = Vec::new();
157
158    for trigger in &extensions.triggers {
159        let handler = parse_trigger_handler_uri(trigger)?;
160        let collected_handler = match handler {
161            TriggerHandlerUri::Local(reference) => {
162                let cache_key = (
163                    trigger.manifest_dir.clone(),
164                    trigger.package_name.clone(),
165                    reference.module_name.clone(),
166                );
167                if !loaded_exports.contains_key(&cache_key) {
168                    let exports = resolve_manifest_exports(
169                        vm,
170                        &trigger.manifest_dir,
171                        trigger.package_name.as_deref(),
172                        &trigger.exports,
173                        reference.module_name.as_deref(),
174                    )
175                    .await
176                    .map_err(|error| trigger_error(trigger, error))?;
177                    loaded_exports.insert(cache_key.clone(), exports);
178                }
179                let exports = loaded_exports
180                    .get(&cache_key)
181                    .expect("manifest trigger exports cached");
182                let Some(closure) = exports.get(&reference.function_name) else {
183                    return Err(trigger_error(
184                        trigger,
185                        format!(
186                            "handler '{}' is not exported by the resolved module",
187                            reference.raw
188                        ),
189                    ));
190                };
191                CollectedTriggerHandler::Local {
192                    reference,
193                    closure: closure.clone(),
194                }
195            }
196            TriggerHandlerUri::A2a {
197                target,
198                allow_cleartext,
199            } => CollectedTriggerHandler::A2a {
200                target,
201                allow_cleartext,
202            },
203            TriggerHandlerUri::Worker { queue } => CollectedTriggerHandler::Worker { queue },
204            TriggerHandlerUri::Persona { name } => {
205                let binding = persona_runtime_binding_for_handler(extensions, trigger, &name)?;
206                CollectedTriggerHandler::Persona { binding }
207            }
208        };
209
210        let collected_when = if let Some(when_raw) = &trigger.when {
211            let reference = parse_local_trigger_ref(when_raw, "when", trigger)?;
212            let cache_key = (
213                trigger.manifest_dir.clone(),
214                trigger.package_name.clone(),
215                reference.module_name.clone(),
216            );
217            if !loaded_exports.contains_key(&cache_key) {
218                let exports = resolve_manifest_exports(
219                    vm,
220                    &trigger.manifest_dir,
221                    trigger.package_name.as_deref(),
222                    &trigger.exports,
223                    reference.module_name.as_deref(),
224                )
225                .await
226                .map_err(|error| trigger_error(trigger, error))?;
227                loaded_exports.insert(cache_key.clone(), exports);
228            }
229            let exports = loaded_exports
230                .get(&cache_key)
231                .expect("manifest trigger predicate exports cached");
232            let Some(closure) = exports.get(&reference.function_name) else {
233                return Err(trigger_error(
234                    trigger,
235                    format!(
236                        "when predicate '{}' is not exported by the resolved module",
237                        reference.raw
238                    ),
239                ));
240            };
241
242            let source_path = manifest_module_source_path(
243                &trigger.manifest_dir,
244                trigger.package_name.as_deref(),
245                &trigger.exports,
246                reference.module_name.as_deref(),
247            )
248            .map_err(|error| trigger_error(trigger, error))?;
249            if !module_signatures.contains_key(&source_path) {
250                let signatures = load_trigger_function_signatures(&source_path)
251                    .map_err(|error| trigger_error(trigger, error))?;
252                module_signatures.insert(source_path.clone(), signatures);
253            }
254            let signatures = module_signatures
255                .get(&source_path)
256                .expect("module signatures cached");
257            let Some(signature) = signatures.get(&reference.function_name) else {
258                return Err(trigger_error(
259                    trigger,
260                    format!(
261                        "when predicate '{}' must resolve to a function declaration",
262                        reference.raw
263                    ),
264                ));
265            };
266            if signature.params.len() != 1
267                || signature.params[0]
268                    .as_ref()
269                    .is_none_or(|param| !is_trigger_event_type(param))
270            {
271                return Err(trigger_error(
272                    trigger,
273                    format!(
274                        "when predicate '{}' must have signature fn(TriggerEvent) -> bool",
275                        reference.raw
276                    ),
277                ));
278            }
279            if signature
280                .return_type
281                .as_ref()
282                .is_none_or(|return_type| !is_predicate_return_type(return_type))
283            {
284                return Err(trigger_error(
285                    trigger,
286                    format!(
287                        "when predicate '{}' must have signature fn(TriggerEvent) -> bool or Result<bool, _>",
288                        reference.raw
289                    ),
290                ));
291            }
292
293            Some(CollectedTriggerPredicate {
294                reference,
295                closure: closure.clone(),
296            })
297        } else {
298            None
299        };
300
301        let flow_control = collect_trigger_flow_control(vm, trigger).await?;
302
303        collected.push(CollectedManifestTrigger {
304            config: trigger.clone(),
305            handler: collected_handler,
306            when: collected_when,
307            flow_control,
308        });
309    }
310
311    harn_vm::install_provider_catalog(provider_catalog);
312    Ok(collected)
313}
314
315pub(crate) async fn collect_trigger_flow_control(
316    vm: &mut harn_vm::Vm,
317    trigger: &ResolvedTriggerConfig,
318) -> Result<harn_vm::TriggerFlowControlConfig, PackageError> {
319    let mut flow = harn_vm::TriggerFlowControlConfig::default();
320
321    let concurrency = if let Some(spec) = &trigger.concurrency {
322        Some(spec.clone())
323    } else if let Some(max) = trigger.budget.max_concurrent {
324        eprintln!(
325            "warning: {} uses deprecated budget.max_concurrent; prefer concurrency = {{ max = {} }}",
326            manifest_trigger_location(trigger),
327            max
328        );
329        Some(TriggerConcurrencyManifestSpec { key: None, max })
330    } else {
331        None
332    };
333    if let Some(spec) = concurrency {
334        flow.concurrency = Some(harn_vm::TriggerConcurrencyConfig {
335            key: compile_optional_trigger_expression(
336                vm,
337                trigger,
338                "concurrency.key",
339                spec.key.as_deref(),
340            )
341            .await?,
342            max: spec.max,
343        });
344    }
345
346    if let Some(spec) = &trigger.throttle {
347        flow.throttle = Some(harn_vm::TriggerThrottleConfig {
348            key: compile_optional_trigger_expression(
349                vm,
350                trigger,
351                "throttle.key",
352                spec.key.as_deref(),
353            )
354            .await?,
355            period: harn_vm::parse_flow_control_duration(&spec.period)
356                .map_err(|error| trigger_error(trigger, format!("throttle.period {error}")))?,
357            max: spec.max,
358        });
359    }
360
361    if let Some(spec) = &trigger.rate_limit {
362        flow.rate_limit = Some(harn_vm::TriggerRateLimitConfig {
363            key: compile_optional_trigger_expression(
364                vm,
365                trigger,
366                "rate_limit.key",
367                spec.key.as_deref(),
368            )
369            .await?,
370            period: harn_vm::parse_flow_control_duration(&spec.period)
371                .map_err(|error| trigger_error(trigger, format!("rate_limit.period {error}")))?,
372            max: spec.max,
373        });
374    }
375
376    if let Some(spec) = &trigger.debounce {
377        flow.debounce = Some(harn_vm::TriggerDebounceConfig {
378            key: compile_trigger_expression(vm, trigger, "debounce.key", &spec.key).await?,
379            period: harn_vm::parse_flow_control_duration(&spec.period)
380                .map_err(|error| trigger_error(trigger, format!("debounce.period {error}")))?,
381        });
382    }
383
384    if let Some(spec) = &trigger.singleton {
385        flow.singleton = Some(harn_vm::TriggerSingletonConfig {
386            key: compile_optional_trigger_expression(
387                vm,
388                trigger,
389                "singleton.key",
390                spec.key.as_deref(),
391            )
392            .await?,
393        });
394    }
395
396    if let Some(spec) = &trigger.batch {
397        flow.batch = Some(harn_vm::TriggerBatchConfig {
398            key: compile_optional_trigger_expression(vm, trigger, "batch.key", spec.key.as_deref())
399                .await?,
400            size: spec.size,
401            timeout: harn_vm::parse_flow_control_duration(&spec.timeout)
402                .map_err(|error| trigger_error(trigger, format!("batch.timeout {error}")))?,
403        });
404    }
405
406    if let Some(spec) = &trigger.priority_flow {
407        flow.priority = Some(harn_vm::TriggerPriorityOrderConfig {
408            key: compile_trigger_expression(vm, trigger, "priority.key", &spec.key).await?,
409            order: spec.order.clone(),
410        });
411    }
412
413    Ok(flow)
414}
415
416fn persona_runtime_binding_for_handler(
417    extensions: &RuntimeExtensions,
418    trigger: &ResolvedTriggerConfig,
419    name: &str,
420) -> Result<harn_vm::PersonaRuntimeBinding, PackageError> {
421    let Some(manifest) = extensions.root_manifest.as_ref() else {
422        return Err(trigger_error(
423            trigger,
424            format!("handler persona://{name} requires a root manifest"),
425        ));
426    };
427    let Some(persona) = manifest
428        .personas
429        .iter()
430        .find(|persona| persona.name.as_deref() == Some(name))
431    else {
432        return Err(trigger_error(
433            trigger,
434            format!("handler persona://{name} does not match a declared persona"),
435        ));
436    };
437    Ok(persona_runtime_binding(name, persona))
438}
439
440/// Lower a manifest persona entry into the runtime binding. Centralised so
441/// every call site (`harn persona` CLI, trigger registration, etc.) carries
442/// the same shape — stages included.
443pub(crate) fn persona_runtime_binding(
444    name: &str,
445    persona: &PersonaManifestEntry,
446) -> harn_vm::PersonaRuntimeBinding {
447    harn_vm::PersonaRuntimeBinding {
448        name: name.to_string(),
449        template_ref: persona_template_ref(persona),
450        entry_workflow: persona.entry_workflow.clone().unwrap_or_default(),
451        schedules: persona.schedules.clone(),
452        triggers: persona.triggers.clone(),
453        budget: harn_vm::PersonaBudgetPolicy {
454            daily_usd: persona.budget.daily_usd,
455            hourly_usd: persona.budget.hourly_usd,
456            run_usd: persona.budget.run_usd,
457            max_tokens: persona.budget.max_tokens,
458        },
459        stages: persona
460            .stages
461            .iter()
462            .map(persona_stage_decl_to_runtime)
463            .collect(),
464    }
465}
466
467fn persona_stage_decl_to_runtime(stage: &PersonaStageDecl) -> harn_vm::StageDecl {
468    harn_vm::StageDecl {
469        name: stage.name.clone(),
470        allowed_tools: stage.allowed_tools.clone(),
471        side_effect_level: stage.side_effect_level.clone(),
472        max_iterations: stage.max_iterations,
473        on_exit: stage.on_exit.as_ref().map(|exit| harn_vm::StageExit {
474            on_complete: exit.on_complete.clone(),
475            on_failure: exit.on_failure.clone(),
476            policy_override: None,
477        }),
478    }
479}
480
481pub(crate) async fn compile_optional_trigger_expression(
482    vm: &mut harn_vm::Vm,
483    trigger: &ResolvedTriggerConfig,
484    field_name: &str,
485    expr: Option<&str>,
486) -> Result<Option<harn_vm::TriggerExpressionSpec>, PackageError> {
487    match expr {
488        Some(expr) => compile_trigger_expression(vm, trigger, field_name, expr)
489            .await
490            .map(Some),
491        None => Ok(None),
492    }
493}
494
495pub(crate) async fn compile_trigger_expression(
496    vm: &mut harn_vm::Vm,
497    trigger: &ResolvedTriggerConfig,
498    field_name: &str,
499    expr: &str,
500) -> Result<harn_vm::TriggerExpressionSpec, PackageError> {
501    let synthetic = PathBuf::from(format!(
502        "<trigger-expr>/{}/{:04}-{}.harn",
503        harn_vm::event_log::sanitize_topic_component(&trigger.id),
504        trigger.table_index,
505        harn_vm::event_log::sanitize_topic_component(field_name),
506    ));
507    let source = format!(
508        "import \"std/triggers\"\n\npub fn __trigger_expr(event: TriggerEvent) -> any {{\n  return {expr}\n}}\n"
509    );
510    let exports = vm
511        .load_module_exports_from_source(synthetic, &source)
512        .await
513        .map_err(|error| {
514            trigger_error(
515                trigger,
516                format!("{field_name} '{expr}' is invalid Harn expression: {error}"),
517            )
518        })?;
519    let closure = exports.get("__trigger_expr").ok_or_else(|| {
520        trigger_error(
521            trigger,
522            format!("{field_name} '{expr}' did not compile into an exported closure"),
523        )
524    })?;
525    Ok(harn_vm::TriggerExpressionSpec {
526        raw: expr.to_string(),
527        closure: closure.clone(),
528    })
529}
530
531pub(crate) fn trigger_kind_label(kind: TriggerKind) -> &'static str {
532    match kind {
533        TriggerKind::Webhook => "webhook",
534        TriggerKind::Cron => "cron",
535        TriggerKind::Poll => "poll",
536        TriggerKind::Stream => "stream",
537        TriggerKind::Predicate => "predicate",
538        TriggerKind::A2aPush => "a2a-push",
539    }
540}
541
542pub(crate) fn worker_queue_priority(
543    priority: TriggerDispatchPriority,
544) -> harn_vm::WorkerQueuePriority {
545    match priority {
546        TriggerDispatchPriority::High => harn_vm::WorkerQueuePriority::High,
547        TriggerDispatchPriority::Normal => harn_vm::WorkerQueuePriority::Normal,
548        TriggerDispatchPriority::Low => harn_vm::WorkerQueuePriority::Low,
549    }
550}
551
552pub fn manifest_trigger_binding_spec(
553    trigger: CollectedManifestTrigger,
554) -> harn_vm::TriggerBindingSpec {
555    let flow_control = trigger.flow_control.clone();
556    let config = trigger.config;
557    let (handler, handler_descriptor) = match trigger.handler {
558        CollectedTriggerHandler::Local { reference, closure } => (
559            harn_vm::TriggerHandlerSpec::Local {
560                raw: reference.raw.clone(),
561                closure,
562            },
563            serde_json::json!({
564                "kind": "local",
565                "raw": reference.raw,
566            }),
567        ),
568        CollectedTriggerHandler::A2a {
569            target,
570            allow_cleartext,
571        } => (
572            harn_vm::TriggerHandlerSpec::A2a {
573                target: target.clone(),
574                allow_cleartext,
575            },
576            serde_json::json!({
577                "kind": "a2a",
578                "target": target,
579                "allow_cleartext": allow_cleartext,
580            }),
581        ),
582        CollectedTriggerHandler::Worker { queue } => (
583            harn_vm::TriggerHandlerSpec::Worker {
584                queue: queue.clone(),
585            },
586            serde_json::json!({
587                "kind": "worker",
588                "queue": queue,
589            }),
590        ),
591        CollectedTriggerHandler::Persona { binding } => (
592            harn_vm::TriggerHandlerSpec::Persona {
593                binding: binding.clone(),
594            },
595            serde_json::json!({
596                "kind": "persona",
597                "name": binding.name,
598                "entry_workflow": binding.entry_workflow,
599            }),
600        ),
601    };
602
603    let when_raw = trigger
604        .when
605        .as_ref()
606        .map(|predicate| predicate.reference.raw.clone());
607    let when = trigger.when.map(|predicate| harn_vm::TriggerPredicateSpec {
608        raw: predicate.reference.raw,
609        closure: predicate.closure,
610    });
611    let mut when_budget = config
612        .when_budget
613        .as_ref()
614        .map(|budget| {
615            Ok::<harn_vm::TriggerPredicateBudget, String>(harn_vm::TriggerPredicateBudget {
616                max_cost_usd: budget.max_cost_usd,
617                tokens_max: budget.tokens_max,
618                timeout_ms: budget
619                    .timeout
620                    .as_deref()
621                    .map(parse_duration_millis)
622                    .transpose()?,
623            })
624        })
625        .transpose()
626        .unwrap_or_default();
627    if config.budget.max_cost_usd.is_some() || config.budget.max_tokens.is_some() {
628        let budget = when_budget.get_or_insert_with(harn_vm::TriggerPredicateBudget::default);
629        if budget.max_cost_usd.is_none() {
630            budget.max_cost_usd = config.budget.max_cost_usd;
631        }
632        if budget.tokens_max.is_none() {
633            budget.tokens_max = config.budget.max_tokens;
634        }
635    }
636    let id = config.id.clone();
637    let kind = trigger_kind_label(config.kind).to_string();
638    let provider = config.provider.clone();
639    let autonomy_tier = config.autonomy_tier;
640    let match_events = config.match_.events.clone();
641    let dedupe_key = config.dedupe_key.clone();
642    let retry = harn_vm::TriggerRetryConfig::new(
643        config.retry.max,
644        match config.retry.backoff {
645            TriggerRetryBackoff::Immediate => harn_vm::RetryPolicy::Linear { delay_ms: 0 },
646            TriggerRetryBackoff::Svix => harn_vm::RetryPolicy::Svix,
647        },
648    );
649    let filter = config.filter.clone();
650    let dedupe_retention_days = config.retry.retention_days;
651    let daily_cost_usd = config.budget.daily_cost_usd;
652    let hourly_cost_usd = config.budget.hourly_cost_usd;
653    let max_autonomous_decisions_per_hour = config.budget.max_autonomous_decisions_per_hour;
654    let max_autonomous_decisions_per_day = config.budget.max_autonomous_decisions_per_day;
655    let on_budget_exhausted = config.budget.on_budget_exhausted;
656    let max_concurrent = flow_control.concurrency.as_ref().map(|config| config.max);
657    let manifest_path = Some(config.manifest_path.clone());
658    let package_name = config.package_name.clone();
659
660    let fingerprint = serde_json::to_string(&serde_json::json!({
661        "id": &id,
662        "kind": &kind,
663        "provider": provider.as_str(),
664        "autonomy_tier": autonomy_tier,
665        "match": config.match_,
666        "when": when_raw,
667        "when_budget": config.when_budget,
668        "handler": handler_descriptor,
669        "dedupe_key": &dedupe_key,
670        "retry": config.retry,
671        "dispatch_priority": config.dispatch_priority,
672        "budget": config.budget,
673        "flow_control": {
674            "concurrency": config.concurrency,
675            "throttle": config.throttle,
676            "rate_limit": config.rate_limit,
677            "debounce": config.debounce,
678            "singleton": config.singleton,
679            "batch": config.batch,
680            "priority": config.priority_flow,
681        },
682        "window": config.window,
683        "secrets": config.secrets,
684        "filter": &filter,
685        "kind_specific": config.kind_specific,
686        "manifest_path": &manifest_path,
687        "package_name": &package_name,
688    }))
689    .unwrap_or_else(|_| format!("{}:{}:{}", id, kind, provider.as_str()));
690
691    harn_vm::TriggerBindingSpec {
692        id,
693        source: harn_vm::TriggerBindingSource::Manifest,
694        kind,
695        provider,
696        autonomy_tier,
697        handler,
698        dispatch_priority: worker_queue_priority(config.dispatch_priority),
699        when,
700        when_budget,
701        retry,
702        match_events,
703        dedupe_key,
704        filter,
705        dedupe_retention_days,
706        daily_cost_usd,
707        hourly_cost_usd,
708        max_autonomous_decisions_per_hour,
709        max_autonomous_decisions_per_day,
710        on_budget_exhausted,
711        max_concurrent,
712        flow_control,
713        manifest_path,
714        package_name,
715        definition_fingerprint: fingerprint,
716    }
717}
718
719pub async fn install_manifest_triggers(
720    vm: &mut harn_vm::Vm,
721    extensions: &RuntimeExtensions,
722) -> Result<(), PackageError> {
723    install_orchestrator_budget(extensions);
724    let collected = collect_manifest_triggers(vm, extensions).await?;
725    let mut bindings: Vec<_> = collected
726        .iter()
727        .cloned()
728        .map(manifest_trigger_binding_spec)
729        .collect();
730    bindings.extend(collect_persona_trigger_binding_specs(extensions)?);
731    harn_vm::install_manifest_triggers(bindings)
732        .await
733        .map_err(|error| PackageError::Extensions(error.to_string()))
734}
735
736pub async fn install_collected_manifest_triggers(
737    collected: &[CollectedManifestTrigger],
738) -> Result<(), PackageError> {
739    let bindings = collected
740        .iter()
741        .cloned()
742        .map(manifest_trigger_binding_spec)
743        .collect();
744    harn_vm::install_manifest_triggers(bindings)
745        .await
746        .map_err(|error| PackageError::Extensions(error.to_string()))
747}
748
749pub fn collect_persona_trigger_binding_specs(
750    extensions: &RuntimeExtensions,
751) -> Result<Vec<harn_vm::TriggerBindingSpec>, PackageError> {
752    let Some(manifest) = extensions.root_manifest.clone() else {
753        return Ok(Vec::new());
754    };
755    let manifest_path = extensions
756        .root_manifest_path
757        .clone()
758        .unwrap_or_else(|| PathBuf::from(MANIFEST));
759    let manifest_dir = extensions
760        .root_manifest_dir
761        .clone()
762        .or_else(|| manifest_path.parent().map(Path::to_path_buf))
763        .unwrap_or_else(|| PathBuf::from("."));
764    let resolved = validate_and_resolve_personas(manifest, manifest_path.clone(), manifest_dir)
765        .map_err(|errors| {
766            errors
767                .iter()
768                .map(ToString::to_string)
769                .collect::<Vec<_>>()
770                .join("\n")
771        })?;
772    let mut bindings = Vec::new();
773    for persona in resolved.personas {
774        let Some(name) = persona.name.clone() else {
775            continue;
776        };
777        for trigger in &persona.triggers {
778            let Some((provider, kind)) = trigger.split_once('.') else {
779                continue;
780            };
781            let provider = provider.trim();
782            let kind = kind.trim();
783            if provider.is_empty() || kind.is_empty() {
784                continue;
785            }
786            bindings.push(persona_trigger_binding_spec(
787                &resolved.manifest_path,
788                &name,
789                provider,
790                kind,
791                &persona,
792            ));
793        }
794    }
795    Ok(bindings)
796}
797
798fn persona_trigger_binding_spec(
799    manifest_path: &Path,
800    name: &str,
801    provider: &str,
802    kind: &str,
803    persona: &PersonaManifestEntry,
804) -> harn_vm::TriggerBindingSpec {
805    let runtime_binding = persona_runtime_binding(name, persona);
806    let id = format!("persona.{name}.{provider}.{kind}");
807    let handler = harn_vm::TriggerHandlerSpec::Persona {
808        binding: runtime_binding.clone(),
809    };
810    let fingerprint = serde_json::to_string(&serde_json::json!({
811        "id": &id,
812        "kind": kind,
813        "provider": provider,
814        "handler": {
815            "kind": "persona",
816            "name": name,
817            "entry_workflow": runtime_binding.entry_workflow,
818        },
819        "budget": runtime_binding.budget,
820        "manifest_path": manifest_path,
821    }))
822    .unwrap_or_else(|_| format!("{id}:{provider}:{kind}:{name}"));
823
824    harn_vm::TriggerBindingSpec {
825        id,
826        source: harn_vm::TriggerBindingSource::Manifest,
827        kind: kind.to_string(),
828        provider: harn_vm::ProviderId::from(provider.to_string()),
829        autonomy_tier: persona
830            .autonomy_tier
831            .map(persona_autonomy_to_vm)
832            .unwrap_or(harn_vm::AutonomyTier::Suggest),
833        handler,
834        dispatch_priority: harn_vm::WorkerQueuePriority::Normal,
835        when: None,
836        when_budget: None,
837        retry: harn_vm::TriggerRetryConfig::default(),
838        match_events: vec![kind.to_string()],
839        dedupe_key: None,
840        filter: None,
841        dedupe_retention_days: 7,
842        daily_cost_usd: persona.budget.daily_usd,
843        hourly_cost_usd: persona.budget.hourly_usd,
844        max_autonomous_decisions_per_hour: None,
845        max_autonomous_decisions_per_day: None,
846        on_budget_exhausted: harn_vm::TriggerBudgetExhaustionStrategy::RetryLater,
847        max_concurrent: None,
848        flow_control: harn_vm::TriggerFlowControlConfig::default(),
849        manifest_path: Some(manifest_path.to_path_buf()),
850        package_name: None,
851        definition_fingerprint: fingerprint,
852    }
853}
854
855fn persona_autonomy_to_vm(value: PersonaAutonomyTier) -> harn_vm::AutonomyTier {
856    match value {
857        PersonaAutonomyTier::Shadow => harn_vm::AutonomyTier::Shadow,
858        PersonaAutonomyTier::Suggest => harn_vm::AutonomyTier::Suggest,
859        PersonaAutonomyTier::ActWithApproval => harn_vm::AutonomyTier::ActWithApproval,
860        PersonaAutonomyTier::ActAuto => harn_vm::AutonomyTier::ActAuto,
861    }
862}
863
864fn persona_template_ref(persona: &PersonaManifestEntry) -> Option<String> {
865    persona
866        .package_source
867        .package
868        .as_ref()
869        .zip(persona.version.as_ref())
870        .map(|(package, version)| format!("{package}@{version}"))
871        .or_else(|| persona.package_source.package.clone())
872        .or_else(|| {
873            persona
874                .name
875                .as_ref()
876                .zip(persona.version.as_ref())
877                .map(|(name, version)| format!("{name}@{version}"))
878        })
879}
880
881pub fn load_personas_from_manifest_path(
882    manifest_path: &Path,
883) -> Result<ResolvedPersonaManifest, Vec<PersonaValidationError>> {
884    let manifest_path = if manifest_path.is_dir() {
885        manifest_path.join(MANIFEST)
886    } else {
887        manifest_path.to_path_buf()
888    };
889    let manifest_dir = manifest_path
890        .parent()
891        .map(Path::to_path_buf)
892        .unwrap_or_else(|| PathBuf::from("."));
893    if manifest_path.extension().and_then(|ext| ext.to_str()) == Some("harn") {
894        return match harn_modules::personas::parse_persona_source_file(&manifest_path) {
895            Ok(document) if !document.personas.is_empty() => {
896                validate_and_resolve_standalone_personas(
897                    document.personas,
898                    manifest_path,
899                    manifest_dir,
900                )
901            }
902            Ok(_) => Err(vec![PersonaValidationError {
903                manifest_path: manifest_path.clone(),
904                field_path: "persona".to_string(),
905                message: "no @persona declarations found".to_string(),
906            }]),
907            Err(message) => Err(vec![PersonaValidationError {
908                manifest_path: manifest_path.clone(),
909                field_path: "persona".to_string(),
910                message,
911            }]),
912        };
913    }
914    let manifest = match read_manifest_from_path(&manifest_path) {
915        Ok(manifest) => manifest,
916        Err(message) => {
917            if let Ok(document) =
918                harn_modules::personas::parse_persona_manifest_file(&manifest_path)
919            {
920                if !document.personas.is_empty() {
921                    return validate_and_resolve_standalone_personas(
922                        document.personas,
923                        manifest_path,
924                        manifest_dir,
925                    );
926                }
927            }
928            return Err(vec![PersonaValidationError {
929                manifest_path: manifest_path.clone(),
930                field_path: "harn.toml".to_string(),
931                message: message.to_string(),
932            }]);
933        }
934    };
935    if manifest.personas.is_empty() {
936        if let Ok(document) = harn_modules::personas::parse_persona_manifest_file(&manifest_path) {
937            if !document.personas.is_empty() {
938                return validate_and_resolve_standalone_personas(
939                    document.personas,
940                    manifest_path,
941                    manifest_dir,
942                );
943            }
944        }
945    }
946    validate_and_resolve_personas(manifest, manifest_path, manifest_dir)
947}
948
949fn validate_and_resolve_standalone_personas(
950    personas: Vec<PersonaManifestEntry>,
951    manifest_path: PathBuf,
952    manifest_dir: PathBuf,
953) -> Result<ResolvedPersonaManifest, Vec<PersonaValidationError>> {
954    let known_names = personas
955        .iter()
956        .filter_map(|persona| persona.name.as_ref())
957        .filter(|name| !name.trim().is_empty())
958        .cloned()
959        .collect();
960    let context = harn_modules::personas::PersonaValidationContext {
961        known_capabilities: harn_modules::personas::default_persona_capabilities(),
962        known_tools: BTreeSet::new(),
963        known_names,
964    };
965    harn_modules::personas::validate_persona_manifests(&manifest_path, &personas, &context)?;
966    Ok(ResolvedPersonaManifest {
967        manifest_path,
968        manifest_dir,
969        personas,
970    })
971}
972
973pub fn load_personas_config(
974    anchor: Option<&Path>,
975) -> Result<Option<ResolvedPersonaManifest>, Vec<PersonaValidationError>> {
976    let anchor = anchor
977        .map(Path::to_path_buf)
978        .unwrap_or_else(|| std::env::current_dir().unwrap_or_else(|_| PathBuf::from(".")));
979    let Some((manifest, dir)) = find_nearest_manifest(&anchor) else {
980        return Ok(None);
981    };
982    let manifest_path = dir.join(MANIFEST);
983    validate_and_resolve_personas(manifest, manifest_path, dir).map(Some)
984}
985
986pub(crate) fn validate_and_resolve_personas(
987    manifest: Manifest,
988    manifest_path: PathBuf,
989    manifest_dir: PathBuf,
990) -> Result<ResolvedPersonaManifest, Vec<PersonaValidationError>> {
991    let known_capabilities = known_persona_capabilities(&manifest, &manifest_dir);
992    let known_tools = known_persona_tools(&manifest);
993    let known_names: BTreeSet<String> = manifest
994        .personas
995        .iter()
996        .filter_map(|persona| persona.name.as_ref())
997        .filter(|name| !name.trim().is_empty())
998        .cloned()
999        .collect();
1000    let context = harn_modules::personas::PersonaValidationContext {
1001        known_capabilities,
1002        known_tools,
1003        known_names,
1004    };
1005    if let Err(errors) = harn_modules::personas::validate_persona_manifests(
1006        &manifest_path,
1007        &manifest.personas,
1008        &context,
1009    ) {
1010        Err(errors)
1011    } else {
1012        let mut personas = manifest.personas;
1013        attach_entry_workflow_steps(&mut personas, &manifest_dir);
1014        Ok(ResolvedPersonaManifest {
1015            manifest_path,
1016            manifest_dir,
1017            personas,
1018        })
1019    }
1020}
1021
1022fn attach_entry_workflow_steps(personas: &mut [PersonaManifestEntry], manifest_dir: &Path) {
1023    for persona in personas {
1024        if !persona.steps.is_empty() {
1025            continue;
1026        }
1027        let Some(entry_workflow) = persona.entry_workflow.as_deref() else {
1028            continue;
1029        };
1030        let Some((path, entry_name)) = entry_workflow.split_once('#') else {
1031            continue;
1032        };
1033        if !path.ends_with(".harn") {
1034            continue;
1035        }
1036        let source_path = manifest_dir.join(path);
1037        let Ok(document) = harn_modules::personas::parse_persona_source_file(&source_path) else {
1038            continue;
1039        };
1040        let entry_name = entry_name.trim();
1041        if let Some(source_persona) = document.personas.iter().find(|candidate| {
1042            candidate.entry_workflow.as_deref() == Some(entry_name)
1043                || candidate.name.as_deref() == persona.name.as_deref()
1044        }) {
1045            persona.steps.clone_from(&source_persona.steps);
1046        }
1047    }
1048}
1049
1050pub(crate) fn known_persona_capabilities(
1051    manifest: &Manifest,
1052    manifest_dir: &Path,
1053) -> BTreeSet<String> {
1054    let mut capabilities = BTreeSet::new();
1055    for (capability, operations) in default_persona_capability_map() {
1056        for operation in operations {
1057            capabilities.insert(format!("{capability}.{operation}"));
1058        }
1059    }
1060    for (capability, operations) in &manifest.check.host_capabilities {
1061        for operation in operations {
1062            capabilities.insert(format!("{capability}.{operation}"));
1063        }
1064    }
1065    if let Some(path) = manifest.check.host_capabilities_path.as_deref() {
1066        let path = PathBuf::from(path);
1067        let path = if path.is_absolute() {
1068            path
1069        } else {
1070            manifest_dir.join(path)
1071        };
1072        if let Ok(content) = fs::read_to_string(path) {
1073            let parsed_json = serde_json::from_str::<serde_json::Value>(&content).ok();
1074            let parsed_toml = toml::from_str::<toml::Value>(&content)
1075                .ok()
1076                .and_then(|value| serde_json::to_value(value).ok());
1077            if let Some(value) = parsed_json.or(parsed_toml) {
1078                collect_persona_capabilities_from_json(&value, &mut capabilities);
1079            }
1080        }
1081    }
1082    capabilities
1083}
1084
1085pub(crate) fn collect_persona_capabilities_from_json(
1086    value: &serde_json::Value,
1087    out: &mut BTreeSet<String>,
1088) {
1089    let root = value.get("capabilities").unwrap_or(value);
1090    let Some(capabilities) = root.as_object() else {
1091        return;
1092    };
1093    for (capability, entry) in capabilities {
1094        if let Some(list) = entry.as_array() {
1095            for item in list {
1096                if let Some(operation) = item.as_str() {
1097                    out.insert(format!("{capability}.{operation}"));
1098                }
1099            }
1100        } else if let Some(obj) = entry.as_object() {
1101            if let Some(list) = obj
1102                .get("operations")
1103                .or_else(|| obj.get("ops"))
1104                .and_then(|v| v.as_array())
1105            {
1106                for item in list {
1107                    if let Some(operation) = item.as_str() {
1108                        out.insert(format!("{capability}.{operation}"));
1109                    }
1110                }
1111            } else {
1112                for (operation, enabled) in obj {
1113                    if enabled.as_bool().unwrap_or(true) {
1114                        out.insert(format!("{capability}.{operation}"));
1115                    }
1116                }
1117            }
1118        }
1119    }
1120}
1121
1122pub(crate) fn default_persona_capability_map() -> BTreeMap<&'static str, Vec<&'static str>> {
1123    harn_modules::personas::default_persona_capability_map()
1124}
1125
1126pub(crate) fn known_persona_tools(manifest: &Manifest) -> BTreeSet<String> {
1127    let mut tools = BTreeSet::from([
1128        "a2a".to_string(),
1129        "acp".to_string(),
1130        "ci".to_string(),
1131        "filesystem".to_string(),
1132        "github".to_string(),
1133        "linear".to_string(),
1134        "mcp".to_string(),
1135        "notion".to_string(),
1136        "pagerduty".to_string(),
1137        "shell".to_string(),
1138        "slack".to_string(),
1139    ]);
1140    for server in &manifest.mcp {
1141        tools.insert(server.name.clone());
1142    }
1143    for provider in &manifest.providers {
1144        tools.insert(provider.id.as_str().to_string());
1145    }
1146    for trigger in &manifest.triggers {
1147        if let Some(provider) = trigger.provider.as_ref() {
1148            tools.insert(provider.as_str().to_string());
1149        }
1150        for source in &trigger.sources {
1151            tools.insert(source.provider.as_str().to_string());
1152        }
1153    }
1154    tools
1155}
1156
1157#[cfg(test)]
1158#[path = "extensions_tests.rs"]
1159mod tests;