Expand description
One seat over the habitats. Each habitat keeps its own crate.
Cards are read-only. Remember/Prefer POST /v1/atoms and never extract
on write. Consensus is a different crate, then the tracker verb. Policyd
is argv law: this process does not reload a pack as a check.
Modules§
- approval
- One-use consent for an ask verdict when the caller has no approval UI.
- hud
ljos hud— exec the separateljos-hudbinary.- jev
- The prompt hook’s judgments through Jev, TypeSafe’s decision model, on TypeSafe’s own API or OpenRouter’s Decisions API: which candidate claims bear on a prompt, whether the prompt corrects the agent, and whether it puts a choice.
- persona_
session - A persona’s session: the runner that thinks as the persona, in a pane the person can watch and talk to, kept across hand-offs.
- sync
- Sharing the seat’s memory across machines through the tracker repository that already travels between them.
Structs§
- BumpRow
- One module of a bump bundle as the tracker will hold it.
- Calibration
- One voter’s forecast record. The bins are the probabilities actually stated, in thousandths, each with how many times it was stated and how many of those events occurred. Murphy’s categories are those values, not a grid this seat invented.
- Campaign
- A campaign state file: the package it builds, the target, its findings.
- Commit
Lock - An exclusive advisory lock on a file, held until dropped. Taking it blocks; a lock that cannot be opened is no lock, and the commit goes on as it would have without one.
- Consensus
Step - Crate
Version - A registry answer and where it came from: the day cache on disk, or the registry itself.
- Event
- One dated event on an issue’s timeline, from whichever store holds it.
- Finding
- One typed finding from an eb-stack campaign state file, flattened to what a seat reads and remembers.
- Forecast
learn_aboutandlearn_anchorstogether, written to the pack: the rows, then the personas the outcome moved. Returns what was written.- Habitat
- One habitat and whether it answers.
- Harness
- One agent runner, as the seat’s own configuration describes it. The seat
ships no runner’s name: the file at
harnesses_pathnames them, one table each, andonboardanddoctorread it. - Harnesses
- The whole file:
[[harness]]tables. - Hold
- What a conversation left beside the claim graph when it took a node: the name it held under, its seat, the runner process, and when. The claim graph keeps only the hashed actor; this is how a later conversation that finds the node held learns who holds it, and whether that conversation is still running.
- Hook
Call - What the runner’s hook hands the seat: the event, and the text worth asking the pack about. From a tool call, the command about to run; from a prompt, the prompt.
- Partition
- Murphy’s partition of the Brier score (1973,
doi:10.1175/1520-0450(1973)012<0595:ANVPOT>2.0.CO;2).
brier = reliability - resolution + uncertainty. - Persona
- A voter with a view of its own: a persona.
anchorin[0, 1]is how far it moves off its ballot in a settle; 0 never moves, 1 is a plain DeGroot voter.entitiesare the domains it speaks to. - Playbook
- A recipe a sitting copies before personas enter.
modelsare optional spawn hints; every panel still ends inljos vote --asthenljos consensus. - Prediction
- One voter’s forecast on one issue: what share the others give each option, or the option it expects to win.
- Push
Call - A
git pushfound in a shell line: where it runs, its arguments afterpush, and theLJOS_CITEit carries. - Push
Facts - What the gate knows about the remote a push goes to.
- Reading
- One reading of a habit: a number the seat keeps measuring, with the
cadence it is measured at. A reading is a claim of kind
habitthat supersedes the reading before it, so the pack holds one live value a habit andsearch --as-ofstill answers what it stood at then; its review clock is the cadence, sodueand the hook say when the next reading is late. - Remembered
- What
remember_findingsdid with one finding. - Rule
- Argv law kept in the pack: a glob over the command line, a verdict, and
the reason a reader sees when it fires.
denystops the action at the runner and underljos policy;askhands it to the person. - Said
- What a habitat printed, kept for a caller that has to hand it on. A non-zero exit is an error carrying stderr.
- Seat
- Who is sitting. The seat is the program that connected: the name a runner remembers, votes and earns trust under, the same across its conversations. The holder is that seat in one conversation: the name its claims are held under, so two conversations of one runner hold two tickets while a vote from either counts for the one voter.
- Step
- One step an onboarding took, or would take.
- Stop
Turn - The turn a stop ends, read from the runner’s transcript: the person’s last request, the shell commands since it, the output of the latest test run (or of the last commands when none ran), and the final message.
- Trust
- One row of the influence graph:
fromlistens totowithweight.aboutscopes the row to the domains it speaks to: a row with none applies everywhere, a row with some applies when one of them meets the issue at hand (its title, or the entities of the island it activates).
Enums§
- Access
- Whose a remote is, as far as the seat can tell.
- Hook
Shape - The hook contract a call arrived in, told apart by its stdin. The
runners share one name for the answer,
permissionDecision, but not what they do with it. - JevVote
- What a Jev ballot did: cast under the persona’s name, or handed to a subagent because Jev was not sure enough.
- Push
Tier - How much a push needs before it runs.
Constants§
- BROAD_
EPSILON - The confidence bound a
broadissue settles under: voters within this L1 distance of each other’s opinion listen to each other. - BROAD_
TAG - The tag on an issue that asks for bounded confidence: a panel for a broad audience is allowed to settle into clusters, and the settle says how far apart they are, where a single-position model would average them away. Without it the anchored model runs.
- CARD_
NAMES - Working-core files this seat will print. Nothing else, and never write.
- CORRECTION_
CUES - Phrases a person uses when the agent has forgotten something it was told. A prompt that opens this way is a preference or a lesson the pack does not hold yet, and the moment to write it is now, before the work that follows.
- DECISION_
CUES - Phrases that put a choice to the agent. A choice with more than one defensible answer is a ballot, and a ballot needs an issue to sit on.
- DECISION_
OPENING - How much of a prompt the decision cues are looked for in.
- DUE_
SHOWN_ TTL_ S - How long a due row stays open to
gradedafter a page showed it. - DUE_
WINDOW_ DAYS - How far back the prompt’s due line looks.
- HABIT_
ENTITY - The entity a habit’s readings carry, so a name finds them.
- HABIT_
EVERY_ S - A habit’s cadence when none is given: a week, in seconds.
- HARNESSES_
EXAMPLE - An example of the file, with placeholder names.
ljos onboard --exampleprints it; the two shapes are a registering command and a config file. - HOOK_
DEADLINE_ MS - How long a context hook may take before it answers with nothing. The shortest runner cut-off seen is grok’s 15 s on a prompt; this leaves it room on a loaded host.
- HOOK_
EVENTS - The events the memory hook fires on when a runner’s table names none:
the prompt, which carries the task in the person’s words. A tool call
carries the command about to run and is a cue too; a runner asks for it
with
hook_events. The default came out of a panel of this seat’s personas: a turn issues many shell commands and one prompt. - HOOK_
MATCHERS - The events the hook knows a matcher for; any other event takes
*. - HOOK_
RERANK_ BUDGET_ MS - How long the prompt hook waits for the reranked search. Runners cut a hook off at 10 to 20 s, and a loaded host has made the rerank alone take longer than that.
- HOOK_
SCORE_ FLOOR - The floor a hit must reach, as a share of the strongest hit’s score, to be injected. A command line matches many claims weakly; only the ones that match it as well as the best does are worth the agent’s context. The floor is not relevance: a vague sentence scores high on unrelated lessons, so a hit must also name a content word of the cue.
- JEV_
ALONE_ AT - How sure Jev must be that a claim bears on a prompt it shares no content word with.
- LEARN_
BETA - The factor a refuted voter’s rows shrink by (Hedge, doi:10.1006/jcss.1997.1504).
- OOM_
RECENT_ S - How long an OOM kill keeps the host row failing.
- PANEL_
BY_ VIEW - How many specialists a panel seats by their views when no domain and no generalist speaks to the issue.
- PLAYBOOK_
NAMES - The closed set. Write, list, bind, and copy refuse any other name.
- PLAYBOOK_
NOTE_ PREFIX - A tracker logbook note that binds a playbook name to an issue. Latest such note wins; empty rest is the sitting-scoped drop finish/release write.
- PLUGIN_
TEMPLATES - The plugins
ljoscarries for runners whose hooks are code, by name.{ljos}in each is filled with the absolute path at onboard. - POLICY_
TCB - Printed on stderr.
ljos-policydis the TCB when it exists. - PRINCIPLES
- Five named principles, invocable mid-sitting, mapped onto existing law.
- PROTOCOL
- The sitting protocol: which store answers which question, the order of
verbs before, during and after the work, and the refusals worth knowing.
ljos protocolprints it,ljos onboardinstalls it as a skill, and the server serves it atljos://protocol. Harness agnostic on purpose. - REQUIRED
- The habitats the seat needs. Encoder and policyd move with the rest.
- RUBRIC
- The scoring sheet a compose is voted on. Personas vote the compose, not accept-at-most-one on the designs.
- SEAT_
ENTITY - The entity every write carries: which seat wrote it. Many seats share one pack, and a reader can then see whose lesson it is reading.
- SEAT_
PATHS - The files that are the seat’s law and its reach into each runner: the binaries the hooks run and the files that register them. An agent that may rewrite them can rewrite the law, so only the person does.
- SEAT_
VERBS - The seat verb a bare tracker verb stands in for: the tracker writes one store, the seat’s verb writes every store and weighs the ballot.
- SEAT_
WORKSPACE - The workspace the seat’s memory lives in when nothing names one. The
pack’s command line keys a workspace to the repository it stands in;
a seat is one memory across every repository it works in, so the seat
pins one.
PACKSET_WORKSPACEoverrides it. - SHIPPED_
PLAYBOOK_ NAMES - The five shipped recipes. Kind
playbook, weighed not recalled. - SITTING_
DUE - How many due rows a sitting prints before the summary line.
- SITTING_
TIMELINE - How many dated events a sitting’s timeline prints. Protocol: last twelve.
- TRUST_
FLOOR - The least a row can fall to, so a voter who is right again is heard again.
- WORK_
NUDGE_ EVERY - Tool calls a conversation may make without a word to the seat before the hook reminds it. A sitting opened at the start and nothing after it is how long work went unrecorded.
Functions§
- add_
entities - Add entities to a body without losing the seat’s.
- age_of
- How long ago a stamp was, in words a reader can place:
today,yesterday,N days ago, then weeks, months and years once the count stops fitting the smaller unit. Empty when the stamp is missing or unreadable,in N daysfor a stamp ahead ofnow. - anchors_
json - Anchors as the settles take them:
{"name": anchor, ...}. - announce_
seat - The MCP server, once a client has said who it is: the seat is the
client’s name. The holder is any
*_SESSION_IDthe runner stamped, else that seat tagged with the runner’s process. The record under the runtime directory is howljosin a shell the same runner opened names the same seat and holder. A runner started from another runner’s shell carries that runner’s ids; it holds under its own process and leaves the parent’s records alone. - as_
thread - Run
fas the thread a runner named on this call, when it named one. A runner that spawns one server for many conversations names each in the call’s metadata rather than in the server’s environment. - ask_
persona ljos ask NAME TEXT: the persona’s own session takes the question, in its open pane or one that continues its session.- atom_
body - Explicit claim body. The text is stored as given; never harvested. The entities open with the seat that wrote it.
- atom_
kind - Remember → lesson, Prefer → preference. Trust rows go through
trust_atom. - atom_
source - Where a claim was written: the runner, the conversation, the host and, when the runner stamped one, the turn. An audit reads a claim’s lineage here instead of guessing it from its entities.
- atoms_
lean - The pack’s live atoms without their dense vectors. Every reader here
wants texts, kinds, review clocks, trust or rules; the vectors are nine
tenths of the listing, and parsing them grew one ljos-mcp from 10 to
66 MB and kept it. A writer older than
embedding=omitsends them anyway, and the answer is the same. - ballots_
from_ json (agent, choice)pairs from a tracker’svote --json.- bind_
playbook - Hold
nameonissueuntil finish or release. A different name while one is held is refused: mid-sitting turns re-read the same note. - block_
output - The answer that keeps an agent going one more round with
reason, in the runner’s words for it. - bound_
playbook - The playbook name this sitting holds, if one was bound. Tracker note is the bind that survives the process; the runtime cache is only when the tracker does not answer.
- brief
- The brief a subagent playing a persona starts from: the persona’s view and domains, what the seat knows on those domains (preferences first), and the issue’s working set. One text, so a panel member reads the same seat the rest do and still reads it its own way.
- brief_
playbook_ blocks - The three blocks a brief carries: playbook step (full body), named principles, arena rubric.
- brier
- Quadratic score of a stated probability against the outcome.
- bump_
issue_ id - A deterministic issue id for a module of a generation: the project, then eight base-36 digits of the module and generation hashed.
- bump_
plan - Put a bundle’s modules on the tracker: one child issue per module under
parent, blockers along the dependency edges, ids the same on every run so a rerun holds what exists and adds what is missing.vissue readythen lists the modules a seat can build now, and a sitting refuses the rest until their blockers close. - bump_
rows - The plan a bundle implies for the tracker: one row per module the lock builds, blockers along the SBOM’s dependency edges. Nothing is written.
- calibrate
- Turn a project’s voting history into trust rows without anyone naming
an outcome: Dawid and Skene’s accuracy per voter
(doi:10.2307/2346806), from
ljos-consensus reliability, turned into the weight every other voter gives that voter bycalibration_weights: log odds, so a voter right nine times in ten outweighs one right six times in ten by five to one, not three to two. Rows are complete and floored atTRUST_FLOOR, so the settle sees the whole graph. - calibration_
from_ atoms - The latest forecast record per voter, from the trust rows that carry one.
- calibration_
weights - The weight a voter of estimated accuracy
pearns: the log oddsln(p / (1 - p)), the optimal weight for independent voters on a two-way choice (Nitzan and Paroush, doi:10.2307/2526438; a weighted majority under these weights is the maximum-likelihood decision), withpheld inside[0.01, 0.99]so a perfect record does not become an infinite vote, and a voter at or under chance atTRUST_FLOOR. The weights are scaled so the most reliable voter stands at one, which is the scale the trust rows live on; the ratios between voters are the rule’s. - came_
due_ since - The due claims that came due at or after
since(RFC 3339): a review date inside the window, or, for a claim never reviewed, a write inside it. The rest is backlog the nudge does not count. - card_
paths - cards
- Read-only cards. Only
CARD_NAMES, never created, never written. - cast_
jev - Cast Jev’s ballot as the persona: the chosen option’s probability is
the ballot’s confidence, the forecast is its prediction, and a note on
the issue says the ballot came from Jev. Jev’s own
confidenceis a spread over the options, not a probability, so it only decides escalation. - cite_
stands - Whether a cite stands: a deed accession
deedar currenttakes, or an issue whose ballots settle (vissue consensus --gate) or that closed as a decision. The text says what it stood on. - claim
- Take a session node, and when the claim graph refuses because the assignee still holds another node, say which tracker id that is and the two verbs that free it. The bare refusal names a 32-hex id nobody can act on.
- claim_
graph_ absent - The directory claimdag would create, when its refusal says the seat has no work graph yet because nothing was ever claimed. A fresh host is not a fault: the sitting’s first claim creates the graph.
- clean_
user_ prompt - The person’s request out of the wrapper a runner puts around it: agy
sends
<USER_REQUEST>...</USER_REQUEST>beside metadata blocks, and only the request is a cue. - command_
segments - The commands a shell line runs: split on
&&,||,;,|and new lines outside quotes, each with leadingNAME=valueassignments and the prefixessudo,env,time,nohupandexectaken off. A rule anchored at a command’s start then seescd x && git pushandFOO=1 git pushas the push they run, and quoted text is not split, so a commit message naming a command is not that command. - complete
- Close a sitting: remember the lesson when there is one, fire the island the issue’s title activates, complete the session node, and learn from the outcome when one is named. Without a lesson the report says so, because a sitting that taught nothing worth two sentences is rare and worth noticing.
- conflicts
- Consolidate the seat’s memory: every claim that replaces an earlier
one (a rewrite, a new object under the same head, a correction, an
explicit supersedes) closes the earlier one’s window and names it.
Candidate contradictions from the geometry of the seat’s memory: the
landscapebinary reads the pack’s embeddings at the point scale and prints the lowest passes between single memories, which on a record of planted contradictions were the contradictions nine times in ten. The replacement rule reads words; this reads distance, in any language. A candidate is for a person orconsolidateto judge; nothing is written here.landscapeis an optional habitat: absent, this says so. - consensus_
steps ljos-consensusfirst, thenvissue consensus, both under the pack’s trust rows when there are any. Missing bins are skipped.- consensus_
steps_ anchored consensus_stepspassing the personas’ anchors to both settles as--susceptibility-of, so a persona holds its ballot as much as it says.- consensus_
steps_ for consensus_steps_anchoredwith the model flags the issue’s tags ask for on the model crate’s settle.- conversation_
tag - A short tag for one conversation from the process that runs it: the pid
in base 36, so
acme-cli-39ureads as a name and not a number. - copy_
playbook - Bind
nametoissueand return the full recipe body. This is the copy into the working set; sitting prints it before recall. - doctor
- Which habitats answer: binaries on
PATH, the pack overPACKSET_URL, the deed store, the tracker, the claim graph. - doctor_
seat - The seat’s own rows: binaries, pack, host key, deed store, tracker, claim graph. What a sitting checks; the runner rows are onboarding.
- drop_
playbook - Drop the sticky name. Finish and release call this; a new task is a
new sitting. Writes an empty
playbook:note so the next sitting does not reprint the previous recipe, and unlinks the runtime cache. - due
- What the pack holds for review now.
- due_of
- The live atoms whose review is due at
now(RFC 3339 UTC), soonest first. A claim that has never entered the review clock has nodue_at; it is due now, and grading it puts it on the clock. Trust and persona rows are weighed, not recalled, and never come up. - due_
on_ island_ first - The due claims with the island’s first, keeping each group’s due order: the claims a sitting’s work bears on are the ones its agent can grade from what it is about to read, rather than the oldest in the pack.
- due_
page - The soonest
SITTING_DUEclaims, how many are due in all, and the clock line. Read-only: the sweep stays onljos dueand on a sitting. - due_
report - The review clock as
ljos dueprints it: the soonestSITTING_DUEdue atoms, then the summary. Those rows are the onesgradedtakes. Withall, every due atom is listed to read, and none is put up for grading: a list of a thousand is a census, not a review. - due_
shown_ live - The ids a due page showed inside
DUE_SHOWN_TTL_S, read fromtext(EPOCH\tIDlines) atnow. - enclose
- Deeds to enclose: the satchel’s
needsplus what the pack cites, once each. - enclosed_
atoms - Every atom in a satchel’s
data/atoms/*.jsonl. - expand_
leading_ tilde rawwith a leading~or~/put againsthome;Nonewhen there is nothing to expand.- finding_
lesson - The lesson a finding leaves: what failed where, then the fix, or that a later attempt got past it. Two short sentences; the pack refuses more, and refuses hard prose.
- finish
- forecasts_
from_ json (agent, choice, confidence)from a tracker’svote --json.- format_
bump_ rows - format_
change - The change since the reading before, signed, or nothing for a first reading.
- format_
consolidation - The pairs a consolidation closed or would close, one a line, then the count and whether it was applied.
- format_
doctor - format_
due - format_
findings - One line per finding: id, status, class, stage, recipe, then the fix or the summary.
- format_
hits - One line per hit: score, how many scorers named it out of how many ran, kind, id, age, text. The age is the one column a reader needs to lay the hits on a timeline; the count is what the hook keys on.
- format_
hubs - One line per hub: score, links, id, text.
- format_
island - One line per activated memory: activation, seed mark, id, text.
- format_
personas - A panel for a runner with no MCP: one brief per persona written to
out, named<persona>.md, and the lines that run it. A runner starts one subagent per file, each ends with the ballot its brief names, andljos consensus ISSUEsettles. - format_
playbook_ copy - The recipe body a sitting copies, including optional spawn hints.
- format_
playbooks - The roster, one playbook per line: name, spawn hints, first sentence.
- format_
readings ljos habit: one line a habit: name, value with unit, the change since the last reading, the age of this one, when the next is due, source.- format_
remembered - format_
seat ljos seat: who is sitting, one field a line.- format_
seat_ row - The doctor’s
seatrow: who votes, who holds, and where the names came from. - format_
steps - format_
sweep - One line on what the sweep did, or nothing when it found nothing.
- format_
write_ ack - One line after a pack write: id, kind, due, text. Not the embedding.
- gate_
push - The verdict the push gate makes of a line the rules asked about:
Nonelets it run. Only anaskon a push is gated; every other verdict, and a line with no push, is the rule’s own. A cited pass is noted on the cited issue, so the record says which decision let it through. - glob_
matches - A glob over a command line:
*matches any run of characters,?one. The match is on the whole line, sorm -rf *isrm -rfand anything after, and*sudo*is sudo anywhere. - graded
- Grade one review: recalled moves the atom out, lapsed brings it back sooner.
- habit
- Take a reading: write it as a claim that supersedes the habit’s earlier
reading, carrying that reading as
was, with its review due one cadence from now. Returns the pack’s answer and the reading it closed. - habit_
text - The claim a reading is stored as. The words are for a reader; the
numbers travel in the atom’s
habitfield. - habits
- The live readings in the seat’s pack.
- hand_
ballot - Hand a persona’s open ballot to its own session, and note on the
issue where it runs.
Nonefor a persona with no runner, whose ballot stays a brief for a subagent. - handover
- Pack a slice of the seat into
out: the tracker’s satchel, the pack’s atoms, the deeds both cite, sealed, and signed when a host key is set. - harnesses_
from - Parse the runners file. An absent file is no runners, not an error.
- harnesses_
path - Where the runners are described:
$XDG_CONFIG_HOME/ljos/harnesses.toml. - has_
unscoped_ inbound - Whether
namealready has the seat’s unscoped inbound row inrows. A third-party unscoped row does not seat this persona. - healthy
- Whether every required habitat answers.
- held_
by_ another_ message - Refusal when another conversation holds the node: names that holder
and still says
held by another, so a concurrent sitting can match it. - held_
issue - The issue this conversation’s holder claimed last and still works: a subagent’s hook runs under its parent’s holder, so this is the work the subagent is a slice of.
- hold_
hook_ context - Remember the prompt’s pack text and the memory ids it names. An empty note leaves a note already held: a later prompt that matches nothing must not erase one the runner has not delivered yet.
- hold_
hook_ note - Hold
contextwith the ids to mark seen when a runner delivers it. - holder_
name - The name this conversation’s claims are held under.
- hook_
already_ running - Whether an identical call (event, session, text) started in the last 20 seconds. A runner that loads another runner’s hook file runs the same hook twice for one event, and both queue on the pack’s one reranker. The first call makes the marker and answers; the second returns at once.
- hook_
call - Read a hook call from the runner’s JSON, or from plain text (an argv
under argv law). Fields:
hook_event_name,tool_name,tool_input(itscommand, else every string value joined),prompt; grok’s camelCasehookEventName,sessionIdandtoolInputread the same. - hook_
call_ as hook_callwith the event the runner’s hooks file named, for a runner whose payload does not carry one.- hook_
context - The context the hook injects. A camel-case runner does not see prompt
stdout, so the ids stay unmarked until the first tool result, or
Stopwhen the turn ran no tool, delivers them. Every other runner is shown this string and the ids are marked now. - hook_
note - The pack note for a prompt, and the memory ids named in it. The ids are not marked seen here: the caller marks them when the runner delivers the note. A camel-case prompt hook’s stdout is discarded, so marking here would burn the note before the model read it.
- hook_
output - The hook’s answer in the runner’s JSON:
additionalContextunder the event that fired. Empty context is no output, which the runner reads as no opinion. - hook_
output_ ruled hook_outputcarrying a rule’s verdict on a tool call:denyoraskas the runner’s permission decision, with the rule’s reason. On a prompt or an argv line the verdict is a line of text.- hook_
subagent - What a hook call says about a subagent: its type when the call fired
inside one (
subagentType, oragent_type), and whether a stop gate already held it this turn (stopHookActive), and the agent’s id when the runner shares one session between a parent and its subagents. - hook_
trace - With
$XDG_RUNTIME_DIR/ljos/hook-tracepresent, one line per hook call tohook-trace.jsonlbeside it: the event as sent and as read, the payload’s top-level key names, the session and subagent type. Key names only, never values, so a runner’s hook contract can be read off a live session without storing what it said. - identity_
or_ seat - The identity a ballot is cast under: the persona named, else the seat
(
whoami), the same name across a runner’s conversations so its record accrues to one voter. - inbound_
floor - The unscoped inbound row a persona is owed: the seat weighs it at 1, everywhere. None when the seat and the persona are the same name (a row cannot weigh itself).
- is_
decision - Whether an issue asks for a decision: a
decisiontag, adecisiontype, or a body line openingOptions:. - is_
regex_ pattern - Whether a rule’s pattern is a regular expression rather than a glob:
it says so with
re:, or it carries a class (\b,\s,\d,\w) or an alternation group, which a glob would read as literal text and never match. - is_
seat_ path - Whether a path names one of
SEAT_PATHS; a backup beside a binary (ljos.bak) is not the binary. - is_
version_ tag - Whether a tag names a release: a version,
v1.2or0.3.0, not a bookmark such ascampaign-sent. - island_
entities - The domains an issue’s island speaks to: the entities of the memories
its title activates, most frequent first, eight at most. What
learnscopes its rows to. - island_
reading - What an activation number is, and whether this call rewrote weights.
- issue_
options - The options an issue puts to a vote: an
Options: A, Bline split on commas, or the- abullets under a bareOptions:line. - issue_
words - The words an issue speaks in: its title’s topic words, its tags, and the entities of the island its title activates when that island is not weak.
- jev_
ballot - Jev’s answer for a persona on an issue, not yet cast: its brief, less the closing instructions a subagent needs, is the state, and the issue’s options are the choices.
- jev_
panel_ stands - Whether a panel’s Jev answers may stand as its ballots: every seated persona sure, and all on one option. Personas answered by one model are correlated voters, so their agreement settles only a question it could not change; a split or an unsure seat goes to subagents.
- jev_
vote - One persona’s ballot through Jev: cast when Jev is sure, noted and left for a subagent when it is not.
- join
- judge_
due_ page ljos due --judge: the review judges weigh each claim on the page against the newer claims about it. One that holds atjev::REVIEW_HOLDS_ATis graded recalled; one at or underjev::REVIEW_FAILS_ATis named for the agent to supersede or withdraw, and stays due; the rest stay due. No claim is lapsed by a judge, since a lapse says a reader forgot it.- last_
user_ text - The text of the person’s last message in a transcript of JSON lines,
read without knowing its schema: the last entry that names a user turn
(a
type,role,sourceorstepTypevalue containinguser), and in it the longest string undertext,content,prompt,message,userMessageoruserResponse. - learn
- The rows every voter holds on every other after
outcomeis known: a voter whose ballot was refuted shrinks bybeta, floored atTRUST_FLOOR; a missing row starts at one. Complete, so the settle sees the whole graph. - learn_
about learnwriting rows scoped toabout: the domains the issue’s island speaks to, so that being wrong about one topic does not cost a voter its standing on every other. An emptyaboutis the unscoped rule.- learn_
anchors - The personas after an outcome: one whose ballot the outcome refuted
moves its anchor toward one by
1 - betaof the gap, so a persona that keeps being wrong listens more; a vindicated one keeps its anchor. The personas that voted are the only ones touched. Acemoglu, Como, Fagnani and Ozdaglar (doi:10.1287/moor.1120.0570) show what a stubborn wrong voter does to a pool; this is the seat’s remedy. - learn_
and_ write - learn_
reading - What a learn did. The rows are the next settle’s weights. This call is not a settle.
The scores, when any ballot stated a probability, are not trust weights.
calibrationis each voter’s record after this outcome is folded in. - learn_
record - Learn from an outcome by the record: each voter’s hits and misses so
far, this outcome added, give its accuracy with one of each smoothed
in, and the rows are the log odds of that scaled to the best voter at
one (
calibration_weights). Measured against multiplicative shrinking (Hedge) on voters of known accuracy, the record reaches the batch calibration and the shrink does not: a voter is weighed by what it got right, not by how many times it has been punished. Rows are complete over the voters and scoped toabout. - learn_
shared learn_aboutwith a fixed share of recovery: after the Hedge step every row moves toward one byshareof the gap, so a voter refuted long ago is not held down forever and the best voter can change (Herbster and Warmuth, doi:10.1023/A:1007424614876). Zero is plain Hedge; the seat’s default.- log_
score - Logarithmic score of the probability assigned to the event that occurred.
- looks_
pasted - Whether a prompt carries pasted material: a pasted block, a code fence, terminal or log output, or many lines. Jev’s injection question is asked of every prompt, and a plain request is not pasted text addressing the agent.
- mark_
seen - mcp_
forward - One tool call answered by a fresh
ljos-mcp: startprogramwithmarkerset, send it the client’s initialize (init, or a plain one), the initialized notification andtools/callwithparams, and return the JSON-RPC answer to the call,resultorerror. - mean_
brier - Mean Brier score over the forecasts that stated a probability, and how
many those were.
Nonewhen nobody stated one. - mean_
log - Mean logarithmic score over the forecasts that stated a probability, how many of those scores were finite, and how many were unbounded.
- murphy
- Reliability, resolution, and uncertainty.
Noneuntil the voter has two forecasts: one forecast makes the partition the score itself. - named_
hook_ spec - The seat’s hooks for a runner whose hooks file maps a hook name to its events: the tool gate on shell commands, the prompt and tool-result notes on each model call, and the stop audit. The payload names no event, so each command is told its own.
- needs_
of - The accessions a satchel’s description says it needs.
- node_
for - The claimdag node standing for
issue, minted with the tracker id as its summary when the graph does not hold it yet. - normalize_
tracker_ env - Expand a leading
~inISSUE_ROOTandVISSUE_ROOTonce, at start. environment.d and MCPenvblocks pass~/...through unexpanded; a tracker crate that predates the fix then resolves it against the working directory, and every childvissueinherits the same relative root. - now_utc
- Now, RFC 3339 UTC to the second, the stamp the pack writes.
- observe
- Add one stated probability to a voter’s record.
- occupancy_
assignee - Occupancy is always
{name}:{issue}. One live claim per name is what made two conversations unseat each other; the issue is already exclusive. Already-scoped names (they contain:) are left alone. - on_path
- onboard
- Register the server and install the skill for one runner named in the
runners file.
jsonregisters nothing and returns the entry to paste.dryreports without writing. - onboard_
from - oom_
recent - Whether the kernel’s OOM count says a kill is recent, and what to keep:
the count and when it last rose. The counter is cumulative since boot,
so a kill counts as recent when the count rose since the last look, or
rose within
OOM_RECENT_S; a first look that finds kills cannot date them and counts them as recent. The record lives in the runtime directory, which a reboot clears with the counter. - open_
blockers - The blockers of an issue that are still open, as
id (STATE), read from the tracker. Empty when the issue is workable, or when the tracker does not answer (the sitting’s doctor already said so). - other_
seat - The seat that wrote a hit, when it was another than this one. Many seats share a pack; a reader is told whose lesson it is reading only when that is news.
- pack
- pack_
last_ write_ ts - The pack’s last write, RFC 3339, for a HUD watch.
Nonewhen the status has no stamp yet. - packset_
consolidate - The rule a write applies on arrival, run over what the pack already
holds. Without
applynothing is written; the pairs are reported. - packset_
forget - Retire one atom from the workspace the cwd resolves to, optionally naming the deed that withdrew it.
- packset_
hubs - The claims the pack’s link graph turns on, highest first: what matters in this seat’s memory by its own connections, before any query.
- packset_
island - The memories a task activates: the pack’s island around the cue. With
fire, the strongest of them fire together and their links gain weight. - packset_
island_ as packset_islandthrough a persona’s lens: the spread follows the weights that persona fired, and a fire writes its weights and not the seat’s. The seat’s own island is the one with no lens.- packset_
search - packset_
search_ as_ of packset_search_optsasked of the pack as it stood atas_of(RFC 3339; a date alone reads as its start): only memories live then answer, what was withdrawn since included and what was learnt since left out.Noneis now. This is the question “what did the seat know when it decided that”, and the pack keeps every record so it can be asked.- packset_
search_ opts packset_searchwith a limit and the cross-encoder rerank: the writer scores the top hits against the query with its reranker, which costs a model call and buys precision. For a brief or a person reading, not for the hook.- packset_
write - packset_
write_ as packset_writeas a persona: the claim carries the persona’s entity, so what a persona learned comes back to it first in its next brief and stays in the seat’s one pack. A persona accumulates its own lessons the way a reviewer does; the seat still reads them all.- packset_
write_ scoped packset_writefor a lesson learned on an issue: it carries anissue:IDentity naming where it was learned, and ascope:NAMEentity when one is given, so the claim travels with that scope’s log rather than the machine’s default.- panel
- panel_
jev - A panel through Jev: every seated persona’s ballot is asked of Jev
first. When all are sure and agree (
jev_panel_stands) they are cast; otherwise none is, and every seat gets a brief inoutfor a subagent, with Jev’s lean noted on the issue. - panel_
steps - The two readings beside a settle, when the pack holds what they need:
the surprisingly popular answer when two or more voters forecast the
others (
predict), and the EigenTrust standing of the voters when trust rows exist. Both are the model crate’s verbs. - parse_
every 7d,24h,2w,30m, or bare seconds.- parse_
playbook_ name - Refuse a name that is not in
PLAYBOOK_NAMES. - parse_
semver - First
N.N.Nin a--versionline. - peek_
hook_ context - The held pack text, left in place.
- persist_
tracker - Commit the tracker file that holds
issueand push it, when the tracker is a git checkout. A write that stays in one working tree is lost to every other host and to a rebuilt one; closures made on one laptop and never committed were how tickets came back open. Only that file is committed (--only), so another seat’s staged work is left alone. Never an error: the verb already happened, and the line says what did not.LJOS_TRACKER_GIT=offskips it;=commitcommits without pushing. - persona_
atom - The
personaatom for the pack: kindpersona, the view as text. - persona_
ballot_ task - What a persona’s runner is asked to do with its ballot: the brief, then how the verdict reaches the seat, under the persona’s own name.
- persona_
entity - The entity a persona’s own claims carry, so a brief can find them.
- persona_
set - The set a persona’s own conclusions live in:
persona-<name>, in the pack’s set alphabet. A set is its own tree for the duplicate and replacement rules, so a persona’s lesson never closes the seat’s or another persona’s, and the seat still reads them all. - personas_
from_ pack - The personas in the seat’s pack.
- personas_
of - The live personas: the latest
personaatom per name. - personas_
speaking_ to - playbook_
among - Pack latest for
name, else the shipped seed. Unknown names are refused even when the pack holds them. - playbook_
atom - The
playbookatom: kindplaybook, the recipe as text. - playbook_
from_ title - A closed-set name the issue title names, else
sit. Longer names win (company-panelbefore a straysittoken);sittingis notsit. - playbook_
name_ from_ issue - The playbook name bound on an issue JSON: the latest logbook note that
opens with
PLAYBOOK_NOTE_PREFIX. Empty rest means this sitting dropped it; do not walk back to an earlier bind. - playbook_
named - Look up one playbook by name: pack latest first, shipped seed only when the pack has no live atom of that name.
- playbook_
named_ on - The playbook name bound on a tracker issue, if any.
- playbook_
opening - The
== playbooksection of a sitting: bind when a name is given, else reprint the sticky body, else say none is bound. - playbooks_
from_ pack - The roster: pack atoms, with the five shipped filled in when missing.
- playbooks_
of - The live playbooks: the latest
playbookatom per name. - policy_
line - policy_
with_ memory - The argv line, then what the pack knows that bears on it: the memory a policy layer injects beside its verdict. The line prints even when the pack is down; the memory is the part that may be empty.
- policyd_
bin POLICYD_BIN, elseljos-policydon PATH.- policyd_
required - Operator switch: missing TCB is a deny. Unset, absence stays open.
- post_
claim - POST one explicit claim. Callers pass Remember/Prefer only.
- post_
hook_ stdout - Stdout for a tool-result hook, and the ids to mark now that the note
was delivered. A camel-case runner takes the note on the first tool
result.
StopadditionalContext would start another round, so the hold is cleared here andStopfinds nothing. Any other runner takes it the same way. A turn with no tool leaves the hold forStop. - predictions_
json - Forecasts as
ljos-consensus surprising --predictionstakes them. - predictions_
of - The latest forecast per agent on an issue.
- prompt_
hook_ stdout - Stdout for a prompt hook. A camel-case runner discards that stdout, so the note is held and the stdout is empty. Any other runner is handed the note directly.
- push_
call - The first
git pushin a line, followingcd DIRandgit -C DIRbefore it. - push_
tier - What the gate makes of a push, from its arguments and the facts about its remote. Pure, so the ladder is tested without a repository.
- push_
tier_ at - The tier of a push read from the repository it runs in: the remote it
names (else the branch’s upstream remote, else
origin) and whether any tag exists there. - read_
campaign - Read an eb-stack campaign state (
campaign.json). - readings_
of - The live readings among
atoms, one a habit, by name. - receive
- Check a satchel that arrived: manifest, deed receipts, signature, and what
the atoms hold; with
import, POST the atoms into this seat’s pack. - record_
due_ shown - Put the rows a due page showed up for grading. A page shared by the CLI and every server of the login lives in the runtime directory.
- records_
from_ atoms - The latest record per voter among the trust atoms that carry one.
- redirect_
seat_ verb - A deny on a bare tracker verb names the exact seat command to run in its place, so the agent runs it instead of guessing at a placeholder.
- release
- Hand a session node back before it is terminal: ready again, assignee cleared, generation moved.
- remember_
findings - Write one lesson per finding a person or a seat resolved (every
finding with
all), cite the state file on the issue when one is named, and say what happened to each. - remote_
slug owner/repofrom a remote URL:git@host:owner/repo.git,https://host/owner/repo,ssh://git@host/owner/repo.- repo_
entity - The entity a repository’s facts carry in the pack.
- repo_
fact_ text - The sentence a repository’s facts are remembered as.
- repo_
facts_ in - The latest facts the pack holds about a repository, from the atoms.
- resolve_
assignee - Resolve an
--assignee/ MCP field for a claim. Empty, a pronoun (seat,you,agent), or this process naming itself is omitted: occupancy is the conversation’s holder, not the product name on the box. A named worker is taken as given. - resolve_
sitting_ playbook - Which playbook a sitting copies: an explicit name, else the name already
bound on the issue (sticky until finish/release), else a closed-set
token in the title, else
sit. - retire_
seat - Drop the records
announce_seatwrote, when the server ends. - review_
summary - One line on the state of the review clock: how many are due, how many
are scheduled, and when the next one comes up. An empty
duewith a next date is a clock that is running; an emptyduewith nothing scheduled is a seat that has remembered nothing. - rows_
about - The rows that apply to an issue about
topic: every unscoped row, and every scoped row one of whose domains is among the topic’s words. - rule_
matches - A rule’s pattern over one command: a regular expression anchored at the command’s start, else a glob. A pattern that does not compile matches nothing.
- rules_
from_ pack - The rules in the seat’s pack.
- rules_
of - The live rules in a set of atoms.
- run
- run_as
runwithVISSUE_AGENTset toidentity, so a ballot or a claim is recorded under a persona’s name rather than the seat’s.- run_
captured - run_
captured_ as run_capturedwithVISSUE_AGENTset toidentity, for a tracker write whose output the caller has to hand on.Noneleaves the environment as it is.- run_fed
- Run a habitat’s verb with
inputon stdin. - runner_
pid - The process that started this one. For
ljos-mcpthat is the runner, and the runner is also above every shell it opens. - runs_
tests - A command line that runs a test suite. Exact, so it is code, not a judgment.
- search_
reading - What a search score is. Empty and nonempty are different facts from a writer that did not answer.
- seat_
command_ for - The exact seat command a denied
vissue VERB ARGSline should have been, its arguments carried over:vissue claim ljos-6c3zisljos sitting ljos-6c3z.Nonefor a line with no such verb. - seat_
for_ thread - The seat for a thread a runner named on a call. The holder is the one a shell of that thread already took, found by the thread’s record; else the thread id whole, recorded so the thread’s shells find it.
- seat_
guard - The seat’s own guard, before any rule: a shell command that writes one
of
SEAT_PATHS(anything but a reader, or a redirect into it), or a file tool aimed at one, is refused.ljos onboardandljositself write them, run by the person. - seat_
name - The name this seat remembers, votes and earns trust under.
- seat_
slug - A name as a seat: lower case, runs of letters and digits joined by one
hyphen.
Acme CLI,acme-cliandacme_cli/1.2are one seat. - seen_
ids - server_
entry - The MCP server entry any runner that reads JSON accepts.
- session_
end - When a session ends, the memories injected during it fire together:
they served one sitting, so their links gain weight and the next
sitting like it walks a heavier path (Hebb, through the pack’s
fire). The seen file goes with the session. Returns how many fired; nothing to fire, or no pack, is zero and not an error, since a hook must not stop a runner from ending. - session_
tag - A conversation tag from a stamped id: ten base-36 digits of FNV-1a over the whole id. A prefix of the id would not do: a UUID v7 opens with its timestamp, so two conversations started in one window share it.
- settle_
flags_ for - The model flags an issue’s tags ask for, beside the rows and anchors.
The kind of work sets the dynamics:
broadruns bounded confidence. - shipped_
playbooks - The five shipped playbooks, bodies in full, model roles as spawn hints.
- sitting
- Open a sitting on an issue, in the protocol’s order, and stop at the first habitat that does not answer: doctor, cards, the review clock, the island the issue’s title activates, the working set, the timeline, the claim. One verb, so the loop that makes the seat a memory runs every time and not only when somebody remembers to run it.
- sitting_
due_ report - The review clock as a sitting prints it: a short prefix, then the summary.
- sitting_
gated sitting, and withanywaythe claim goes through even when the issue’s blockers are open. Without it a blocked issue is refused before anything is claimed: the tracker’s graph says what is workable, and a seat that sits on blocked work sits on nothing it can finish.playbooknames the recipe copied into== playbookbefore recall; absent, a name already bound, else a closed-set token in the title, elsesit. Sitting always binds one of the five before claim. Finish and release drop the sticky name.- skill_
text - The skill file a harness loads: front matter, then the protocol.
- stop_
audit - Why an agent about to stop is held for one more round, from a Jev
audit of the turn;
Nonelets it stop. Only a runner’s first attempt is audited, only with Jev on, and only a final message long enough to claim anything. - stop_
hook_ stdout - Stdout for
Stop, and the ids to mark now that the note is delivered. A continuation (stop_active) says nothing: the firstStopalready delivered the note. - stop_
turn_ from_ transcript - Read a JSONL transcript of
userandassistantentries whosemessage.contentis text or blocks (text,tool_use,tool_result). - subagent_
brief - What a subagent is told on its first tool result: the issue its parent holds and how its result joins it. A subagent that is not told the issue cannot cast a ballot on it, and a sitting of its own would contend with its parent’s.
- subagent_
stop_ reason - The stop gate for a subagent: once, when its parent holds an issue, the reason the subagent is kept working one more round. A gate that already held it this turn, or a parent holding nothing, lets it stop.
- take_
hook_ context - Take the held pack text once. Empty if nothing was held.
- take_
hook_ note - Take the held note and its ids, and remove both files.
- tcb_
check - One line from
ljos-policyd check -- argv. None if the binary is absent or failed to start. Absence is not a deny. - timeline
- The issue’s timeline, the three stores read as one dated list, oldest first: the tracker’s logbook (creation, state changes, claims, notes), the deeds the issue cites with the time each was produced, and the memories the issue’s title activates with the time each was written. The reader gets time as data, not as stamps to do arithmetic on: each line carries its age and the gap since the line before it, and a later line supersedes an earlier one on the same matter.
- timeline_
events - The issue’s timeline as dated rows. The HUD paints this; it does not
parse
ljos timelinestdout. Tracker rows come fromvissue_core::agent::show_json. Deed rows still shelldeedar evidence, a named gap (deedar::Store::evidence). - topic_
words - The words an issue is about, for scoping trust rows: its title, lower case, three letters or longer.
- touches_
seat - Whether a hook call’s cue is the seat’s own verbs or tools.
- tracker_
git_ drift - Commits the tracker checkout holds that origin does not. The count is always named. A live background push, or commits younger than the push wait, stay healthy: the sitting already waited that long. Older drift fails the row, and a leftover refused-push log names the reason.
- tracker_
show_ json - One issue as JSON from the tracker library. Same card as
vissue show --json. - tracker_
state - The tracker row from
vissue identity: version, the root and prefix it resolved, and where the root came from. A root that is relative, missing, or holds no prefix directory fails the row: tickets filed there are invisible to every other seat. When the root is a git checkout with an upstream, the row also names how many commits origin lacks. - trim_
num - A number as a person writes it: up to four decimals, no trailing zeros.
- trust_
atom - A
trustatom for one row.whyare deed accessions it cites. - trust_
from_ pack - The live trust rows in the seat’s pack.
- trust_
json - Rows as the consensus takes them:
[[from, to, weight], ...]. - trust_
rows - The live rows in a set of atoms: the latest
trustatom per(from, to). - under_
a_ runner - Whether this process runs under an agent runner: the environment carries a runner’s conversation, or a process above it is a runner, one whose server left a seat record or one the runners file names. Consent is the person’s, so the verbs that grant it refuse here.
- utc_at
secsafter the epoch, RFC 3339 UTC to the second, as the pack writes.- verdict_
for - The verdict the rules give a command line: the first
denywins, then the firstask, else none, each tried on the whole line and on every command in it. Returns the rule that fired. - whoami
- Who is sitting, with nothing set. The seat:
LJOS_SEATor the tracker’sVISSUE_AGENTwhen someone set one; else what the MCP client said at initialize; else the process tree above this shell, which is the runner that opened it or the server that runner opened; else the login user, who is the seat when no program is. The holder is any*_SESSION_IDthe runner stamped, ahead of the process tag, so MCP sitting and CLI sitting of one conversation are one occupancy name; else the seat tagged with the conversation’s process. - withdraw_
prediction - Take back
agent’s forecasts on an issue: each prediction atom it wrote there is deleted, leaving the pack’s tombstone, so the settle reads the voter as forecasting nothing. Returns how many went. - work_id
- A claimdag id for a name: the name itself when it is already 32 hex, else FNV-1a 128 of it. One tracker id maps to one node; one assignee to one actor.
- work_
nudge - Count this conversation’s tool calls since it last touched the seat, and
on a
PostToolUsethat reachesWORK_NUDGE_EVERYsay what to record: a note, a lesson or a deed on the issue it holds, or an issue to open when it holds none. A subagent is left to its brief. - write_
persona - POST one persona. A persona of the same name already in the pack is
superseded, so a rewrite moves the roster without leaving the old view
live. Every persona is owed one unscoped inbound trust row;
--abouton a later trust row only adds weight, it does not replace that floor. - write_
playbook - POST one playbook. A playbook of the same name already in the pack is superseded, so a rewrite moves the recipe without leaving the old body live.
- write_
prediction - POST one forecast.
expectis an option name or{option: share}. - write_
rule - POST one rule.
- write_
trust - POST one trust row.
- write_
trust_ record write_trustcarrying the voter’s record on the row.
Type Aliases§
- Learned
State - Trust rows, personas, and each voter’s forecast calibration.
- Standing
- A voter’s record: how often the outcome agreed with its ballot, and how often not, carried on every trust row into that voter.