Expand description
turnframe-runtime: what a user’s turn actually does. The model proposes meaning,
deterministic code decides effects, committed events decide claims.
orchestrator::Orchestrator::handle_turn runs the pipeline of spec §23, one stage
per module, so a trace, a phase marker and a replay record point at the same place.
The invariants the stages make concrete are tabulated in docs/architecture.md, and
where each signal fires in docs/telemetry.md.
| Stage | Module | What it decides |
|---|---|---|
| configuration | config | how much autonomy the model gets, which risk classes a sandbox refuses, the conservative defaults |
| budget | budget | what a turn may spend, and which bound stopped it |
| understand | understand (private) | what the turn asks, read by small verified model tasks into one Understanding |
| resolve | resolve | which record “the Ferri trip” is, or that it is a question; never a guess (I8) |
| policy | policy | whether a command may run now, and if not, which card would authorize it |
| reduce | reduce | every act’s explicit result for the whole turn (§13, I11) |
| interactions | interactions | durable cards, persisted before any sentence refers to them (§15) |
| resume | resume | what a card remembers, so answering it continues the act it interrupted |
| execute | execute | admission before effect, optimistic concurrency, the outbox, one atomic commit (§16) |
| compose | compose | receipts from committed events, one answer per question, and an acknowledgement written from the turn’s outcome and reviewed |
| stream | stream | nothing that states an outcome goes on the wire before the commit (§18.5) |
| trace | trace | every event and model call of a turn, as one JSON line each |
| recover | recover | after a crash: resume by idempotency key, regenerate the answer, or reconcile |
| dispatch | dispatch | the external-effect saga: claim a due outbox row, send it, settle it |
| planning | planning | the pipeline stopped before the first effect, for a path running beside an existing one |
| divergence | divergence | what the two paths disagreed about |
§Example
Configure the runtime and check that a sandbox refuses what §11.4 says it must.
use turnframe_core::prelude::*;
use turnframe_runtime::config::{OrchestrationMode, OrchestratorConfig, ResourceBudget,
SandboxAcknowledgement};
let config = OrchestratorConfig::conservative();
config.validate()?;
assert_eq!(config.mode, OrchestrationMode::Deterministic);
let sandbox = OrchestrationMode::sandboxed_autonomous(
ResourceBudget::conservative(),
SandboxAcknowledgement::i_accept_unreviewed_autonomous_writes(),
);
assert!(sandbox.allows_risk(RiskClass::ReversibleLowRisk));
assert!(!sandbox.allows_risk(RiskClass::ExternalRegulated));Wiring a whole orchestrator needs a workflow registry, a provider pool and a
set of stores; the runnable version lives in the integration tests, where
tests/support/mod.rs assembles the sample trip and traveler domains
against the in-memory stores and a scripted provider.
Modules§
- attachments
- The turn’s files, on their way to a model.
- budget
- The resource budget of the sandboxed autonomous mode (spec §11.1).
- compose
- Response composition: what the assistant is allowed to say (spec §10, §17.3, §18, §23 steps Q to U).
- config
- Orchestration modes and runtime configuration (spec §11.1, §11.4, Appendix A).
- conversation
- The conversation as a turn loads it: earlier messages, and what cannot be started.
- copy
- Server copy: the sentences the runtime writes itself, which a user reads. Each copy
struct ships English and Italian; a deployment declares the languages it serves with
OrchestratorBuilder::locales, and building fails while any sentence has no text in one of them. - dispatch
- The outbox dispatcher: the second half of the external-effect saga (spec §16.4, §16.5, ADR-007).
- divergence
- A shared vocabulary for what two turn paths disagreed about.
- effort
- The effort a turn runs at, resolved into the profiles, budgets and settings it runs
under.
mediumwith nothing configured is the configuration as it is. - execute
- Command execution: the journal, the domain, the outbox and the one atomic write (spec §16, §23 steps M and N).
- interactions
- The persistent interaction engine (spec §15, §23 steps C, L and P).
- orchestrator
- The public facade: one turn, start to finish (spec §23, §29).
- planning
- Planning a turn without performing it (spec §23 steps A–K).
- policy
- Whether a command may run now, and if not, what would let it (spec §14.3).
- recover
- Crash recovery (spec §23.1).
- reduce
- The whole-turn reducer (spec §13).
- resolve
- Deterministic target resolution (spec §12).
- resume
- What a card remembers, so an answer continues the work it interrupted (spec §13.3, §15.3).
- stream
- Safe streaming (spec §18.5).
- trace
- A trace of whole turns, for a person debugging one: the message that arrived, each step of its understanding, what was understood and decided, every model call with its prompts and answer, and the reply with its replay record.