npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@gatanot/orrery-protocol

v0.2.8

Published

Transport-neutral CBOR protocol for remote pi sessions

Readme

@gatanot/orrery-protocol

Runtime-neutral routed envelopes, CBOR encoding, and byte-stream framing for the experimental Pi protocol.

Protocol version 8 defines:

  • a version handshake that identifies the logical serverId;
  • explicit server and Session request targets;
  • correlated requests and responses with opaque strict-JSON payloads;
  • request cancellation, opaque subscription updates, and out-of-band attachment changes;
  • non-empty opaque error codes and bounded transport messages.

A server target contains { serverId }; a Session target contains { serverId, sessionId, attachmentId }. The combined route fences calls to one logical server, durable Session, and live presentation attachment. Management attach() and detach() return no routing identifiers; the server publishes the selected live route in an out-of-band attachment message. Disconnecting releases only that presentation's attachment after admitted calls settle.

Chord owns the payload semantics carried inside these envelopes: { serviceId, instance?, member, args } calls, the $chord.service control vocabulary, service catalogues, subscription snapshots and updates, service error codes, and the independent Delta path codecs for replicated states. pi-protocol validates that each opaque payload is strict JSON but does not validate or export its Chord grammar. Clients and servers parse those values through @gatanot/orrery-chord at the service adapter boundary.

Session-directory state, management results, transcripts, models, plugins, and all other application values remain opaque service data. The real Session and AgentHarness remain process-local. Server and Session calls route opaquely to their owning providers, where Chord and the application validate and invoke them.

Server and worker lifecycle is intentionally outside this public protocol. The experimental local coordinator is only an opaque message router; each replaceable server process owns the private lifecycle protocol.

Each wire frame consists of a four-byte unsigned big-endian payload length followed by one definite-length CBOR item. encodeClientMessage() and encodeServerMessage() validate and encode complete frames. ClientMessageDecoder and ServerMessageDecoder accept arbitrary stream fragmentation and coalescing.

import {
  PROTOCOL_VERSION,
  encodeClientMessage,
  ServerMessageDecoder,
  type ClientHello,
} from "@gatanot/orrery-protocol";

const hello: ClientHello = { type: "hello", version: PROTOCOL_VERSION };
transport.send(encodeClientMessage(hello));

const decoder = new ServerMessageDecoder({ maxFrameLength: 1024 * 1024 });
for (const message of decoder.push(incomingChunk)) handleServerMessage(message);
decoder.end();

All envelope schemas reject unknown object properties, and codecs recursively reject non-JSON opaque payloads, including non-finite numbers, byte arrays, undefined, prototypes, and cycles. Envelope violations, malformed CBOR, and invalid framing throw ProtocolValidationError. Payload-specific adapters must perform their own semantic validation after decoding. Transports must preserve byte order. Peer authentication and authenticated service contexts are not implemented by the experimental transport.

Default limits are 16 MiB per CBOR payload/frame, 1,000,000 array elements or map entries, and 64 nested item levels. The protocol is experimental and has no compatibility guarantees.