@network-harness/core-data
v0.2.0
Published
Part of the network harness: @network-harness/core-data.
Readme
@network-harness/core-data
Claims ctx.data. The source registry, the policy check every access passes
through, the executor for operations that apply sources, and the consent queue.
apply performs; it never returns material. A protocol names what to use and
where it should go, and the operation happens on its behalf. The order inside is
the point: resolve the operation, check policy, spend an approval if one is
required, and only then read the contents -- so a refusal at any earlier step
means nothing was read. There is exactly one method in this package that reads a
source's bytes, and it exists to be called by apply.
The receipt is not traced. A receipt is the provider's answer to the caller; an endpoint that echoes what it was sent would otherwise put the credential into the trace, which is the one place in the node that keeps everything. The trace records the operation, the provider, and the source names.
Consent is asynchronous, and an approval is spent. ask records a question
and returns; the human answers over /consents; the decision arrives as an event
in the asker's context. An apply that needs consent is refused with
CONSENT_REQUIRED rather than parked, because a protocol reacts to an event and
returns -- waiting would hold a dispatch open on human time. The approval it
names must be the caller's, for that operation, and unused: it admits one apply,
not a standing permission. A question nobody answers in time is denied,
attributed to the system rather than the human.
Defaults are asymmetric on purpose. Data is default-deny: a source is visible to an extension only if a rule says so, because a source shown to the wrong extension cannot be unshown. Operations are default-ask: stopping to ask costs the human a decision they were always entitled to make.
The private directory must resolve outside the data directory. An LLM run's working directory is inside the data directory, so a private directory within it would be readable by a model -- which would silently undo the descriptor/data split the whole design rests on. Refused in the daemon's preflight and again by this component at load, so editing the entry file is not a way around it.
