Imported from zeroclaw-labs/zeroclaw (
crates/zeroclaw-runtime/AGENTS.md). Install upstream withnpx skills add zeroclaw-labs/zeroclaw --skill zeroclaw-runtime. Copyright stays with the author.
zeroclaw-runtime: Transitional Holding Crate
This crate is a temporary holding area, not a permanent home. It contains 126K LOC of subsystems extracted from the original monolith that have not yet been decomposed into their final crate structure.
Do not add new functionality here, unless the Core Team has granted a recorded exception (see below). The RFC's Phase 2-4 roadmap defines the decomposition plan: agent loop, gateway, channels orchestrator, daemon, cron, security, observability, hardware, TUI, skills, and doctor will each be extracted into dedicated crates or converted to WASM plugins.
Exceptions
Extraction is the default. The Core Team may grant a bounded exception when immediate extraction would require a disproportionate refactor, or would establish a crate boundary the roadmap does not intend. See ADR-016.
An exception must name its permitted scope, intended destination, approving authority, and either an expiry or a review condition, and must be recorded before the feature it covers merges. An expiry ends the permission, so further additions need Core Team renewal; it does not require removing code that already landed. A review condition only obliges reconsideration.
An exception is granted by adding its row to the table below through normal review, approved by the Core Team. The row is the record: a decision that lives only in a review thread has not been made. A feature pull request cannot grant itself one: the contract it would be waiving is the one constraining it.
An exception requires a concrete supported use case. Code with no receiving caller does not qualify; retirement or an explicit ownership decision is the right answer there.
An exception permits continued work on a subsystem already held here. It never permits introducing a new subsystem, and it does not generalise from one subsystem to another.
Active exceptions
| Scope | Destination | Approved by | Expires or reviewed |
|---|---|---|---|
Provider-image recovery in src/agent/agent.rs, src/agent/loop_.rs, src/agent/turn/{mod,provider_call,stream_consume,max_iter}.rs, and src/tools/send_message_to_peer.rs, limited to the bounded recovery and live-state wiring proposed in #10480 |
Agent-loop owner in the planned zeroclaw-kernel extraction |
@JordanTheJet, approved in #10949 on 2026-09-18 | Review at the agent-loop extraction design review, or before expanding recovery eligibility or retained state |
Peer-inbox lifecycle in src/tools/send_message_to_peer.rs and src/control_plane/{task_registry.rs,task_store_sqlite.rs}, limited to the #9597 TaskRecord registration, terminal settlement, and focused lifecycle tests around existing authorized agent-peer dispatch |
Agent-loop and task-lifecycle owners in the planned zeroclaw-kernel extraction |
@JordanTheJet, approved in #11030 on 2026-09-21 | Review when agent-loop or control-plane extraction begins, or before expanding peer lifecycle scope |
Pre-turn tool-elicitation hints in src/agent/agent.rs, src/agent/loop_.rs, src/agent/tool_execution.rs, and src/agent/turn/{elicitation,mod,tool_specs}.rs, limited to the default-off, admitted-channel turn flow proposed in #10325; no new tool execution or routing authority |
Agent-loop owner in the planned zeroclaw-kernel extraction |
@IftekharUddin, approved in #11047 on 2026-09-24 | Review at the agent-loop extraction design review, or before widening trigger sources, retained hint state, or tool execution authority |
Prefix-fingerprint instrumentation in src/agent/turn/mod.rs and src/agent/turn/provider_call.rs, limited to #10990: compute system_chars, system_sha256, tools_count, and tools_sha256 from the finalized logical-request inputs and attach them to the existing llm_request event, with focused regressions |
Agent-loop request-event producer in the planned zeroclaw-kernel extraction |
@IftekharUddin, approved in #11047 on 2026-09-24 | Review at the agent-loop extraction design review, or before expanding fingerprint inputs, retained state, trace access, or emission policy |
Runtime composition contract in src/composition.rs, and the *_with_capabilities entry-point adapters that consume it in src/agent/{loop_.rs,agent.rs,turn/mod.rs} and the capability-carrying DaemonRegistry starter signatures in src/daemon/{registry.rs,mod.rs}, limited to the #10993 composition API and the migration steps in docs/book/src/architecture/runtime-composition.md. Does not cover moving concrete provider, memory, or tool construction into this crate |
Composition owner in the planned zeroclaw-kernel extraction |
@IftekharUddin, approved in #11092 on 2026-09-24 | Review at the agent-loop extraction design review, or before the contract adds a capability kind beyond providers, memory, tools, outbound channels, and the observer |
Session-persistent prompt integration proposed in #10407, limited to primary Chat-turn owner admission and bounded injection, strict attachment-mutation approval and RPC transport, sensitive-egress redaction, hook exclusion and lifecycle pairing, exclusion of attachment capabilities from unsupported turn types, session-incarnation and queued-Kill lifecycle fencing, atomic alias-set deletion and scoped owner checks, durable/public RPC identity propagation, registration and reserved-name protection, localized messages and focused regressions. Paths relative to crates/zeroclaw-runtime: src/agent/{agent.rs,approval_bridge.rs,cost.rs,loop_.rs,prompt.rs,system_prompt.rs,tool_execution.rs}, src/agent/turn/{approval_gate.rs,call_prep.rs,context.rs,history_append.rs,mod.rs,parse_response.rs,post_exec.rs,provider_call.rs,results_collect.rs,tool_specs.rs}, src/approval/mod.rs, src/{i18n.rs,lib.rs}, src/rpc/{approval_channel.rs,context.rs,dispatch.rs,local.rs,session.rs,turn.rs,types.rs,wss.rs}, src/tools/{delegate.rs,mod.rs,shell.rs,skill_tool.rs,spawn_subagent.rs}, and locales/{en,es,fr,ja,zh-CN}/{cli.ftl,tools.ftl}. Only production-reachable behavior and its regression tests are covered; no unused cancellation machinery, new subsystem, storage/tool implementation moved into runtime, or ACP/cron/delegate/subagent/SOP/one-shot/auxiliary attachment support |
Agent-loop and RPC owners in the planned zeroclaw-kernel extraction; registration, identity adapters and localization follow their owning subsystem |
@Audacity88, approved in #11439 on 2026-10-03 | Review at the agent-loop or RPC extraction design review, whichever occurs first, or before widening supported session types, approval or sensitive-egress policy, lifecycle behavior or retained state. Unlisted paths or behavior require a separate Core Team decision |
Startup recovery of abandoned session turns in src/live_config_authority.rs, limited to #11432: the ConfigOwnershipGuard::recover_abandoned_turns adapter (and its logging variant), which hands the data directory the guard locked to zeroclaw_infra::recover_abandoned_session_turns, and the call to it in LiveConfigAuthority::new_owned. The recovery itself, its once-per-process claim, and the session-store transition live in zeroclaw-infra. No new admission, routing, or tool authority |
The owner of process and config-lifecycle ownership in the planned zeroclaw-kernel extraction |
@Audacity88, approved in #11524 on 2026-10-05 | Review when live_config_authority is extracted, or before recovery covers state other than session run state |
Manual sops.run in src/rpc/dispatch.rs, limited to #10513/#10522: route new manual ExecuteStep runs through RpcContext.sop_driver_handles and spawn_and_register_sop_driver; fail closed without an open generation, settle refused runs, and test admission plus per-step scope enforcement. No new driver, policy, run source, or RPC method. |
RPC/daemon socket owner in the planned zeroclaw-kernel IPC extraction |
@IftekharUddin, approved in #11111 | Review at zeroclaw-kernel IPC extraction or before widening to other RPC methods or run sources |
Stability tier: Experimental; no stability guarantee. Decomposition begins at v0.8.0.
