A max-tokens response that included a tool call persisted assembler-transformed content next to replay metadata projected from the untransformed native message, so the next request died in history reconstruction with INVALID_REPLAY_STATE and the session stayed permanently stuck. Write side: the finish chunk's replayState becomes a typed ReplayEnvelope — opaque response-level metadata plus optional per-block entries aligned with the emitted block sequence. BlockAssembler computes one keep/drop decision for blocks and entries together, so stored metadata always describes stored content and retained blocks keep their signatures. pi-ai splits its state into a version-2 response half and per-block signature entries. Read side: durable content is authoritative. toPiAssistant degrades any unusable state — foreign kind, other versions (including the flat v1 form already on disk), malformed metadata, or content/block mismatches — to the existing provider-neutral conversion with an onReplayDegrade diagnostic instead of failing the request, which un-bricks sessions poisoned before this change. Covered by assembler and replay unit tests, an agent-loop continuation regression, keyless real-composition continuation tests (native pruned-envelope replay and legacy flat-state degrade), and the authored keyless snapshot scenario max-tokens-continue through the assembled ACP app.
core/ — product API spine
English | 中文
The session log, system-prompt assembly, tool registry, agent vocabulary, deployment-default model selection, and concrete loop that form the harness's default control spine. These are product packages — the stable surface plugins and consumers build against.
| Package | Role | ctx key |
|---|---|---|
scope/ |
Scoped-context registration primitive | library — no ctx key |
session/ |
Event-sourced session log and in-memory store | ctx.sessions |
system-prompt/ |
Prompt and tool-schema assembly registry | ctx.systemPrompt |
tools/ |
Scoped tool registry and execution pipeline | ctx.tools |
agent/ |
Agent interface, registry, and event vocabulary | ctx.agents |
agent-default-model/ |
Default model selection shared by Agent entry points | ctx.agentDefaultModel |
agent-loop/ |
Default concrete agent driver | ctx.agentLoop |
scope supplies the shared scoping primitive. agent owns the public contract, while agent-loop is its default implementation; extension plugins depend on the seam so the driver remains swappable. agent-default-model owns the deployment selection an Agent entry point uses only when a session has no selection of its own.
Runnable compositions belong to examples/agent-spine-demo; this group owns only the swappable spine pieces.
The subsystem reference — the package-by-package loop map, the Agent handle and its delivery/interception contracts — is docs/subsystems/core.md; the default runnable composition is examples/agent-spine-demo.