<feed xmlns='http://www.w3.org/2005/Atom'>
<title>cloud9.git/9harness/build.zig, branch main</title>
<subtitle>9p for zig</subtitle>
<id>https://git.0x4200.cafe/cloud9.git/atom?h=main</id>
<link rel='self' href='https://git.0x4200.cafe/cloud9.git/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://git.0x4200.cafe/cloud9.git/'/>
<updated>2026-09-25T20:52:33Z</updated>
<entry>
<title>Rename 9harness to 9agents; README, file-backed qids, worded errors</title>
<updated>2026-09-25T20:52:33Z</updated>
<author>
<name>Gabriel Schneider</name>
<email>gbrls@0x4200.cafe</email>
</author>
<published>2026-09-22T13:30:02Z</published>
<link rel='alternate' type='text/html' href='https://git.0x4200.cafe/cloud9.git/commit/?id=df20863879fe2d83077534f4726a985ffc239def'/>
<id>urn:sha1:df20863879fe2d83077534f4726a985ffc239def</id>
<content type='text'>
- 9harness/ becomes 9agents/ (build option -D9agents, package paths).
- 9agents serves /README, reports qid paths from the file's (dev, ino)
  and qid versions that move with the file, and names its refusals.
</content>
</entry>
<entry>
<title>9harness: the harness fs daemon</title>
<updated>2026-09-21T18:20:40Z</updated>
<author>
<name>Gabriel Schneider</name>
<email>gbrls@0x4200.cafe</email>
</author>
<published>2026-09-21T17:23:27Z</published>
<link rel='alternate' type='text/html' href='https://git.0x4200.cafe/cloud9.git/commit/?id=b4db588dd5b92d647b661c2dc17b40925af92348'/>
<id>urn:sha1:b4db588dd5b92d647b661c2dc17b40925af92348</id>
<content type='text'>
The last item of the 9P plan, replacing zmxify's introspection half: a
read-only, fresh-from-disk 9P view of every agent harness's state on
this machine, posted as `harness` like any other service, so a shell
inside a 9ns --mntgen mount reads it at /mnt/9p/harness with no setup.

  /pid /uptime   /claude/{projects,history,skills}
  /codex/{sessions,session-index,history}
  /omp /hermes /dsh     the mirrors
  /skills/{claude,codex,omp}

Nothing is cached: a lookup, getattr or readdir walks the real
filesystem, so a transcript grows as its harness writes it and a new
session appears as soon as its file lands. Writes answer EPERM, and no
name that looks like a credential, key, token or auth store is ever
answered at any depth.

Three findings from the adversarial pass, each with its regression:

- The read path composed &lt;base&gt;/&lt;rel&gt; and opened it in one call, which
  follows symlinks. A name swapped for a link between the walk and the
  read served bytes from outside every pinned root (proved against
  /etc/passwd). Every stat, read and readdir now resolves through
  openIn, which walks from the base one component at a time with
  O_NOFOLLOW, and O_PATH for the intermediates, so no component can
  redirect the walk. O_PATH also keeps a fifo in a root from parking the
  daemon in open(); a read refuses anything but a regular file.
- Joining a child onto an empty relative path returned an uncopied
  scratch slice, so every file at the top of a mirror root (/hermes/x,
  /dsh/x) listed but read back uninitialized stack bytes.
- A directory past the comptime caps was served short, and a short
  listing cannot be told from a small directory. The caps answer NFILE
  now. Staging also stops at the first record that does not fit instead
  of packing a shorter one behind it, which dropped that entry from the
  listing across the read boundary.

Suites: 13/13 unit (fake HOME, never the live roots), 36/0 end-to-end
including the mntgen money shot and the live ~/.claude/.credentials.json
proved unreachable, 131/131 programs-test.
</content>
</entry>
</feed>
