Files
stack/adapters
jason.woltje 172368612c feat(capabilities): task workspaces + tools allowlist plumbing (#20)
- task schema: optional workspace (absent | :run ephemeral | named
  persistent under dataRoot/workspaces) and capabilities.tools (pi
  documented tool allowlist); strict validation, traversal-proof names
- runner: creates host workspace, passes MOSAIC_WORKSPACE (container
  path) + MOSAIC_TOOLS; result.json records both
- pi adapter: cds into workspace; --tools when allowlist present else
  --no-tools
- mock adapter: logs delivered MOSAIC_* vars to stderr as deterministic
  plumbing evidence (dash prints 'export K=v', so use env not export)

Closes #20
2026-09-02 22:03:46 -05:00
..

Mosaic runtime adapters

An adapter is the entire harness-specific surface of the system. Everything upstream of an adapter — configuration, contracts, missions, tasks, run records — is harness-agnostic; everything inside an adapter may assume one specific agent runtime.

Contract

An adapter lives at:

/opt/mosaic/adapters/<name>/adapter.sh

and must be executable. The dispatcher (/opt/mosaic/src/run-agent.sh) selects it via MOSAIC_ADAPTER (default: pi) and execs it after the system prompt has been generated.

Inputs (environment):

Variable Meaning
MOSAIC_SYSTEM_PROMPT_FILE Absolute path to the generated system prompt (contracts + optional mission section). Read it; do not modify it.
MOSAIC_REQUEST The exact user request text (may contain newlines).
MOSAIC_PROVIDER Configured provider name.
MOSAIC_MODEL Configured model id.

Optional, adapter-specific (documented per adapter):

Variable Meaning
MOSAIC_MOCK_RESPONSE mock only: the verbatim response to emit

Outputs:

  • stdout: the model response text — the only channel the orchestrator captures
  • stderr: diagnostics (never credentials)
  • exit 0: success; nonzero: failure

Rules

  1. Adapters print ONLY the response on stdout. Status lines go to stderr.
  2. Adapters never read configuration files; the resolved settings arrive via environment.
  3. Adapters never write outside /var/lib/mosaic.
  4. Adding an adapter requires: a new directory, the contract implementation, and adding the name to the allowlist in scripts/mosaic-config.mjs.

Included adapters

  • pi — the pinned @earendil-works/pi-coding-agent CLI in noninteractive print mode (-p), ambient discovery disabled, stdin detached.
  • mock — deterministic echo of MOSAIC_MOCK_RESPONSE. Test-only: never use it where a real model response is required.