Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/request-for-change/rfc-crew-agent-sdk-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -223,7 +223,7 @@ kinds of undeclared hole:
| `ClaudeCodeProvider is not None and isinstance(...)` guards against a name hard-coded to `None` (`session.py:170`, `subagent.py:131`) | 11 sites | Statically unreachable; nine `session.py` branches and two `subagent.py` branches are dead-but-maintained |
| Defensive attribute probes across the provider boundary (`session_pid.py` (`_collect_active_pids`) probes `_proc` and `_active_proc`, `chat_runner.py:867`, `knowledge/llm_pool.py:325`) | 4 | Duck typing in place of a type |
| Comment clusters naming the companion or a deleted module as the supplier of behaviour | 19 | The seam's real contract lives in prose |
| Refusal / downgrade mechanisms, including the degrade log line at `config/loader.py:4647-4652` and five capability non-memberships | 9 | — |
| Refusal / downgrade mechanisms, including the degrade log in `acp_backends.resolve_selected_backend()` and five capability non-memberships | 9 | — |
| Live `_is_claude` branches inside `acp/` | 13 | — |
| CC-symbol lines in `src/kiro_crew` | 146 (352 with `test/`) | — |

Expand Down
2 changes: 1 addition & 1 deletion docs/system-specs/features/agent-host-contract.md
Original file line number Diff line number Diff line change
Expand Up @@ -260,7 +260,7 @@ path a public build takes when an operator picks Claude Code.
| Methods returning a neutral value purely for a companion to override | 6 |
| `ClaudeCodeProvider is not None and isinstance(...)` guards against a name hard-coded to `None` | 11 sites, 2 sentinels (`session.py:200`, `subagent.py:144`) |
| Comment clusters naming the companion or a deleted module as the supplier | 19 |
| Refusal / downgrade mechanisms | 9, including one degrade log line (`config/loader.py:4647-4652`) and five capability non-memberships |
| Refusal / downgrade mechanisms | 9, including the degrade log in `acp_backends.resolve_selected_backend()` and five capability non-memberships |
| Live `_is_claude` branches inside `acp/` | 13 |
| CC-symbol lines in `src/kiro_crew` | 146 (352 including `test/`) |

Expand Down
20 changes: 15 additions & 5 deletions docs/system-specs/modules/config.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,15 @@ booleans and non-integral, malformed, or non-finite values. Imported settings ar
type-validated before they are written, and the CLI converts typed values before
writing.

The config module (`kiro_crew/config/loader.py`) loads runtime configuration from `~/.kiro/crew/config.json` using stdlib dataclasses with sensible defaults.
The config package loads runtime configuration from `~/.kiro/crew/config.json`
using stdlib dataclasses with sensible defaults. Responsibilities are split in
one direction: `config/sections.py` owns section DTOs, field defaults, and their
coercion/normalization rules; `config/resolution.py` owns raw overlay merging,
top-level section classification, and degraded-input tracking; and
`config/loader.py` owns the compatibility facade plus persistence, validation
orchestration, cache fingerprinting, migration, and runtime binding resolution.
`loader.py` re-exports the historical DTO, helper, and constant names so existing
callers keep the same import surface.

A feature whose section spends tokens on the user's behalf defaults to off and
documents its knobs in its own spec — `session_summary` is the current example
Expand Down Expand Up @@ -803,7 +811,7 @@ class TelegramConfig:
allow_forum: bool = False # serve supergroup forum Topics as per-Topic sessions (Slack-thread style). Fail-closed: also requires the supergroup's chat_id in allowed_forum_chat_ids, and only real Topics (message_thread_id present) are served — ordinary groups and the supergroup General chat are denied
allowed_forum_chat_ids: list[int] = [] # numeric supergroup chat_ids permitted to run forum-topic sessions; empty = deny all groups (fail closed)

# Additional top-level DTOs (not fully expanded here — see loader.py):
# Additional top-level DTOs (not fully expanded here — see sections.py):
# OrchestratorConfig, CronHistoryConfig, TunnelConfig, InstancesConfig, HeartbeatConfig,
# WorkspaceConfig, MemoryStoreConfig, ExternalRegistryConfig,
# KiroCrewAgentConfig, SlackConfig.
Expand Down Expand Up @@ -897,7 +905,8 @@ screenshot.
### Security-Bounded Config Clamp

Resource-limit and timeout knobs are clamped to hard ceilings **at load time**, not
just at the dashboard write gate. The ceilings are the single source of truth in
just at the dashboard write gate. The ceilings are owned beside the field models
in `sections.py` and re-exported by `loader.py`; the load-time clamp remains in
`loader.py`:

| Constant | Value | Field |
Expand Down Expand Up @@ -946,8 +955,9 @@ closing the direct-config-edit DoS gap.

### `resource_limits`: one block, three mechanisms, two meanings of `0`

`ResourceLimitsConfig` (`config/loader.py`) carries the kernel confinement
ceilings for spawned agent processes. It is the one config block whose keys are
`ResourceLimitsConfig` (`config/sections.py`, re-exported by
`config/loader.py`) carries the kernel confinement ceilings for spawned agent
processes. It is the one config block whose keys are
read by more than one enforcement mechanism, and two of those keys mean
**different things** to two of them:

Expand Down
Loading
Loading