Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,23 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
profiles are unaffected — `tole-core` defaults do not change.

### Added
- `tole acp`: tole as an **Agent Client Protocol agent** over stdio
(issue #95) — editors (Zed et al.) drive durable tole sessions:
`session/new`/`session/load` map to the JSONL session store, prompts run
full tole turns, the final answer streams as an `agent_message_chunk`,
and Write/Destructive tool calls surface as
`session/request_permission` requests — the editor human approves, with
Destructive consent being a genuine per-call decision. Provider config
is only required when a prompt actually runs. The session map survives
across prompts (a first-run regression where fresh state replaced the
map after one turn — caught by CodeCora review — is fixed, along with
session-id path-traversal and mutex-poisoning hardening). The
session-map lock is held only briefly — a running turn keeps its OWN
storage lock, so the reader loop stays live for permission routing
(the first implementation deadlocked protocol routing for up to the
permission timeout whenever a client opened a session while a
permission request was pending — caught by CodeCora review). Sessions
reject concurrent turns (busy) and panic-safe un-busy via Drop.
- `tole mcp`: tole as an **MCP server** over stdio (issue #94) — the
registry's hardened tools (jailed file ops, argv-validated git, detached
jobs, memory loop, cora/uteke integrations) become callable by any MCP
Expand Down
3 changes: 3 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,9 @@ tole is the agent harness of the CodeCora ecosystem — the hands:
(jailed file ops, git, jobs, memory) to any MCP client. ReadOnly tools are
always callable; Write tools require `--allow` patterns; Destructive tools
are structurally absent.
- **tole as an ACP agent**: `tole acp` speaks the Agent Client Protocol —
editors (Zed et al.) drive durable tole sessions, and tool approvals
surface as permission requests in the editor.

Every ecosystem integration is probe-first: a missing binary degrades to a
one-line warning, never a phantom tool.
Expand Down
Loading
Loading