
مترجم LinkML للعقود لباحثي الأمن
النية التعريفية → عقد تنفيذ حتمي → وكيل / بيئة تشغيل
يحوّل Decretum النية المنظمة إلى عقد تنفيذ حتمي للوكلاء وبيئات التشغيل.
Decretum هو مُصرِّف تنفيذ تعريفي محايد المجال. فهو يجمع المخططات والوصفات والملفات الشخصية وسجلات المزوّدين/التكاملات والاستكشاف والتحقق والسياسات والحل الحتمي لإنتاج عقد تنفيذ محمول.
البحث الأمني هو المجال المرجعي لـ Decretum، وليس حدوده المعمارية. يمكن لنموذج المُصرِّف نفسه وصف هندسة البرمجيات، وأتمتة البنية التحتية، وهندسة البيانات، والاستجابة للحوادث، والتجارب العلمية، وغيرها من الأعمال التقنية القابلة للتكرار.
Decretum ليس بيئة تشغيل. إنه يحدد ما يمكن تنفيذه وينتج عقد تنفيذ محمول. وهو لا ينفذ العمل، ولا يدير تفاعل الوكيل/الباحث، ولا يجمع الأدلة، ولا يحتفظ بالنتائج، ولا ينشئ التقارير.
بعد التصريف، يتوقف Decretum. يُمرَّر العقد إلى بيئة تشغيل أو وكيل خارجي.
إذا احتاج التنفيذ لاحقًا إلى قدرة جديدة أو تغيّر في المتطلبات، يعود الطلب إلى Decretum للتحقق والحل وإعادة التصريف.
Schema = what exists / semantic boundaries
Recipe = what should be done
Profile = execution characteristics and preferences
Registry = available implementations
Resolver = deterministic capability binding
Compiler = portable contract generation
Harness = actual execution and interaction
Store = persistent execution/research memory
الفصل المهم هو:
DECRETUM
Declarative Execution Compiler
|
+---------------+---------------+
| | |
Schema Recipe Profile
"what" "do" "how"
| | |
+---------------+---------------+
|
Resolver
|
capability + provider + integration
+ harness + readiness + policy
|
v
Execution Contract
|
v
External Harness/Agent
|
+------------+------------+
| | |
execute interact persist
| | |
+------------+------------+
|
Store
نواة المُصرِّف محايدة المجال. تعيش الدلالات الخاصة بالمجال في السجلات والمخططات بدلاً من فروع المُصرِّف.
أمثلة:
تساهم حزمة المجال بالقدرات والمخططات والوصفات والملفات الشخصية وبيانات المزوّد الوصفية. وهي لا تغيّر دلالات المحلّل/المُصرِّف الأساسية.
markdown ممتاز للشرح. لكنه ليس واجهة تنفيذ حتمية.
يفصل Decretum بين:
human intent
|
v
structured schema + recipe + profile
|
v
validated resolution
|
v
portable execution contract
|
v
agent / harness execution
يمنح هذا الوكلاء حدودًا قابلة للقراءة آليًا مع إبقاء خيارات التنفيذ خارج الوصفة.
يمكن لمهمة برمجية استخدام المُصرِّف نفسه:
apiVersion: decretum.dev/v1
kind: ExecutionRecipe
domain: software_engineering
id: build-user-service
name: Build User Service
version: "1.0"
objective: Build and validate a Python service.
capabilities:
- source.read
- source.modify
- dependency.install
- test.execute
- artifact.build
- container.build
profiles:
infrastructure: local-dev
language: python
testing: pytest
container: docker
agent: coding-agent
completion:
required:
- tests_pass
- artifact_built
- container_built
يمكن تصريف النية نفسها مقابل مجموعة تفضيلات أخرى:
profiles:
infrastructure: isolated-dev-vm
testing: pytest
container: podman
agent: enterprise-coding-agent
تصف الوصفة النية. ويعبّر الملف الشخصي عن التفضيلات. ويحدد سجل المزوّدين ما هو متاح فعليًا.
id: suspicious-network-investigation
name: Suspicious Network Investigation
version: "1.0"
role: threat_researcher
objective: Determine whether the sample creates unexpected network activity.
capabilities:
- process.observe
- network.capture
- artifact.collect
infrastructure_profile: isolated-linux-vm
instrumentation_profile: linux-network-observation
harness_profile: interactive-research
لا تحتوي الوصفة على دورة حياة Lima/Docker، أو تنفيذ MCP، أو مطالبات الوكيل، أو كود خاص ببيئة التشغيل.
لا ينفذ Decretum الخطوتين 9–10.
DISCOVER
|
PROPOSE
|
SEMANTIC REVIEW
|
APPROVE
|
CANONICAL CAPABILITY
|
PROVIDER IMPLEMENTATIONS
يمكن للاستكشاف أن يقترح قدرة، لكنه لا يستطيع تعديل الدلالات الأساسية بصمت.
git clone https://github.com/Opposum0112/Decretum.git
cd Decretum
uv sync
decretum capabilities discover
decretum validate recipes/<recipe>.yaml
decretum resolve recipes/<recipe>.yaml
decretum compile recipes/<recipe>.yaml
لا شيء في مسار validate/resolve/compile في Decretum ينفذ العمل.
Capability
|
Provider
|
Integration
|
Execution surface
|
Harness compatibility
|
Host/provider readiness
|
Policy compatibility
|
READY / BLOCKED
لا يصبح Decretum عمدًا:
بدلاً من ذلك:
Decretum
= declarative intent -> deterministic contract
Harness / Agent
= interactive execution environment
Store
= persistent execution or research memory
راجع ARCHITECTURE.md، وdocs/execution-contract.md، وdocs/domain-model.md للاطلاع على الحدود التفصيلية.