Introduce HarnessError in dsh-llm (the leaf package): a stable machine-routable
code distinct from the message, cause chaining, name from the subclass, plus
isHarnessError. LlmError, ToolArgsError, and InvariantError now extend it.
Tool failures carry the structure end-to-end: ToolExecutionResult gains
error: { name, code } (populated from a thrown HarnessError), and the loop
forwards it onto the tool/result session event (which gained the same optional
field) for retry/sandbox plugins and replay. The loop's toError wraps non-Error
throws in a HarnessError(code: UNKNOWN, cause) instead of a bare Error.
Landed last and in isolation so it's a pure upgrade over the plain Error+code
the earlier PRs used — independently revertible. Graduates RFC 005 pt 2 ->
ADR 0015; RFC 005 now fully implemented.
RFCs
Proposals for substantial future work — reviewed before implementation, unlike ADRs (which record decisions already made). Each RFC groups a related set of ideas from the quality/robustness proposal (2026-06-11); statuses move proposed → accepted → implemented (then usually graduate to an ADR).
| # | Title | Status |
|---|---|---|
| 001 | Property-based testing for protocol-shaped code | implemented |
| 002 | Mutation testing as the coverage counterweight | proposed |
| 003 | Deterministic tests + replay invariant fixture + race stress | proposed |
| 004 | Architectural rules: dependency-cruiser, adapter conformance kit | proposed |
| 005 | Runtime arg validation, structured error taxonomy, dev-mode invariants | implemented |
| 006 | Doc-sync enforcement and API extractor reports | implemented (pts 1-2; pt 3 deferred) |
| 007 | Supply chain checks and vendor drift verification | proposed |
| 008 | Deep-readonly public surfaces | implemented (revised) |