{"slug": "jiti-kernel-openai-generations-and-recovery-ascii-diagrams", "title": "JITI kernel, OpenAI generations, and recovery ASCII diagrams", "summary": "A developer built a kernel that keeps a running Lisp world alive while an external controller queries an OpenAI model for the next action to try. The model never edits memory directly; it proposes a single validated action that an SBCL worker checks against generation tags and invariants before accepting or restoring a checkpoint, rejecting stale proposals as out-of-date.", "body_md": "The project keeps a running Lisp world alive while an outside controller asks an OpenAI model what to try next.\n\n```\n                         \"What should we try?\"\n                                  |\n                                  v\n+------------------+       +------------+       +------------------+\n| Running Lisp     | ----> | Controller | ----> | OpenAI Responses |\n| world + kernel   | view  |            | prompt| API              |\n+--------+---------+       +------+-----+       +--------+---------+\n         ^                        |                      |\n         |                        | action               |\n         |                        v                      |\n         |                 +------+-----+                |\n         +-----------------+ SBCL worker|<---------------+\n           result / state  |             |  JSON proposal\n                           +-------------+\n```\n\nThe model never directly edits memory. It proposes one small, validated action; the worker decides whether that action is safe and current.\n\n```\n+----------------------------------------------------------------+\n|                         Lisp world                              |\n|                                                                |\n|  data table       function definitions       application state |\n|  +-----------+    +-------------------+     +----------------+  |\n|  | :x = 0    |    | (defun add ...)   |     | counters, ...  |  |\n|  +-----------+    +-------------------+     +----------------+  |\n|                                                                |\n|  The world adapter knows how to:                               |\n|    observe it       checkpoint it       restore it              |\n|    export it        import it           record accepted forms  |\n+----------------------------------------------------------------+\n```\n\nThe kernel manages only what the world adapter can describe. External files, arbitrary threads, and other side effects need their own adapter support.\n\n``` php\n+--------+    +-----------+    +------------+    +----------+\n| Observe| -> | Propose   | -> | Validate   | -> | Execute  |\n| world  |    | one action|    | generation |    | in worker|\n+--------+    +-----------+    +------------+    +----+-----+\n                                                    |\n                                                    v\n                                           +--------+--------+\n                                           | Check invariants|\n                                           +--------+--------+\n                                                    |\n                                +-------------------+-------------------+\n                                |                                       |\n                                v                                       v\n                           +----+-----+                           +-----+----+\n                           | Accept   |                           | Restore  |\n                           | revision |                           | checkpoint|\n                           +----------+                           +----------+\nphp\nTime ------------------------------------------------------------->\n\nKernel:       view at generation 7 ------- state changes ------- generation 8\n                 |                                                   ^\n                 |                                                   |\nOpenAI:         receives view 7 -------- returns action tagged 7 ---+\n                                                                     |\nWorker:         sees current generation 8                            |\n                 |                                                   |\n                 +-------------------- reject as stale --------------+\n```\n\nA generation is like a CS50 problem-set version number. The answer must match the version of the question that produced it.\n\n```\nWorker stack (still alive)\n\n+------------------------------+\n| worker-main                  |\n|  +------------------------+  |\n|  | evaluate application   |  |\n|  |   error!               |  |<---- condition is signaled\n|  +-----------+------------+  |\n|              |               |\n|              v               |\n|  +------------------------+  |\n|  | condition-loop         |  |\n|  | restart menu:          |  |\n|  |   0/0 use-value        |  |\n|  |   0/1 retry            |  |\n|  +-----------+------------+  |\n+--------------|---------------+\n               |\n               v\n        worker pauses and\n        waits for controller\n```\n\nA resume action selects a restart ID and supplies a Lisp list of arguments. The restart exists only while this worker is paused; it is not saved across a process restart.\n\n```\n                 checkpoint C\n                       |\n                       v\n              +--------+--------+\n              | outer evaluation|\n              |                  |\n              | repair 1         |\n              | repair 2         |\n              | resume call      |\n              +--------+---------+\n                       |\n             +---------+---------+\n             |                   |\n             v                   v\n       all checks pass       any failure\n             |                   |\n             v                   v\n       keep changes          restore C\n```\n\nThe outer call and repairs share one provisional checkpoint. A failed repair rolls back the entire attempt, preventing half-applied changes.\n\n```\n                 candidate world\n                       |\n             +---------+----------+\n             |                    |\n             v                    v\n      Safety invariants       Goal predicates\n      \"must never break\"      \"what we want eventually\"\n             |                    |\n             v                    v\n      failure => reject       failure => keep working\n                                  |\n                                  v\n                         all goals pass => success\n```\n\nThis allows useful intermediate revisions: a candidate can be incomplete while still being safe.\n\n```\nProcess A                         Disk                         Process B\n---------                         ----                         ---------\n\naccepted world ---- export ----> revision-123/\n                                  manifest.sexp\n                                  exported world\n                                        |\n                                        +--> CURRENT = revision-123\n\ncrash\n  |\n  v\n                                  recover-session\n                                        |\n                         +--------------+--------------+\n                         |                             |\n                         v                             v\n                   read CURRENT                 read diagnostics\n                         |                             |\n                         v                             v\n                   import revision             keep recent history\n                         |                             |\n                         +--------------+--------------+\n                                        |\n                                        v\n                              fresh worker, fresh stack\n```\n\nRecovery restores accepted managed code and data. It does not replay unfinished Lisp forms or pretend that an old call stack survived the crash.\n\n```\nstore/\n├── CURRENT                 points to the accepted revision\n├── revision-123/\n│   ├── manifest.sexp       identity, parent, SBCL version, events\n│   └── exported world      managed data and reconstructible code\n└── events.sexp             diagnostic attempts and conditions\n```\n\n`CURRENT` is authoritative. A torn final diagnostic record is archived during recovery and cannot replace the accepted revision.\n\n``` php\nobserve -> propose -> generation-check -> checkpoint -> execute\n        -> pause/repair if needed -> safety-check -> accept or restore\n        -> publish accepted revision -> observe again\n```\n\nSuppose the running application begins with one rule:\n\n```\nprice = 100.00\nrate  = 5%\ntax   = 5.00\ntotal = 105.00\n```\n\nThe user asks: `Create a sales-tax calculator using a 5% tax rate.`\n\n```\n(progn\n  (defun sales-tax (price)\n    (* price 0.05))\n  (defun total-price (price)\n    (+ price (sales-tax price))))\nview generation 0\n        |\n        v\ncheckpoint world\n        |\n        v\ninstall definitions\n        |\n        v\nsafety checks pass\n        |\n        v\naccept revision 1, generation 1\njs\n(sales-tax 100.00)   => 5.00\n(total-price 100.00) => 105.00\n```\n\nThe user asks: `Support different tax rates.`\n\n```\n(progn\n  (defun sales-tax (price rate)\n    (* price rate))\n  (defun total-price (price rate)\n    (+ price (sales-tax price rate))))\nphp\nrevision 1\n    |\n    | checkpoint\n    v\ntry new definitions\n    |\n    +--> checks pass --> accept revision 2\n    |\n    +--> checks fail --> restore revision 1\njs\n(total-price 100.00 0.05) => 105.00\n(total-price 100.00 0.08) => 108.00\n```\n\nThe user asks: `Use different rates for food and non-food items.`\n\n```\n(progn\n  (defun sales-tax (price rate)\n    (* price rate))\n  (defun total-price (price item-type)\n    (let ((rate (if (eq item-type :food)\n                    0.02\n                    0.08)))\n      (+ price (sales-tax price rate)))))\n+------------------+\n                 | total-price      |\n                 | price, item-type |\n                 +--------+---------+\n                          |\n                          v\n                 item-type = :food?\n                    /             \\\n                  yes              no\n                   |                |\n                rate 0.02        rate 0.08\n                   \\                /\n                    v              v\n                 price + price * rate\njs\n(total-price 100.00 :food)     => 102.00\n(total-price 100.00 :clothing) => 108.00\ncandidate calculator\n                          |\n                +---------+----------+\n                |                    |\n                v                    v\n          goal predicates       safety invariants\n          desired behavior      must-never-break rules\n                |                    |\n                v                    v\n       food total is 102.00   tax is never negative\n                |                    |\n                v                    v\n          incomplete goal      failure rejects attempt\n          means keep working\n```\n\nFor example:\n\n```\n;; Goal: desired behavior\n(lambda ()\n  (and (= (total-price 100.00 :food) 102.00)\n       (= (total-price 100.00 :clothing) 108.00)))\n\n;; Safety invariant: never accept a negative tax\n(lambda ()\n  (and (>= (sales-tax 100.00 0.02) 0)\n       (>= (sales-tax 100.00 0.08) 0)))\n```\n\nIf a proposal accidentally makes food tax negative:\n\n```\n(defun total-price (price item-type)\n  (+ price\n     (if (eq item-type :food)\n         (* price -0.02)\n         (* price 0.08))))\nrevision 2\n    |\n    v\ncheckpoint C\n    |\n    v\nrun bad proposal\n    |\n    v\nsafety invariant fails\n    |\n    v\nrestore C\n    |\n    v\nrevision 2 is still live\n```\n\nThe next user request starts from the last accepted calculator, not from the half-applied bad change.\n\n``` php\n+------------+       +------------+       +------------+\n| Revision 1 | ----> | Revision 2 | ----> | Revision 3 |\n| fixed 5%   |       | caller rate|       | food rules |\n+------------+       +------------+       +------------+\n      |                    |                    |\n      v                    v                    v\n  total(100)          total(100,.08)      total(100,:food)\n      105                  108                  102\naccepted revision 3\n        |\n        v\nprocess crashes\n        |\n        v\nread CURRENT\n        |\n        v\nload revision 3\n        |\n        v\nstart fresh worker\n        |\n        v\nfood and non-food behavior returns\n```\n\nThe accepted calculator and managed data return from disk. The old call stack and live restart objects do not; those exist only inside the original worker.", "url": "https://wpnews.pro/news/jiti-kernel-openai-generations-and-recovery-ascii-diagrams", "canonical_source": "https://gist.github.com/ghuntley/b8e28634090c51895d7972ff6a7c5619", "published_at": "2026-10-04 05:38:30+00:00", "updated_at": "2026-10-04 06:38:12.790561+00:00", "lang": "en", "topics": ["ai-agents", "large-language-models", "ai-tools", "developer-tools"], "entities": ["OpenAI", "SBCL", "OpenAI Responses API"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/jiti-kernel-openai-generations-and-recovery-ascii-diagrams", "markdown": "https://wpnews.pro/news/jiti-kernel-openai-generations-and-recovery-ascii-diagrams.md", "text": "https://wpnews.pro/news/jiti-kernel-openai-generations-and-recovery-ascii-diagrams.txt", "jsonld": "https://wpnews.pro/news/jiti-kernel-openai-generations-and-recovery-ascii-diagrams.jsonld"}}