# Agent Unary gRPC contract This directory is the project-owned W02 protocol baseline, created from the confirmed R01–R03/R05/R07–R13 responsibilities in `docs/contracts/通信与事件数据交互_v0.1.md` and the crash/authorization rules in `docs/architecture/G0开发准备与契约冻结提案_v0.1.md`. - Transport is Unary gRPC over mTLS; no internal MQ, bidirectional audio stream, or HTTP call-execution callback is introduced. - The protocol carries control, authorization, facts, metadata and restricted upload grants. It never carries recording/audio bytes. - `call_execute_json` and `payload_json` preserve the approved external JSON bytes; this Proto does not create a second external SaaS Schema. - `ExecuteAuthorized` carries the project-local `agent-authorized-origination.v0.1` decision. The Dispatcher persists a one-shot issued/refused decision after checking task × selected-line policy; the Agent checks only active session identity and the Dispatcher-issued exclusive deadline. This method is enabled only with an explicit isolated Mock adapter, which sends **no SIP**. Dispatcher V3 mixed/real startup rejects this path; neither the existing `Execute` method nor MQ provides a fallback. - `ApplyApprovedTaskControl` applies a task-level control for the authenticated Dispatcher and numeric tenant. Pause/stop first close Agent admission, then hang up or drain registered active calls before returning success; stop cannot resume. The approved-call runner must register active calls before this RPC can protect a live process; that main-entry integration is still pending. It does not use an execution binding, command ID, revision CAS, or control message deduplication. The Dispatcher remains the durable task authority. - `accepted` is durable receipt only; `applied`, terminal state and verified asset facts require later evidence. - IDs, epochs, boot/session generations, operation IDs and explicit idempotency keys are retained for idempotency, fencing and unknown-result reconciliation. - `ERRORS.md` is the companion error/CAS/fencing contract; it defines when a response is only accepted and when a caller must reconcile instead of retrying. Generation is deterministic with the pinned local tools: ```sh buf lint buf breaking --against '.git#branch=HEAD' buf generate ``` The Proto/Go package has no implementation-generation suffix. The existing `protocol_version` metadata (`agent.v1`) remains the meaningful wire-protocol version; field numbers are never reused. Production mTLS credentials and endpoints are deployment inputs, not repository contents. `ERRORS.md` and the Proto are released together; a field or semantic change requires a new compatibility review.