System Architecture
Autolang is a capability-based orchestration language and deterministic runtime designed specifically for AI-generated code. It provides language-level capability control between untrusted AI agents and host applications, replacing general-purpose runtimes inside isolation boundaries.
System Overview
AI models are untrusted and are responsible solely for generating orchestration scripts. Once source code is produced, all subsequent operations are deterministic, strictly type-checked, and resource-bounded under the complete authority of the host application.
AI Agent & Prompt Generation
The AI model writes high-level orchestration logic. The model holds no database handles, secrets, or direct operating system access.
Autolang Compiler (Layer 1)
Verifies syntax against registered capability signatures. Rejects hallucinated methods at compile time and emits structured diagnostics.
Autolang Virtual Machine (Layer 2)
Executes bytecode within strict instruction limits. Traps execution loops, isolates heap memory, and enforces default-deny capability boundaries.
Declared Capability Interfaces
Explicitly registered host interfaces mapping allowed operations. Marshals arguments safely across native language boundaries.
Host Application & Business Systems
Trusted host environment (Node.js / C++ / Go) holds secrets and executes persistent business logic outside VM memory accounting.
Runtime Ownership Matrix
Clear boundaries separate non-deterministic AI generation from deterministic runtime execution and host business authority:
| Component | System Ownership & Authority |
|---|---|
| AI Model | Generates orchestration scripts; completely untrusted; holds no credentials or direct socket access. |
| Autolang Compiler | Performs static verification, ensures Surface Match compatibility, and emits structured compiler diagnostics. |
| Autolang VM | Deterministic stack interpreter; enforces instruction budgets and managed memory quotas; default-deny security. |
| Capabilities | Explicitly declared interfaces mapping VM calls to verified host delegates with parameter type validation. |
| Host Application | Owns absolute authority, database handles, API credentials, and execution policy configuration. |
| Business Systems | Downstream infrastructure (CRM, ERP, Payment, Storage); accessed strictly via host-controlled native code. |
Defense-in-Depth: Autolang + OS Isolation
Autolang does not compete with Docker, Firecracker, or KVM. Hardware and container virtualization provide operating system isolation, while Autolang provides language-level capability control.
Autolang replaces the general-purpose runtime (such as Python or Node.js) that would otherwise execute untrusted AI code inside those isolation layers. Running Autolang inside a microVM or container forms a robust two-tier defense-in-depth model:
Autolang Execution Runtime
KVM • Firecracker • Docker • Cloud Sandboxes
Enterprise Business Infrastructure
Credentials, production databases, and financial systems reside safely outside the guest runtime.
Execution Pipeline
Every AI request flows through four distinct, verifiable architectural stages:
LLM Code Generation
Generates orchestration code. The AI model's responsibility ends entirely once the source text is emitted.
Compiler Verification & Diagnostics
Performs lexing, parsing, symbol resolution, and static type checking. Rejects invalid calls before execution and emits structured diagnostics if self-correction is required.
Deterministic VM Execution
Executes instructions via a custom stack interpreter. Enforces opcode budgets, monitors VM memory allocation, and traps unhandled exceptions.
Host Capability Dispatch
Unwraps parameters and invokes host application functions under host authority. Downstream enterprise business systems are executed safely outside VM memory accounting.
Compiler vs. VM Division of Labor
The compiler and VM maintain a strict division between static analysis and deterministic execution:
| Compiler (Static Analysis & Correctness) | VM (Deterministic Execution & Bounds) |
|---|---|
| Parses source code into AST | Executes bytecode instructions in stack interpreter |
| Enforces static type checking and null safety | Evaluates operand stack and local variable registers |
| Emits structured diagnostics for AI self-correction | Decrements and enforces opcode instruction budgets |
| Validates declared capability library bindings | Tracks managed memory allocations and traps leaks |
| Rejects unknown identifiers before execution begins | Dispatches validated calls to host native delegates |
Host Application Authority
Autolang is an embedded language and runtime; it never runs as an unconstrained standalone server. The embedding host application (Node.js, C++, or Go) acts as the central authority:
Capability Registration
Declares explicit function interfaces using registerBuiltInLibrary(). AI can call only what the host exposes.
Credential & Socket Isolation
Database sockets, private keys, and API tokens remain completely outside VM memory. AI scripts receive only capability handles.
Enterprise Business Execution
Executes trusted business systems (CRM, ERP, Billing) in host native code. AI orchestrates the flow; host executes the logic.
Resource Governance
Configures strict instruction limits (e.g. 50,000 opcodes) and memory quotas to prevent execution loops and resource starvation.
Capability Boundary & Dispatch Flow
AI scripts orchestrate host capabilities instead of implementing core business logic directly. Scripts never hold credentials or database sockets:
AI Script Invokes Capability
Untrusted script calls declared identifier
VM Type & Budget Enforcement
Validates argument types against registered interface; decrements opcode budget
Native Parameter Marshaling
Parameters unwrap across native boundary without exposing VM pointers
Host Executes Under Full Authority
Host code authenticates request, binds credentials, and triggers enterprise business systems
Host Session Lifecycle
The lifecycle of a compiler and VM session within an embedding host follows a clean, deterministic lifecycle:
Create Compiler
ACompiler.create() initializes the compiler instance inside the embedding worker process.
Register Capabilities
Binds capability interfaces and native function delegates via registerBuiltInLibrary().
Compile AI Script
Parses source text, checks types, and outputs a validated binary bytecode chunk.
Bounded VM Execution
Executes bytecode under configured opcode budget and memory ceiling. Traps timeouts cleanly.
Instant VM Reset & Next Task
Clears operand stack and execution buffers in ~1ms without reallocating compiler memory. The process is immediately ready to run the next AI script.
Related Documentation
This Architecture overview provides the core system map. For implementation details, explore the related documentation:
Runtime & VM Internals
Deep dive into C++ VM internals, AObject struct memory layouts, stack frames, and allocation arenas.
Philosophy & Vision
Core design philosophy, default-deny security model, and performance context vs container isolation.
Native Libraries
How to define @native interfaces and register capability bindings with the compiler.
Security & Sandboxing
Configuring HTTP domain rules, file path allowlists, and instruction limit caps in host code.