Case study 18 / 26
Tarn
A small language for agent workflows: deterministic tasks, typed capability-gated tools, and record/replay of every side effect.
- Status
- Research
- Period
- 2026
- Domain
- ai · experiments
- Language
- Go
- Last push
- 06 SEP 2026
- License
- MIT
- Source of claims
- README.md, docs/LANGUAGE.md, ARCHITECTURE.md
Every side effect is a typed tool call that needs an operator-granted capability; tasks run in deterministic order; and any run can be recorded and replayed without the outside world. Go standard library only, with a gradual static checker, formatter and REPL.
01/The problem
Agent workflows are written in general-purpose languages where any library call can hit the network, concurrency reorders output, and reproducing an incident means re-running against a world that has moved on.
02/The system
Every side effect is a typed tool call that needs an operator-granted capability; tasks run in deterministic order; and any run can be recorded and replayed without the outside world. Go standard library only, with a gradual static checker, formatter and REPL.
03/Implementation
- 01Typed tool declarations bind host functions; arguments and results are checked in both directions at the boundary.
- 02Per-namespace capabilities on the command line (--allow http,fs,env,time,rand,proc), enforced at the call site with a message naming the missing flag.
- 03Cooperative tasks (spawn / await) that run in spawn order, so output is identical on every machine; par_map for real parallelism when wanted.
- 04--trace records every tool call; --replay serves them back and stops if the program diverges from the recording.
- 05Gradual static checker, an idempotent formatter and a REPL built on the same parser.
04/Engineering
Replay that verifies
A recording isn't just fed back: the replayer checks the program makes the same calls, in the same order, with the same arguments.
Time and randomness are tools too
time.now and rand.int go through the same capability system, and --seed fixes the RNG — there is no other source of nondeterminism.
05/Interface
No product screenshots are published for this project. The visual above is a code-driven representation of how it behaves, built from the repository source — not a screenshot.
06/Tech stack
- Go
- Standard library only
- Gradual typing
- Record / replay
07/Result
Verified outcomes
- Tests under the race detector: 20 static-error cases, deterministic task output across 20 runs, replay equality and divergence detection, and an 8,000-program fuzz that must never panic.
Known limitations
- Tree-walking interpreter — right for orchestration, wrong for number crunching; no floats, structs or pattern matching yet.
08/Links
Next case study
Spindrift →